Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Friday, 20 February 2015

Microsoft Achieves Privacy Standard

Microsoft has achieved the globally recognized ISO/IEC 27018 privacy standard for Azure, Office 365, and Dynamics CRM Online. And here is the BSI certificate to prove it! These services are now aligned with the standard’s code of practice for the protection of Personally Identifiable Information (PII) in the public cloud.

Further Information

Announcement last Monday by Microsoft's General Counsel & Executive Vice President, Legal and Corporate Affairs, Brad Smith:
http://blogs.microsoft.com/on-the-issues/2015/02/16/microsoft-adopts-first-international-cloud-privacy-standard/
"With the Microsoft Cloud, you’re in control", he concludes, and it's hard to deny that's a step in a good direction.

Wednesday, 30 May 2012

Implied Consent (Cookies)

What Cookies are set by this Site?

This blog is a web site, within the meaning of the EU cookie law. It uses cookies. As such, it is governed by regulations set forth by the Information Commissioner's Office. What cookies are used here, and why?

Google Analytics

...is a web service provided by Google, Inc. Google Analytics sets a cookie in order to evaluate how visitors find and use the web site. This feature does not collect any personal information about you. I occasionally browse the reports generated by Google Analytics in order to to evaluate just how devastatingly unpopular my blog is.

Cookies from the Blog

...which resides on the Google-owned blogger.com platform. Blogger.com sets various cookies related to that service. I don't control the dissemination of the cookies set by the blogger.com platform, except for the Google Analytics cookies explained above.

Dog Biscuit's Trading Pages

If you visit my archived Yes & Led Zeppelin bootleg trading site, some of your search preferences will be saved by cookie for your next visit. The information saved in this cookie never leaves your browser. In fact that entire site comprises nothing but static HTML pages and a bunch of exclusively client-side JavaScript; there is no server component (yes, the entire database is in that script).

I am certainly not using cookies to gather information about your browsing habits or to push advertisements at you. If you have reason to think you picked up a tracking cookie here, it might mean I've been hacked; please contact me, for example by leaving a comment on a post - anonymously if you prefer.

This has been a public service announcement made necessary by a directive of the European Commission, confusing a worthy goal (securing web users' privacy) with a particular technology (cookies).

Saturday, 28 January 2012

On International Data Privacy Day

Europe to Google

Really, Google? You're getting rid of over 60 different privacy policies and replacing them with one that's a lot shorter and easier to read? Gee, thanks for doing that! I do have trouble with anything requiring an adult's attention span. What's that, your new policy covers multiple products and features, reflecting your desire to create one beautifully simple and intuitive experience? Terrific! You believe this stuff matters? Well that's great, just great.

First of all: why oh why, in the name of all that's hairy (and private); why did you ever send this notification to my Sky Mail account? I know you provide their service; but you know, that only makes them, not me, your customer. My contract is with Sky. They carry a privacy policy, to which I've agreed. Your opinions were neither sought nor welcome, and your policy (or policies) has (or have) no dominion over me there.

Secondly: do you never learn? You killed the much over-hyped Google Buzz in 2010 by deliberately implementing and obscuring such default privacy settings as would shame Facebook. You just killed off any last chance of social network success, by enforcing your account naming policy in Google+ (latest feeble "concessions" notwithstanding). Now you impose, without an opt-out, this unification of accounts across all Google services. What makes you think that I will continue to want to entrust any of my business correspondence, private letters, other documents and messages, contact lists, calendars, photographs, videos, even this blog, to such a capricious company? To you, who might delete everything I own at any time, on a whim and without appeal, simply because you suddenly decide you don't like my name?

Thirdly and finally: shut up, sit down, and pay attention. European citizens will not have privacy policies dictated to them by their service providers. Europe shall determine the privacy policy to be applied to, and by, its service providers. That, or else providers will no longer be providers to Europeans.

Sufficient Unto The Day

And the same applies across the pond. Facebook Live, in conjunction with the National Cyber Security Counsel, streamed last Thursday's NCSA event anticipating International Data Privacy Day (which is today). This included the keynote opening speech by Federal Trade Commissioner Julie Brill, but if Zuckerberg and co thought their coverage would smooth the ride, then it's safe to say she surprised them. The full text of her remarks can be read here:

http://www.ftc.gov/speeches/brill/120126datarivacyday.pdf

But here are a few samples.
Our enforcement actions in the privacy area are also a call to industry to put important privacy principles into practice. Facebook and Google learned this the hard way.

The Commission’s complaint against Facebook alleges a number of deceptive and unfair practices [...] These include the 2009 changes made by Facebook so that information users had designated private became public.

We also addressed Facebook’s inaccurate and misleading disclosures relating to how much information about users apps operating on the site can access [...] that the company misrepresented its compliance with the U.S.-EU Safe Harbor. And we called Facebook out for promises it made but did not keep: It told users it wouldn’t share information with advertisers, and then it did; and it agreed to take down photos and videos of users who had deleted their accounts, and then it did not.
Google received similar coverage of the FTC's complaint against them in the Buzz era. Both companies settled their respective complaints, and have been left embarrassingly subject to a decades-long regime of shame, rehabilitation, audit and assessment. Yet both seem determined to keep testing and risking their parole.

