Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Wednesday, April 08, 2009

Phorm launch in the horizon


Phorm (also known as Webwise) has declared that it is finally set to launch its service in the UK with BT's ISP service. Phorm is a service that allocates web users a unique number, it then monitors websites that the user has visited and looks for recurring keywords related to its advertisers. It then associates those keywords with the user's number, so that when the user visits a site containing a web advert, it will display relevant commercials. For a more detailed explanation, read Richard Clayton's excellent report.

As a founding supporter of ORG, I do not like Phorm. I understand their claims of anonymity and security, but I am still not convinced that this level of surveillance is either useful or necessary. Phorm seems to add an unwanted layer of interception to the internet, and I am not sure that users will like to have such records made of their browsing habits. Phorm claims that it destroys those records, but I am still uneasy. Who is to say that in this difficult financial climate, they won't change their data retention practices to sell more information about web users?

Something that is perhaps unsurprising, yet still disappointing, is that Phorm seems intent in misrepresenting and hiding what it does to the public. There was a public outcry when they conducted a series of test runs with unsuspecting BT customers. BT is also intent in claiming that Phorm's main function is to "increase protection against online fraud". They also seem to brush all consumer concerns under the rug. They claim:

"That being said, what we did not take into account was the fact there would be a very small number of very determined people who would do their very best to make it appear in the worst popular light. I am surprised by the fact, after it has been repeatedly explained how the technology works, they seem to be very keen on misunderstanding what it does."
No, thanks to people like Richard Clayton, we do understand how it works quite well, and we are still very concerned about it. As a BT customer I won't be opting in of the system, as the Information Commissioner has declared that Phorm can only operate with the consent of the user.

If you don't like Phorm, join the Facebook campaign. Phew, I managed to reach the end of the post without any clever "eph" replacement, ephing well done. Doh!

Friday, April 03, 2009

The cameras are at the gates!

The unveiling of Google StreetView UK is being met with that uniquely British mixture of outrage, amusement and derision that I can never quite get right (much like the intricacies of the English language I suspect, but I digress). On Wednesday the village of Broughton in Buckinghamshire blocked the StreetView car from entering the town because of concerns that it could be used by burglars to check out houses. A villager saw the car approaching and quickly alerted his neighbours, who promptly blocked the van from coming into town.

I wonder who is in the right here legally speaking. Does Google have the right to circulate around town taking pictures? Have the neighbours the right to block the van from entering the village? My instincts tell me that Google would have the right to circulate in a public road, but this is an area of law completely alien to me.

What has surprised me more than the level of coverage is the clear opposition to Street View from privacy advocates, to the extent of threatening to sue Google. I know that there are potential privacy issues, but really, aren't people taking things too far? I have found Street View extremely useful, helping me find a restaurant in London and to identify a place where I will be speaking later today. Could I have done those things without Street View? Sure, but knowing where you're going in advance is a great advantage, particularly if you're running late. I personally think that the benefits greatly outweigh the annoyances and privacy concerns.

Needless to say, there are hundreds of amusing stories developing as we speak. Fred Goodwin's house was supposed to be blanked out, but the next-door neighbour's home was mistakenly removed instead. There is also a divorce in the making, as a woman found out that his husband had been cheating on her when she saw his car in front of his mistress' house. The mind boggles.

I for one recognise potential privacy issues, but I am delighted by the technology. And yes, I have already wasted some time simply clicking on the arrow. It is strangely addictive.

Update: Thanks to Jac for pointing out that the divorce story in The Times is a hoax.

Friday, March 13, 2009

New report on the state of global Cyber-censorship released

Yesterday was World Day Against Cyber-censorship [insert snarky comment about the abundance of "Days against X" here]. To celebrate (is "celebrate" the right word?), Reporters Without Borders has released a report on the state of internet control and surveillance. The report labels 12 countries as "enemies of the internet", claiming that they have turned their access to the network into an intranet, allowing them to completely monitor what gets through. The Dirty Dozen of censorship are Burma, China, Cuba, Egypt, Iran, North Korea, Saudi Arabia, Syria, Tunisia, Turkmenistan, Uzbekistan and Vietnam. Other countries mentioned in the document as places which exert excessive control are Australia, Bahrain, Belarus, Eritrea, Malaysia, South Korea, Sri Lanka, Thailand, United Arab Emirates, Yemen, and Zimbabwe.

