Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, March 09, 2026

Meta Considers X-Ray Glasses That Work

  

Superman supposedly had X-ray vision, which in the movies and comic books about him, he used only for noble and righteous purposes such as catching crooks.  But teenage boys could easily think of other things they might do with such an ability, and I'm sure there are jokes out there involving Superman, Lois Lane, and—well, on to more serious matters. 

           

In the back pages of Superman comic books in the 1950s, you might find an ad for X-ray glasses for the amazingly low price of $1.25.  Like most things that are too good to be true, these turned out to be nothing but cardboard specs with two small holes where the lenses would go.  The holes were covered with a textured plastic that created a diffraction effect whenever something with a sharp outline in front of you was strongly backlit.  Instead of just dark and light, the glasses produced a kind of broad gray area extending a fixed distance inside the outline.  When you viewed a hand this way, the effect was reminiscent of an X-ray, but only if you used your imagination.  And as for looking at backlit women, it still took a lot of imagination to see anything other than a slightly smaller silhouette of the actual person.

 

The thing Meta is considering is no joke, however.  According to a report in The Independent, a UK media outlet, the New York Times revealed last month an internal Meta memo which considers adding AI facial-recognition technology to its smart glasses. 

 

No such features are yet available commercially from Meta, but the idea drew strong criticism from women's-rights groups such as Refuge.  The charity tracks technology-related abuse, and claims that in 2025, referrals to its "technology-facilitated abuse and economic empowerment team" rose by 62% over 2024, to 829. 

 

Clearly, stalkers and other malefactors who are invading women's privacy are exploiting whatever technology they can get their hands on, from general Internet searches to facial-recognition technology applied to online images.

 

Suppose a man could simply wander around in a crowded place such as a shopping mall or bus terminal and find out all kinds of details—name, address, email, phone—for any woman he looks at.  It doesn't take much imagination to see how this situation could go bad very fast.  And even if Meta takes steps to prevent such potentially harmful activity, once the hardware is in place, determined individuals will figure out ways to bypass safeguards. 

 

It remains to be seen whether Meta can overcome the apparently steep barrier that has fended off efforts by Google, Apple, and others to turn smart glasses into a popular thing.  I don't know whether the hardware is still inadequate (battery life, resolution, weight, etc.) or whether people simply don't like the idea of weird internet stuff cropping up all the time in their field of vision, but the track record of smart glasses (as opposed to virtual-reality (VR) glasses that take over your visual field completely) is not good. 

 

But it's foolish to think that just because they haven't caught on yet means they never will.  And if they do, what is to prevent a bad actor from picking out a likely-looking woman in a crowd and digging up whatever he can find on her?

 

Today, someone trying to do that has to at least carry a smartphone around and point it at the intended victim.  But smart glasses, like a spy camera, make the act of photography invisible, so no one is aware that they're being imaged.  Of course, the ubiquity of security cameras in both commercial and residential spaces means that much of the time we're being photographed without our knowledge anyway.  Stores and banks have a motivation not to misuse the data thus captured, however.  Some guy walking around with smart glasses doesn't.

 

Whatever Meta decides to do about facial recognition with smart glasses, the prospect will be only one more brick pulled down from the wall of privacy that used to surround us, but is now not much more than a pile of rubble.  And as the Independent article points out, even if a company promises to keep data private subject to state and federal law, governments can and do require companies to divulge such data on demand.  So privacy is only privacy if the government lets you have it, rather like right-of-way on a freeway:  you don't have it unless someone gives it to you.

 

Of course, there are positive and defensive ways of using the same technology that can be used for stalking.  As a teacher, my poor ability to connect names to faces means that I rarely learn all my students' names before the end of the semester.  It would be great if I could just look at each one and see their names pop up underneath their faces—with their permission, of course.  And a few months ago, I was on a jury trying a case of indecent exposure in a public place.  During the trial, a critical piece of evidence turned out to be clips from the victim's dashcam that caught clear images of the man who a few minutes later committed the crime for which he was convicted.

 

So I have no doubt that good things could result from smart glasses becoming cheaper, better-performing, and more widespread.  But at the same time, it should be possible for a well-resourced outfit like Meta to come up with technological means to prevent unauthorized identification of people via facial-recognition technology.  It might involve some larger-scale privacy initiative that would offer potential victims the option not to be recognized by smart glasses.  Wouldn't that be nice?  The company would moan and groan about how expensive it would be, but they should compare whatever the safeguards would cost them, to the prospect of lawsuits by victims and family members who get stalked, attacked, or even killed by men who use Meta's technology to find their victims. 

 

Mark Zuckerberg, the choice is yours.

 

Sources:  An article on the National Review website at https://www.nationalreview.com/2026/03/you-cant-escape-the-ai-grid/ informed me of the Meta memo, which was also covered by The Independent at https://www.independent.co.uk/news/uk/home-news/meta-glasses-facial-recognition-domestic-abuse-b2923551.html.  A well-researched YouTube video tracing "X-ray" glasses back to the early 1900s and showing what you see through them is available at the Laura Legends channel at https://www.youtube.com/watch?v=rdVrTqaJrS4. 

Monday, December 22, 2025

The Spy in Your Living Room

 

Did you know that your smart TV will in all likelihood (a) use audio and video recognition technology to determine exactly what programming you are watching every second, whether it's over-the-air TV, cable TV, streaming, or even something you're watching from a computer hooked up to your TV as a monitor, (b) send this data to servers run by the TV manufacturers, who then (c) market the data to whoever's interested in it, and can combine it with other cross-platform data to create a detailed profile of your viewing, phoning, and living habits? 

 

I didn't know either.

