/* ---- Google Analytics Code Below */
Showing posts with label Personal Data. Show all posts
Showing posts with label Personal Data. Show all posts

Thursday, April 07, 2022

Google Pulls Apps Harvesting Data

 This kind of thing has been done for a long time, good to see Google noticing in this case, but Google  gathers lots of data too for advertising purposes.

Google pulls apps that may have harvested data from millions of Android devices

The apps took users' precise location, email, phone numbers and more, researchers said.

S. Dent, @stevetdent,  April 7th, 2022   in Engadget

Google has pulled dozens of apps used by millions of users after finding that they covertly harvested data, The Wall Street Journal has reported. Researchers found weather apps, highway radar apps, QR scanners, prayer apps and others containing code that could harvest a user's precise location, email, phone numbers and more. It was made by Measurement Systems, a company that's reportedly linked to a Virginia defense contractor that does cyber-intelligence and more for US national-security agencies. It has denied the allegations.

The code was discovered by researchers Serge Egelman from UC Berkeley and the University of Calgary's Joel Reardon, who disclosed their findings to federal regulators and Google. It can "without a doubt be described as malware," Egelman told the WSJ. 

Measurement Systems reportedly paid developers to add their software development kits (SDKs) to apps. The developers would not only be paid, but receive detailed information about their user base. The SDK was present on apps downloaded to at least 60 million mobile devices. One app developer said it was told that the code was collecting data on behalf of ISPs along with financial service and energy companies. Measurement Systems also said it wanted data mainly from the Middle East, Central and Eastern Europe and Asia. 

"A database mapping someone’s actual email and phone number to their precise GPS location history is particularly frightening, as it could easily be used to run a service to look up a person’s location history just by knowing their phone number or email, which could be used to target journalists, dissidents, or political rivals," Reardon said in the AppCensus research blog.

Though Google has pulled those apps from the Play Store, the researchers noted that they still exist on millions of devices. At the same time, they found that the SDK stopped collecting user data after their findings were revealed.  ... ' 


Wednesday, March 02, 2022

Defense of Personal Data

Chip said to aid personalization

Toward a Stronger Defense of Personal Data

By MIT News February 25, 2022

Saurav Maji and colleagues at the Massachusetts Institute of Technology (MIT) have designed an integrated circuit chip that can thwart power side-channel attacks with less energy expenditure than common security methods.

The chip is based on threshold computing, which splits data into random components for individual processing by the neural network before assembling the final result.

Maji said information leakage from the device is always random, and can never expose any side-channel data.  An optimization function reduces computing power by cutting the amount of multiplication needed to process data, and shields the network by encrypting the model's parameters.

This application-specific integrated circuit (ASIC) chip that can be implemented on an Internet of Things device to defend against power-based side-channel attacks.    

From MIT News

View Full Article  

Monday, December 20, 2021

Monetizing your Personal Data

 Did considerable exploratory work in this space.  And considering the included risk.

Monetizing Your Personal Data

By Keith Kirkpatrick

Communications of the ACM, January 2022, Vol. 65 No. 1, Pages 17-19   10.1145/3495563

During the initial wave of commercialization of the Internet in the mid-to-late 1990s, companies began collecting personal information from visitors to their Websites. The value proposition laid out by Internet companies seemed simple: allow companies to track and capture user behavioral and demographic data, in exchange for free access to content, as well as a more personalized and tailored experience that was based on an individual's browsing and shopping habits.

However, few users or market observers could have projected the evolution of the market for data, which has become far more complex and valuable than previously imagined. In fact, large companies such as Google, Facebook, Amazon, and Alibaba, among others, have generated massive profits by leveraging the data collected, not only using it to improve the personalization and usability of their own sites, but by reselling that data to advertisers, to the tune of billions of dollars per year. In fact, March 2021 data from eMarketer indicated the Internet advertising market generated $378.2 billion in 2020, and projected that figure will rise to nearly $646 billion by 2024.

"Everything you do creates data that's being bought and sold," says George Stella, chief revenue officer of BigToken (bigtoken.com), a data broker that enables consumers to collect revenue from the use of their personal data. "So, the ad tech industry has collected a ton of information from people without their permission over the last 20-plus years, and made billions and billions of dollars off of it."

A key barrier to empowering people to generate revenue from their data is awareness. "Less than 200 or 300 million people out of 7.1 billion people globally are even aware that their data is being used or sold, and that they can actually benefit from these sites," says Sagar Shah, client partner with artificial intelligence (AI) technology firm Fractal (www.fractal.ai).

