/* ---- Google Analytics Code Below */
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Tuesday, May 02, 2023

GPT is Back in Italy

This block was reported some time ago and now has been resolved.  How this will long time connects with Euro GDPR is still unclear. 

ChatGPT accessible again in Italy, By Shiona McCallum,Technology reporter   in the BBC

Access to the ChatGPT chatbot has been restored in Italy.

It was banned by the Italian data-protection authority at the start of April over privacy concerns.

It maker, OpenAI, which is backed by Microsoft, said it had successfully "addressed or clarified" the issues raised.  It said its privacy policy was now accessible to people before they registered for ChatGPT and there was a new tool to verify the age of users.

The Italian data-protection authority, also known as Garante, had temporarily restricted the chatbot and launched a probe over the artificial intelligence application's suspected breach.   As Garante had accused OpenAI of failing to check the age of ChatGPT's users who are supposed to be aged 13 or above, OpenAI said it would offer a tool to verify users' ages in Italy upon sign-up.

OpenAI explained that it would also provide a new form for European Union users to exercise their right to object to its use of personal data to train its models.

The Italian regulator told the BBC it "welcomed the measures OpenAI implemented" but called for even more compliance.  In particular, the spokesperson said, around "implementing an age verification system and planning and conducting an information campaign to inform Italians of what happened as well as of their right to opt-out from the processing of their personal data for training algorithms."

Garante said it would carry on its "fact-finding activities regarding OpenAI also under the umbrella of the ad-hoc task force that was set up by the European Data Protection Board."   An OpenAI spokesperson said it appreciated the Garante for being collaborative, and that it would continue ongoing constructive discussions.

Millions of people have used ChatGPT since it launched in November 2022.   It can answer questions using natural, human like language and it can also mimic other writing styles. Microsoft has spent billions of dollars on it and it was added to Bing last month.   It has also said that it will embed a version of the technology in its Office apps, including Word, Excel, Powerpoint and Outlook.

Bard, Google's; rival artificial-intelligence chatbot, is now available, but only to specific users over the age of 18.

Saturday, March 04, 2023

EU Digital Strategy

 So many directions to regulate.    Note considering the influence US Law

The EU digital strategy: The impact of data privacy on global business

McKinseu:  March 1, 2023 | Commentary

By  Daniel Mikkelsen, Sebastian Scheurle,   Henning Soller , and Malin Strandell-Jansson

New data regulations from the European Union require organizational attention, and three key steps can help navigate the data privacy landscape.

The data regulations in the European Union (EU) have recently received significant attention specifically due to the advent of the General Data Protection Regulation and the rulings around Schrems II—whereby the Court of Justice of the European Union found that the protection of personal data had limitations due to domestic law in the United States—as well as the access and use by US public authorities of personal data transferred from the EU, and recent developments such as e-privacy.

While these developments have led to major changes in data privacy, one of the other goals of the regulation—to establish a market for data and facilitate data exchange between companies—has not been reached to date.

This lack of action has led to the potential for further regulatory activity to define an agenda for how to uplift the data capabilities of European companies, create a market for data, and regulate activities around AI. These activities are typically summarized as the EU digital strategy. While regulation adds further requirements and obligations to any data-enabled business, it also creates an opportunity for competitive advantages for those that best derisk their data transformations.

The EU digital strategy offers organizations both challenges and opportunities, but these regulations will likely continue to evolve, so organizations should remain aligned with the regulatory process. ... ' 

Thursday, February 09, 2023

Sharing Health Data without consumer Consent

Sharing Health Data without consumer Consent

ACM NEWS

FTC Accuses GoodRx of Sharing User Data Without Consent

By CNet, February 2, 2023

GoodRX users may have given up more than they thought

GoodRx will pay $1.5 million and be barred from sharing user data with outside companies for advertising purposes under a deal that would settle allegations that it shared some of its users' most intimate health-related information with companies like Facebook and Google.

The Federal Trade Commission characterized the action, which is pending approval by a federal court, as the first of its kind under its Health Breach Notification Rule, adding that the agency won't hesitate to use its full legal authority to take action against companies that willingly misuse or exploit consumer data.

"Digital health companies and mobile apps should not cash in on consumers' extremely sensitive and personally identifiable health information," Samuel Levine, director of the FTC's Bureau of Consumer Protection, said in a statement.