 

Just possibly, you may be one of the few people who know about the Vizio lawsuit filed by the New Jersey attorney general in 2017, joined by the Federal Trade Commission.  The issue there was the Automated Content Recognition (ACR) software installed in every Vizio set.  ACR takes audio and video snippets of whatever is being played on the TV and sends them to be matched to vast databases of content.  In this way, the TV maker has a second-by-second profile of exactly what you are watching.  Simply knowing that some third party can spy on your viewing habits is bad enough.  But when they turn around and sell that information without your permission to advertisers or even nefarious actors (what if you use your TV as a monitor to check your bank account?), insult can turn quickly into injury.

 

Vizio settled the lawsuit by paying fines and promising to improve its disclosure practices.  But clearly, if the new lawsuit filed by Texas Attorney General Ken Paxton on Dec. 15 of this year is any indication, ACR is still very much with us.

 

The companies named in Paxton's suit are Sony, Samsung, LG, Hisense, and TCL Technology.  Paxton is concerned that China's National Security Law will allow its government to obtain data on U. S. citizens that is obtained by TV companies based in China.  ACR data-harvesting is a big deal.  One report said that at one point, Vizio was making more money selling ACR-acquired data than it was from selling TVs. 

 

In retrospect, this isn't surprising.  The idea that the customer is the product made the Google founders billionaires, so if the technical capability is there, why shouldn't TV makers share in the moolah?  It's virtually impossible to even come near a mobile phone without having it figure out what kind of coffee you like, where you go for vacation, and what you talk about while you're waiting in line at the grocery store.  That particular privacy horse is miles away from the barn, and there seems to be no way of getting it back.

 

But the idea that the outfit which made my TV is profiting from selling my viewing habits is a new one on me, anyway.

 

I'm old enough to remember when companies had to go to a lot of trouble to find out what shows were being watched, back in the 1960s when there were only three networks and maybe a local channel or two.  Firms such as the Nielsen ratings people first asked selected consumers to keep written diaries of what they watched.  This was a rather irksome process of questionable accuracy, so later Nielsen developed a machine they called the Audimeter.  It automatically recorded the channel setting of the selected family's TV so they no longer had to write anything down. 

 

Of course, such families were highly aware that they were being watched, and perhaps even took pride in being able to "vote" in a sense for shows that they liked.  But that system is worlds away from the invasive practice of ACR, which every purchaser of TVs from certain brands participates in without his or her knowledge.

 

A study was made of how much trouble it is to turn off the ACR on a new TV, and the number of clicks required range from 11 to 27, once you figure out what the manufacturer calls their variant of ACR.  Names like "Smart Features," "Enhanced Viewing Experience," and my favorite, "Personalized Recommendations" obscure the true nature of the function. 

 

Opinions of Attorney General Paxton vary widely, and I am no fan of his in general.  But in the case of ACR, I think his actions are highly warranted, especially because the data-gathering has been successfully concealed from millions of consumers. 

 

Privacy is an odd kind of right that doesn't come first to mind when one thinks of human rights.  The phrase "life, liberty, and the pursuit of happiness" from the Declaration of Independence encapsulates the gist of rights that we in the United States lay claim to.  But the right to privacy, which can be defined as the right of keeping one's activities, personal data, and other identifying information away from scrutiny by strangers, is essential to one's freedom of action and even thought. 

 

We are living at a time when, rightly or wrongly, certain opinions and trends of thought are being seized upon by government agencies and used to penalize individuals and groups.  A case affecting my own university comes to mind.  A professor at Texas State University gave a talk last September at an online conference that was being monitored by a conservative blogger, who re-posted his words as an example of inflammatory speech advocating the overthrow of the U. S. government.  Texas Governor Greg Abbott's office reposted the item and brought pressure to bear on President Damphousse of Texas State University, who fired the tenured faculty member.  The faculty member is suing the University, but currently he is out of a job.

 

Right now, the worst use that TV manufacturers are making of their ACR-gathered data is to sell it to advertisers and marketers.  Perhaps it's annoying to watch a show on water skiing and then get bombarded by water-ski-equipment ads, but it's not a fundamental breach of your civil rights, exactly.  What if at some point, the government decides that anybody who watches Show X is a traitor to the country, and deserves to be deported?  That sounds ludicrous now, but if you had told me even five years ago that a tenured professor would be summarily dismissed for something he said in an online conference, I would have been reluctant to believe it. 

 

Sources:  The news release about Ken Paxton's lawsuit against five TV makers is at https://texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans.  The website Captain Compliance has a detailed explanation of ACR and its implications at https://captaincompliance.com/education/privacy-alert-how-automated-content-recognition-acr-is-watching-everything-you-watch/.  I also referred to a news item at https://www.kxan.com/news/texas-politics/texas-ag-sues-several-tv-companies-says-smart-tvs-are-spying-on-texans/ and the Wikipedia articles on Vizio and audience measurement.


Monday, November 11, 2024

How Artificial Is the Artificial State?

 

In this week's New Yorker, Harvard historian and author Jill Lepore writes about something she calls "the artificial state," and takes a pretty dark view of it.  In light of last week's election, it's worthwhile to consider her criticisms, and ask how seriously democracy has been compromised by the automation of politics and elections.

 

Several paragraphs in, she gets around to defining the artificial state:  ". . . a digital-communications infrastructure used by political strategists and private corporations to organize and automate political discourse."  Before you can say something is wrong, you have to have a standard by which to judge rightness.  It's not entirely clear to me what Lepore has in mind as the ideal of democracy unencumbered by digital meddling.  Perhaps the closest she comes to posing an ideal or legitimate use is when she wishes these technologies could be reinvented as "well-regulated, public-interested digital utilities."  So one of the things that bothers her the most about the way politicians use digital technology these days is that it is largely unregulated, and instead of being directed to the public interest, it is controlled by private corporations or entities.

