Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, June 22, 2012

In No Shape to Play

Drat. I'm so out of practice that it only just occurred to me that the baby's been asleep for an hour, and I could have been playing Skyrim all this time.

But I'm so out of practice that I hesitate to start now, because it will probably take me half an hour to remember the controls, and I can't stay up late playing unless I want to be really tired all day tomorrow, because I certainly can't plan on sleeping in.

Maybe tomorrow night.

In the meantime, I recommend this interesting story by Jay Stanley on Blog of Rights. He lost his credit card, and in order to prove that he was himself and get a new one, had to correctly answer a question based on information "obtained from third-party information services."

It turned out that the third-party information service was wrong, meaning that he couldn't prove he was himself.

The piece has interesting thoughts about account security (good in principle, but if it's so secure you can't access it, that's a problem); creepy information gathering (some company out there is just collecting bits of possibly-correct information about you and selling it to other companies for 'security' questions and who knows what else, and you have no real way to know what they have on file for you or correct any errors); and the way that even though we often hate phone trees* and assume that "getting to a human" will help resolve a problem, in this case "there was little difference between computer agent and human agent" because the human had no authority to override the computer.


*Not me, I love phone trees and will happily push buttons all day rather than talk to a person, as long as I can actually accomplish what I need to. But then, I hate people and can hardly wait for the arrival of our robot overlords. As long as they can get stuff done.

Friday, March 2, 2012

Precious, Precious Content

Props to the Krafty Librarian for reading the policies on content ownership for a ton of different social media sites and reporting them in one handy post.

It turns out some sites basically claim ownership of anything you post on them to do whatever they want with, while others specify that you do own your content, but still claim the right to use it in various ways.

To some extent I suppose that seems fair. If I build a platform other people like to use, it's reasonable if I get to benefit from their activity in some way. What way, though? Well, that's the question.

Since many of us are not going to swear off social media, I guess we'll all just play along with the grand experiment and see what happens. But if you want to be better informed along the way, it couldn't hurt to read up about these sorts of policies to figure out exactly what different companies can do with the information you give them.

Then make sure an unpredictable portion of that information is weird but plausible lies, just to throw them off.

For example, I used to collect china figurines of geese, preferably geese wearing gingham hats. Ideally there would be a basket tucked under one wing. Flowers in the basket were optional.

It was a thing I did.


Thursday, January 26, 2012

Speaking of Privacy...

And as long as we're on the subject, many of you will probably have received Google's friendly email notice about their new, Google-wide privacy policy, covering all Google sites.

Identity Woman has a review, and is not a big fan. I think she makes a good point:
I think in one way she is right the people like her - who went to college and have mainstream white collar jobs are on these fora with their real names
...and therefore, it won't be a huge deal to a lot of such people (like me).

On the other hand, if you are a person who has online interests that are significantly different from your offline life, or different sorts of online interests that you like to keep separate, it could at the very least be something of a hassle to have everything you do online mashed into one easy-to-access package.

Hm.

Wednesday, January 25, 2012

Turn It Up!

I don't have or know much about Spotify, a music service in Europe, but Ben Goldacre reports that it has potentially distressing privacy issues for those who don't care to have their information shared widely.

It's an interesting example of the way that some of these social networking features seem to view things. Why wouldn't everyone want everyone else to know exactly what music they're playing at all times?

It seems like a vision of the internet as a crowded apartment building where everyone lives next door to everyone else and the walls are thin. And the keyholes are large and easy to peek through.

It's so easy to know what your neighbors are doing! And it's cool, because we're all good friends.

Wednesday, August 24, 2011

StealthNet

Go Make Me a Sandwich has a guest post offering a nice introduction to internet anonymity (crucial tip: be extremely paranoid).

It mentions metadata! Not the sort librarians apply to records, though. The type that software and gadgets automatically add to your documents and photographs (autometadata?). The post notes that metadata is not necessarily bad, but can be trouble in the wrong situation:
Pictures, for example, store all kinds of juicy things as EXIF data, including in the case of some phones and cameras, geolocation. Office documents, pdfs, spreadsheets; all sorts of things can hold data that can identify you. This junk is called Metadata. Not a big deal (it can even be personally useful) until you’re posting information, say, about unethical practices about your boss on your anonymous blog and your employer uses metadata from a posted .docx file to find out it was you. Oops. Now you’re fired. Or worse.
Again, this is not librarian metadata, but I'm all for spreading awareness of metadata in general, so cheers to the mention that, if you're not worried about anonymity, it can be useful.

