data security
There Is No Such Thing As A Privacy Setting On Facebook
Posted December 17th, 2009 by BillAll of the recent discussion about Facebook's change to its privacy policy obscures one frequently minimized point: privacy doesn't really exist on Facebook. While there is minimal control over what appears onscreen, this should not be confused with real, actual privacy, or the ability to control what is known about you. Facebook has your information, and by virtue of using their site, you have provided them a degree of control over your personal information.
This becomes particularly apparent when looking at Third Party Application developers. These external applications can access data in ways that are not immediately obvious to the end user, and in some cases this seems to work against people's obvious desires. In short: third party applications get the same access as the account that installed them, so if your privacy settings are set to friends only, and a third party app installed by a friend requests your information, it can get it. So, your privacy is as good as your least discrete friend's judgment.
But issues around abusing privacy aren't new for Facebook. They have these types of issues a few times a year, every year. Flash back to the launch of Beacon:
"Facebook still collects your data. Whether or not they show it onscreen or not is only marginally relevant. They have records of how you have used their site, and that information is valuable to people who want to sell you things."
Facebook has a well worn track record of disastrous handling of user data. In the beginning of 2009, Facebook pre-emptively changed their ToS. People were not happy, but people should not be surprised, as this is normal behavior for Facebook.
And Facebook's current "privacy policy" has some gems -- really, there are too many to list, but my favorite is probably from Section 3: Information You Share With Third Parties: "We take steps to ensure that others use information that you share on Facebook in a manner consistent with your privacy settings, but we cannot guarantee that they will follow our rules." Translation: People will get your information through our site, and we don't really have much/any control over what they do with your information.
And, of course, Facebook can change their privacy settings at will, thus eliminating the illusory value of these settings in the first place, as illustrated by this very conversation.
Some other good reads on this:
- The Facebook Blog: http://blog.facebook.com/blog.php?post=197943902130
- Electronic Frontier Foundation: http://www.eff.org/deeplinks/2009/12/facebooks-new-privacy-changes-good-...
- From ReadWriteWeb: http://www.readwriteweb.com/archives/facebooks_privacy_move_violates_con...
Google Apps, and Privacy
Posted March 12th, 2009 by BillI came across another discussion on the use of Google Apps within K12 organizations -- this is a lightly edited version of my reply in that thread:
With Google Apps, the real value for Google isn't in "owning" your content. The value for them is in mining it, and then using that information to hone their business selling ads and working with affiliate advertisers -- and their privacy policy expressly states that your data will be used in this way.
From Google's Privacy Policy, at http://www.google.com/privacypolicy.html
Log information – When you access Google services, our servers automatically record information that your browser sends whenever you visit a website. These server logs may include information such as your web request, Internet Protocol address, browser type, browser language, the date and time of your request and one or more cookies that may uniquely identify your browser.
So, they can track a request for a specific web site to a specific user, and can keep track of what an individual does over time.
Affiliated Google Services on other sites – We offer some of our services on or through other web sites. Personal information that you provide to those sites may be sent to Google in order to deliver the service. We process such information under this Privacy Policy. The affiliated sites through which our services are offered may have different privacy practices and we encourage you to read their privacy policies.
The approximate translation: when using Google Apps, you might get sent to another site, and this site might have a different privacy policy, and this site might share a different set of your private information with us. You may or may not know when this is happening, but it's your responsibility to know when to check for the privacy policy of these sites.
Then, the policy goes on to list why Google is collecting this information:
- Providing our services, including the display of customized content and advertising;
- Auditing, research and analysis in order to maintain, protect and improve our services;
I've chosen a very small section of the privacy policy here, but the full policy goes into much more detail, including info about geographical data.
For a sense of what can be inferred from even very rough user data, take a look at the fallout that occurred when AOL released search data from it's userbase. This search data is nowhere near as precise as what Google collects, but it still revealed an astonishing range of information about its users.
So, when schools are using Google Apps, every member of that community is participating in unpaid marketing research. If you are buying Google Apps as part of a service, you are paying to participate in market research.
As a closing thought, I'd like to hear the conversation that ensued if a person walked into the head of school's/principal's office and said the following:
"I'd like to enroll all of our Middle School students in an unpaid marketing research program. They'll never know it's going on, and every facet of their online collaboration will be tracked as part of the study. Oh, and it comes with email."
It Hurts. Please, Make It Stop.
Posted February 21st, 2009 by BillRecently, via a listserv where I participate, I learned about a site called StudyBlue. This site was touted as part of a new set of tools supporting networked learning; my response is reposted below.
My response
Hello, all,
At the risk of being a curmudgeon, we need to look at the terms of use of the services we are using/promoting.
