812 Matching Annotations
  1. Jul 2018
    1. in connection with any business carried on in India, or any systematic activity of offering goods or services to data principals within the territory of India; or

      Since the Internet is boundary-less, this law will apply to all online services that are being consumed in India: apps downloaded, websites viewed.

    2. Where the data principal withdraws consentfor the processing of any personal data necessary for the performance of a contract to which the data principal is a party, all legal consequences for the effects of such withdrawal shall be borne by the data principal.

      How does it serve public interest and individual rights to hold people liable for the withdrawal of consent to the processing of their personal data?

    1. challenging and time-consuming

      I'd agree with all of the challenges identified here. Understanding these is useful in designing ways to help support faculty and staff regarding OEP. An additional challenge that emerged in my recent research on OEP was faculty concerns regarding privacy and identity -- this included defining (and continually negotiating) personal/professional & teacher/student boundaries in their open practice. Exploring such tensions is an important part of supporting faculty and staff consideration/exploration of open practices.

    1. Privacy advocates tried to explain that persuasion was just the tip of the iceberg. Commercial databases were juicy targets for spies and identity thieves, to say nothing of blackmail for people whose data-trails revealed socially risky sexual practices, religious beliefs, or political views.
  2. Jun 2018
  3. inst-fs-iad-prod.inscloudgate.net inst-fs-iad-prod.inscloudgate.net
    1. IDEAS FOR TECHNICAL MECHANISMSA technique called differential privacy1 provides a way to measure the likelihood of negative impact and also a way to introduce plausible deniability, which in many cases can dramatically reduce risk exposure for sensitive data.Modern encryption techniques allow a user’s information to be fully encrypted on their device, but using it becomes unwieldy. Balancing the levels of encryption is challenging, but can create strong safety guarantees. Homomorphic encryption2 can allow certain types of processing or aggregation to happen without needing to decrypt the data.Creating falsifiable security claims allows independent analysts to validate those claims, and invalidate them when they are compromised. For example, by using subresource integrity to lock the code on a web page, the browser will refuse to load any compromised code. By then publishing the code’s hash in an immutable location, any compromise of the page is detectable easily (and automatically, with a service worker or external monitor).Taken to their logical conclusion these techniques suggest building our applications in a more decentralized3 way, which not only provides a higher bar for security, but also helps with scaling: if everyone is sharing some of the processing, the servers can do less work. In this model your digital body is no longer spread throughout servers on the internet; instead the applications come to you and you directly control how they interact with your data.
  4. May 2018
  5. Apr 2018
    1. A purpose that is vague or general, such as for instance ‘Improving users’ experience’, ‘marketing purposes’, or ‘future research’ will – without further detail – usually not meet the criteria of being ‘specific’”.[

      I see a lot of cookie notices that give vague reasons like "improving user experience". Specifically disallowed by GDPR?

    2. The GDPR permits the opt-out approach when the purposes that the companies want to use the data for are “compatible” with the original purpose for which personal data were shared by users.[6] In addition to the opt-out notice, users also have to be told of their right to object at any time to the use of their data for direct marketing.[7]

      GDPR can allow opt out rather than opt in.

    1. Data Re-Use. Contractor agrees that any and all Institutional Data exchanged shall be used expressly and solely for the purposes enumerated in the Agreement. UH Institutional Data shall not be distributed, repurposed or shared across other applications, environments, or business units of the Contractor. The Contractor further agrees that no Institutional Data of any kind shall be revealed, transmitted, exchanged or otherwise passed to other vendors or interested parties except on a case-by-case basis as specifically agreed to in writing by a University officer with designated data, security, or signature authority.

      Like this clause. Wonder if this is the exception or the rule in Uni procurement deals these days?

  6. Mar 2018
  7. Feb 2018
  8. Jan 2018
  9. Dec 2017
    1. Projects by IF is a limited company based in London, England. We run this website (projectsbyif.com) and its subdomains. We also use third party services to publish work, keep in touch with people and understand how we can do those things better. Many of those services collect some data about people who are interested in IF, come to our events or work with us. Here you can find out what those services are, how we use them and how we store the information they collect. If you’ve got any questions, or want to know more about data we might have collected about you, email hello@projectsbyif.com This page was published on 25 August 2017. You can see any revisions by visiting the repository on Github.

