Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Monday, September 16, 2013

Primer on Big Data Privacy in United States, Europe

Lawyers and technologists face many challenges from the proliferation of Big Data, and one of the most pressing is data privacy. Governments and businesses collect massive amounts and many types of data in ways seemingly unimaginable just a few years ago.

Friday, June 21, 2013

More Data on Privacy, but Picture Is No Clearer

Now, one by one, the companies are putting out data intended to reassure their users that the government gets information on just a tiny number of people. Over the weekend, Facebook and Microsoft released reports about the overall number of data requests they had received from United States law enforcement agencies. On Monday, Apple joined the chorus.

But rather than provide clarity, the companies’ disclosures have left many questions unanswered.

Apple, for example, said that from Dec. 1, 2012, through May 31, 2013, it received between 4,000 and 5,000 requests for data, covering 9,000 to 10,000 accounts, from American law enforcement agencies. Facebook said it got 9,000 to 10,000 requests for information about its users, covering 18,000 to 19,000 user accounts, in the last six months of 2012.

How many of those requests were from investigators seeking to sniff out the next terrorist?

The companies said they were not allowed to say, although they noted that the requests were commonly related to things like local police investigations and searches for missing children. That continuing restriction prompted both Google and Twitter to say they would not publish similar data until they could separate national security requests from the rest.

“We still don’t know what is allowed and how these programs are being implemented,” said Amie Stepanovich, director of the Domestic Surveillance Project at the Electronic Privacy Information Center, a nonprofit group.

But the companies were under immense pressure to announce something. If customers do not trust that Facebook or Microsoft or Google will keep private data confidential, they could use those services far less, undermining the companies’ business model.

“They’ve got to say to the consuming public that we care about your data, we’re going to do everything we can to preserve your data, and absent a national security contingency, no one gets access to your data,” said Adonis Hoffman, an adjunct professor at Georgetown University, who has served as a legal adviser to both the government and the advertising industry.

Pressing on the companies from the other side are the country’s intelligence agencies, which prohibit companies from disclosing virtually anything about the requests for national security data without permission.

“The nature of these orders are that they themselves are secret,” said one frustrated executive at a company involved in discussions with the government over disclosure issues.

Despite a week of arduous negotiations since the first reports about the National Security Agency’s seeking private data from nine major technology companies, the firms still cannot say much. “The government will only authorize us to communicate about these numbers in aggregate, and as a range,” Facebook wrote when it posted its data late Friday night.

Still, for tech companies that had never before released a transparency report, like Facebook and Apple, the data shed some light on their practices.

Apple, for example, noted in its report that it never gives the government copies of electronic conversations that take place over iMessage and FaceTime because they are protected by encryption that even Apple cannot break. “Similarly, we do not store data related to customers’ location, Map searches or Siri requests in any identifiable form,” the company said.

Google and Twitter, which had previously released transparency reports, said that lumping all law enforcement requests together, like Apple and the others did over the weekend, would be even less transparent.

Microsoft, which put out its first transparency report in March, decided to disclose the aggregate numbers but said it was pressing for further disclosure. Google, which published its first transparency report in 2010, has been the most aggressive in pushing for more disclosure. In March, it began breaking out data on one type of government request — National Security Letters, which request information on Americans — saying it had received 0 to 999 requests.

Permission to disclose that came after more than a year of negotiations with the government, and Google had been seeking permission to publish data on the other major type of national security request — information on foreigners demanded under the Foreign Intelligence Surveillance Act — even before news of Prism, the government’s surveillance program, broke, according to a person briefed on those discussions. It is still in talks to try to publish more detailed data, the person said.

By pushing to be able to publish more data on national security requests, the companies were hoping to shift the debate from the data exchange between the tech companies and the government to how the government can be more transparent about it.

Still, even if the government gives permission to break out FISA requests as a separate data point, the numbers are unlikely to tell the whole story. For every formal FISA request the government makes, intelligence agents are able to add names and additional search queries to that request for up to a year afterward, so the amount of data requested could be much higher.

Also, when the government gave Google and Microsoft permission to publish the number of national security letters they receive, it required them to publish the numbers in increments of 1,000, instead of the exact number, and would most likely do the same for FISA requests.

