Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, 12 September 2013

FTC: Facebook privacy policy review part of regular monitoring

The Federal Trade Commission is examining Facebook’s proposed new privacy policy, which has rankled privacy activists who contend it allows users to be inserted into advertisements without their consent.

The FTC’s review is not an inquiry, but part of a regular monitoring program set in place after a 2011 settlement with Facebook, an agency spokesman said Wednesday.

The social networking site proposed updates in August to its policies that explain how people’s content is used in advertisements for which they receive no compensation. Facebook contends the change merely clarifies language that already allowed such use.

As a result, six privacy groups complained to the FTC in a Sept. 4 letter, saying the changes to its Data Use Policy and Statement of Rights and Responsibilities violate the 2011 settlement.

The proposed change to Facebook’s Statement of Rights and Responsibilities states that users give permission to Facebook to use their name, profile picture and content in connection with commercial, sponsored or related content.

“This means, for example, that you permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you,” according to the proposed update. It goes on to state, “We do not give your content or information to advertisers without your consent.”

A Facebook spokesman said via email that “we routinely discuss policy updates with the FTC and this time is no different. Importantly, our updated policies do not grant Facebook any additional rights to use consumer information in advertising. Rather, the new policies further clarify and explain our existing practices.”

Facebook reached an agreement with the agency in November 2011 after the agency alleged the site was repeatedly sharing information that users believed was private. Under the settlement terms, Facebook admitted no guilt but agreed to obtain users’ consent before sharing their information beyond their established privacy settings.

Under the FTC order, Facebook isn’t required to submit changes to its privacy and data use policy to the agency. But the order does require Facebook to obtain third-party certifying audits every two years over the next 20 years to ensure its privacy program meets or exceeds the order’s requirements.

Facebook has faced other legal pressure over how it has used people’s data.

The U.S. District Court for the Northern District of California approved on Aug. 26 the establishment of a $20 million fund for people whose personal information was allegedly used without permission in “sponsored stories,” an advertising product that draws on items people have indicated they “Like” on the site.

Facebook will pay $15 each to users who submitted valid claims and were part of the class-action suit, filed in 2011. The settlement also called on Facebook to makes changes to its Statement of Rights and Responsibilities to give users clearer guidelines on how their information is used in sponsored stories.


View the original article here

Thursday, 5 September 2013

Privacy groups want FTC to oppose Facebook's policy changes

IDG News Service - Six privacy groups have asked the U.S. Federal Trade Commission to strike down proposed changes to Facebook's policies, as they violate a 2011 settlement with the agency over user privacy.

"The changes will allow Facebook to routinely use the images and names of Facebook users for commercial advertising without consent," the groups wrote in a letter Wednesday to the FTC. The groups asked the commission to enforce its 2011 order.

Facebook announced in August proposed updates to its Data Use Policy and Statement of Rights and Responsibilities, two key documents that explain how the social network collects and uses people's data.

In the revised Statement, Facebook states that by joining the site, users "permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you." In the original Statement, people can use their privacy settings "to limit how your name and profile picture may be associated with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us," the groups said.

The changes proposed by Facebook follow the approval by the U.S. District Court for the Northern District of California, San Francisco division of a US$20 million fund for Facebook to settle a class-action lawsuit against the site's "sponsored stories" advertising program. The complainants, some acting on behalf of minors, had alleged that their names and likeness had been used without their prior consent in "sponsored stories" advertisements shown to their online friends on the social networking website.(

"The pending changes arise from a class action settlement in which the attorneys who purported to represent the interests of Facebook users granted the company a right that was contrary to the company's policy at the time the litigation was initiated," wrote the groups, which include the Electronic Privacy Information Center, Center for Digital Democracy, Consumer Watchdog, Patient Privacy Rights, U.S. PIRG, and the Privacy Rights Clearinghouse.

As a result, Facebook users who "reasonably believed" that their images and content would not be used for commercial purposes without their consent could find their pictures showing up on the pages of their friends, endorsing the products of Facebook's advertisers, the groups wrote. "Remarkably, their images could even be used by Facebook to endorse products that the user does not like or even use," they added.

