Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, April 21, 2010

Facebook sucks

So, Facebook is rolling out a new system to obliterate your privacy. It hasn't swept up all users yet (I think fb does these things alphabetically, so it might take a day or two). Anyway, any status update or comment you have posted that includes the phrase "university of x" where x=the name of your university, is now on a PUBLIC page that anyone can read whether or not they are one of your friends and regardless of whether you have set the information to private (or "friends only") or whatever. If you have comments posted like "Professor y sucks" and the post also includes "university of x" then Professor y is going to be able to read that comment. It may also include pictures you have posted with captions like "party at university of x" which, given that Res Life uses social network sites to track down under-age drinkers may turn out to be a problem for some people. I haven't been converted over yet but some of my friends are finding their status updates and comments all over the place about pretty much any interest.

So, I'm not really sure what is going on here, but I have deleted all my info from my profile and suggest you look into this, particularly if you have status updates that might get you in trouble with the university or, you know, anyone else.

update: Here is facebook's info about this but information about how to opt out isn't until the end of the post. There will be a new privacy setting called "Friends, tags, and connections" that will default to "everyone" until you go in and change it. And I think you really really should. That setting won't show up as an option until your account has been converted to the new system. You will know that you have been exposed to the world when you log in and get a pop-up message about sharing contact info. Even if you say no to everything in the pop-up, you will still have to go in and manually set the privacy options.

Thursday, April 1, 2010

Olmstead for the 21st century?

Privacy is a hotly contested political concept, and not just in the area of abortion rights and sexual freedom. From Olmstead on, the Supreme Court has tended to lag behind the public's expectation of privacy in new technology. Current law regarding electronic privacy is out of date in many surprising ways and there is a great deal being written, litigated, and legislated regarding the proper balance between electronic privacy and other social interests.

Friday, February 19, 2010

More on the laptop cam privacy case

More details are emerging on the laptop camera student privacy case. The school district claims that it would only use the remote activation feature if the laptop was reported stolen. According to an email from one of the students involved in the lawsuit, the green lights next to the webcams would come on from time to time and students were told this was just a "glitch."

UPDATE: Additional details emerging, along with an FBI investigation.

Thursday, February 18, 2010

Privacy violation

Hmnmm, wonder if this one is a privacy violation.

According to the filings in Blake J Robbins v Lower Merion School District (PA) et al, the laptops issued to high-school students in the well-heeled Philly suburb have webcams that can be covertly activated by the schools' administrators, who have used this facility to spy on students and even their families. The issue came to light when the Robbins's child was disciplined for "improper behavior in his home" and the Vice Principal used a photo taken by the webcam as evidence.
Follow the link to find the class action filing against the school.

Thursday, February 11, 2010

Microchips, religion, and privacy

The Virginia House has a bill to ban involuntary implantation of micro-chips in people.
Del. Mark L. Cole (R-Fredericksburg), the bill's sponsor, said that privacy issues are the chief concern behind his attempt to criminalize the involuntary implantation of microchips. But he also said he shared concerns that the devices could someday be used as the "mark of the beast" described in the Book of Revelation.

"My understanding -- I'm not a theologian -- but there's a prophecy in the Bible that says you'll have to receive a mark, or you can neither buy nor sell things in end times," Cole said. "Some people think these computer chips might be that mark."

Cole said that the growing use of microchips could allow employers, insurers or the government to track people against their will and that implanting a foreign object into a human being could also have adverse health effects.

"I just think you should have the right to control your own body," Cole said.
ad_icon

The religious overtones have cast the debate into a realm that has made even some supporters uneasy and caused opponents to mock the bill for legislating the apocalypse.

Wednesday, February 3, 2010

Educational privacy or informational lockdown

A small college in Florida requires every faculty member, staff person, and administrator to sign a very stringent confidentiality agreement that apparently prohibits them from discussing anything that happens on campus. Is this about privacy, or about control over information? Does this protect employee or student privacy, or does it protect the administration of the college from criticism and chill public debate about campus policies?

