Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, November 15, 2009

Thatcher has died

Canadian Transport Minister John Baird got some sad news the other day: His 16-year-old tabby cat had died. He let some of his friends know by a quick text reading “Thatcher has died.” And that’s when panic set in.

The text was misinterpreted, and quickly spread. Soon the Canadian Prime Minsiter was alert of Margaret Thatcher’s demise.

According to the AP: Harper's aide Dimitri Soudas, back in Ottawa, was dispatched to confirm the news and start preparing an official statement.

Except the former UK Prime Minister, like Kanye, wasn’t – and is not – dead.

So there are a few lessons learned here. One of which is that Thatcher’s office apparently doesn’t have prepared statements for the death of their 84-year-old ex-PM – which is a little astounding. The second is the speed at which misinformation can be spread. The whole ordeal was resolved within 20 minutes – but it goes to show what an impact a sliver of information can have on the web.

Wednesday, November 11, 2009

Outed by Facebook?

Facebook has certainly been a helpful tool in the coming out process for many. Simply set your interests to “men,” and you can cause a flurry of interest.

But what if you want to be a little more discrete for whatever reason? Maybe you’re uncomfortable, maybe you’re shy, maybe it’s nobody’s business. That’s a discussion for another time – but OK, you want to keep your sexuality private.

Well, two MIT students recently came up with a program that can accurately predict whether someone is gay, based on otherwise innocuous information on facebook.

Here’s how it works, via The Boston Globe:

Jernigan and Mistree downloaded data from the Facebook network, choosing as their sample people who had joined the MIT network and were in the classes 2007-2011 or graduate students. They were interested in three things people frequently fill in on their social network profile: their gender, a category called “interested in” that they took to denote sexuality, and their friend links.

Using that information, they “trained” their computer program, analyzing the friend links of 1,544 men who said they were straight, 21 who said they were bisexual, and 33 who said they were gay. Gay men had proportionally more gay friends than straight men, giving the computer program a way to infer a person’s sexuality based on their friends.

Then they did the same analysis on 947 men who did not report their sexuality. Although the researchers had no way to confirm the analysis with scientific rigor, they used their private knowledge of 10 people in the network who were gay but did not declare it on their Facebook page as a simple check. They found all 10 people were predicted to be gay by the program. The analysis seemed to work in identifying gay men, but the same technique was not as successful with bisexual men or women, or lesbians.

Interesting. So that raises the question of whether Facebook then allows advertisers – like Atlantis Cruises – to specifically target the LGBT community.

Surprisingly, the short answer is no. The longer answer, via Slate, is this:

When companies advertise on Facebook, they're allowed to choose a range of demographic characteristics that determine which people see their ads. It's possible that Atlantis didn't choose to limit its ads just to gay people but, say, to all single men under 40 who live near San Francisco. This way the company gets to people like you—folks who aren't out on Facebook but who might still be in the gay-cruise demographic.

The Facebook rep added a couple other points: Ads aren't selected based on groups you've joined or based on your friends. You weren't shown the gay-cruise ad because your friends are gay or because you became a fan of the group "No on Prop 8," for instance.

But there is one caveat: If a friend of yours presses "Like" on an ad, Facebook will show you the ad, too, plus a note saying which of your friends liked it. The company also uses the "Like" feature to determine which ads to show you in the future.

Saturday, November 7, 2009

What does Google know about you?

Google reminded us again this week of exactly how much it knows about us all, when it unveiled Google Dashboard.

Dashboard is a nifty tool that shows you all the information Google has on you. Well, maybe not all, but some. Or maybe just a sliver.

You can get to Google Dashboard through a link in the “personal settings” section the “my account” page. According to the Google Systems Blog:

The dashboard lists some of the information associated with the Google services you use: your name, your email address, the number of contacts, the number of conversations in your Gmail inbox, your Google profile, the most recent entries from the web history etc.

It's a long answer to the question: "What does Google know about me?".

Yeah, except it really doesn’t answer that question at all, according to many. Google knows a lot more about you than that. Of course they know your email address and Gmail history. But what they’re not telling you is what they know about server logs, cookies and internet-based advertising systems that pull various pieces of data about all of us.

Dashboard is a good step in the direction of transparency and reinforcing a level of trust among Google users. But this service raises more questions than it answers and it will be interesting to see how high Google is willing to raise the curtain on the data they keep.

Incidentally, all these links track back to Google. Think they know that? Probably – but they won’t tell you.

Tuesday, November 3, 2009

Parenting in the Digital Age

I’ve posted before about my four-year-old niece. She can use the computer, she can navigate the cable box and she’s comfortable with a cell phone. But the scary part is none of this is extraordinary for her – it’s just part of life.