The report does make an interesting point about the effectiveness of cyber-censorship:

"But is blocking of news online still effective? Through experience and thanks to their technical knowledge, Internet users have learned to get round some censorship installed on the Web by their governments. In countries where access to news is prized, it is not unusual to find software to defeat online censorship installed on computers in cybercafés, and also managers willing to put them to use if need be. Internet experts belonging to some of the most recognised institutions constantly create and fine-tune software versions so as to adapt them to the reality of the virtual world and to ensure that news is accessible to all."
While the document mentions some private companies, I was surprised not to find mention of some of the new censorship threats in countries like the UK, such as Cleanfeed. Nevertheless, this is a sobering and welcome reminder of just how restrictive the web can be.

Tuesday, November 11, 2008

Googleverse: Utopia or Dystopia?

It is a bit tired to say that Google's stranglehold on the search engine market seems unshakeable. To offer a couple of ironic factoids, I found the accompanying image using Google Image Search, and this blog is published in Blogger, a Google-owned service.

Many people have been warning us about Google's dominance for a while, yet we continue to use it for a variety of reasons, from convenience to the fact that it works well. Spiegel Online has published a very interesting article on the growing backlash against some of Google's more controversial services, such as StreetView, but also building a disturbing picture of the amount of data mining going on at the Mountain View company. Gmail users have become accustomed (and immune) to warnings about the practice of Google searching for keywords in their messages to target contextual advertising. iPhone users can also be tracked when using Google Maps in their mobile devices, which tell Google exactly where you are.

The practices at Google cut right to the heart of the modern debate about Internet privacy that is usually the topic of discussion in various conferences I attend. Those who do not see privacy breaches as a problem, tend to offer three arguments. One is whether there is safety in numbers. With the amount of data that Google gathers, is it possible for any person to actually misuse it? Your personal information is lost in petabytes of meaningless noise available online, so it is unlikely that someone will actually access it. The other argument is, so what? If the user gets a free and useful service, who cares if the company makes a buck by providing context advertising to the consumer? The third is of course the issue of privacy itself. If you have nothing to hide, then why bother about what information is held by Google or any other company?

These are legitimate answers to the issue of privacy, but I cannot help being slightly worried by the far-reaching power of Google. I am also concerned about the environment of unaccountability in which Google is allowed to operate. In Europe we have data protection law for a reason, and perhaps it is time for regulators to look at Google's practices and start asking questions about lines crossed.

It is clear that privacy is a growing concern in the media due to the widely advertised privacy blunders by government officials. We also have a public debate prompted by the Daily Mail editor riling about growing privacy protection due to human rights legislation. If privacy is back on the menu, then the largest online perpetrator should certainly come under regulatory scrutiny, regardless of whether one believes that its practices are not such a big threat to our rights.

Wednesday, January 30, 2008

ECJ strikes balance between IP and data protection

(via Cedric Manara) The European Court of Justice has decided on a case in which it calls for a balance to be struck between intellectual property rights and the protection of personal data. Enter Case C-275/06, Productores de Música de España v Telefónica de España. This is your average P2P downloads privacy case, pitting ISPs against the music industry. The question in these cases is usually the same: should ISPs disclose personal data when dealt with a request by a content provider? It is easy to find out the ISP where a file-sharer is connected, so most P2P enforcement cases fall into the issues of privacy and data protection.

This particular case is no different, Promusicae is a collective association of Spanish musicians, which initiated civil procedures against Spanish ISP Telefónica in order to obtain the identity of users sharing music through KaZaA. The court in first instance granted the request, but Telefónica appealed on the grounds that data protection law does not present an exception on the disclosure of personal data for civil cases, only for criminal proceedings. This is what makes this case so important in my opinion, the EU has in place directives dealing both with copyright and data protection. When confronted with a conflict, what should national courts do?

There are two directives in conflict, Privacy on Electronic Communications (2002/58) and Copyright (2000/31). The court first tackles privacy and data protection, and claims that the directive "does not preclude the possibility for the Member States of laying down an obligation to disclose personal data in the context of civil proceedings." Then the Court tackles copyright directive, and concludes that none of the IP directives "require the Member States to lay down, in order to ensure effective protection of copyright, an obligation to communicate personal data in the context of civil proceedings."

Therefore the Court is compelled to issue a balance. EU law does not require the Member States, in order to ensure the effective protection of copyright, to lay down an obligation to disclose personal data in the context of civil proceedings. The Court's decision reads:

"...Member States must, when transposing the directives on intellectual property and the protection of personal data, rely on an interpretation of those directives which allows a fair balance to be struck between the various fundamental rights protected by the Community legal order. Further, when implementing the measures transposing those directives, the authorities and courts of the Member States must not only interpret their national law in a manner consistent with the directives but also make sure that they do not rely on an interpretation of them which would be in conflict with those fundamental rights or with the other general principles of Community law, such as the principle of proportionality."
The word Salomonic springs to mind.