Monday, May 13, 2013

Privacy Breach on Bloomberg’s Data Terminals

The company confirmed that reporters at Bloomberg News, the journalism arm of Bloomberg L.P., had for years used the company’s terminals to monitor when subscribers had logged onto the service and to find out what types of functions, like the news wire, corporate bond trades or an equities index, they had looked at. Bloomberg terminals, which cost an average of more than $20,000 a year, are found in nearly every banking and trading company.

Bloomberg said the functions that allowed journalists to monitor subscribers were a mistake and were promptly disabled after Goldman Sachs complained that a Bloomberg reporter had, while inquiring about a partner’s employment status, pointed out that the partner had not logged onto his Bloomberg terminal lately.

The incident led to broader concerns about the line at Bloomberg between its lucrative terminal business and the hypercompetitive newsroom, threatening to undermine the credibility of both. In a secretive world that thrives on opacity, traders and financial firms jealously guard every speck of information about their activity to avoid tipping their hand on their trades and investments.

“On Wall Street, anonymity is critically important. Secrecy and the ability to cover one’s tracks is paramount,” said Michael J. Driscoll, a former senior trader at Bear Stearns who now teaches at Adelphi University. He added: “If Bloomberg reporters crossed that line, that’s an issue.”

The news gathering technique appears more widespread than the Goldman incident, which was first reported by The New York Post. A preliminary analysis at Bloomberg revealed that “several hundred” reporters had used the technique, a person briefed on the analysis said. (Bloomberg employs more than 2,400 journalists worldwide. A spokesman declined to comment on the analysis and said no reporters had been fired.)

There are also fears that the monitoring may have gone beyond Wall Street. Banking regulators at the Federal Reserve are examining whether their own employees were subject to tracking by Bloomberg reporters, according to people briefed on the matter. A spokeswoman for the Fed declined to comment.

There are now more than 315,000 Bloomberg terminal subscribers worldwide who rely on the desktop computer for research, trading, communication and a constant stream of financial information and news.

But as it turned out, what the subscribers were doing was not always confidential. Bloomberg reporters used the “Z function” — a command using the letter Z and a company’s name — to view a list of subscribers at a firm. Then, a Bloomberg user could click on a subscriber’s name, which would take the user to a function called UUID. The UUID function then provided background on an individual subscriber, including contact information, when the subscriber had last logged on, chat information between subscribers and customer service representatives, and weekly statistics on how often they used a particular function. A company spokesman said both of those functions had been disabled in the newsroom.

Terminals never allowed journalists to see specific securities or trades, but even general hints of what users are searching could provide a glimpse into Wall Street’s thinking — powerful currency in the competitive world of financial journalism. Daniel L. Doctoroff, chief executive of Bloomberg L.P. and a close confidant to the company’s founder, Michael R. Bloomberg, said in a memo to employees that “client trust is our highest priority and the cornerstone of our business.” Mr. Bloomberg stepped away from day-to-day operations when he became mayor of New York City.

Last month, the company further centralized its data security efforts, including appointing Steve Ross, a senior executive, to the newly created role of client data compliance officer.

“To be clear, the limited customer relationship data previously available to our reporters never included access to our trading, portfolio, monitor, blotter or other related systems or our clients’ messages,” Mr. Doctoroff said. He posted a damage control message to clients on the Bloomberg terminal and blog, calling the reporting practice a “mistake.”

Nathaniel Popper contributed reporting.

Monday, December 24, 2012

Sunday, October 21, 2012

As Microsoft Shifts Its Privacy Rules, an Uproar Is Absent

Microsoft instituted a policy on Friday that gives the company broad leeway over how it gathers and uses personal information from consumers of its free, Web-based products like e-mail, search and instant messaging.

Almost no one noticed, however, even though Microsoft’s policy changes are much the same as those that Google made to its privacy rules this year.

Google’s expanded powers drew scathing criticism from privacy advocates, probing inquiries from regulators and broadside attacks from rivals. Those included Microsoft, which bought full-page newspaper ads telling Google users that Google did not care about their privacy, an accusation it quickly denied.

The difference in the two events illustrates the confusion surrounding Internet consumer privacy. No single authority oversees the collection of personal information from Web users by Internet companies. Though most companies have written privacy policies, they are often stated in such broad, ambiguous language that they seem to allow virtually any use of customers’ personal information.

