Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, September 8, 2011

9/11's (and Google's) effect on technology

Marketplace had a great piece today on Alessandro Acquisti's work on his Face Matching Algorithms of Dooooom. As in, he takes a photo of the NPR interviewer with his iPhone, and it immediately pulls up everything about the guy.

From a technological perspective it's all fascinating, but from a privacy perspective it's downright terrifying. This is all reflects a lack of citizen and governmental understanding of data. You share some information with your grocery store, get a frequent shopper card, you don't realize how this data is being brokered, merged, sold, to countless numbers of people. Furthermore, a photo you post with some friends at a party, even if you don't tag it-- all you need is one identifiable photo (Driver's license registry?), and BOOM, there it is.

Add this to fraudulent SSL certificates running amok, and I really feel like we're up a creek.

This is a great time to become a security researcher. Grad students, forget all those other CS topics - do security. Or systems. Or both! There are plenty of important problems that need solving ASAP.

Wednesday, July 6, 2011

Burn after reading

I received an unencrypted email yesterday which had in the title "CONFIDENTIAL AND PRIVATE". It also had instructions that if I were to print out its PDF attachment, I must shred it immediately after reading it.

Clearly we Computer Scientists are doing a bad job with public outreach here. So, hey, chance to educate.

Email is hardly ever secure. I say 'hardly ever' because it is possible to encrypt email, and it is also possible to send email on secure, closed networks, free from the pull of the internet sea.

But most of the average email your average person is sending is being sent in the clear, unencrypted. This is a lot like walking down the street holding a big sign with the contents of your email. Which is recorded by a camera. And a lot of people can watch the video at any point in the future. Also, the video is archived in a library 4ever*.

The metaphor of a paper postal letter may have made sense about 15-20 years ago, but it's no longer valid. A letter sent by physical mail is much harder for lots and lots of people to read, unless someone tampers with the mail, makes a photocopy, etc. It also had ephemerality - you really could burn it after reading.

I pretty much operate under the assumption that any determined person can read my email and all unencrypted files on my computer. I also assume any emails I send could end up being forwarded to others, printed out, or posted on some blog somewhere.  Err on the side of caution, and all.

--------
(*) Ok, except a library is a bad metaphor because it's not necessarily easy for people to find this video. (aka. "security through obscurity"). Nor is it necessarily around for ever, but it could be.

Wednesday, April 27, 2011

Sony! Soni! Soné!

I am very disappointed in you.

You get hacked, have 77 million credit and debit card numbers stolen but wait one week before telling your customers. And now you face a class action lawsuit, a senator demanding answers, and possibly lots of "angry mums". (Watch out for those angry mums! Like Bob! Or is he a daisy?)

And, given your track record on security (i.e., installing rootkits on customer's machines), you're not really in a good place right now.

The right thing to have done would have been come clean initially. Be honest with your customers from the start - "We stored information we shouldn't have, we didn't encrypt your data, and it's all been stolen. Call your bank and change your debit and credit card numbers."

Other companies, please take note. Only store the data you need to. Tighten your existing controls.  Do not think yourself invulnerable, or something's gonna getcha, little Walter.

Friday, March 18, 2011

RSA hack - Trouble with a capital T

It seems RSA was hacked today. This means, if you use one of those nice little SecureID fobs to connect to your corporate server or bank, it may have been compromised.

This is a big deal. Using two-factor authentication is an industry gold standard, and RSA is one of the most prolific manufacturers of such fobs.

Securious has a nice write up of the fact vs. fiction surrounding the attack, including a note that this was an APT attack, not some random script kiddie in Germany.

I'm not trying to stir up panic here, but if you work with sensitive data, this might be a good time to add another layer of encryption on it*. There are lots of free solutions, like True Crypt, or if you're on a Mac the easiest thing to do is create a password protected disk image. Remember not to use the same password for your encrypted disk partition that you use for anything else (logging in, email, etc.). But also don't lose this password - if you do then your data is "irrevocably lost". Whee!

