728x90_newspapers_dark_1.gif
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Friday, November 19, 2010

Satisfied with Google's promise to restrain Street View, FTC drops privacy ... - Washington Post

The federal government has ended an inquiry into a privacy breach involving Google's Street View service, satisfied with the company's pledge to stop gathering e-mail, passwords and other information from residential WiFi networks as it rolls through neighborhoods.

Wednesday's decision by the Federal Trade Commission is a sharp contrast with the reaction of regulators in Europe. The United Kingdom has launched a new investigation into Google's collection of unencrypted WiFi data, exposing the company to potential fines. Germany told Google to mark its Street View cars that take pictures of neighborhoods and homes. The Czech Republic banned Google from expanding its mapping software program.

The differences highlight an increasing gap between regulators in the United States, where the freewheeling Internet culture has birthed many of the social networking sites and search engines used worldwide, and governments in Europe and Canada, which tend to be much more aggressive about privacy.

"Part of it is cultural, and part of it is that the U.S. and Europe have radically different privacy regimes," said Chris Calabrese, legislative counsel for the ACLU. "The European model is extensive data protection in private information, and the U.S. model is piecemeal."

The result is a rising number of trans-Atlantic conflicts. The Obama administration has been criticized for its efforts to allow law enforcement to surveil Internet networks, for instance. In addition, the European Union is pushing back against U.S. demands to share data about U.S.-bound air passengers.

Many European nations have laws that sanction or fine companies for learning too much about Web users and sharing that information with other companies. Regulators there tend to focus on consumers' rights to their own information on the Internet. In the United States, companies argue that consumers lose their rights after information is shared with a third party.

U.S. regulators are working on suggestions for how far companies can go with information they collect, store and share about Internet users. Those suggestions, to be released in a report by the FTC in the coming weeks, could result in a legislative road map for Congress. But because of the agency's limited rule-making power, the FTC's report could have limited impact, privacy groups fear.

The advocates also argue that U.S. companies have a strong voice in debates at the FTC and on Capitol Hill over privacy legislation. As a result, critics say, the U.S. government has been more sensitive to how privacy regulation or laws could affect the businesses of Web sites like Facebook and Amazon and media sites, such as The Washington Post and CNN.com.

"We are trying to develop a framework with input of many stakeholders that would be useful as we all go forward on privacy," said Jessica Rich, deputy director of the FTC's Consumer Protection Bureau.

In a letter to Google on Wednesday, the FTC said privacy concerns from its Street View cars' data collection were allayed when the search giant announced that it would beef up privacy training for employees and not use any collected data for any Google products or services.

"This assurance is critical to mitigate the potential harm to consumers from the collection of payload data," David Vladeck, head of the FTC's Consumer Protection Bureau, wrote in closing the review.

While taking photos of cars and homes, Google's Street View cars were also collecting information about the placement of WiFi networks. After German authorities investigated the practice, Google said its cars had accidentally also collected Internet user data - or payload data - while passing homes.

"We are deeply disappointed that FTC dropped the ball on Google," said Jeffrey Chester, executive director of the Center for Digital Democracy. "It took other regulators in Germany and Canada to expose the extent of the privacy violation. And the U.S. is saying it will continue to be absent on this issue."


View the original article here

Monday, November 8, 2010

Facebook Vows to Fix a Flaw in Data Privacy - New York Times

At the same time, you agree that Facebook can use that data to decide what ads to show you.

It is a complicated deal that many people enter into without perhaps fully understanding what will happen to their information. It also involves some trust — which is why any hint that Facebook may not be holding up its end of the bargain is sure to kick up plenty of controversy.

The latest challenge to that trust came on Monday, when Facebook acknowledged that some applications on its site, including the popular game FarmVille, had improperly shared identifying information about users, and in some cases their friends, with advertisers and Web tracking companies. The company said it was talking to application developers about how they handled personal information, and was looking at ways to prevent this from happening again.

Facebook’s acknowledgment came in response to an article in The Wall Street Journal that said several popular applications were passing a piece of data known as a user ID to outside companies, in violation of Facebook’s privacy policy.

