Wednesday, October 17, 2007
Facebook ordered to get tougher on privacy for children
In response to a spate of issues involving sexual predators using MySpace, Facebook began promoting itself as a safe online environment for children. To test their claims, investigators from the New York Attorney General’s office posed as teenagers and within a matter of days after posting their profiles on Facebook, had received numerous sexually suggestive messages from adults. Their complaints, registered using Facebook’s online form, went unanswered for weeks.As a result of their investigation, New York state prosecutors accused Facebook of false advertising and the New York Times reports that yesterday, Facebook was ordered to immediately post stronger warnings about the risks to children using the site and to provide a quicker response to thousands of complaints daily about inappropriate sexual messages.
The changes are part of a settlement with the New York attorney general, Andrew M. Cuomo, whose office last month announced that it had been investigating whether the Web site misled users by promoting itself as a place where minors were safe from sexual predators.
Mr. Cuomo said the settlement would serve as a “new model” under which law enforcement and Internet companies could work together to protect children and recognize that they share responsibility to police illegal activity online.
By using consumer-protection laws to tackle the thorny problem of Internet safety, Mr. Cuomo appears to be building on the tactics of his predecessor, Gov. Eliot Spitzer, who used state laws to prosecute fraud on Wall Street.
“Any site where you are attracting young people, you must assume you are simultaneously attracting those who would prey on young people,” Mr. Cuomo said in an interview. “Whether you are a shoe company or you’re an Internet company, consumer protection laws apply.”
Chris Kelly, Facebook’s chief privacy officer, stood beside Mr. Cuomo to announce the deal and called the settlement part of the company’s effort to grow while maintaining users’ sense of safety and community. “We actually think we’ll end up attracting more people” because of the new measures, he said.
The settlement also requires Facebook to hire an independent company to track its responses to complaints and to report twice a year to Facebook and the attorney general.
In an earlier post, I expressed concern about Facebook’s default “wide-open” privacy settings and their announcement that profiles would be made available to third parties and eventually over the Internet using an automatic opt-in model. I complained to Facebook about this practice and my particular concern about the risks to minors. While their response was timely, coming within a few days of my original complaint, it completely skirted my concerns about using a negative opt-out, as well as the issue of putting children at risk:
We appreciate your feedback and will take it into consideration moving forward. Please keep in mind that a public search listing is simply a basic search result that allows people to know that you have a Facebook profile even if they do not yet use the site. Your public search listing will only be available if you allow “Everyone” to search for you on Facebook and have the “Allow anyone to see my public search listing” checkbox toggled on. You can adjust these settings from the Search section of the Privacy page.If Facebook truly cared about their users' privacy, and particularly the privacy of minors, their user profiles would default to allow maximum privacy, allowing users to choose to opt in to make their profiles available for searching on the Web. In light of these kinds of policies and their response to valid privacy concerns, it’s encouraging to see the privacy practices of social-networking sites like Facebook coming under closer scrutiny, particularly with respect to the safety of children.
Also note that people who do not yet use Facebook will not be able to interact with you or view your full information without registering with the site. Your public search listing will not affect any of your normal Search privacy settings. A non-Facebook user viewing your result would see the same search result if they registered with the site.
Your public search listing will also eventually appear in search engine indexes, making it even easier for your friends to connect with you. To change this option, please go to the Search section of the Privacy page and deselect the option to “Allow my public listing to be indexed by external search engines.”
By more efficiently connecting people, we hope that we can make your experience more meaningful on the site. Let me know if you have any further questions.
Thanks for contacting Facebook,
Kristjan
Customer Support Representative
Tuesday, October 9, 2007
Librarians: best knowledge managers for our new world
From the b.eye Business Information Network, Dr. Ramon C. Barquin has an informative article about the role that modern librarians can play in the brave new information world.If there is one profession that has traditionally been underutilized in terms of the contribution they can make to business intelligence and knowledge management, it is the librarians.
...Finding anything and making sense out of it as we move from intelligence to knowledge will be very challenging. ...I would take every major portal where navigation is a problem and give a group of librarians the job of improving it.
...That is where librarians can make a big difference. Give them the right tools, and they will become the best knowledge managers for our new world.