WIRED’s Geek Dad blog takes on this topic in a recent post about how to raise an internet-savvy kid:

When I was growing up, getting a phone in your room (or even your own line!), if you were fortunate enough, was a major step in the process between feeling like a child and growing into an adult. Like driving your own car or getting your own bank account, getting your own phone was a step towards independence and a nexus moment between a trusting parent and a maturing child. Today, the phone is no longer even the standard communication method between two 13-year-olds. E-mail, IM and social networks are the most common forms of communication between teens and new studies have shown that Generation Y is becoming increasingly reliant on e-mail as their preferred form of communication. This means kids are growing up to become even more reliant on the internet and technology in their lives.

So what is the right age to let your kids get online? Obviously it’s a moving a target, but perhaps Billy Ray should have had a chat with Miley, before she dove head-first into Twitter.

The full post is worth a read. Check it out here.

Monday, November 2, 2009

No on 1; Yes on Disclosure

There is a time and place for everything – even privacy.

Cloaked behind a veil of secrecy, the National Organization for Marriage (NOM), a NJ-based anti-LGBT hate group, has been leading the fight in Maine to repeal that states same-sex marriage law.

This past week, according to the Portland Press Herald, a federal judge “ruled that Maine's reporting requirements for ballot question campaigns do not violate the First Amendment of the U.S. Constitution” and that NOM must disclose its donor list.

"Maine is entitled to conclude that its electorate needs to know, on an ongoing basis, the source of financial support for those who are taking positions on a ballot initiative," wrote Judge D. Brock Hornby in his ruling.

While this issue doesn’t stem from the digital domain, any issue of privacy has online implications. Last year, a California court ruled “Yes on 8” donors must be made public, and that information was quickly used by gay marriage supporters, mapping contributors and boycotting businesses.

Maine’s citizens will vote on the law this Tuesday on Ballot Question 1. Voting no preserves the state's gay marriage laws. If you are in Maine, please vote NO.

Saturday, October 31, 2009

Facebook continues its tightrope walk

Long plagued by issues of digital privacy, Facebook continues to navigate the fine line between protecting its users personal data and maintaining a profitable, ad-based business model. This past week, Facebook tried to appease both sides of the argument – those pesky, privacy-demanding users, and the oh-so attractive big-money advertisers.

In a blog post on the site, Facebook’s vice president of communications and public policy, Austin Haugen announced that the company was making its privacy policy open for review and comment – the same way solicited user feedback on its statement on rights and responsibilities in February.

He said, “Our primary goals remain transparency and readability, which is why we've used plain language and included numerous examples to help illustrate our points.”

According to InternetNews.com:

The controversy that set the democratic process in motion at the beginning of the year stemmed from concerns that Facebook was asserting perpetual control over its users' information and content, even after they deleted their account.

In response, Facebook has stated unequivocally that users own their own data, and further fleshed out its position on the ownership issue with the privacy policy released today.

Haugen’s blog post continues on with a detailed and straightforward explanation of how user information is used and the differences between deleting and deactivating an account – and the privacy implications with each – as well as how it collects and leverages user data with its online advertising.

And at the same time, Facebook was standing up for the little guy and offering a shade more transparency, simultaneously, it unveiled a “roadmap” for developers and to create and implement applications to tap into the FB user base.

According to MediaPost: Among the key updates in store, Facebook will enable developers to ask for users' primary email address within applications to facilitate direct contact. At the same time, developers will only be able to send notifications and invitations via email, a user's Facebook Inbox or the News Feed and other activity streams.

But Haugen addressed this in his blog post, saying “Keep in mind that applications will never be given your email address unless you explicitly grant them permission, and like other websites you can always choose to unsubscribe if the service is no longer of value.”

Facebook is certainly chasing a moving target, as the web develops and people become more savvy about internet privacy. But it sounds like they’re continuing to walk the tightrope for now.

Monday, October 26, 2009

Digital Stranger Danger

I’m no Annie Leibovitz, but I know my way around a camera and I make pretty good use of Flickr, one of the leading photo sharing sites on the Web.

As a sharing and networking platform, Flickr is pretty amazing. It’s a great source for feedback and inspiration on your photos – and I’ve even sold a few of my images. But every now and then, it’s a little disconcerting to realize how open all your images are to the reset of the world.

Flickr offers varying levels of privacy and copyright settings, but any fifth grader can figure out how to pull an otherwise “protected” image from the Internet. I’ve even pulled a few for work and school projects. But it wasn’t until Gothamist nabbed a photo of mine that it really hit home.

