Tag: privacy

  • The US Government finally put an End to Phone Records Collection Program

    The US Government finally put an End to Phone Records Collection Program

    Yesterday marked the end of NSA’s program to collect bulk phone records in the United States. Advocates all over the world questioned the The US government fairness about surveillance technology and started pushing for privacy since former NSA contractor Edward Snowden exposed the program to journalists 2 years ago.

    The masses gained the government attention earlier this year with Congress passing the USA Freedom Act. But in light of the terror attacks that rocked Paris earlier this month, many hawkish lawmakers have attempted to hold off on shutting it down.

    Reports reaching us says that the Office of the Director of National Intelligence announced on Sunday that the program shut down as scheduled.

    As the program finally came to its ultimate doom, privacy advocates took a victory lap on Monday. Here are those hot takes.

    Senator Ron Wyden of Oregon wrote:

    “This program’s very existence was concealed from the American public for over a decade.  Across two administrations, senior officials from US intelligence agencies and the Justice Department repeatedly made false and misleading statements that concealed the truth about what they were doing.  These officials relied on a secret body of law to justify the mass surveillance of the American people. Fortunately, in America sooner or later the truth always comes out.  When Americans found out about this secret, unconstitutional surveillance two years ago, they were rightfully outraged.  And they made their voices heard.  The result was historic reform legislation that required the government to shut this program down.”

    Senator Mike Lee said:

    “Today both the safety and Constitutional rights of American citizens are more secure thanks to the USA Freedom Act. Not only did the USA Freedom Act strengthen the Fourth Amendment rights of all Americans by ending the bulk collection of personal data, but it also better ensured national security by closing a loophole that prevented the government from tracking foreign terrorists once they entered the United States.”

    Members of the House of Representatives also reiterated their support of the law. Bob Goodlatte, John Conyers, Jim Sensenbrenner and Jerrold Nadler issued the following statement:

    “The implementation of the USA Freedom Act represents government at its best: it is the product of a robust public debate and intense bipartisan negotiations dedicated to finding a way to protect our Constitutional rights while enhancing the safety of our country. The bipartisan law ends the bulk collection of telephone metadata once and for all, enhances civil liberties protections, increases transparency for both American businesses and the government, and provides national security officials targeted tools to keep America safe.”

    The implementation of the Freedom Act highlights that in a government marked by gridlock, there have been many major policy decisions that impact the tech industry from Washington this year. After little happened for the industry last year, 2015 brought significant reforms to the government surveillance and made net neutrality the law of the land.

  • Facebook is facing a law suit. Reason? Scanning user’s Messages

    Facebook is facing a law suit. Reason? Scanning user’s Messages

    From the revelation that Facebook scans through its user’s messages to deliver “tailored” ads, a U.S. judge has ruled that they must face a class-action lawsuit. Facebook’s bid to dismiss the lawsuit, filed by users Matthew Campbell and Micheal Hurley back in 2013, was dismissed by U.S. District Judge Phyllis Hamilton in Oakland. According to the details of the suit, until October 2012, when Facebook had said they stopped the practice, the large social networking company was scanning through user’s private messages for website URLs. This information was then used to deliver tailored advertisements to the user. By doing so, Facebook violated the federal and state privacy laws, which they broke by reading their users’ personal and private Facebook messages without their consent.

    Facebook had shown that the Electronic Communications Privacy Act covered the practice to the district court. The social networking giant also stated that it discloses to all users that the company might use the information they receive from the users about them for data analysis.
    However, Judge Hamilton wasn’t satisfied with Facebook’s explanation. She stated that Facebook had not offered a sufficient explanation of how the challenged practice falls within the ordinary court of business. She also added that the disclosure wasn’t specific enough to establish that users expressly consented to the scanning of the content of their messages.
    Facebook’s unwillingness to offer any details regarding its targeted advertising practice prevents the court from being able to determine whether the specific practice challenged in this case should be considered ‘ordinary,’” added Judge Hamilton.

    Facebook is continuing to stay silent on any comments about the case.
    Google is also under the hammer for the same message-scanning practices, though they aren’t facing a class-action suit like Facebook. Many experts in the field believe that the result of both of the lawsuits will have a major impact on how we use technology to communicate in the future.