Having a user ID allows someone to look up that user’s name and any data posted on that person’s public profile, like a college or favorite movies, but not information that the user had set to be visible only to friends.

Privacy advocates and technology experts were split on the significance of the issue.

“That is extremely serious,” said Peter Eckersley, a senior staff technologist at the Electronic Frontier Foundation, an online liberties group.

Mr. Eckersley said advertisers could use the user IDs to link individuals with information they had collected anonymously about them on the Web. “Facebook, perhaps inadvertently, is leaking the magic key to tracking you online,” he said.

At the same time, Mr. Eckersley said there was no evidence that anyone who had access to this data had actually misused it.

Zynga, the maker of FarmVille and other games on Facebook that have a combined 219 million users, did not respond to requests for comment.

Several technology pundits and bloggers minimized the issue, with some saying that credit card companies and magazines have access to far more detailed information about customers than any Facebook application.

Facebook also sought to play down the importance of the leak, saying the sending of user IDs appeared to have been inadvertent. “Press reports have exaggerated the implications of sharing” a user ID, Mike Vernal, a Facebook engineer, wrote on a company blog for application developers. “Knowledge of a UID does not enable anyone to access private user information without explicit user consent.”

In a statement, Facebook said that while it would be a challenge to do so, it planned to introduce “new technical systems that will dramatically limit the sharing of user IDs,” and would continue to enforce its policies on outside applications, shutting them down when necessary. It added that the companies that had received the user IDs said they had not made use of them.

Regardless, the problem underscores another challenge facing the company: Facebook has grown so rapidly, in both users and in technical complexity, that it finds it increasingly difficult to control everything that happens on its site. In addition to more than 500 million Facebook users, there are more than one million third-party applications running on the site.

The latest information leak was made possible by a quirk in a long-established technical standard used by Web browsers. The standard allows Web sites to record the address of the page a user clicked on to arrive there, a bit of information known as a referrer.

Facebook has been including user IDs in these referrers for some time, and last year technology experts pointed out that user IDs had leaked to advertisers that way. Facebook fixed that this year, but apparently never addressed the problem when it came to referrers used by applications on its site.

“Facebook isn’t benefiting from it, and Facebook is not intentionally leaking this data,” said Christopher Soghoian, a privacy advocate and research fellow at the Center for Applied Cybersecurity Research at Indiana University. “But it is not a trivial thing to re-engineer their systems.”

This year he filed a complaint with the Federal Trade Commission, claiming Google was leaking personal information because search terms appeared in its referrers.

The latest issue may have had particular resonance with Facebook users because the company has been reeling from a series of privacy controversies, in part because it has been subtly pushing users to share data more publicly.

This year, for example, many users complained when Facebook changed the way in which users expressed preferences for certain movies or bands, essentially making it more difficult to keep that information private.

And in May, after a series of complaints from some users and privacy advocates, the company made wholesale changes to its privacy settings.

Mark Zuckerberg, the company’s chief executive, apologized to users, saying the settings were often too complicated for people to understand. Despite the changes, the privacy issue has continued to dog Facebook.

“This is one more straw on the camel’s back that suggests that Facebook needs to think holistically not just about its privacy policies, but also about baking privacy into their technical design,” said Deirdre Mulligan, a privacy expert and professor at the School of Information at the University of California, Berkeley.


View the original article here

Wednesday, October 27, 2010

Facebook Keeps Privacy Features Comin' - Mediapost.com

In its latest effort to ease privacy concerns, Facebook on Tuesday unveiled additional security features, including the ability to request a one-time password for use on public computers. "The feature ... allows you to text 'otp' to 32665 from a mobile phone associated with your account to get a password to use on a public computer, such as at a library or Internet café," reports the Los Angeles Times.

"The measure helps protect people from keylogging programs or malware." Another new feature lets users see all the active sessions on their account, as well as log out remotely. The top social network also plans to routinely ask users to update their account information, such as their phone number and the security question that helps prove one's identity. Kudos to Facebook for continuing to pursue a more secure environment for users, but that last endeavor sounds more like a ploy to keep members' personal information up to date -- important to advertisers willing to pay a premium for reliable demographic data.


View the original article here