Yes! Use it to organize and manage your data!

Also, be paranoid. Besides the metadata note, which yeah is probably not the interesting part to anyone but me, there are helpful tips on passwords, anonymous browsing, thoroughly erasing files, and more.






Sunday, February 6, 2011

Confinement of Information

Have you ever been curious as to whether there were any government files kept on your suspicious behavior?

Have you ever considered filing a Freedom of Information Act (FOIA) request to get access to said hypothetical records?

Erich Vieth of Dangerous Intersection tried it with the Department of Homeland Security, and offers some illuminating commentary on the unhelpful response he received.

As a librarian, I was particularly struck by the fact that DHS states it "does not maintain a central index of records about individuals."

This means that in order to access records, you must "describe the records you are seeking with as much information as possible," including "the type of record you are seeking, the DHS component you believe created and/or controls the records, the precipitating event that you believe warranted the creation of records and the time period that you believe the records or files were created and compiled."

So you have to know what happened, before you can get information about what happened.

And if you don't know of a specific precipitating event that might have resulted in records-creation, and you just wonder if your name shows up anywhere in their files, too bad, they have no way to find it.

Is apparently what they're saying, although that seems ridiculous.

Because seriously, no central index? You can't just look up a person's name?

That's grand for privacy purposes, perhaps, since it means it must be very difficult to find out what you know about anyone unless you know exactly what they've done and when, but it's kind of incredible to me from an information organization standpoint.

How do you ever look anything up? I suspect there's some twisty language trick going on, like maybe they have several non-central indexes that they consult one by one, or they officially call it 'main index' instead of 'central index,' or something.

If not, they really ought to look into that, because if you're trying to keep track of people who've done or who might do things, being able to look them up by name and find all the references associated with that name (maybe even cross references to alternative forms of the name, if you want to get fancy!) can really help.

I know, because I use this trick with authors of books all the time.

It's super-handy, DHS folks! Talk to your local librarian for more information about how you can use indexing to make your job easier!

.

Tuesday, June 8, 2010

DNA-Colored Glasses

Here's an interesting health/technology/privacy issue for you: the ACLU's Blog of Rights talks about DNA testing for newborn infants (often useful since it can identify genetic disorders that might be treated), and what happens to the samples collected (often not specifically stated in any consent forms presented to parents).

The post notes

As you might imagine, DNA samples are valuable to different parties for different reasons. So it's now common for states to hold onto the blood samples for years, even permanently. Some states also use the samples for unrelated purposes, such as in scientific research, and give access to the samples — or even the samples themselves — to others.

I'm all about scientific research, but there are certain rules about informed consent and so forth that I think it's probably just as well we adhere to carefully, even if there might be some really really cool thing we could figure out by letting that adherence come a little unstuck.

Is it a big deal if the state hangs onto peoples' DNA samples from when they were born and makes use of them in various ways as the need arises?

I honestly don't really know. But as many ways as you can think that it would be extremely handy to have everyone's DNA on file, you can also think of ways that it's kind of disturbing.

For example, it will make it really easy for the killer robots to track you once they take over the government.

.

Tuesday, May 18, 2010

Hold On, Let Me Tell the World Something

T.Scott has an interesting take on the Facebook privacy issue in this post descriptively titled "It May As Well Be On the Front Page of the NYT."

The post suggests that the problem is not necessarily about privacy or lack of privacy, it's whether expectations of privacy match up with reality. If you go into something like Facebook with limited expectations, and a policy of assuming that everything you post online could be seen by everyone in the world, you'll have fewer unpleasant surprises. (Except possibly, depending on your level of extroversion, how little everyone in the world cares.)

This rings true for me to some extent, possibly because I also have pretty much tended to assume that anything I post could be seen by anyone, even though in reality almost no one cares. And in general things are in fact fairly private, in the sense that if you're one of several million people talking to themselves in public, you're relatively safe even if you're talking about your darkest secrets, because what are the odds that anyone who knows you is going to hear? Among multitudes lies anonymity.