While the Internet advertising market is massive, putting specific monetary value on each individual user's personal data is highly variable, not only due to people's different demographic profiles, but also to the type of data and its relative level of abundance or scarcity. For example, data on demographics that are in limited supply (such as data on Middle Eastern male consumers) is more valuable than demographic data on white millennial women. Similarly, the browsing data of individuals seeking to purchase a Tesla or Ferrari automobile within the next month would be valued more highly by data brokers and advertisers than the data of someone browsing for the best deals on a used Chrysler minivan.

Regardless of the type of data, personal data has value on both the legitimate advertising market and the black market, where stolen records can be sold to various parties. Data broker Invisibly (www.invisibly.com) provides a listing of various types of data available for sale on the dark web, ranging from a Social Security number (valued at just $0.53) to a complete healthcare record ($250). There also is significant value attached to personal information that is collected, bought, and sold through legitimate operations, such as data brokers and Internet advertising firms.

Left out of this equation are the end users generating that data who, for the most part, do not share in any of that revenue. Enter companies such as the aforementioned BigToken, Invisibly, and Killi (killi.io), each of which serve as middlemen or brokers between consumers and the companies that collect data. The goal is to create a user ownership model in which consumers retain more control over their data, who is permitted to capture it, and who can profit from it.

"There's a whole industry built around the unscrupulous gathering of customer data to optimize sales," says Rick Hoskins, founder of Filter King, a seller of HVAC filters via its eponymous online site. "We take a lot of care not to source customer data unethically. As a business owner, allowing normal people to monetize their data would take a massive weight off my shoulders. It would cut the knees out from under this sketchy shadow industry stealing people's information for profit. Not only would it give us, online marketers, access to more data, it would let us access it ethically."  .... ' 

Full article in ACM

Friday, October 01, 2021

The Value of Phone Location Data

 The Another example of how valuable personal data can be.

ACM NEWS

There's a Multibillion-Dollar Market for Your Phone's Location Data

By The Markup, September 30, 2021

Companies that you likely have never heard of are hawking access to the location history on your mobile phone. An estimated $12 billion market, the location data industry has many players: collectors, aggregators, marketplaces, and location intelligence firms, all of which boast about the scale and precision of the data that they've amassed.

Location firm Near describes itself as "The World's Largest Dataset of People's Behavior in the Real-World," with data representing "1.6B people across 44 countries." Mobilewalla boasts "40+ Countries, 1.9B+ Devices, 50B Mobile Signals Daily, 5+ Years of Data." X-Mode's website claims its data covers "25%+ of the Adult U.S. population monthly."

In an effort to shed light on this little-monitored industry, The Markup has identified 47 companies that harvest, sell, or trade in mobile phone location data. While hardly comprehensive, the list begins to paint a picture of the interconnected players that do everything from providing code to app developers to monetize user data to offering analytics from "1.9 billion devices" and access to datasets on hundreds of millions of people. Six companies claimed more than a billion devices in their data, and at least four claimed their data was the "most accurate" in the industry.

Full article

Wednesday, August 04, 2021

Big Fines for Amazon Under GDPR

Good to know the implications of the EU GDPR.  Note how Amazon sees the gathering of customer data. On to the EU court.

EU Fines Amazon Record $888 Million Over Data Violations   By Bloomberg, August 2, 2021

Luxembourg's CNPD data protection authority fined Amazon a record $888 million for breaching the EU's General Data Protection Regulation (GDPR).

The EU regulator charged the online retailer with processing personal data in violation of GDPR rules, which Amazon denies. The ruling closes an investigation triggered by a 2018 complaint from French privacy rights group La Quadrature du Net.

Amazon says it gathers data to augment the customer experience, and its guidelines restrict what employees can do with it; some lawmakers and regulators allege the company exploits this data to gain an unfair competitive advantage.

Amazon also is under EU scrutiny concerning its use of data from sellers on its platform, and whether it unfairly champions its own products.

From Bloomberg  

Friday, May 28, 2021

Fake Job Offers

No longer in the market, but in between had received a number of 'too good to be true' offers to start employment.   Many via Linkedin.     Although they look targeted, a quick search finds them broadly scoped, and they quickly fall apart.   No legit company will ask for detailed personal data up front.  Caution is important.

How to Tell a Job Offer from an ID Theft Trap  in Krebs on Security

One of the oldest scams around — the fake job interview that seeks only to harvest your personal and financial data — is on the rise, the FBI warns. Here’s the story of a recent LinkedIn impersonation scam that led to more than 100 people getting duped, and one almost-victim who decided the job offer was too-good-to-be-true.

