The increased monitoring and profiling of Internet users by companies such as Google and its DoubleClick online advertising subsidiary is widely seen as one of the biggest threats to online privacy. But in reality, said university professor Paul Ohm, the potential for the same kind of activities by ISPs poses a much greater privacy risk.
Ohm, an associate professor of law at the University of Colorado Law School in Boulder, published a research paper titled "The Rise and Fall of Invasive ISP Surveillance" late last month. The 77-page document chronicles the different market pressures and technology advances that are shaping the behavior of ISPs and warns of "a coming storm of unprecedented and invasive" surveillance of users by such companies.
[ Learn how to secure your systems with Roger Grimes' Security Adviser blog and newsletter, both from InfoWorld. ]
It isn't an opinion that is shared by everyone, but the issue has been getting an increasing amount of attention from privacy advocates and lawmakers.
Much of Ohm's concern has to do with the vantage point that ISPs have on the Web and their ability to take advantage of it in a hitherto unprecedented manner. In many ways, ISPs are far more able to track, monitor, and profile user behavior than Google and other online advertising vendors are, he said in an interview.
"I'm not saying that they are invading your privacy right now," Ohm said. "What the paper does is to play out the possibilities. ISPs have the power to obliterate privacy."
According to Ohm, ISPs have been fairly good custodians of online privacy -- until recently, at least. But a couple of factors are driving a change in the status quo, he claimed. One of them is the growing availability of sophisticated deep-packet inspection technologies that enable companies to collect and mine huge amounts of very granular information about Internet usage. ISPs looking to broaden their revenue sources could increasingly look to monetize this data -- for instance, by selling it to behavioral advertising firms, Ohm said.
Google's enormous success in the online advertising market has "redefined expectations for both profitability and privacy online," Ohm wrote in his report. He predicted that ISPs will attempt to replicate Google's success by trying to monetize user data at the expense of privacy protections. Offering them potential help are advertising firms such as NebuAd Inc. and Phorm, which are looking to partner with ISPs to access, analyze, and categorize the behavior of users for targeted advertising purposes.

Sign up to receive Security Resource Alerts
A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.
Download now! »Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.
Download now! »This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.
View now! »