That said, I don't talk about my darkest secrets (which I assure you are so blood-curdling and hair-raising that even to tap the keys required to describe them would send me into conniptions right here), because you never can tell.

Someone could always come along and overhear at any time, even if they never did before (especially given the archival nature of web communication), and I think it's wise to remember that. I also do think that some people may have unrealistic expectations of how close-to-the-vest their information actually is out there on the social web, on blogs, networking sites, ratings sites, etc.

On the other hand, to look at a slightly different angle on the question, I feel sympathy for people who may themselves post cautiously but wind up appearing online in the indiscreet posts of other people. You definitely hear things like "I don't even have a Facebook account, but my bitter ex-boyfriend is using his to post drunken photos of me!", and that really does seem like a problem.

You can control your own online behavior, but may have no control over what someone else does, and other people can make your secrets just as public as you can if they have the information.

Which gets into non-Facebook issues like "be careful who you trust with your secrets," and I guess would technically be a legal issue (who owns a person's image/info and has a right to post it?--can you make them stop?) rather than strictly one of privacy policies.

Because it might well be against a policy to post pictures of people who don't want you to, but it's not as if Facebook is going to be requiring signed consent forms for every photo posted. It would have such an inhibiting effect on people posting photos at all that Facebook would probably lose members to Flickr or someplace that didn't have such a requirement, and there you are. You can't be losing members! Those precious, precious eyeballs and tidbits of personal, advertise-to-able information are the blood of life.

It's just a lot easier for random stuff you say or do to be seen by everyone in the world these days, and I do understand the plaint that it sucks to basically be told you have to be careful about everything you do or say everywhere, because someone else might catch you on their cellphone camera, even if you've always been the soul of discretion online.

Its one thing to assume everything you post online might as well be on the cover of the New York Times, and another to live your life assuming that you could also be the subject of someone else's NYT piece at any moment. Are we all tiny celebrities potentially being stalked by part-time paparazzi?

It's an interesting world.

But overall, yes, I agree with the original post: assume everything you put online is public! Wildly, outrageously public! Everyone in the world is looking at it right now!

At the same time, lest that give you an inflated sense of self-importance, you should also assume that no human eye will ever see it.

This is a nice bit of mental gymnastics that I like to think will help keep the brain in shape.

.

Saturday, April 3, 2010

Genes Shall Roam Freely!

There's something a little creepy about the idea that someone could take out a patent on human genes (or any genes, really, but it's closer to home when they're human), so I was interested to see this ACLU update from Monday about a district court ruling saying that such patents are invalid.

I don't think anyone has ever expressed interest in acquiring legal ownership of any genes expressed by my personally, but if they do, they're doomed to sorrow and disappointment! So there.

.

Tuesday, February 23, 2010

Spies! All Spies!

Ugh. I'm sure everyone's heard of the high school that provides students with laptops, equipped with cameras, which can be remotely activated and used to take pictures of the students without their (or their parents') knowledge or consent.

I wonder if this was in some fine print in a contract students/parents needed to sign to get the computer? "I the undersigned do hereby agree that you can spy on my kid at will"?

[Staring suspiciously at my own webcam. Because I bought this computer myself, but who knows who might have gotten to it? I'm inclined to stick masking tape over the camera eye right now.]

I saw this on Alas, A Blog.

.

Friday, February 12, 2010

Google Pulls Back the Curtains

Rather than provide updates about my personal travel-whining situation, which has just become a ghastly failure in every way, I will note that there seem to be some fairly serious privacy concerns about Google Buzz, the latest hot thing from our technological overlords.

Apparently it links all your info from various Google accounts (Picasa, Reader, Gmail, etc.) and shows bits of that to everyone you're linked with.

Clearly a potential problem if you maintain an pseudonymous blog, like Dr. Isis at On Becoming a Domestic and Laboratory Goddess, or have an abusive ex-husband like Harriet Jacobs at Fugitivus, or if there's any other circumstance in which you might not want every person on your frequent-contact list to see what blogs you read, etc.

