Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, September 3, 2013

First NSA, now DEA - the scope of snooping expands

According to a report in the NY Times, DEA and local drug enforcement officials have had access to decades of information on phone calls compiled in an AT&T database.
  The Hemisphere Project is a partnership of federal and local drug enforcement with telecom giant AT&T.  Under the Project, AT&T is paid to embed their employees with drug-enforcement units across the country.  When presented with an administrative subpoena (granted by the DEA, not a judge or grand jury), the AT&T embed can access AT&T's internal database and provide the specified information.
  The AT&T internal database contains records of every call that went through an AT&T switch, user info, and location information.  It was originally constructed to facilitate billing, and contains records of all calls going through AT&T switches since 1987.  Training slides for Hemisphere personnel (sent to the Times by an activist) stress the secrecy of the project -
“All requestors are instructed to never refer to Hemisphere in any official document,” one slide says. A search of the Nexis database found no reference to the program in news reports or Congressional hearings. 
The Obama administration has acknowledged the existence of the Hemisphere Project and its extraordinary scale and scope, but suggested that it's not a privacy issue because the database is maintained by AT&T, and not the government.
Jameel Jaffer, deputy legal director of the American Civil Liberties Union, said the 27-slide PowerPoint presentation, evidently updated this year to train AT&T employees for the program, “certainly raises profound privacy concerns.”
“I’d speculate that one reason for the secrecy of the program is that it would be very hard to justify it to the public or the courts,” he said.
AT&T declined comment.

Source -   Drug Agents Use Vast Phone Trove, Eclipsing N.S.A.'sNew York Times

Tuesday, April 30, 2013

Did You Know? - Email Privacy

In the U.S., the Electronic Communications Privacy Act (ECPA) currently allows law enforcement agencies can subpeona two broad classes of emails without having to show probable cause or obtain a warrant - any email that's been opened by its recipient, and any email that's at least 180 days old.
  Now this might not have made waves when the ECPA was initially passed in 1986, but some recent high-profile email snooping has brought the practice to light.
While ECPA was designed to balance people's privacy rights with the needs of law enforcement agencies investigating crimes, privacy rights groups have accused the Department of Justice of taking an overly broad interpretation to ECPA, based on the agency's reading that old emails aren't subject to protection under the Stored Communication Act.
After the Ninth Circuit Court of Appeals, which covers the western United States -- including California -- ruled that the Stored Communications Act did apply to emails, the Justice Department advised investigators that when accessing emails more than 180 days old without using a warrant, they should do so outside the court's jurisdiction. 
When the US Justice department starts advising law enforcement to ignore the law (as long as they don't get caught in the Ninth Circuit), that's ringing the privacy alarm bells and asking for added legislative and judicial oversight.

One reaction is the Leahy-Lee ECPA Amendments Act, which was approved by the Senate Judiciary Committee last week.  The bill would require law enforcement to obtain warrants in order to access stored online communications and content (including documents, pictures, and other information stored in the cloud).
"I have long believed that our government should obtain a search warrant -- issued by a court -- before gaining access to private communications," Senate Judiciary Committee Chairman Patrick Leahy (D-Vt.) said...
I'm hopeful for speedy passage through Congress, and a Presidential signature.  But Congress has had trouble getting online and privacy laws right, and one has to wonder whether this President would be willing to reign in his own Dept. of Justice.  Given this administration's track record of ignoring laws and court rulings it doesn't like, I'm not so positive about the eventual outcome.

Source -  Email Without A Warrant? Senators Not SoldInformation Week

Tuesday, March 19, 2013

The Internet, Big Data, and the Surveillance State

In a recent opinion piece for CNN, Bruce Schneier proclaimed: "The Internet is a surveillance state."

The Internet's never been secure or private - by design.  It's design goals were to be open and shared - to make it universally accessible, flexible, and adaptable.  And for those who remember the DARPA (defense-related) roots, even there the primary goal was survivability rather than security.  There's a reason the military's never relied on it.
  Sure, there are things you can do to make Internet use somewhat more private - use encryption, route through anonymizers, etc.  But still, every bit of data carries addresses, and all that flexibility and sharing requires that basic information on users and connected devices be readily available.  Add the fact that every data packet travels public routes where they can be duplicated, and ISPs and servers regularly back-up content and messages, and you realize that the Internet is a very public place.  As for encryption, industries trying to rely on encryption for copyright protection (as well as governments) have found that every encryption system is beatable, given enough brains, computing power, and time.  That many governments seek to restrict the use of encryption technology is a matter of laziness and cost rather than a fear of totally private communications.
  For a long time, the sheer volume of Internet traffic provided a bit of privacy protection for common users - searching through the volume of packets and files, identifying and matching traffic through multiple sites, etc. was just too problematic.  But if you had the resources, you could often break through whatever privacy/security roadblocks used (if any).  Schneier offers three recent illustrations -
  • the Chinese military hackers that have been attacking U.S. and European government, military, and commercial sites, were identified in part as they accessed their Facebook accounts through the same networks and hardware used for the hacking.
  • a leader of the LulzSec hacker collective was identified and arrested, reportedly because he slipped up and once logged into an IR chatroom in the clear - without masking his IP address as was his normal practice.
  • Paula Broadwell, who had an affair with then CIA Director David Petraeus, was identified despite only logging into the anonymous email account created and used for the affair from public internet sites.  The FBI reportedly identified her by matching hotel and service receipt records from the times of the emails, and finding hers was the one name in common.
Schneier's point is that Internet traffic is widely tracked, and not only by governments and counter-espionage organizations.  Google does it on everything running through one or another of their sites.  Google also tracks and records websites and content for its search engines.  Blogger.com, for example, lets me know who's visited this blog, where you're from, what OS you're running, and how you found me.  Apple tracks user behaviors on iPhones and iPads.  Facebook tracks its members and their behaviors, and backs up their content and submissions.  They've also admitted tracking their members non-Facebook activities, and using cookies to track online behaviors of non-members who visit Facebook pages.  Pretty much every commercial site builds profiles of users and customers.  And metrics firms collect and track data (anonymized, they say) on users and their Internet behaviors in terms of data traffic flows..