It really makes you think about what you post on the Web. Especially when it comes to friends, family and colleagues.

We’ve all heard about the hazards of posting photos of yourself from last night’s bender on Facebook. I think we all get the idea of erring on the side of prudence with that sort of thing.

But now as I get older and friends start to get married, I’m starting to see more and more friends posting innocent and sometimes painfully cute photos of their kids online. Thanks for sharing, but have you thought it through?

Yesterday, the New York Times explored the varying points of view on posting kids’ photos online. Mostly, they agreed on one thing – no bathtub photos – but that’s about it.

Many parents view issues of Web privacy are simply a modern reality that they need to accept and live with. One mom said “Hundreds of kids die in swimming pools every year, but we don’t shut down all the pools.”

Still others keep their kids on digital lock-down. A mother, so paranoid about privacy that she wouldn’t even give her name for the Times piece, recently caused an awkward situation with a friend who posted a picture of her son on Facebook.

Maybe there’s a happy medium between the total laissez-faire and witness protection approaches.

According to the Times: Regardless of what danger may come to your children by posting pictures, there is one hazard whose existence no one can question: other parents. And their wrath could be enough to make anyone think twice before posting photos of little Charlie’s fourth birthday party.

I think about my own four-year-old niece. She’s a photogenic little girl who already has a bigger digital footprint than many of my friends. Should we be worried about her online privacy? Maybe.

Are we over-thinking this a bit? According to some, we are. Via the Times:

Prof. David Finkelhor, director of the Crimes Against Children Research Center at the University of New Hampshire, says TV shows like the “Dateline NBC” program, “To Catch a Predator,” have falsely inflated the danger of the Internet.

“Research shows that there is virtually no risk of pedophiles coming to get kids because they found them online,” said Stephen Balkam, chief executive of the Family Online Safety Institute. While the debate makes this crime seem common, he said, all the talk is really just “techno-panic.”

My sense is there’s always going to be danger for kids, and it’s the parents’ responsibility to help navigate and educate according to what’s appropriate for the individual child. Looking back, there was always that one mom who couldn’t let their kid go to the mall without a chaperone – and that one who barely knew where their kid was. It’s the same here – just online.

Sunday, October 25, 2009

Time Warner leaves 64,000 customers vulnerable

It’s pretty impressive that Time Warner Cable manages to provide universally dismal service and yet stays in business. Yay cable monopoly!

From their laughable customer support to the dysfunctional cable boxes, TWC is really one of the most hateable companies. And here’s just one more reason: A “gaping” security hole in their cable modem routers left approximately 64,000 homes wide open to cyber attack.

The hole was discovered by David Chen, who blogs at Chenasaurus, when he was doing work on his friend’s modem.

Chen writes: From within your own network, an intruder can eavesdrop on sensitive data being sent over the Internet and even worse, they can manipulate the DNS address to point trusted sites to malicious servers to perform man-in-the-middle attacks. Someone skilled enough can possibly even modify and install a new firmware onto the router, which can then automatically scan and infect other routers automatically.

He said he called Time Warner to report the problem, to which they said “we are aware of it but we cannot do anything about it.” CNN says there’s a temporary patch in place until the cable company can come up with a permanent solution.

Ummm … Thanks TWC.

Wednesday, October 21, 2009

Kanye West is not dead

Several reports today confirmed that Kanye West is not dead. Yay?

While rumors surrounding his death circulated through Facebook and Twitter, fake news sites with reports of the singer’s demise quickly sprouted up, appearing on Web searches and ultimately infecting searchers computers with malware.

According to The Toronto Star: Using search-engine optimization, the hackers pushed Web pages claiming to have information about West's "death" to the top of search engines. When worried fans clicked on the pages, their computers would be infected with fake anti-virus software.

For better or worse, Kanye’s alive (sorry Taylor). Regardless, as Counter Measures blogger Rik Ferguson points out, this showcases how quickly criminals can capitalize on Internet memes. Kinda crazy.

Tuesday, October 20, 2009

I will not be a statistic! Um, unless theres's a discount ...

A few weeks ago, I posted about a recent study from UPenn and UC Berkley that found nearly 70 of Americans oppose being tracked online by advertisers – among other findings.

This past weekend, NPR’s “On the Media” featured a great interview Joseph Turow, lead author of the study and professor of communication at the Annenberg School for Communications at the University of Pennsylvania.

In his conversation with Bob Garfield, Turow sums up his findings:

What the public is concerned about is that the pictures that advertisers draw about you are becoming more and more vivid, and whether or not they have pictures that you would agree with is a really big question. So I think the issue here is how much do people know about what’s going on, and do they have any control over it?