 

Another positive development she would like to see is the recognition of what one philosopher calls "epistemic rights."  Epistemology is the science of knowing, so epistemic rights are the right to be either known or unknown—another way of expressing the right to privacy, perhaps.  She also cites a British author and member of the Labour Party Josh Simons, who has written a book advocating the A. I. Equality Act, which would "assert political equality as a guiding principle in the design and deployment of predictive tools."

 

Turning to problems, she points out that after Elon Musk took over the former Twitter (now X) in 2022, the number of accounts on Twitter that are bots (i. e. not real people but digital simulacra commanded by a central authority) is between 11% (according to X) and 66% (according to an independent study).  That's not a real solid statistic to base a criticism on, but most people will agree that there is some measure of chicanery going on in the social-media world, where the origin of any given click-bait comment is essentially impossible to determine, and being skeptical about whether it came from a person or a machine is just common prudence.

 

There is no doubt in my mind that a good part of the blame for today's hyper-polarized politics is assignable to the drive to extremes that Lepore cites, a drive that is based not on high-minded aspirations for the good of democracy, but on profits.  That being said, profits are necessary for private companies to function.  The opposite alternative is for the government to own and run and regulate everything, which would certainly take care of the well-regulated part of Lepore's ideal digital democracy. 

 

But whether a government-run cyberspace would be public-interested is not clear.  Left to themselves, government-run organizations tend to become government-interested rather than public-minded.  One recent example is the way that the U. S. Department of Education did a face-plant with its attempt to follow Congress's instructions to simplify the Free Application for Federal Student Aid website and system.  The resulting dumpster-fire disaster had universities all over the country pushing back their application deadlines and losing millions of dollars of student financial aid, a mess which I understand is ongoing to this day.  With the election of Donald Trump, Secretary of Education Miguel Cardona is packing his desk and checking his retirement plans.  If Cardona's work is an example of how government can operate digital systems in the public interest, good luck with getting it to run politically-oriented social media.

 

If the Department of Education depended for its operating revenue on having a smoothly-working website, with a real downside consequence if it wasn't, either we'd have a smoothly-working website or in a short while we wouldn't have a Department of Education at all.  And the latter outcome would be just fine with certain parties shortly to occupy the executive branch of government. 

 

Despite all the bots, the Musks running X and Bezoses running Facebook, and every other problem Lepore cites, and despite the fears of armed attacks on polling sites, the election we just experienced last week took place peacefully and issued in an outcome that was not desired by the majority of experts and would-be regulators that Lepore would put in charge of our digital political system.  And I'm sure that she would say, "See what happened?  Democracy failed!  All these young black and Hispanic men are voting against their self-interest because they've been bamboozled by the system."

 

Now some people are easily bamboozled, but a principle of democracy that Lepore didn't mention in her article is that if a person meets the minimal legal requirements to vote (age and citizenship, primarily), he or she is free to vote any durn way they please.  That principle assigns any responsibility for avoiding bamboozlement to the individual, not to any government agency in charge of preventing voter bamboozling. 

 

I almost hate to say it, but Lepore shows that many people in the higher reaches of academia are more parochial (isolated in a small group of like-minded individuals) than most of the average Joes and Jills they criticize.  The problem of regulating political speech was stated well by the Roman poet Juvenal when he asked "Quis custodiet ipsos custodes?" meaning "Who watches the watchmen?"  Any such regulation inevitably introduces bias, and while there are certain incendiary types of speech that common sense says should be prohibited, the distortions of the present "artificial state," as Lepore puts it, are something that the average voter probably takes into account before voting.

 

I do agree with Lepore that digital technology has severely altered the way the democratic process works in this country.  But I think the answer is not less democracy and more autocratic control, but more democracy in the sense of grass-roots movements towards things like local bans on smartphones for people under 16 or so, and some kind of back-to-reality movement whose outlines are not clear at this time.  In the meantime, we can rejoice that most of the dire predictions about last week's elections didn't come true.  But of course, dire is in the eye of the beholder. 

 

Sources:  Jill Lepore's "The Artificial State" appeared on pp.69-71 of the Nov. 11, 2024 edition of The New Yorker.  I referred to the Wikipedia article "Quis custodiet ipsos custodes?"

Monday, February 06, 2023

Is Your HP Printer Really Yours?

 

In choosing to make Charlie Warzel's printer stop working because of an expired credit card, the corporate giant HP picked the wrong consumer to pick on.  Warzel happens to be a staff writer at The Atlantic.  In "My Printer Is Extorting Me," Warzel excoriates HP and the general tendency of Big Tech to keep long strings attached to items that we thought we'd bought, only to find that the old notion of "fee simple title," meaning total possession of a thing, is history as far as digital stuff is concerned.

 

It happened this way.  Back in 2020 during the pandemic, Warzel decided his family had to have an inkjet printer, and he went online—practically the only option then—and bought an HP model for more than $200.  Without really knowing what he was doing, but making what was a rational decision at the time, he also signed up for an HP program called Instant Ink.  Allegedly, Instant Ink monitors your ink cartridges, and when one of them is getting low, it automatically generates a shipping order and delivers the requisite cartridge to your door before you even knew you needed it.  At least, that's how it's supposed to work.

 

The cost for this service was $5.99 a month, based on the number of pages you typically print in a month (100 pages for $5.99).  I checked the HP website for this service, and it's unclear what happens if you sign up for the 100-page plan and unintentionally print, say, 101 pages in February, the shortest month.  Does that bump you up to the next highest level? 

 

Anyway, that and many other aspects of the program were not clear to Warzel, who began to receive ink cartridges until the day that the credit card he'd used for the service expired.

 

If your credit card number expires or has to be changed, one of the vicissitudes of modern life is trying to remember all the different places you've given it to, so as to hunt them up and tell them what the new number is.  When this happened to Warzel, HP was one of the places he forgot to notify.  But they reminded him quick.