According to the FTC's complaint, GoodRx, which helps users find deals on prescription drugs and offers telehealth and other health-related services, shared its users' data with outside companies for advertising purposes, despite promising it wouldn't.

From CNet   

Monday, January 09, 2023

A Detailed example of Cellphone and Camera Tracking in Idaho

From a comment on Bruce Schneiers post on Cellphone tracing and related technologies used by law enforcement to track suspect behavior, actual and inferred    This is regarding the recent Idaho murders.      Informative regarding how much and how the data was found.   And considerable privacy implications. 

(By PaulN • January 9, 2023 2:16 PM

It’s very interesting looking at the Affidavit for the Idaho4 case from a privacy perspective. Here’s a link to the court filing. Much of the affidavit is a cell phone analysis combined with a surveillance camera analysis.

https://coi.isc.idaho.gov/docs/case/CR29-22-2805/122922%20Affidavit%20-%20Exhibit%20A%20-%20Statement%20of%20Brett-Payne.pdf

Note that there are many opsec (operations security) fails with this specific suspect: used his own car, did stakeouts with his cell phone turned on, turned his phone off at the specific time of crime… it shows how serious opsec has to be a lifecycle. Anyway.

I don’t know the burdens of a proof that permit getting warrants for this information; certainly its stemming from a legitimate investigation.  ...' 

Saturday, November 05, 2022

Linkedin Leverages Data for Success Prediction

The Linkedin data begs for such studies to be done, should they be? 

LinkedIn ran undisclosed social experiments on 20 million users for years to study job success

By USA Today, September 28, 2022

A new study analyzing the data of over 20 million LinkedIn users over the timespan of five years reveals that our acquaintances may be more helpful in finding a new job than close friends.

Researchers behind the study say the findings will improve job mobility on the platform, but since users were unaware of their data being studied, some may find the lack of transparency concerning.  

Published this month in Science, the study was conducted by researchers from LinkedIn, Harvard Business School and the Massachusetts Institute of Technology between 2015 and 2019. Researchers ran "multiple large-scale randomized experiments" on the platform's "People You May Know" algorithm, which suggests new connections to users. 

In a practice known as A/B testing, the experiments included giving certain users an algorithm that offered different (like close or not-so-close) contact recommendations and then analyzing the new jobs that came out of those two billion new connections....

Privacy advocates said some of the 20 million LinkedIn users may not be happy that their data was used without consent. .... 


Friday, September 23, 2022

Training Neural Nets on Small Devices

 Good direction.

We Can Train Big Neural Networks on Small Devices

IEEE Spectrum

Matthew Hutson, September 20, 2022

A new training method expands small devices' capabilities to train large neural networks, while potentially helping to protect privacy. The University of California, Berkeley's Shishir Patil and colleagues integrated offloading and rematerialization techniques using suboptimal heuristics to reduce memory requirements for training via the private optimal energy training (POET) system. Users feed POET a device's technical details and data on the architecture of a neural network they want to train, specifying memory and time budgets; the system generates a training process that minimizes energy usage. Defining the problem as a mixed integer linear programming challenge was critical to POET's effectiveness. Testing showed the system could slash memory usage by about 80% without significantly increasing energy consumption.  ...

Friday, September 09, 2022

Considering Mass Surveillance

Cops Wanted to Keep Mass Surveillance App Secret; Privacy Advocates Refused

By Ars Technica, September 9, 2022  in CACM

Much is known about how the federal government leverages location data by serving warrants to major tech companies like Google or Facebook to investigate crime in America. However, much less is known about how location data influences state and local law enforcement investigations. It turns out that's because many local police agencies intentionally avoid mentioning the under-the-radar tech they use—sometimes without warrants—to monitor private citizens.

As one Maryland-based sergeant wrote in a department email, touting the benefit of "no court paperwork" before purchasing the software, "The success lies in the secrecy."

This week, an investigation from the Electronic Frontier Foundation and Associated Press—supported by the Pulitzer Center for Crisis Reporting—has made public what could be considered local police's best-kept secret. Their reporting revealed the potentially extreme extent of data surveillance of ordinary people being tracked and made vulnerable just for moving about small-town America....

It took the Electronic Frontier Foundation months and more than 100 public records requests to gather thousands of pages of evidence to compile a clear picture that shows how local law enforcement increasingly mines location data.... 

From Ars Technica  

Wednesday, August 31, 2022

COPPA and more Online

More on COPPA and updates, protecting children online.