The Edward Waters agreement, revised this month, is mandatory and classifies all on-campus material as confidential data. That includes employee records, policy documents and even in-class material unless otherwise approved for release.

Faculty, staff and administrators are all included, and any violations can be met with a daily $5,000 fine and additional legal action.

Thursday, January 28, 2010

Happy Data Privacy Day!

Yes, someone decided it is data privacy day today, just in time for us to start working on privacy in class. Anyway, follow the link for links to major corporations' data privacy policies - Intel, Google, etc are all there.

How easy is it for websites to identify me?

Really, really, easy, in a sense. Every website collects a lot of information about your computer, its configuration, and your browser. This constitutes a kind of fingerprint that could be used to identify you. Want to learn more? Visit the Electronic Frontier Foundation's Panopticlick site and test the machine that you are on. My office machine was "unique" in over 85,000 machines tested so far, and I generally set my browser for as much privacy as I can (consistent with still being able to use the browser in a convenient way).

EFF is a good resource in general for all things related to internet privacy and security. They have legal guides for bloggers, tips, and commentary. They also work as an advocacy group for internet freedom and security with political and legal mobilization strategies.

Thursday, January 14, 2010

Watch list problems

Compiling watch lists sometimes leads to fairly ridiculous outcomes like this:
“Meet Mikey Hicks,” said Najlah Feanny Hicks, introducing her 8-year-old son, a New Jersey Cub Scout and frequent traveler who has seldom boarded a plane without a hassle because he shares the name of a suspicious person. “It’s not a myth.”
Lists can lead to a lot of false positives possibly undermining the goals of making the list in the first place. Lists can also be fairly easy to evade, if one is determined enough.

Mario Labbé, a frequent-flying Canadian record-company executive, started having problems at airports shortly after Sept. 11, 2001, with lengthy delays at checkpoints and mysterious questions about Japan. By 2005, he stopped flying to the United States from Canada, instead meeting American clients in France. Then a forced rerouting to Miami in 2008 led to six hours of questions.

“What’s the name of your mother? Your father? When were you last in Japan?” Mr. Labbé recalled being asked. “Always the same questions in different order. And sometimes, it’s quite aggressive, not funny at all.”

Fed up, in the summer of 2008, he changed his name to François Mario Labbé. The problem vanished.

What other sorts of effects might these lists have, intentional or not?

Wednesday, March 19, 2008

Too many watchlists

We are all familiar with the no-fly lists and the ways in which they can complicate air travel for people with similar names to those on the lists. It turns out, there are more of these lists than most of us have been aware, although the existence of these lists is not itself secret (in fact, here is the list of about 6000 names). (Washington Post)

More American consumers have gotten caught up in a special brand of watchlist purgatory because their names are similar to ones on OFAC's list of "specially designated nationals," according to e-mails and other documents released under court order yesterday. By law, businesses are barred from conducting transactions with anyone on the list. Yesterday's court-ordered release of documents to the Lawyers Committee for Civil Rights of the San Francisco Bay Area, offers a window into the kinds of disruptions suffered by those ensnared in the process, as well as the difficulty of clearing their names.

More businesses are seeking, as part of a credit check, to know whether a person is also on the OFAC list. Failure to do so can bring a stiff penalty. Often a person whose name is similar to a name on the watchlist will be flagged by credit bureaus, which produce the reports businesses use to decide who is eligible for a car or home loan or to rent an apartment.

The Lawyers Committee sued the Treasury Department last year under the Freedom of Information Act for records of complaints relating to OFAC's list. Last year, the group documented the cases of at least a dozen people denied services, including being blocked from buying exercise equipment. Yesterday's partial release of records raised at least 30 new cases in which people sought OFAC help.

If you have ever tried to clear a mistake from your credit report, or been the victim of identity theft, you know what a hassle it can be to deal with the credit bureaus. Now mix in the feds and fear of terrorism and you have a recipe for a kafka-esque soup of obstacles and frustrations.