 

One day not long after his card expired, he went to print something and found that his printer had quit working.  Looking into the matter, he was dismayed to discover that the reason it had quit was that his credit card had expired, and "the company had effectively bricked my device in response."

 

Apparently, all he had to do to get it running was to go out into the real world and seek a set of genuine (not imitation!) HP printer cartridges, and his printer would start working again.  He doesn't say whether he did that or resolved to go back to quill pens and foolscap.  But the type of problem he experienced is increasingly common, and Warzel discovered several other examples of situations in which tech companies exert eerie and disturbing control over things that consumers thought they had purchased outright.

 

As Warzel points out, HP is only engaging in a particularly nasty form of commerce that traces its roots back to at least the early 1900s.  The first consumers who installed light bulbs and later discovered that, unlike a kerosene lamp, an incandescent lamp burns out with alarming frequency, may have felt something close to the outrage that Warzel felt when his printer quit.  It may have been the electric-lighting industry that gave rise to the business saying, "The weakness of the goods is the strength of the trade."  Back in the early days of electric lighting, you might buy only a few lamp fixtures, but you'd buy hundreds of light bulbs over the years, furnishing a steady revenue stream for GE or whoever was making bulbs at the time.  It's for the same reason that Kodak sold cheap cameras, because they made back any money they lost on camera sales by selling the film for them. 

           

The digital printer industry is only the latest version of this kind of system, which I hesitate to call a scam.  But by using its ability to trace each individual cartridge and exert remote control over them, and the printer that uses them, HP may have pushed their advantage a bit too far.  It was too far for Warzel, at any rate.

 

The Polish philosopher and sociologist Zygmunt Bauman (1925-2017) wrote a book entitled Liquid Life.  I haven't read it, but the notices of his work I have come across attribute to him the perception that one of modern life's strong tendencies is to blur formerly clear-cut distinctions.  Take privacy, for example.  As recently as the 1970s, when one made a phone call, one could be reasonably assured that nobody was listening other than the person you called at the other end of the line, and that if your phone rang, it was another person who had a legitimate personal reason to call you.  Nowadays, of course, our very conversations, on and off the phone, are monitored by digital spies who start throwing ads for printer cartridges at us if we so much as mention printers in casual conversation. 

 

And there was an invisible barrier a typewriter crossed, say, when you walked out of the store with it.  Up to that moment it belonged to the store.  But once you paid for it, it belonged to you—you could type with it, use it for a paperweight, or take it out to the lake and use it as a boat anchor (some of the old IBM Selectrics would have served this purpose admirably).  And nobody—not the store, not IBM—could have stopped you.

 

Perhaps we'll just have to get used to the leaky liquid nature of digital ownership, but Warzel seems to think we will have lost something important in the process. 

 

Sources:  Charlie Warzel's article "My Printer Is Extorting Me" appeared on The Atlantic's website at https://www.theatlantic.com/technology/archive/2023/02/home-printer-digital-rights-management-hp-instant-ink-subscription/672913/.  I also referred to the HP Instant Ink website at https://instantink.hpconnected.com/us/en/l/v2 and the Wikipedia article on Zygmunt Bauman.

Monday, June 15, 2020

Amazon's Ban on Police Use of Its Face Recognition Software


Last Wednesday, June 10, the tech giant Amazon announced that it was banning police agencies from using its face recognition technology Rekognition for a year.  The company gave no official reason for its timing, although it comes less than two weeks after the death of George Floyd at the hands of the Minneapolis police force. 

Critics have charged that face recognition technology in general, and Rekognition in particular, has biases when it comes to race or gender.  According to an Associated Press report, in the past Amazon has defended its software against the results of studies by MIT researchers who showed that such software marketed by Microsoft, Amazon, and IBM sometimes made mistakes that put darker-skinned people and women at a disadvantage.  (Microsoft and IBM pledged to address the deficiencies as a result.)  Amazon's product is a fairly minor player in a field that includes products from Japan and Europe as well, which many police agencies use.  Both Amazon and other producers have called for federal regulation of face recognition technology amid concerns of abuse and bias.

Another portion of the human anatomy has been used for identification by police and security agencies for decades, largely without recent controversy:  the unique patterns on fingertips.  But at least so far, fingerprints cannot be sensed remotely, and taking them usually requires the cooperation or at least physical contact with the individual being examined.  With the proper optical technology, one can image a face from a distance of a kilometer or more, leading to the possibility of mass identification in crowds with software that can unambiguously connect faces to persons.

Speaking from an engineering ethics viewpoint, we can identify the parties in this controversy as follows.  There are the firms that make face-recognition technology.  There are the customers and potential customers for such technology, which include but are not limited to law-enforcement agencies, governments in general, and also private firms wanting to make personalized advertisement appeals, for example.  There are regulatory agencies with the potential ability to regulate such technology.  And then there is the general public, a subset of whom are criminals, but the vast majority of whom are just ordinary people trying to live their lives in these lately rather extraordinary times. 

The dangers of misusing face-recognition technology are many, even if it works perfectly.  In China, for example, it is already being used in combination with other techniques to monitor movements and activities of the general public in what we in the U. S. would consider gross violations of privacy.  But even if the agency using the technology was entirely benign (and if there are real human beings running it, it won't be entirely benign), flaws in the technology such as a preferential tendency to make false positive identifications of darker-skinned people will lead to injustices such as innocent persons being identified, and possibly arrested and worse, in connection with wrongs they did not commit. 

So concerns like these are probably behind the motivation that made Amazon ban its Rekognition software from police use for a year.  Such concerns comprise at least one reason that face-recognition firms have called for federal regulation of the technology as well.

However, it does seem rather perverse for a company to defend a product they made for police departments, only to turn around and take it away from them for a year.  And here I wish to tread lightly, because in today's "cancel culture," anything you say can be used against you, as the police used to say (and maybe still say, for all I know).  Only you used to have to be formally charged with a crime for that to be the case, but no longer.  Anyway, here goes.