Last week, someone began posting classified notices on LinkedIn for different design consulting jobs at Geosyntec Consultants, an environmental engineering firm based in the Washington, D.C. area. Those who responded were told their application for employment was being reviewed and that they should email Troy Gwin — Geosyntec’s senior recruiter — immediately to arrange a screening interview.

Gwin contacted KrebsOnSecurity after hearing from job seekers trying to verify the ad, which urged respondents to email Gwin at a Gmail address that was not his. Gwin said LinkedIn told him roughly 100 people applied before the phony ads were removed for abusing the company’s terms of service.

“The endgame was to offer a job based on successful completion of background check which obviously requires entering personal information,” Gwin said. “Almost 100 people applied. I feel horrible about this. These people were really excited about this ‘opportunity’.”   ... ' 

Wednesday, June 24, 2020

Price of Personal Data

Looking for the full report mentioned here, will post when I get a reference.  Back to the our long time looked at question of what the price of private data should be, and how should people be made to understand the implications?

Brits will sell their personal data for pennies  

Surprising findings from an Okta report on digital identity suggest Brits would be willing to part with valuable personal data for a surprisingly low amount  .... 
By  Alex Scroxton, Security Editor  in ComputerWeekly  ... 

Friday, June 05, 2020

Privacy Threats in Intimate and Personal Relationships

Fascinating thoughts on the topic, true is too little discussed.   Though I would think divorce lawyers have seen it all.

Privacy threats in intimate relationships
Karen Levy and Bruce Schneier 
Department of Information Science, Cornell University; 2Cornell Law School, Ithaca, NY, USA; 3 Berkman Klein
Center for Internet and Society, Harvard University; and 4 Belfer Center for Science and International Affairs,  Harvard Kennedy School, Cambridge, MA, USA
Email: karen.levy@cornell.edu
Received 11 December 2018; revised 10 March 2020; accepted 8 April 2020

Abstract
This article provides an overview of intimate threats: a class of privacy threats that can arise within our families, romantic partnerships, close friendships, and caregiving relationships. Many common assumptions about privacy are upended in the context of these relationships, and many otherwise effective protective measures fail when applied to intimate threats. Those closest to us know the answers to our secret questions, have access to our devices, and can exercise coercive power over us. We survey a range of intimate relationships and describe their common features. Based on these features, we explore implications for both technical privacy design and policy, and offer design recommendations for ameliorating intimate privacy risks.

Keywords: intimacy; family; abuse; children; relationships; privacy .... "

See further in Schneier's blog with discussion.

Sunday, May 31, 2020

Why Consumers Are Willing to Share Personal Information on Smartphones

Intriguing difference between phones and laptops. 

Why Consumers Are Willing to Share Personal Information on Smartphones

Wharton’s Shiri Melumad speaks with Wharton Business Daily on Sirius XM about why consumers share personal information on smartphones.

Nearly everyone has experienced some version of phubbing, a term to describe being snubbed by someone who is more engrossed in their smartphone screen than the conversation or activity taking place in front of them. These powerful little devices have changed virtually everything about human communication, including the way we interact with each other. New research from Wharton marketing professors Shiri Melumad and Robert Meyer finds that people are more willing to share deeper and more personal information when communicating on a smartphone compared with a personal computer. In their paper, “Full Disclosure: How Smartphones Enhance Consumer Self-Disclosure,” the professors explain that it’s the device that makes all the difference. Smartphones are always at hand, and their tiny screens and keypads require laser-focused attention, which means the user is more likely to block out other concerns.

The findings are important for marketers looking to make the most out of user-generated content, especially the kind that can be shared with other potential customers. “The more personal and intimate nature of smartphone-generated reviews results in content that is more persuasive to outside readers, in turn heightening purchase intentions,” the professors write in their paper. Melumad recently joined the Wharton Business Daily radio show on Sirius XM to discuss the research. (Listen to the podcast at the top of this page.)

An edited transcript of the conversation follows. ..."


Monday, January 13, 2020

Humanizing Assistants a kind of Privacy Invasion?

From a retail perspective, with further expert comment.

Does humanizing virtual assistants undermine consumer privacy?    by Tom Ryan in Retailwire

A university study finds people increasingly attributing lifelike qualities to virtual assistants and warns this may cause them to reveal more personal information to the companies that use them than they otherwise would.

“These agents are data gathering tools that companies are using to sell us stuff,” said Edward Lank, a professor at the University of Waterloo’s David R. Cheriton School of Computer Science, in a statement. “People need to reflect a little to see if they are formulating impressions of these agents rather than seeing them as just a piece of technology and trusting them in ways based on these impressions.”

