Saturday, November 23, 2013

Vint Cerf's not wrong, idea of privacy as anonymity may be an anomaly

Vint Cerf is someone for whom I have great respect, and a piece of advice: If you ever say anything in public about privacy, choose your words carefully. For example, if you say "Privacy may actually be an anomaly," then a lot of people will assume you said: Privacy is an anomaly. At which point they will stop listening and turn to Twitter to tell you how wrong you are.

I'm pretty sure that what you meant to say was that privacy, as a sense of being entitled to anonymity in all you do, is a concept born of the industrial age and the emergence of large cities where it was possible to achieve a level of anonymity unheard of in agrarian villages.

Do I think that particular concept of "privacy" is  sustainable? Let me preface my answer with a disclaimer: I am a paid up supporter of EFF and I am totally opposed to mass warrantless electronic surveillance and suspicionless physical stop-and-frisk.

But in my opinion, privacy as some people define it today, with a heavy emphasis on anonymity, is not sustainable. This is not because privacy is not a good thing or anonymity a bad thing. But the world has changed. Mass global travel. Complex virtual worlds. Huge online transaction flows. Ubiquitous mobile communication. This is a totally new world and not everyone in it is a good person.

We need to think about how we want privacy to work within this new world. A global digital economy cannot be sustained without trust and accountability, which require identity, and that requires sharing personal information.

For example, if I want to travel to another country I will be required to reveal a lot about myself in order to be granted entry. That's fine by me. And I want my government to know a lot about the people who come to my country. That doesn't mean I want my country to watch everyone all the time and hassle anyone who looks different, but all members of a society need to be onboard with the idea of transparency, without which we cannot have accountability.

I'm not sure if all of that was on Vint's mind when he was speaking, but I know what he means about villages because I've talked about this myself, since the last century. I was fortunate to spend the early years of the commercial Internet living in a small Scottish village (trying to use a dial-up modem over phone lines chewed by sheep did not feel fortunate, but other aspects of the experience made up for it). Of course, the early Internet went through a phase, alluded to by Glen Greenwald in a recent radio interview, where anonymity was not only possible but also liberating.

I won't go on about village life but just think of HIPAA today, then that village 20 years ago, where prayers were said in church on Sunday for people whose medical conditions were openly shared. Heck, you knew who'd seen the doctor that week because you'd watched him making house calls. A degree of privacy was available on demand, but acting anonymously was not easy, as our daughter discovered when neighbors told us where she he had been seen, and with whom.

http://privacyforbusiness.com/reader.html
I alluded to that experience when I published "Privacy for Business" in 2002 (that 240 page book is still available for free download as a .pdf). By 1999 it had become clear to me that digital access to information fundamentally transformed information. To put it another way, information is not just about facts, but also where they are stored and who can access them, plus the ease and speed of access. Telling Debbie at the village store my food preferences did not mean they entered a database. No computer recorded the fact that I had to run a tab at times when my royalty check was late.

On the other hand, when I moved back to a city I did not hesitate to get a discount card at the supermarket chain because frankly that type of tracking does not bother me (and will not unless I find someone is doing evil things with it). I was less willing to share my income information. But as I researched my privacy book I was struck by how many people equated privacy with being able to live anonymously, as though hiding everything you do from everybody was the goal of privacy. Fair enough I suppose, if that is what you mean by privacy, go for it, but then you have to explain why hundreds of millions of people around the world like to share details of their lives on Facebook.

In other words. we are now entering a very challenging period in human history, where the need to protect the citizens of the world from the murderous and unscrupulous will rub up against the desire of honest citizens to control the amount of information about them that is acquired, and by whom, and how it is used. Hopefully this friction will not be framed as a need to surrender some amount of privacy for some amount of security, but as a debate about how much transparency among persons and institutions is necessary to create trust and the wealth and benefits that trust brings to society.

Vint did not to say what another industry veteran once famously said: "Privacy is dead." That was Scott McNealy (someone else who hadn't read my advice about public statements on privacy). I happen to think Scott was trying to say what Vint was trying to say: It's all about present notions of privacy evolving in the light of massive technological change. Notions of privacy have existed since the dawn of humanity, but they have changed over time. Privacy as it was thought of in times past may not exist in the future. But then again, future iterations of privacy may evolve to be even better. A better future is what technology should be about, on that we can all agree with Vint Cerf.

Tuesday, April 30, 2013

Privacy, transparency, credentials and travel: When it could be good to be known

Have you ever waited in line at a security checkpoint thinking: "I wish these people knew exactly who I am, in which case they would know that I'm not a threat and could be waived through?" Maybe it's me, but I have that thought a lot, even though I know full well that the entity doing the controlling might want to know a lot about me in order to give me a free pass or expedited processing.

