Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, July 14, 2011

The Fight for Control of our Virtual LIves


I've focused somewhat obsessively on the Google+ pseudonymity policy here, ever since the story broke last week about the suspension of people using avatar-based identities. The reason the issue resonates so strongly for me is that it relates to the extremely consequential question of who should be in charge of our virtual lives: The corporations who create the platforms which enable them, or the netizens who live them through the platforms. This recent presentation by Rebecca MacKinnon provides a good overview of the issue and offers ideas about how we might work together for the democratization of the internet.

Tuesday, March 16, 2010

A Mini-Rant on Privacy and Identity

seesaw 2
One of the peculiarities of the electronic environment is that people become so profoundly involved in each other that they lose that sense of private identity. Marshal McLuhan
The future McLuhan saw germinating in the late 1960s is growing like a weed today within the electronic garden of pervasive social networking. The identities we once fashioned within the isolation of our own nuclear-family homes, now live in the tribal consciousness of the global village. Our sense of personal identity cannot withstand the weight of the world peering at us through the SocialNet.

We've put our privacy to the knife through a thousand small cuts, bleeding status updates upon the digital waters. And although we reflexively startle and panic when Facebook or Google pushes us deeper into the ocean, we have been swimming out to sea on our own just as hard and as fast as we can. So relax. Enjoy. And be aware.

Saturday, February 27, 2010

Pseudonymity is Hard: Why Your Secret Virtual Identity Has Never Been Safe.

While I reveled in a year of high-profile virtual pseudonymity, the human behind the scenes often felt like a fugitive. Constant vigilance was required to mitigate the risks of inadvertently revealing clues online that would connect the two identities. One slip and the game could be over.

It doesn't take the proactive work of hackers or stalkers to blow your identity. As with most computer issues, user error is the most likely source of a problem. Here are a couple of easy ways to shoot yourself in the virtual foot:
  • Sending a social network status update from the wrong identity.  I hate to admit it, but I made this careless mistake a few times. And the tweets weren't vague, but announcements of new blog posts. Fortunately, I noticed immediately, deleted the tweets and no one was the wiser.
  • Typing in the wrong chat window. I suspect that most of us have made this mistake. I've been lucky. The half dozen times this happened resulted in nothing more than a little embarrassment. 
Outside of such errors, there are many of ways to expose clues to your identity in day-to-day web surfing. Every time you view a website, information about you such as your IP address, the link you clicked to reach the site and your Internet Service Provider is passed along and probably logged. This is a problem when the information can be connected to your identity, such as in the case of the Plurk Hole I wrote about back in September, 2008.

Peter Stindberg wrote today about a similar security hole exposed by the new media sharing feature of the Second Life client. The really insidious part of this particular "feature" is that your IP info can be pulled by just passing in the vicinity of the shared media. And someone with even a small amount of know-how can easily tie your avatar identity to the the IP-related information.

Truth is, there is no absolutely certain way to hide your identity. The more active you are with a pseudonymous identity and the more you extend it through multiple social networks, blog commenting, etc., the more risk you take that someone will gather enough nuggets to make a connection.

Personally, I always assumed my pseudonymity would eventually be compromised. I therefore chose to do nothing under the Botgirl identity that would negatively impact my human identity if it were ever revealed. Unfortunately, for some people, merely exposing the connection between the identities would cause harm.

Outside of constant vigilance, you can reduce (but not eliminate) the risk of identity exposure by using a software program such as Tor or Anonymizer that can mask your IP address and other tell-tale information.

Anyone else have tips on safe identity surfing? Or horror stories?

Sunday, February 14, 2010

Newest Crazy Google Buzz Privacy Question

Buzz Extension

Maybe the Google legal department thinks Buzz should be classified like a drug, because this is certainly in the scary disclaimer category:
This extension will have access to your browsing history and private data on all websites.
Thanks for the warning and all, but what's up with that?

Thursday, February 11, 2010

Google Buzz Overtakes Facebook in Race to Bottom of Privacy Barrel

Google Buzz launched this week with default privacy settings that publicly disclose a user's most frequent chat and e-mail partners.  If that wasn't bad enough, they buried opt-out settings so deeply that it takes an 11 step tutorial to find your way through the counter-intuitive maze of links leading to the required pages. You'd think the company that pioneered simple UI design could do better if they wanted to.