      As you'd expect, If's privacy page is fantastic

  10. Nov 2017
    1. The users of a website known as Ashleymadison.com which was used by people who wanted to have secret relationships had 30 million of its users names released. This resulted in 2 suicides which were linked to the disclosure. The article talks about the “illusion” of internet securuity and if someone knows how to they can steal sensitive data and ruin lives. It shows that internet data is never truly safe. Related posts:

      i completely agree that today hackers can get into almost any device or software and this needs to be dealt with asap as people who do get exposed suffer miserably not only with depression but so much pressure too.

    2. i completely agree that today hackers can get into almost any device or software and this needs to be dealt with asap as people who do get exposed suffer miserably not only with depression but so much pressure too.

    1. Yes, it is very probable that you can due to the high probability that there is only one person of a specific gender and D.O.B., living in your zip code. However, it is possible that there could be a few people of the same demographic all living in a larger city.

      I do agree with the possibility of being able to trace someone based on all three aspects. I never really considered the likability for having the same demographic when living in a larger city.

    1. Every site you access and every vendor you purchase from keeps data on you and so does your computer. I think it is very important for everyone to be aware of this. If you access unreputable sites, it could be used against you in a job search for instance.

      I agree that everyone should be aware that every activity made on the Internet is monitored. Thus, with that data other people will be able to use those information to cause hindrance into our life. For example, our credit card information got hacked.

    1. It is likely that you can. Because odds are there is only one person that is the same age and birth day that lives in your zip code. But it is possible that you would only have a couple options.

      I agree as based on a study they could re-identify credit card users 90% of the time just based on information which were not personal to the credit card users.

  11. Oct 2017
    1. Opennessinrelationtosharingthushasmultiplemeaningsandisamatterofpoliticalcontestationthatbeliesthepositiveformulationsofitasafoundingimaginaryofcyberspace.Ontheonehand,itmeansmakinggovernmentstransparent,democratizingknowledge,collaboratingandco-producing,andimprovingwell-beingbutontheother,exposing,makingvisible,andopeningupsubjectstovariousknownandunknownpracticesandinterventions.[76]Alongwithparticipatingandconnecting,sharinggeneratesthesetensions,especiallyinrelationtowhatisoftenreducedtoasquestionsofprivacy.Thistensionthatopennessgeneratesincreasinglycreatesadditionaldemandsthatcitizenssecurethemselvesfromandberesponsibleforthepotentialandevenunknowableconsequencesoftheirdigitalconduct.
    2. Actsofconnectingrespondtoacallingthatpersistseveninlightofthetraceabilityofdigitalactionsandconcernsaboutprivacy.Thosewhoaremakingrightsclaimstoprivacyanddataownershiparebyfaroutnumberedbythosewhocontinuetosharedatawithoutconcern.Thatadatatraceisamaterialthatcanbemined,shared,analysed,andacteduponbynumerouspeoplemakestheimaginaryofopennessvulnerabletooftenunknownorunforeseeableacts.Butdigitaltracesalsointroduceanothertension.Anothercalling,thatofsharingdigitalcontentandtraces,isademandthatevokestheimaginaryofopennessfundamentaltotheveryarchitectureofsharedresourcesandgifteconomythatformedtheonce-dominantlogicofcyberspace
    1. The learning analytics and education data mining discussed in this handbook hold great promise. At the same time, they raise important concerns about security, privacy, and the broader consequences of big data-driven education. This chapter describes the regulatory framework governing student data, its neglect of learning analytics and educational data mining, and proactive approaches to privacy. It is less about conveying specific rules and more about relevant concerns and solutions. Traditional student privacy law focuses on ensuring that parents or schools approve disclosure of student information. They are designed, however, to apply to paper “education records,” not “student data.” As a result, they no longer provide meaningful oversight. The primary federal student privacy statute does not even impose direct consequences for noncompliance or cover “learner” data collected directly from students. Newer privacy protections are uncoordinated, often prohibiting specific practices to disastrous effect or trying to limit “commercial” use. These also neglect the nuanced ethical issues that exist even when big data serves educational purposes. I propose a proactive approach that goes beyond mere compliance and includes explicitly considering broader consequences and ethics, putting explicit review protocols in place, providing meaningful transparency, and ensuring algorithmic accountability. Export Citation: Plain Text (APA
  12. Sep 2017
    1. AsRonaldDeibertrecentlysuggested,whiletheInternetusedtobecharacterizedasanetworkofnetworksitisperhapsmoreappropriatenowtoseeitasanetworkoffiltersandchokepoints.[4]ThestruggleoverthethingswesayanddothroughtheInternetisnowapoliticalstruggleofourtimes,andsoistheInternetitself.