In fact, when it comes to the U.S. government, it already does know a lot about me. And you might be surprised to hear this, but I'm fine with that, so far.

If I were to place myself on the "privacy meter" on the right, I am very much an open book. This could just be a matter of personality, but as I was standing in line at passport control in Houston last week, it occurred to me that my embrace of transparency may also have something to do with my being an immigrant, a naturalized U.S. citizen, someone who chose to live in America (about 30 years ago).

I think there may be subtle ways in which my attitude to privacy differs from that of some other American citizens, namely, the ones who just happened to be born here and never left. As I sometimes say during presentations about privacy to American audiences: "Unlike most of you, I passed a test to be here." (This line gets a big laugh, even among very conservative audiences, which I take as a sign of the natural good humor and empathy of the American public.)

Sunday, April 28, 2013

Privacy still a vital concern for online businesses

In light of Privacy Awareness Week, I just wanted to remind folks about availability of my privacy book, the first few chapters of which are still a decent primer on privacy for business, despite being about ten years old. The book is free to download in handy .pdf format, searchable and with a table of contents. Here is the opening of Chapter 1:
Privacy is currently a subject of great concern to many consumers. You probably know this already—you are reading this book—but the point is worth emphasizing. No business today can claim ignorance of the importance of privacy as a concern among consumers, a concern that can have significant business impacts, from increased costs to revenues lost, from brand dilution to stock price depression. Every company that wants to interact with customers via the Internet should know that privacy concerns are the primary impediment to such interaction.
And more from later in the same chapter:
Privacy is a formidable challenge because nobody yet understands exactly what privacy means in today’s highly interconnected, heavily computerized, data-dependent world. About the best we can say is that privacy in the information age is a work in progress. In the same way that environmental risks continue to emerge as the dark side of the industrial/technological age, emerging privacy risks have been cast as the dark side of the information age. Whether or not you agree with that assessment, it is indisputable that many people see databases and computer networks as a threat to their personal privacy. Thus, to the extent that your business depends on access to, or makes use of, personal information, you will want to provide reassurances to those who need them, regarding the handling and protection of their personal information.

Interested? Why not download it now?

Privacy Awareness Week 2013

The Asia Pacific Privacy Authorities forum invite you to participate in Privacy Awareness Week (PAW) 2013 to be held from 28 April to 4 May. PAW is held each year to promote greater privacy awareness and the importance of protecting personal information.

Privacy Awareness Week 2013

Privacy Fail: Why someone without MS gets MS related marketing material

This NYT article of privacy caught my eye because for a while we thought my wife might have Multiple Sclerosis. So, like the person in the article, I also researched MS on the web. The article describes how a "search online for information about various diseases, including M.S., on a number of consumer health sites" lead to targeting as an MS sufferer (which has serious potential ramifications for health insurance, employment, etc.).

Provides a good window into the murky market in personal data, a lot of it wholly erroneous. Now consumers have to add "murky data markets" to "dark markets" and the "deep web" when it comes to areas of concern about electronic privacy, data security, and the power of free (to-do-harm) markets.
 
Personal Data Takes a Winding Path Into Marketers’ Hands - NYTimes.com

Monday, June 27, 2011

National Data Breach Law Proposed : Massachusetts Data Privacy Law Blog

"So my question to ponder as I sail adrift in this storm is whether the Massachusetts requirement that businesses have a Written Information Security Program will be eliminated by the passage of this bill in its current state. You see, the proposed Federal law specifically says “supersede any provision of the law…relating to notification…” It doesn’t say any more or any less."

National Data Breach Law Proposed : Massachusetts Data Privacy Law Blog:

Friday, June 24, 2011

Compliance Guide: The New European Online Privacy Law

"The EU recently enacted its new Privacy and Electronic Communications Directive (the “E-Privacy Directive”), an important new policy directive establishing rules for the use of cookies for tracking/storing information on European users will change. Prior to the enactment of the E-Privacy Directive, website operators with customers in the EU were simply required to: (a) inform website users how they use cookies; and (b) provide “opt out” information.

Under the new rules, which went into effect on May 25th, 2011, cookies can only be placed on computers where the user has given their express consent, except in cases in which a website operator doing something that is “strictly necessary” for a service specifically requested by the user."

Compliance Guide: The New European Online Privacy Law:

New cookies law: Are you EU-compliant?

The new EU ‘Cookies’ law took effect on 2011-05-25, a European law requiring organizations’ websites that track users’ cookies – the personal information stored by PCs, iPads and smartphones – to first secure explicit permission from site visitors - The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011.