Posted by Sharon E. Herbert at Tuesday, October 09, 2007 0 comments
Labels: Business Intelligence, Knowledge management, Librarians
Saturday, October 6, 2007
Homeland Security's Chertoff: more surveillance, less privacy
Michael Geist reported on the BBC news site about Chertoff’s presentation at this year’s global privacy conference, where the theme was “Terra Incognita”, the latin term for unknown lands:
In a room full of privacy advocates, Chertoff came not with a peace offering, but rather a confrontational challenge.
He unapologetically made the case for greater surveillance in which governments collect an ever-increasing amount of data about their citizens in the name of security.
For example, in support of his security agenda, he noted that US forces in Iraq once gathered a single fingerprint from a steering wheel of a vehicle that was used in a bombing attack and matched it to one obtained years earlier at a US border crossing.
He added that there was a similar instance in England, where one fingerprint in a London home linked to a bombing was matched to a fingerprint gathered at a US airport (the identified person was actually innocent of wrongdoing, however).
Chertoff explained that in the autumn the US intends to expand its fingerprinting collection program by requiring all non-Canadians entering his country to provide prints of all ten fingers (it currently requires two fingerprints).
In the process, his vision of a broad surveillance society - supported by massive databases of biometric data collected from hundreds of millions of people - presented a chilling future. Rather than terra incognita, Chertoff seemed to say there is a known reality about our future course and there is little that the privacy community can do about it.
Posted by Sharon E. Herbert at Saturday, October 06, 2007 1 comments
Labels: David Brin, Department of Homeland Security, Michael Geist, Privacy, Security
Tuesday, September 11, 2007
2020: The future of surveillance
Imagine a world where …- every single one of your activities outside your home was monitored on closed-circuit cameras
- your computer’s ip address was fixed, allowing anyone to track your activity and making your computer a hot property for thieves wanting to hide their identity
- all monetary currency has disappeared and your electronic transactions are all tracked, unless you pay extra to "scrub" your transaction
- you will be required by law to wear an identity transponder at all times so that you can be readily identified
- your insurance company is able to monitor the groceries you buy and what you consume in a restaurant in order to charge higher rates to subscribers who eat junk foods
These are just some of the predictions forecast in DM News by Robert Gellman, a Washington-based privacy and information policy consultant and former chief counsel to the U.S. House subcommittee on information, justice, transportation and agriculture.
2020 is just 13 years away – how close are we to living in the world that Gellman predicts?
Photo by: Gavin Stewart, Creative Commons Attribution 2.0
Thursday, September 6, 2007
Facebook uses negative opt-out to make profiles public
Facebook users received notifications this week that the company is planning to make user profiles available to non-users and eventually make them searchable on the Internet, as reported today by the BBC:The function will initially allow anyone who is not registered with the site to search for a specific person. More controversially, in a month's time, the feature will also allow people to track down Facebook members via search engines such as Google.
The firm said that the information being revealed is minimal.
… The public search listing will show the thumbnail picture of a Facebook member from their profile page as well as links allowing people to interact with them. But, in order to add someone as a friend or send them a message, the person will have to be registered with Facebook.
Users who want to restrict what information is available to the public or
opt out of the feature altogether can change their privacy settings. They have a
month to do so.
Now, Facebook is pulling down the walls of their environment and allowing anyone, anywhere to see its users’ profiles – unless users choose to opt out. The negative opt-out technique means that if users do not respond, Facebook will assume they have granted permission for their profiles to be made public.
Roger’s Cable in Canada tried the negative option technique in the mid-90’s, delivering a package of new speciality services with automatic increased costs to customers’ bills. Customers were outraged, the company backed away from their plan and by 1999, Canadian parliament outlawed the practice.
The negative opt-out is at best unfair and at worst a huge violation of trust:
It presumes that everyone will read the opt-out notification within the month – there are purportedly 39 million Facebook accounts, a large percentage of which have likely become inactive or are used infrequently, so those users’ information will probably go public without their knowledge or consent.
It takes advantage of a low response rate. Studies have shown that only about 15% of users will respond to a negative opt-out. Facebook stands to make a greater profit using this method than requiring users to opt in.
It takes advantage of the relationship developed between service provider and customer. Facebook is presuming that it can use its customers’ information in whichever way it deems fit, with a minimum of input from users.
