Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Apr 4, 2012

Not Surprising

Consumers really do care about their privacy, according to a Consumer Reports survey:

According to a Consumer Reports press release, the national survey found that 71% of respondents said they were very concerned about companies selling or sharing their information about them without their permission. Another 65% of smartphone owners don't like that apps can access their contacts, photos, locations and other data without permission from them.

Who knew? ;-)

Aug 26, 2010

Not really so funny

Recently I posted my thoughts regarding Eric Schmidt's comments about on-line privacy and his prediction that we'll eventually have to change our identities to get away from on-line indiscretions. In a related WSJ article Mr. Schmidt explains how Google will be able to predict what we want because Google knows:

'...roughly who you are, roughly what you care about, roughly who your friends are.' Google also knows, to within a foot, where you are.


So again, if Google knows all of this it then shouldn't it d be able to help us get rid of it? Granted we might not be able to delete every shred of information, but getting to the bulk of it is a good start.

With all its irony this bit by Stephen Colbert makes the point very eloquently:

Of course, there is one other answer. Google and Facebook could stop invasively data-mining and selling our private lives to the highest bidder. But that would be asking them to change who they are. And that's not fair.


Tipper might rate this NSFW although it is safe for Comedy Central.

The Colbert ReportMon - Thurs 11:30pm / 10:30c
The Word - Control-Self-Delete
www.colbertnation.com
Colbert Report Full Episodes2010 ElectionFox News

Aug 9, 2010

For more in the "What do they know?" department...

I shared with you last week Google's Social Circle, to demonstrate how Google maps you're social network. You can also see all the data Google keeps on you here. Make of it what you will.

Aug 2, 2010

The Business of Online Ads and Browsers

The Wall Street Journal recently published a few articles on Online Privacy issues. In "Microsoft Quashed Effort to Boost Online Privacy," the article points out that today's browser business is primarily in support of advertising sales:

As online advertising grows more sophisticated, companies playing prominent roles in consumers' online experiences have discovered they have access to a valuable trove of information. In addition to Microsoft, such companies include search-engine giant Google Inc., iPhone maker Apple Inc., and Adobe Systems Inc., whose Flash software makes much of the Internet's video, gaming and animation possible. These companies now have a big say in how much information can be collected about individual users.

The article details the internal struggle at vendors who are in the business of producing browsers and online advertising solutions. Big stakes for all, basically putting the consumer in charge of their privacy. As if we had a clue. This was the topic of a conversation I was having with Diana Kelley at SecurityCurve this morning; consumers have little to no idea what's being tracked or how. We trust the vendors and the providers that they have our best interests in mind when in fact they have their own best interests in mind. That usually involves making as much money as they can giving away free stuff to consumers.

For more insight on what is tracked and by whom, check out WSJ's article "What They Know."

May 21, 2010

Herre we go again...

Sigh, this is classic for anyone who's worried about data privacy when developing web-based apps. The WSJ reports today that:

The practice, which most of the companies defended, sends user names or ID numbers tied to personal profiles being viewed when users click on ads. After questions were raised by The Wall Street Journal, Facebook and MySpace moved to make changes. By Thursday morning Facebook had rewritten some of the offending computer code.

Advertising companies are receiving information that could be used to look up individual profiles, which, depending on the site and the information a user has made public, include such things as a person's real name, age, hometown and occupation.

So if you click on an ad from your profile page, the referring URL is sent to the advertiser without being scrubbed. Looks like steps are being/have been taken by at least Facebook, but this is a rookie mistake. To ameliorate the sting of yet another Facebook privacy smack-down, other social networks are doing the same:

In addition to Facebook and MySpace, LiveJournal, Hi5, Xanga and Digg also sent advertising companies the user name or ID number of the page being visited. (MySpace is owned by News Corp., which also owns The Wall Street Journal.) Twitter—which doesn't have ads on profile pages—also was found to pass Web addresses including user names of profiles being visited on Twitter.com when users clicked other links on the profiles.