ACM NEWS

Protecting Children's Privacy Online   By Gregory Goth, Commissioned by CACM Staff, August 30, 2022

Digital games and educational apps for children can be a boon. They keep youngsters engaged in interactive play and learning, and can give parents a break.

Unfortunately, though, a large percentage of those games' characters and features are designed not to altruistically enlighten children, but to make them spend more time on the platform–and to get their parents to spend more money on extra features.

"We assume adults are better at recognizing persuasion pressure and are hopefully less magically engaged with their parasocial relationships with characters," said Jenny Radesky, M.D.,  principal investigator of the Radesky Lab at the University of Michigan Medical School. "Kids' relationships with Elmo or Daniel Tiger or Strawberry Shortcake are very important to them, and they are more likely to follow those characters' instructions."

In her lab's most recent research on children's mobile apps, Radesky found concerning evidence that game developers are putting their interests ahead of their young audience in designing and creating their products: only 20% of 133 mobile apps played by 160 children aged 3 to 5 had no manipulative design features intended to better monetize the child's experience.

The manipulative features Radesky and her colleagues found included parasocial relationship pressure, fabricated time pressure, navigation constraints, and the use of "attractive lures" to encourage longer game play or more in-app purchases. These features are usually tied to data collection mechanisms that exploit a child's inherent trust.

The study, published in the Journal of the American Medical Association's JAMA Open, seemed to confirm concerning results published elsewhere in recent months:

An analysis of evident privacy policies in products in the Google and Apple app stores by fraud, privacy, and compliance data analytics firm Pixalate, found 11% of child-directed apps in the Google Play store, and 21% of those in the Apple store, had potential access to users' personal information but no detectable privacy policy; almost 250,000 had no discernible country of origin, a nightmare for enforcement agencies.

An examination by Human Rights Watch of how well (or poorly) educational technology deployed for remote schooling during the Covid-19 pandemic protected children's privacy found that 145 of 169 educational applications "appeared to engage in data practices that put children's rights at risk, contributed to undermining them, or actively infringed on these rights."

Radesky said that while it is evident across all this research that children's privacy and priorities are given short shrift by app and game designers, it is also an encouraging sign that children's needs are now being given more widespread attention. What is not so evident is some sort of consensus about how best to address these shortcomings.

Numerous existing laws such as the U.S. federal government's Children's Online Privacy Protection Act (COPPA), in place since 1998 and updated in 2013, and the European Union's General Data Protection Regulation (GDPR), in place since 2018, offer some level of privacy protection. However, the increasing complexity of the digital ecosystem has revealed loopholes in some of these policies that allow app developers to skirt the boundaries–and sometimes, to cross the line–of what's thical, if not outright illegal.  .... ' 

For example, COPPA's primary goal is to place parents in control of the information online games and services collect from their children under age 13. According to the Federal Trade Commission (FTC), it applies without question to developers whose products collect, use, or disclose personal information from those children, or on whose behalf such information is collected or maintained (such as when personal information is collected by an ad network to serve targeted advertising).  .... ' 

Tuesday, August 30, 2022

Deploying Decentralized, Privacy-Preserving Proximity Tracing

Considerable and  interesting, below an intro, very relevant, much more at the link.

Deploying Decentralized, Privacy-Preserving Proximity Tracing

By Carmela Troncoso, Dan Bogdanov, Edouard Bugnion, Sylvain Chatel, Cas Cremers, Seda GĂŒrses, Jean-Pierre Hubaux, Dennis Jackson, James R. Larus, Wouter Lueks, Rui Oliveira, Mathias Payer, Bart Preneel, Apostolos Pyrgelis, Marcel SalathĂ©, Theresa Stadler, Michael Veale

Communications of the ACM, September 2022, Vol. 65 No. 9, Pages 48-57  10.1145/3524107

Contact tracing is a time-proven technique for breaking infection chains in epidemics. Public health officials interview those who come in contact with an infectious agent, such as a virus, to identify exposed, potentially infected people. These contacts are notified that they are at risk and should take efforts to avoid infecting others—for example, by going into quarantine, taking a test, wearing a mask continuously, or taking other precautionary measures.

n March 2020, as the first wave of the COVID-19 pandemic was peaking, traditional manual contact tracing efforts in many countries were overwhelmed by the sheer volume of cases; by the rapid speed at which SARS-CoV-2 spread; and by the large fraction of asymptomatic, yet infectious, individuals.