The groups also object to what they consider a "deemed consent" that Facebook requires from minors. Under the proposed changes, minors have only to represent that at least one of their parents or legal guardians has also agreed to the terms of the section, and the use of their name, profile picture, content, and information, on their behalf. Such deemed consent "eviscerates any meaningful limits over the commercial exploitation of the images and names of young Facebook users," the groups wrote.

Facebook said the proposed update did not change its ad practices or policies, but only made things clearer to people who use the service. "As part of this proposed update, we revised our explanation of how things like your name, profile picture and content may be used in connection with ads or commercial content to make it clear that you are granting Facebook permission for this use when you use our services," wrote a Facebook spokeswoman in an email.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Privacy groups want FTC to oppose Facebook's policy changes

IDG News Service - Six privacy groups have asked the U.S. Federal Trade Commission to strike down proposed changes to Facebook's policies, as they violate a 2011 settlement with the agency over user privacy.

"The changes will allow Facebook to routinely use the images and names of Facebook users for commercial advertising without consent," the groups wrote in a letter Wednesday to the FTC. The groups asked the commission to enforce its 2011 order.

Facebook announced in August proposed updates to its Data Use Policy and Statement of Rights and Responsibilities, two key documents that explain how the social network collects and uses people's data.

In the revised Statement, Facebook states that by joining the site, users "permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you." In the original Statement, people can use their privacy settings "to limit how your name and profile picture may be associated with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us," the groups said.

The changes proposed by Facebook follow the approval by the U.S. District Court for the Northern District of California, San Francisco division of a US$20 million fund for Facebook to settle a class-action lawsuit against the site's "sponsored stories" advertising program. The complainants, some acting on behalf of minors, had alleged that their names and likeness had been used without their prior consent in "sponsored stories" advertisements shown to their online friends on the social networking website.(

"The pending changes arise from a class action settlement in which the attorneys who purported to represent the interests of Facebook users granted the company a right that was contrary to the company's policy at the time the litigation was initiated," wrote the groups, which include the Electronic Privacy Information Center, Center for Digital Democracy, Consumer Watchdog, Patient Privacy Rights, U.S. PIRG, and the Privacy Rights Clearinghouse.

As a result, Facebook users who "reasonably believed" that their images and content would not be used for commercial purposes without their consent could find their pictures showing up on the pages of their friends, endorsing the products of Facebook's advertisers, the groups wrote. "Remarkably, their images could even be used by Facebook to endorse products that the user does not like or even use," they added.

The groups also object to what they consider a "deemed consent" that Facebook requires from minors. Under the proposed changes, minors have only to represent that at least one of their parents or legal guardians has also agreed to the terms of the section, and the use of their name, profile picture, content, and information, on their behalf. Such deemed consent "eviscerates any meaningful limits over the commercial exploitation of the images and names of young Facebook users," the groups wrote.

Facebook said the proposed update did not change its ad practices or policies, but only made things clearer to people who use the service. "As part of this proposed update, we revised our explanation of how things like your name, profile picture and content may be used in connection with ads or commercial content to make it clear that you are granting Facebook permission for this use when you use our services," wrote a Facebook spokeswoman in an email.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Privacy groups ask FTC to oppose Facebook's policy changes

Six privacy groups have asked the U.S. Federal Trade Commission to strike down proposed changes to Facebook's policies, as they violate a 2011 settlement with the agency over user privacy.

"The changes will allow Facebook to routinely use the images and names of Facebook users for commercial advertising without consent," the groups wrote in a letter Wednesday to the FTC. The groups asked the commission to enforce its 2011 order.

Facebook announced in August proposed updates to its Data Use Policy and Statement of Rights and Responsibilities, two key documents that explain how the social network collects and uses people's data.

In the revised Statement, Facebook states that by joining the site, users "permit a business or other entity to pay us to display your name and/or profile picture with your content or information, without any compensation to you." In the original Statement, people can use their privacy settings "to limit how your name and profile picture may be associated with commercial, sponsored, or related content (such as a brand you like) served or enhanced by us," the groups said.