So, for example, if you get an ad, say, from NewYorkTimes.com and it’s tailored to you, it would be great if there were a way that you could know, a) that’s it tailored for you, b) where did they get those data from, c) how does it fit into a larger picture of you that that advertiser or that periodical has? And can you do anything about it?

But what people don’t realize is that advertisers have been doing this for years in the off-line world. Just look at the example of zoned newspaper editions. The NY Times sells a different version of the paper in the North East versus the Mid West. As Garfield points out, the digital world just amplifies the scope of what advertisers can do – analyzing the data “a batrillion ways.”

The funny thing though, is that supermarkets have more data on you than most websites according to Turow. It’s not just a loyalty play, but every time you use a discount card they grab a little more data about your purchase behavior in exchange for a few pennies. And as megastores grow in popularity, many more of us consolidate our shopping experience in one place. Now Wal-Mart can track how you buys groceries, clothing, prescriptions and even how you bank . But still we shop, swiping our club cards and dropping bits of data along the way.

Worth it? Maybe. Duane Reade gives me $5 back for every $100 I spend (which happens way too often). I’m OK if they know what kind of toothpaste I use as long as I get a little something out of the deal.

So the question we come back to is: How much is your privacy worth? A few cents off deodorant, a little extra browser functionality?

As we get savvier about online (and off-line) data collection, it’s a question we’re going to face more and more. For me, like any good communications person, my answer is “it depends.” It depends on how the data is collected – are they just taking it, or did they ask my permission? It depends on what it’s used for – obviously I know it’s used to market at me, but my data be given out? And it depends on what’s in it for me – don’t just take data from me, but give me something back.

Time will tell, but as we move further into the digital future people will become more savvy and less sensitive about data collection and what they allow be collected. We’ll see.

Sunday, October 18, 2009

NYT: Medical Records No Safer than Movie Rental Info

What do Netflix and your health insurer have in common? More than you might think, according to an article in yesterday’s New York Times.

For starters, both collect personal data about, like your name, address, phone number, credit information, payment history, purchase behavior and preferences.

And both strip personally identifiable information from these records, which are then sold to researchers and marketers to ultimately better understand and target you as a consumer.

While that may be a little creepy, it’s nothing out of the ordinary and totally legal. But, according to researchers at the University of Texas at Austin, it is possible to re-identify individuals associated with the data based on otherwise innocuous information we all leave around the web – like chat logs, Twitter feeds, online comments and blogs.

Similar to a scam artist rummaging through your trash for bank statements you thought you destroyed, researchers say that your online footprint can aid in re-identifying information that is otherwise scrambled and scrubbed.

And while it might just be a little embarrassing for your Netflix history to get out (What do you mean you rented Another Gay Movie?), health records carry heavier implications and could cause irreparable “social, professional and financial harm,” according to the Times.

The scary thing is that there’s really nothing protecting the consumer at this point. If companies scramble and de-personalize your data, they’re in the clear to use it however they want. And it’s big business.

According to George Hill, an analyst at Leerink Swann, a health care investment bank, the clinical information market represents $8-10 billion in sales annually.

Yet while there are no safeguards to prevent reverse-identification of consumer data, the risk is evident.

According to the times: In 1997, for example, a researcher identified the medical records of William Weld, then the governor of Massachusetts, by correlating birthdays, ZIP codes and gender in voter registration rolls and information published by the state’s government insurance commission.

In the Times article, Dr. Deborah Peel, director of a Texas-based watchdog group, likened consumer risk to the Paris Hilton Sex Tape: “Once personal health data gets out there … it is going to be out there forever.”

Saturday, October 17, 2009

A Just Death: Act To Prevent Predatory Marketing Practices against Minors

Claiming that it violated the First Amendment, companies like Yahoo!, AOL, eBay (disclosure: client), and News Corp. as well as the Association of National Advertisers, the Motion Picture Association of America and the civil liberties advocacy group Center for Democracy & Technology, yesterday convinced the Maine legislature to repeal an act designed to protect minors from aggressive data collection.

What sounded like a great idea to protect children was doomed from the start though. According to the Wall Street Journal, Maine’s attorney general decided not to enforce the law even before it was scheduled to go into effect, with the understanding that minors under 13 were already protected by the Children’s Online Privacy Protection Act.

While applauding the law’s intent, the committee determined that the “Act To Prevent Predatory Marketing Practices against Minors” was too broad and limiting – and could affect whether major companies do business in the state.

According to MediaPost, the law “prohibits companies from knowingly collecting personal information or health-related information from minors under 18 without their parents' consent.”

In theory that’s great, but there are some major pitfalls.