The Terms of Use of StudyBlue, available at http://www.studyblue.com/Terms.htm, contain the following language:
"By posting Member Content to any part of the Web site, you automatically grant, and you represent and warrant that you have the right to grant, to the Company an irrevocable, perpetual, non-exclusive, transferable, fully paid, worldwide license (with the right to sublicense) to use, copy, perform, display, reformat, translate, excerpt (in whole or in part) and distribute such information and content and to prepare derivative works of, or incorporate into other works, such information and content, and to grant and authorize sublicenses of the foregoing."
However, this site is one of the rare cases that has Terms that are worse than Facebook's (who at least pay lip service to respecting user's privacy decisions).
From the StudyBlue terms of service, from the link above:
"When you upload Member Content as Private the Company will not post the information to any other Member without your permission. However, upon leaving a class or course, any Member Content left uploaded as Private will be made Public for the life of the Web site. You may remove your Private Member Content from the Web site before you leave a class or course. If you choose to remove your Private Member Content before leaving a class or course , the license granted above will automatically expire. If you do not remove your Private Member Content from the Web site before you leave a class or course, the license granted above will not expire and will continue indefinitely."
So, if you create private content in a course/group, it will become public if you leave the course without deleting it. Moreover, on a quick read through, these terms say nothing about what happens if a user wants to delete their account. Under these terms, there seems to be no way for a user to delete their content, which is, according to these terms, licensed in perpetuity to StudyBlue.
Facebook recently enraged a portion of their user base by similar behavior: http://consumerist.com/5150175/facebooks-new-terms-of-service-we-can-do-... or http://is.gd/jDf4
The web opens up an array of options for teaching, learning, and connecting, but we need to remember that learning should be organized around the needs of the student/learner. The cost of joining a website should not be complete loss of control over your content, and as technology advocates we need to become more aware of the ramifications of data control and data portability within networked learning environments. In short, learners deserve better than the terms offered at StudyBlue, Facebook, Ning, etc. Why should a prerequisite of social learning be the loss of control over how your work is used/reused? By promoting sites that are predicated on an intellectual land grab of learner-created content, we perpetuate the lie that this is acceptable behavior.
Hands Off
Posted February 20th, 2009 by BillIn an earlier post this year, I held out hope that 2009 would finally be the year where people started taking data ownership and data portability seriously.
As Facebook often does, they help illustrate why this is relevant, and why this is something people should care about.
The fun began a few weeks ago, when Facebook changed their Terms of Service. Last weekend, Consumerist described the specifics of the changes:
Facebook's terms of service (TOS) used to say that when you closed an account on their network, any rights they claimed to the original content you uploaded would expire. Not anymore.
Now, anything you upload to Facebook can be used by Facebook in any way they deem fit, forever, no matter what you do later. Want to close your account? Good for you, but Facebook still has the right to do whatever it wants with your old content. They can even sublicense it if they want.
To summarize, the old version of Facebook's Terms of Service used to specify that, when a person deleted their account, their content went with them (and never mind that the process of deleting an account has proven, well, troublesome for some).
Facebook founder Mark Zuckerberg initially defended the change (does this remind anyone else of the response to Beacon?), but 24 hours later Facebook announced that they would revert to the original terms of service.
But really, the hue and cry over Facebook's terms of service misses the larger point: when you put your data into a hosted service, you are allowing it to slide outside of your control. This is true of most hosted services, including Facebook, Ning, MySpace, etc. Facebook's change of the license terms illustrates a larger point: they control your data. More importantly, sites like Facebook and Ning allow people who have no ties to either company to access your data via third party apps. A quick read through the Developers Terms of Service for both Facebook and Ning show that developers of these apps can access user data and content, but this creates an enormous gray area: if someone deletes their account, what happens to any data collected by these third party application developers? I would love to hear of the mechanisms in place that measure how application developers abide by the rules concerning user data.
So, when evaluating a platform for use by you, by your class, or within your school, department, district, or organization, make sure to read the privacy policy, terms of service, and any applicable third party developer terms of service. All of these affect how the work of people within your site will be treated, and potentially used -- which is especially relevant given that most of these sites include terms that allow for indiscriminate resuse and republication of content posted in the site.
At the risk of stating the obvious, none of these are concerns for sites built using open source tools.
And for those curious about where this ends, it looks like Facebook's interest in user data extends beyond the grave.
The More Things Close, the More They Stay the Same
Posted January 15th, 2009 by BillLike I said earlier, maybe 2009 will be the year that people start taking data ownership seriously.
A spate of closings from Google, and the elimination of any free version of Sprout Builder should go a ways toward reinforcing what should have been obvious for a long time: when you rely on a free service, you are ceding control.
And, services close. License terms change. We don't need to look very hard to see examples of what happens when these services go away. Personally, I'd rather take on the work of archiving my own work (aka, keeping track of my own stuff) than trying to rebuild large pieces of my own work. And yes, Open Source tools help us have more control of our own work.
RE services closing, this should not be surprising. Really, I'm more surprised that anyone would actually be surprised.
And, a ht to Stephen Downes for continuing to highlight these issues, and Brian Lamb and Cole Camplese say more intelligent things about this.