New cookies law: Are you EU-compliant?

Tuesday, May 4, 2010

Two Posts on the Subject of Facebook and Privacy


I realize it has been a while since I posted here, but I wanted to note these two privacy-related posts because they are different aspects of the same problem.

Mark Zuckerberg Faces the Privacy Meter: Facebook trends open book

Face it folks, it’s time to dust off the Privacy Meter for a quick check of Facebook founder Mark Zuckerberg. According to an internal source, Mr. Zuckerberg has placed himself in the camp made (in)famous in 1999 by Scott McNealy, the CEO of Sun Microsystems, who was reported to have said: “You already have zero privacy anyway, so get over it.” Mr. Zuckerberg’s position was recently described by a Facebook insider in response to this question: “How does Zuck feel about privacy?” Response: “He doesn’t believe in it.” (More...)

Facebook Tool Might Help With Privacy Settings and Awareness

Using Facebook means sharing personal information with at least some people, but Facebook sometimes makes changes to the way sharing works. Knowing exactly what you share and with whom can be hard to figure out. (More...)

Disclaimer: Okay, so I have severely neglected this blog. Bad blogger! No Bloggie Award! Frankly, I blame that age-old pair of challenges: Too many blogs and not enough time. I have been blogging, just not here. And some of my posts in other places have been privacy-related. I admit, I'm still trying to resolve the many-niche-blogs versus unified-blogging theory. Please bear with me.

Monday, July 30, 2007

Sunday, July 29, 2007

Tuesday, June 26, 2007

Teenage Tracking Systems: do kids have limited privacy rights?

Noticed this article recently on tracking systems that help parents keep tabs on teen drivers. As my friends will confirm, I was trying to put one of these together myself about 12 years ago. I happen to think it might have altered the course of my daughter's life if I could have mated GPS to CDMA or GPRS. And I think anyone who has a teenager will understand the desire to track their travels. But it raises interesting questions (a great way to spark classrooom discussion of privacy). For example, at what point does a person achieve their right to privacy?

Some people will be eager to point out that, legally speaking, in the United States, driving is a privilege and not a right. And no right to privacy exists as to your location when in public. But still, I think some teenagers would be inspired to research this question if you told them they were going to be tracked.

Monday, June 25, 2007

Are People Quitting Google in Droves? Time will tell

After pondering aloud in my last post about consumer attitudes to Google I did a little digging and found this on the "browser blog" at Fortune.com:

Google corners nearly two-thirds of US search market
The latest search market share numbers are in from Hitwise: in the four weeks ended March 31st, Google (GOOG) racked up fully 64.13% of all US searches. That’s up more than 10% since March 2006, and, if trends hold, Google’s share will pass the two thirds mark by August. In the same period, Yahoo (YHOO), Microsoft (MSFT), and Ask (IACI) all lost share. As the old Wall Street hands like to say: “Liquidity begets liquidity.”

Clearly, this is not good news for the search also rans, particularly as it covers a period when all of them made major and costly improvements to their search engines. Ask.com for example, rolled out an impressive local search service in 2006 and also greatly improved its image searching, and yet its share declined nearly a half a point, to a fragile 3.48%, in the course of the year.

Conventional wisdom has long held that Google is vulnerable to vertical attacks, i.e. search engines that carve out category niches. The new Hitwise data suggests, however, that Google is actually gaining influence in valuable verticals...

That post was dated April 11 and Google was at 64.8% by June according to the blog at Hitwise, readable here. I will keep watching these two sites to see if there is any evidence of a prviacy-fear induced slowdown in Google growth. If Google does not pass the 2/3 mark by August, look for Privacy International to claim some credit.
.

Wednesday, June 20, 2007

Google Brain Implants: Not yet, likely never

You have to love the opening of this recent article about Google, sourced from Reuters, but written up by New Zealand TV:
Most people missed the announcement about how Google Inc. wants to burrow inside your brain and capture your most intimate thoughts. That's because it never happened. But Google, the world leader in web search services, is the focus of mounting paranoia over the scope of its powers as it expands into new advertising formats from online video to radio and TV, while creating dozens of new internet services.

Interestingly the article -- available online here -- quotes two people at Google who work on privacy. A lot of the recent Google/privacy stories, sparked by the Privacy International press release about its interim report, give the impression that nobody at Google bothers with privacy. The NZ story quotes Nicole Wong, "the Google attorney who oversees a team of lawyers who consider privacy and other policy issues that go into the making of each product," and Peter Fleischer, "Google's global privacy counsel."