Now if all these were separate, private, and secure, they may be seen by many as the acceptable cost for the services and benefits provided by the Internet and various online services.  Even if they were shared, it might not be so bad, if it would take significant time and effort to try to link things together (particularly if you're looking for patterns in behavior).  If "surveillance" was too costly or inconvenient to be used regularly or for trivial purposes.
However, that's increasingly not the case, due to technology advances and the rise of Big Data.  If you haven't heard the phrase before, Big Data refers to a range of programs and techniques for trolling extremely large data sets (such as online tracking data) to tease out and identify patterns and links.  With Big Data to help, the sheer volume of online data is no hindrance.  Automated systems can scan millions of emails in real time looking for key words or phrases.  Automated systems can match online searches, or the use of certain apps, to purchasing behaviors and location data from mobile devices to send users a coupon for a nearby store or restaurant.  And data storage costs keep falling.  (And while not exclusively Internet, facial recognition software and the myriad private and public video cameras can be used to track a person's movements).
  As Schneier puts it,
This is ubiquitous surveillance: All of us being watched, all the time, and that data being stored forever. This is what a surveillance state looks like, and it's efficient beyond the wildest dreams of George Orwell.
Nor does there seem to be an easy solution, or a means of opting out.
There are simply too many ways to be tracked. The Internet, e-mail, cell phones, web browsers, social networking sites, search engines: these have become necessities, and it's fanciful to expect people to simply refuse to use them just because they don't like the spying, especially since the full extent of such spying is deliberately hidden from us and there are few alternatives being marketed by companies that don't spy.
So, Schneier concludes, welcome to an Internet without privacy; welcome to the Internet surveillance state.  While public interest groups try to raise concerns about privacy, and individuals rant, the public doesn't seem to mind - as long as Amazon and Netflix make good recommendations, YouTube lets you know about the latest "cute kitty" viral video, and social media don't charge fees.  The Internet was never truly private in the first place, and isn't likely to ever significantly shift in that direction.  In part because one of the significant public values of the Internet comes from the lack of privacy and the ability to find and make connections.  What international and national regulatory moves there are are about giving governments more control over the Internet, and more access to the information it transmits and generates.  Which means even fewer real privacy protections.

  If that worries you - and it should - you could go offline.  But in a modern global information society, that comes at a high cost.  Or you could try to level the playing field, as David Brin suggests in The Transparent Society - let us, as citizens, have the same access to surveillance of government activities as the government has over our activities.  Make government truly transparent, rather than settling for "transparency" being defined as giving people access to information the government wants to provide them.  Turn the cameras around, open records, and let the public see what government actually does, rather than only what the government claims it's doing (true or not).  Or hoping that an (increasingly scarce) honest and aggressive press will investigate and report, and do the monitoring for them.

Sources -  The Internet is a surveillance stateCNN Opinion
David Brin's Transparency website

Edit - fixed some typos

Tuesday, November 27, 2012

Hacking Greece

Greek authorities have arrested a man in possession of 9 million online personal records.  Police confirmed that the records included identity card details, tax numbers, vehicle license plate numbers, and home addresses, suggesting that the data was obtained from government sources.  It's unclear how the files were obtained, or what the man planned to do with the information, but it's most likely the data was hacked from government databases, or illicitly copied from them.

Still, it's the size and comprehensiveness of the theft that's the significant thing.  While it appears that there is some duplication among the 9 million files, the total population of Greece is around 11 million.  So basically, if you're a Greek adult citizen, somebody had a lot of your personal identification numbers.
And Greece has another big national concern to deal with.

Source -  Greek Man Accused Of Stealing Data on 9 Million CitizensDarkReading.com

Tuesday, November 20, 2012

Leahy's Email Privacy Bill does 180

Last May, Senator Pat Leahy (D, Vt.) introduced the "Electronic Communications Privacy Act Amendments Act of 2011" (PDF), ostensibly to ensure that police and government agencies needed a search warrant to access private conversations and information about locations of mobile devices.  The bill was, in part, a response to arguments from Obama's Dept. of Justice that "warrantless tracking should be permitted because Americans enjoy no "reasonable expectation of privacy" in their, or at least their cell phones', previous locations."

