Archive for the ‘Anonymity’ Category

Google thinks you don’t need privacy

Tuesday, December 15th, 2009

You Have Zero Privacy Anyway — Get Over It

This is a good article by David Adams on OSnews talking about a recent quote by Google CEO Eric Schmidt saying “If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place.” David compares this to a similar and infamous quote by Sun’s Scott McNealy.

I think the reality is not that privacy is dead, or unimportant, but that it is hard. Maintaining privacy requires thought and vigilance, now more than ever. Much as I love it, the Internet is the most surveillance enabled and friendly technology ever created.

Question from a long time customer

Sunday, September 27th, 2009

A long time customer recently sent in the following question. Since it should be of broad interest, I asked his permission to anonymous post and answer it here.

How do you know that subscribing to an anonymizer does not simply mark you for observation?

We all know the NSA is capable of intercepting any electronic communication, and with gajillions of electronic communications happening every second, how would the NSA (or the FBI or the CIA or whoever it is who watches us) know which of those communications to watch?

Seems like the people wanting anonymity would be the first on the list.

Surely they COULD, couldn’t they? That is, get the subscriber lists, which would enable them to intercept communications this side of the proxy - i.e., intercept on the way out, on the way TO the proxy, BEFORE it gets securely tunneled? And no, that would not be possible with the web, but it would with email. Supposedly.

This is what has been proposed to me. What do you think? Does it have any validity?

It is certainly the case that the government could, in principle, monitor your access to privacy services. As long as that access is over a strongly encrypted connection, the contents of your communication, what sites you are visiting or who you are communicating with would be protected. The strength of your anonymity is then largely determined by the number of other users of the same service with which your traffic is being mixed.

In the United States, the use of privacy tools is not restricted. Strict separation of intelligence from law enforcement functions should prevent drift net monitoring of your use of Anonymizer from leading to any kind of legal investigation. The huge number of Anonymizer subscribers would also make this difficult and highly visible.

Outside of the US it is another story. Many countries exercise much greater control over the Internet. Even if it were not blocked by the Iranian government, accessing the Anonymizer website from within Iran would be a risky activity. Once again, the key here is safety in numbers. We have run anti-censorship tools in Iran that supported over 100,000 users. With those numbers, it is awkward for the government to go after people simply for using the service. This is not to say that if you are already under observation for some other reason that it would not give them added ammunition. Privacy tools are generally very effective at keeping you below the radar, but can be much less effective once you are on the radar for whatever reason.

The reality is that there is no evidence of widespread Internet surveillance being used in the US to track users of privacy services. As long as the connection to the service is well encrypted, you should be fine.


Google stands up to Korean push against anonymity

Sunday, April 19th, 2009

YouTube Korea squelches uploads, comments | Digital Media - CNET News

I am very pleased that Google is taking a stand against Korean anti-privacy laws. The law in question requires large Internet services (like YouTube) to collect real name information about any user posting content or comments. In response, Google has completely cut off any posting or commenting through the Korean version of the site. The solution Google proposes is that users should simply log in to a non-Korean version of the site and post away. This way Google never  needs to capture identifying information.

It will be interesting to see if Korea responds by trying to block access to all non-Korean versions of YouTube. Obviously anonymity tools provide an excellent end run around this kind of restriction.

I find myself of two minds on how to feel about this action. On the one hand, it respects Korea’s right to set its own laws within its borders, without allowing any one country to dictate how the rest of the world will use such tools. On the other hand, I find such anti-privacy policies so repugnant, I would like to see companies simply refuse to comply and pull hardware out of that country while continuing to provide the service.

In defense of extreme unmoderated anonymity

Saturday, April 18th, 2009

Doug Feaver - Listening to the Dot-Comments - washingtonpost.com

I am quite impressed with this article by a former executive editor of the Washington Post. He makes a strong case for the importance of anonymous comments. Attribution immediately leads to self censorship. Anonymous comments give a much better picture of what people really think rather than what they would like to be seen to be thinking. It is not pretty, but it is reality.

Competition in privacy policies finally starting

Thursday, December 18th, 2008

For many years privacy advocates have claimed that if users were fully informed and aware of privacy policies then they would vote with their feet. Privacy policies would become part of the free market decision making process, in addition to price, brand, reputation, convenience, etc.