Wednesday, January 16, 2008

Patent for office surveillance software


Times Online has a report on new office surveillance software being designed by Microsoft. The software will monitor worker's performance by wireless sensors that measure "heart rate, body temperature, movement, facial expression and blood pressure." Even more interesting is the fact that the technology is the subject of a patent application by Microsoft.

Scary stuff, although the I'll save the moral panic for when the technology is widely available. I could insert a gratuitous mention to 1984, but I'd rather not.

Friday, December 21, 2007

The strange world of blog comments

While this blog has achieved decent readership figures, the comment function is still rather under-used. There are several reasons for that: in my experience there seems to be a critical mass of readers vs comments, which I have not reached yet; Blogger's interface does not encourage comments; and also most of my readers do so via RSS feed (250 daily subscribers to the feed).

I do not delete comments, unless they are spam, even if they are critical of what I have written (one warranted criticism here, and one laughable attempt here). The most common type of spam is about Costa Rican property (such as with this post), and about WoW gold farming for obvious reasons, but most intriguingly, this post generates a lot of in-game currency spam! There must be a Korean game named ILAWS...

Despite the lack of comments, there have been some notable exceptions. Some of the most commented posts are on hot topics, such as Free Software, software patents, and P2P. However, there is one post that still generates comments to this day, and it is this post about sex offenders. Given the nature of the comments, I am guessing that the post comes up highly when someone is searching for sex offender registers, or something similar.

However, in a weird sequence of posts I found one that is even stranger, which I reproduce without the names:

"I noticed that you had a variety of sex-orientated posts and they are moderated. Please make sure that when you read this that you don't post it for all to see, I'm a attorney in North Texas and it would cause me and my office manager X all sorts of grief if seen and reported. I'm planning a surprise trip for him, so we can leave between Christmas and February. We're interested in Eastern European countries where the age of consent for same sex is lowered to 13 or 14. To avoid attention could you post a 1 liner, "Fun for boys in Grapevine TX" with the age and county, so that it wouldn't draw any attention, such as "Fun for boys in Grapevine TX 13 Siberia". If you needed to e-mail back to me post the 1 liner, "Fun in Grapevine TX please email me".
Sincerely,
Y"
I believe a prank (or something nastier) is being played on someone. I googled the combination of names and found a post under this same name in a website advertising gay erotic products. Even more bizarre, the person who is supposed to have made this post is indeed a lawyer in Texas specialising in Family Law, but in a strange twist there are records of disciplinary action taken against him in the Texas bar for, amongst other things, deceit and misrepresentation (suffering a 3 year suspension). As I see it, there are two possibilities here:
  • The comment's author is truly monumentally stupid and decided to leave evidence in a blog of his plans to engage in under-age sex. I find this option highly unlikely.
  • The author is engaged in a systematic smear campaign designed to tarnish a lawyer's reputation through the use of blogs, forums and search engines. The fact that this is a family lawyer could mean that this person has a serious enemy online.
This brings home once more one of the most serious pitfalls in the participatory web. The potentials for misuse of all of these amazing tools is disproportionate. Although these attacks are lost in minor blogs that nobody who knows the person is ever likely to read, the damage would be done through Google. Nowadays we all google potential employees, people we meet randomly, speakers at a conference, etc. Imagine that a person was looking to hire this lawyer. The first page of results shows that he was suspended from practice, and later on he would find some unsavoury pages. The result is easy to fathom.

Monday, September 24, 2007

GikII 2

(The cast of GikII visit Jeremy Bentham on their way to the obligatory pub visit)

As I mentioned earlier, last week we held the second edition of GikII in London. PDF versions of the presentations can be downloaded from the site so that you can wonder at the geek's superior PowerPoint and Keynote skills.

As last year, the quality of the papers and discussion was very high indeed, and continuing with the GikII motto, it was like a good conference, but without all the boring papers. I particularly enjoyed Ray Corrigan's look at the copyfight in medieval Ireland; Jordan Hatcher's presentation on tattoos and copyright; Daithi Mac Sithigh's paper on LOLcats and network neutrality (you have to see it, it does make sense); and Judith Rauhofer's "Privacy is Dead - get over it".