As the bill nears its scheduled vote next week, its come out that the bill has been dramatically rewritten.  Rather than protecting privacy, the revised bill specifically allows more than 22 Federal agencies "to access Americans' e-mail, Google Docs files, Facebook wall posts, and Twitter direct messages without a search warrant."  The revised bill would also expand the powers of the FBI and Homeland Security "to gain full access to Internet accounts without notifying either the owner or a judge."
Christopher Calabrese, legislative counsel for the American Civil Liberties Union, said requiring warrantless access to Americans' data "undercuts" the purpose of Leahy's original proposal. "We believe a warrant is the appropriate standard for any contents," he said. 
Leahy is said to have been pressured by groups representing police and district attorneys, as well as some strong politicking from the US. Justice Dept., to limit online privacy protections, or at least include major exemptions.  The revised bill does retain some protections from local and state police actions, but critics say it opens the floodgates for misuse at the Federal level.

Source -  Senate bill rewrite lets feds read your e-mail without warrantsCNet News

Sunday, November 11, 2012

Apps & Personal Data - Android, Not So Good

Two recent research reports are raising questions about just how much free apps are costing you - in terms of personal & private data.  Android apps in particular.
  The Bit9 study, found that more than a quarter of Android apps access personal data such as contacts and email, while 42% get GPS information, 31% access phone calls and phone numbers, and 9% could cost you money (mostly through premium SMS text message charges) - and not always with your permission.
"What's interesting about the mobile world is that [risky] apps aren't always malicious," Bit9's Sverdlove says.  In a (mobile-friendly) enterprise, the key is apps with access to potentially sensitive information could be exposed or abused, he says.
  Juniper Networks looked at 1.7 million apps available through Google Play,  They found that free apps were four times more likely to track locations than paid apps, and more than three times more likely to access user address books and contacts.
"It's OK for a free app to check location if they want to advertise. That's reasonable. But what's not is not being transparent and clear [about necessary permissions], and not providing the end user with really good data to make decisions" on whether to download the app, (Juniper's Dan Hoffman) says.
Juniper found that almost 7% of free apps can access address books, 2.6% can send text messages without the user knowing, 6.4% can make calls, and 5.5% can access the device's camera.  And only a small fraction of the apps actually used the personal data they collected to target third-party ads.
  Juniper also found that the worst offenders were cards and casino games apps (84% of those apps can use the device's camera, and 85% can text) and racing apps (99% can send SMS texts, 95% can place phone calls).

The full Juniper report is available here, and the full Bit9 study, here. 

Source -  More Than 25% Of Android Apps Know Too Much About You,  DarkReading

Saturday, September 29, 2012

Interpreting COPPA and Children's Privacy - A Step Too Far?

The main thrust of the Children's Online Privacy Protection Act (COPPA) was to limit Web site operators collecting personal information from children without the express permission of their parents.   The FTC (Federal Trade Commission), which oversees COPPA compliance, recently started considering expanding COPPA coverage and reach by broadening definitions of "personal information," "knowingly collecting," and website "operator."  While COPPA explicitly gives the FTC the ability to define, or re-define, those terms, the proposed expansions are substantial, and would significantly expand both the activities covered and the online sites and services covered.  While a number of children's and privacy advocacy groups fully support efforts to protect children's privacy, a number of industry groups have legitimate concerns that some of the proposed expansions could have significant unintended effects for all Internet users.  The Interactive Advertising Bureau (IAB), for example, indicated in formal comments to the FTC that enforcement of the expanded definitions (as formally proposed) could "restrict children’s access to online resources by undermining the prevailing business model" and "pose technical challenges to the effective functioning of the online ecosystem."
  So what are the issues, and what's really at stake?

"Operators" - or who does COPPA apply to? 
The statutory language of COPPA defined operators essentially as commercial website operators who collect personal information from users and where the website is either directed towards kids, or are general interest sites that knowingly collect personal information from children under the age of 13.  The current proposals would ad to that group third-party services such as social media plug-ins, ad networks, online gaming, and mobile apps.  In proposing the expansion, the FTC provided this rationale -
"The Commission now believes that the most effective way to implement the intent of Congress is to hold both the child-directed site or service and the information-collecting site or service responsible as covered co-operators... (A)n operator of a child-directed site or service that chooses to integrate into its site or service other services that collect personal information from its visitors should be considered a covered operator... Although the child-directed site or service does not own, control, or have access to the information collected, the personal information is collected on its behalf."
While the intent may be to assure that sites don't avoid protecting kids' privacy by farming data collection to a third party, it's difficult to frame regulatory language that would differentiate websites take use third parties to collect personal information, and/or benefit from collected user information, from websites with no interest in, or use for, user data yet link to services and sites that do. The proposed expansion would also make third party operators who collect user information liable for COPPA compliance if any affiliated or networked website is directed towards children, regardless of whether the "third party operator" has any interest in, or intent to, collect user information from children. If the implementing language is too broad, it could have the effect of making every website or online service provider legally liable for the content focus and user data collection practices of every website or online service they are linked to, or interact with. Given the nature of the internet, holding publishers liable for the COPPA compliance of affiliated services or linked sites and services would likely create a logistical nightmare of previewing and vetting of content, focus, and any user data collection practices. In their formal comments on the proposed changes, the Interactive Advertising Board (IAB) claimed that "pose technical challenges to the effective functioning of the online ecosystem." Particularly for website operators or online publishers who aren't commercial and have no interest in, or use for, user data.