  • Will our privacy problems be solved by 2025? Responses released in Pew study

    Will our privacy problems be solved by 2025? Responses released in Pew study

    As more innovators and tech gurus crawl into the ever-growing technology and internet market, the concern between users and their privacy online become more and more dominant. According to a Pew Research Center study, policymakers and tech innovators will have a hard time to respond.

    Experts responded to a survey with split opinions on the matter that politicians and tech innovators can create “secure, popularly accepted, and trusted privacy-rights infrastructure by 2025 that allows for business innovation and monetization,” while offering people accessible options for protecting their personal info.

    Looking at the results of the survey, about 55% of the 2,511 people surveyed said they believed a accepted privacy-rights infrastructure would exist in the next decade. The other 45% said it would, however. Regardless to the surveyed thoughts on the future of online privacy, many had agreed that online life is public nature.

    Almost everybody agrees this new environment is coming,” said Lee Rainie, co-author of the study. “About half say we will make accommodations and about half say it’s an inexorable blob that will swallow people’s lives…and leave people in an environment where they have little control over their privacy.”

    Pew’s survey uncovered common threads among responses; many experts agreed that security and privacy are “foundational issues of the digital world” and that people don’t require much more than the draw of convenience to share their personal information.

    “Lack of concern about privacy stems from complacency because most people’s life experiences teach them that revealing their private information allows commercial (and public) organisations to make their lives easier (by targeting their needs), whereas the detrimental cases tend to be very serious but relatively rare,” Bob Briscoe, chief researcher in networking and infrastructure for British Telecom, wrote in his response.

    We are living in an unprecedented age of surveillance, said John Wilbanks, chief commons officer for the biomedical research company Sage Bionetworks.

    I do not think 10 years is long enough for policymakers to change the way they make policy to keep up with the rate of technological progress. We have never had ubiquitous surveillance before, much less a form of ubiquitous surveillance that emerges primarily from voluntary (if market-obscured) choices,” he said.

    What does this mean for the media, which often relies on targeted ads mined from readers’ personal data? The widespread use of personalized ads is a fait accompli, Rainie said. They aren’t going anywhere.

    People don’t freak out now when they see ads that they see on other sites, or ads related to things they search for,” he said. “What experts would say is it’s a settled issue, not a top-of-mind problem.”

    The tricky part is figuring out “the Internet of things,” Rainie added, and adapting to future changes in the display and rendering of information.

    And social and cultural norms are ever-changing, said Homero Gil de Zuniga, director of the Digital Media Research Program at the University of Texas-Austin. That includes perceptions of privacy.
    “By 2025, many of the issues, behaviors, and information we consider to be private today will not be so,” he told Pew. “Information will be even more pervasive, even more liquid, and portable. The digital private sphere, as well as the digital public sphere, will most likely completely overlap.

    What do you think of the idea of still not having an accepted, private-rights infrastructure by the next decade? Leave a comment below with your thoughts.

    sources:
    latimes.com

  • Basic Privacy Tips for Internet & Social Media

    Basic Privacy Tips for Internet & Social Media

    PC WORLD – Recent headlines about shadowy government agencies, high-profile hack attacks, and your face in Google ads drive home a crucial point: Your online privacy is best protected when you keep an iron grip on the information you’re handing out. If your info is on a server somewhere, it’s not truly yours.

    So many core aspects of our lives have shifted to the cloud, mostly to our great benefit: Gmail and Outlook.com maintain our email archives. Dropbox and SkyDrive make your files available anywhere, anytime. Windows 8.1 searches include Bing results by default. Google Now dishes out the information you need before you even know you need it.

    But every gain in convenience comes with a loss of control, and that loss of control all too often comes bundled with privacy or security woes.

    You can take some simple precautions to minimize the amount of personal information that you have online. But before we get started, remember that this data checkup is about what you’re comfortable with. You could follow all the tips in this post, tighten up on just a few of the practices mentioned below, or go even farther down the rabbit hole than the suggestions offered here. Digital privacy is not a zero-sum or a one-size-fits-all proposition. If nothing else, this article can help you make better decisions about the information you share with the services you love.