I know that the law wasn't literally aimed at preventing terrorists from buying exercise equipment but, you know, unless terrorist suspects start entering arm wrestling competitions, is there any good reason that we should apply the watch list to treadmill and bowflex machines? Isn't this a problem of a law being so overbroad in application that it is likely to fail to do what it is intended to do (either by being so extensive as to be unworkable, or engendering so much hostility from innocent people minding their own business that the laws get overturned)?

Updated: The New York Times points out that a lot of people have been concerned about the list, probably because while the list is not that long (6000 names) many of the names are common Arab and Latino names that are shared by many people who are not listed.

A Federal District Court judge in San Francisco last month ordered the Treasury Department to release all the complaints after a Freedom of Information Act request, Mr. Hwang said. He said his organization believed that what they received was only a small fraction of the complaints filed. Among other indications, he said, was that Henry Paulson Jr., the Treasury secretary, said in Congressional testimony last year that his department fielded up to 90,000 telephone complaints about the list over one year.

Monday, March 17, 2008

What's so funny about... wiretapping

There was a good, brief summary of past abuses of wiretapping power in yesterday's LA Times. For a detailed, documented account see David Cole and James X. Dempsey's Terrorism and the Constitution.

From Julian Sanchez in the LA Times op-ed section:

But focusing on the privacy of the average Joe in this way obscures the deeper threat that warrantless wiretaps poses to a democratic society. Without meaningful oversight, presidents and intelligence agencies can -- and repeatedly have -- abused their surveillance authority to spy on political enemies and dissenters.

The original FISA law was passed in 1978 after a thorough congressional investigation headed by Sen. Frank Church (D-Idaho) revealed that for decades, intelligence analysts -- and the presidents they served -- had spied on the letters and phone conversations of union chiefs, civil rights leaders, journalists, antiwar activists, lobbyists, members of Congress, Supreme Court justices -- even Eleanor Roosevelt and the Rev. Martin Luther King Jr. The Church Committee reports painstakingly documented how the information obtained was often "collected and disseminated in order to serve the purely political interests of an intelligence agency or the administration, and to influence social policy and political action."

Thursday, January 17, 2008

ATT and internet privacy

(updated below)

ATT wants to start filtering all internet traffic that passes through their equipment for copyright infringement. This would affect ATT subscribers, obviously, but also most of the rest of us as ATT owns various bits and pieces of the internet. This dovetails with the internet surveillance that the Director of National Intelligence would like to impose. We already know how seriously ATT takes the privacy of their customers (not at all seriously) when the government asks for private data.

Start training your carrier pigeon (or your owl) because that soon may be the only way to have a private communication with anyone you can't see in person.

Update: I spoke too soon, I guess they will be watching your owls and pigeons too.

Wednesday, January 16, 2008

Internet surveillance

The Director of National Intelligence has publicly stated that the government needs the power to observe everything that happens on the internet.
The nation's top spy, Michael McConnell, thinks the threat of cyberarmageddon! is so great that the U.S. government should have unfettered and warrantless access to U.S. citizens' Google search histories, private e-mails and file transfers, in order to spot the cyberterrorists in our midst. (Wired "Threat Level" blog)
There are many angles from which we can observe the claims for new power that McConnell makes. Aside from the practical question of whether searching everything that happens on the internet is likely to be an effective strategy, think about this from the perspective of our current reading on political fear. Assuming, for the sake of argument, that looking for a needle in the world's largest haystack won't provide a whole lot of bang for our intelligence buck (although I suppose we could use prison labor - scanning internet traffic could be the 21st century equivalent of breaking rocks for punishment), why would McConnell want to publicly advocate for this power? If it won't work, what is it for? What sort of political fear is involved here? Will constant and pervasive internet monitoring have effects we can recognize through the literature on the politics of fear?

Did anyone watch the Democratic candidates debate last night? That too featured references to the politics of fear, particularly by Obama.



Updated: Here is the clip - Obama on politics of fear.