"Knowingly collecting," or what evidence of intent or purpose is required?
The FTC is also proposing to expand the standard of intent by shifting from applying to operators who knowingly collect kids' personal information, to apply when operators might have "reason to know" that personal information is being collected from or content is directed towards children under the age of 13.
In regulatory and legal circles, reason-to-know is widely acknowledged as a broader, looser standard than actual knowledge of actions or behaviors. The FTC, as noted in the quote above, sees their mandated purpose as protecting children's privacy by requiring parental consent to collect personal information from kids, even if it is not knowingly and intentionally collected. The reason-to-know standard would extend COPPA to at least some incidental collection of covered user data, but not the absolute coverage that many advocacy groups have called for. They would prefer to see that privacy coverage and requirements for parental consent for data collection from kids be universal, to assure that no personal information is ever collected from children under thirteen without explicit parental consent.
Implementing a vaguer and looser standard can be problematic - "knowingly" is a clear and precise standard, even if can be difficult to provide. "Reason-to-know" is not precise, but has been interpreted in other settings as existing when an individual could reasonably expect something is probable - in this setting, would not be surprised if a third party operator collected personal user information or directed content or services to kids. Still, there's a lot of imprecision and uncertainty left - for example, should a blogger targeting seniors that links to an online social gaming app be e know what user information the app collects, or whether children under 13 are playing that social game app?
And if combined with an expansion if the definition of operators to second and third parties, the costs of compliance are spread to those who are only peripherally involved with children or collection of user data.

"Personal information," or just how personal does information need to be?
To a very large extend, the Internet, mobile, and social media systems run on user data, because sending and receiving information requires some kind of address. Data transfers online need IP addresses; mobile communications require unique identifiers for devices or users; and social media need to know where to send whatever stuff we share with friends and followers. The original statutory language of COPPA used older offline definitions widely used in privacy contexts - names, street addresses, social security numbers, phone numbers; and added email addresses as a nod to the Online context. But in an ever-evolving online ecosystem, these aren't our only addresses, or unique identifiers. If the concern about collecting personal information is that whatever other information or behaviors that are being collected can be directly linked to a specific individual, then the FTC really does need to look at what it defines as personal information.
Last year, the FTC proposed expanding the definition of "personal information" to include any "unique identifier" that could be used to link a child's activities on multiple sites. The proposal identified a few examples of unique identifiers - IP addresses, device serial numbers, tracking cookies. The online world is replete with unique identifiers; as are the worlds of mobile devices, wireless services, mobile phones, and social media. As I said earlier, they all need addresses - and addresses that aren't relatively unique identifiers aren't that useful. Are the FTC's examples appropriate?
In one sense, clearly not. As the IAB pointed out, the problem with the listed identifiers is that they aren't necessarily user-specific - what they are are primarily device identifiers. If there are, or may be, multiple users, that can decouple these unique identifiers from an unique person. (We've gone through this with IP addresses, which were initially permanently assigned to a device. When the number of devices exploded, and Internet Service Providers noted they weren't always on, they switched to dynamic IP addressing, where the unique address is assigned when the device is actively connected, but tossed back into the ISP's pool of IP addresses when the device was disconnected, to be assigned to another device when it actively connects. To uniquely link an IP address with a specific computer, you now need both the dynamic IP address and the time). The proposed new unique identifiers permit the delivery of content and advertising to a device, not to an identified individual," the IAB argues.
In addition, device identifiers are largely automatically generated and provided with online activities without user input or direct authorization. This creates a variety of potential issues - are dynamic IP addresses new unique identifiers that require user or parental validation of permission to use? would COPPA be invoked if several distinct online services share a common password/login (linking across sites)? Would Internet-connected devices need to be child-proofed in the absence of parental consent to collecting device identifiers? How might this impact "TV Everywhere" implementation, which needs unique identifiers not only as device address, but for validation of eligibility to receive specific content? How might that affect the potential distribution of children's programming, or educational content or games? There's a real conflict between the need for tracking use and validating eligibility through the use of unique identifiers and tracking user behaviors and the primary funding mechanisms for websites and online services (advertising and subscriptions). Defining unique identifiers poorly or inappropriately would create significant compliance costs that could only be avoided by prohibiting children's access and use. In such a case, the IAB expressed concern that it could "restrict children’s access to online resources by undermining the prevailing business model."
A closer look at the FTC's proposals and supporting arguments suggests that their real concern was the potential use of behavioral advertising techniques on children under 13. The FTC did include a specific proposal for a ban on using behavioral targeting techniques on young children without their parents' permission. But the courts can be reluctant to apply content-related bans without specific evidence of harm. That could explain the FTC's choice of specific unique identifiers and emphasis on linking behaviors and information across sites - their list mirrors what is needed for behavioral advertising to occur. Thus, the FTC may have felt that expanding the definition of "personal information" in that specific direction could be a backdoor means to limit behavioral advertising to kids. The problem here is that these same elements are also at the heart of a great many other online services and activities, so this expansion would have unintended (I hope) negative consequences in many other areas. Particularly if the expansion of "personal information" to include a range of other "unique identifiers" and the idea of "persistent identifiers" defined as identifiers shared across sites or services, gets carried through to other privacy regulation.
Including device registration numbers as "personal information" could really impact the rapidly expanding growth of mobile services, as apps and services would need to find other means to identify and validate devices and uses. The whole foundation of social media and interconnected sites and services is similarly built on the availability of "persistent identifiers."