The changes proposed by Facebook follow the approval by the U.S. District Court for the Northern District of California, San Francisco division of a US$20 million fund for Facebook to settle a class-action lawsuit against the site's "sponsored stories" advertising program. The complainants, some acting on behalf of minors, had alleged that their names and likeness had been used without their prior consent in "sponsored stories" advertisements shown to their online friends on the social networking website.(

"The pending changes arise from a class action settlement in which the attorneys who purported to represent the interests of Facebook users granted the company a right that was contrary to the company's policy at the time the litigation was initiated," wrote the groups, which include the Electronic Privacy Information Center, Center for Digital Democracy, Consumer Watchdog, Patient Privacy Rights, U.S. PIRG, and the Privacy Rights Clearinghouse.

As a result, Facebook users who "reasonably believed" that their images and content would not be used for commercial purposes without their consent could find their pictures showing up on the pages of their friends, endorsing the products of Facebook's advertisers, the groups wrote. "Remarkably, their images could even be used by Facebook to endorse products that the user does not like or even use," they added.

The groups also object to what they consider a "deemed consent" that Facebook requires from minors. Under the proposed changes, minors have only to represent that at least one of their parents or legal guardians has also agreed to the terms of the section, and the use of their name, profile picture, content, and information, on their behalf. Such deemed consent "eviscerates any meaningful limits over the commercial exploitation of the images and names of young Facebook users," the groups wrote.

Facebook said the proposed update did not change its ad practices or policies, but only made things clearer to people who use the service. "As part of this proposed update, we revised our explanation of how things like your name, profile picture and content may be used in connection with ads or commercial content to make it clear that you are granting Facebook permission for this use when you use our services," wrote a Facebook spokeswoman in an email.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service.
More by John Ribeiro, IDG News Service


View the original article here

Monday, 2 September 2013

Facebook's disclosures remind us not to count on privacy

In releasing its first report on government requests for user information, Facebook is reminding businesses and consumers that use of the Internet today requires self-censorship.

The report released last week shows also that the U.S. government—which is the single biggest requester with between 11,000 and 12,000 requests—is only one of many seeking data from Facebook. Total non-U.S. requests numbered about 15,000 during the first half of this year.

Facebook's Global Government Requests Report is meant to assure users that the company is doing everything it can legally to protect their privacy. Google does the same through its biannual Transparency Report.

The number of users specified in the requests was from 20,000 to 21,000. The majority of the requests were related to criminal cases, such as robberies or kidnappings.

Facebook handed over at least some data in 79 percent of the requests, showing that Facebook refused to release data when it could.

"We scrutinize each request for legal sufficiency under our terms and the strict letter of the law, and require a detailed description of the legal and factual bases for each request," said Colin Stretch, Facebook's general counsel. "We fight many of these requests, pushing back when we find legal deficiencies and narrowing the scope of overly broad or vague requests."

Nevertheless, neither Facebook nor any other company can refuse a legitimate government request, so it is up to users to think before posting and to avoid becoming friends with anyone who seems shady.

Brian Blau, an analyst with Gartner, said people should also follow their employer's policies for using social networks, so they don't say anything that can taint the company's brand.

However, government monitoring should not stop organizations from using Facebook for marketing, sales leads and customer support, said Alan Lepofsky, analyst for Constellation Research. "Engaging with prospects and fans would rarely involve confidential information that anyone should be worried about the government having access to," Lepofsky said.

Once the conversation with a potential or current customer becomes more detailed, the interaction should be taken off Facebook, he said. At that point, all information should be stored internally in a customer relationship management system or a tracking tool for customer support.

facebook logo

Experts applauded Facebook's decision to release the report in order to give users a realistic view on online privacy. However, Rick Holland, analyst for Forrester Research, said Facebook was being selective about its transparency.

Rather than just disclose government requests for data, Holland would like to see Facebook provide a lot more details on how and what it shares with advertisers, including information on customers and prospects gathered from the pages of businesses.

"I don't know if there's any risks to companies that way, but behind the scenes, I'd love to see the same level of transparency on how they're making money on [the data]," Holland said.