Say, you have different contacts in different contexts and don't especially need to merge them all into one big social network soup.

Apparently you don't even have to sign up for Buzz for certain aspects of this to kick in, which means that even though I do not have a Buzz account, I need to worry about this because of my Picasa, Reader, Blogger and Gmail accounts (I have Docs, too--can other people see what documents I'm working on?).

Not cool, Google.

You should fix that.

-----------------------------

Some hours later:
Update from Harriet Jacobs at Fugitivus about how Google is working on it.

.

Thursday, January 7, 2010

Tell No One

Interesting article in the New York Times (via Double X) about the difficulties of severing contact with former boy- or girlfriends after a breakup, in the bold new age of social networking.

We've probably all heard by now about the strange awkwardness of breaking up with someone by changing your Facebook status to 'single,' and become somewhat familiar with the way that social networking, like a small town, can ensure that everyone in a circle of friends knows everyone else's business.

I can see how this would add layers of complexity to already difficult circumstances, and it's of modest but not pressing interest to me.

The part of the article that does surprise me is the line "Sharing passwords to e-mail accounts, bank accounts and photo-sharing sites is the new currency of intimacy."

Hm. I am dubious. Do people really do this? Just say, 'here are my email passwords--check it out'?

By this standard, I am without intimacy in my marriage. I share my passwords with no one. No one!

Not even for little things like Hulu or Amazon. My passwords are mine alone. Sometimes I sit in my room turning them over and over in my mind and hissing "my preciousssssss."

Then I make a swallowing noise in my throat. It's just so delicious.

Granted, this privacy would become problematic if I died suddenly. My online bank account would be troublesome to access. Good luck straightening out the details of my retirement accounts and so forth. And if you wanted to gather some of my photos from Picasa, go through my half-written fiction, try to assemble the details of what I was working on so you could finish my important e-book cataloging project, well, that would be tough too.

Start guessing!

Anyway, I don't know. Do my spouse and I have a sad and distant relationship, with our separate social networking accounts and secret passwords?

That's what you call a rhetorical question, I guess, since I'm not particularly interested in changing things even if someone tells me the answer is "yes." I just find the idea of sharing that kind of information a little weird.

But I know different people have different levels of comfort, and if someone else thinks it's totally cool to swap Facebook passwords with their significant other, and finds it a little weird that I huddle in the dark clutching mine close to my chest as if they could save me from the harsh grip of true intimacy, well, as long as they're not married to me (and as far as I know they aren't), it's no concern of mine.

.

Thursday, December 3, 2009

No, I Can't Prove That's Me

Interesting Blog of Rights post on Real ID, the proposed national ID card that's been bandied about for years now.

I was a little fuzzy on the details of this plan (I remember reading about it years ago when it was first bandied, and then, like many of us, I kind of forgot about it when no major changes to my immediate state ID were forthcoming).

For example, I had forgotten that if your state's acceptable forms of identification don't comply with Real ID, you're supposedly not allowed to use said ID when going through airport security. As the post explains, states were not happy about this (there were numerous objections based on privacy concerns, and it would also cost a lot to implement Real ID requirements):

[A]lmost half [of the states] passed statutes or resolutions saying that they would not participate in the program. Every state was supposed to be compliant by May of 2008; none of them were.

This left the Department of Homeland Security (DHS) with an unpalatable choice. They could effectively shut down air travel in the U.S., or issue blanket exemptions to all 50 states.

After choosing option B and giving the states exemptions and a new deadline of December 2009, we find that here in December 2009, Real ID is still not in our wallets.

I guess sometimes ignoring things (or, more actively, passing statutes or resolutions against them) is the way to go.

.

Tuesday, June 2, 2009

My Name? Uh...Timmy.

Dangerous Intersection has an interesting post about the slow disintegration of anonymity in our busy high-tech culture.

Specifically, it's about the irritation of having to give your name to accomplish all kinds of not-really-name-needing business. The incident in the story here is that the author asked for a price on something in a store (I'm assuming maybe an art gallery or jewelry store or something where prices are too uncouth to be listed, and high enough to make it worth keeping track of who wants them), and the salesperson stated that she needed a name in order to reveal it.