A Step Too Far?
The FTC clearly has the authority to consider redefining these key aspects of COPPA, and strong arguments can be made that it needs to, considering how the online world has changed in the last decade. (Not to mention the pressures being applied by a variety of advocacy and industry groups).  The most immediate need is for the FTC to seriously consider expanding the definition of "personal identifiers."  The original statutory examples are mostly borrowed from regulatory language applying to analogue and physical concerns.  The language, for the most part, is far too narrow to reflect data or information that can identify individuals in an online world filled with myriad "unique identifiers" that could easily be used to link individuals with the information they provide and the actions they take online. But you can't ban or limit the use of all unique identifiers without crippling the Internet, or an increasing number of media devices and services - or banning their use by the people who's privacy you're trying to protect. Redefining "personal information" needs to be approached with a surgeon's scalpel rather than a blunderbuss, as any change is likely to have widespread and profound implications.
  In any consideration of expanding the kinds of identifiers to be included in a definition of "personal information" the FTC (and regulators generally) shouldn't pick them because they might achieve a specific policy goal. Even if they do, they'll also impact any other uses that rely on or utilize that specific type of identifier. Regulators need to consider the other implications and effects of proposed regulatory changes before redefining things - otherwise someone's likely to wonder why it didn't do what it was supposed to, and/or how to fix the mess it's created somewhere else.

Sources  -  FTC Proposes New Curbs On Collecting Data From ChildrenOnlineMediaDaily
IAB: Proposed Children's Privacy Rules Undermine Business Model,  OnlineMediaDaily
FTC,  Proposed Rules Changes for Children's Online Privacy Protection Rule
FTC's COPPA website










Thursday, July 12, 2012

Wireless Surveillance On Rise

In response to a Congressional inquiry, nine US wireless carriers indicated that they had received more than 1.3 million requests for user data from U.S. law enforcement agencies in 2011.

  Most carriers provided only a aggregated total of requests, although there was enough information to suggest that the number of requests had been increasing between 12% and 16% per year.  MetroPCS, a small carrier emphasizing prepaid service, revealed it received about 12,000 requests a month between the start of 2006 and May, 2012.  AT&T provided more details on the requests they had received -
Of the 131,400 subpoenas and 49,700 warrants it received in 2011, only 965 were rejected. (For reference: AT&T had 103,200,000 customers that year. On average, that makes more than one subpoena for every thousand AT&T customers (although it's just possible that one very naughty customer got all the subpoenas.))
AT&T indicated that it has a staff of 100 people dedicated full-time to dealing with such requests.  Other carriers indicated that while federal law indicates that should reimburse carriers for the cost of collecting the requested user data, law enforcement agencies rarely do.
  While most requests require a warrant or subpoena, there is also a class of requests that can be classed as emergency (for example, getting address for a customer calling 911 but unable to provide their location).  The study also revealed another class of requests that worry privacy advocates - cell tower dumps.  Instead of focusing on a particular user or phone number, a tower dump requests information from all users whose calls passes through a particular tower over some period of time.  Tower dumps can include hundreds or even thousands of users, most of whom would not be the target of investigations, and whose private information would still end up in the hands of authorities.

Look for this to continue to be an issue.

Sources - In First U.S. Accounting of Wireless Phone Surveillance, Carriers Reveal 1.3 Million Requests for User Data, PopSci
More Demand on Cell Carriers in SurveillanceNY Times
Congressman Markey's office has posted the Carrier responses (reports).

Wednesday, February 29, 2012

Europe reacts to ACTA - The Other Problematic Anti-Online Piracy Policy

For those following the SOPA/PIPA issue in the U.S. (Earlier posts here and here), it's time to turn the focus onto its global equivalent, the Anti-Counterfeiting Trade Agreement (ACTA).  ACTA aims to be an intellectual property enforcement treaty aimed at stemming global commerce in counterfeit products, generic medicines, and Internet based copyright infringement.  Unlike almost every other international treaty or trade agreement, negotiations over the language of ACTA were kept secret.  The U.S. declared information about ACTA to be a State Secret when consumer interest groups filed Freedom of Information Act requests for documents related to the treaty and U.S. government negotiating positions (despite sharing Treaty language with a number of industry trade groups and large corporations)..  Legislatures in a number of countries were asked to ratify, or pass resolutions of support for,  ACTA without being provided access to actual Treaty language.  Nevertheless, various documents and drafts of sections were leaked during 2009 and 2010.  By spring 2010, enough of a draft was released that groups of academics and public interest groups were holding meetings to address a series of concerns.  In June, one such group concluded "that the terms of the publicly released draft of ACTA threaten numerous public interests, including every concern specifically disclaimed by negotiators," and a group of 75 law professors signed a letter asking President Obama to halt efforts to push ACTA and work to address concerns over language that would abridge long-established rights, and his announced plan to commit the U.S. to ACTA solely on the basis of his executive authority (Under the U.S. Constitution, international treaties like ACTA are supposed to be ratified by Congress before they become valid).

These concerns remained unaddressed, and representatives of 31 governments (all but one advanced industrial economies) last October.  Many EU states were pressured to sign, and the European Parliament was supposed to ratify the agreement to extend coverage to the full EU community, but a number of states expressed serious reservations, and a wave of public protests erupted.  The European Commission has attempted to defuse the concern by pulling ACTA ratification, pending a review by the European Court of Justice as to possible conflicts with guaranteed privacy (and other human) rights.  It seems unlikely that this will halt what seems to be a growing concern about privacy, Internet-freedom, and protecting user's rights. 