Facebook and Google: sufficiently evil, unto the day.

Wednesday, 25 January 2012

EU Data Protection Reform 2012

Europe Sets the Standard

The European Commission today proposed a comprehensive reform of the EU's 1995 data protection rules, to strengthen online privacy rights and boost Europe's digital economy. The text of the proposals (pdf) comprises a hefty 91 articles and supporting material, spread over 120 pages. Here, summarised in the form of annotated bullet points, are eight of the most important and/or controversial aspects from an initial reading of today's proposals.
  • One Rule for All
The intention is to introduce a single regulation (law) across all 27 member countries. This contrasts with the 1995 directive, which specified only the desired results. While these results were themselves binding, they were left to the individual states to implement, using their own chosen methods and mechanisms. Nobody seriously considers the outcome of that process, predictably enough a patchwork of 27 variegated rule sets, to have been a resounding success.
  • No Geographical Boundaries
Article 3 declares the scope of the new regulation, which would extend to anyone, anywhere in the world (yes you too, America!), involved in the processing of any personal information, relating to any EU citizen. And by personal information is meant not only names, dates, and places, but also technical data such as IP or Mac addresses; (explicitly) information of a genetic, biometric, or health nature; and so on. Service providers like Facebook or Google must accept these obligations in full, or else deny their services to EU citizens.
  • The Right to Erasure
Article 17 guarantees EU citizens the right to "extended erasure" of their personal data. Not only will the organization that processes personal data have to erase it on demand, but the they will also have to "take all reasonable steps, including technical measures" to get any copy, link, or replication on the Internet removed. Now, although in practice search engine data removal can mostly be automated, data removal from e.g. sites repeating CC-licensed Wikipedia content could be problematic.
  • Data Portability
Article 18 introduces the right to data portability - that is, to obtain a complete copy of stored or active data in a structured format. For example, this will allow users to switch between web mail systems with all their data intact.
  • Mandatory Assessments
Article 30 binds organizations to systematic security risk evaluations; unlawful forms of processing, unauthorized disclosure, dissemination or access, or alteration of personal data must be prevented. Here, the commission reserves the right to define: what constitutes the state of the art, for specific sectors and in specific data processing situations, in particular taking account of developments in technology and solutions for privacy by design and data protection by default.
  • Mandatory Notifications
Article 31, already being dubbed the Playstation Clause, requires organizations to disclose to their supervisory authority, effectively immediately, and in any case within a maximum of 24 hours, any personal data security breach. Sony famously waited one full week before telling their SEVENTY MILLION customers their personal data might have been compromised. This provision has of course come in for immediate and heavy criticism; 24 hours is not a lot of time for the kind of investigations that might be needed to avoid many false alarms. It might also be too short an interval to prepare measures to ensnare hackers, and serve only to warn them their attacks have been noticed and actioned.
  • Enforcement: Data Protection Officers
Article 36 provides for data protection officers, designated in regard to their knowledge on data protection laws, who will be independent, and will receive no instructions pertaining to the exercise of their function. These officers will be mandatory in three prescribed cases, namely:
  1. for any public authority or body;
  2. for any company permanently employing more than 250 persons; and
  3. for any company whose core activity consists of monitoring data subjects [qv].
One important corollary is the end of general notifications to local agencies, which measure alone should simplify the regulatory environment and save an expected 130 million € per annum.
  • Enforcement: Enormous Fines
Article 79 aims to give the legislation the necessary "teeth" to enforce these rules. This it does by providing individual national data privacy agencies with huge administrative sanctions. Various levels are countenanced, depending upon the particular violation, but the headline figures are: up to one million €, and up to 2% of an enterprise's annual worldwide turnover. Just to put that in context, to Microsoft in 2008, that would have come to 1.2 billion € plus tips.

Conclusion

It's a bold proposal, obviously designed to take the lead in the international areas of user privacy, data ownership, and data security. Certain of its provisions appear superficially to be quite "heavy" in their commercial import; some rather impractical, and maybe idealistic, although given the technological representation present and the consultancy that has taken place over the last 17 years, certainly not as naive as recent American proposals in adjacent fields (SOPA, ProtectIP). The Commission has clearly decided to take a stand against the piecemeal, partial, and largely failed implementations of its earlier directive. It will be very interesting to see how and where this extensive new structure flexes under the opposing pressures of commerce and politics in coming months.

Picture: Berlaymont building of the European Commission (Wikipedia).

Tuesday, 23 August 2011

FOADIACFWLS

Turning the Heat on the Cold Callers

Got another phone call yesterday from a lady in India, number withheld, asking if I had a Windows PC. None of your business, I informed her. It may be none of my business, but we are having a lot of trouble with the infections on your computer! she offered.

I thought about stringing her along, as I usually do; but I was busy. I had work to do. And I'm getting a bit tired of these organised criminal gangs of cold calling bastards, ripping off innocent and vulnerable users for hundreds of pounds with their fake antivirus scams. So on something of an impulse, I suggested: Fuck off and die in a car fire with leather seats!