The publicity surrounding George Floyd's death has led to both intense outrage expressed in print, in words, and in massive demonstrations, as well as to criminal acts such as looting and rioting.  Understandably, a lot of the hostility inspired by Floyd's death has been directed against law enforcement agencies ranging from local police organizations up to and including the federal government.  Recently, some have called for "defunding" police forces, the interpretation of which varies, but at a minimum means a punishing cut in financial support.

Order is a fundamental need for any functioning society.  It is not the ultimate good of society, which lies elsewhere, but it is needed as much as food and water.  Because there are always a few people who will not follow the rules simply because someone in authority tells them to, most functioning societies of any size have law-enforcement agencies. 

The modern concept of law includes the principle that it applies equally to everybody.  Sometimes the police fall short in trying to achieve that ideal, and certain groups that include minorities receive unfair treatment.  Every reasonable means should be used to try to remedy such wrongs, and to get closer to the ideal of equal treatment under the law. 

But to penalize entire organizations for the wrong acts of a few of their members is to erode the very thing we are trying to achieve, namely, equal treatment under the law.  A crippled (or, perish the thought, abolished) police force will lead to increased disorder, and a reaction that may well institute a much harsher order than any of us want. 

Speaking specifically of Amazon and Rekognition, if the software really didn't work that well, Amazon should never have sold it to the police in the first place.  Taking it away for a year looks suspiciously like the time I took away my 10-year-old nephew's toys for a day to punish him for not minding his aunt and uncle.  And one can certainly question the right of a private company to punish police departments, which are under the authority of those governmental divisions that control them, not Amazon. 

Sources:  The Associated Press article about Amazon's banning Rekognition from police use appeared in numerous news outlets, including the Tampa Bay Times on June 12 at https://www.tampabay.com/news/2020/06/10/amazon-bans-police-use-of-its-face-recognition-for-a-year/.  The argument about the rule of law was inspired by an interview I heard with Princeton professor Robert P. George on the Sheila Liaugminas Relevant Radio network show "A Closer Look."

Monday, April 29, 2019

Facebook, Privacy, and Regulation


In what may signal a change in attitude, the U. S. Federal Trade Commission is talking about fining Facebook billions of dollars for breaching a privacy agreement between the company and the FTC.  At issue is how Facebook uses the data it gleans from its users and whether Facebook has asked permission before sharing private data with third parties. 

In a recent AP article, reporter Barbara Ortutay says Facebook has set aside $3 billion in case the FTC fines the firm.  This is somewhat of a drop in the bucket of Facebook profits, which are estimated to be over $20 billion this year.  But still, it's large enough to attract investors' attention, and so the publicly traded company mentioned it in a recent news release. 

Privacy is one of the more nebulous concepts in ethics and law, as opposed to murder, say.  With murder you generally have a dead body and a definite event that produced it.  But privacy is all in the mind, or rather, minds—the mind of the person whose privacy has been violated, and the minds of those who allegedly know something about the victim that the victim doesn't want known.  And figuring out what is in peoples' minds isn't that easy.

One of the earliest institutional guarantees of privacy is what the Roman Catholic Church calls the "seal of confession."  Catholics are supposed to confess all their mortal sins periodically to a priest in what's called the sacrament of penance or reconciliation.  In turn, the Church promises on behalf of its priests never to reveal what is confessed.  A priest who breaks the seal of confession is subject to immediate defrocking, and so some priests have become martyrs rather than reveal secrets they learned in the confessional to government agencies, for example. 

There are many differences between confessing one's sins to a priest and posting your latest trip to a bar on Facebook, but structurally the situations are similar.  In each case, there is a person who is providing information that they would like to keep private:  the penitent in the confessional, or the person posting something on Facebook.  There is also the desired audience which the person wants to reach:  the priest (and presumably God) in the confessional, the intended circle of chosen friends in the case of Facebook.  There is the institution whose job it is to ensure that privacy is maintained:  the Church in the one case and Facebook in the other.  And finally, there's everybody else—the rest of the world which is supposed to remain wholly ignorant of what is going on in the private interchanges between priest and penitent in the one case, or Facebook and the user in the other case.

There have been isolated cases in which the seal of confession has been broken, but they have been rare, probably owing to the drastic penalty the Church exacts on a priest who breaks the seal.  In the case of Facebook, things are much different.  For one thing, individual users have no sure way of knowing if Facebook shares their private information with advertisers.  So it's reasonable that another institution with enough resources to investigate such large-scale questions systematically should get involved, in this case the FTC.  Instead of the seal of confession, we have a 2011 agreement reached between the FTC and Facebook which bound the company for twenty years to ask for "affirmative express consent" before Facebook shares any data the user hasn't made public with a third party.

Here's where things get tricky.  Anyone who deals with computers knows that whenever you sign up with a new service or install new software, you get asked to consent to something that most people blow by without reading.  If you try reading the terms and conditions, as they're called, you will either waste hours on it or have to hire a lawyer to figure out what you're really committing to.  This digital equivalent of fine print on a written contract is where companies like Facebook sometimes try to bury things you may not like if you knew about them.  But the case the FTC has against Facebook may amount to something like in clause 4 of paragraph 3.7A, you actually agreed to let Facebook share what you thought was private data with anybody who will pay for it. 

The question of whether clicking a button that says you read and understood the terms and conditions without really doing that is "affirmative express consent" has two answers.  The technical answer is, yes, it does, and if you didn't read and understand all that legal boilerplate it's your own fault.  The practical and man-on-the-street answer is, no it doesn't, because nobody but a corporate lawyer getting $300 an hour for the job is going to read and understand all that stuff in the sense that is intended, and making ordinary non-lawyers press the button is simply a CYA (cover-your-afterparts) action on the part of the company.  And the FTC may be saying that Facebook hasn't been covering well enough.