In a post on the Atlantic blog, Tyson Barker suggest that Anti-ACTA protests tap into major concerns -
"In Germany and the former communist states of Central Europe, where history is rife with examples of states using vaguely worded laws as tools for invasive domestic surveillance, privacy and Internet openness as core rights have worked their way into political discourse and even into party structure. The Pirate Party took more than seven percent in the European elections in Sweden in 2009. Germany's Pirate Party took 8.9 percent of the vote in the Berlin state elections in 2011 and now polls seven percent nationally. Spain and the Czech Republic's Pirate Parties have won municipal representation on city councils.... The confluence of issues around privacy, data protection, net neutrality and open sourcing could become a permanent fixture in the European political landscape, just as ecological issues have in the past thirty years."
 Sources -  Europe in Turmoil Over Internet Anti-Piracy Legislationthe Atlantic
If You Thought SOPA Was Bad, Just Wait Until You Meet ACTAForbes.com

Sunday, February 5, 2012

Google Tries Defining Sharing as Privacy (Updated)

Recently, Google standardized its privacy policies across all of its platforms, as well as sharing and correlating user information obtained on its various services.  In a move to quiet the howls from privacy advocates, Google researcher Jessica Staddon is releasing a research paper arguing that social media sharing of personal information helps you build a public image, which in turn helps build trust and enhances privacy.,
"[W]e present survey evidence that 'vanity' searches are associated with an important privacy need," Staddon writes. "We also present evidence compatible with the conjecture that social annotations in search support privacy by enabling better self-representation and thus more privacy-aware sharing." 
 They key to the seeming contradiction that becoming more public promotes privacy lies in defining privacy.  Staddon, while not giving a precise definition seems to equate privacy with being able to build one's own representation of their public self through social media, and that input from the social media community can help reinforce and validate that representation.  Staddon asserts that there are "huge privacy advantages" in facilitating perception, both of one's self-image as well as how they represent themselves in the community.  I'm not clear how this directly helps maintain privacy, or resolve privacy issues or problems.  Perhaps looking at how Staddon supports the argument can help.
  Staddon reports on two research studies.  The first is a small scale study which suggested a relationship between "vanity searching" one's name, and concern about one's reputation.  It's a very weak link though, based largely on the result that most of those who didn't vanity surf said they weren't concerned about their online reputation at all.  The second study was an experiment to test whether adding social annotations (likes or popularity) to an article's search result (title, snippet of text and url) had an impact on an user's interest in further engagement with the article.  Staddon reports that there were small, but statistically significant differences in a user's interest in reading the article, further looking into the topic, or bookmarking it - but no meaningful difference in whether or not a user would "share" the article with others through social media.  So where does privacy come in? 
  In the first study, Staddon seems to suggest that a concern about reputation can motivate reputation monitoring through vanity surfing, and jumps to the argument that social media can be a mechanism for reputation monitoring (not a direct finding of the study).  Even following that line of argument, the implication is that concern for privacy might drive one type of social media use, not that social media use improves privacy.
  In the second study, one social media use (aggregated social annotations) had a small impact in terms of improving further engagement, except for through social media.  This might be argued to suggest that, for some, trust in social annotations might impact engagement - but not that engagement improves trust.  Trust is tied to perception of social media annotations, and not a result of minimally heightened engagement.
  As such, neither of the studies directly indicates that social media use has positive implications for privacy, much less that "social media both facilitates reputation monitoring and trust building, both of which are compelling for privacy."  The evidence and argument provided in support of the claim that social media use promotes privacy are incomplete, indirect, and insufficient. The only real argument for improved privacy through social media lies in Staddon's example of an indirect benefit - that having more and better personal information about others could impact on an individual's likelihood of self-disclosing personal information to another.  In other words, it's basically an argument that less privacy for you might help me maintain my level of privacy. And that's not much of an argument for social media supporting privacy, either.

UPDATE: 
It turns out that privacy regulators in the EU don't like Google's plan to consolidate privacy statements and user information across its many platforms, in order to begin compiling more detailed user profiles.
Privacy policy in Europe is different from US concerns, and is focused more on sharing or revealing personal information to others. 

  Google argues that it only plans on using the aggregated personal information internally, to improve its personalization and recommendations, and to better target advertising. However, there seems to be no way for users to opt out of the new privacy policy, or prevent aggregation, short of signing out and using multiple accounts.
  In the meantime, some members of Congress are asking the Federal Trade Commission if the new policy violates an early anti-trust settlement in which Google promised to obtain the express consent of users before sharing their information.
  I think Google wants to make the case that all of the separate services are still part of Google, and thus there is no outside sharing.  I'm not so sure that the Courts will agree, but they might.


Sources -  Google Study: Social Media Enhances PrivacyInformation Week Security
Vanity or Privacy? Social Media as a Facilitator of Privacy and Trust, Jessica Staddon, Google
Google, EU Spar Over Privacy ChangesOnline Media Daily

edit log -  Updated with EU/US privacy concerns, 6 Feb 2012

Thursday, December 8, 2011

More technology, less privacy

Post contributed by Asia Farmer -


Smartphones have the ability to do just about anything in this day and time. What seems to be the new catch is tracking locations via smartphone and other devices. Keeping track of where you are and have gone along with that of your friends is the norm for this generation. Smartphones have the ability to track one’s exact location without that person even thinking twice about it. Social media sites like Facebook and Twitter have even jumped on the bandwagon with providing ways for users to broadcast their exact location at that exact moment through a simple post or status update.
  Websites like Four Square, Loopt, and Gowalla have made the job much easier by allowing users to voluntarily track their locations and make comments and reviews. Websites like these provide ways where one can track others by signing up through Facebook. Smartphones also have the ability to act as portable GPS systems and include applications for maps that also track exact locations. Much of what is done on our handy dandy smartphones is being tracked by towers through cell phone companies.
  With technology on the rise with tracking every move and locations, it can also aid law enforcement and in doing their jobs by protecting citizens. Many people may consider it unjust for law enforcement and the government to get in the loop to find criminals via new technology. However, with many people directly and indirectly providing the information to the world leaves it up for grabs for anyone.

