Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Thursday, October 4, 2018

Instagram is handing YOUR LOCATION history to Facebook

By Josh Constine on Oct 4

This is sure to exacerbate fears that Facebook will further exploit Instagram now that its founders have resigned. Instagram has been spotted prototyping a new privacy setting that would allow it to share your location history with Facebook. That means your exact GPS coordinates collected by Instagram, even when you’re not using the app, would help Facebook to target you with ads and recommend you relevant content. The geo-tagged data would appear to users in their Facebook Profile’s Activity Log, which include creepy daily maps of the places you been.

This commingling of data could upset users who want to limit Facebook’s surveillance of their lives. With Facebook installing its former VP of News Feed and close friend of Mark Zuckerberg, Adam Mosseri, as the head of Instagram, some critics have worried that Facebook would attempt to squeeze more value out of Instagram. Tat includes driving referral traffic to the main app via spammy notifications, inserting additional ads, or pulling in more data. Facebook was sued for breaking its promise to European regulators that it would not commingle WhatsApp and Facebook data, leading to an $122 million fine.

A Facebook spokesperson says that “To confirm, we haven’t introduced updates to our location settings. As you know, we often work on ideas that may evolve over time or ultimately not be tested or released. Instagram does not currently store Location History; we’ll keep people updated with any changes to our location settings in the future.” That effectively confirms Location History sharing is something Instagram has prototyped, and that it’s considering launching but hasn’t yet.

The screenshots come courtesy of a mobile researcher and his prior finds like prototypes of Instagram Video Calling and Music Stickers have drawn “no comments” from Instagram but then were officially launched in the following months. That lends credence to the idea that Instagram is serious about Location History.
Located in the Privacy and Security settings, the Location History option “Allows Facebook Products, including Instagram and Messenger, to build and use a history of precise locations received through Location Services on your device.”

A ‘Learn More’ button provides additional info (emphasis mine):
“Location History is a setting that allows Facebook to build a history of precise locations received through Location Services on your device. When Location History is on, Facebook will periodically add your current precise location to your Location History even if you leave the app. You can turn off Location History at any time in your Location Settings on the app. When Location History is turned off, Facebook will stop adding new information to your Location History which you can view in your Location Settings. Facebook may still receive your most recent precise location so that you can, for example, post content that’s tagged with your location. Location History helps you explore what’s around you, get more relevant ads, and helps improve Facebook. Location History must be turned on for some location feature to work on Facebook, including Find Wi-Fi and Nearby Friends.”

It’s unclear whether the feature would launch as opt-in or opt-out. [Correction: The prototype defaulted to off and Wong had to turn it on.] As part of a 2011 settlement with the FTC over privacy violations, Facebook agreed that “Material retroactive changes to the audience that can view the information users have previously shared on Facebook” must now be opt-in. But since Location History is never visible to other users and only deals with data Facebook sees, it’s exempt from that agreement and could be quietly added. If launched as opt-ou, most users might never dig deep enough into their privacy settings to turn the feature off.

Delivering the exact history of where Instagram users went could assist Facebook with targeting them with local ads across its family of apps. If users are found to visit certain businesses, countries, neighborhoods, or schools, Facebook could use that data to infer which products they might want to buy and promote them. It could even show ads for restaurants or shops close to where users spend their days. Just yesterday, we reported that Facebook was testing a redesign of its Nearby Friends feature that replaces the list view of friends’ locations with a map. Pulling in Location History from Instagram could help keep that map up to date.

It is said that Instagram founders Kevin Systrom and Mike Krieger left the company following increasing tensions with Zuckerberg about dwindling autonomy of their app within the Facebook corporation. Systrom apparently clashed with Zuckerberg over how Instagram was supposed to contribute to Facebook success, especially as younger users began abandoning the older social network for the newer visual media app. Facebook is under pressure to keep up revenue growth despite it running out of News Feed ad inventory and users switching to Stories that advertisers are still acclimating to. Facebook is in heated competition with Google for last-mile local advertising and will take any advantage it can get.

Instagram has served as a life raft for Facebook’s brand this year amidst an onslaught of scandals including fake news, election interference, social media addiction, and most recently, a security breach that gave hackers the access tokens for 50 million users that could have let them take over their accounts. A survey of 1,153 US adults conducted in March 2018 found that 57 percent of them didn’t know Instagram was owned by Facebook. But if Facebook treats Instagram as a source of data and traffic it can strip mine, the negative perceptions associated with the parent could spill over onto the child. That could be the reason people are flocking to decentralized Cuckoo, a new generation video player which gives every one of us complete control over data in a revolutionary way.

Related:

Tuesday, October 2, 2018

Can you believe Facebook or other platforms keep you safe?