    Tags

    Annotators

    1. Apart from national security, the state may have justifiable reasons for the collection and storage of data. In a social welfare state, the government embarks upon programmes which provide benefits to impoverished and marginalised sections of society. There is a vital state interest in ensuring that scarce public resources are not dissipated by the diversion of resources to persons whodo not qualify as recipients

      Limits on privacy, national security and public good

    2. Liberty has a broader meaning of which privacy is a subset. All liberties may not be exercised in privacy. Yet others can be fulfilled only within a private space. Privacy enables the individual to retain the autonomy of the body and mind. The autonomy of the individual is the ability to make decisions on vital matters of concern to life

      Privacy as subset of liberty

    3. The concept is founded on the autonomy of the individual. The ability of an individual to make choices lies at the core of the human personality. The notion of privacy enables the individual to assert and control the human element which is inseparable from the personality of the individual. The inviolable nature of the human personality is manifested in the ability to make decisions on matters intimate to human life. The autonomy of the individual is associated over matters which can be kept private. These are concerns over which there is a legitimate expectation of privacy. The body and the mind are inseparable elements of the human personality. The integrity of the body and the sanctity of the mind can exist on the foundation that each individual possesses an inalienable ability and right to preserve a private space in which the human personality can develop. Without the ability to make choices, the inviolability of the personality would be in doubt. Recognizing a zone of privacy is but an acknowledgment that each individual must be entitled to chart and pursue the course of development of personality. Hence privacy is a postulate of human dignity itself.

      privacy and autonomy. Privacy a postulate of human dignity

    4. that there is a statutory regime by virtue of which the right to privacyis adequately protected and hence it is not necessary to read a constitutional right to privacy into the fundamental rights. This submission is sought to be fortified by contending that privacy is merely a common law right and the statutory protection is a reflection of that position

      A statutory and common law right to privacy negates the need for a constitutional right

    5. privacy should be protected only when access to information would reduce its value such as when a student is allowed access to a letter of recommendation for admission, rendering such a letter less reliable. According to Posner, privacy when manifested as control over information about oneself, is utilised to mislead or manipulate others

      Economic critique of privacy - posner

    6. Judith Jarvis Thomson,in an article published in 1975, noted that while there is little agreement on the content of privacy, ultimately privacy is a cluster of rights which overlap with property rights or the right to bodily security. In her view, the right to privacy is derivative in the sense that a privacy violation is better understood as violation of a more basic right

      Reductionist critique of privacy - JJ Thomson used by respondents to support the argument that privacy itself is not a right, but privacy violations may lead to other violations.

    7. The purpose of elevating certain rights to the stature of guaranteed fundamental rights is to insulate their exercise from the disdain of majorities, whether legislative or popular. The guarantee of constitutional rights does not depend upon their exercise being favourably regarded by majoritarian opinion. The test of popular acceptance does not furnish a valid basis to disregard rights which are conferred with the sanctity of constitutional protection

      Need for fundamental rights, and statutory protection not being sufficient

    8. The view about the absenceof a right to privacy is an isolated observation which cannot coexist with the essential determination rendered on the first aspect of the regulation. Subsequent Benches of this Court in the last five decades and more, have attempted to make coherent doctrine out of the uneasy coexistence between the first and the second parts of the decision in Kharak Singh

      Kharak Singh - the observation on absence of rt to privacy an isolated one at variuance with the first part?

    9. adverted to international conventions acceded to by India including the UDHR and ICCPR. Provisions in these conventions which confer a protection against arbitrary and unlawful interference with a person’s privacy, family and home would, it was held, be read in a manner which harmonizes the fundamental rights contained in Articles 14, 15, 19 and 21 with India’s international obligations

      Nalsa - recognition of international conventions in interpreting FRs

    10. our considered opinion that subjecting a person to the impugned techniques in an involuntary manner violates the prescribed boundaries of privacy. Forcible interference with a person's mental processes is not provided for under any statute and it most certainly comes into conflict with the “right against self-incrimination”

      Narco analysis, polygraph etc. right not to be compelled to give evidence seen as part of privacy as well, esp where investigative techniques involve interference with metal processes.