Her immediate response was: You fuck off, you son of a bitch. [click] [bzzz]

Now I'm going to take a wild guess, that a genuine technical support organisation would have had a much higher level of professionalism than that. Maybe next time I'll go with I can tell you I don't have money. But what I do have are a very particular set of skills...

Oh! and also, wouldn't it be great, using a combo of tech, psych, and you know, Jeff Goldblum, to be able to upload a virus to them?

Thursday, 30 June 2011

Facebook: An Ugly Stupid Service

... designed to teach you to systematically undervalue your privacy.

Author and freedom fighter Cory Doctorow in great form on this subject, censorship, psychology, and education (from TEDxObserver):



Rediscovered this morning at this Boing Boing post - itself inspired by John Scalzi's Whatever.

TEDTalks are distributed under a Creative Commons (CC) licence.

Friday, 22 April 2011

Freedom House Report

UK: Worst of a Good Lot

Sponsored by the United Nations Democracy Fund (UNDEF), Freedom House just published the report Freedom On The Net 2011.

The good news: UK narrowly escapes relegation from the first division, retaining its Internet freedom status designation of "Free" (up to 30 points) with a nail biting 25 bad boys - up from 2009's (adjusted) total of 23 strikes. Only Italy and South Africa, at 26 points each, fare worse in this division.

Trajectory: Slight Decline

The full league tables are here:

http://www.freedomhouse.org/images/File/FotN/MainScoreTable.pdf

The most worrying aspect, for user rights activists anyway, emerges when these scores are analysed by the three broad UNDEF categories: obstacles to access, limits on content, and more disturbingly than those, violations of user rights.

1: Obstacles to Access

The first category assesses barriers to access, both infrastructural and economic; governmental blocking of apps and/or tech; and control over access providers. Clearly there is some room for mitigation in this category, as not all of a network's shortcomings are necessarily planned to be such. The UK however makes no capital of this mitigation, scoring but a single point here - the best performance in fact among all of the (now 37) nations covered by this year's report.

2: Limits on Content

Next the survey considers "content limits" - all forms of censorship, including website filtering and blocking, content manipulation, and the availability, diversity and usage of digital media for social and political activism and news. Here we find the UK scraping its arse along the bottom of the channel, tying with Italy on 8 points, only South Africa worse on 9.

The Internet Watch Foundation comes under particular and extensive criticism for its persistent technical incompetence, absence of clarity and transparency in its blocking and removal criteria and actions, its inadequate appeals process, and lack of any judicial (or even governmental) oversight.

3: Violations of User Rights

That just leaves legal protections, restrictions and prosecutions, surveillance, privacy, imprisonment, and harassment including physical attacks. No surprises here, with the UK emphatically at the bottom of the division on 16 points (second worst is Italy on 12).

The disastrous Digital Economy Act is highlighted, although the interim conclusion on that score states "In a positive development, the newly elected coalition government has promised to review and repeal a number of laws that negatively affect online free expression and privacy." As we have now seen this fail to happen, there must be doubt over the UK's overall "Free" status today.

Conclusions

Internet freedom in the UK is measurably deteriorating year by year, as evidenced by the decline in the "free" status reported by successive Freedom House biennial surveys. The country specific report provides the details:

http://www.freedomhouse.org/images/File/UK2011.pdf

Many of these reasons have already been well publicised, for example:
  • The expansive restrictions of English libel law are identified as having "...a significant chilling effect on both content producers and ISPs."
  • Further high profile cases, illustrating the frequently ass like nature of the law, are included; such as freedom to tweet your frustration about airport closures through the medium of mad parody, and police sanctioning of cybercafe snooping by proprietors.
It's hard to escape the conclusion that we have already seen the UK's final days at the top table of Internet freedom.

Wednesday, 8 December 2010

Microsoft's "Do Not Track" Response

IE9 Extreme Preview



On December 1st, the American Federal Trade Commission released its report on consumer privacy, the catchy "Protecting Consumer Privacy in an Era of Rapid Change" (PDF). As detailed in the commission's press release, there are two major talking points in the report:
  1. a proposed framework to balance (a) consumers' privacy interests, with (b) innovation relying on consumer feedback to develop new, beneficial products and services;
  2. a suggested “Do Not Track” mechanism, probably a persistent browser setting, providing control over collection of data about users' online searching and browsing activities.
Microsoft were quick off the mark, with Chief Privacy Officer Brendon Lynch responding that same day, via the legal and policy On The Issues blog, thanking the FTC (note: they also collaborated with the Article 29 Working Party in the EU) for the opportunity to participate in the roundtables forming the basis of the report, and after bigging up a little IE8, promising that Internet Explorer 9 will continue this focus and leadership on enabling our customers’ choice and control with respect to their online privacy, and to support the FTC’s continued work to engage all interested stakeholders on these important issues.

In the follow-up, Chief Privacy Strategist Peter Cullen presents a considered review of the issues, and of events leading up to the announcement of a Tracking Protection Feature in IE9, whence the above video demonstration.

Via: Associated Press.