Source - How much privacy can smartphone owners expect?  BBC News Magazine

Sunday, October 23, 2011

Facebook challenged on profiling preteens


Post submitted by Molly McCurdy (edited and elaboration by BJB) -

  Facebook is a convenient way to stay in touch with friends and has become a pivotal advertising tool for companies; but what you may not know is that all of your personal information is packaged up into a profile, which is then marketed to advertisers.   When Facebook was initially created in 2004 as a social networking site for college students, the user had to have a college email address to register and open a page. In 2006, Facebook allowed anyone with an email address to register, although its terms stated that users must be 13 or older.  Now, seven years later, the website has transformed into an advertising powerhouse with users of all ages participating. But in a generation where cyber bullying and online predators are a serious problem, where is the age limit for Facebook users?
   The 1998 Children’s Online Privacy Protection Act prohibited any website from collecting personal information from a child under the age of 13 without parental consent - thus Facebook's choice of 13 as its lower age limit.  However, it's a soft limit, and can be bypassed.  Also, there is no prohibition against parents registering their kids on Facebook.  A Consumer Reports study last May estimated that more than 7.5 million U.S. Facebook users were under the age of 13; and 5 million were under 10. Moreover, their study found that most of their use was unsupervised by parents. Other studies indicate that about three-quarters of parents report occasionally monitoring their kids' social media accounts - but 80% of kids report using privacy settings to block at least some content from parents' view.. In any case, it's pretty clear that parents aren't always supervising and monitoring their kids' use of Facebook (or other social media sites).  Critics aren't only concerned with privacy and data collection - there are also charges that Facebook provides no increased security precautions for minors, and dioes not block advertising to kids..
   Within weeks of Consumer Reports releasing their article, Facebook founder Mark Zuckerberg announced that they would challenge the COPPA law. A New York Times Magazine piece speculated that it is not certain why they want children’s membership so badly but brand loyalty does come into play - “The younger the child, the greater the opportunity to build brand loyalty that might transcend the next social-media trend. And crucially, signing up kids early can accustom them to “sharing” with the big audiences that are at their small fingertips.”
   Facebook provides a "free service", but like many media, operating costs are offset by advertising and marketing revenues.  When you create an account on Facebook you are providing personal information about yourself that goes into a “personal profile” if you will. You enter your; age, hometown, activities, “likes”, your friends, where you vacation etc. This enables the ads to be highly targeted, including targeting kids.  The more connected you are with the site, the more “likes” you post, the more personalized your ads will be on the side of the page. Some find the targeted marketing helpful, and appreciate the advertisements. For others, the concept of Facebook marketing you for profit is simply outrageous. But kids are considered special, and there is greater concern about the influence of advertising and marketing directed towards young people.  It doesn't help when a Facebook's sales chief notes that friend referrals are a potent form of online advertising, giving Facebook even greater incentives to track kids' online behavior.  Lisa Wirthman, in a Denver Post Op-ed, stated that “Parents need to pull back the curtain and understand that Facebook has no motivation to make its site safer for minors when restricting data collection from kids directly contradicts its business model.”
   Whether Facebook is directly violating COPPA is open to debate - Facebook correctly states that to get an account, you must either state you are 13 or older, or have a parent register you.  If you lie about either, Facebook can close the account, and they do, when they are notified of the situation.  Critics argue that this kind of reactive enforcement isn't enough, and that the law should be interpreted as requiring parental permission to be collected for each separate Facebook session.  They also suggest that Facebook should actively screen questionable accounts, or at least make privacy settings for kids default to the "no marketing of info" setting.
    Whatever interpretation wins in court, Facebook faces a PR issue with how they handle kids, and their personal information and behaviors, in the system.

Sources - That Facebook friend might be 10 years old, and other troubling newsConsumer Reports
Facebook and Your TeenagerDenver Post
Why Facebook Is After Your Kids, NY Times Magazine

Monday, August 8, 2011

Some ISPs redirect search results

Just when I finish one post, something else comes along. A report published in New Scientist, based on research by UC-Berkeley's International Computer Science Institute, indicates that more than ten Internet Service Providers (ISPs) are redirecting search traffic headed for Yahoo and Bing.  The report says that when users search for brand names on those engines, the ISP is sending them directly to the brand's site rather than displaying the actual search results.  The report indicates that the ISPs had also been doing the same thing for searchers on Google, but recently stopped.
The report suggests that this behavior, sharing user info with outsider firms, raises privacy issues and may violate network neutrality principles. It also has potential financial impacts for the search engines, as referral fees paid by some companies would also be redirected.  Expect lawsuits.

