Why Do You Know So Much About Me

62
Why DoYou Know So Much About Me? Privacy in the Digital Age

description

This is the 9th lecture of my Interactive Global & Regional Marketing course. This lecture covers privacy in the digital age.

Transcript of Why Do You Know So Much About Me

Page 1: Why Do You Know So Much About Me

WhyDoYouKnowSoMuchAboutMe?

PrivacyintheDigitalAge

Page 2: Why Do You Know So Much About Me
Page 3: Why Do You Know So Much About Me
Page 4: Why Do You Know So Much About Me

NottalkingaboutsurveillanceNottalkingaboutthegovernment

Butrather

Thevoluntarydisclosureofpersonalinformationtoprivateinstitutions

Page 5: Why Do You Know So Much About Me

Wesayonething.Iwantmyprivacy.

Wedosomethingelse.Here’smydata.Takewhatyouwant.

(justgivememystuff)

Page 6: Why Do You Know So Much About Me

43%ofonlineusersclaimthattheyarelikelytoreadtheprivacypolicyofawebsitebeforebuyinganything

Page 7: Why Do You Know So Much About Me
Page 8: Why Do You Know So Much About Me

WhatPrivacyStatementsSay

Page 9: Why Do You Know So Much About Me

26%actuallyconsultedtheprivacypolicy

Evenmoreodd,therewasnodifferencebetweenprivacyfundamentalists,pragmatists,ortheunconcerned

Page 10: Why Do You Know So Much About Me

71%wanttocontrolwhocanaccesstheirpersonalinformation

Page 11: Why Do You Know So Much About Me
Page 12: Why Do You Know So Much About Me

75%havesupplied

• Firstname• Lastname• E‐mail• Streetaddress

50%havesupplied

• Phonenumber• Birthday• Creditcardinformation

Page 13: Why Do You Know So Much About Me

“Youhavezeroprivacy.Getoverit”

ScottMcNealyFormerCEOSunMicrosystems

Page 14: Why Do You Know So Much About Me

“Ifyouhavesomethingyoudon’tanyonetoknow,maybeyoushouldn’tbedoingitinthefirstplace.”

EricSchmidtFormerGoogleCEO

Page 15: Why Do You Know So Much About Me

“Peoplehavegottenmorecomfortablenotonlysharingmoreinformation,butmoreopenlyandwithmorepeople.”

MarkZukerbergFacebookCEO

Page 16: Why Do You Know So Much About Me

Whatdoyouthinkprivacyis?

Page 17: Why Do You Know So Much About Me

Privacyis….?  Secrecy,Concealment,Seclusion,Solitude,Confidentiality,Anonymity

  PrejudicialInformation  PersonallyIdentifiableInformation(PII) Whateveryouwantittobe

Page 18: Why Do You Know So Much About Me

Privacyistheclaimofindividuals,groups,orinstitutionstodetermineforthemselveswhen,how,andtowhatextentinformationaboutthemiscommunicatedtoothers.

Page 19: Why Do You Know So Much About Me

Viewedintermsoftherelationoftheindividualtosocialparticipation,privacyisthevoluntaryandtemporarywithdrawalofapersonfromageneralsocietyintoaconditionofanonymityorreserve.

Page 20: Why Do You Know So Much About Me

Privacyistheabilityofanindividualorgrouptosecludethemselvesorinformationaboutthemselvesandtherebyrevealthemselvesselectively.

Page 21: Why Do You Know So Much About Me

PrivacyinColonialAmerica  Findanopenfieldtotalk  Sneakoffintothewoods  Noprivacyindoors  Churchesencouragedneighborstosnooponeachother

Page 22: Why Do You Know So Much About Me

Privacyinthe1800s  Long‐distancecommunicationbytelegraph  Letters  Concernaboutinvasivepress  Snoopingdiscouraged  Gossip,WordofMouth

Page 23: Why Do You Know So Much About Me

Privacyfrom1900‐1965  Firstbuggingdevice  Searchofelectronicconversationsconstitutional  Telephonecommunicationsoverwires  ColdWarpromptsgovernmenttoincreasesurveillanceofcivilianswithouttheirknowledge

