privacyprivacy

Thoughts on dataliberation.org

Announced today over at the Google Public Policy blog is "DataLiberation.org: Liberate your Data!"

We're a small team of Google Chicago engineers (named after a Monty Python skit about the Judean People's Front) that aims to make it easy for our users to transfer their personal data in and out of Google's services by building simple import and export functions. Our goal is to "liberate" data so that consumers and businesses using Google products always have a choice when it comes to the technology they use.

I may be wrong, but I do believe this is the first time I read about an entire team within such a big firm entirely dedicated to the issue of data portability. The irony here is that Google's track record in the past hasn't been perfect - as I've highlighted more than once - and as much as the decidedly non-Googlish branding and informal tone seem to conspire to lend the project a certain dissociation from the big G, it is very much real, as noted by the aforementioned Public Policy post and the wealth of information on how to delete / export your data from Google services.

The slow, dumb rise of Facebook "Hackers"

Original article.

According to Trend Micro, an internet security firm, more than 40% of teens are "social hackers".

Sigh. I remember a day when being a hacker meant that you had to actually know how to do something.

The "social hackers" are still split by gender though. Boys are twice as likely to go for the profile assassination, while girls are three times more likely to go straight for the PayPal.

What can I say - boys want power, girls love the bling. It's the nature of things.

The "new" idea of "social hacking" is that many social details are on view via social networking sites such as Facebook. A competent social hacker can find information which tends to give away security question answers.

And an incompetent target will use public information in their own security questions and password. And deserve everything they've got coming.

Rik Ferguson of Trend Micro said, "It's the online version of kids breaking into school to change their reports, it's just so much easier now."

Breaking into school to change your report card took planning, skill and cojones.

Anything that can be done from behind the safety of a computer screen requires nothing more than an Internet connection, a decent mix of self-loathing and lack of self confidence, and maybe some Red Bull. Sure, maybe a "social hacker" (*cough* *hack* *cough*) can find out where you live and hang out by hacking into your Facebook profile, but then what? Years of sitting on a couch with his laptop drinking latte mochaccinos will have left his body too weak and atrophied to pose any real threat.

I, on the under hand, can find out where you live, chase you down because I can run faster than you, and then dead-lift you off a bridge.

See kids? It's about branching out.

Oh, and it's called social engineering, and it's not new at all.

Social Networks I do use indeed

Everyone and their cross-eyed cousin already knows that I don't use Facebook. But it's not not untrue that I don't use any social networking services while I am bodysurfing on the Internets. I happen to visit a quite a few on a day-to-day basis - but unlike most of the folk on Facebook and the like, little things like “privacy” and “usefulness” come into play when I'm making a decision about whether or not I should cuddle up to the newest, trendiest Totally Interesting Thought-provoking Social Network (hereafter referred to as “TITSnet”).

booya bitches

Not all social networks are created equal, and I don't treat them all the same either. There are networks where I'll use my full name as my username, and there are a couple very good reason for this - pseudonyms are for cowards, serial killers and fairies, and I want an easy way to keep track of all the stupid shit I say on the Internet. Fact: Over 100% of the corwardly / racist / ignorant comments that people see fit to post for the world to see are done behind the relative safety of anonymity. I think anonymity is a precious commodity not to be wasted on triflin' things like racism and such, so I save my pseudonyms for more important things like international espionage and / or dating websites. Sometimes I'll kill two birds with one stone and show off my multiple passports to my blind date and then we'll eat the birds.

I get asked - yes, like, everyday - about which social networks I recommend / use. The short answer is none / lots. The long answer is "I'm about to tell you, so pipe down!". So, in the interest of pouring some much-needed chlorine into the e.coli infested swimming waters of the Internet, please enjoy this small collection of my S.N.O.T.S (Social Networks Of The Season):

Facebook, privacy, control, and creepiness

So, some anonymous dude (who is actually not quite as anonymous as he'd like to believe) left some comments on my nearly 2-year-old post about closing my Facebook account, then decided to try and prove a point about his views on privacy by cleverly looking up my cell number (which is public) and doing a Google search to find a photo of me (which is also public).

The point he ended up proving, of course, is that he's a slightly creepy person who calls up random people about an old blog post they wrote when he disagrees with them. Also, he knows how to perform the shit out of a Google search.

