Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Wednesday, 16 June 2010

Wi-fi issues: access and use

When travelling, if one does not have a smartphone or blackberry, it becomes really annoying not to be able to use wi-fi knowing that lots of networks are available. the silliness of it all appeared when I was in Gare du Nord Paris, compared to St Pancras - London. You would have guessed I was a Eurostar traveller. At St Pancras, free wi-fi; in 45 minutes, I checked my e-mails, sent a couple of documents I could not have done so if I had a smartphone. At Gare du Nord, well, no free wi-fi if you do not have a Eurostar business status; the provider SFR was asking a minimum of 2 euros, I recall, for about 30 minutes. Well, I know it is not that expensive, but it is such a hassle (you have to register, type your card number...; a good 15 mins wasted to just access). Result: I did not pay. and I am sure I am not the only to have done so.

of course, one could argue that to call, one has to pay, whether in a phone box, from a landline or a mobile. Why not for wi-fi? well Finland contemplates opening the network to all, getting rid of its offence to use open wi-fi. Of course, open wi-fi means less security. But then, why not charged for higher security? I would actually have paid for added security if I had to send sensitive data or connect to sensitive data website. but for ordinary websites, such as what is the weather back home or train time data, frankly I felt put off.


In contrast, Google's collection of private data is inadmissible. yet, whether it was intended to or an accident, an involuntary consequence not foreseen, is something else. I can't imagine the firm having done it on purpose, at least after until they were (made) aware of it if they continued despite knowledge.
What i am surprised is that the data collected was not destroyed immediately. Governments have no right to look at the data.

Google WiFi Data Caught In Legal Limbo (TechDirt, 27 May 2010)


Wider European Scrutiny of Google on Privacy from NYTimes as reported in Business and HR Watch, 21 May 2010 http://www.business-humanrights.org/Links/Repository/1000957


Obviously, the argument is based on the assumption that privacy is important. Some argue it is not; but I fully disagree. Our ancestors fought, sometimes to death, for a bit of privacy and not just privacy from government's spying. Privacy is essential and it is not because people don't go into mass protest about it that the issue/the right does not matter




Thursday, 20 May 2010

Privacy infringement

The two infringements make you wonder what non-famous companies do and how they are controlled:

Google Admits It Was Accidentally Collecting Some Open WiFi DataData (TechDirt, 14 May 2010)
EU watchdog slams Facebook privacy settings (Euractiv, 14 May 2010)

and new challenges ahead...

Obviously the question is a matter of sensibility as the US tend to be less concerned than Europe.
Draft Of Privacy Bill Introduced... And Pretty Much Everyone Hates It (TechDirt, 5th May 2010)

Friday, 7 May 2010

The gold mine: ID and other data thefts

Between the NHS desktops that were hacked and controlled as part of a botnet, and facebook accounts also hacked, it is obvious that security and privacy are at the heart of cybercrime. Accessing illegally and controlling data/computers is at the heart of a successful criminal entreprise.

"Over 1,000 NHS desktops part of botnet, says Symantec" (ZDnet.co.uk, 23 April 2010)

"iDefense: 1.5 million Facebook accounts for sale" (ZDnet.co.uk, 23 April 2010)

Therefore, one wonders why employers ease restrictions on employees using social networking sites, when usually the security of their own IT systems is average or bad. "Managers ease restrictions on Facebook use" (ZDnet.co.uk, 23 April 2010)

especially when a study by the French CNIL reveals that the most common password used is "123456"!!!!!! JDN, 22 January 2010

Privacy of Wi-fi data: Google Street View

A very interesting story that does not seem to make the big headlines despite its crucial importance in my view.
Google Street View, already criticised for other reasons, all linked to privacy, acknowledged that it takes the Wi-Fi details of people, i.e. their MAC addresses, that will be able to any user using location-based services. In other words, your neighbour or your potential hacker can know all about your Wi-fi, making easier to hack into your computer.
A "bemol" though: if you have configured your Wi-Fi device not to broadcast, the signal and information should not be available. Another reason to do it, if you have not already done so.
"Google explains why Street View cars record Wi-Fi data"

when we know that Google will have 96 pc of the UK roads on it: "Google Street View to cover 96pc of UK roads"