Web companies like Microsoft and Google have been moving aggressively to expand their abilities to gather and sort information about individuals’ habits and interests — even as Congress, federal regulators and the Obama administration have been seeking ways to protect Internet users against unwanted privacy incursions.

Microsoft’s policy, which it calls its Services Agreement, allows it to analyze customer content from one its free products and use it to improve another service — for example, taking information from messages a consumer sends on Windows Live Messenger and using it to improve messaging services on Xbox. Previously, that kind of sharing of information between products would not have been allowed under Microsoft policies, which limited the use of data collected under one of its products to that product alone.

Microsoft has promised, however, that it will not use the personal information and content it collects to sell targeted advertising. It will not, for example, scan a consumer’s e-mails to generate ads that might interest the user. Google does that, and expanding its ability to draw on that content was part of the reason Google changed its privacy policy this year.

But the new Microsoft policy does allow for such targeted advertising. Microsoft promised not to do so in blog posts and e-mails informing its customers about the change, but not in the formal policy. That has some privacy advocates nervous.

“What Microsoft is doing is no different from what Google did,” said John M. Simpson, who monitors privacy policy for Consumer Watchdog, a California nonprofit group. “It allows the combination of data across services in ways a user wouldn’t reasonably expect. Microsoft wants to be able to compile massive digital dossiers about users of its services and monetize them.”

Jack Evans, a Microsoft spokesman, says the company’s plans are benign. He differentiates between the Services Agreement, also known as the terms of use, that was changed on Friday and the company’s Privacy Policy, which was last updated in April.

“Over the years, we have consistently informed users that we may use their content to improve the services they receive,” Mr. Evans said in a written statement. “For instance, we analyze content to improve our spam and malware filters in order to keep customers safe. We also do it to develop new product features such as e-mail categorization to organize similar items like shipping receipts in a common folder, or to automatically add calendar invitations.

“However,” he added, “one thing we don’t do is use the content of our customers’ private communications and documents to create targeted advertising. If that ever changes, we’ll be the first to let our customers know.”

Microsoft’s new services agreement affects only its free, Web-based products, not the software programs that individuals and companies buy off the shelf for home or business use. It covers Hotmail, and its related e-mail service, Outlook.com, but not the Outlook e-mail and calendar program that is individually loaded onto computer hard drives and widely used by corporations. Bing, its search engine, is covered, but Internet Explorer, its browser, is not.

Microsoft’s pledge not to use the data from its Web services to target advertising has some credibility, given the company’s broader privacy initiatives. The company has said it will include a “do not track” feature in its new Internet Explorer 10 Web browser that prevents online advertising companies from monitoring the browsing habits of users so they can target promotions. Microsoft has made “do not track” the default setting on the new version of Explorer, a move that has caused a firestorm among online advertising companies.

Saturday, October 6, 2012

Fan Sites Settle Children’s Privacy Charges

In a complaint, the Federal Trade Commission said that Artist Arena, the operator of the sites, violated a children’s online privacy rule by collecting personal details — like the names, e-mail addresses, street addresses and cellphone numbers — of about 101,000 children aged 12 or younger without their parents’ permission.

The law, called the Children’s Online Privacy Protection Act, or Coppa, requires operators of Web sites to notify parents and obtain verifiable parental consent before collecting, using or disclosing personal information about children younger than 13.

The sites are BieberFever.com, SelenaGomez.com, RihannaNow.com and DemiLovatoFanClub, which is no longer in operation. The agency did not accuse the pop stars themselves of any wrongdoing.

At a conference on children’s marketing in New York on Wednesday, Edith Ramirez, a member of the F.T.C., said the settlement still required ratification in court.

As part of the registration process, the four fan sites asked users to submit personal details including their birth dates that would enable members to create online profiles, post messages and sign up for newsletters about the pop stars, the complaint said. Because the sites therefore knew the children’s ages, the F.T.C. charged, the company had knowingly collected information and failed to properly notify their parents.

“These were fan sites that knew that a very substantial percentage of users were 12 or under,” said David C. Vladeck, the director of the F.T.C.’s bureau of consumer protection. “There is really no excuse for violations like these.”

Artist Arena, a division of the Warner Music Group that manages artist fan clubs, neither admitted nor denied the agency’s allegations. Warner first invested in Artist Arena in 2007 and bought the company in 2010. James Steven, a spokesman for Artist Arena, declined to comment. The fan sites no longer allow children under 13 to register as members.

