Blog

  • Google = Web-Nielsen?

    Joe Hall here.

    Google appears to be trying to better measure household and end-user internet traffic, similar to how Nielsen measures cable and television watching habits (“Google Screenwise: New Program Pays You To Give Up Privacy & Surf The Web With Chrome”).  In a new program, called Screenwise, Google will pay individuals a token amount ($5 up front plus $5 every three months) to install a browser extension that monitors what web sites you visit and how you use those sites.  For households, Google has a router device that will presumably capture all the household internet activity, and it pays a bit better ($100 up front plus $20 per month).

    This leaves me with a ton of questions:

    • While the browser extension will measure web traffic (port 80, in geek speak), will the router appliance measure all internet traffic?
    • Does the router appliance have a way of “seeing” into encrypted sessions using HTTPS, such as when you visit your bank? (It could do this by asking individuals to install a certificate on their machines that would allow the appliance to pass through encrypted client sessions as if it were the client and then re-encrypt the content when passing back to the user… otherwise known as a man-in-the-middle (MITM) attack).
    • Just what is the router capturing?  I doubt it, but is it also sniffing wifi, cellular signals, etc.?
    • What are the specific terms of service and privacy policy for screenwise? How long will such information be kept? Is it associated with personally-identifiable information or is demographic information enough?
    • Don’t these prices seem exceedingly low for the amount of information the user is giving up? I would most certainly price my detailed web surfing logs an order of magnitude or two ($50-500) higher than this.
    • I wonder how they’ll avoid gaming… for example, I only rarely use Chrome as I prefer the control I get from FireFox. If I sign up and only use Chrome once in a while, do I still get the incentive?
    • Will this information be combined with other Google information, now that Google can share data about your activities across all of their products?
    • Will this also capture data when Chrome is in it’s private browsing mode (incognito)?  That seems very unwise.
  • Your IP address is just like a zip code! Thanks, Google!

     

    Google has a new ad campaign in the NY subways!

    “You live in Peoria.

    Do you really need a plumber from New York?

    We didn’t think so. Imagine the service charge for a start. That’s why search engines, including Google, give you results based on your city or region.

    They can do this by using your computer’s IP address. It’s a number like 209.85.229.147, which acts like a zip code to tell them the rough area your computer is in.”

    They just want to help you out, guys! Google’s providing much better customer service!

    Sigh…

  • Google consent decree

    This is what the Google-FTC consent decree says about changing it sharing practices:

    II.
    IT IS FURTHER ORDERED that respondent, prior to any new or additional sharing by
    respondent of the Google user’s identified information with any third party, that: 1) is a change
    from stated sharing practices in effect at the time respondent collected such information, and 2)
    results from any change, addition, or enhancement to a product or service by respondent, in or
    affecting commerce, shall:

    A. Separate and apart from any final “end user license agreement,” “privacy policy,”
    “terms of use” page, or similar document, clearly and prominently disclose: (1)
    that the Google user’s information will be disclosed to one or more third parties,
    (2) the identity or specific categories of such third parties, and (3) the purpose(s)
    for respondent’s sharing; and

    B. Obtain express affirmative consent from the Google user to such sharing.

    Here is the relevant definition:

    “Third party” shall mean any individual or entity other than: (1) respondent; (2) a service
    provider of respondent that: (i) uses or receives covered information collected by or on
    behalf of respondent for and at the direction of the respondent and no other individual or
    entity, (ii) does not disclose the data, or any individually identifiable information derived
    from such data, to any individual or entity other than respondent, and (iii) does not use
    the data for any other purpose; or (3) any entity that uses covered information only as
    reasonably necessary: (i) to comply with applicable law, regulation, or legal process, (ii)
    to enforce respondent’s terms of use, or (iii) to detect, prevent, or mitigate fraud or
    security vulnerabilities.

    Interestingly, the Facebook consent decree has similar, but less restrictive, language:

    II.
    IT IS FURTHER ORDERED that Respondent and its representatives, in connection
    with any product or service, in or affecting commerce, prior to any sharing of a user’s
    nonpublic user information by Respondent with any third party, which materially exceeds the
    restrictions imposed by a user’s privacy setting(s), shall:

    A. clearly and prominently disclose to the user, separate and apart from any “privacy
    policy,” “data use policy,” “statement of rights and responsibilities” page, or other
    similar document: (1) the categories of nonpublic user information that will be
    disclosed to such third parties, (2) the identity or specific categories of such third
    parties, and (3) that such sharing exceeds the restrictions imposed by the privacy
    setting(s) in effect for the user; and

    B. obtain the user’s affirmative express consent.

    Nothing in Part II will (1) limit the applicability of Part I of this order; or (2) require Respondent
    to obtain affirmative express consent for sharing of a user’s nonpublic user information initiated
    by another user authorized to access such information, provided that such sharing does not
    materially exceed the restrictions imposed by a user’s privacy setting(s). Respondent may seek
    modification of this Part pursuant to 15 U.S.C. §45(b) and 16 C.F.R. 2.51(b) to address relevant
    developments that affect compliance with this Part, including, but not limited to, technological
    changes and changes in methods of obtaining affirmative express consent.

  • Proposed Amendment to Privacy Act

    J.D. Bean

    Proposed Amendment to the Privacy Act: The Privacy Act Modernization for the Information Age Act of 2011

    – Introduced October 18th, 2011 by Senator Daniel K. Akaka chairman of the Senate Subcommittee on Oversight of Government Management, the Federal Workforce, and the District of Columbia

    – Available At: http://www.gpo.gov/fdsys/pkg/BILLS-112s1732is/pdf/BILLS-112s1732is.pdf

    – More Info At: http://akaka.senate.gov/press-releases.cfm?method=releases.view&id=b5750831-557f-452d-a96d-b98dc967de57

    – Relevance: The amended act would overturn Doe v. Chao, update definitions and language to better correspond with modern IT techniques/concepts, codify the OMB definition of “personally identifiable information”, and extend the enhanced authority to investigate privacy act violations currently enjoyed by the Department of Homeland Security’s Chief Privacy Officer to additional agency CPOs. The act would stregthen civil and criminal remedies for Privacy act violations and updates both exceptions for agency notice of disclosure requirements and the requirements to agency publication of notices of systems of records.

  • Digital Data on Patients Raises Risk of Breaches

    Vladimir Andric

     

    http://www.nytimes.com/2011/12/19/technology/as-patient-records-are-digitized-data-breaches-are-on-the-rise.html?_r=1&ref=identitytheft

     

    Digital Data on Patients Raises Risk of Breaches

     

    Another article confirming the “stick with it like glue” as the major security principle when it comes to data protection in the world of electronic data management systems. The health industry is reported to have lost $6.5 billion to consequences of data breaches in 2010, and 2011 estimates show a 32% increase in the number of reported breaches. The article offers some interesting points on dealing with such data breaches and liability issues.

     

    And for an international perspective, http://www.aboutidentitytheft.co.uk/ provides an outlook of how the United Kingdom deals with identity theft issues.

  • What Google knows about You!

    Eleni Gessiou

     

    Lately, Google advertises its logo about the new privacy policy “One policy, one Google experience”!

    So, I spent some time reading the overview and searching (in Google of course!) for it..

    The results of my research are the following links:

    https://www.google.com/dashboard/

    http://www.google.com/s2/search/social?hl=en

    and especially if you own an Android mobile phone:

    https://www.google.com/contacts_v2/#contacts

    Now you can find all your friends’ phone numbers using your web browser only! Convenient or Scary?…

    Take a look at what Google knows about you and tune your privacy policies!

    Now, I’m sure.. Google knows everything!

  • Proposed EU Data-Privacy Rules Require Breach Disclosure within 24 Hours

     

    Josh Perles

    Proposed EU Data-Privacy Rules Require Breach Disclosure within 24 Hours

     

    Part of a comprehensive suite of data-privacy reforms, the proposed rules would require any firm with EU customers to notify affected individuals and the relevant authorities within 24 hours of detecting a breach.

     

    The draft legislation has received mixed responses.  Though designed to enhance consumers’ ability to manage personal data, critics point out that the short deadline may ultimately undermine privacy goals by interfering with law enforcement investigations, distracting from damage control, and creating confusing false alarms.

     

    Some view the proposal as a reaction to the PlayStation Network breach last spring, after which Sony failed to notify customers for over a week.  Even if the proposal never comes into effect, it sends a strong message to IT firms: step up your data-privacy game or risk strict regulation.

     

    http://www.nextgov.com/nextgov/ng_20120127_6325.php?oref=topnews

  • Privacy of Financial Data News: International Accounts, Voluntary Disclosure, and Privacy

    Caitlin Urbach

    Privacy of Financial Data News: International Accounts, Voluntary Disclosure, and Privacy

    The IRS announced on January 9, 2012 that it was instituting another voluntary disclosure program for those with foreign bank accounts.

    Taxpayers with foreign bank accounts with more than $10,000 in them are required to note the account on their income tax return and on a form entitled “Report of Foreign Bank and Financial Accounts” (FBAR), and those who fail to report these accounts are subject to significant financial penalties as well as possible criminal punishment. According to a recent Forbes article, the voluntary disclosure program that the IRS has created provides for reduced penalties in order to incentivize disclosure, and is also accompanied by the implied threat that the government will pursue offenders more diligently once the disclosure period ends. While this program provides a significant opportunity for those who have evaded detection in the past and would like to take advantage of the relative leniency of the program’s penalties, the very requirement of disclosure highlights how little financial privacy is permitted between U.S. taxpayers and the government. Even with required disclosure to the government, however, foreign bank accounts may provide some additional privacy relative to domestic accounts and so continue to have their advocates in the United States. A Business Insider contributor recently commented that the United States government monitors domestic accounts in a way that is not possible

    overseas– the Financial Crimes Enforcement Network, which is part of the U.S. Treasury, requires banks to fill out reports whenever a customer’s financial activity is deemed suspicious. While an international bank account might not be the panacea that those seeking financial privacy from the U.S. government have hoped for, some may continue to use foreign bank accounts for the increased privacy that they may offer. The IRS voluntary disclosure program provides a limited opportunity for those who want to benefit from the increased privacy abroad due to the lack of monitoring, while minimizing the legal consequences such individuals would face if they were found not to have disclosed offshore account information.

    Links to articles:

    IRS FBAR voluntary disclosure initiative:

    http://www.forbes.com/sites/irswatch/2012/01/10/deja-vu-yet-another-irs-fbar-voluntary-disclosure-initiative-2/

    Commentary on suspicious activity reports and U.S. banks:

    http://www.businessinsider.com/why-308127404-americans-are-going-to-get-hosed-2012-1

  • HOPE 9 call for speakers

    The ninth Hackers On Planet Earth conference will take place in New York on July 13-15, 2012. Organizers have issued a call for speakers on a wide variety of topics, including “cryptography, copyright, telecommunications, new technologies, research, experimentation, surveillance, countersurveillance, privacy, anonymity, censorship, hardware hacking, programming, democracy and law, education, social engineering, digital protests, [and] hacking society.”

  • Researcher’s Video Shows Secret Software on Millions of Phones Logging Everything

    “The Android developer who raised the ire of a mobile-phone monitoring company last week is on the attack again, producing a video of how the Carrier IQ software secretly installed on millions of mobile phones reports most everything a user does on a phone.”  Read more here.