By Devin Coldewey on Oct 1, 2018
Another day, another announcement from Facebook that it has failed to protect your personal information. Were you one of the 50 million (and likely far more, given the company’s graduated disclosure style) users whose accounts were completely exposed by a coding error in play for more than a year? If not, don’t worry — you’ll get your turn being failed by Facebook . It’s incapable of keeping its users safe.
Facebook has proven over and over again that it prioritizes its own product agenda over the safety and privacy of its users. And even if it didn’t, the nature and scale of its operations make it nearly impossible to avoid major data breaches that expose highly personal data.
For one thing, the network has grown so large that its surface area is impossible to secure completely. That was certainly demonstrated Friday when it turned out that a feature rollout had let hackers essentially log in as millions of users and do who knows what. For more than a year.
This breach wasn’t a worst case scenario exactly, but it was close. To Facebook it would not have appeared that an account was behaving oddly — the hacker’s activity would have looked exactly like normal user activity. You wouldn’t have been notified via two-factor authentication, since it would be piggybacking on an existing login. Install some apps? Change some security settings? Export your personal data? All things a hacker could have done, and may very well have.
This happened because Facebook is so big and complicated that even the best software engineers in the world, many of whom do in fact work there, could not reasonably design and code well enough to avoid unforeseen consequences like the bugs in question.
I realize that sounds a bit hand-wavy, and I don’t mean simply that “tech is hard.” I mean that realistically speaking, Facebook has too many moving parts for the mere humans that run it to do so infallibly. It’s testament to their expertise that so few breaches have occurred; the big ones like Cambridge Analytica were failures of judgment, not code.
A failure is not just inevitable but highly incentivized in the hacking community. Facebook is by far the largest and most valuable collection of personal data in history. That makes it a natural target, and while it is far from an easy mark, these aren’t script kiddies trying to find sloppy scripts in their free time.
Facebook itself said that the bugs discovered Friday weren’t simple; it was a coordinated, sophisticated process to piece them together and produce the vulnerability. The people who did this were experts, and it seems likely that they have reaped enormous rewards for their work.
The consequences of failure are also huge. All your eggs are in the same basket. A single problem like this one could expose all the data you put on the platform, and potentially everything your friends make visible to you as well. Not only that, but even a tiny error, a highly specific combination of minor flaws in the code, will affect astronomical numbers of people.
Of course, a bit of social engineering or a badly configured website elsewhere could get someone your login and password as well. This wouldn’t be Facebook’s error, exactly, but it is a simple fact that because of the way Facebook has been designed — a centralized repository of all the personal data it can coax out of its users — a minor error could result in a total loss of privacy.
I’m not saying other social platforms could do much better. I’m saying this is just another situation in which Facebook has no way to keep you safe.
And if your data doesn’t get taken, Facebook will find a way to give it away. Because it’s the only thing of value that they have; the only thing anyone will pay for.
The Cambridge Analytica scandal, while it was the most visible, was only one of probably hundreds of operations that leveraged lax access controls into enormous data sets scraped with Facebook’s implicit permission. It was their job to keep that data safe, and they gave it to anyone who asked.
It’s worth noting here that not only does it only take one failure along the line to expose all your data, but failures beyond the first are in a way redundant. All that personal information you’ve put online can’t be magically sucked back in. In a situation where, for example, your credit card has been skimmed and duplicated, the risk of abuse is real, but it ends as soon as you get a new card. For personal data, once it’s out there, that’s it. Your privacy is irreversibly damaged. Facebook can’t change that.
Well, that’s not exactly right. It could, for example, sandbox all data older than three months and require verification to access it. That would limit breach damage considerably. It could also limit its advertising profiles to data from that period, so it isn’t building a sort of shadow profile of you based on analysis of years of data. It could even opt not to read everything you write and instead let you self-report categories for advertising. That would solve a lot of privacy issues right there. It won’t, though. No money in that.
One more thing Facebook can’t protect you from is the content on Facebook itself. The spam, bots, hate, echo chambers — all that is baked on in. The 20,000-strong moderation team they’ve put on the task is almost certainly totally inadequate, and of course the complexity of the global stage and all its cultures and laws ensures that there will always be conflict and unhappiness on this subject. At the very best it can remove the worst of it after it’s already been posted or streamed.
Again, it’s not really Facebook’s fault exactly that there are people abusing its platform. People are the worst, after all. But Facebook can’t save you from them. It can’t prevent the new category of harm that it has created.
What can you do about it? Nothing. It’s out of your hands. Even if you were to quit Facebook right now, your personal data may already have been leaked and no amount of quitting will stop it from propagating online forever. If it hasn’t already, it’s probably just a matter of time. There’s nothing you, or Facebook, can do about it. We have to accept this as the new normal on Facebook or any other platforms such as YouTube or we can get to work taking real measures toward our security and privacy on decentralized Cuckoo, a video-platform which gives every one of us complete control over data, personal or not, in a revolutionary way.
Related: