Saturday, March 15, 2014

Readings for next class

Assuming the weather holds, I'd like you to be prepared to discuss the following in class:

  1. Ownership, Control, Access, and Possession (OCAP) or Self-Determination Applied to Research, available online here. This is one of the few introductions to First Nations conceptions of privacy. 
  2. The paper on Cultural Privacy by Kukathas (published in the Monist), that you found as part of your reference exercise.
The theme this week is group/cultural/communal conceptions of privacy. Questions to consider include:
  1. Can there be cultural or group rights to privacy?
  2. If so, what grounds them? Michael should have mentioned that our legal tradition grounds privacy rights/interests in individualistic norms, such as autonomy, dignity (etc).
  3. What grounds the OCAP principles?
  4. What tensions will arise between individual and communal interests under OCAP? [For those who want to do a quick bit of extra reading, see Section 5.2.3 of one of my papers, found here. Be warned it is a pre-print draft, so there are some errors].
  5. Do you buy Kukathas' analysis of cultural privacy rights?

Thursday, March 13, 2014

Target hackers should have been thwarted by routine malware maintenance



So this actually all happened before our course even started (November 2013). There was essentially a major data breach for Target customers, and it was later realized that many of them had saved credit card information registered to their Target accounts. This is a pretty standard measure for websites involved with online shopping because it optimizes checkout convenience, but obviously a major problem if your company’s mainframe is hacked. 

A recent update (this article) indicates that at least eight former employees had knowledge of the hack, and that despite the malware Target had set up to protect itself against this kind of predicament and various precautionary measures taken, hackers obviously succeeded in infiltrating the system regardless. In fact, it was stated by the director of threat intelligence operations at McAfee (presumably the programmer of this malware) that Target did not have a sufficient grasp of how to utilize the program, since a simple protective feature that would have thwarted the attack had been manually dismissed by Target due to a misconception regarding the use of that feature. 

In my opinion, this is disturbing on several levels. Firstly, whether or not you are prone to online shopping, websites on which you have registered an account have a record of your personal data that could be made available through hacking. Companies obviously take various security measures to increase consumer confidence in using the services they offer, but it remains largely up to the consumer to offer some incentive for a company to do this job properly. As long as Target’s consumer base doesn’t deplete in response to this hack (which it hasn’t in any substantial way) and no large-scale damages seem to have been reported that could ground a tort claim through the company’s negligence, there is no lasting ramification on this company despite its egregious error with respect to delicate customer information.

Can we really continue to argue that there should be no punitive or statutory implications for such cavalier treatment of personal information, particularly in light of the significant role these kinds of accounts in our society? I’m skeptical that this gray area in the law can continue for much longer when it already seems so impractical.

Recent Amendment to Australia Privacy Laws

Australia recently amended its privacy laws. The Australian Privacy Principles (APPs) came into force yesterday – March 12, 2014.  There are several significant changes in the amendment. Most notably, the new law granted new powers and remedies to the privacy commissioner (OAIC) in enforcing its decisions, such as accepting written undertakings from organizations and enforcing it through court. Under the new law, OAIC is also allowed to seek civil penalty orders of up to $1.7 million for repeated breaches by organizations, and $340,000 for individuals.


We may need to wait for a couple of years to assess the effects of amendments on the compliance of the law – particularly the greater enforcement power and the significant penalty for breaches. If these methods do have a positive impact on the compliance of the new law, should Canada follow Australia and amend our privacy laws accordingly? 

Here's a link to the APP. 
For those interested, here is a brief overview of the Australian Privacy Law


Amazon and big data predictions


Last week, we spoke about the process of companies such as Netflix collecting consumer data and then evolving to serve consumers with products exactly tailored to their interests. This issue was also discussed in the Big Data Ethics article. The authors were concerned that big data predictions could categorize consumers with its algorithms, serve us the things that we supposedly like in a way that ultimately limits our choices and the growth of our personal identities. In this article, it seems that Amazon was doing this kind of data collection before Google and Facebook. The company has morphed into a provider of all kinds of services from bookseller, to publisher, to seller of household appliances, delivery service to TV show creator. This article is a great read. It shows a company that has really mastered the big data collection process and questions whether Amazon’s monopoly could give Amazon too much control over the exchange of ideas in US society.

Wednesday, March 12, 2014

A tv news segment on data brokers that is worth watching

Television newsmagazine 60 Minutes aired a segment about online data brokers. There's a concern that no one really knows exactly how many companies are tracking online users or to what extent. However, there's a belief among industry watchdogs that enough information is collected to accurately build our individual profiles, including things such our race, religious view, political affiliations, family medical history, if we've had STDs, and the list goes on an on. The information is then churned into lists that are for sale: lists containing the names of gays and lesbians, people who have bipolar disorder, and those who have gambling, sexual and alcohol addictions. One company, for example, has 1,500 pieces of information about 200 million Americans.
The American government acknowledges there is virtually no oversight of data brokers. One Senator has proposed a bill to introduce regulation but says it's being stonewalled by the big 3 U.S. data broker companies. The CEO of one of them told 60 Minutes that the industry is capable of self-regulating, yet says he doesn't go online and share his personal information. He says consumers ought to know the internet is an "advertising medium." Hmmm. He also adds regulating the data brokers would "cripple" the economy.
It's a very interesting segment. Even better is the extra clip called "How to Defend Your Privacy." It's definitely worth 6 minutes of your time.

The Data Brokers: Selling your information (the main segment)






Class Cancelled!

Internet dating, good not to forget?

We spoke about the right to forget in a number of circumstances last week, and it brought to mind an article in the Hamilton Spectator regarding a known sexual offender. He has been identified in a profile for a number of dating sites. The article refers to a woman who was able to identify him as someone she once knew in a circle of friends and that she was contacted by him on the "Plenty of Fish" dating site. It is interesting to see how the privacy interests of the offender are not "protected" as we discussed previously. The knowledge of his offences are public record and it's also interesting to think of how we are basically relying on public knowledge of his past to "protect" potential online suitors from exposure. I wonder whether there are any implications or feasible ways to track or prevent this type of computer activity from being undertaken by an offender, at least while on parole. If an offender cannot own a car or drink, and is supposed to be reporting relationships with women, it seems like access to the internet makes the latter difficult to monitor. It is a twist on our discussion, and perhaps unfortunately, a more common problem than tracking sex offenders due to the lower likelihood of a public following and subsequent recognition. I would hope that the dating service providers will react to complaints made and find an effective way of blocking his access (at least if they are coming from a personal computer), although the practicality of preventing any access makes blocking his access completely unlikely. I'm thinking a different username and fake photo would obviously not be hard to obtain to create an account.