Researchers had 20 subjects interact with Alexa, Google Assistant and Siri and then asked them about the personalities of the virtual agents and to create an avatar for each. Alexa’s sentiment was seen as genuine and caring, while Siri’s was viewed as disingenuous and cunning. Alexa’s individuality was commonly described as neutral and ordinary, while participants considered the individuality of Google — and Siri, especially — more defined and pronounced.   .... " 

Saturday, December 28, 2019

Your Data is Shared and Sold

Further look at personal data and its use and regulations.

Your Data Is Shared and Sold…What’s Being Done About It?
Oct 28, 2019 Europe, North America

Earlier this month, California Gov. Gavin Newsom signed into law amendments to the California Consumer Privacy Act (CCPA), the most sweeping state data privacy regulations in the country. The law, which takes effect on Jan. 1, regulates how data is collected, managed, shared and sold by companies and entities doing business with or compiling information about California residents. Some observers contend that because no business would want to exclude selling to Californians, the CCPA is de facto a national law on data privacy, absent an overarching federal regulation protecting consumer information.

“The new privacy law is a big win for data privacy,” says Joseph Turow, a privacy scholar and professor of communication at the Annenberg School for Communication at the University of Pennsylvania. “Though it could be even stronger, the California law is stronger than anything that exists at the federal level.” Among other stipulations, the CCPA requires businesses to inform consumers regarding the types of personal data they’ll collect at the time they collect it and also how the information will be used. Consumers have the right to ask firms to disclose with whom they share the data and also opt out of their data being sold.

The CCPA comes on the heels of the EU’s General Data Protection Regulation (GDPR), which took effect in May 2018. According to the United Nations Conference on Trade and Development, 107 countries have data privacy rules in place including 66 developing nations. In the U.S., there was a “significant” increase in data privacy bills being introduced this year, with at least 25 states and Puerto Rico starting such legislation, according to the National Conference of State Legislatures. Notably, this bill count doesn’t include related legislation on topics such as cybersecurity.  .... "

Saturday, November 23, 2019

Epidemics and use of Personal GPS Data

Recall our work with bioterrorism modeling, link below.  Not just a matter of disease epidemics.

During Epidemics, Access to GPS Data from Smartphones Can Be Crucial
Ecole Polytechnique Fédérale de Lausanne (Switzerland)
By Sandrine Perroud

Researchers at Ecole Polytechnique Fédérale de Lausanne (EPFL) in Switzerland and the Massachusetts Institute of Technology have found that human mobility is a major factor in the spread of vector-borne diseases such as malaria and dengue. The researchers used mobile phone data and census models to effectively predict the spatial distribution of dengue cases in Singapore, based on data from actual reported cases in 2013 and 2014. The team also demonstrated that the types of data used in their study could be obtained without infringing on people's privacy. Said EPFL's Emanuele Massaro, "We need to think seriously about changing the law around accessing this kind of information – not just for scientific research, but for wider prevention and public health reasons." ... '

Friday, November 15, 2019

Should Customers be Paid for their Data?

From a retail perspective, below the outline, more at the link

Should customers just be paid for their data?   by Guest contributor
Wise Marketer Staff

In light of rising security failures, more calls are being heard for businesses to tangibly pay customers for their data.

“California’s consumers should also be able to share in the wealth that is created from their data,” California governor Gavin Newson declared in February in proposing such a “data dividend” concept. “[Tech companies] make billions of dollars collecting, curating and monetizing our personal data [and so should] have a duty to protect it.”

But is the direct transfer of wealth from corporations to customers the panacea? Let’s play devil’s advocate and explore some of the claims supporting the “data dividend” concept:  ... " 

Thursday, November 14, 2019

Examples of ISP's Use of Personal Data

Mentioned a Mozilla letter to the US Congress on the use and sale of personal data.  I am using it as part of a discussion today regarding the value of data.

In particular gives examples of how personal data has real value, and gives specific examples, in the way ISPs are using data.  Via Steve Gibson in TWIT  'Security Now’

Now:  https://www.grc.com/sn/SN-740-Notes.pdf


Tuesday, November 12, 2019

Google Accesses Health Data

Been looking at personal data uses and abuses.  Google has been and is now again in the mix:

Google is to get access to millions of Americans’ personal health data'

The news: Google has signed a deal with Ascension, the second-largest hospital system in the US, to collect and analyze millions of Americans’ personal health data, according to the Wall Street Journal. Ascension operates in 150 hospitals in 21 states. 

