Showing posts with label EFF. Show all posts
Showing posts with label EFF. Show all posts

Tuesday, February 18, 2014

Mind Your (Online) Privacy !!

Introduction to Online Privacy
Online privacy is a very much debated topic in today's digital world. You cannot work in 
the web industry without thinking about who will be tracking your details every time 
you key in your sensitive information.

A couple of years ago, we witnessed EU laws came out strict regarding cookies. Even 
now, EU countries are thinking about taking action against Google, who is considered by 
them as high risk to people's privacy, even though useful in many ways. 
     
Google's Eric Schmidt on the other hand, although had emphasized the importance of 
privacy, had also indicated that definitions of privacy are changing as a result of so much 
information being willingly surrendered to the internet. In a 2009 statement, he 
suggested that if a person wanted to keep something private, it was probably because 
they shouldn't be doing it in the first place !! Sounds right sometimes, but not always !! 
Again creepy for the years to come, to all who plans to continue using Google !!

2011 statistics says, almost 140 views for every human being alive at that time !!
Facebook founder Mark Zuckerberg said three years back that in the age of social 

Is Facebook Privacy Policy Good Enough ?
So let's go back a little and think about what is privacy and how different it is when it 
comes to online privacy..

A Brief History Of Privacy        
Privacy as we know it - a term that we understand and define based on the culture in 
which we are raised - is a relatively modern concept. Prior to the rise of democracy 
privacy merely referred to a man's right to be left alone, free from physical harm.

If each man's thoughts and opinions were valuable and important, then protecting an 
individual's personal space, ideas and feelings became suddenly more important.

No longer could the State simply invade people's homes to billet soldiers, conduct 
searches - registering births, deaths and marriages became a topic for debate as did 
taxation and the State's invasion into people's financial affairs.

Even so, it was not until the age of technology that privacy became a real concern for the 
average individual, in the form of online privacy.

Online Privacy in today's world of Emerging Technologies
Contrary to the previous times, in the last 10-15 years, however, we have willingly tossed 
aside our own right to a private life, not just through our obsession with the lives of 
celebrities, but through our desperate need to emulate fame through reality TV shows, 
blogging, live streaming our lives onto the internet.

Most of us have embraced Facebook, Twitter,  MySpace, Flickr and LinkedIn as an easy 
means of keeping in touch with friends and family and of making business contacts and 
finding others with shared interests. What we fail to consider is how our willingness to 
make our private lives public reverses those hard-won rights to decide what to make 
public and what to keep private, as the more we happily put into full public view the less 
we inherently reserve the right to keep private. 

Auto-complete features in web already have your data !!

With the emerging trends of tracking website activity in place, people have started to 
discuss about online privacy ever than before.

Yearly mentions about "Online Privacy" (from NYTimes)
It is very important that not just those of us working within the internet industry,
encouraging increased use of social networks and using technology to gather increasingly 
large amounts of information about people's lives, their likes and dislikes, their habits and 
their buying patterns, understand the wider implications of changing our definition of 
privacy, but that members of wider society understand how this will affect their lives as 
individuals, and that we analyze the good and the bad aspects of this cultural shift. 

The future of Online Privacy
Let us just say that you will be tracked wherever you go in all aspects. You can watch the 
below video for a better understanding of this.

          
So, who all should we be aware of ? 
Well, even a school kid can take a guess at this and get it right.

Most importantly, Google and Facebook, because of the simple and alarming fact that we
are giving them tons of information every single day about ourselves !! NSA is an another
agency who keeps track of people through their cellphones (almost 5 billion cellphones
tracked by NSA everyday !!).

Below is a short video which shows how much Google already knows each of us !!


Which technologies/methods are used to collect your data ? 
For example, Google openly admits that they collect and track 6 different kinds of your 
personal information !!

1) Device information:   
    Your android smartphone talks back to Google and sends back information such as your
device ID, model, network details etc.
2) Log information:   
    Whenever your android phone uses Google' services it logs your call activity, such as
the other caller's number, duration of conversation.
3) Location information:  
    When you use a location-enabled Google service, the company may collect and process
information about your actual location, like GPS signals sent by a mobile device.
4) Unique application numbers:  
   Information about the apps you install may be sent to Google when you install or
 uninstall that service or when that service contacts the company’s servers for automatic
 updates and other unspecified reasons.
5) Local storage:  
        Google may collect and store information, including “personal information,” on your
device using browser web storage such as HTML5 and application data caches.
6) Cookies and anonymous identifiers:  
       The company says it uses unspecified technologies to collect and store information
when you visit a Google service, possibly including sending one or two cookies or
anonymous identifiers to your device, even when you interact with services the company
offers to thier partners.

Google is storing all your passwords (Chrome Keychain) and  also storing your financial
details - account numbers and card information - in your Google Wallet. Pretty much
everything about us !!! They have also admitted to scanning emails of non-Gmail users -
who wouldn't have likely agreed to Google’s terms - sending email to Gmail users. 