And don' tell me advertisers armed with URL referrers back to user profile pages are making sure they are getting user's consent before looking at the profiles.

Facebook said its practices are now consistent with how advertising works across the Web. The company passes the "user ID of the page but not the person who clicked on the ad," the company spokesman said. "We don't consider this personally identifiable information and our policy does not allow advertisers to collect user information without the user's consent."

A URL referrer (i.e., user ID of the page) is a technicality; if it goes back to the user's profile page then it is a breach of a policy not to divulge personally identifiable information to 3rd parties.

I repeat myself, I'm glad all of this is happening. The social media is growing up and it's the consumers that are ensuring that things are getting safer out there. Apparently when experts expose security issues the fixes languish:

The sharing of users' personally identifiable data was first flagged in a paper by researchers at AT&T Labs and Worcester Polytechnic Institute last August. The paper, which drew little attention at the time, evaluated practices at 12 social networking sites including Facebook, Twitter and MySpace and found multiple ways that outside companies could access user data.

I know it's hip to buck the established/academic technology world in social media tech circles, but sometimes these smarty-pants can actually help to prevent some embarrassing moments.

Facebook, MySpace Confront Privacy Loophole - WSJ.com

May 14, 2010

The Evolution of Privacy on Facebook

Seems that Facebook is the latest privacy poster-child highlighting the strains that come between a service provider seeking a way to cash-in on our desire to socialize and the responsibility the provider assumes to protect its users.

Recent blog posts and articles have recently come out on the (de)evolution of privacy on Facebook since 2005. Kurt Opsahl of the EFF provides an handy timeline of changes to Facebook's Terms of Service through the years. This posting prompted Matt McKeon at IBM Research's Center for Social Software to create a more specific timeline and interactive chart (click on image below for link to interactive chart and blog post).


Matt points out on his blog:
However, Facebook hasn't always managed its users' data well. In the beginning, it restricted the visibility of a user's personal information to just their friends and their "network" (college or school). Over the past couple of years, the default privacy settings for a Facebook user's personal information have become more and more permissive. They've also changed how your personal information is classified several times, sometimes in a manner that has been confusing for their users. This has largely been part of Facebook's effort to correlate, publish, and monetize their social graph: a massive database of entities and links that covers everything from where you live to the movies you like and the people you trust.

In a May 13th blog post, Ken Opsahl continues his coverage and urges Facebook to "follow its own Principles." According to Opsahl, Facebook's current privacy practices coupled with Elliot Scrage's (Facebook's VP for Public Policy) flippant responses in a recent NYT readers' question and answer piece, amount to a boatload of double-speak coming out of Palo Alto when it comes to user data privacy.

Social software wants to be open by nature. Which is crux of the current Facebook privacy kerfuffle. Without openness connections can't be made. However, with any social group there are implied rules for who can participate, what gets shared, and how. From a user's point of view, social wants to be open, but not that open.

A third party, who's purpose it is to facilitate, moderate, and monetize social activity, can be at odds to the purpose of the user. It is the third purpose of the service provider, making money, that creates the tailspin. Today Facebook takes the point of view that the act of registering for a Facebook account is implicit permission for Facebook to use any information a user posts for Facebooks own purposes (we're talking about making money here). Facebook is not just there to facilitate the connections that users want to make. After all, Facebook isn't free for Facebook.

If you look at Matt's interactive chart big changes happened between 2007 and 2009. Yea, I know a whole year, but I suspect 2008 would show some other interesting data, like jumps in numbers of users, increased numbers of applications, and even increased investment into Facebook. In other words Facebook's business changed and the opening up of user data provided the means for creating monetary value in Facebook.

Social networking has reached a tipping point where the "trust" levels are diminishing as usage rises. As more people and applications use the information we post in social networks, the more skittish we become. Not without reason, the rise in spam/malware attacks, bullying, "checking-up on" by employers/neighbors/creditors, and identity theft on social media is an indication of how valuable the social media dirt is to others. Of course users want more protections with consistent policies and experiences. But maybe we're gonna have to pay for that luxury.