For a general view of privacy issues Google services raise, see the letter addressed to the company ten European authorities in charge of protecting IT users privacy, CNIL, press release 20 April 2010. See also (in French), "Les gardiens de la vie privée exhortent Google à respecter les lois" (Depeches du Juris-Classeur, 23 April 2010)

Thursday, 18 March 2010

Passport control: awaking the dead

"Is Elvis Dead? Who Knows, But His Passport Made It Through Airport Security In Amsterdam", TechDirt 01 March 2010

I like the irony of it all. Trying to secure identities of people, and yet failing badly...

Tuesday, 16 March 2010

The power of images and data

Three articles, all connected around several themes.

The first one is about Chatroulette's site which works on the basis of logging in for random chats with people all over the world (well, at least that is what they tell you). The principle may seem great but exhibitionists and voyeurs populate the site so much that whoever uses it is sure to encounter some unpleasant images or chat on a regular basis, about one every ten chats. The problem is that students, children, anybody has access to it.
What I found fascinating is the fact that people want to spend time at random with images displayed, often of their own private homes. There is a sense that their privacy is not infringed because the others do not know where they live... But that is on the basis that they reveal nothing of themselves. Yet, even with one image (that can be captured from the webcam), somebody can start tracking down the person since some websites allow to search for matching pictures. Anonymity cannot really exist.

"Online voyeurs flock to the random thrills of Chatroulette", The Observer, 14 February 2010 page 20
On an anedoctal use of Chatroulette, "Band 'Releases' New Album Via Chatroulette" 15 February 2010
and for the French Secretary of State to ask for regulation of Internet at an international level: "Nadine Morano demande à l’ONU de réguler Internet", 01net, 25 February 2010

The second article is about comments made by Mark Zuckerberg, one of the founders of Facebook that "people have gotten really comfortable not only sharing more information and different kinds, but more openly and with more people", and that lack of privacy as a "social norm". The article astutely points out the constrast between the affirmation and the reality of Mr Zuckerberg's behaviour to withdraw pictures from his facebook page! We may feel comfortable with others' lack of privacy, but not with our own. There is here an element of voyeurism, like with gossip: it is fine to gossip about others, but not about ourselves!
Even more interesting is a Sunday Times poll explained in the article, where 63% disagree with the statement that privacy matters less than before and 70% say they are worried about communication of private data.
There is an obvious need to redefine privacy in the internet age, I would add, in the Facebook age. What does it mean in legal terms?
There is also a question of education and responsiblity here. All those examples of people having posted images of others (without their knowledge) in embarrassing situations with unintended consequences of loss of jobs, refusal of qualification etc... There is a need to learn about our responsiblity towards others, like when on the road, and seeing a bad driver - one cannot pretend not seeing him/her and continue driving, one has to adapt-; but there is also a need to learn not to take images at face value, that seeing somebody being drunk once does not mean s/he is unfit for a job. Relativity... a new relationship to images and words on the net...

"Facebook’s Mark Zuckerberg says privacy is dead. So why does he want to keeps this picture hidden?" The Sunday Times, 17 January 2010 page 12

For an earlier version of the same problem on Facebook, "Public lives: Does the internet know too much about us?", The Independent, 30 June 2008

The third article is about the EU being worried about Google and the YouTube case in Italy. Europe Looms as Major Battleground for Google, The NY Times, 14 February 2010 (the printed version is titled: In Europe, Unease with Google's Power Grows - bad English by the way)


On the issue of privacy and speech, see Global Network Initiative

Fraud, spam and co

An old article I retrieved today from my pile. The author, Charles Arthur, wonder whether convicting spammers in the US will put an end to spam. A rather pessimist response, understandably. What interested me was the fact that spam can be linked to fraud and criminal organisations with data collected beeing sold back or with botnet spamming created and then offered to eastern European criminal gangs.
So as usual, if people were not so gullable, there will be a bit less fraud and spam.