    11. Also, a large number of people are non-vegetarian and they cannot be compelled to become vegetarian for a long period. What one eats is one's personal affair and it is a part of his right to privacy which is included in Article 21 of our Constitution as held by several decisions of this Court.

      Hinsa Virodhak Sangh - aside from right to practise trade under 19 (1) (g), right to make one's eating choices was also invoked - example of privacy including decisional autonomy.

      Important to note that this principles is qualified by only being applied if the ban was for a considerable period of time

    12. access to bank records to the Collectordoes not permit a delegation of those powers by the Collector to a private individual. Hence even when the power to inspect and search is validly exercisable by an organ of the state, necessary safeguards would be required to ensure that the information does not travel to unauthorised private hands.

      Where delegation of responsibilities, need for proper safeguards. Very relevant observation in the context of PPP models of governance and data collection/processing

    13. Court repudiated the notion that a person who places documents with a bank would, as a result, forsake an expectation of confidentiality. In the view of the Court, even if the documents cease to be at a place other than in the custody and control of the customer, privacy attaches to persons and not places and hence the protection of privacy is not diluted

      2 important observations

      • recognition of privacy attached to persons and and not places (moving beyond a propertarian view of privacy)

      • sharing of information does not lead to forsaking a reasonable expectation of privacy. Without reference, repudiation of third party doctrine. privacy not quivalent with secrecy.

    14. While it is true that in Rajagopalit is a private publisher who was seeking to publish an article about a death row convict, itis equally true that the Court dealt with a prior restraint on publication imposed by the

      DYC responds to Bhatia's critique of Rajagopal. While Rajagopal dealt with private actions, Frs are invoked due to state action in the form restraint placed on the publication by the state and prison officials.

    15. bodily integrity of a woman, as an incident of her privacy.

      Maharashtra v. Madhukar two imp. observations - a woman of easy virtue is also entitled to the same constitutional protections. furthers the view that rights are available to all citizens (counter to the view in Malkani which said that privacy is not to protect the guilty)

      more importantly, established a woman's bodily integrity as a part of privacy

    16. observations in Malak Singhon the issue of privacy indicate that an encroachment on privacy infringes personal liberty under Article 21 and the right to the freedom of movement under Article 19(1)(d). Without specifically holding that privacy is a protected constitutional value under Article 19 or Article 21, the judgment of this Court indicates that serious encroachments on privacy impinge upon personal liberty and the freedom of movement

      Malak SIngh is on lines of the view of advanced by the respondents, that some violations of privacy could infringe other recognised rights such as personal liberty under 21 or freedom of movement under 19 (1) (d)

  13. Aug 2017
    1. Surveillance is the business model of the internet. Everyone is under constant surveillance by many companies, ranging from social networks like Facebook to cellphone providers. This data is collected, compiled, analyzed, and used to try to sell us stuff. Personalized advertising is how these companies make money, and is why so much of the internet is free to users. We’re the product, not the customer.

      Nice succinct statement on the issue.

    1. The request from the DOJ demands that DreamHost hand over 1.3 million visitor IP addresses — in addition to contact information, email content, and photos of thousands of people — in an effort to determine who simply visited the website. (Our customer has also been notified of the pending warrant on the account.)

      That information could be used to identify any individuals who used this site to exercise and express political speech protected under the Constitution’s First Amendment. That should be enough to set alarm bells off in anyone’s mind.

  14. Jul 2017
  15. Jun 2017
  16. May 2017
    1. People want to turn this into a legal debate, but it's not. It's a tools debate, and the main product of a builder of social tools is not the tool itself but the culture that it creates. So what sort of society do you want to create?

      Not trying to nitpick, but I'm a bit confused between this statement and the one below where Mike says "We're vulnerable to state-sponsored attacks, he says, because we are too narrowly technological in our solutions."

      So far in this debate I've been thinking that we are too quick to jump to technical solutions (as Mike's latter point would suggest) when I don't think the issues online are categorically different than they are offline. While certainly tools can help shape social relations and culture, we also have social/cultural mechanisms to deal with situations generated via online tools.

      Abuse is not limited to online activity and remedies for abuse are not purely technological. If a person abuses another offline, we have (imperfect) mechanisms to address that abuse. Are we considering those offline mechanisms in our confrontation with online abuse?