Tech companies, including Facebook, Google and Microsoft, are pressing the U.S. government for more flexibility in categorizing information requests, particularly in light of recent revelations of massive data collection on Internet activity by the U.S. National Security Agency.

Companies are prohibited from providing anything more than a range of the number of NSA requests and of affected user accounts.


View the original article here

Saturday, 31 August 2013

Facebook's new face recognition policy astonishes German privacy regulator

A German privacy regulator is astonished that Facebook has added facial recognition to a proposed new privacy policy it published on Thursday.

"It is astonishing to find the facial recognition again in the new proposed privacy policy that Facebook published yesterday. We therefore have directly tried to contact officials from Facebook to find out if there is really a change in their data protection policy or if it is just a mistake of translation," Hamburg Commissioner for Data Protection and Freedom of Information Johannes Caspar said in an email on Friday.

The Hamburg data protection commissioner, already at odds with Facebook over its use of face recognition technology, reopened its proceedings against the company in August last year, telling the company to either obtain explicit consent for face recognition from users, delete the data, or face a lawsuit, Caspar said at the time.

Facebook turned off facial recognition for all European users in September last year, and said it would delete all face recognition templates for existing users in Europe.

The German commissioner stopped its proceedings against Facebook in February, when it confirmed that the company had deleted the facial recognition data gathered on German users without their consent.

Facebook founder Mark Zuckerberg.

Turning on facial recognition again in Germany might be illegal, Caspar said, adding that it depends on how Facebook implements it. The social network should ask for the explicit and informed consent of the user, Caspar said.

"That means that there has to be offered an opt in for users," he added.

Facebook initially deleted the face recognition data in response to recommendations from the Irish Data Protection Commissioner that it adjust its privacy policy. The company's Irish subsidiary is responsible for the data of users outside the U.S. and Canada, and therefore falls under the jurisdiction of the Irish DPC, which also confirmed independently that Facebook had deleted the face recognition data .

On Thursday, Facebook proposed changes to its privacy policy on Thursday, including one related to the tag suggest feature that uses facial recognition in order to let users easily tag friends in photos they upload.

Tag suggest is used in the U.S. in the same way it was used in Europe before it was turned off. Facial recognition software is used to calculate a unique template of a user's appearance based on facial features using variables such as the distance between the eyes, nose and ears.

"We are able to suggest that your friend tag you in a picture by scanning and comparing your friend's pictures to information we've put together from your profile pictures and the other photos in which you've been tagged. You can control whether we suggest that another user tag you in a photo using the 'Timeline and Tagging' settings," the proposed change reads.

Facebook proposed the change in its U.S. privacy policy, and also in translated versions of the policy for European countries, including Germany.

However, according to the Irish DPC, Facebook does not yet intend to offer the service in Europe.

Facebook Ireland consulted the Irish DPC in relation to its proposed privacy policy changes and confirmed that this feature is not yet available in Europe, said Ciara O'Sullivan of the Office of the Data Protection Commissioner in an email. "Any proposed changes to this position would be discussed with our Office," she said.

The Irish DPC suggested to Facebook Ireland that it clarify to its users that the tag suggest feature is not currently available in Europe, she added.

Facebook is still working with regulators to find a way to turn face recognition back on in Europe, a Facebook Germany spokeswoman said in an email.

Loek Essers focuses on online privacy, intellectual property, open-source and online payment issues.
More by Loek Essers, IDG News Service


View the original article here

Friday, 30 August 2013

NTIA's mobile privacy push has failed, groups say

IDG News Service - Lobbyists derailed an effort by the Obama administration to create mobile privacy standards, a privacy group charged Thursday, while some participants in the process conceded it lacked focus.

The U.S. National Telecommunications and Information Administration's year-long multistakeholder process on mobile privacy, culminating in July in a proposed code of conduct for mobile app developers, also failed to fully examine mobile data collection efforts and marketing techniques, the Center for Digital Democracy said in a report released Thursday.