* Obviously all the "check with your (IT) doctor" disclaimers apply here.

Thursday, February 17, 2011

Those who trade security for coffee deserve neither

A recent article reports results from a survey which shows, among other things, that companies are spending more money on coffee for their employees than securing their "web applications", whatever that means. (In this day and age, is there any application that doesn't have at least some network-facing capability?)

In any case, being an advocate of both strong coffee and strong encryption, I can understand the dilemma. You need to caffeinate your sysadmins so they can keep up their daily grind of writing Javascript, while still allowing them to esperesso themselves that, actually, not beaning standards compliant is going to cause a latte problems.

(Coffee pun hat tip)

Tuesday, February 15, 2011

Check yo self

FSP's post today on getting blogged about reminded me of something I meant to write about awhile ago. And that is - ways to actively monitor how others talk about you publicly.

I highly suggest setting up several Google Alerts. This is a great service that emails you whenever someone mentions your name on a site Google indexes*. You can set this up for general search results, as well as for blogs, twitter, and news articles.

You also can set up citation alerts in Google scholar, which will tell you if someone has cited you generally, or you can set one up for individual papers if you're so inclined.

For these alerts, I have quite a few variations of my name, for example:
(Ada A. Lovelace) OR (A. Lovelace) OR (Lovelace, A.) OR (Lovelace AND Analytic Engines) 
etc.

I've found these alerts invaluable, because over the years I have given several talks where my privacy requests were violated. This happened along the lines of:
"Can we have a copy of your slides?"
"No."
"Pretty Please? It's for those poor undergraduate students who couldn't attend your talk today."
"No."
"Pleeeeease? We promise not to put it on the internet."

Because I'm a pushover when it comes to pleas about wee undergraduate students, I acquiesced, and sure enough two weeks later, surprise! There are my slides.

But these alerts have also relayed good news, for example, I've learned of news articles about my research I didn't know existed, learned of entirely unexpected paper citations, and, I also discovered a really juicy paper basically trashing one of the subfields I work in. (Not trashing me specifically, just saying something factual about my publication frequency).

So, these alerts are worth setting up. Unless you're the academic equivalent of Lindsay Lohan, in which case I do not recommend this service.

(*) If you're a Bing person, sorry - there are no Bing alerts at present. Their academic.research.microsoft.com site offers RSS subscriptions, though I imagine there is a fair bit of overlap with Google scholar. 

Friday, October 22, 2010

Pseudo-anonymity: Defense

Back to our FIFO queue! Today we have...

pop(Pika):
The other day I made a mistake and left a comment on someone's blog under my own first name instead of the pseudonym. I deleted it as soon as I noticed, but then I got a bit paranoid if anyone could see who I am just from that one single comment. So I googled my first name.

And got the shock of my life.

I am there, my workpage pops up immediately, right on the first page of results... 
How googleable are you? 
I meant to post about this topic months ago, but found myself struggling with how to appropriately discuss it. The problem with me writing a post like this is I could give hints on how to 'out' someone who is blogging/internetting pseudo anonymously, and I don't really want to do that for obvious reasons. The good news is that most of the techniques to de-anonymize bloggers remain firmly in the realm of researchware, but I wouldn't bank on that being the case for too much longer.

Instead, I'd like to suggest a few defensive things pseudo anonymous netizens can do to help maintain their anonymity. Some of these suggestions are social, some are technical, but nearly all are grounded in the privacy literature.

1) Don't tell anyone you know in your open (non-anon) life about your pesudo-anonymous identity/blog. Someone will tell someone, and the next thing you know someone posts something somewhere revealing your real name. People are awful at keeping secrets, and if you ever become a famous (or controversial) blogger you run the risk of someone accidentally (or purposely) outing you.

