For those that are new to the reason that Phorm is bad from an enduser perspective lets provide a useful anology from BadPhorm
Sending / Receiving letters
Every letter you send or receive is transported by the postal service. You write a letter, put it in an addressed envelope, send it to the recipient and it is delivered there safe and secure. You also receive letters the same way - safe and secure.
One day the post service do a deal with a junk mail outifit. The way it works is: every letter you sent is opened, the contents copied and sent to adsnoopers, and your original letter routed on it's way. The same applies to letters you receive: what is sent to you is opened, copied, processed...
The adsnoopers then use your information to determine what type of ads to send you.
Now the legal teams will say you are totally anonymous - the adsnoopers don't get to see your address on the envelope...
But they do get to see everything inside those envelopes...
Read any messageboard? Everything you read will be sent to adsnooper.
Post on any messageboard? Everying you send will be sent to adsnooper.
Regularily update your facebook page? Your id, details etc. are all sent to adsnoopers.
Read mail via a webmail package, enter bank account details and ? It can all be sent to adsnoopers.
In summary not just what urls you visit, or what search terms you search for are processed but nearly everything you type and read is analysed and processed.
There is very little users can do to prevent this. The service forces you to opt out via a cookie and each time you reset your cookies you have to opt out again.
The best option is to get this kind of invasion of privacy banned at the start.
In the meantime who can tell me how to set my server up for http tunnelling?
*obviously ssl / https will be a bit difficult to read but the info is still sent to adsnoopers. There is a statement that "any sequence of 3 or more numbers is filtered out" so that they do not capture bank account details and credit card numbers. This implicitly proves that they do read everything you post and type.