Golden Pages - Spam Fodder?  

Privacy And Spam
Golden Pages Online Directory Raises Privacy Concerns
0030 Hrs 05 July 1999

When the Irish version of the Yellow Pages went online, it made all the phone number details, all the e-mail addresses, all the  websites in it's paper and CD-ROM directories available online. The databases are a direct marketeer's dream and the e-mail address directory is widen open to being harvested by spammers.

The Golden Pages is an attempt to exploit the popularity of the paper edition of the Irish version of the Yellow Pages. Each of Telecom Eireann's telephone directories has a Yellow Pages section. TE apparently has a majority sharholding of the company. The website is hosted on a Telecom Internet webserver. You don't have to dig too deeply beneath the gaudily designed and graphically intense frontpage to find TE.

The Golden Pages Online site is yet another attempt at a portal. This time it has a few good things going for it such as a number of unique and exploitable data sets. However the aesthetic quality is poor and the overall design is gaudy and reminiscent of the early days of the web. It tries too hard to imitate the paper version of the Golden Pages.

The aim of the Golden Pages site was to provide some kind of portal where people could find out details like phone numbers, addresses, e-mail addresses and websites. There was even a rather colourful TV guide. At the core of the operation were the Golden Pages data set and the Telecom Eireann phone directory. At this stage it should be pointed out that ex-directory numbers were not included.

The main problem with the site, from a security point of view is that the people involved do not seem to have appreciated the situation into which they were putting data. Most online personal telephone directories do not allow bulk retrieval based on areas. The paper form of the directories are indexed alphabetically. The only thing approaching such usability is the Telecom Eireann Phone Directory CD.

The Golden Pages online directory only superficially limits the results to 100 records. Examining the source code of the results frame, the comments explaining how the URL is constructed are plainly visible. These limitations are not hard-coded from the server side and are open to manipulation. It is possible to create an URL that will download the telephone directory for a whole city from the Golden Pages site.

From a web perspective this is an appallingly poor design in that it gives away control over the data to the client side and the control is the only thing that the Golden Pages has going for it. Once people can build the type of directory they want, the Golden Pages site becomes a once a month trip to refresh data.

There is an e-mail address directory on the site. This is a more pressing concern from an internet viewpoint. Unsolcited Commercial E-mail (SPAM) is a major problem on the internet. A few weeks ago there was a post from a Dublin based company offering cash for Irish e-mail lists. The fuel of the spammers is e-mail address lists. The Golden Pages has exposed the e-mail addresses in their directory for harvesting. It is an extraordinarily trivial task for a spammer to harvest the 5580 or so e-mail addresses that the Golden Pages has on it's site.

It is clear that the people behind the Golden Pages site share the same shallow mindset of TE's local.ie venture. Portals are not a case of "if you build it, they will come". Unfortunately the "they" in this case may be the internet's equivalent of sharks attracted to a newly dead corpse oozing it's lifeblood of information into the net.

Responsible sites that deal with Irish e-mail addresses tend to use a blind system where the sender is isolated from the recipient. Esearch is a very good example of this approach and it makes it difficult for a spammer to harvest addresses. However the Golden Pages site has no such technologically sophisticated solution. The result is that they 5880 or so e-mail addresses are potentially vulnerable to spammers.

The website directory is similarly vulnerable. Though the accuracy of some of the website's URLs tends to vary. In a few cases companies gave e-mail addresses for URLs and URLs for e-mail addresses. Directories like www.niceone.com and www.iesearch.com do not have much to fear from the Golden Pages website directory. While the Golden Pages may have some website details of questionable accuracy and value, the real Irish search engine sites offer context where the Golden Page offers addresses.

The discussions of the Golden Pages website on the Irish Internet Association mailing list have even made it as far as being mentioned in that august publication, but with dubious technological accuracy, the Irish Times. The mailing list was described as a chat room on the website. The report in the Irish Times was simplistic as the true nature of the disaster was not perceived. Instead it was represented as being a privacy problem of small proportions. What the Irish Times report did not make clear was that there is absolutely no real protection on the data in the Golden Pages directories. Direct Marketers or spammers could easily harvest the data from them.

The way that the data is made available on the Golden Pages site, without any care for how that data could be used and without any real safeguards from the server side, indicates a complete lack of planning. It would probably be more accurate to say that the people responsible were just ignorant of the threats that the internet holds for unprotected data. It would not be the first time and it will not be the last.

Data Harvesting And Legalities

One of the main law cases in the Irish jurisdiction dealt with Kompass. Apparently someone had found a better and quicker method of accessing Kompass' online database than via Kompass's user interface. A critical point here is that Kompass' Acceptable Use Policy document states specifically that  "The Licensee shall not access the Kompass Service by any means, or in any sequence, other than those provided by the Kompass Service as part of its normal user interface". The AUP on the Golden Pages site makes a reference to unfair extraction but does not specifically state that you have to use a browser.

After the article above was posted to the web and a posting concerning the lack of a standard user interface clause in the AUP, staff at Golden Pages modified their AUP to include one. [0010 Hrs 05071999].

It is worrying to think that the people behind the Golden Pages online directory would think that spammers would be detered by such an apparently weak AUP.

Update To Follow - Monday 05 July 1999

Section: Irish I-News

Web Ireland Internet Awards Get Real?   07 June 2000
Eircom Hi-Speed - Just ISDN   24 May 2000
Online.ie - The Future Of The Irish Internet?   20 March 2000
Local Ireland - Still Clueless   20 March 2000
Could Technology Journalists Kill Online.ie's Technology Section?   20 March 2000
Unison - The Sound Of One Hand Clapping   27 February 2000
The Rise Of The E-jits   25 February 2000
Denial Of Service Attack Cripples Major Websites   09 February 2000
Eircom To Float Internet Division?   28 January 2000
New IEDR Rules To Permit Generics?   28 January 2000
More Irish Sites Cracked   16 January 2000
Sunday Business Post Discovers Cyber Promo Two Years Too Late!   16 January 2000
The Irish Cracks Of 1999   16 January 2000
Adornais Beats Adornis/Nua   02 November 1999
Ashford Beats Adornis/Nua   21 October 1999
Web Ireland Internet Business Awards   15 October 1999
Eircom Launches Free ISP   14 October 1999
Security Flaw Hits Ireland.com   01 September 1999
Esat Flat Rate Access Nukes TE   11 August 1999
Will Flat Rate Access Destroy Free ISPs?   11 August 1999
Domain Name Typo Causes Red Faces   30 July 1999
WebIreland's Strange Content Problem  28 July 1999
GP -Offline Marketing Fails Online  09 July 1999
Golden Pages Directory - Spammer Fodder?  04 July 1999
Oceanfree - Ireland's First Free ISP  10 June 1999
Is ireland.com Really A Portal? [27 May 1999]
local.ie - Not Local Or A Portal [26 May 1999]
Pro-Spam Article On ireland.com [20 Mar 1999]
Problems For ireland.com [15 Mar 1999]
IT Launches ireland.com [10 Mar 1999]
Irish ISP Attacked [17 Feb 1999]


© 2000 Hack Watch News
McCormac's Hack Watch News, Hack Watch News and Syndicated HackWatch are trademarks of Hack Watch News 

 

 

Recommended

Digital Darwinism - Buy The Book
 

Webonomics - Buy The Book
 

Information Architecture - Buy The Book
 
 Front Page
 Hack News
 Irish iNews
 Legal Action
 Telecoms
 Business
 Digital TV
 Cryptography
 BookReviews
 Linux News
 Security
 Microsoft
 Software
 Internet
 Black Book
 BookShop
Section Index