"While the [Obama] administration had an opportunity to advance the privacy and consumer protection interests of the American public, it failed to engage in the serious scrutiny and leadership these issues require," Jeffrey Chester, CDD's executive director, wrote in the report. "Missing almost entirely from the more than yearlong discussion was the impact that current digital marketing, mobile, and app-related business models have on the capability of a consumer to make meaningful privacy choices."

The NTIA's decision to separate out mobile privacy for discussion ignored significant cross-platform tracking of consumers, Chester said. The privacy discussions were "dominated by industry lobbyists," leading to weak consumer safeguards, he wrote. Other privacy advocates agreed, saying they were under-represented during the discussions.

The NTIA's process was "really horrible," added Susan Grant, director of consumer protection at the Consumer Federation of America. Grant called on the Obama administration to push for a baseline consumer privacy law during an NTIA meeting Thursday afternoon to discuss lessons learned in the first round of discussions. After a baseline privacy law, multistakeholder discussions could fill in some gaps, Grant said.

The NTIA's process also lacked focus and an agenda and needed more expert testimony about mobile privacy practices, other participants in the discussions said Thursday's meeting at the NTIA. The NTIA has additional privacy discussions planned. The data collection practices discussed during the NTIA meetings often didn't echo real-life practices, said Morgan Reed, executive director at the Association for Competitive Technology, a trade group representing app developers.

Other participants criticized the process for allowing contentious attacks during the discussions.

Some participants defended the NTIA and the process, however. Critics wanting more progress should realize that major change happens "incrementally" in Washington, D.C., said Stuart Ingis, counsel to the Digital Advertising Alliance, a self-regulatory advertising group.

Even though the process was flawed, the group has produced the mobile code of conduct that's now being tested, said Michelle De Mooy, senior associate for national priorities with Consumer Action. With no real deadline in the NTIA process, industry participants had little incentive to move forward with any initiatives, but the group eventually approved the code of conduct, she said.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

A federal push for mobile privacy has failed, critics say

Lobbyists derailed an effort by U.S. President Barack Obama’s administration to create mobile privacy standards, a privacy group charged on Thursday, while some participants in the process conceded it lacked focus.

The U.S. National Telecommunications and Information Administration’s year-long multistakeholder process on mobile privacy, culminating in July in a proposed code of conduct for mobile app developers, also failed to fully examine mobile data collection efforts and marketing techniques, the Center for Digital Democracy said in a report released Thursday.

“While the [Obama] administration had an opportunity to advance the privacy and consumer protection interests of the American public, it failed to engage in the serious scrutiny and leadership these issues require,” Jeffrey Chester, CDD’s executive director, wrote in the report. “Missing almost entirely from the more than yearlong discussion was the impact that current digital marketing, mobile, and app-related business models have on the capability of a consumer to make meaningful privacy choices.”

The NTIA’s decision to separate out mobile privacy for discussion ignored significant cross-platform tracking of consumers, Chester said. The privacy discussions were “dominated by industry lobbyists,” leading to weak consumer safeguards, he wrote. Other privacy advocates agreed, saying they were under-represented during the discussions.

The NTIA’s process was “really horrible,” added Susan Grant, director of consumer protection at the Consumer Federation of America. Grant called on the Obama administration to push for a baseline consumer privacy law during an NTIA meeting Thursday afternoon to discuss lessons learned in the first round of discussions. After a baseline privacy law, multistakeholder discussions could fill in some gaps, Grant said.

The NTIA’s process also lacked focus and an agenda and needed more expert testimony about mobile privacy practices, other participants in the discussions said Thursday’s meeting at the NTIA. The NTIA has additional privacy discussions planned. The data collection practices discussed during the NTIA meetings often didn’t echo real-life practices, said Morgan Reed, executive director at the Association for Competitive Technology, a trade group representing app developers.

Other participants criticized the process for allowing contentious attacks during the discussions.

Some participants defended the NTIA and the process, however. Critics wanting more progress should realize that major change happens “incrementally” in Washington, D.C., said Stuart Ingis, counsel to the Digital Advertising Alliance, a self-regulatory advertising group.

Even though the process was flawed, the group has produced the mobile code of conduct that’s now being tested, said Michelle De Mooy, senior associate for national priorities with Consumer Action. With no real deadline in the NTIA process, industry participants had little incentive to move forward with any initiatives, but the group eventually approved the code of conduct, she said.

