Ask the Decoder: How are algorithms telling our stories for us? (Al Jazeera, 8 Oct 2014) – Jean Yang went on a big trip through Europe this summer, from Edinburgh, Scotland, to Dubrovnik, Croatia, to Oslo, Norway, and back. Like a good tourist, she took pictures on her phone, an Android, throughout her trip. When she returned home, she found a surprise package in her Google+ notifications: a neatly collated, summarized, annotated digital scrapbook titled “Trip.” Jean shared the album with me with this message: “ This is equally cool and creepy: Google made this scrapbook of my June travels based on a random selection of photos I took – and also its knowledge of where I was. It’s kind of nice to have this information organized automatically, but this is really trusting them with a lot of information. It would be funny if they took quotes from emails I sent during this time and put in quotes relevant to the places. “Oslo is so expensive! My second dinner of wonton soup cost 68 kroner.” I’m curious how they decide what to include.” When I spoke with Jean later, she was surprised in part because she didn’t know this feature existed. She was also a little taken aback by all the location information included, given that she hadn’t been using her roaming phone plan or data while abroad. So how did Google pull this together? And why did it leave Jean with mixed feelings? We looked into the program. Google introduced this scrapbooking feature in May, just before Jean’s trip. The company calls it Stories : “Your best photos are automatically chosen and arranged in a fun timeline to show the highlights of your trip or event.” There’s an example scrapbook here . * * *

Verizon Wireless injects identifiers that link its users to Web requests (ArsTechnica, 24 Oct 2014) – Cellular communications provider Verizon Wireless is adding cookie-like tokens to Web requests traveling over its network. These tokens are being used to build a detailed picture of users’ interests and to help clients tailor advertisements, according to researchers and Verizon’s own documentation. The profiling, part of Verizon’s Precision Market Insights division, kicked off more than two years ago and expanded to cover all Verizon Wireless subscribers as part of the company’s Relevant Mobile Advertising service. It appends a per-device token known as the Unique Identifier Header (UIDH) to each Web request sent through its cellular network from a particular mobile device, allowing Verizon to link a website visitor to its own internal profiles. The service aims to allow client websites to target advertising at specific segments of the consumer market. While the company started piloting the service two years ago, privacy experts only began warning of the issue this week, arguing that the service is essentially tracking users and that companies paid for a fundamental service that should not be using the data for secondary purpose. [ Polley : AT&T, also, apparently – go here to test your own carrier.]

 

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/watcharakun

Great privacy essay: Fourth Amendment doctrine in the era of total surveillance (NetworkWorld, 30 July 2014) – When you signed up with your ISP, or with a wireless carrier for mobile devices, if you gave it any thought at all when you signed your name on the contract, you likely didn’t expect your activities to be a secret, or to be anonymous, but how about at least some degree of private? Is that reasonable? No, as the law currently suggests that as a subscriber, you “volunteer” your personal information to be shared with third-parties. Perhaps not the content of your communications, but the transactional information that tells things like times, places, phone numbers, or addresses; transactional data that paints a very clear picture of your life and for which no warrant is required. I’d like to direct your attention to an essay titled “Failing Expectations: Fourth Amendment Doctrine in the Era of Total Surveillance” by Olivier Sylvain , Associate Professor of Law at Fordham University School of Law. He said, “Today’s reasonable expectation test and the third-party doctrine have little to nothing to offer by way of privacy protection if users today are at least conflicted about whether transactional noncontent data should be shared with third parties, including law enforcement officials.” * * * Sylvain argues that “the reasonable expectation standard is particularly flawed if it has the effect of encouraging judges to seek guidance from legislatures on constitutional norms and principles. Judicial review is the vital antimajoritarian check against excessive government intrusions on individual liberty under our constitutional scheme. This is a responsibility that courts cannot pass off to the political branches when, as is the case today, most people expect that the cost of network connection is total surveillance.”