"Will convicting five major spammers put an end to spam?" The Guardian, 24 June 2010


For other articles on sale of private data and fraud,
"Welcome to DarkMarket – global one-stop shop for cybercrime and banking fraud", The Guardian, 15 January 2010, page 3

"T-Mobile staff sold customers' details to rivals", The independent, 18 November 2009

Further fraud this time with carbon trading, "Fraud Besets E.U. Carbon Trade System", The NY Times, 8 February 2010

and issues of security for smartphones: "Mobile security: Hackers kept at bay by lack of a standard platform" Financial TImes 15 February 2010

Friday, 5 February 2010

Surveillance

Apparently, "Obama Quietly Issues Ruling Saying It's Legal For The FBI To Break The Law On Accessing Phone Records" (TechDirt, 22 January 2010)

and I find this even more astonishing: the harm exists, it is to each individual. "Judge Dismisses Lawsuit Over Warrantless Wiretapping, Appeal Planned" (TechDirt, 22 January 2010)

It is as astonishing as Bill Gates stating it's business and if Google does not want to comply to China, too bad! http://www.business-humanrights.org/Documents/MicrosoftreChinacensorship (25 January 2010)

Anonymity on the web

A very simple explanation, common sense, but as true as for anonymity by post mail: can't certify identities without using existing means of identification...

"You Can't Get Rid Of Anonymity Online, Even If You Wanted To" (TechDirt, 4 February 2010) refering to the blog of Bruno Schneier http://www.schneier.com/blog/archives/2010/02/anonymity_and_t_3.html


A change compared to the UK court position earlier on a blog written by a police officer:
"Israeli Court Supports Anonymity For Online Commenters" (TechDirt 26 January 2010)

Friday, 22 January 2010

Privacy, piracy, copyrights and censorship

The theme of the week seems to turn around protecting privacy.

"Hacking Surpassing Human Error For Data Breaches?" (TechDirt, 19 January 2010). For the author, the answer is actually positive: hacking is a major threat, more that insiders leaking data.

In the fight against piracy, will privacy be waived? "Swedish ISP Refuses To Give Up Info; Says IPRED Violates EU Privacy Rules" (TechDirt, 18 January 2010)

"The Similarity Between ACTA And Chinese Internet Censorship" (TechDirt, 20 January 2010) in that both requires strong involvement from ISPs. I also think that both infringed on privacy. But the issue of ISPs involvement is also close to more traditional searches and seizures: "Once Again, FBI Caught Breaking The Law In Gathering Phone Call Info; But Real Issue Is Why Telcos Let Them" (TechDirt, 19 January 2010)

Obviously, all this debate supposes there is such thing as privacy about data online. Hence the issue about cloud computing and expectations of privacy. "Do You Have Any Legal Right To Privacy For Information Stored Online?" (TechDirt, 19 January 2010) THe US have actually articulated that notion of expectation of privacy, even though the answer is not satisfactory: it is not because it is online that there is no expectation of privacy. It all depends on where and what was intended to be done with the data.

France Considers 'Right To Forget' Law, Apparently Not Realizing The Internet Never Forgets (TechDirt, 8 January 2010)


Tuesday, 8 December 2009

Towards an international protection for privacy

The CNIL (French quango to protect freedom of information and liberties) website reports of a conference to elaborate/create international standards that would overcome the patchy protection offered by national legislations to internet users. The article is in English, and is also available in French
"Privacy Policy: a first step towards international standards" (CNIL, 10 November 2009)

Thursday, 2 July 2009

Privacy: the cost of protecting it

Avis d’expert : Données personnelles : une dictature de la transparence sans les moyens de l’assurer ? par Patrick Deleau – Tribune Solutions (08 June 2009)