There was a heavy privacy slant this year, perhaps because we are finally coming to a realisation that there is something indeed creepy about all of the technologies deployed against us. Yet, we are willingly walking into the networked society and accepting the Panopticon with open arms. I was intrigued by the many mentions of some technologies which trawl the Internet for information about you. I had heard and tried some services before, such as Spock, Pipl and Wink, yet I found the information incomplete and inaccurate, nothing that a good Google search would not uncover. Nevertheless, I found to my amusement that there is a 63-year-old Andres Guadamuz living in California.

However, I had never heard of ZoomInfo before, so I gave it a try. Oh. My. God. The website uses intelligent agents to trawl the web in search of information, and what it found was surprisingly accurate, although it is clear that my life began when I moved to the UK. Nevertheless, I was also interested that the system decided to award me with a PhD and a Chair in one go... perhaps I could offer that information next time I ask for a promotion?
"The computer thinks that I am well qualified... give me a Senior Lectureship... Now!"

Update: Jordan's paper has been BoingBoinged. Well done!

Thursday, September 06, 2007

Facebook profiles to be made public


Yesterday I woke up to this message on Facebook. Profiles are now available from Facebook's main page (the one you get without being logged in), and soon the listings will also make their way to browsers such as Google. It is possible to change privacy settings in order to place restrictions on search capabilities, so Facebook has a good argument on any privacy abuses that may result from this. Their full statement reads:

"You can control whether you have a public search listing, and where it appears, from your Search Privacy page.
Since your search privacy settings are set to "Everyone," you now have a public search listing. This means that friends who aren't yet on Facebook will be able to search for you by name from our Welcome page. Public Search Listings may only include names and profile pictures.
In a few weeks, these public search listings can be found by search engines like Google. No privacy rules are changing; anyone who discovers your public search listing must register and log in to contact you via Facebook."
This seems like the latest in a growing trend towards higher integration between Web 2.0 tools, and it may be the last nail in the coffin of online privacy. In 1999, Scott McNealy said "You have zero privacy anyway, get over it", his words ring true even to this day, and clearly reflect my own experience with privacy.

At some point (circa 1999), I used to cherish my online privacy, and I believe that my younger self would be appalled by the amount of information that I have made available online. In the early days of the Internet, search engines were less efficient at picking all sorts of data. But as my online presence gained momentum, I realised that the amount of information out there was beyond my control. The curse (and blessing) of having a distinctive and unusual name is that I tend to have a high Google visibility. What to do then? "Get over it" seems like a good motto to live your online life by. Releasing information on your own through social networking has the effect that at least some of the information coming up in search engines is data that you uploaded yourself.

Perhaps we will all have to grow used to the world of the Panopticon, and we should start to assume that we are bing watched at all times. Just because you're paranoid doesn't mean that they're not after you...

Tuesday, July 17, 2007

Caught on Facebook

The Times Online reports on the use of Facebook to enforce some of Oxford University's strict regulations on post-exam celebrations. I have it on good authority that students post pictures of drunken shenanigans on Facebook, some of which fall foul of existing rules. Staff have used those pictures to warn and discipline students. My favourite part of the article is this:

"Alex Hill, 21, a maths and philosophy student, received an e-mail stating that three of her photos provided evidence that she had engaged in “disorderly” conduct. “I don’t know how the proctors got access to it,” the St Hugh’s College student said. “I thought my privacy settings were such that only students could see my pictures."
There's the problem, you see? People assume that Facebook's privacy settings offer some form of security blanket, but they do not. People have already lost their job because of failing to understand that simple fact. There are many problems with thinking that what happens on Facebook stays on Facebook. This line of arguments ignores the very simple truth about information in digital environments; paraphrasing the Replicator Technology Principle, once something has been digitised, copies of it can and will be made. Those drunken pictures are one forward button away from dissemination. Similarly, what is to say that those proctors are not listed as students as well? Interestingly, when I became part of Facebook, it did not assume that I was a member of staff, it assumed I was a student. There is also the assumption that the large list of friends who has access to all your personal details will always behave as "friends". The problem of course, is that the use of the word "friend" hides the fact that most of those on the list are at best acquaintances. And the last in the chain is Facebook itself. Will they always play nice with the very vast amount of sensitive personal data they hold? Forgive me if I declare scepticism on that.

Seems like the student union is not happy about the development:
"The students are livid that their online world is being gatecrashed. Martin McCluskey, president of Oxford University Student Union, said: “While we do not condone unruly, violent or disorderly behaviour, we believe that the university’s use of private photos from the Facebook site in disciplinary procedures is disgraceful."
Private photos? Posting pictures in a social network site does not precisely mean the pictures are private. Anyway, I have mentioned before that I have a love/hate relationship with social networking. I think it's a great idea, but I'm baffled by the liberty with which people treat their personal data. My view of online privacy is quite simple. There isn't any. Anything that I have ever done and written online is stored somewhere, and it can be traced. Failing to understand that simple fact is asking for trouble.