Page 24: Why Do You Know So Much About Me

Privacyfrom1965‐1990 WatergateScandal  Personalcomputers  Public‐keyencryptioninvented  Internetemerged  Sensationalistjournalism

Page 25: Why Do You Know So Much About Me

Privacyfrom1990‐2001  Noprivacyforpublicfigures Wirelesscommunication  Cameras  Satellites  Confusionoverwhoownscontentoncomputernetworks

Page 26: Why Do You Know So Much About Me

PrivacyAfterSeptember11th  Privatecustomerinformationdivulgedtofederalauthoritieshuntingforterroristsorcriminals

  Airportsearches  PollsintheUSindicatedthatpeoplethinkthatthe1stamendmentoftheUSConstitutionmightgotoofar

Page 27: Why Do You Know So Much About Me

TotalInformationAwareness  Post9/11projectto:

  [Create]enormouscomputerdatabasestogatherandstorethepersonalinformationintheUnitedStates,includingpersonalemails,socialnetworkanalysis,creditcardrecords,phonecalls,medicalrecords,andnumerousothersources,withoutanyrequirementforasearchwarrant.Additionally,theprogramincludedfundingforabiometricsurveillancetechnologiesthatcouldidentifyandtrackindividualsusingsurveillancecamerasandothermethods.

Page 28: Why Do You Know So Much About Me

Television&Privacy  1992broughtthelaunchofRealityTelevisionwhereeveryone’slivesbecamepublicconsumption

  Thisbroughtaboutshowsaboutpeople:  Livingtogetherinhomesandislands  Familiesstrugglingwithpersonalissues  Celebritiesprivateissuesmadepublic  Peopleshowingofftheirstupiditytowinmoneyandfame

  Inshort,RealityTVtooktheprivacydiscussiontoanewlevel

Page 29: Why Do You Know So Much About Me

PrivacyToday  YouTubehasendedallformsofpersonalprivacy  Bloggershavemadetheirpersonal(andtheirfriends/acquaintances)livestopicsofdiscussionoftheentireworld

  Andthencamesocialnetworks…. Wearecomfortablesharingourlivesandthoughtsinstantlywiththousandsofpeople–closefriendsandstrangersalike

Page 30: Why Do You Know So Much About Me

WaysTechnologyThreatensPrivacy  Phishing Malware&Spyware  SocialNetworkingsites  Photo&VideoSharing WebHistory  TargetedAdvertising&Cookies

  CloudComputing  ElectronicMedicalData  PublicWi‐Fi  RetailLoyaltyCards WorkplaceComputers  CellPhones

Page 31: Why Do You Know So Much About Me

WhyPrivacyHasChanged?  Curiosity  Convenience  TheInternetandEvolvingTechnology  SocialTrends  Desiretorelate&sharewithothers  Identity  Fame  Posterity

Page 32: Why Do You Know So Much About Me

Theprimarybusinessmodeloftoday’smostsuccessfulcorporationisthemonetizationinthemasscollection,correlation&analysisofindividualprivatedata

Page 33: Why Do You Know So Much About Me

PrivateInfoMonetized  Acxiom–750billionpiecesofinformationor1,500factson½billionpeople  Correlate“consumer”infofromsignups,surveys,magazine

subscriptions  USD1.38billionturnoverforFY2008

  Colligent–Actionableconsumerresearchderivedfromsocialnetworks

  Rapleaf–450millionsocialnetworkprofiles  Submitrequestandaggregatedsocialnetworkprofilesreturned

withinaday  Phorm

  Uses“behavioralkeywords”–keywordsderivedfromacombinationofsearchterms,URLsandevencontextualpageanalysisovertime–tofindtherightusers

Page 34: Why Do You Know So Much About Me

HowItAffectsUs?