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/Stuart Miles

What the Internet can see from your cat pictures (NYT, 22 July 2014) – Your cat may never give up your secrets. But your cat photos might. Using cat pictures – that essential building block of the Internet – and a supercomputer, a Florida State University professor has built a site that shows the locations of the cats (at least at some point in time, given their nature) and, presumably, of their owners. Owen Mundy, an assistant professor of art who studies the relationship between data and the public, created “I Know Where Your Cat Lives” as a way of demonstrating “the status quo of personal data usage by startups and international megacorps who are riding the wave of decreased privacy for all,” Mr. Mundy wrote in a post about the site . Using images of cats uploaded to photosharing services, including Flickr, Twitpic and Instagram, Mr. Mundy extracted latitude and longitude coordinates that many modern cameras, especially those in smartphones, attach to each image. His site displays random images from a sample of one million of the many millions of pictures tagged with the word “cat” online. The images are displayed on a map using satellite imagery, with nearby cat photos also visible. Specific street addresses are not displayed, but the geographic information can leave few details to the imagination in rural areas.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/apolonia.

Net neutrality a key battleground in growing fight over encryption (InfoWorld, 21 July 2014) – Plans to favor some Internet packets over others threaten consumers’ hard-won right to use encryption, a digital privacy advocate says. Activists and tech companies fended off efforts in the U.S. in the 1990s to ban Internet encryption or give the government ways around it, but an even bigger battle over cryptography is brewing now, according to Sascha Meinrath, director of X-Lab, a digital civil-rights think tank launched earlier this year. One of the most contested issues in that battle will be Net neutrality, Meinrath said. The new fight will be even more fierce than the last one, because Internet service providers now see dollars and cents in the details of packets traversing their networks. They want to charge content providers for priority delivery of their packets across the network, something that a controversial Federal Communications Commission proposal could allow under certain conditions. Encrypted traffic can’t be given special treatment because it can’t be identified, Meinrath said. That could eliminate a major revenue source for ISPs, giving them a strong reason to oppose the use of encrypted services and potentially an indirect way to degrade their performance, he said. Meinrath laid out parts of this argument in a recent essay in the June issue of Critical Studies in Media Communication , called “Crypto War II” and written with tech policy activist Sean Vitka.

Provided by MIRLN.

Note from MIRLN Founder, Vince Polley:

Polley : Others have reported seeing their Netflix speeds INCREASE when using VPN connections (which block your home ISP from seeing what kind of traffic you’re running). Me, too. Interesting.]

 

Image courtesy of FreeDigitalPhotos.net/rejithkrishnan

Meet Executive Order 12333: the Reagan rule that lets the NSA spy on Americans (Washington Post, 18 July 2014) – Even after all the reforms President Obama has announced, some intelligence practices remain so secret, even from members of Congress, that there is no opportunity for our democracy to change them. Public debate about the bulk collection of U.S. citizens’ data by the NSA has focused largely on Section 215 of the Patriot Act, through which the government obtains court orders to compel American telecommunications companies to turn over phone data. But Section 215 is a small part of the picture and does not include the universe of collection and storage of communications by U.S. persons authorized under Executive Order 12333. From 2011 until April of this year, I worked on global Internet freedom policy as a civil servant at the State Department. In that capacity, I was cleared to receive top-secret and “sensitive compartmented” information. Based in part on classified facts that I am prohibited by law from publishing, I believe that Americans should be even more concerned about the collection and storage of their communications under Executive Order 12333 than under Section 215. Bulk data collection that occurs inside the United States contains built-in protections for U.S. persons, defined as U.S. citizens, permanent residents and companies. Such collection must be authorized by statute and is subject to oversight from Congress and the Foreign Intelligence Surveillance Court. The statutes set a high bar for collecting the content of communications by U.S. persons. For example, Section 215 permits the bulk collection only of U.S. telephone metadata – lists of incoming and outgoing phone numbers – but not audio of the calls. Executive Order 12333 contains no such protections for U.S. persons if the collection occurs outside U.S. borders. Issued by President Ronald Reagan in 1981 to authorize foreign intelligence investigations, 12333 is not a statute and has never been subject to meaningful oversight from Congress or any court. Sen. Dianne Feinstein (D-Calif.), chairman of the Senate Select Committee on Intelligence, has said that the committee has not been able to “sufficiently” oversee activities conducted under 12333. Unlike Section 215, the executive order authorizes collection of the content of communications, not just metadata, even for U.S. persons. Such persons cannot be individually targeted under 12333 without a court order. However, if the contents of a U.S. person’s communications are “incidentally” collected (an NSA term of art ) in the course of a lawful overseas foreign intelligence investigation, then Section 2.3(c) of the executive order explicitly authorizes their retention. It does not require that the affected U.S. persons be suspected of wrongdoing and places no limits on the volume of communications by U.S. persons that may be collected and retained.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/Suat Eman.