Update: Seems like this story has legs. There are excellent posts from panGloss and Collected Voices, and lively commentary at The Guardian's Organ Grinder.

Friday, May 18, 2007

Data Protection film-making

Faceless is an unusual film for many reasons. The plot, apparently, talks of a world where everybody's faceless due to calendar reform (huh?), but one day a woman wakes up and finds she has a face (Terry Gilliam meets Kafka).

What makes the film truly unique is that it is the world's first CCTV feature thanks to the magic of the Data Protection Act 1998 and of London's unequalled surveillance network. The film-maker, Manu Luksch, has created a story by simply walking in front of CCTV cameras, and then making a data subject request to obtain the data held about her. She then edited out the faces in the crowd (save her own) and edited the footage with a voice over. According to the director/script-writer/actress:

"For FACELESS, the filmmaker swaps data controllers for a film team, already installed surveillance devices for cameras and cranes, and a lawyer for a script writer. The process of accessing these images activates multiple legal layers of regulations concerning these recordings: Data Protection Act 1998, Article 8 Human Rights Act 1998, Freedom of Information Act 2000, as well as aspects of copyright and image rights. It is this information that mirrors the way society relates to its techno/mediated environment and tries to arrange and control itself. The arrangements expressed in these legal codes is used to craft a story."
I think the Data Protection aspect is pretty straightforward. Data subjects have the right to access data held on them, and this includes CCTV footage. However, I find the copyright aspects intriguing. Who owns CCTV footage? I'm guessing that the owner is the institution making the recording, and I am guessing that the editing together of all the images is enough to warrant originality. What about image and personality rights?

(Via BBC's Digital Planet podcast)

Thursday, March 08, 2007

Trouble with jurisdiction

While listening to the excellent podcast Digital Planet from the BBC, I heard a horror story about the problems of regulating cyberspace. While just a couple of days ago I sounded rather optimistic about the prospects of regulating online environments, this story lays bare some of the real problems of enforcing some specific practices conducted online.

The story commented on the case of an anonymous worker from a company that is peripherally related to animal testing. His personal details were posted in an American activist website, and since then he has been the subject of constant harassment, abuse, vandalism and death threats. With the UK government's clamp-down on animal protesters in full force, many illegal activities have moved abroad, particularly online activism. Sites like Bite Back, based in the USA, provide propaganda for the activities of the Animal Liberation Front and other organisations. Some of those sites have been posting the personal address and personal details of all sorts of people. The problem for the targets is the lack of regulation with regards to personal privacy in the United States.

Imagine you were the target of such an attack. What would you do? The answer is: not much. While posting personal details on a website would definitely contravene Data Protection in the UK (and Europe in general), this is not the case in the U.S., where most of these sites are protected by the First Amendment. If there is a criminal offence being committed in the UK, then the Crown Prosecution Service could seek extradition, but I wonder if the American judiciary would be willing to enforce such a request as the opposing values are privacy vs freedom of speech.

Funnily enough (in a perverse way), if we were talking about copyright infringement, the site would remain open only as long as you can say DMCA.

Tuesday, November 14, 2006

Survey on privacy expectations of bloggers

Karen Mc Cullagh has requested that I publicise this survey on privacy expectations of bloggers. If you blog, click on the link and take the survey. Karen says:

What this study is about…?

I'm conducting an online survey to explore the privacy attitudes and expectations of bloggers as part of my PhD research, which is sponsored by the ESRC and Office of the Information Commissioner, UK.

If you participate you will be asked to answer questions anonymously about your blogging practices (i.e. what kind of information you write about on your Blogger, Bebo, Myspace, LiveJournal, Xanga, Facebook, Friendster etc.) and your expectations of privacy when publishing online.

What will happen your answers...?

All answers will be stored and analysed on a confidential basis.

The responses will be used to inform academic and policy discussions on blogging practices and attitudes towards privacy.

Link to the survey:

Please take part in the survey: http://www.ccsr.ac.uk/privacysurvey/

Finally, could you please encourage other bloggers to participate in the study.

It takes less than 5 minutes to complete the survey!

Further information:

For further information on my research please visit

http://www.ccsr.ac.uk/staff/km.htm

Many thanks,

Karen