2) Don't write things that would be devastatingly embarrassing for you if you were outted. As I said, right now it's easy to be a little bit anonymous online, but I would not at all bet on that trend continuing. I saw a paper presented at a conference recently that scared the crap out of me, so do take heed.

3) If you blog, turn on the comment approval settings. If you use facebook or other social networks, even if it's under your pseudonym, turn on the settings to approve your wall posts / picture sharing / etc. Seriously, lock that puppy down. Better to introduce a delay then suffer the consequences of someone commenting, "Great post, Imelda D! See you at lunch tomorrow."

4) Never forget: once it's out there, it's out there. There are no takebacks in the era of RSS feeds and google. There is no ephemerality. Be extra careful when you post something not to sign your real name, discuss something specific about your location, etc. You have absolutely no idea who is subscribed to get a blog's comments, and once their RSS reader grabs it, there's nothing you can do.

5) There is a lot of literature on how people can infer your identity based on your interests, social network friends, etc. (See references in this post). Some people who work in the security/privacy fields make their name on this kind of thing, no pun intended. Again, this supports my first suggestion to keep your pseudo-anonymous life and your non-anonymous life as separate as possible. If you need to share something personal, change some details here and there. You know, say you love dogs instead of cats.

6) Use Tor, or another anoymizer web browsing service when visiting other people's blogs/websites. Definitely anonymize your IP when commenting elsewhere under your pseudonym. While Google Analytics provides a slight layer of anonymity and lets your individuality get lost in the noise, not all trackers are so gracious. Remember, every time you hit a webserver, your IP address is logged. It is trivial to deduce who you are based on your IP. So you are completely relying on the good graces of the website/blog owner not to out you. By using an anonymizer, you can at least protect yourself a bit better.

I think that's it for now. Happy pseudo-anonymous blogging!

Friday, July 23, 2010

The google gossip trade

Photo by Sklathill
The NYT has a fantastic article in this weekend's magazine on something I have been stamping my feet about for years. It is about how the permanence of our digital lives (a lack of ephemerality) is significantly affecting our physical day-to-day lives, often in adverse ways.  (I unfortunately don't have the time to summarize the article - please go read it, it's very well written.)

Our world has not only become a panopticon, but it is a permanent, indexed, fully searchable one. This is not merely your employer seeing a photo of you being goofy at a party, this is a permanent record of your daily existence of which you increasingly have absolutely no control over.

The right to anonymity and ephemerality of action is something we take for granted when acting in the physical world. The problem is that the digital world does not in any way reflect these assumptions. Not only is everything you do online often fully archived and linkable to you, but with the advent of social media everything other people post about you is too.

There are a ton of papers in the literature about how online activities we believe to be anonymous are not at all. Seemingly innocuous and anonymous net activity can reveal one's search queries, social security number, phone number, sexual orientation, political views, travel plans, oh, and, one's real identity when they thought they were anonymous. I think I meet a new researcher mining Twitter for gold just about every other day. The fact is, computer scientists are clever folks, and coming up with these kinds of algorithms is quite easy.  And they're the good guys/gals.

Being a private person, I find these papers terrifying. But when I talk to many people about it, they say, "I don't care. I have nothing to hide." This is a selfish and, frankly, privileged attitude to have. For people living in countries with authoritarian governments, anonymity is often the only path to freedom. Imagine the Underground Railroad or hidden Jews during the Holocaust being successful with 24/7 video surveillance, with automatic face tagging being posted to live feeds on Facebook. Or more recently, imagine someone using these techniques to out Iranian green party members. They'd be killed. And I don't think the counter-argument holds; I doubt such a permanent panopticon will suddenly engender good behavior.

One of the best things about our freedom as human beings is that other people quickly forget our stupid, embarrassing moments. People don't always know who we are everywhere we go. We can take many risks freely. But, increasingly, neither our technology nor our legislation is supporting us in this. And that, in my opinion, is very dangerous indeed.