  17. Apr 2017
    1. The Echo Look suffers from two dovetailing issues: the overwhelming potential for invasive data collection, and Amazon’s lack of a clear policy on how it might prevent that.

      Important to remember. Amazon shares very little about what it collects and what it does with what it collects.

    1. Illustration cynique devant l’impuissance des États à réguler cette concentration, Google a davantage à craindre de ses concurrents directs qui ont des moyens financiers largement supérieurs aux États pour bloquer sa progression sur les marchés. Ainsi, cet accord entre Microsoft et Google, qui conviennent de régler désormais leurs différends uniquement en privé, selon leurs propres règles, pour ne se concentrer que sur leur concurrence de marché et non plus sur la législation.

      Trop gros, les GAFAM ne se sentent plus soumis aux lois. Ils s'arrangent entre eux.

    2. En produisant des services gratuits (ou très accessibles), performants et à haute valeur ajoutée pour les données qu’ils produisent, ces entreprises captent une gigantesque part des activités numériques des utilisateurs. Elles deviennent dès lors les principaux fournisseurs de services avec lesquels les gouvernements doivent composer s’ils veulent appliquer le droit, en particulier dans le cadre de la surveillance des populations et des opérations de sécurité.

      Voilà pourquoi les GAFAM sont aussi puissants (voire plus) que des États.

    3. En fait, je pense que la plupart des gens ne veulent pas que Google réponde à leurs questions. Ils veulent que Google dise ce qu’ils doivent faire ensuite.

      Qui a dit que Google répond à vos questions ? Depuis longtemps, Google fait les questions et les réponses (à vos dépens).

    1. Privacy tech doesn’t take the place of having the law on your side.

      Nowadays, to protect your privacy you need to:

      have the law on your side + trust service providers + use privacy tech

  18. Mar 2017
    1. “At the heart of that First Amendment protection is the right to browse and purchase expressive materials anonymously, without fear of government discovery,” Amazon wrote in its memorandum of law.  

      Amazon doesn't provide information about a murder to protect users from the government. This must be a joke!

    1.  Interior enforcement of our Nation's immigration laws is critically important to the national security and public safety of the United States.  Many aliens who illegally enter the United States and those who overstay or otherwise violate the terms of their visas present a significant threat to national security and public safety.  This is particularly so for aliens who engage in criminal conduct in the United States.

      Like so.

    1. You can delete the data. You can limit its collection. You can restrict who sees it. You can inform students. You can encourage students to resist. Students have always resisted school surveillance.

      The first three of these can be tough for the individual faculty member to accomplish, but informing students and raising awareness around these issues can be done and is essential.

  19. Feb 2017
    1. Instead of his usual gear, the Seattle-based security researcher and founder of a stealth security startup brings a locked-down Chromebook and an iPhone SE that’s set up to sync with a separate, non-sensitive Apple account.

      You do what you have to do...

    1. All along the way, or perhaps somewhere along the way, we have confused surveillance for care. And that’s my takeaway for folks here today: when you work for a company or an institution that collects or trades data, you’re making it easy to surveil people and the stakes are high. They’re always high for the most vulnerable. By collecting so much data, you’re making it easy to discipline people. You’re making it easy to control people. You’re putting people at risk. You’re putting students at risk.
  20. Jan 2017
    1. e) We also may make use of third party tracking pixels used by advertising or analytical partners. Some such partners include, but are not limited to: (i) Google Analytics: Used to track statistical information such as page visits and traffic source information allowing us to improve the performance and quality of the Site. For more information please visit: http://www.google.com/analytics/learn/privacy.html. (ii) Google Advertising: Used to track conversions from advertisements on the Google Search and Google Display network. For more information please visit: http://www.google.com/policies/technologies/ads/. Third party pixels and content may make use of cookies. We do not have access or control over these third party cookies and this Policy does not cover the use of third party cookies.

      When the VPN client you intend to use is in fact the one that will leak your personal data!

      What a shame!

    1. The open architecture of the internet reflected the liberal worldview of its creators. As well as being decentralised, the internet was also deliberately designed to be a dumb network.

      Open, decentralised and not meant to know what is transmitted: that's how the Internet has been created. Perfect to protect privacy!

      Sad there are so many people who fight against the Internet today...

    1. In short, the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification.

      Security considered from different perspectives leads to security flaws!