Many people quickly and independently proposed using ubiquitous smartphones to implement digital contact tracing (DCT). In this new approach, an app on a user's phone could record contacts (encounters with other people) of sufficient time duration. If a physically close contact was diagnosed as infected, the app could inform the phone's potentially infected user. The envisioned technology would complement manual contact tracing by notifying people faster; reducing the burden on trained contract tracers; increasing scalability; and finding anonymous contacts, such as those in public spaces like shops and transportation, who would be otherwise unreachable through traditional systems.  ...>

Thursday, August 11, 2022

Privacy and Robots in the Home

 Implications of Amazon's acquisition of iRobot and more:

iRobot CEO Colin Angle on Data Privacy and Robots in the Home In light of Amazon’s recent acquisition, we revisit our 7 September 2017 Q&A with iRobot’s CEO    BY EVAN ACKERMAN

Editor’s note: Last week, Amazon announced that it was acquiring iRobot for $1.7 billion, prompting questions about how iRobot’s camera-equipped robot vacuums will protect the data that they collect about your home. In September of 2017, we spoke with iRobot CEO Colin Angle about iRobot’s approach to data privacy, directly addressing many similar concerns. “The views expressed in the Q&A from 2017 remain true,” iRobot told us. “Over the past several years, iRobot has continued to do more to strengthen, and clearly define, its stance on privacy and security. It’s important to note that iRobot takes product security and customer privacy very seriously. We know our customers invite us into their most personal spaces—their homes—because they trust that our products will help them do more. We take that trust seriously."

The article from 7 September 2017 follows:

About a month ago, iRobot CEO Colin Angle mentioned something about sharing Roomba mapping data in an interview with Reuters. It got turned into a data privacy kerfuffle in a way that iRobot did not intend and (probably) did not deserve, as evidenced by their immediate clarification that iRobot will not sell your data or share it without your consent.

Data privacy is important, of course, especially for devices that live in your home with you. But as robots get more capable, the amount of data that they collect will increase, and sharing that data in a useful, thoughtful, and considerate way could make smart homes way smarter. To understand how iRobot is going to make this happen, we spoke with Angle about keeping your data safe, integrating robots with the future smart home, and robots that can get you a beer.  .... ' 

Sunday, August 07, 2022

Who Owns Teslas Data?

 The Ownership of data developed in process.

Who Actually Owns Tesla’s Data?  The company, says the company—but other interpretations persist By MARK HARRIS   in IEEE Spectrum

On 29 September 2020, a masked man entered a branch of the Wells Fargo bank in Washington, D.C., and handed the teller a note: “This is a robbery. Act calm give me all hundreds.” The teller complied. The man then fled the bank and jumped into a gray Tesla Model S. This was one of three bank robberies the man attempted the same day.

When FBI agents began investigating, they reviewed Washington, D.C.’s District Department of Transportation camera footage, and spotted a Tesla matching the getaway vehicle’s description. The license plate on that car showed that it was registered to Exelorate Enterprises LLC, the parent company of Steer EV—a D.C.-based monthly vehicle-subscription service.

Agents served a subpoena on Steer EV for the renter’s billing and contact details. Steer EV provided those—and also voluntarily supplied historical GPS data for the vehicle. The data showed the car driving between, and parking at, each bank at the time of the heists. The renter was arrested and, in September, sentenced to four years in prison.  ... ' 

Privd AI for Differential Privacy

 Surveillance privacy from Cameras

Researchers from MIT CSAIL Introduce ‘Privid’: an AI Tool, Build on Differential Privacy, to Guarantee Privacy in Video Footage from Surveillance Cameras

By Annu Kumari -March 30, 2022  This research summary article is based on the paper 'Privid: Practical, Privacy-Preserving Video Analytics Queries' and MIT article 'Security tool guarantees privacy in surveillance footage'

Surveillance cameras have an identity crisis exacerbated by a conflict between function and privacy. Machine learning techniques have automated video content analysis on a vast scale as these sophisticated small sensors have shown up seemingly everywhere. Still, with increased mass monitoring, there are currently no legally enforceable standards to curb privacy invasions.

Security cameras have evolved into wiser and more capable tools than the grainy images of the past, which were frequently used as the “hero tool” in crime dramas. Video surveillance can now assist health regulators in determining the percentage of persons using masks, transportation departments in monitoring the density and flow of automobiles, cyclists and walkers, and businesses in gaining a better understanding of buying habits. But why has privacy remained a second-class citizen?