I've never had this happen to me, but I have been faintly annoyed to be asked for my ZIP* code when making purchases in stores.

"What's it to you?" I think.

I usually give a false one, like from the town where I was born (that'll throw 'em off).

If I'm paying by credit card, which I almost always am, they can look it up for themselves if they have to have it.

And, in fact, at the self-check-out in the grocery store near me, you have to enter your ZIP code on the keypad when paying by credit card, and it knows if you lie (yeah, I tried it) and won't let you complete the purchase. They say it's an anti-theft measure--so be on notice that if you steal someone's credit card, you should also figure out where they live before you go grocery shopping at Shaw's with it.

Anyway, I guess I'm not really in a position to complain about loss of anonymity when I practically refuse to buy except with credit, meaning that a long, clear and personalized trail of everything I buy everywhere is available for review.

Nevertheless, I understand the annoyance. It feels sometimes that everyone wants your information so they can try to sell things to you. I've become suspicious of requests for this information if they don't have a purpose that makes sense to me. Sometimes I'll give a fake name!

Not usually Timmy, though, unless I'm online.

Is this misrepresentation wrong of me? I'm going with "not really." Dishonest, yes, but in way that doesn't mean enough to matter much.


*I may be the only person in the world who doesn't work for the post office who capitalizes this, because I have a recollection of it originally being an acronym for Zoning Improvement Plan, and I have respect for the acronyms.

Saturday, February 28, 2009

Nothing to Read Here, Move Along

I love how Bad Science neatly explains statistical concepts. Here, a nice breakdown of why false positives make useful terrorist-detection data mining programs fairly impossible.

Briefly, given the ratio of non-terrorists to terrorists, you couldn't make such programs accurate enough to catch actual terrorists without also catching so many non-terrorists (say, millions) as to render the whole thing pointless.

Which is unfortunate in a way, because it sounds nice to just say that if we set the computers loose on all of our phone records and internet activity and credit card purchases and travel history and library use, they'd be able to handily separate the nasty, plotting wheat from the inoffensive, law-abiding chaff.*

But if we give up all that privacy and get in exchange a decent chance of winning the Next Sack of Terror Flour lottery, it no longer seems like such a good deal. The numbers do not appear friendly towards the national surveillance idea. 

Of course, there's already a lot of surveillance and data collection going on in all kinds of organizations, as noted in a post from Schneier on Security, where the concept of "data pollution" is introduced. 

The author suggests that the vast quantities of data collected and stored on anyone who does much of anything in the digital world has the danger of becoming the pollution issue of the time. He argues that the casual conversations and exchanges we all have every day are not intended to be preserved and analyzed: we're used to being able to toss off comments or ideas without having others examine them and bring them back to haunt us later, but anyone who puts anything out there in public can't really rely on this.

This is obviously a concern for famous people, many of whom do and say really stupid stuff that amuses or horrifies us as viewers--but if someone followed me around all the time filming me and making note of everything I said, I'd undoubtedly look like an inconsistent, absent-minded, babbling loon. 

Also, my makeup and fashion sense would be revealed as dreadful; who dresses me? Half-trained monkeys?

As Schneier says,

Conversation is not the same thing as correspondence. Words uttered in haste over morning coffee, whether spoken in a coffee shop or thumbed on a BlackBerry, are not official correspondence. A data pattern indicating "terrorist tendencies" is no substitute for a real investigation. Being constantly scrutinized undermines our social norms; furthermore, it's creepy. Privacy isn't just about having something to hide; it's a basic right that has enormous value to democracy, liberty, and our humanity.

Well, these days, with our social networking and the wide array of cameras and video, we can all look like babbling loons!

I guess we can take comfort in the fact that there are a lot of us.


*This analogy presented as a shout out to the gluten-intolerant. Rock on, you noble spelt-eaters!


Saturday, September 6, 2008

Let Us Once More Consider Facebook

I don't even spend that much time on Facebook (I swear! six or seven hours a day, tops!), but I do seem to frequently find other people talking about it and want to chip in.

This time, librarian.net recommended a paper called "Facebook and the Social Dynamics of Privacy," and said paper proved very interesting. 