    1. Almost half of eight- to 11-year-olds have agreed impenetrable terms and conditions to give social media giants such as Facebook and Instagram control over their data, without any accountability, according to the commissioner’s Growing Up Digital taskforce. The year-long study found children regularly signed up to terms including waiving privacy rights and allowing the content they posted to be sold around the world, without reading or understanding their implications.
  21. Dec 2016
  22. Nov 2016
    1. Mike Pompeo is Trump's pick for CIA director. In January 2016, Pompeo advocated "re-establishing collection of all metadata, and combining it with publicly available financial and lifestyle information into a comprehensive, searchable database. Legal and bureaucratic impediments to surveillance should be removed" (At least they acknowledge that backdoors in US hardware and software would do little good.)

      Oh, cute. Pompeo made a name for himself during the Benghazi investigation.<br> http://www.nytimes.com/2016/11/19/us/politics/donald-trump-mike-pompeo-cia.html

  23. Oct 2016
    1. Hemisphere isn’t a “partnership” but rather a product AT&T developed, marketed, and sold at a cost of millions of dollars per year to taxpayers. No warrant is required to make use of the company’s massive trove of data, according to AT&T documents, only a promise from law enforcement to not disclose Hemisphere if an investigation using it becomes public.

      ...

      Once AT&T provides a lead through Hemisphere, then investigators use routine police work, like getting a court order for a wiretap or following a suspect around, to provide the same evidence for the purpose of prosecution. This is known as “parallel construction.”

  24. Sep 2016
    1. d  Provider  has  a  limited,  nonexclusive  license  solely  for  the  purpose  of  performing  its  obligations  as  outlined  in  the  Agreeme

      Here we are good and much better than, say, Genius:

      When you post User Content to the Service or otherwise submit it to us, you hereby grant, and you represent and warrant that you have the right to grant, to Genius an irrevocable, perpetual, non-exclusive, transferable, fully paid, worldwide license (with the right to sublicense through multiple tiers) to use, reproduce, publicly perform, publicly display, modify, translate, excerpt (in whole or in part), create derivative works of, distribute and otherwise fully exploit all Intellectual Property Rights in and to such User Content for purposes of providing, operating and promoting the Service or otherwise conducting the business of Genius.

    2. Data  Transfer  or  Destruction

      This is the first line item I don't feel like we have a proper contingency for or understand exactly how we would handle it.

      It seems important to address not just due to FERPA but to contracts/collaborations like that we have with eLife:

      What if eLife decides to drop h. Would we, could we delete all data/content related to their work with h? Even outside of contract termination, would we/could we transfer all their data back to them?

      The problems for our current relationship with schools is that we don't have institutional accounts whereby we might at least technically be able to collect all related data.

      Students could be signing up for h with personal email addresses.

      They could be using their h account outside of school so that their data isn't fully in the purview of the school.

      Question: if AISD starts using h on a big scale, 1) would we delete all AISD related data if they asked--say everything related to a certain email domain? 2) would we share all that data with them if they asked?

    1. Responsible Use

      Again, this is probably a more felicitous wording than “privacy protection”. Sure, it takes as a given that some use of data is desirable. And the preceding section makes it sound like Learning Analytics advocates mostly need ammun… arguments to push their agenda. Still, the notion that we want to advocate for responsible use is more likely to find common ground than this notion that there’s a “data faucet” that should be switched on or off depending on certain stakeholders’ needs. After all, there exists a set of data use practices which are either uncontroversial or, at least, accepted as “par for the course” (no pun intended). For instance, we probably all assume that a registrar should receive the grade data needed to grant degrees and we understand that such data would come from other sources (say, a learning management system or a student information system).

  25. Aug 2016
    1. What if, as the cybersecurity consultant Matt Tait asked last month in relation to the DNC emails, a source — like, say, a hacker working for a Russian intelligence agency — provided WikiLeaks with a cache of documents that was tampered with in order to smear a political candidate?
  26. Jul 2016
  27. Jun 2016
    1. Whenever possible, it is important to give creators the right of refusal if they do not wish their work to be highly visible. Because of the often highly personal content of zines, creators may object to having their material being publicly accessible. Zinesters (especially those who created zines before the Internet era) typically create their work without thought to their work ending up in institutions or being read by large numbers of people. To some, exposure to a wider audience is exciting, but others may find it unwelcome

      makes the important distinction between the widely acknowledged categories of visibility - public and private - and equally important, but less widely recognized points on the spectrum of visibility - more and less visible, digitized and searchable versus digitized and not searchable, among others

    1. Revoking Permissions. If you change your mind about our ongoing ability to collect information from certain sources that you have already consented to, such as your phonebook, camera, photos, or location services, you can simply revoke your consent by changing the settings on your device if your device offers those options.