Privid

Currently, the footage is retrofitted with blurred faces or black boxes. This prevents analysts from asking some legitimate questions (for example, are people wearing masks? ). Dissatisfied with the present status quo, MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL) developed a system with other institutions to better guarantee privacy in surveillance video footage. The system, dubbed “Privid,” allows analysts to input video data searches and then adds a tiny amount of noise (additional data) to the result to ensure that no one can be identified. The method is based on a formal notion of privacy known as “differential privacy,” which permits without having access to aggregate statistics about private data disclosing individually identifying information. ... ' 

Monday, July 18, 2022

Digital Privacy Looking Grimmer

From ACM:  So to what degree do we accept it?  And how?  While protecting everyone else?

In a Post-Roe World, the Future of Digital Privacy Looks Even Grimmer    By The New York Times, July 15, 2022

Welcome to the post-Roe era of digital privacy, a moment that underscores how the use of technology has made it practically impossible for Americans to evade ubiquitous tracking.

In states that have banned abortion, some women seeking out-of-state options to terminate pregnancies may end up following a long list of steps to try to shirk surveillance — like connecting to the internet through an encrypted tunnel and using burner email addresses — and reduce the likelihood of prosecution.

Even so, they could still be tracked. Law enforcement agencies can obtain court orders for access to detailed information, including location data logged by phone networks. And many police departments have their own surveillance technologies, like license plate readers .... 

The state of digital privacy is already so far gone that forgoing the use of digital tools altogether may be the only way to keep information secure, security researchers said.

From The New York Times

View Full Article  

Thursday, June 30, 2022

NIST Tracks Software for Investigations

Broader than just software related aspects it seems,  digital files in any criminal  investigation,  will this lead to privacy objections? 

NIST Update to Software Reference Library Will Aid Criminal Investigations  

NIST, June 27, 2022

The U.S. National Institute of Standards and Technology (NIST) updated its National Software Reference Library (NSRL) to make it easier to search through data on electronic equipment seized in police raids during criminal investigations. In the database's first major update in 20 years, the number and type of records in the database were broadened to reflect the growing diversity of digital files that law enforcement might find on a device. NIST also has revised the records' format to make the NSRL more searchable. The SQLite format makes it easier for users to create tailored filters to screen files for desired content. Said NIST's Doug White, “The update should make it easier for police to separate the wheat from the chaff." 

Sunday, June 12, 2022

Apple vs. Feds: Is iPhone Privacy a Basic Human Right?

 HBS Case

Apple vs. Feds: Is iPhone Privacy a Basic Human Right?

26 MAY 2022| by Avery Forman

Leaders today must be ready to take a stand on thorny social and political issues. A case study by Nien-hĂȘ Hsieh and Henry McGee examines how Apple CEO Tim Cook turned calls for data access into a rallying cry for privacy, and the complexities that followed.

Apple CEO Tim Cook didn’t come to his post with an activist agenda, yet when law enforcement officials began pressuring the company to hand over iPhone users’ data without their permission, Cook took what he believed was a moral stance to protect consumers’ privacy.

He knew taking this position would embroil the company in an ugly fight—one that risked alienating some shareholders—but he felt strongly that Apple should champion its customers’ basic human right to privacy.

“We believe that a company that has values and acts on them can really change the world,” Cook said in 2015, a year after Apple debuted new privacy measures that blocked law enforcement from accessing its customers’ data. “There is an opportunity to do work that is infused with moral purpose.” He said shareholders who were only looking for a return on investment “should get out of the stock.”  .... ' 

Monday, June 06, 2022

Guaranteed Smart Home Privacy?

 Well tested in open contexts?

Peekaboo! A System to Guarantee Smart Home Privacy

Carnegie Mellon University CyLab Security and Privacy Institute

Daniel Tkacik, May 31, 2022

Researchers at Carnegie Mellon University's CyLab Security and Privacy Institute have developed a privacy-sensitive architecture for smart home applications. Peekaboo accepts requests from developers to share certain pieces of data, and guarantees only the minimum data needed to satisfy the requests is exchanged. The architecture has developers first declare all the data they intend to gather and under what conditions, where that data is being sent, and its granularity; an in-home hub then arbitrates between all devices in the home and the outside Internet. CyLab's HaoJian Jin said, "The Peekaboo protocol will allow users to manage privacy preferences for all of their devices in a centralized manner through the hub. Imagine not just a privacy nutrition label for an individual device, but a privacy nutrition label for an entire home."  ... '

Tuesday, May 17, 2022

Federated Learning and Privacy

Definitions of the terms and much more...  

