Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, July 16, 2019

Facebook, why are you showing me adverts for [!!!]

So, I started getting adverts for [!!!]*** in my feed recently, and my first thought after I haven't been searching for that, was I haven't been talking about that. That pub conversation about the creepy ads that pop up suggesting something discussed earlier that day, like an over-eager personal assistant trying to anticipate needs you never thought you had, that happens nowadays. And I don't think it's just internet pareidolia, seeing order and intent in the random straw-scatter of commercial trolling. Although I'm still not sure why the internet is bringing me [!!!].

So, I'm fairly loose with my permissions on my phone - I'm a Google Guide, I have a timeline, I run phone games with sweeping permissions, linked up to my Facebook. Bixby's only partially set up (my assistant app) but I use google to identify music quite a lot, so it's used to listening. I should be a nice visible smear of data to the main data-brokers, with a location, interests, soundtrack and oh, waaay more. But could it really be listening?

Sure, I think so. I'm not even sure it would be hard. I'm while I'm not an expert in this area by any means here is my hypothesis.

All listening apps (and Facebook is one, because you can use it for phonecalls) keep a small amount of audio in buffer at all times (and Google is one, so you can run audio searches) so it can check for activation phrases (and Apple is one so it can run Siri) and become better at understanding your voice (and honestly, I could go on here for a while). Google knows where these files live. Possibly, lots of programmes know where these files live. If your phone and operating system are aligned (oh, and they have to be, so that audio can be improved on phone calls with poor connections) then those files can be accessed, analysed and used, perhaps to improve speech recognition technology (Google are open about doing this) and perhaps to give you a pair of jeans that might match the conversation you had about them earlier.

You'll notice I'm not saying this in a tone of any great panic. Part of the nature of buffered information is that it is both disposable and rapidly disposed, and audio is data-heavy. The vast bulk of this audio information will be dumped, though (as various experiences with web-cam data breaches have taught us), there are probably some bits and bobs retained as baseline, sample and reference, blah blah blah. That little ripple of activity around the data food source of the noise you're making is a weak and evanescent signal, not strong enough to do more than tweak an ad or improve a location report.

Who's listening? Mainly algorithms and analysis software, though good old Amazon puts samples to human ear. And what's it linked up to? If you visit that article (again - you probably read it once already) you'll note that it came from a whistle blower worried that they had neither reporting mechanism nor capability for troubling audio content. They couldn't identify the users as data was stripped of identification data on the way to the human listener, so no mechanisms for reporting data according to concerns about the individual was included in the business process. Protecting privacy and avoiding responsibility often do go hand in hand; and I suspect that you may insert qualifiers into that sentence. But it isn't always about what's possible. It's also about what's practicable.

So: algorithms filtering my audio wormcast for actionable data that my be used to fine-tune my advertising offer before said audio is dispersed by the tides of automated data cleansing? Practicable.  My phone listening in on my every word and alerting a third party when I make produce concerning content? Possible, and sadly I do know that there are apps for that, which are often used in the context of abuse, grooming and domestic violence. But doing that for everyone? Neither practicable (we don't have the resources for follow-up) nor possible (the processing power required would not be available) nor profitable (signal to noise ratio all wrong).

Tech giants listening to everything I say and using it to build a profile of me that could be used to deepfake my identity? In my dreams. No, seriously, I dream of having that much processing power dedicated to replicating my identity. It's a sort of tech immortality. Or not, I guess. Would you care?

To return briefly to [!!!], ****I should clarify that [!!!] in this case does not refer to the band. It's just a thing, you know. But not a thing I'd discuss in a public context. Never mind here's some music

Monday, July 02, 2018

life on the post-GDPR internet

Ever since GDPR landed, there has been an explosion of websites with full-page privacy flashes on the way in, redirects to unescapable permissions pages and from some providers, denial pages, either subtle (cookie-enforced trap-pages that cannot be passed), deniable (go to my plain-text version!!!!) or outright ("we have decided not to serve users within the European Union").

None of this is coming across as protecting the user, particularly as all those "solutions" bar the outright denial involve granting the sites more rights and permissions than they were previously exercising while withdrawing service to a larger or greater extent. So added to all the sites behind browser-buggering levels of advertising, undismissable startup flashes and paywalls, we now have to add all the sites that got into a strop over GDPR, and in their excitement let their legal and advertising staff trample over their UX and content workers in their rush to smack their users round the head repeatedly while yelling "look what you made us do!!!!!".