    Giving Google the cold shoulder

    When it comes to minimizing your digital footprint, we have to start with Google. Just imagine the dossier the company has on you: search history, sites you visit, Google Play purchases, location data from Android and Chrome and Maps, your Google Drive documents…it looks like a lot when it’s all spelled out like that, doesn’t it?
    To its credit, Google takes data security seriously, receiving fairly good marks in the Electronic Frontier Foundation’s annual “Who has your back?” survey. But Google also makes heavy in-house use of your data, a point that touched a nerve with announcements of the company’s plans to use your real name and face in online advertising (not to mention Microsoft’s “Scroogled” campaign).
    Divorcing Google isn’t a realistic option for most people, though, given its superior services and sheer ubiquity. Switching to Microsoft’s services still leaves your information in the cloud. So what can you do if you want to reduce the amount of data you’re sharing with either online monolith?
    Firefox’s private browsing mode kills cookies dead.
    To start, you can keep Google from collecting and sharing your data as much as possible. Using your browser’s private/incognito mode will erase tracking cookies, including Google’s, when you close it. You can also tell Google to stop trailing you in your account’s Web History page (at the expense of Google Now features) and take a minute to tweak your general Google privacy settings.
    Another solution is to replace what Google services you can with more private alternatives. Do you use Google Docs but don’t really need its online capabilities? Try the open-source Libre Office suite. If you need only basic image-editing capabilities, skip Picasa and stick to Paint.net. What about Google Drive’s on-the-go docs? We’ll talk more about cloud storage later.
    And if you can cut the Google cord completely, there’s always the nuclear option. (Here’s how to shutter your Microsoft account for good measure.)

    Facebook

    Google may have a wide reach, but when it comes to mapping your social connections, no company knows more than Facebook. And just like Google, Facebook is practically impossible to shut out of your life. You need it to sign in to your favorite services, play games, chat, and keep in touch with pals.
    Tweaking your Facebook profile’s privacy settings can keep other people’s eyes at bay—but Facebook itself has a reputation for questionable user data decisions. How to give Zuck the cold shoulder without divorcing Facebook completely?
    You don’t want to be among the first Graph Search results for “Males in New York that like Drugs and Marijuana” or anything similar. Mind those Likes, and those privacy preferences.
    Easy: Stop hitting that “Like” button so much and consider removing past thumbs-ups. Don’t add extra information to your profile such as life events, places you’ve lived, and so on. (Below’s a video on deleting life events.)
    Finally, decide whether you want to continue sharing your photo library online. Is anybody really looking at them, or are they just fodder for Facebook’s face-detection algorithms?
    Facebook also tracks you as you travel from site to site, using the Like buttons embedded on each. Make sure you’re signed out of Facebook to prevent that from happening, or use your browser’s private mode.
    You can delete your Facebook account if you’re able (and willing) to cut the socialite cord completely.

    Cloud storage

    If you slap your files in a cloud-storage locker for anytime, anywhere access, you probably don’t want to give up that convenience. You can, however, seize control of your cloud documents by encrypting them, which helps protect against the data breaches (such as two that happened to Dropbox and Apple) and government information requests faced by many cloud providers.
    Note that while many services (such as Dropbox) encrypt your data on their servers, they control the encryption keys in most cases. That means you are not in control of when or for whom that encrypted data is unlocked, but it also makes using the service easier—just enter your login information and go!
    A truly “zero-knowledge” cloud provider such as SpiderOak or Wuala, on the other hand, never has access to your encryption key, meaning that only you can unlock your data. (Don’t lose the key!) Alternatively, you could manually encrypt files bound for SkyDrive, Google Drive, Dropbox, SugarSync, or any other cloud service, using a tool like TrueCrypt or the cloud-focused BoxCryptor.
    Western Digital’s My Cloud connected storage drive lets you build your own private cloud.
    Or, if you want anytime, anywhere access to your files but don’t want to entrust your stuff to anyone else, you could use a Net-connected storage drive like Western Digital’s My Cloud to create your own personal cloud-storage solution.

    All the rest

    We’ve taken care of your major online accounts, but what about all those random accounts you have connected to your social networks? Go through the settings of your Facebook, Twitter, and Google+ accounts to see the list of apps and services connected to them. Then simply remove access permissions for the ones you no longer use.
    Speaking of apps and services, part of good data hygiene is regularly deleting accounts you’ve left by the wayside. Go ahead: Close that MySpace profile and kill your Klout score if you’re not using them.