ACT’s Reed commended participants for being able to “manage the chaos” of the process to come up with a code of conduct.

CDD’s report, coming from a group critical of the process from the onset, raised some legitimate issues, De Mooy said in an interview. But there was also a need for privacy advocates who “engaged in the process despite its flaws,” she said.

The NTIA also defended the process, with a spokeswoman saying Thursday’s meeting is an effort to improve moving forward. “The process involved true give-and-take,” she said. “Stakeholders started with widely disparate views but came together and reached compromises to find common ground.”

The multistakeholder discussions were a new process for the NTIA, Lawrence Strickling, the agency’s administrator, said at Thursday’s meeting. “We know this was different,” he said. “It has been a learning experience for all of us.”

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

Tuesday, 27 August 2013

Sept. 23 deadline looms for business compliance with HITECH Act on patient privacy

Computerworld - Organizations handling healthcare data have a month to comply with new security and privacy requirements under the Health Information Technology for Economic and Clinical Health (HITECH) Act.

After Sept. 23, all covered entities, including online storage vendors and cloud service providers, will be subject to new breach notification standards and limitations on how they can use and disclose PHI. They will also be required to ensure that their business associates and subcontractors are compliant with the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA). The HITECH Act amended portions of HIPAA by adding new security and privacy provisions on patient information.

In addition, covered entities will be required to have updated patient privacy notices in place that state the patient's rights over the data and how the data can be used and shared.

Unlike the original HIPAA privacy and security rules, which primarily applied to healthcare organizations and insurance companies, the new HIPAA Omnibus rules apply to business associates and their subcontractors. Under the omnibus rules, a business associate of a healthcare provider, such as a cloud service provider, is directly liable for protecting any patient data it handles, even if the vendor is just storing the data.

Business associates are also liable for ensuring that any subcontractor it hires, such as a document-shredding company, is similarly protecting PHI.

The new rules for safeguarding PHI create a complex liability chain, said Peter MacKoul, president of consulting firm HIPAA Solutions LC. A covered entity or a business associate could face stiff civil penalties for a breach by a subcontractor, regardless of how far down the chain the subcontractor might be, he said.

Under Omnibus HIPAA rules, covered entities and business associates are directly responsible for protecting against the use of PHI by employees, contract workers, trainees and even unpaid volunteers and interns, MacKoul noted.

The rules also give healthcare organizations and business associates less latitude to determine when to make a breach notification, he said.

Previously, a healthcare organization needed to notify individuals of a data breach only if there was a serious risk of financial or reputational harm. Under the new requirements, covered entities and business associates will be required to issue a breach notification in most cases, unless they can specifically show there is a "low probability" of the breached data being misused, MacKoul said.

Healthcare companies will be required to consider four specific factors, including the nature of the data that was breached and whether PHI was acquired or viewed only, to determine the seriousness of a breach. Importantly, breach notification requirements can be triggered even if an employee, contractor or unpaid volunteer uses PHI in an impermissible manner, he said.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Thursday, 22 August 2013

Tech legal news site Groklaw shuts down because email privacy 'is impossible'

Technology legal news website Groklaw is shutting down due to concerns over the continued availability of secure email in the wake of revelations about U.S. government surveillance.

"The owner of Lavabit tells us that he's stopped using email and if we knew what he knew, we'd stop too," site founder Pamela Jones said in a farewell post Tuesday. "There is no way to do Groklaw without email. Therein lies the conundrum."

Groklaw, which was launched 10 years ago, has been known for its exhaustive coverage of technology law, particularly involving software patents, open source software and privacy issues.

Tuesday, 20 August 2013

Google says UK privacy laws don't apply to Safari cookies dispute

Google has told British consumers in a privacy claim that it does not have to answer to English courts and U.K. privacy laws don’t apply to it, according to the law firm for the plaintiffs.

Legal documents filed by the Internet company show that Google will contest the right of Safari users in the U.K. to bring a case in the country where they live and use Google’s service, the law firm Olswang said in a statement on Sunday.