It appears this process is actually starting to take place in one industry: search engines. It is likely that they have been the first because of the significant public focus on privacy issues around search over the last few years.

First Google said they would “anonymize” their logs after 18 months, which they later shortened to 9. Yahoo countered with 13 months and has now gone to 90 days. I talked about Google’s 18 month policy back in March 2007. In August 2007 I mentioned a CNET Report on privacy ratings for Search engines.

This tit for tat shortening of the identifiable log retention policies suggests that pressure around this issue is meaningful to the search engine giants. What is somewhat less clear is whether the pressure is from the market, or from the media / politicians / government.

It is still the case that the logs are not actually deleted, but rather the source IP address and user ID cookies are stripped out. There is a good Wikipedia article on the scandal around a release of “anonymized” AOL search information, and how it was still possible to identify individual users in the data.

The real proof of this trend towards privacy policy competition will be when we see elements of privacy policies being promoted front and center on diverse websites as part of their competitive positioning / marketing.

Sarah Palin email hacker

Wednesday, September 24th, 2008

There have been a lot of articles lately talking about the fact that the person who hacked in to Sarah Palin’s Yahoo! account used “an anonymizer”. The articles also say that the privacy provided was compromised.

The unfortunate misuse of Anonymizer’s registered trademark has created some confusion. The person who hacked the account used a privacy service, but not one connected in any way to Anonymizer Inc.

Privacy in Chrome and IE8

Thursday, September 4th, 2008

Both Microsoft’s new beta of IE 8 and Google’s beta of their new browser Chrome tout new enhanced privacy features. I have seen a few articles like this one, that talk about this issue. The Safari browser has had these features in the production version for a long time.

Privacy is a complex multi-headed beast. All of these browsers address one privacy concern while ignoring others. These browsers protect you from risks associated with the stored local data about your web browsing activities. Normally, browsers keep a history of recently visited URLs, a cache of recently visited pages (for faster retrieval) and cookies from the websites you have visited (possibly not at all recently). These browsers enable you to take control of what is recorded by your browser, and how long it is kept. This is a good and important development.

These new security capabilities do nothing to protect you from information gathering by the sites you visit, or from your ISP (see my previous post on that). Your IP address is still completely visible to any site you visit, ISPs can still intercept all your traffic.

These new privacy features are an important part of a user’s toolbox, but they should not give one a false sense of security. They are part of the solution, but not a complete solution.

High resolution tracking through cell phones

Tuesday, May 20th, 2008

It appears that a company is now selling a tool that will allow high resolution tracking of the motion of customers through stores and malls by triangulating on their cell phones. The technique involves tracking the phone through its globally unique IMEI number. The company claims that this is anonymous because only the phone company knows the correspondence between the IMEI and the customer’s real name.I have very little faith in that protection. There are simply too many ways one might extract that kind of information, which could then become widely available. One could even connect the location information and IMEI data to checkout records. After a couple of trips, it would be fairly unambiguous. This is certainly clever, but disturbing. There is no opt-in or opt-out, and the tracking takes place passively with no ability for the user to detect that it is going on.Shops track customers via mobile phone - Times Online

It is not easy to stay private

Tuesday, May 13th, 2008

New Sites Make It Easier To Spy on Your Friends - WSJ.com This article does not break any new ground, but does a nice job of listing and discussing a number of tools one can use to gather information on people. They pull from on-line information sources as well as public records for things like criminal history. For employers, it would be a good place to start before hiring someone to do a full background check.The big take away at the end is that you need to make sure you reduce your Internet footprint, specifically by taking care to check the privacy box on many sites, and to simply provide no or false information to others. For example, although I would never provide a wrong age to gain access to a restricted website, I almost never provide my correct birthday because to many other sites (like banks) use that as part of your identity verification. 

David Brin Rebuts Schneier In Defense of a Transparent Society

Saturday, March 15th, 2008

David Brin Rebuts Schneier In Defense of a Transparent Society Here is David’s own rebuttal to the Schneier article on the Transparent Society I blogged about earlier.