Source: "ISPs Redirect Search Traffic On Yahoo, Bing, Raising Legal, Privacy Issues," Online Media Daily

Tuesday, June 14, 2011

More Privacy News

The Digital Advertising Alliance has added two of the larger groups representing ad agencies to a group working on the creation of privacy standards for Online Behavioral Advertising.  The centerpiece and public face of the effort is the "Advertising Option" icon, which will be included in or with online ads, indicating participation in the program (and hopefully, adherence to the industry's self-imposed standards about privacy in the collection and use of online behavioral data).
Participation in the privacy standards program creates certain responsibilities on the part of various parts of the online advertising industry.  For media and creative agencies, it means identifying what parts of the campaign incorporates online behavioral advertising, and ensuring a place to insert the icon and/or links to systems allowing users to opt-out.  For ad networks and advertisers, it means an agreement to abide by the standards, providing an opt-out option and complying with user opt-out requests.

It's a good sign that the industry has recognized and is addressing the issue of privacy, as the Internet offers abundant opportunity to amass data on its users.
I wish the program success.

Source: "Digital Ad Alliance Creates Privacy Rules for Online Ads", Online Media Daily
Website for the "Self-Regulatory Program for Online Behavioral Advertising."

(revised to remove typo and add Source link)

Facebook - Trouble with Faces?

Some of the oldest and largest public interest/advocacy  groups concerned about online privacy have asked the Federal Trade Commission to force Facebook to suspend operation of a new feature that uses facial recognition software to identify people appearing in other people's photos.  The complaint argues that the automatic tagging system amounts to an automated online identification system that largely occurs outside of individual's knowledge or consent; and as such exposes individuals to unknown risks.  The complaint calls for Facebook to obtain "opt-in" consent before sharing information about them in new ways.
Facebook has replied that it's previously announced its automatic tagging feature as it's become available in countries.  They say that users can "opt-out" - that if you become concerned about particular applications of automatic tagging, you can reconfigure your privacy settings to not automatically tag your image (if you can figure out how).  They also claim that if other users 'tag" you in their photos, you can ask for your name to be removed after the fact.  [Opt-in permissions require specific consent be obtained prior to the collection and/or use of information, while opt-out permissions only stop the use or sharing of the information collected after notification that you've opted out].  Those backing the complaint argue that Facebook still hasn't provided adequate information about the range and extent of personal information that it collects on its users, and that the opt-out option fails to prevent continued collection of the biometric data, or require the deletion of data already collected.  They say that Facebook has left open the potential for the service to market or share the data with advertisers, app developers, and the government without users' permission.  Name searches could reveal information about you that you had no idea was there.

So the fundamental lesson about the Internet needs to be expanded.  No longer do you need to realize that once you post things on the Internet, it's always out there somewhere, so be careful as to what you post.  Now, you may also want to be careful about what your friends post - those potentially embarrassing photos your friends posted from last Spring Break may show up at a later job interview.

Source: "Privacy Groups File FTC Complaint About Face Recognition", Online Media Daily

Monday, May 9, 2011

"Do Not Track" Legislation

From Eric Hutchinson: 

California is in the process of trying to pass a “do not track” bill that would require companies doing business online in California to offer an “opt-out” privacy mechanism for users of those companies’ services. Google, Facebook, Time Warner Cable, CTIA – The Wireless Association, the California Chamber of Commerce and around thirty other associations and companies wrote a letter to the Senate stating the bill would, “create an unnecessary unenforceable and unconstitutional regulatory burden on Internet commerce.” If the bill is passed, consumers would be able to opt out of data collection such as the date and hour of online access, the location from which the information was accessed, the means by which it was accessed and other information collected every day by these companies. The companies call the legislation unconstitutional, because they claim it’s an appropriation of Congress’s authority over interstate commerce.

Thursday, April 28, 2011

More on Apple tracking

From Jennifer Sprouse:


 
The Huffington Post has released an article on Apple finally speaking up over the allegations that they've been using the iPhones to track their customers. Apple has been somewhat logging informations of where their users are. What they claim right now is that it's not tracking the user, but the phone through Wi-Fi hotspots and cellphone towers. 
 
Source: "Apple: We've 'Never' Tracked Your Phone,Huffington Post

Wednesday, April 27, 2011

Jobs: Apple erred in handling iPhone Data issue.

From Jocelyn Blake-

There has been controversy about Apple's faulty location data on the iPhone and iPad. Steve Jobs has been on medical leave but he made sure to personally explain the situation to the public. "Confirming speculation from some security researchers, Apple said in the statement posted on its Web site that the file in people’s iPhones is not a log of their location but rather 'the locations of Wi-Fi hotspots and cell towers surrounding the iPhone’s location, which can be more than one hundred miles away from the iPhone.' " Many people were thinking that Apple was invading the public's privacy when that was not the case. After all, we live in a panoptic society were everyone enjoys displaying a critiqued image of themselves. However, we also value our right to place something for all to see as opposed to invasion of privacy. Any time we use a new piece of technology, we have to give a new piece of our identity. 

Smartphones: Evidence or Protected by Privacy?

From Jennifer Sprouse:


Here's an interesting article from the Atlantic magazine asking the question of whether cops should be allowed to search your phone- including email, photographs, and text messages- without obtaining a warrant. I think this is something that we should all be mindful of considering that our cell phones are our personal property, but this article raises the question of how personal our things are, and if the laws set in place already against warrantless searches and seizures will actually stand in the long run.