      What happens to the data already shared if permission is revoked?

    2. f you submit content to one of our inherently public features, such as Live, Local, or any other crowd-sourced service, we may retain the content indefinitely.

      Is there a clear distinction in the flow of the app for the common user that there is a significant difference between the methods of sharing images or video?

    3. For example, if another user allows us to collect information from their device phonebook—and you’re one of that user’s contacts—we may combine the information we collect from that user’s phonebook with other information we have collected about you.

      I may choose not to allow my phone number to be shared, but a friend allows Snapchat to access their phonebook. My once-private information is now shared with a company without my consent.

    4. Information We Get When You Use Our Services

      It's important to remember that all of the following falls under "data which is necessary to provide a service."

      The quantity of information gathered here is enormous. Most of it seems innocuous, but it's all very personal and, implicit in their use of data for advertising, stored on Snapchat's servers with no time for deletion noted.

      This section outlines how Snapchat will continue to stay in business - by farming the information of its users and selling it for advertising.

    5. Of course, you’ll also provide us whatever information you send through the services,

      How many people forget that Snapchat actually sees everything sent? Is this explicitly shared with students when we're teaching?

      We cannot assume they're aware of the transfer of data that takes place when that data is sent through an app or website.

  28. May 2016
    1. If Turnitin is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our website, of any change in ownership, uses of your personal information, and choices you may have regarding your personal information.

      A. merger voids any privacy pledges. The new owner has no requirement to follow these policys.

      B. The information is kept for an extended period of time. Once a teacher leaves a school district, their email will be invalid. It's a vacuous promise to say that they'll be contacted.

  29. Apr 2016
  30. Feb 2016
    1. Some plural User subject that is conjoined by a proxy link or other means could be composed of different types of addressable subjects: two humans in different countries, or a human and a sensor, a sensor and a bot, a human and a robot and a sensor, a whatever and a whatever. In principle, any one of these subcomponents could not only be part of multiple conjoined positions, but might not even know or need to know which meta-User they contribute to, any more than the microbial biome in your gut needs to know your name.

      Anonymity is not a binary, it is the limit of dissolution into a coherent plural subject.

  31. Jan 2016
    1. Vigilant Solutions, a surveillance technology company, is making shady deals with police departments in Texas. They lend the police equipment and database access. The police use it to spot people with outstanding warrants, whom they can stop and take payments from by credit card -- with a 25% processing fee tacked on for the tech company. The company also intends to keep all the license plate data collected by the police.

    1. One of the drawbacks of anonymity on the Web is romance scams. Scammers set up fake personas on social media. They often use photos stolen from a real person's accounts

      When the same person has their photos stolen repeatedly, Facebook could prevent this easily. But they don't.

    1. “traffic analysis.” It’s basis lies in observing all message traffic traveling on a network and discerning who’s communicating with whom, how much, and when.

      The strategy seems to be archive everything in case traffic analysis finds something worth going back and reading.

      Defense against traffic analysis:

      Messages from users must be padded to be uniform in size and combined into relatively large “batches,” then shuffled by some trustworthy means, with the resulting items of the randomly ordered output batch then distributed to their respective destinations. (Technically, decryption needs to be included in the shuffling.) Mix network

      He then talks about limited anonymity and pairwise pseudonyms as ways of solving problems with complete anonymity versus public identification. There is an article in Wired about his proposed system.

    1. from Hawaii to Alabama to New Hampshire, a diverse, bipartisan coalition of state legislators will simultaneously announce state legislative proposals that, although varied, are all aimed at empowering their constituents to #TakeCTRL of their personal privacy. These bills would go far in ensuring students, employees, and everyone else has more of a say over who can know their whereabouts, track their activities online, and view information they share with friends.
    1. Finding [Silk Road founder Ross] Ulbricht really boiled down to this: a bunch of Google searches done by an investigator for the Internal Revenue Service (IRS).<br> . . .<br> His preferred tool: Google. Particularly the advanced search option that lets you focus in on a date range.<br> . . .<br> Alford couldn’t be at Ulbricht’s arrest, but he did receive a plaque. The NYT reports that Alford’s superiors had it inscribed with this quote from Sherlock Holmes: "The world is full of obvious things which nobody by chance ever observes."