I do not personally use Facebook, although my wife does and lets me know if she finds anything important on it that she thinks I ought to know.  As I said to begin with, privacy is a fuzzy concept which in the digital age we live in has come to mean different things to different people.  Younger people especially seem not to mind sharing things on public sites that forty or fifty years ago would have been confined to the privacy of one's diary kept under lock and key.  I suppose the best we can do is to make clear what users expect in the way of privacy, in terms that users themselves can understand, and then use government regulation if necessary to keep organizations like Facebook from abusing the trust that their users place in them.  And if it takes billion-dollar fines to get a company's attention, then I say go to it. 

Sources:  The AP article by Barbara Ortutay about the potential Facebook fine was carried by numerous news outlets, including the print edition of the Austin American-Statesman on Apr. 26, 2019, where I saw it.  One online location that is not protected by a pay-to-get-behind-it firewall (an increasingly common practice these days) where the article can be viewed is the website of West Virginia's Bluefield Daily Telegraph at https://www.bdtonline.com/region/possible-b-facebook-fine-echoes-european-tech-penalties/article_6c3bfa1d-9d83-58b3-8417-08fc8688ccd4.html. 

Monday, November 27, 2017

Uber Under Pressure for Data Breach


In recent years, the rideshare-app company called Uber has not led anyone to believe they would win a corporate personality contest.  Their aggressive growth and shouldering aside of municipal regulations and the charges of sexual harrassment that ultimately led to the resignation of Uber co-founder Travis Kalanick last June have now been followed by a revelation that Uber had a massive data breach in October of 2016, over a year ago, and didn't make it public till last week.  Besides probably violating state laws, this latest flap raises serious questions about the responsibility of companies to protect consumers' data, and what companies should do when that data is compromised.

Here is apparently what happened.  A year ago last October, Uber discovered that hackers had obtained about 57 million names, addresses, and emails of customers who had used Uber's services.   The hackers also snagged driver license numbers for over half a million of these people.  Then they pulled a classic blackmail act:  for a mere $100,000, the hackers offered to destroy the data and keep the whole thing a secret.  Under the reign of Kalanick, Uber agreed to this deal.  The company claims that they have evidence that the data was destroyed, but one can be permitted to wonder about something that amounts to proving a negative. 

The main problem with all this skulduggery, other than the breach itself, was the way Uber handled it.  Many state laws require companies to disclose major data breaches like this within a stated time, usually within four to six weeks of discovery.  Uber clearly didn't do this.  And even if Uber's new CEO, Dara Khosrowshahi, had disclosed the incident upon taking up his new job in September, instead of waiting for two months, Uber would have still been violating these laws. 

As hacks go, in terms of numbers and the kind of data stolen, there have been worse incidents.  But still, knowing that your email and linked phone number, and maybe your driver license number, are floating around out there in the hands of blackmailers, is not a comforting thought.  Even worse is the fact that Uber caved so fast to the blackmailers' demands.  True, not many hackers offer to destroy the data they've stolen, but words are cheap. 

What should consumers do when faced with a choice to either (a) deal with a company that offers an attractive service at a good price, but has a reputation for shady actions with regard to its own employees, hackers, and the law, or (b) well, maybe there isn't another good choice, except to try calling an old-fashioned cab and hope for the best?  (Full disclosure:  I have never used Uber, airbnb, or any of those other newfangled apps that are breaking down the time-honored traditional service industries.  There's nothing intrinsically wrong with using them, and many millions of happy customers continue to do so.  But I have no personal experience with them myself.) 

Even if a person is well aware of Uber's less-than-stellar corporate reputation, in many cases one doesn't have a choice:  Uber has chased away most of the competing apps (Lyft being an exception in some locations).  To use anything else may require a great deal of conscious effort and ingenuity, and in some locations and situations it simply may not be possible at all.

There is a paradox in the fact that the digital online world on the one hand promises an infinity of options and choices.  But on the other hand, when it comes to certain close-to-essential services such as search engines, online transportation apps, and Internet service providers, the list of workable choices at a given time and place is usually radically limited to a few, or even one. 

From a business point of view, this narrowing of choices is a function of what is called the network advantage.  As Ma Bell found out around 1890 when the telephone network was experiencing rapid growth, every customer a network company adds not only increases the company's customer base, but also makes that same company more valuable to all of its other customers.  That doesn't apply in exactly the same way to Uber as it does to AT&T, but the principle is the same:  the biggest firm in a network-intensive business automatically has built-in advantages over everybody else, and so you usually end up with a winner-take-most situation.  For those lucky enough to invest in the biggest company before it takes over the whole market, it is a very attractive deal indeed.  But for consumers wishing to have a meaningful choice among a number of alternatives, the dominance of a single firm is less than salutary.

The concept of privacy, and the related idea of security, may simply have to keep changing as we seem to accept risks that a few years ago would have simply been unacceptable.  Even in the Middle Ages, there was no such thing as absolute security.  A man carrying a purse of gold coins was always liable to run into some ruffians who would knock him down and rifle through his possessions.  But one of the basic attractive features of civilization is that under most circumstances, people can go about their daily business using services that they need, without unduly running the risk of somebody coming along and taking valuables from them. 

Now that identity theft is so easy, it's something that is ethically equivalent to a purse of gold coins carried by a Middle Ages merchant.  But in the wild-West environment that is the global Internet, we have left the providing of security largely to service firms themselves, with results such as the Uber breach that are far from encouraging.  In breaking the law requiring timely notification, Uber became one with the hackers, at least to the extent of ignoring the law.  Unfortunately, none of its customers knew what they were up to.  And now that we know, many people will simply shrug the incident off as one of the risks of modern digital life.