“Project Nightingale”: Eventually, data from all of the company’s patients (birth dates, lab results, diagnoses, and hospitalization records, for example) could be uploaded to Google’s cloud computing systems, with a view to using artificial intelligence to scan electronic records, or diagnose or identify medical conditions. The project, code-named Project Nightingale, began in secret last year, the WSJ reports. Neither patients nor doctors have been notified.  ... " 

Friday, October 11, 2019

Tracking Your Data: Exist

Brought to my attention:

Exist: Track everything together. Understand your behaviour.

By combining data from services you already use, we can help you understand what makes you more happy, productive, and active.

Bring your activity from your phone or fitness tracker, and add other services like your calendar for greater context on what you're up to.

Start your free trial  ... 

Monday, October 07, 2019

Should Companies have to Pay for your Data?

Some work is going on to figure this out.    But will we get all the freebees we have come to expect?

Should companies have to pay you to use your personal data?  in Retailwire  with expert comments
by George Anderson with expert retail comment.

Andrew Yang, one of the candidates among the large field running to be the Democratic Party’s presidential nominee in 2020, issued a new policy proposal this week that makes the case that digital data should be treated as a property right under law. 

He points to the fact that businesses, known and unknown, have access to vast amounts of personal data on Americans. These companies use the data collected to make money while not always paying close enough attention to protecting it. Reputable firms have asked Congress to create better, clearer rules on the collection and use of data. .... " 

Saturday, September 29, 2018

Berners-Lee Says we can Control our Data, and Need to do it Now

But how will this influence the economics of the Web in the last decade?  Will the economics be there to continue to drive its development?  Or will it go back to an excellent academic system?  Reading more.   Excellent description here, and see also  https://solid.inrupt.com/

One Small Step for the Web…
By Tim Berners-Lee in Medium

Director of the World Wide Web Consortium (W3C) w3.org, the place to agree on web standards. Founded webfoundation.org - let the web serve humanity

I’ve always believed the web is for everyone. That’s why I and others fight fiercely to protect it. The changes we’ve managed to bring have created a better and more connected world. But for all the good we’ve achieved, the web has evolved into an engine of inequity and division; swayed by powerful forces who use it for their own agendas.

Today, I believe we’ve reached a critical tipping point, and that powerful change for the better is possible — and necessary.

This is why I have, over recent years, been working with a few people at MIT and elsewhere to develop Solid, an open-source project to restore the power and agency of individuals on the web.

Solid changes the current model where users have to hand over personal data to digital giants in exchange for perceived value. As we’ve all discovered, this hasn’t been in our best interests. Solid is how we evolve the web in order to restore balance — by giving every one of us complete control over data, personal or not, in a revolutionary way.  ... "

Also see: https://solid.inrupt.com/ for more about their approach.

Tuesday, September 18, 2018

Uninformed Consent

Persistence of Surveillance online.   A non-technical survey of hidden capabilities and implications.

  Uninformed Consent  in the HBR

Companies want access to more and more of your personal data — from where you are to what’s in your DNA. Can they unlock its value without triggering a privacy backlash?

Three years ago the satirical website The Onion ran an article with the headline “Woman Stalked Across 8 Websites by Obsessed Shoe Advertisement.” Everywhere she went online, this fictional consumer saw the same ad. “The creepiest part,” she says in the story, “is that it even seems to know my shoe size.” The piece poked fun at an increasingly common — if clumsy — digital marketing technique. But today its gentle humor seems almost quaint. Technology has advanced far beyond the browser cookies and retargeting that allow ads to follow us around the internet. Smartphones now track our physical location and proximity to other people — and, as researchers recently discovered, can even do so when we turn off location services. We can disable the tracking on our web browsers, but our digital fingerprints can still be connected across devices, enabling our identities to be sleuthed out. Home assistants like Alexa listen to our conversations and, when activated, record what we’re saying. A growing range of everyday things — from Barbie dolls to medical devices — connect to the internet and transmit information about our movements, our behavior, our preferences, and even our health. A dominant web business model today is to amass as much data on individuals as possible and then use it or sell it — to target or persuade, reward or penalize. The internet has become a surveillance economy.    ... "

Thursday, March 22, 2018

On GDPR

Useful Informatica white paper on GDPR, brought to my attention.  Which happens come May 25.   Implications for Assistants?

In the WP: " ... The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union. It addresses the export of personal data outside the EU. The GDPR aims primarily to give control back to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.[1] When the GDPR takes effect, it will replace the 1995 Data Protection Directive (Directive 95/46/EC).[2] .... "