Federated Learning and Privacy

By Kallista Bonawitz, Peter Kairouz, Brendan Mcmahan, Daniel Ramage

Communications of the ACM, April 2022, Vol. 65 No. 4, Pages 90-97  10.1145/3500240

Machine learning and data science are key tools in science, public policy, and the design of products and services thanks to the increasing affordability of collecting, storing, and processing large quantities of data. But centralized collection can expose individuals to privacy risks and organizations to legal risks if data is not properly managed. Starting with early work in 2016,13,15 an expanding community of researchers has explored how data ownership and provenance can be made first-class concepts in systems for learning and analytics in areas now known as federated learning (FL) and federated analytics (FA).

With this expanding community, interest has broadened from the initial work on federations of mobile devices to include FL across organizational silos, Internet of Things (IoT) devices, and more. In light of this, Kairouz et al.10 proposed a broader definition:

Federated learning is a machine learning setting where multiple entities (clients) collaborate in solving a machine learning problem, under the coordination of a central server or service provider. Each client's raw data is stored locally and not exchanged or transferred; instead, focused updates intended for immediate aggregation are used to achieve the learning objective.

An approach very similar in both philosophy and implementation, federated analytics17 can be taken to allow data scientists to generate analytical insight from the combined information in decentralized datasets. While the focus here is on FL, much of the discussion on technology and privacy applies equally well to FA use cases.

This article provides a brief introduction to key concepts in federated learning and analytics with an emphasis on how privacy technologies may be combined in real-world systems and how their use charts a path toward societal benefit from aggregate statistics in new domains and with minimized risk to individuals and to the organizations who are custodians of the data.  ...... ' 

Sunday, April 24, 2022

Security Tool Based on Surveillance Footage

 Have been thinking for sometime, how do you balance security and privacy in a world of quickly advancing and automated surveillance?  

Security tool guarantees privacy in surveillance footage  in MIT News

“Privid” could help officials gather secure public health data or enable transportation departments to monitor the density and flow of pedestrians, without learning personal information about people.

Rachel Gordon | MIT CSAIL,  March 28, 2022

Surveillance cameras have an identity problem, fueled by an inherent tension between utility and privacy. As these powerful little devices have cropped up seemingly everywhere, the use of machine learning tools has automated video content analysis at a massive scale — but with increasing mass surveillance, there are currently no legally enforceable rules to limit privacy invasions. 

Security cameras can do a lot — they’ve become smarter and supremely more competent than their ghosts of grainy pictures past, the ofttimes “hero tool” in crime media. (“See that little blurry blue blob in the right hand corner of that densely populated corner — we got him!”) Now, video surveillance can help health officials measure the fraction of people wearing masks, enable transportation departments to monitor the density and flow of vehicles, bikes, and pedestrians, and provide businesses with a better understanding of shopping behaviors. But why has privacy remained a weak afterthought? 

The status quo is to retrofit video with blurred faces or black boxes. Not only does this prevent analysts from asking some genuine queries (e.g., Are people wearing masks?), it also doesn’t always work; the system may miss some faces and leave them unblurred for the world to see. Dissatisfied with this status quo, researchers from MIT’s Computer Science and Artificial Intelligence Laboratory (CSAIL), in collaboration with other institutions, came up with a system to better guarantee privacy in video footage from surveillance cameras. Called “Privid,” the system lets analysts submit video data queries, and adds a little bit of noise (extra data) to the end result to ensure that an individual can’t be identified. The system builds on a formal definition of privacy — “differential privacy” — which allows access to aggregate statistics about private data without revealing personally identifiable information.

Typically, analysts would just have access to the entire video to do whatever they want with it, but Privid makes sure the video isn’t a free buffet. Honest analysts can get access to the information they need, but that access is restrictive enough that malicious analysts can't do too much with it. To enable this, rather than running the code over the entire video in one shot, Privid breaks the video into small pieces and runs processing code over each chunk. Instead of getting results back from each piece, the segments are aggregated, and that additional noise is added. (There’s also information on the error bound you're going to get on your result — maybe a 2 percent error margin, given the extra noisy data added). 