Page 35: Why Do You Know So Much About Me

White’sTaxonomyofOnlinePrivacyInvasion

Web

Request

CrossSiteTracking

RichBrowserEnvironments

ApplicationData

Aggregation,Correlation&Meta‐Data

Page 36: Why Do You Know So Much About Me

Taxonomy–WebRequest  Asinglewebrequest

  Animageonawebsite

  Onewebpageismadeupofmultiplerequests

  WhatTheyCanFindOut  Location(Latitude,Longitude,

City,Country)  Language  OperatingSystem&Browser  Whatsiteyoucamefrom  ISP  Haveyoubeenherebefore?

Web

Request

Page 37: Why Do You Know So Much About Me

Taxonomy–CrossSiteTracking  Usingcookiestotrackacrosscomputersandaffiliatedsites

  Cookieisstoredonyourcomputerandsentwitheveryrequest

  Cookiesusuallyassociatedwithlogindetails

 WhatTheyCanFindOut  Whoyouare  Whatsitesyouvisit  Behavioralprofiles

CrossSiteTracking

Page 38: Why Do You Know So Much About Me

Taxonomy–RichBrowserEnvironments  RichWeb2.0Technologies

  JavaScript/AJAX  Flash/Silverlight

 WhatTheyCanFindOut  Browserhistory  Clipboarddata  Keypresses  Visualstimulus  Browserplugins  Desktopdisplaypreferences

RichBrowserEnvironments

Page 39: Why Do You Know So Much About Me

Taxonomy–ApplicationData  RichInformationInputs  Structured&UnstructuredData  Searchrequests  E‐mails  Calendaritems  InstantMessage

Communications

  WhatTheyCanFindOut  Whoyouare  Whoyourfriendsare  Whatyou’redoingonSunday  YourInterests

ApplicationData

Page 40: Why Do You Know So Much About Me

Taxonomy–Aggregation,Correlation&MetaData  Combiningthepreviouslevels

  Meta‐Data–Includeinteractionswithapplications

  Aggregation–combiningtheinformationfromvarioussources

  Correlation–normalizingentitiesacrosssources

  Providesinformationyoumaynotbeawareof

  Whattheycanfindout  Socialnetworks  Behavioralprofiles  Psychologicalprofiles  Deepdatabases

Aggregation,

Correlation&

Meta‐Data

Page 41: Why Do You Know So Much About Me

HowDoesInformationGetRevealed?

Page 42: Why Do You Know So Much About Me

ByISPs  ISPsalwaysknowyourIPaddressandtheIPaddresstowhichyouarecommunicating

  ISPsarecapableofobservingunencrypteddatapassingbetweenyouandtheInternetbutnotproperly‐encrypteddata

  Theyareusuallypreventedtodosoduetosocialpressureandlaw

Page 43: Why Do You Know So Much About Me

ByE‐Mail Maybeinappropriatelyspreadbytheoriginalreceiver Maybeintercepted Maybelegallyviewedordisclosedbyserviceprovidersorauthorities

Page 44: Why Do You Know So Much About Me

ByDiscussionGroups  Thereisnobarrierforunsolicitedmessagesoremailswithinamailinglistoronlinediscussiongroup

  Anymemberofthelistorgroupcouldcollectanddistributeyouremailaddressandinformationyoupost

Page 45: Why Do You Know So Much About Me

ByInternetBrowsers Mostwebbrowserscansavesomeformsofpersonaldata,suchasbrowsinghistory,cookies,webformentriesandpassword

  Youmayaccidentallyrevealsuchinformationwhenusingabrowseronapubliccomputerorsomeoneelse's

Page 46: Why Do You Know So Much About Me

BySearchEngines  SearchengineshaveandusetheabilitytotrackeachoneofyoursearchesbyIPaddress,searchtermsandtimeofday

Page 47: Why Do You Know So Much About Me

HowDoWeKnow‐AOL  Aug7,06‐AOLapologizedforreleasingsearchlogdataonsubscribersthathadbeenintendedforusewiththecompany'snewlylaunchedresearchsite.

  Almosttwoweeksbeforethat,AOLhadquietlyreleasedroughlytwentymillionsearchrecordfrom658,000usersontheirnewAOLResearchsite.