So it sounds like Google has a lawyer devoted to privacy and another attorney leading a product review team that has privacy as part of its remit. This is clearly not enough for some privacy advocates and so, if I was Google I would very publicly create a job entitled Chief Privacy Officer and then hire someone with a good industry reputation for the post. That might allay the fears of privacy advocates. In the meantime I am keeping a watch out for any surveys that indicate consumers have any privacy fears that are keeping them away from Google.
.

Monday, June 18, 2007

The Actual Interim Privacy Rankings: Is Google really hostile and aggressive?

With so much chatter about the "Google Sucks at Privacy" story put out by Privacy International, I thought it would be useful to provide a link to their source document: interimrankings.pdf . Here's a quote:
We are aware that the decision to place Google at the bottom of the ranking is likely to be controversial, but throughout our research we have found numerous deficiencies and hostilities in Google's approach to privacy that go well beyond those of other organizations.

I have to say that the use of the word "hostilities" in this context is surprising. I've been involved in some pretty serious privacy and security cases and nobody was accused of hostility in their approach to privacy. For example, I was involved when the Federal Trade Commission brought charges against Eli Lilly for violating privacy. I helped Microsoft comply with certain requirements imposed by the FTC to settle charges arising from security and privacy issues. But hostilities? Here's more:
While a number of companies share some of these negative elements, none comes close to achieving status as an endemic threat to privacy [my emphasis]. This is in part due to the diversity and specificity of Google's product range and the ability of the company to share extracted data between these tools, and in part it is due to Google's market dominance and the sheer size of its user base. Google's status in the ranking is also due to its aggressive use of invasive or potentially invasive technologies and techniques.

If Google is guilty of "aggressive use of invasive technologies and techniques" where are the regulators and politicians and consumer outrage? Surely Google hasn't bribed them all.
Google's increasing ability to deep-drill into the minutiae of a user's life and lifestyle choices must in our view be coupled with well defined and mature user controls and an equally mature privacy outlook. Neither of these elements has been demonstrated. Rather, we have witnessed an attitude to privacy within Google that at its most blatant is hostile, and at its most benign is ambivalent. These dynamics do not pervade other major players such as Microsoft or eBay, both of which have made notable improvements to the corporate ethos on privacy issues.

I feel compelled to add a phrase to that last sentence: "after consumer outcry." Microsoft was dragged before the FTC and eBay was heckled by members. I'm not aware of widespread consumer outcry over Google. So, I suggest you read the above-referenced "interim" document and decide for yourself. Note that the report was compiled
...using data derived from public sources (newspaper articles, blog entries, submissions to government inquiries, privacy policies etc), information provided by present and former company staff, technical analysis and interviews with company representatives.

and
Because the 2007 rankings are a precedent, Privacy International will regard the current report as a consultation report and will establish a broad outreach for two months to ensure that any new and relevant information is taken into account before publishing a full report in September.

Does Privacy International make its case or is it really just trying to force Google into a dialogue by holding out the hopes of a less critical final report?
.

Saturday, June 16, 2007

Privacy Watchdog Tags Google Worst on Web

As you have probably noticed, a UK-based group called Privacy International has ranked Google dead last among a dozen major Internet-based companies in terms of protecting users' privacy: Privacy Watchdog Tags Google Worst on Web.
The sheer size of Google, coupled with the company's ability to share user data between its various subsidiaries, led Privacy International to bestow the [dubious] distinction on the Net's biggest search engine.
This rank ranking might also have had a tiny bit to do with the fact that Privacy International seems to have a really bad relationship with Google. PI is the same organization that put out a press release in 2004 headed "Privacy watchdog vows to bring Gmail to heel." Perhaps not surprising then that PI has not been able to have much of a conversation with Google (which it sued in 16 countries). When PI asserts that Google has an “entrenched hostility to privacy,” one wonders if PI doesn't have an entrenched hostility to Google.

I doubt PI have won any friends within Google with this headline-grabbing "worst of the worst" verdict. Yet one does wonder what exactly Google thinks about privacy. You can get some fascinating insight over at Ray Everett-Church's Privacy Clue.

And I doubt that consumers in general will be avoiding Google in droves because of what PI says. After all, as stated in my last post, consumers are more concerned about “environmental issues, followed by pension and other retirement benefits, and health care.”

Monday, June 11, 2007

In Corporations They Don’t Trust - New York Times

An interesting angle on the privacy debate was revealed in a piece by Paul Brown in the New York Times a couple of days ago. The gist of the piece was that "senior executives really do not have a clue." Brown cited a study in the McKinsey Quarterly, the business journal of McKinsey & Company, that found “a trust gap between consumers and global corporations, as well as a lack of understanding among business leaders about what consumers really expect from companies.” For example, when asked what three concerns would be most important to them over the next five years,
“Executives predicted consumers would put job losses and offshoring first, followed by privacy and data security, and the environment...[whereas]...almost half of the consumers picked environmental issues, followed by pension and other retirement benefits, and health care.”

