<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rube Reality &#187; Privacy</title>
	<atom:link href="http://rubereality.com/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://rubereality.com</link>
	<description>Ruminations of an unrepentant rube</description>
	<lastBuildDate>Tue, 07 Sep 2010 23:32:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Facebook&#8217;s New &#8220;Privacy&#8221;</title>
		<link>http://rubereality.com/2009/12/13/facebooks-new-privacy/</link>
		<comments>http://rubereality.com/2009/12/13/facebooks-new-privacy/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 12:57:56 +0000</pubDate>
		<dc:creator>Herkimer</dc:creator>
				<category><![CDATA[Tech & Science]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social networking]]></category>

		<guid isPermaLink="false">http://rubereality.com/?p=347</guid>
		<description><![CDATA[From Facebook&#8217;s help page on the privacy/security settings update: Some settings are changing with the recent updates to Facebook privacy, but Facebook’s commitment to providing you control over your information is not. Here’s a summary of what’s changing: Providing me control over my info&#8230;Well, let&#8217;s just see, shall we? The Privacy page has been simplified, [...]]]></description>
			<content:encoded><![CDATA[<p>From Facebook&#8217;s help page on the privacy/security settings update:</p>
<blockquote><p>Some settings are changing with the recent updates to Facebook privacy, but Facebook’s commitment to providing you control over your information is not. Here’s a summary of what’s changing:</p></blockquote>
<p>Providing <em>me</em> control over <em>my</em> info&#8230;Well, let&#8217;s just see, shall we?</p>
<blockquote>
<ul>
<li>The Privacy page has been simplified, and in that process, some settings have been consolidated. For security reasons, you will now be required to enter your password if you’d like to update your privacy settings.</li>
</ul>
</blockquote>
<p>Huh. Simplified &amp; consolidated &#8211; nice way to say &#8220;we rearranged the screen and got rid of some of those peskier settings.&#8221; And what security reason could justify entering my password to update my privacy settings? If someone has hacked my account that shouldn&#8217;t be messing with those settings, then they <em>already</em> have my password! Entering my password a second time does nothing to enhance my security or privacy &#8211; and it&#8217;s arguably worse without strong encryption being used.</p>
<blockquote>
<ul>
<li>A privacy control has been added to the publisher at the top of your home and profile page. This allows you to set privacy on individual posts. For example, you could post a status to Everyone or only to Friends. Learn more on the Publisher help page.</li>
</ul>
</blockquote>
<p>OK, even this curmudgeon has to admit this is a good thing.</p>
<blockquote>
<ul>
<li>Instead of having networks for regions (eg., Australia or New York City), people’s locations are now listed in the &#8220;Current City&#8221; or &#8220;Current Region&#8221; field of their profiles. This means if you use the &#8220;Friends and Networks&#8221; privacy setting, the networks part only applies to work and school networks.</li>
</ul>
</blockquote>
<p>What&#8217;s this have to do with security or privacy? Read on&#8230;</p>
<blockquote>
<ul>
<li>A basic set of information is publicly available, meaning it’s visible to anyone that’s able to navigate to your profile, applications you use on Facebook, and websites you connect with via Facebook. This information includes your name, profile picture, gender, current city, networks, friend list, and Pages. Any additional information (eg., photos or videos) will only be exposed if your privacy settings allow it.</li>
</ul>
</blockquote>
<p>This is where facebook is screwing the pooch. By providing all this information publicly, a hell of a profile can be built about any given person. This is a paradise for spammers, scammers, stalkers, and sickos. It&#8217;s a tyrannical government&#8217;s new tool. It&#8217;s a pedophile&#8217;s wet dream. And it&#8217;s a nightmare for anyone who desires or needs privacy.</p>
<blockquote><p>Keep in mind that anyone who navigates to your profile will be able to view your publicly available information and information you’ve made visible to Everyone. While you do have the option to hide your Friend List from being visible on your profile, it will be available to applications you use and websites you connect with using Facebook. In addition, your profile picture appears in places you make comments and posts. You can always change your current profile picture or lower your search visibility if you choose.</p></blockquote>
<p>Oh, yeah, the application gap. It amazes me the amount of info an application can get not just about me, but about my friends. Yes, the API documentation mentions what personal information you&#8217;re not supposed to retain about your users, but there&#8217;s no system security behind that API to enforce it. Oh, sure, there are the various agreements for facebook developers &#8211; but the honor system does no good when facebook does nothing to enforce those agreements. In reality, the more money an application makes, the more ad revenue facebook is getting a cut of &#8211; and the less likely they are to do anything about it. So the worst offenders (Zynga, for example) make millions scamming people. It&#8217;s only a matter of time before someone sells all the info they&#8217;ve mined out of facebook profiles. Maybe that&#8217;s why zynga is using <a title="iesnare" href="http://www.codingthewheel.com/archives/online-gambling-privacy-iesnare" target="_blank">iesnare</a>, and maybe that&#8217;s why I haven&#8217;t heard a peep from facebook since I filed a privacy violation about that issue.</p>