  Thedataincludesanumberassignedtotheanonymoususer,thesearchterm,thedateandtimeofthesearch,andthewebsite(s)visitedasaresultofthesearch.

  NYTimeswasabletoidentifyseveralusersbycross‐referencingwithphonebooks/publicrecords

Page 48: Why Do You Know So Much About Me

HowDoWeKnow–DepartmentofJustice  Jan06,theUSDeptofJusticeissuedasubpoenaaskingpopularsearchenginestoprovidea"randomsampling"of1millionIPaddressesthatusedthesearchengine,andarandomsamplingof1millionsearchqueriessubmittedoveraone‐weekperiod.

  Thegovernmentwantedtheinformationtodefendachildpornographylaw.

 Microsoft,YahooandAOLcompliedwiththerequest,whileGooglefoughtthesubpoena.

Page 49: Why Do You Know So Much About Me

HowDoWeKnow‐Google  Googlecollectsmassiveamountsofuserdata  Gmailhasamachinereadingemailtoimprovetherelevanceofadvertisementsdisplayed

  GoogleStreetView‐public/privateproperty&peoplecapturedinimages

  Searchhistoriesarekeptfortwoyearsandidentifiedviaacookie

Page 50: Why Do You Know So Much About Me

ByIndirectMarketing Webbugs‐agraphic(inawebsiteoragraphicenabledemail)thatcanconfirmwhenthemessageorwebpageisviewedandrecordtheIPaddressoftheviewer

  Thirdpartycookies‐awebpagemaycontainimagesorothercomponentsstoredonserversinotherdomains.Cookiesthataresetduringretrievalofthesecomponentsarecalledthird‐partycookies.

Page 51: Why Do You Know So Much About Me

WhatAreCookies?  Cookiesaredatapacketssentbyaservertoawebclientandthensentbackunchangedbytheclienteachtimeitaccessesthatserver

  Cookiesareusedforauthenticating,sessiontrackingandmaintainingspecificinformationaboutusers,suchassitepreferencesorthecontentsoftheirelectronicshoppingcarts

  Cookiesareonlydata,notprogramsorviruses  Therearetwotypesofcookies‐persistentandnon‐persistent

Page 52: Why Do You Know So Much About Me

WhyDon’tWeLikeCookies?  Cookiescanbehijackedandmodifiedbyattackers  Cookiescanbeusedtotrackbrowsingbehaviorsosomethinktheyaretagged

Page 53: Why Do You Know So Much About Me
Page 54: Why Do You Know So Much About Me

ByDirectMarketing  Directmarketingisasalespitchtargetedtoapersonbasedonpreviousconsumerchoices.

  Itiscommonthesedays Manycompaniesalsosellorshareyourinformationtoothers.Thissharingwithotherbusinessescanbedonerapidlyandcheaply

Page 55: Why Do You Know So Much About Me

ByInstantMessaging  YourIMconversationcanbesavedontoacomputerevenifonlyonepersonagrees

 WorkplaceIMcanbemonitoredbyyouremployer  SPIM‐SpamdistributedinIM

Page 56: Why Do You Know So Much About Me

ByEmployers  76%ofemployersmonitoremployeeswebsiteconnections

  65%usetechnologytoblockedconnectionstobannedwebsites

  55%monitoremail

Page 57: Why Do You Know So Much About Me

ByCybercrime  Spywaretakesadvantageofsecurityholestoattackthebrowserandforceittobedownloadedandinstalledtogatherinformationwithoutyourknowledge

  Phishingoccurswhencriminalslurethevictimintoprovidingfinancialdatatoanunsecurewebsite

  Pharmingoccurswhencriminalsplantprogramsinthevictim'scomputerwhichredirectthevictimfromlegitimatewebsitestoscamlook‐alikesites

Page 58: Why Do You Know So Much About Me

Facebook“Privacy”

Page 59: Why Do You Know So Much About Me
Page 60: Why Do You Know So Much About Me
Page 61: Why Do You Know So Much About Me
Page 62: Why Do You Know So Much About Me