An analysis of the CNIL's 2008 report on its work to protect privacy. There seems to be a shift in liability from Government to private firms which, in French law, are responsible to protect access to private data and to ultimately destroy it. The liability is actually of a criminal nature with heavy fines, up to 1.5 millions of euros and 5 years emprisonment. Considering that most firms do not know what the law is about and do not have the capacity to comply with the legislation, this is quite scary. The CNIL also notes that it does not have the means to continue its role in the field as the audits, which would help the firms to understand what they need to do, cannot be financed.

Update on China's filtering software

China puts brakes on internet-filter rollout - ZDNet.co.uk (01 July 2009)

After the uproar when people learnt that China ordered computers made in the US to incorporate a filtering software, there seems to be a back up. Obviously, the Minister of Industry and Information Technology refused to acknowledge attempts to curtail free speech. As in the West, the official line is that filtering is necessary because of child porn. But I wonder what it really means? Will they do it next time without bothering to say anything, 'hidding' the software in the hard drive?

PC makers lobby, but prepare for China censorware (ZDnet.co.uk 29 June 2009)

See also in French:

Logiciel de filtrage Web : la Chine fait marche arrière (JDN, 1 July 2009)


I don't think the EU Chamber of commerce's opinion had any influence, although one never knows how much concerns about money may have weighted in the balance.

EU Chamber urges China to rethink internet filter (ZDnet.co.uk, 30 June 2009)






Friday, 26 June 2009

Security and cloud computing

Academics warn recently about the dangers of cloud computing, where softwares and data are stored in online companies' servers and accessible from the internet. E.g.: mobileme for Apple, Dropbox, etc... It's strange because it is one of the reasons why I have still not used those services, although I have to admit I am tempted sometimes for the sheer ease of accessing data anywhwere as long as I have a connection.

Cloud computing et confidentialité des e-mails (Euractiv, 17 June 2009)

Report on privacy in social networking

The national privacy watchdogs (often administrative authorities) produced a report on privacy and social networking. They are particularly concerned about the level of disclosure and the lack of prior consent of all parties involved, whether what is disclosed are pictures, details of life in writing or videos. They recommend that whoever posts information, notably pictures, obtains prior consent of people involved or face exclusion from the social network.
Given that the basis of those networks is to share information, often without consent, the recommendation would be a blow to those technologies. I personally think it is not the way forward; rather, we should differentiate between those participating in the network and those not participating. Those in, by the fact of subscribing, should have a opt-out; those not in should have an opt-in.
More sensible is the recommendation that social networks warn clearly and extensively at the level of disclosure faced by their users and how that information could be used against them or their family and friends.

See the summary on Euractiv
http://www.euractiv.com/fr/societe-information/vie-prive-rseaux-sociaux-online-loupe-ue/article-183506

For the report itself, Article 29 Data Protection Working Party

It is worth comparing with the 2007 report from ENISA, the rather silent EU agency on cyber issues, Enisa Position Paper EU agency for network and information security suggests updating legislation to face new social networking-related risksPdf external (25 October 2007)

Thursday, 25 June 2009

"pro"-piracy policy, anti-piracy policy and distorted language and

Woman Who Owned No Computer, But Got Sued By The RIAA, 'Settles' Techdirt: "Woman Who Owned No Computer, But Got Sued By The RIAA, 'Settles'" (TechDirt, 19 June 2009)

As pointed out, one cannot settle when the facts established demonstrate an impossibility to commit the action. The RIAA is manipulating the language to appear victorious when its actions embody utter failure.
More troubling, is the issue of evidence. What would have happened if this woman owned a computer but never filed share? How is the RIAA collecting its evidence? Are we not here faced with illegal surveillance?