I was driving Mir - much more stalker-worthy material than I, if you ask me - to pick up some food for her dog, when my cell rings:

  • Is this Steven Mansour, from stevenmansour.com, about the facebook post?
  • Yup, who's this?
  • Just wanted to tell you that nothing is private, case in point I found your phone number, I'm not trying to stalk you or anything but you know how easy it is to find information about people on the internet.
  • Ok...
  • Ok.
  • Goodnight!
  • *click*

Followed by Mir and I looking at each other with a quizzical "WTF?".

So yes - it's true! You can find lots of information about people on the Internet, off and on Facebook. Especially if that information is, you know, supposed to be public in the first place. I don't hide my contact information from the world, and even if I did, a simple whois lookup on anyone (including Mr. "Anonymous") would be more than enough to get any more information about anyone else. That's why closed networks like Facebook are so insidious - people put more information on there than they would on an obviously public page such as this one, with the misconception that only their friends and family can access it. They - especially young people - are duped into jumping into bed with Facebook with the idea that they can retain control over who gets to access what.

They can't.

So what can we keep private? Lots. I'm pretty open - I make a point to use my real, full name in online games or on the handful social networks left that are genuinely useful to me; it makes it easier for me to keep track of and aggregate everything I'm doing. On others - ones where I prefer remaining private - I always use a pseudonym, encryption and TOR. There is data (music, videos, games) on my home PC that you'd probably be able to access without much difficulty if you really wanted to get at my Lionel Ritchie Paris Hilton Audioslave high-fidelity OGG files. Then there is other data and information that anyone would have a bitch of a time trying to find, decipher, crack and decrypt.

So, what's the point? Well, that problems with privacy control and things like identity theft have been around long before the Internet ever came to be, and will stick around long after the Internet has withered to dust copper flakes. That it's about corporate responsibility, education, and governance - not paranoia. That anyone with a phone book and fingers can find whoever they're looking for. And finally, whether you live down the street or in Florida, that you shouldn't look up my number and call me unless you've got something to say.

Or unless you're a blond-haired blue-eyed college cheerleader from the south. Then, you can just ask.

privacy

Concordia shuts down wired Facebook access

Facebook access at Concordia available on wireless network only

Starting September 2008, access to the social networking service Facebook will be available only on Concordia’s wireless network.

The service will no longer be accessible from desktop computers with only a wired connection to the Concordia University network.

[...]

Concordia’s network administrators are not trying to block access to Facebook, but to manage the manner in which the Concordia community accesses the service.

The university has decided to implement the restriction because of concerns that the continuing reliability of the Concordia wired network could be compromised because of spam, viruses and leaks of confidential information related to use of the social networking site.

I'll admit that the given reasons behind the restrictions are obviously bullshit / filler text (spam and viruses aren't any more likely to come from Facebook than from other web service that users are allowed to access). The real reasons behind this change are somewhat more political and pragmatic: control the amount of time that students, staff and faculty spend wasting their working hours on Facebook. If they've made this change there probably was already a problem with users using Facebook in excessive or inappropriate ways (which, of course, Facebook is designed to encourage).

Indeed, pretty much everyone I know who uses Facebook in any useful way has become less productive than they were before joining Facebook. Either way, Concordia is to be commended for stepping in and making what may well be a very unpopular decision for reasons that those without all the facts may not fully understand yet - this is, in essence, one of the principle roles of any government.

I try to steer clear of statements like "the ends justify the means", but I think it might very well apply here.

(via Christine)

Dude sued for fake Facebook profile

Sigh. I suppose it's normal that my first post in a few weeks here would be about Facebook.

So, some dude set up a mischievous fake Facebook profile for some other dude in London, and ended up having to pay £22,000 in damages for libel and breach of privacy.

A businessman whose personal details were "laid bare" in fake entries on the Facebook social networking website has won a libel case at the High Court.

Mathew Firsht was awarded £22,000 in damages against an old school friend, Grant Raphael, who created the profile.

I'm not exactly sure how much £22,000 equals in real money, but I think the conversion process in my head puts it hovering somewhere near a gazillion dollars.

Why is this semi somewhat passingly important?

CBC Daybreak Interview

Just a quick note to let y'all know that I'll be speaking on CBC's Daybreak tomorrow (Thursday) morning at about 7:40 AM.

It's at 88.5 on the FM dial for those of you who don't know. You can also listen live online on the Daybreak website if you're not local.

I'll be talking about Internet policy, privacy, and - you guessed it - Facebook. Smile