It puts users – including minors – at risk by exposing their profile information to the wider world. Many Facebook users are not well-informed about the myriad of privacy settings required to lock down one’s profile. Many users leave their entire profile, including date of birth, workplace, residential neighbourhood and status (e.g. “I’m vacationing in Aruba all week!”) open to entire networks of thousands of members to view. While users’ entire profiles will not be available to search on the Web - not yet, anyway – it opens the door for greater abuse.
In using the negative opt-out technique, Facebook is violating the trust and the privacy of millions of loyal users. If users and regulators allow Facebook to proceed with this tactic - what's next? What other web services do you use that may decide to share your personal information or web history with a third party, assuming that your silence to a negative option grants them your "permission"?
Saturday, September 1, 2007
Lessons from the massive privacy breach at Monster.com
Last week’s massive security breach affecting Monster.com is a reminder of what is at stake as we all come to rely on web-based services for everything from shopping to dating to job searching. For those unfamiliar with the service, Monster.com is an international job search site, where employers can post job ads and employees can post their resumes and apply for positions. According to CRN Business:The stolen data, which was found on a remote server and shut down by Monster.com this week, included users' names, addresses, phone numbers and e-mail addresses. Symantec security researchers first reported the incident last week, although it's still not clear when the breach first occurred.
The data was collected by the Trojan Infostealer.Monstres, which likely used stolen login credentials of legitimate employment recruiters to gain access to the site's resume database, according to a posting by Symantec researcher Amado Hidalgo on Symantec's Web site. The unsuspecting job seekers whose information was stolen then became the victims of various phishing e-mail scams attempting to empty their bank accounts.
To be safe, he said, all Monster.com users should assume that their contact information has been taken.
Ianuzzi offers little comfort to Monster’s customers:
"I want to be clear and I want to be frank: There is no guaranteed fix," Iannuzzi said. "I wish I could say . . . there will be absolutely no way that the Monster site can be compromised. I cannot ever make that promise, and no Internet company can." (emphasis is mine).
Some ways you can reduce your risk:
1. When signing up for a Web service – anything from Facebook to Ticketmaster alerts to a blogging utility – how much personally identifiable information are you required to provide? How important is the service to you when weighed against the risk of your personal data being stolen or unlawfully accessed?
2. Could you access this service in another way? For example, is it possible to apply for a job by e-mailing the employer directly, rather than uploading all of your application data to a Web service?
3. When you are making an on-line purchase, be sure the vendor is providing a secure means of making the transaction – look for the https:// prefix in the URL (e.g. https:// www.abc.com). You should see a lock box on your screen if the site is secure.
4. Make sure you run anti-virus software regularly to ensure that key sniffers are not at work on your computer. Because you cannot be assured that this is happening in libraries and internet cafes, don’t access your on-line banking service or make financial transactions on public Internet computers.
5. If you are using a wireless Internet connection, secure it to ensure that no one can access your computer.
6. When making a transaction online, always decline the option for the service to retain your credit card information. The inconvenience of re-keying this information is not worth the risk of a data breach.
7. Vote with your feet and with your money. Don't support companies or services that aren't taking data security seriously. If you have a concern about the amount of personal data you are required to provide in order to access a service, don't go ahead with the transaction. Write the companies and let them know your concerns. Read their privacy policy thoroughly.
Most of us wouldn’t leave our houses without locking the doors, but we can so easily become complacent about the amount and type of personal information we share in our day-to-day activities.
Posted by Sharon E. Herbert at Saturday, September 01, 2007 6 comments
Labels: Consumers, Monster.com, Privacy breaches
Monday, August 27, 2007
This is Privacy Awareness Week
Privacy Awareness Week is a promotional campaign first initiated by Privacy Victoria (Australia) in 2001. This year, for the first time, Privacy Awareness Week has gone international.The week is an opportunity for organizations and agencies covered by privacy legislation to promote privacy awareness to their staff, customers, and to the wider community. The theme for Privacy Awareness Week 2007 is ‘Privacy is your business'.
In Australia: Privacy Victoria
Posted by Sharon E. Herbert at Monday, August 27, 2007 4 comments
Labels: Australia, Canada, Privacy, United Kingdom, United States
Tuesday, August 21, 2007
Andrew Feldmar on the Colbert Report
Back in April, I wrote about Canadian researcher Andrew Feldmar, who was held at the border and subsequently barred from entry into the U.S. because a border guard googled his name and discovered he'd tried LSD in the name of scholarly research over 30 years ago.