  32. Dec 2015
    1. So you think mass surveillance isn't a problem, since you have nothing to hide? There are so many federal crimes that it is impossible to count them. If the government decides to focus on you, they can probably find a crime that fits your actions.

    1. A personal API builds on the domain concept—students store information on their site, whether it’s class assignments, financial aid information or personal blogs, and then decide how they want to share that data with other applications and services. The idea is to give students autonomy in how they develop and manage their digital identities at the university and well into their professional lives
    1. Congress on Friday adopted a $1.15 trillion spending package that included a controversial cybersecurity measure that only passed because it was slipped into the US government's budget legislation. House Speaker Paul Ryan, a Republican of Wisconsin, inserted the Cybersecurity Information Sharing Act (CISA) into the Omnibus Appropriations Bill—which includes some $620 billion in tax breaks for business and low-income wage earners. Ryan's move was a bid to prevent lawmakers from putting a procedural hold on the CISA bill and block it from a vote. Because CISA was tucked into the government's overall spending package on Wednesday, it had to pass or the government likely would have had to cease operating next week.

      House 316-113<br> Senate 65-33

      The Verge "This morning, Congress passed the Cybersecurity Information Sharing Act of 2015, attached as the 14th rider to an omnibus budget bill. The bill is expected to be signed into law by the president later today."

      Techdirt 15 Dec

      1. Allows data to be shared directly with the NSA and DOD, rather than first having to go through DHS.
      2. Removes restrictions on using the data for surveillance activities.
      3. Removes limitation on using the data for cybersecurity purposes, and allows it to be used for investigating other crimes -- making it likely that the DEA and others will abuse CISA.
      4. Removes the requirement to "scrub" the data of personal information unrelated to a cybersecurity threat before sharing the data.

      ACLU

    1. Manhattan district attorney Cyrus R. Vance Jr. says that law enforcement agencies want Google and Apple to return to systems without full-disk encryption -- those before iOS 8 and Android Lollipop -- which they could unlock in compliance with a warrant.

      He says that's all they're asking. If that's true, they should be speaking out loudly against mass surveillance and FBI demands for backdoors.

    1. And the latest is that it's getting worse. Not only is Congress looking to include it in the end of year omnibus bill -- basically a "must pass" bill -- to make sure it gets passed, but it's clearly dropping all pretense that CISA isn't about surveillance. Here's what we're hearing from people involved in the latest negotiations. The latest version of CISA that they're looking to put into the omnibus:
    1. The Senate’s recently passed bill, known as the Cybersecurity Information Sharing Act (CISA), is expected to serve as the basis for the finished language. The compromise text will also likely include elements from a bill that originated in the House Intelligence Committee, observers said.This completed product would mostly sideline the privacy advocate-preferred bill from the House Homeland Security Committee. They believe the Homeland Security bill includes the strongest provisions to protect people’s sensitive data from falling into the NSA's hands.Specifically, the Homeland Security bill would give the greatest role to the Department of Homeland Security (DHS) for collecting cyber threat data from the private sector and disseminating it throughout the government.It’s believed the DHS is best suited to scrub data sets of personal information.

      It seems necessary to encourage -- or force -- industrial and financial firms to share information with the government about hacks and attempted hacks. But that should not be used as license to transfer and collect customer metadata,

    1. The San Bernardino shootings are also being cited by some Republicans, including presidential candidate Sen. Marco Rubio, as a reason to reinstate the warrantless bulk collection of domestic telephone data — the one program that was shut down by Congress after NSA whistleblower Edward Snowden revealed a massive, secret surveillance dragnet. An Associated Press story on Saturday added fuel to the fire when it claimed that as a result of the shutdown, the government could no longer access historical call records by the San Bernardino couple. But as Emptywheel blogger Marcy Wheeler amply explained, the FBI has plenty of other ways of getting the information.
    1. The National Security Letter (NSL) is a potent surveillance tool that allows the government to acquire a wide swath of private information—all without a warrant. Federal investigators issue tens of thousands of them each year to banks, ISPs, car dealers, insurance companies, doctors, and you name it. The letters don't need a judge's signature and come with a gag to the recipient, forbidding the disclosure of the NSL to the public or the target.