The Internet company refused to accept service of the lawsuit in the U.K., instead forcing the plaintiffs to serve the company in California, the law firm added.

The lawsuit is still in early days, and Google is expected to argue that its customer-facing services in the U.K. are provided out of the U.S.

A group of Internet users in the U.K. said in January they were seeking damages, disclosure and an apology from Google for its alleged undermining of the security settings on Apple’s Safari browser to track online usage covertly.

Olswang initiated the legal action on the behalf of three claimants backed by a campaign called “Safari Users Against Google’s Secret Tracking.”

It followed an announcement in August last year by the Federal Trade Commission in the U.S. that Google agreed to pay a $22.5 million civil penalty to settle charges that it misrepresented to users of Safari that it would not place tracking cookies or serve targeted ads to those users, violating an earlier privacy settlement between the company and the FTC.

The FTC alleged that Google placed advertising tracking cookies on consumers’ computers, in many cases by circumventing Safari’s default cookie-blocking setting. Google denied any wrongdoing.

The filing by Google is not public. Google did not comment.

“It seems to us absurd to suggest that consumers can’t bring a claim against a company which is operating in the U.K. and is even constructing a $1 billion headquarters in London,” Marc Bradshaw, a plaintiff in the lawsuit, said in the statement.

“I argued just over a year ago that Google should be forced to answer to the courts in the jurisdiction where a complaint is filed especially if they have an office there and that it is a mockery of our judicial system if they are permitted to evade judicial process by hiding behind a parent company in California,” said privacy advocate Alexander Hanff in a blog post on Sunday.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service.
More by John Ribeiro, IDG News Service


View the original article here

Monday, 5 August 2013

Browser privacy tools still lack bite, security analysts say

Browser vendors continue to implement privacy in a halfhearted way, with Internet Explorer's default use of cookie "do not track" technology being the best of a weak job, a new assessment by NSS Labs has argued.

Currently, the latest versions of all four leading browsers—IE, Firefox, Chrome, and Safari—implement Do not track - but only Internet Explorer 10 installs it switched on by default, NSS Labs' latest Comparative Analysis found.

The cookie-tracking setting can be enabled in the other three, but only by locating an option in a menu setting. The authors are especially critical of Chrome, which requires users to find and expand a nested Advanced Settings tab to enable the feature.

Even Microsoft treats the do not track as a design afterthought, burying the settings where only the most curious non-expert users might chance upon it.

NSS Labs interprets this lack of enthusiasm for the setting as revealing each vendor's "philosophical views on consumer privacy," while accepting that do not track remains ineffective as a privacy control while advertisers remain free to ignore it as they please.

browsers

"Until legislation is passed that will mandate compliance with the user intent of Do not track, the feature will remain a polite request that will be ignored by the advertising industry," write authors Randy Abrams and Jayendra Pathak.

With third-party cookies, Safari and IE are given the thumbs up, with the former blocking all by default, and IE implementing a partial block. Although Firefox and Chrome don't activate this setting by default, Firefox in particular offers granular control over a setting that is vital to automate access to many commonly used sites.

Other privacy features—the ability to control geolocation, private browsing, and tracking protection lists—all fall down to some extent.

Controlling geolocation (the ability for a site to detect a user's country location), all four browsers prompt as required, but in order to disable the setting completely Firefox forces users to access the technically demanding about:config page.

Uniquely, IE9/10 allows Tracking Protection lists from third-party vendors, essentially lists of sites for IE to block third-party cookies automatically unless the setting is overridden by the user.

Overall, then, IE comes out on top for privacy thanks to the relative simplicity of its slider controls and privacy templates, but none of the four are given a ringing endorsement.

It remains unclear to what extent browser privacy and features such as do not track are valued or even understood by users. A YouGov poll from late last year found that consumers valued ease of use more highly than the ability to block cookies, although the same survey admitted that many disliked targeted ads which follow users even when they have left sites.

Do not track has certainly upset some advertisers, with the Digital Advertising Alliance (DAA) recently lobbying a W3C discussion on how to standardize the way that not track should work.


View the original article here