Maybe it is, but to my mind, accepting and tolerating such things is a step backwards in the progress of civilization.

Sources:  I referred to reports on the Uber data breach at Gizmodo.com, posted on Nov. 24 at https://gizmodo.com/uber-s-new-ceo-was-told-about-the-companys-massive-data-1820722228, and the Washington Post at https://www.washingtonpost.com/news/the-switch/wp/2017/11/24/uber-is-sued-over-massive-data-breach-after-paying-hackers-to-keep-quiet/.  I also referred to the Wikipedia articles on Travis Kalanick and Uber.

Monday, November 13, 2017

From Cops On the Beat to Spycams and Algorithms


Police departments these days are using the latest technologies in data analytics and surveillance, often without letting either the public or their own higher-ups know about it.  A recent online article in Slate asks whether these public-safety measures are threatening privacy to the extent that instead of Big Brother, we now have to worry about a lot of Little Brothers snooping around.

Consider these cases. 

For the last several years, the Chicago police force has operated a system that does for arrests what a credit score does for loan applications.  Every person arrested gets a computer-generated "threat score" that rates their chances of either committing a crime in the future or being the victim of one.  People with higher threat scores get extra attention such as home visits.  In domestic-abuse cases, this could have the desirable effect of providing more security for an abused wife or girlfriend, and that is certainly a laudable goal.  But as anyone who has had their credit rating fouled up by a rating agency knows, mistakes in these systems can happen.

And in Baltimore, a firm was hired to fly a private plane above the city and take wide-angle high-resolution video with no particular crime scene in mind, just to furnish a God's-eye view of everything going on in the event that some of it turned out to be criminal activity.  When the citizens of Baltimore heard about it, they raised such an outcry that the program was terminated.  But similar technology is available and is being used elsewhere—maybe even in your town.

We already know about police-car dashcams and body cameras, which have been viewed as protecting the rights of citizens as much as aids to police trying to enforce the laws.  But wider-scope systems such as database-generated algorithms and synoptic surveillance not targeted at a specific crime or criminal are new things, and for understandable reasons, some law-enforcement authorities are not being as open as they could be about using them.

There is some justification for this.  One can argue that a novel surveillance method can be more effective if the people being spied on don't know about it.  But this argument is lost on the millions of stores that have prominent signs saying things like, "Smile! You're on TV" and otherwise make no secret that customers are being watched electronically, as a deterrent to shoplifting. 

Also counter to that argument is the notion that in a democracy, citizens have a right to know what methods law-enforcement authorities are using, and to make a considered judgment as to whether the alleged benefits of reduced crime and improved public safety outweigh the potential harm to what remains of our privacy. 

The Slate article treats the fact that there are around 17,000 separate law-enforcement organizations in the U. S. as a problem, because any given location may be under the authority of several of them, and sometimes it's a big headache even to figure out who to ask about these things.  But the Big Brother reference I began with comes from George Orwell's dystopian novel 1984, which featured "telescreens" everywhere that not only projected images of a Stalin-like figure named Big Brother, but reminded everyone that Big Brother was watching, through hidden cameras.  For most of the novel's lifetime, nobody worried about universal spycams becoming a reality, because the only way for every citizen to be watched was to hire enough people to sit there and watch the screens, which would have meant as late as the 1960s, it would have taken maybe 50 or 100 million people monitoring the 200 million or so U. S. citizens—clearly an impractical project. 

But now with digital storage, face-recognition algorithms, and artificial intelligence, spying on everybody in the U. S. all the time is still a remote possibility, but not nearly as remote as it used to be.  Things have reportedly progressed a lot farther along these lines in Great Britain, where it's not possible to walk outside in London for more than a few feet without becoming a feature in somebody's surveillance camera somewhere.

In such a highly spied-upon situation, it's a good thing that there are 17,000 different policing authorities instead of one big one, as George Orwell imagined in 1984.  Even if a few of them go overboard, the damage will be limited to that authority's geographic region.

But this isn't an argument for complacency.  Actions that affect the privacy of the average law-abiding citizen, especially when funded with that law-abiding citizen's taxes, need to be made known to said law-abiding citizen.  And so when police departments and other government-run security organizations start doing wholesale data gathering on innocent and guilty alike, this kind of thing needs to be advertised or made public in some way that brings the awareness of the activity to those who are directly affected by it.

Abuses of these technologies can happen.  It's probably because policing authority is so diffused in this country that we don't have more scandals relating to the abuse of surveillance technology.  The FBI, one of our few national-scope law-enforcement agencies, has been involved in a few such cases, but eventually Congress or someone else outside the executive branch manages to blow the whistle on them and correct the abuse. 

But many municipalities don't have such a mechanism to ensure that law-enforcement agencies inform the public they are watching that certain technologies are being used.  The Slate article cites a program sponsored by the American Civil Liberties Union called "Community Control over Police Surveillance" that can serve as a model of accountability.  I haven't studied the ACLU's efforts in this regard and can't vouch for its effectiveness, but it would probably be a good place to start.

Privacy is a much-neglected right in some areas of U. S. life.  We have gradually been trained by private interests to say good-by to it whenever we log online and do a search or buy a product.  But in going about our daily lives, and especially in our homes, it is a valuable thing to know that one is not being watched by a stranger who could, if he chose, use information gathered about you to complicate your life in some way.  At the very least, if such things happen, the people who are paying the taxes that pay for the systems need to know what they're buying—and refuse to buy it if they don't like it. 

Sources:  The article "The Fragmented Surveillance State" by Andrew Guthrie Ferguson appeared on the Slate website at http://www.slate.com/articles/technology/future_tense/2017/11/the_united_states_fragmented_surveillance_system.html.  More information about the ACLU's Community Control over Police Surveillance program can be found at https://www.aclu.org/issues/privacy-technology/surveillance-technologies/community-control-over-police-surveillance.  And George Orwell's novel 1984 was published in 1949, when television was just beginning to appear in large numbers of private homes in the U. S.