Because this is what it feels like. Come on, the world. Plenty of providers were able to look at GDPR, shrug and carry on, because that was what was being done already. No need to go off on a hysterical tizzy, guys - particularly as the horse has bolted here. My data is spattered through your servers, and no amount of privacy notices is going to change that, not now, not tomorrow and not for the future. particularly as I am a fully signed up Google-tithed, LJ-using, open Twitter account carrying, eyes-open-on-Instagram member of the open web.

It's not even shutting the stable door after the horse has bolted, It's more like repeatedly slamming the barn door in my face while all my stuff is already strewn all over the grass outside.

Just. Stop it.


Thursday, May 24, 2018

GDPR emails - the good, the bad and the inexplicable

Great news!!! Most organisations were already compliant with GDPR. Not that that stopped a lot of organisations going quite bananas over it (though not, predictably, the ones who were illegally buying my contact details and then illegally using them to spam me with (at best) grey legal marketing, gambling and dating "opportunities").

I'm going to quote my personal favourite notice here, because it's brief, to the point, and covers all the necessary:

Organisations have different approaches. [Redacted] is proceeding on the basis that people who have already signed up to receive our newsletter might reasonably want to continue to have it sent to their email addresses. This is referred to as relying on processing on the basis of 'legitimate interest'. As always, we will include a link to allow you to opt out of receiving our newsletters at any time.

This, plus a pretty picture, was an elegant sufficiency. But so many went down a different path. And here, in reverse order, are my GDPR email top of the flops:
  1. Three paragraphs of whingeing about the GDPR. I understand your woes. I feel them, having been to two briefings, one meeting, a compulsory e-learning and numerous informal chats on the topic this year. But if you're struggling so hard with the concept of data privacy perhaps your orgaisation is, I don't know... the kind that doesn't do that kind of thing?  Newsflash: these organisations exist and they send out LOADS of email, all the time. 
  2. Four increasingly needy emails in a row, three after I'd updated my preferences. Can it, Janet, I already said yes.
  3. A link to update my preferences, that lead to a form to input my information again, which you already have, or you wouldn't be contacting me. For heaven's sake, do we know each other or not?
  4. A link to update my preferences, that lead to a form to input my information again, which you already have, which then returned the error message "[redacted] is already subscribed to this list". I know that, you know that - but will you still love me tomorrow I still get your emails after 25th May?
  5. And in top place, standing out as a true beacon of practice in this area: An email explaining that the list you were subscribed to is being closed and you need to subscribe to a new GDPR-compliant list. On click-through, this form is asking you for a lot more personal information than you had previously shared with the company; it also has autofill disabled and a CAPTCHA that will not load in your (only very slightly slightly flaky) browser. Two browsers later, and the problem is still not resolving on desktop. Entry via the ipad (why is so much design still i-pad first?) finally loads the CAPTCHA - it's the notorious picture-style which drops into its usual round of fail. I wrestle the CAPTCHA to a standstill ... and the form crashes.
Never mind, eh.

There has been some really lovely practice in this area too - friendly checks, information pre-loaded, tidy forms, pretty design. Just for balance's sake, you understand.

Friday, January 26, 2018

don't deny them their data points

So I was at some training again yesterday and there was the usual chat about how much people online know abut you, and how bad it is that, that the government and the private companies all know where you are and what you're doing and I was back suddenly to five years ago and writing a paper about how a culture shift was needed, because so many people felt they were protecting people by not recording things about them. The fear their details would be stored up and used against them later, the desire to protect them from the judgement of others was overwhelming.

The urge comes from a good place, but I feel it is fundamentally misguided.

Recording people's information accurately, respectfully and securely is an act of true respect for that individual. Every time you squirrel, omit or conceal a person's data points you are denying them recorded reality. You are making yourself adjudicator, gatekeeper. You are asserting privilege, and denying others their rights.

Each data point changes the world. Those of us lucky enough to be purchasing, paying, buying, reproducing, shaping, constructing and changing are constantly creating data-casts around us. Those whose data gets squirrelled and forgotten are often the damaged, disenfranchised and disengaged.

Don't deny them their data points.