Another puzzling aspect of their privacy policy is the disconnect between the language on the Buzz for mobile acceptance page and the actual Terms of Service.

Before using the mobile version, you must "agree that Google will use your location when you use Buzz." But the actual ToS stipulates, "You can also choose to exclude your location from all of your posts."

So which is it?

It seems to me that Google is following the lead of Facebook founder Mark Zuckerberg, who wrote in an open letter, "We've worked hard to build controls that we think will be better for you". I guess from their point of view, what's best for us is full disclosure of all personal information.

I don't believe that Google and Facebook are taking this stance out of pure self-interest. Instead, I think they equate "what's good for the network" with "what's good for the customer." And if a few individuals have information disclosed that they'd rather not share, well, that's the price we pay for the wondrous benefits of data-mined utopia, right? Right?

Friday, January 15, 2010

Is the "Age of Privacy" Really Over?

Facebook founder Mark Zuckerberg recently stated that social norms related to privacy have evolved since the company's founding in 2003. He said,
"People have really gotten comfortable not only sharing more information and different kinds, but more openly and with more people."
What's interesting is the leap of logic he made from the valid point that social sharing is now a mainstream practice to the dubious unilateral decision made to change the default privacy settings for 350 million Facebook users:
"A lot of companies would be trapped by the conventions and their legacies of what they've built, doing a privacy change - doing a privacy change for 350 million users is not the kind of thing that a lot of companies would do. But we viewed that as a really important thing, to always keep a beginner's mind and what would we do if we were starting the company now and we decided that these would be the social norms now and we just went for it."
I've railed on Linden Lab in the past about anti-consumer provisions in the Second Life Terms of Service (TOS) agreement. But they're just following the standard software industry practice of issuing one-sided agreements that secure all conceivable corporate interests and preemptively strip customers of any leverage they might otherwise have had in case of a legal dispute.

The overall issue of equitable TOS agreements is going to be an increasingly important concern because dependence on software-based capabilities is transitioning from an optional personal decision to a mandatory part of life in our modern culture.

The ability to manage our own privacy is not just a matter of controlling access to our information on a site-by-site basis, but also depends upon our ability to limit how information about us can be collected, shared and aggregated as a whole. The more virtual our lives become, the more third-parties will have the ability to monitor our activities, integrate data from multiple sources and use the information in their own interests.

The same technology that drives the personalized advertising messages you see on Facebook and Google today, can potentially be used by organizations such as insurance companies, financial institutions and potential employers to calculate our "worthiness" by automated analysis of aggregated information ranging from blog comments to video favorites on YouTube.

It seems to me that privacy laws such as those that have been introduced to protect health data in the United States (HIPAA) should be extended to a wider range of information. This would mean that social networks such as Facebook would be required to provide a minimum standard of privacy controls that they could not arbitrarily change through TOS amendments. It would also further limit the ability of companies such as Equifax to aggregate and share personally identifying information.

The best source for information on net-related privacy issues is the  Electronic Frontier Foundation. And they have a very cool xkcd tshirt option if you make a donation.

Monday, September 15, 2008

Reputation management of online identities: Privacy part 1

Privacy: Level 7

Controversy broke out Saturday in the Second Life Plurk community only a few days after my initial post on the topic. Codie had taken the threads from her very popular Bold Sex Question of the Day (BSQOTD) and posted them on her blog. The response was swift and urgently negative. At least from a few concerned Plurkers.

Although the original pages are accessible on Plurk to the 400+ people on Codie's friend and fan lists, some participants were concerned that the reputation of their pseudonymous virtual identity would be damaged if their participation was archived on search-engine accessible web pages. Codie graciously pulled the archive from her site within the hour.

The tempest in a teapot made me realize that many people care deeply about the reputation of their online identities. I thought it would be in the public interest to put out a little guide to managing virtual ID reputation, with a special emphasis on the spectrum of private and public communication and activity.

Since I'm in the final stretch of taking care of a million undone tasks for Sunday's 11AM SLT opening of my art exhibition in New Caerleon, (shameless plug) I'm going to take it slow. But I was all hot and bothered about this idea and just couldn't help myself from getting started.