    The tip of the iceberg

    Now that you have at least some of your data under control, you could look at numerous other things, as well.
    We briefly touched on restricting who can track your browsing while online. For a real eye-opener, try using Abine’s DoNotTrackMe add-on for a week and see how many tracking cookies the add-on blocks. You could also use a stand-alone email program configured using the POP3 protocol to save your email locally and wipe your messages from your provider’s servers. (Here’s the info you need to do just that with Outlook.com, Gmail, and Mozilla’s Thunderbird client.)
    For an even more comprehensive look at the topic, check out Macworld’s seven-part series on protecting your online privacy—but note that some of the tips apply only to Apple’s ecosystem.
    Going off-grid online is borderline impossible these days, but taking just a short time to tidy up your online footprint can pay big dividends for your security and your privacy. And remember: It’s up to you just how far down the rabbit hole you go. Happy deleting!
  • Storify explains Facebook privacy more illusion than fact

    Storify explains Facebook privacy more illusion than fact

    A chicken wing gets hot when you turn it on A dustup over the republication of private Facebook status updates on Storify points to how privacy on the social network is relative and users must remain vigilant to avoid getting burned.
    The online controversy started Friday when the business news site AGBeat reported that a person using Strorify’s Chrome browser extension or bookmarklet could essentially copy and paste private Facebook content.
    Storify is a tool for stringing together photos, videos and status updates from socialnetworks. The site is popular with bloggers and journalists.
    Whatever Facebook content a person has access to can be republished on Storify. This means that private status updates from personal profiles and private groups can be copied. The ability of third-party sites or apps to breach Facebook privacy has been a concern for sometime.
    In its 2012 State of the Net report, Consumer Reports warned that Facebook data is shared more widely than users may wish. “Even if you have restricted your information to be seen by friends only, a friend who is using a Facebook app could allow your data to be transferred to a third party without your knowledge,” the consumer watchdog group said.

    Facebook compares Storify to someone taking a screenshot of a post and then republishing it somewhere else on the Web. On Monday, the social network seemed to distance itself from the controversy, implying that the person copying the information has the responsibility for not sharing their friends’ private updates.
    “The behavior appears to result from Storify users utilizing a browser extension that essentially cuts and pastes content available to that user to the Storify site,” a Facebook spokesperson said in an email. “This is not a result of the Storify application for Facebook.”
    Storify washed its hands of the controversy, saying the site does not give people access to content on the Web they would not already be able to see.
    “By using our bookmarklet or Chrome browser plugin, you can indeed collect text, photos and video from all around the Web, including what is visible to you on Facebook,” Storify co-founder Burt Herman said in a blog post. “That media may not have been intended for a wider audience, but it’s up to you if you want to publish it more widely.”
    This passing of the buck to users is an example of why privacy advocates want even tougher privacy restrictions on Facebook than what is contained in a settlement the site reached with the Federal Trade Commission last year. The agreement requires Facebook to create a comprehensive privacy program and to have independent audits of its privacy practices conducted every two years.
    Some privacy advocates also want Facebook to provide full access to all data collected on a user, stop creating facial recognition profiles without user consent and cease tracking users across the Web.
    Consumers Union, which publishes Consumer Reports magazine, supports a national privacy law that would hold all companies to the same standards.
    In the meantime, privacy advocates recommend maximizing privacy settings and to always assume that anything posted on Facebook can be seen by friends, family, employers, government agencies, health insurance companies and law enforcement.  

  • Twitter flop gave third-party apps unauthorized access to private messages

    Twitter flop gave third-party apps unauthorized access to private messages

    Users who signed into third-party Web or mobile applications using their Twitter accounts might have given those applications access to their Twitter private “direct” messages without knowing it, according to Cesar Cerrudo, the chief technology officer of security consultancy firm IOActive.
    The issue is the result of a flaw in Twitter’s API (application programming interface) that led to users not being properly informed about what permissions an application will have on their accounts once granted access. Cerrudo described the problem and explained how he discovered it in a blog post published Tuesday.
    Applications that allow users to log in with their Twitter accounts have to be registered with Twitter at https://dev.twitter.com/apps. During registration, their developers have to declare the level of access the applications will have on people’s accounts: “read only,” “read and write” or “read, write and access to direct messages.”