According to the WSJ:

In the complaint, the Maine Independent Colleges Association, for example, protested that the law would prevent Maine colleges from sending marketing materials to minors who requested information without first obtaining parental consent.

And according to MediaPost:

[Opponents] argued that the law could result in companies like Something Fishy -- which offers an online forum where teens discuss eating disorders. Something Fishy appears to violate the Maine law because it allows minors under 18 to register and participate without parental permission.

According to the AP (me), Maine’s lawmakers got it right on this one. But again, this showcases how society needs to keep an open mind to all sides as we move ahead in the digital future.

Photo via MediaPost

Wednesday, October 7, 2009

Cloud Computing: A cautionary tale

It was revealed last week that hackers had stolen sensitive account information from a major online payroll processing company to directly target its customers.

PayChoice, a company that provides online payroll tools to over 125,000 organizations and back-end support to 250 other payroll companies, was breached. Hackers emailed PayChoices customers directly with detailed information about their accounts to coerce them into giving up their passwords.

According to the Washington Post: Unlike typical so-called "phishing" scams -- which are sent indiscriminately to large numbers of people in the hopes that some percentage of recipients are customers of the targeted institution -- this attack addressed PayChoice customers by name in the body of the message. The missives also included reference to each recipient's onlineemployer.com user name and a portion of his or her password for the site.

PayChoice is taking appropriate steps to understand what happened and to correct any issues caused. Nevertheless, this serves as a cautionary tale as we move further down the road to decentralized cloud computing.

Monday, October 5, 2009

How much should the Government Control the Internet?

Last week, the Associated Press explored the issue of how much the U.S. Government should control the Internet.

Similar to how planes were ordered grounded after 9/11, should the President be able to hit the kill-switch on the Internet if there is a catastrophic online attack?

According to the AP (lol), “At least 18 bills have been introduced as Congress works carefully to give federal authorities the power to protect the country in the event of a massive cyberattack. Lawmakers do not want to violate personal and corporate privacy or squelching innovation. All involved acknowledge it isn't going to be easy.”

Wednesday, September 30, 2009

Riding the Wave

Google is riding the wave of world domination with its next product launch ... uh ... Google Wave, which is billed as an online portal that blends email, instant messaging, social networking and workplace collaboration in a single application.

Wave was first debuted in May, and according to C-Net is set to be rolled out to a much wider test audience today.

Tech geeks apparently had their minds blown when they first saw the application a few months back.

Again, according to C-Net, developers “compared Wave to how Google Maps (perhaps not coincidentally developed by the same people behind Google Wave) awoke developers to the possibilities presented by Ajax technologies, which had been around for some time but had yet to gain traction as some of the core technologies used to build the modern Web.”

So again, the question is what is your privacy worth? Can Google have just a little more information in exchange for some more personal data? Broadly, I’d be OK with it. Wondering what all five of my readers think.

Tuesday, September 29, 2009

Obama's got his Head in the Clouds

It’s a little startling, but I hardly know where any of my files are. I know how to get them, and I’m pretty confident they’re secure. But truly, I have no clue where much of my information is actually stored.

My company just moved offices. Before we did, I sat near the company’s servers where all our digital files were saved. Now our servers are “off-site” – wherever that is – and everything is available through a slightly clunky web-based system.

And it’s the same story with my personal life. I’m a heavy user of Google Docs, Gmail, etc. I have family photos, class papers, insurance documents, loan information saved … somewhere. Where? Not sure.

Without realizing it, I’ve fallen into cloud computing and it’s pretty great. I can get nearly any file mostly anywhere. Traveling, working from home, on my iPhone – virtually everything I need is accessible with little more than a password.

As with anything there are advocates and opponents from the cloud computing idea. The pro-cloud community hails it as the future of computing, increasing users’ online productivity, ability and agility. Opponents see it as, among other things, a vulnerable computing process ripe for data theft.

Perhaps both sides are right. It’s a great new tech advancement with certain vulnerabilities that need to be addressed. As a standard consumer with average computing needs, I’m OK with that.

Nevertheless, even while online privacy advocacy groups like the Electronic Privacy Information Center (EPIC) are pressing for an FTC investigation into the safety of cloud computing, the Federal government launched Apps.gov, a website where federal agencies can access “cloud-based” IT services.

While EPIC doesn’t necessarily oppose cloud computing, it claims that Apps.gov – and really cloud computing as a concept – doesn’t adequately address issues of privacy and security, leaving sensitive information about citizens and the government vulnerable.

It’s a debate that will go on for a while, but it’s nice to see the first president to have a Blackberry is jumping into Web 2.0 – although, hopefully, with the appropriate level of caution.