For example, the code might output the number of people observed in each video chunk, and the aggregation might be the “sum,” to count the total number of people wearing face coverings, or the “average” to estimate the density of crowds. 

Privid allows analysts to use their own deep neural networks that are commonplace for video analytics today. This gives analysts the flexibility to ask questions that the designers of Privid did not anticipate. Across a variety of videos and queries, Privid was accurate within 79 to 99 percent of a non-private system.

“We’re at a stage right now where cameras are practically ubiquitous. If there's a camera on every street corner, every place you go, and if someone could actually process all of those videos in aggregate, you can imagine that entity building a very precise timeline of when and where a person has gone,” says MIT CSAIL PhD student ​​Frank Cangialosi, the lead author on a paper about Privid. “People are already worried about location privacy with GPS — video data in aggregate could capture not only your location history, but also moods, behaviors, and more at each location.” 

Privid introduces a new notion of “duration-based privacy,” which decouples the definition of privacy from its enforcement — with obfuscation, if your privacy goal is to protect all people, the enforcement mechanism needs to do some work to find the people to protect, which it may or may not do perfectly. With this mechanism, you don’t need to fully specify everything, and you're not hiding more information than you need to.   .... '   (more with links to supporting papers) 

Friday, April 15, 2022

Location Privacy Challenged by Data From Friends, Strangers

Data From Friends, Strangers Shows Where You Are

Futurity.org, Lindsey Valich, April 11, 2022

An international team of scientists determined that data from friends and strangers can be used to predict someone's location, even when their personal devices' data-tracking functions are inactive. The University of Rochester's Gourab Ghoshal and colleagues analyzed three location-based social network datasets compiling millions of check-ins on applications like Brightkite, Facebook, and Foursquare, and one call-data record with over 22 million calls by almost 36,000 anonymous users. The team applied information theory and measures of entropy to learn that the mobility patterns of people with social ties to an individual incorporate as much as 95% of the data required to anticipate that individual's movements; even data from strangers could be used to predict up to 85% of a person’s movements. ...  

Saturday, April 02, 2022

Digital Identities: Here for the EU

More broadly, how do we manage the notion of readable digital identity?  Its use, misuse and maintenance?    Now and in the future.   Good piece.    

Europeans Wary of New Digital Identity    By Arnout Jaspers, Commissioned by CACM Staff, March 31, 2022

Europeans now need a digital QR code verifying their coronavirus immunization status in order to cross borders. Critics say the new European Digital Identity (EDI) framework tries to capitalize on that requirement to strangle the privacy of its citizens; others say the EDI could actually benefit privacy, if done right.

To buy alcohol in the European Union (EU), you need to prove that you are at least 18 years old, typically by handing a photo identification card to the cashier. But why should the cashier be able to read your full name, date and place of birth, and Social Security or driver's license number, before selling you a bottle of wine?

Unlike a physical ID, a digital ID can perform selective disclosure: it only shows the relevant attribute (in this case, verifying that the holder is 18 or older) and nothing else. 

This is how the European CoronaCheck app is set up: after scanning the QR code, the app displays a green flag if the app confirms the person being tested has been vaccinated, or was infected with the virus and can show proof of recovery, or detects proof of a recent negative PCR-test (or any combination of the three).  If none of those three conditions (or combination of them) is detected, the app displays a red flag.

A European Digital Identity, in the vision of the European Commission, would provide every EU citizen with a digital wallet ID that can perform selective disclosure on many more attributes. The wallet will contain personal data like one's fiscal number (in the U.S., this would be a Social Security number; in the Netherlands, it is the BSN number), but also detailed information on health and education; almost anything the owner wants to put in the wallet.

It will typically reside on the owner's smartphone, and the owner has to give permission for it to display specific attributes. A doctor might be allowed to see all the medical information, while a university in Italy would only be allowed to verify whether the owner really received her bachelor's degree from Oxford University.

In February, the European Commission released a call for proposals to develop an app for such a wallet ID. While the Commission does not have the authority to demand that all 27 EU member-states use the same app, it can enforce certain data and privacy standards.

The initiative has caused concern among privacy advocates, and an uproar among more-extreme anti-EU activists, who see the European Digital Identity as a decisive step towards total, CCP-style control of EU citizens.   .... '