The author, James Grimmelmann, offers some good background information on social networking, and a solid discussion of the ways that interactions with other people and use of applications on Facebook can build up a fairly detailed picture of who you are.

Your name and location, who you know and their names and locations, any additional personal details you care to post, the kinds of relationships you have with the people you know (do you often 'poke' certain people, exchange 'gifts' with others, play games with others?), can all be seen through your profile and actions.

The kinds of things you think are interesting, and thus, in a sense, who you are, will also show up in the status messages you post, the kinds of games you choose to play, the gift-images and poke-messages you send, the 'Cause' pages you subscribe to and the institutions you declare yourself a fan of, and so on.

He talks about the fact that this picture of you is not entirely under your control as a Facebook user, since even if you keep your own privacy controls set to high, other people can leave their profiles open (or make them public at any time without consulting you), including any statements you've written on their 'wall,' pictures tagged as you on other peoples' pages, comments about you, etc.

I liked the discussion about peoples' motivations for giving away so much information on these sorts of sites. The article says that there's a natural interest in being able to control the way that other people see you: people want to look good to others, and being able to present yourself on a site with a personal profile of carefully chosen details and images is an appealingly straightforward way to do this.

It's plainly also true that social networking sites are good for, well, networking socially: keeping in touch with friends, making new connections, getting to know more about acquaintances. 

There's strong presentation of the idea that the value of social networking depends on people sharing information: you need buy-in, you need people to be on the site, using its tools and playing with its applications, or else there's no point. These sites are interesting and can be fun and useful, and that value depends on having a mass of users willing to put in the time and share the information.

But there are also real concerns about sharing too much information, making too much available about yourself or someone else. The article suggests that we tend to assume much more privacy than we really have: we think we're posting pictures and comments for our friends, and don't really keep in mind the fact that things posted on the internet can be rapidly disseminated much more widely. 

Similarly, we assume that something we send to another person will be received the way we meant it ("clearly, that comment about Betty was just between you and me!"), while in fact, without the clues of expression and tone that we get in face to face conversation, the person may take the message to be public, or neutral, and see nothing wrong with passing it on.

We've all heard stories about people who were refused jobs because their potential employers saw pictures of them mixing martinis for children or whatever, and a lot of the users of these sites are surely not much concerned with whether such-and-such personnel manager for a company they'll want to work for in ten years but haven't heard of yet is going to think their profiles are as amusing as they seem right now. 

This made me think about the idea that the web is 'small-town-izing' the world: that in a small town (and potentially in a highly web-enabled world) everyone knows everyone's embarrassing youthful (or otherwise) exploits, but you all just live with it and go about your business anyway. I mean, what else can you do? 

And, not to present questions without suggestions for answers, the article also presents some thoughts about policies and tools that probably won't help to protect privacy on social networking sites (anything that makes it harder to connect with other users, since that's what people are there to do), as well as some that might (education of users, as well as policies implemented by the sites).

There's a lot more in the article, but I've already rambled on long enough. In any case, I'm not really doing it justice, but do recommend it as an interesting look at an interesting piece of the web.


Tuesday, August 12, 2008

Keeping in Touch

I got a friendly note yesterday from the Alumni Association at my alma mater (hi, Alabama!), asking for information on what I'm doing, how the family is faring, what the harvest looks like (hair), whether my hereditary weeping boils have subsided, and so forth. 

I would return the lovely postage-paid card with spaces for filling in my name, address, home phone, place of employment and work phone, but...well, it's just a postcard. All that information is just there, totally exposed in the mail for anyone to see! 

Not that anyone cares, but with all the identity theft worries these days, is it really a good idea to send that kind of information through open mail?

I admit this may be an unreasonable apprehension. After all, my home phone is listed in the phone book (I think---I haven't looked at a phone book in years, so I'm just guessing), my work phone will be on the internet once that website is updated, and I put my home address on the outside of every piece of mail I send anyway, usually in the form of one of those little return address labels that various  organizations send out in the vain hope that people will give them money. (I suppose some kind people must actually give them money.)

Am I getting weirdly paranoid about harmless low-tech identity-distribution, while blithely strewing personal information to the trillion-plus corners of the internet, and, therefore, spending my worry-points in exactly the wrong place?

It is entirely possible.