The proposed settlement comes at a time when the agency is preparing to extensively strengthen the children’s online privacy protection rule for the first time since its introduction more than a decade ago.

In an effort to keep pace with innovations like mobile apps and facial recognition technology, the agency has proposed to widen both the kinds of data about children that would require parental consent and the kinds of operators — like advertising networks or data miners — whose activities could be subject to the rule.

Last week, major corporations including Apple, Facebook, Google, Microsoft and Viacom responded, submitting public comments to the F.T.C. in which they argued that some of the proposed changes were so unworkable that they could deter companies from providing sites and online services to children.

“To ensure that the Internet continues to be a robust and enriching place for children, the commission should avoid promulgating rules that frustrate operators’ ability to continue providing the same quantity and quality of sites and online services, including those that are directed to children,” Michael D. Hintze, Microsoft’s chief privacy counsel, wrote in comments to the agency.

But the case of the pop star Web sites bolsters the viability of at least one of the agency’s proposals: that child-friendly sites aimed at audiences of varying ages must either assume all users are under 13, or screen users for age to identify those for whom data collection requires prior parental consent.

Some companies, like Viacom, have objected to this proposed change, saying that such a screening process might cause some sites to block children from participating or deter some children, who might then end up on inappropriate adult sites that do not screen users for age.

But BieberFever.com and the other fan sites, even if they failed to properly notify parents, seemed to be able to collect information on tens of thousands of children who willingly identified themselves as being younger than 13.

“Marketers need to know that even a bad case of Bieber Fever doesn’t excuse their legal obligation to get parental consent before collecting personal information from children,” Jon Leibowitz, the chairman of the F.T.C., said in a statement. “The F.T.C. is in the process of updating the Coppa rule to ensure it continues to protect kids growing up in the digital age.”

Each of the fan Web sites had slightly different registration processes. But the agency charged that Artist Arena had falsely claimed that it would not activate a child’s registration without parental consent.

SelenaGomez.com, for example, required users who wanted to sign up for the online fan newsletter to enter information like their e-mail address, birth date, parent’s name and e-mail address, and in some cases full name, city, state and ZIP code as well, according to the complaint. The child then received an on-screen notice that said “registration successful” and was able to edit his or her online profile, the complaint said.

The site sent the child’s parent an e-mail saying that it needed parental consent to complete the child’s registration. According to to the complaint, the e-mail falsely stated that if a parent did not want to approve the child’s registration, “you do not need to do anything else: simply do not click on the above link.” Regardless of the parent’s actions, the site had already registered the child, the complaint said.

From April 25, 2010, to Aug. 2, 2011, SelenaGomez.com registered 10,026 children for its fan newsletter and 2,196 children for its fan club. The site also collected and kept information on 48,531 children who started but did not finish the registration process, the complaint said.

As part of the settlement, Artist Arena agreed to delete the personal information about children under 13. The company also agreed that the sites, in places where they collect personal data, would prominently display links to a federal Web site, www.OnGuardOnline.gov, that offers information on protecting children’s privacy online.

Saturday, September 29, 2012

F.T.C. Moves to Tighten Online Privacy Protections for Children

The moves come at a time when major corporations, app developers and data miners appear to be collecting information about the online activities of millions of young Internet users without their parents’ awareness, children’s advocates say. Some sites and apps have also collected details like children’s photographs or locations of mobile devices; the concern is that the information could be used to identify or locate individual children.

These data-gathering practices are legal. But the development has so alarmed officials at the Federal Trade Commission that the agency is moving to overhaul rules that many experts say have not kept pace with the explosive growth of the Web and innovations like mobile apps. New rules are expected within weeks.

“Today, almost every child has a computer in his pocket and it’s that much harder for parents to monitor what their kids are doing online, who they are interacting with, and what information they are sharing,” says Mary K. Engle, associate director of the advertising practices division at the F.T.C. “The concern is that a lot of this may be going on without anybody’s knowledge.”

The proposed changes could greatly increase the need for children’s sites to obtain parental permission for some practices that are now popular — like using cookies to track users’ activities around the Web over time. Marketers argue that the rule should not be changed so extensively, lest it cause companies to reduce their offerings for children.

“Do we need a broad, wholesale change of the law?” says Mike Zaneis, the general counsel for the Interactive Advertising Bureau, an industry association. “The answer is no. It is working very well.”