In that sense, Norway's position to avoid general surveillance for just an issue of IP makes much more sense.
Norway Decides Privacy Is More Important Than Protecting The Entertainment Industry's Business Model (TechDirt, 24 June 2009)

Obviously, Norway's position obliges to rethink piracy and the IP rules. The analysis of Shakespeare's work and how the famous poet and writer borrowed from traditional folk tales and their various interpretations by other authors is quite enlightening about the real issue IP legislation create, especially in a world which works on the basis of networks and sharing.
"Would King Lear Ever Have Been Written If Copyright Law Existed?" (TechDirt, 23 June 2009)
"The Guardian Embraces Crowdsourcing The News In Useful Ways" (techDirt, 24 June 2009) (The Guardian put online all the data on the MPs' expenses scandal - ordinary people digged out what they found interesting and journalists just check and put the information within a broader perspective

Wednesday, 10 June 2009

Theft/acces to confidential data

BT researchers bought on e-bay 300 hard drives and checked their data content. The results are surprising and scary: 34% of the drives contain data easily identifiable to real persons or companies, some contained high security data such as log in of the French ambassador in Germany or information about US firms making missiles.
I can't believe people are silly enough to sell on e-bay disks that have not been reformated with complete erasure of data, especially in high-risk domains.

"Des disques durs d'occasion très bavards sur eBay" (JDN, 13 May 2009)

And it is no better when data is not even encrypted like the Royal Air Force's data!
Vols de données dans l'armée de l'air britannique (JDN, 28 May 2009)

"Hacked ATMs let criminals steal cash, PINs" (ZDnet.co.uk, 5 June 2009)

Wednesday, 3 June 2009

Social networks: world and power

With always/often talk of Facebook, but this is not the only one on the web. Others in non English languages are actually attracting more customers, in China obviously, but also Brazil, Russia, Netherlands etc...
"Ces réseaux sociaux qui résistent à Facebook Sonico.com au Brésil" (JDN, 2 June 2009)
I wonder if their business models are better than those of Facebook. Note though that the Russian internet business man just 'bought' Facebook ...

"Judge 'Friends' Lawyer During Case, Influenced By Defendant's Website" (TechDirt 2 June 2009) or how a judge disqualified himself by contacting one party's lawyer with the new technologies during the trial!!! One wonders about the judge's sense of duty.
On collection of data/communication of data to the public:

Self-explanatory
"If You Rob A Bank, Perhaps You Shouldn't Brag About It On MySpace" (TechDirt 2 June 2009)

Not criminal as such, but interesting about the degree of non privacy (to be expected really):
"Analyzing Labor Data Via Facebook Status" (TechDirt, 2 June 2009) or how the words hired/fired on posting were used to analyse the trend in financial crisis management....

Wednesday, 27 May 2009

Privacy

Number 10 will not investigate Phorm (ZDnet.co.uk, 20 May 2009) - not as bad as the title lets it think. No investigation by the Executive because the Information COmmissioner is competent. Separation of powers...

But this is as bad as it gets: Google would look at its employees' behaviours to detect those who wish to leave the company... "Google recherche maintenant dans les cerveaux de ses employés" (JDN. 21 May 2009)

Thursday, 7 May 2009

Piracy and ISPs' attitude in Sweden

Exploiting a gap in the law, Swedish ISPs do not keep any content nor any log on their customers. A radical stand to maximise privacy against the Governments' trend (like the UK) to want to keep data.

"More Swedish ISPs Decide To Keep No Logs To Protect Users" (TechDirt, 29 April 2009)

The movement is linked with the piracy case against Pirate Bay which is also a party with a seat in the EU Parliament "Swedish Pirate Party may win EU Parliament seat" (ZDnet.co.uk, 6 May 2009). Maybe there'll be a change in policy in the future?

For the origin of piracy, a truely international crime at the time, see "A Look Back At The History Of The Word 'Pirate'" (TechDirt, 30 April 2009) who refers to a SSRN paper "The Framing of 'Piracy': Etymology, Lobbying & Policy" from K. Matthews Dames