Again, if you think Google still has not breached your privacy, you should probably take
a closer look at what Google aims for with the acquisition of Nest for $3.2billion
purchase. 

Google can now start tracking how you move around your house and what you do when
you are not online !! A very serious privacy breach, again hoping will not turn disastrous.

Facebook, on the other hand aims to track your online social behavior, your interests and
website activity more and learns more about you and start recognizing your friends using 
state-of-the art facial recognition algorithms acquired from Face.com and also starts 
showing marketing campaigns and recommendations for you. This had caused a lot of  
privacy concerns a while ago. They seem to have subdued at the moment, while we hope
these will not be used against us in the future !

Organizations protecting Online Privacy
The Electronic Frontier Foundation (EFF), the Center for Democracy and Technology
(CDT), the American Civil Liberties Union (ACLU) and Fight for the Future are the main 
organizations against Online Privacy. Two years back, they collectively conducted a
campaign against Cyber Intelligence Sharing and Protection Act (CISPA), which actually
was not clearly defined such that it may dismantle existing protections provided by the
Federal Wiretap Act and the Electronic Communications Privacy Act and other laws.

                  Tactics/Workarounds to protect online privacy
                  1) Creating multiple identities: Interestingly, Google itself had come up with an 
                   interesting workaround to protect online privacy. The central idea is to create multiple
                   identities (accounts) for the same person, so that your personal and demographic data  
                   will not be tracked along with your official identity. This is just a way to provide 
                   abstraction, both accounts can be still be identified and grouped together. 
                  2) Clearing cookies : Clearing cookies will help protect online privacy temparorily
                  3) Using different Web Browsers : Using different Web Browsers for personal and
                       business use will help provide an extra layer of abstraction.
                  4) Using PrivateBrowsing feature in Web Browsers
                  5) Using BrowserExtensions that help protect privacy
     
                  In addition to the above, there are some tips provided by EFF and TRUSTe .


7) Big Data: The End of Privacy or a New Beginning? - Research paper by Ira S. Rubinstein 

8) A Theory of Creepy: Technology, Privacy and Shifting Social Norms- Research paper by Omer Tene and Jules Polonetsky




Monday, February 17, 2014

An Update on Do Not Track and Privacy

In his January 2013 post to the Digital Analytics - University of Utah course blog, McCall Lewis wrote about the ongoing debate surrounding online consumer privacy and efforts towards a standard for "Do Not Track" [i].  McCall correctly stated that 2013 would be the year that these issues came to the consciousness of the consumer at-large. In this post, I intend to explore the ongoing saga of Digital Privacy and how consumers and online entities are reacting.

Digital Privacy in 2013, In a Nutshell (Help!  I'm in in a nutshell!)

It is safe to say that by the close of 2013, no American was completely isolated from developments in the world of digital privacy.  This was the year of Edward Snowden and Wikileaks, which exposed such government spying programs as PRISM, Tempora, and MUSCULAR [ii].  If people were not previously concerned with the monitoring of their internet behavior, it is hard to believe that they were not starting to think about it.  Most relevant to Digital Analytics is the allegation that the NSA was using cookies to piggyback on the tools that digital advertising firms were using to "pinpoint targets for government hacking and to bolster surveillance".  Google, Yahoo!, and Microsoft announced plans to encrypt traffic between their data centers, with Microsoft indirectly comparing the threat to that of Chinese government-sponsored hacking [iii].


Beyond allegations of government spying, other news events triggered a growing concern for digital privacy amongst citizens.  It was revealed that Google, despite their unofficial corporate motto being "Don't be evil", was collecting and storing data on WiFi networks while driving the avenues and boulevards in their mapping vehicles [iv].  Inadvertent or not, this revelation made big headlines in the year of Digital Privacy concerns.  Beyond government and corporate spying, there were a number of black-hat news stories as well.  Major retailers such as Target and Neiman Marcus were victims large-scale data breaches in which personal and credit card information were stolen from their servers.  While nothing connected to a network is ever totally secure, some of the details surrounding these breaches made it clear that retailers were not doing everything that they could to protect this sensitive data. In this particular case, the suspected security snafu source was an HVAC contractor that was given the keys to the castle, which were thusly compromised [v].

Current Sentiment
Not surprisingly, there have been numerous studies trying to suss out what the consumer reaction is to all of this. A University of Vienna focused on the act of "Virtual Identity Suicide" within the online social networking site Facebook.  The single biggest cause for this phenomenon, where a user deletes as much of their content as possible before permanently locking themselves out of their account, were concerns over privacy.  Among users studied, over 48% expressed this viewpoint [vi]. It turns out, they have a right to be concerned. Austrian law student Max Schrems found out, in 2010, that Facebook had over 1,200 pages of data on him alone.  This included data that he had never been supplied, but had been linked to him through his friends contact list.  As big-data analytics gets more powerful, this could translate into an enormous amount of personal information being available to online companies [vii].
Using information like Facebook collects, identification of protected classes is not only possible, but on the verge of child's play.  The Center for Digital Democracy is making efforts to address its concerns to the FTC.  They state that technologies such as hyper-local targeting, geo-fencing, and cross-platform targeting will allow for rampant discrimination.  The sorts of questions that it is illegal for employers to ask (age, marital status, sexual orientation) will become easily attainable information [viii].
TrustE, a digital privacy management company, conducted a study regarding consumer opinions about Online Behavioral Advertising recently [ix].  They found that 69% of internet users understood the value trade-off of online ads versus free content, but only 26% are willing to actually accept the same.  It seems as though most internet users feel powerless in the process that they need to just accept what is offered.  The study also showed that 62% of users would be more willing to do business with a company that allowed them to opt-out of targeting.