The current federal rule, the Children’s Online Privacy Protection Act of 1998, requires operators of children’s Web sites to obtain parental consent before they collect personal information like phone numbers or physical addresses from children under 13. But rapid advances in technology have overtaken the rules, privacy advocates say.

Today, many brand-name companies and analytics firms collect, collate and analyze information about a wide range of consumer activities and traits. Some of those techniques could put children at risk, advocates say.

Under the F.T.C.’s proposals, some current online practices, like getting children under 13 to submit photos of themselves, would require parental consent.

Children who visit McDonald’s HappyMeal.com, for instance, can “get in the picture with Ronald McDonald” by uploading photos of themselves and combining them with images of the clown. Children may also “star in a music video” on the site by uploading photos or webcam images and having it graft their faces onto dancing cartoon bodies.

But according to children’s advocates, McDonald’s stored these images in directories that were publicly available. Anyone with an Internet connection could check out hundreds of photos of young children, a few of whom were pictured in pajamas in their bedrooms, advocates said.

In a related complaint to the F.T.C. last month, a coalition of advocacy groups accused McDonald’s and four other corporations of violating the 1998 law by collecting e-mail addresses without parental consent. HappyMeal.com, the complaint noted, invites children to share their creations on the site by providing the first names and e-mail addresses of their friends.

“When we tell parents about this they are appalled, because basically what it’s doing is going around the parents’ back and taking advantage of kids’ naïveté,” says Jennifer Harris, the director of marketing initiatives at the Yale Rudd Center for Food Policy and Obesity, a member of the coalition that filed the complaint. “It’s a very unfair and deceptive practice that we don’t think companies should be allowed to do.”

Danya Proud, a spokeswoman for McDonald’s, said in an e-mail that the company placed a “high importance” on protecting privacy, including children’s online privacy. She said that McDonald’s had blocked public access to several directories on the site.

Last year, the F.T.C. filed a complaint against W3 Innovations, a developer of popular iPhone and iPod Touch apps like Emily’s Dress Up, which invited children to design outfits and e-mail their comments to a blog. The agency said that the apps violated the children’s privacy rule by collecting the e-mail addresses of tens of thousands of children without their parents’ permission and encouraging those children to post personal information publicly. The company later settled the case, agreeing to pay a penalty of $50,000 and delete personal data it had collected about children.

It is often difficult to know what kind of data is being collected and shared. Industry trade groups say marketers do not knowingly track young children for advertising purposes. But a study last year of 54 Web sites popular with children, including Disney.go.com and Nick.com, found that many used tracking technologies extensively.

“I was surprised to find that pretty much all of the same technologies used to track adults are being used on kids’ Web sites,” said Richard M. Smith, an Internet security expert in Boston who conducted the study at the request of the Center for Digital Democracy, an advocacy group.

Using a software program called Ghostery, which detects and identifies tracking entities on Web sites, a New York Times reporter recently identified seven trackers on Nick.com — including Quantcast, an analytics company that, according to its own marketing material, helps Web sites “segment out specific audiences you want to sell” to advertisers.

Ghostery found 13 trackers on a Disney game page for kids, including AudienceScience, an analytics company that, according to that company’s site, “pioneered the concept of targeting and audience-based marketing.”

David Bittler, a spokesman for Nickelodeon, which runs Nick.com, says Viacom, the parent company, does not show targeted ads on Nick.com or other company sites for children under 13. But the sites and their analytics partners may collect data anonymously about users for purposes like improving content. Zenia Mucha, a spokeswoman for Disney, said the company does not show targeted ads to children and requires its ad partners to do the same.

Another popular children’s site, Webkinz, says openly that its advertising partners may aim at visitors with ads based on the collection of “anonymous data.” In its privacy policy, Webkinz describes the practice as “online advanced targeting.”

If the F.T.C. carries out its proposed changes, children’s Web sites would be required to obtain parents’ permission before tracking children around the Web for advertising purposes, even with anonymous customer codes.

Some parents say they are trying to teach their children basic online self-defense. “We don’t give out birth dates to get the free stuff,” said Patricia Tay-Weiss, a mother of two young children in Venice, Calif., who runs foreign language classes for elementary school students. “We are teaching our kids to ask, ‘What is the company getting from you and what are they going to do with that information?’ ”