Monday, February 20, 2017

Can Anything Echo Hears Be Used Against You In a Court of Law?


That's the question raised by a murder case out of Bentonville, Arkansas.  On Saturday, Nov. 21, 2015, James Bates invited three friends over to watch an Arkansas Razorbacks game.  The men had some drinks, and when one of them, Owen McDonald, left around 12:30 AM, Bates was still up and around. 

The next morning, Bates called 911 to report that he'd found one of his guests, Victor
Collins, floating face-down, dead in Bates's hot tub.  He claimed he'd gone to bed and left Collins still awake.

After checking with McDonald and looking at the physical evidence, police began to doubt Bates's story.  The deck around the hot tub was wet despite near-freezing temperatures, and Collins' body had sustained numerous injuries consistent with his being strangled to unconsciousness and then put in the hot tub to drown.  Bates's home was equipped with both an Amazon Echo and a smart water meter.  As part of the investigation, police attempted to obtain evidence from the operators of both devices.

The Bentonville utility department was very helpful.  The smart meter records hour-by-hour water usage.  Up to midnight the most water used in an hour at Bates's home that fateful evening was ten gallons.  But between 1 AM and 3 AM, somebody used 140 gallons, the most ever recorded by that meter in a short time.  This was consistent with Bates' use of a water hose to rinse away blood, which police found traces of anyway near the hot tub. 

The way the Echo works is similar to other digital assistants such as Apple's Siri.  It passively listens, holding audio in a local buffer memory, until it "hears" the wake-up word—in the case of Echo, it's "Alexa."  Then it sends the preceding and following minute or so of audio to the Amazon cloud, where sophisticated voice-recognition software decodes the request and does whatever the inquirer has asked, within the limits of the software, of course. 

It was a long shot to begin with to hope that the Echo would have recorded to the cloud anything of relevance.  The investigators were hoping that on the off chance Echo "woke up" sometime during the murder, they could obtain useful information.  But they ran into a wall with Amazon, which claimed that their request was outside the bounds of what Amazon considers reasonable.  All that Amazon would tell them was Bates's purchase information regarding the Echo, which has been physically taken into custody by law enforcement.

On the strength of the smart-meter evidence, Bates has been charged with the murder of Collins, but is currently out on bail awaiting trial.  In the meantime, numerous privacy and electronically-stored-evidence legal experts have commented on the case, as it is one of the first to involve the relatively new digital assistants, and also one in which the company operating the device has refused to cooperate to the extent requested by law enforcement.

As David Pogue points out in a commentary in Scientific American, one can understand Amazon's reluctance to give a public impression that every Echo is a potential stool pigeon.  The product has been very popular up to now, and Amazon doesn't want to do anything to dampen the law-abiding public's enthusiasm. 

But it's interesting to me to note the contrast between the different attitudes that the local utility company had toward the request for information, and what Amazon has done.  The fact of the matter is, once again technology has outpaced the ability of the legal system to keep up with it.

Generally speaking, the laws of evidence allow law enforcement personnel to request all sorts of information once they have obtained a valid search warrant.  Telephone and text message records, Fitbit data, records of Internet searches, and even video game data have all been used as evidence in criminal cases, according to Holly Howell, a writer at the legal website Cumberland Trial Journal. 

But the difference here between the smart-meter data and the Echo data is that smart meters aren't bought by consumers who have a lot of other choices about where to spend their money on smart meters, and personal assistants like Echo are.  One can detect a whiff of hypocrisy in the stance of Amazon, whose profitability increasingly relies on the rich mines of data it extracts from the digital behavior of its customers, and the way it sells such data or otherwise profits from it.  Admittedly, anyone who has spent any amount of time on the Internet knows that unless you take extreme precautions to prevent information mining, the websites you visit are going to share information about your searches with whoever they think might be interested, as long as the interested parties pay for it.  So when you're online, you know you can easily be observed, just like in the old days of three-network TV you knew that no matter how good the show was, it would sooner or later be interrupted by a commercial.  It's just something we've learned to put up with.

But doing a deliberate Internet search is one thing, and just minding your own business and going about your private life is another.  I suppose if I became a bed-bound invalid I would find some use for an Echo or a Siri, but other than that I have no plans to get one.  But if I did, I would be undoubtedly creeped out if I thought the thing was listening to everything I said and was relaying it to some anonymous cloud server that would do Heaven knows what with the information. 

So I can see why Amazon is reluctant even to give the impression that Echo is really listening to everything you do, in any meaningful sense.  But as the Internet of Things keeps advancing, both criminals and law-enforcement personnel will increasingly find uses for them—the one group in committing ingenious crimes, and the other in solving those crimes.  And currently, the laws concerning what is valid evidence have to be twisted out of their traditional context to apply to at least some of these novel technologies.  Asking for more laws these days is not a popular thing to do, but it does seem like there needs to be some legislation that will clarify the status and obligation of firms such as Amazon when products they sell and operate inadvertently obtain information that can be used in judicial proceedings.

The discovery process of Mr. Bates's trial begins next month, and so we'll have to wait till then to see if the police ever found anything useful on his Echo.  In the meantime, if you have a personal digital assistant, watch what you say around it.  It might rat on you.

Sources:  I came across the Collins murder case in David Pogue's column "Your Echo is Listening," in Scientific American (March 2017), p. 28.  I also referred to Holly Howell's article "Is Evidence Gathered from 'Smart' Devices the New Way to Catch Dumb Criminals?" in the Cumberland Trial Journal at http://www.cumberlandtrialjournal.com/is-evidence-gathered-from-smart-devices-the-new-way-to-catch-dumb-criminals/.