In other words, CxOs think consumer concern about privacy and data security is greater than it really is. Why would this be, apart from the obvious generalized conclusion that CxOs are out of touch with consumers? I suspect it has something to do with the relentless pressure from security and privacy advocates as well as extensive negative media coverage of security breaches that expose private data. And you might add to that the increasing likelihood that such breaches will be followed by lawsuits, some of which may name CxOs. They may be out of touch with consumers but they are very likely to be in touch with their own self-interests.

Thursday, May 31, 2007

Is the Web Built on a Lack of Privacy?

There are some interesting observations in this TimesOnline article triggered by a BlueCross privacy breach: The web is built on a lack of privacy. The writer is Jonathan Weber, the founder and editor in chief of NewWest.Net, a regional news service focused on the Rocky Mountain West in the United States. As co-founder and editor in chief of the Industry Standard, Mr. Weber is no stranger to the vagaries of the digital age. I'm sure many of us share his righteous indignation:
A few weeks ago I got a letter from Empire Blue Cross, my one-time health insurer, explaining that there had been an unfortunate incident regarding my personal information (and that of my wife and children too, as it turned out). The letter explained at some length how the company had rigorous policies to insure the confidentiality of patient information, requiring that such information be encrypted and so forth. But the company didn't take the trouble to ensure that it's high-minded – and legally required – policy was actually being implemented, and a CD containing unencrypted personal information on many people, including me, had gone missing.
(To digress from privacy for a moment, this letter sounds like it was written by the same BlueCross hack that penned a recent letter to my wife and I informing us that, as a result of cost savings, increased efficiency, and improvements in health care, our monthly premium was being increased by 20%.)

Weber goes on to muse about the potentials for abuse now that so much data about us is stored somewhere out there, by somebody over whom we have scant control (often somebodies who themselves have less than complete control). Yet at the same time, it is our willingness to share information about ourselves that has enable many features of the web, not least of which is the amazing amount of valuable content that is dished up for free (where 'free' equals 'in return for knowledge about the person accessing the infrormation').


The extent to which people accept, or feel comfortable with, this state of affairs varies greatly, as you might expect (particularly if you have listened to my podcast on The Privacy Meter--plug, shameless plug). This is reflected in the comments on the article which display a range of privacy attitudes. They include the infamous quote from Scott McNealy, founder of Sun Microsystems: "You have no privacy. Get over it." (Note: This quote is almost always used out of context but has become a handy verbal marker, serving as everything from a rallying cry or portent of end times, depending upon the quoter's point of view).

The fact is, this stuff is complicated. Some people are more 'open' about their lives than others but you can be very 'open' and still object to careless handling of your data. On the other hand, some people who like their right to privacy have a tendency to confuse it with a right to anonymity, which gets even less of a mention in the Constitution and Bill of Rights than privacy.

There is also a non-trivial socio-economic element to choices about personal privacy. Some people can afford to let the world know all about them without fear of the economic consequences. As someone well-established in his profession, I don't see that much harm would come to me from announcing to the world that I am gay (I am not) but other people fear, sometimes with very real justification, that they will be discriminated against if some of their private choices are made public. The U.S. military's "Don't ask, don't tell" policy towards homosexuality would seem to be a case in point. (During the first 1o years of this policy some 10,000 members of the armed forces were discharged for being homosexual--suggesting that the policy's intent, respect for the privacy of military personnel, was somehow not met).

The whole area of medical privacy, which is where this post started, is a massively complex can of worms. Suppose I present myself to my doctor with a huge bruise on my leg. If the 'fact' that this bruise was caused by me skydiving (it was not) gets into 'the system,' then the cost of various insurance policies involving me could go even higher (yes, there is a data bank somewhere that stores information on your lifestyle and yes, insurance companies do consult it). In other words, if you're Bruce Willis and command $20 million per movie, you can do and say just about anything you like and not care who knows it. The rest of the world needs, for economic reasons, to be, to varying degrees, more circumspect.

Bilking the Elderly, With a Corporate Assist

Wonder why the American public has a dim view of corporate America? Read this article: Bilking the Elderly, With a Corporate Assist. First appeared in the New York Times.

Big name data firms doing business with crooks who target the elderly. And some banks less than eager to put a stop to abuses. Why aren't the privacy police all over this?