Ongoing Efforts
The WC3 is spearheading a Do-Not-Track and privacy working group, but things are not going as well as could be hoped.  One of the biggest internet watchdog and lobbying organizations, the EFF (Electronic Frontier Foundation), has lost confidence in the group [x].  They have directly stated that if the group continues in the direction that it is currently headed, that they may be forced to drop out.  Another watchdog group has a similar stance.  Jeffrey Chester, of the Center for Digital Democracy as called the efforts of the group "a farce".  It appears as though the group cannot even get the definition of tracking nailed down.  Are they concerned with 1st party cookies, 3rd party cookies, or other methods of data collection?  Original efforts in the Do-Not-Track space only targeted 3rd party cookie based ads, providing a guise of privacy to the relatively uneducated user.
It is unclear what the future may bring in terms of digital privacy, but it is doubtful that it will continue to be as unregulated as it currently is.  The European Union is enacting tough laws, requiring explicit consent in some areas, rather than the arguably implicit consent given by endless EULAs and TOCs that no one actually reads.  If the FTC gets involved in the United States, things are likely to change.


[i] Lewis, McCall ‘The “Do Not Track” Debate’ Digital Analytics – University of Utah, January 26, 2013. http://dauofu.blogspot.com/2013/01/the-do-not-track-debate.html
[ii] Wikipedia contributors, "Edward Snowden," Wikipedia, The Free Encyclopedia, http://en.wikipedia.org/w/index.php?title=Edward_Snowden&oldid=595457266 (accessed February 5, 2014).
[iii] Wikipedia contributors, "MUSCULAR (surveillance program)," Wikipedia, The Free Encyclopedia, http://en.wikipedia.org/w/index.php?title=MUSCULAR_(surveillance_program)&oldid=595197410 (accessed February 5, 2014).
[iv] “Street View: Google given 35 days to delete wi-fi data”, from BBC News: Technology, June 21, 2013. http://www.bbc.co.uk/news/technology-23002166
[v] Feinberg, Ashley “Last Month's Massive Target Hack Was the Heating Guy's Fault” Gizmodo, February 5, 2014. http://gizmodo.com/last-months-massive-target-hack-was-the-heating-guys-1516926877
[vi] Munson, Lee “Half of Facebook-quitters leave over privacy concerns” NakedSecurity, September 18, 2013. http://nakedsecurity.sophos.com/2013/09/18/half-of-facebook-quitters-leave-over-privacy-concerns/
[vii] Solon, Olivia “How much data did Facebook have on one man? 1,200 pages of data in 57 categories” Wired.co.uk, December 28, 2012. http://www.wired.co.uk/magazine/archive/2012/12/start/privacy-versus-facebook
[viii] Submitted by demedia, “CDD Calls on FTC to Protect Privacy in today's Hyper-local, geo-targeting, cross-platform, Big Data Era/Warns of Discriminatory Practices with mobile device tracking”, Center for Digital Democracy, February 6, 2014. http://www.democraticmedia.org/cdd-calls-ftc-protect-privacy-todays-hyper-local-geo-targeting-cross-platform-big-data-erawarns-disc
[ix] Deasy, Dave “TRUSTe Study Reveals Increased Transparency and Privacy Controls Produce More Positive Feelings about OBA” TrustE Blog, September 19, 2013. https://www.truste.com/blog/2013/09/19/truste-study-reveals-increased-transparency-and-privacy-controls-produce-more-positive-feelings-about-oba/
[x] Fung, Brian “The Internet’s best hope for a Do Not Track standard is falling apart. Here’s why.” The Washington Post Online, The Switch, October 11, 2013. http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/11/the-internets-best-hope-for-a-do-not-track-standard-is-falling-apart-heres-why/

Thursday, May 2, 2013

Search engines & privacy

Credit to www.realtrafficproductions.com
The current Big 3

A brief search engine primer

Search engines have changed the computing world, become a mainstay of the Internet, and have changed the marketing landscape in ways never thought possible. Initially, a search engine was designed to find keywords in a manually created index of all websites, or information on the world wide web. In it's earliest state, a search engine was a simple query or a program. Today, a search engine is much more than just a simple query. Now they have evolved into complex systems that span data centers and are the bread and butter of global corporations.