    When users attempt to log into such an application for the first time using their Twitter accounts, they get redirected to an authorization page on Twitter’s website that lists the permissions requested by the particular application.
    Cerrudo said that he discovered the issue while he was testing an application developed by a friend that had a “read, write and access to direct messages” permission declared with Twitter.
    When he first signed into the application with his Twitter account, he was redirected to an authorization page that informed him that the application would be able to read tweets from his timeline, see which users he follows, follow new users on his behalf, update his profile information and post tweets on his behalf, he said. The page clearly noted that the application would not be able to access direct messages or the account’s password.
    “After viewing the displayed web page, I trusted that Twitter would not give the application access to my password and direct messages,” he wrote on the blog. “I felt that my account was safe, so I signed in and played with the application.”
    The researcher noticed that the application had functionality to access and display direct messages, but the feature didn’t appear to be working. This made sense because he hadn’t been asked to grant that permission.
    However, after signing in and out of the application and Twitter a few times, his direct messages started appearing in the application. When checking the list of applications authorized to interact with his Twitter account (Settings > Apps) he noticed that the application did in fact have the read, write, and access direct messages permissions.
    “I realized that this was a huge security hole,” Cerrudo said.
    The researcher confirmed Tuesday that he successfully reproduced the behavior several times by revoking access to the app and going through the authorization process again without being warned that the app would be able to read his private messages. The issue was reported to Twitter on Jan. 16 and was addressed in less than 24 hours, he said.
    “They said the issue occurred due to complex code and incorrect assumptions and validations,” Cerrudo said in the blog post.
    However, Twitter’s fix does not seem to apply retroactively. After Twitter fixed the issue, the app Cerrudo was testing that already had access to his account continued to display direct messages despite never receiving authorization from him to do so, he said.
    Twitter users should check if any of the apps they authorized in the past also gained access to their direct messages without their knowledge, Cerrudo said. This can be done by reviewing their permissions on the Twitter Settings > Apps
    page.
    Cerrudo decided to make this issue public because it can have serious implications and because Twitter did not issue a public advisory or announcement about it. The company should maintain a dedicated page where it can inform users about security issues, he said.
    Twitter did not immediately respond to a request for comment.

  • Facebook’s Recommendations Bar: A Privacy Concern?

    Facebook’s Recommendations Bar: A Privacy Concern?

    Facebook has rolled out a new feature called the Recommendations Bar for website owners. The Recommendations Bar allows website owners to tap into the social network’s database of what you and your friends read, share, and like.
    Here’s how it works: as you read a story on a website that has the Recommendations Bar feature activated, you’ll see pop-up windows in the bottom right corner of the page. The pop-up window will contain stories from the website that your Facebook friends have shared or liked. The window also contains a Like button, allowing you to like the story without ever leaving the website.
    Also Read: How to install Facebook Recommendation Bar In Your Blog

    Several sites already use this feature, including the tech blog Mashable, entertainment site Wetpaint, and U.K.-based tabloid The Mirror. Recommendations are limited to articles on the website that were shared by Facebook users. Websites using the new feature reportedly see as much as three times as many clicks on stories that are recommended in the pop-up boxes.
    This feature obviously benefits the website owner, but what’s the benefit to you? There isn’t really one–it’s just another reason to be worried about your privacy on the social networking site.
    Don’t get me wrong–relevant recommendations from friends might be helpful. There’s a good chance that the recommended content will be something that we’ll be interested in reading, since we often pick our friends based on shared interests.

    But there’s another side to this issue, and that’s the potential privacy concern. When Facebook debuts services that share, without your explicit permission, what you’re doing online…well, it always seems to go south.
    In May, my colleague Sarah Jacobsson Purewal noted this issue regarding Facebook’s social reader apps. She said these types of features create a “giant circle of awkward oversharing that people have little control over.” Who knows–what you’re reading might reveal things about yourself that you’re not necessarily willing to share with the world.
    Since there’s no way to control what type of content is shared, except to not share or like it altogether, your personal reading habits will be on display for all your friends. The only positive here is hat, unlike Social Reader, you physically need to take action on Facebook–whether you share or like the story–for it to show up in the Recommendations Bar.