<p>The pages and friendlist are the two most egregious violations of privacy. You can build a fairly good picture of, for example, a person&#8217;s political affiliations, religious beliefs, and sexual tendencies, by examining their pages. Why does this need to be public? I used to be able to selectively show that to whoever I wanted or to nobody at all. Same deal with the friendlist &#8211; I could customize who would see that (and had it set to only the people I really knew in real life and trusted) &#8211; now it&#8217;s an all-or-nothing setting.  The setting to hide your friendlist from your profile doesn&#8217;t even do a thing to ensure the privacy of that. For example, if you&#8217;re logged onto facebook, take a look at Mark Zuckerberg&#8217;s <a title="Mark Zuckerberg's profile" href="http://www.facebook.com/zuck" target="_blank">profile</a>, and you&#8217;ll see he has hidden his friendlist from his public profile. However, by appending anybody&#8217;s facebook account id or account name to the end of www.facebook.com/friends/?id=, you can see their entire friend&#8217;s list, regardless of their privacy settings &#8211; <a title="Mark Zuckerberg's friend list" href="http://www.facebook.com/friends/?id=zuck" target="_blank">this</a> is Zuckerberg&#8217;s friend list, which I&#8217;m sure he won&#8217;t mind being shared like this since that base url is hardly a secret, and the same info can be gotten by platform applications and Connect sites.</p>
<blockquote><p>Publicly available information includes your name, profile picture, gender, current city, networks, friend list, and Pages. This information makes it easier for friends, family, and other people you know to connect with you.</p></blockquote>
<p>No, it makes facebook more like twitter, publicizes more of everyone&#8217;s info &#8211; especially when the search engines start crawling publicly enhanced profiles and putting together their own <a title="Social Graph" href="http://blogs.zdnet.com/BTL/?p=5156" target="_blank">social graphs</a> &#8211; and frankly only makes it easier for more people to connect with me who I <em><a title="Marketers relishing info sharing" href="http://www.theregister.co.uk/2009/12/11/facebook_privacy_furore/" target="_blank">don&#8217;t want to hear from</a></em> at all. In reality, despite the way this change has been spun by facebook, <em>I</em> have <em>less</em> control over my information with this change.</p>
]]></content:encoded>
			<wfw:commentRss>http://rubereality.com/2009/12/13/facebooks-new-privacy/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>The Fox is Guarding the Hen-house</title>
		<link>http://rubereality.com/2009/12/04/the-fox-is-guarding-the-hen-house/</link>
		<comments>http://rubereality.com/2009/12/04/the-fox-is-guarding-the-hen-house/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 04:32:28 +0000</pubDate>
		<dc:creator>Herkimer</dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Tech & Science]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[White House]]></category>

		<guid isPermaLink="false">http://rubereality.com/?p=275</guid>
		<description><![CDATA[From a research paper published by some Berkeley researchers: The Obama Administration is considering whether to change policy concerning the use of HTTP cookies on government websites. Currently, government officials require a “compelling need” to use persistent HTTP cookies, and must disclose their use in a privacy policy. In light of this we arbitrarily chose [...]]]></description>
			<content:encoded><![CDATA[<p>From a <a title="Research paper" href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1446862" target="_blank">research paper</a> published by some Berkeley researchers:</p>
<blockquote><p>The Obama Administration is considering whether to change policy concerning the use of HTTP cookies on government websites. Currently, government officials require a “compelling need” to use persistent HTTP cookies, and must disclose their use in a privacy policy.</p>
<p>In light of this we arbitrarily chose six government websites to determine whether Flash was being used to assign unique values to visitors. Of the 6 government sites we tested, 3 had Flash cookies. Three were set by whitehouse.gov, one of which was labeled, “userId.” Five of these sites used persistent HTTP cookies.</p>
<p>Whitehouse.gov disclosed the presence of a tracking technology in its privacy policy, but the policy does not specify that Flash cookies are present, nor does it provide any information on how to disable Flash cookies.</p></blockquote>
<p>The White House &#8220;<a title="White House disclosure" href="http://www.whitehouse.gov/privacy/" target="_blank">disclosure</a>&#8221; still doesn&#8217;t mention Flash cookies or how to disable them. It does however state the following:</p>
<blockquote><p>This persistent cookie is used by some third party providers to help maintain the integrity of video statistics. A waiver has been issued by the White House Counsel&#8217;s office to allow for the use of this persistent cookie.</p>
<p>If you would like to view a video without the use of persistent cookies, a link to download the video file is typically provided just below the video.</p></blockquote>
<p>If the White House videos can be viewed without the use of persistent cookies, than what <em>compelling</em> reason is there for this waiver?</p>
<p>This is so like this administration (and the several previous ones as well): Make a rule, then have the White House Counsel issue waivers for it. Obama&#8217;s first executive order was to forbid lobbyists from presidentially appointed positions &#8211; a waiver for that was issued before the day was out, and in less than a week, the second most important post in the Pentagon was given to a lobbyist. Not to mention Obama&#8217;s claim of &#8220;sovereign immunity&#8221; when it comes to lawsuits against the government concerning warrant-less wiretapping.</p>
<p>Until we have government officials who respect the Rule of Law &#8211; instead of the Rule of Individuals &#8211; and honor their oath to the Constitution, they shouldn&#8217;t expect anyone to trust them.</p>
]]></content:encoded>
			<wfw:commentRss>http://rubereality.com/2009/12/04/the-fox-is-guarding-the-hen-house/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
