97
Privacy in Social Networks Carlos Ordonez David Matusevich

Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

PrivacyinSocialNetworks

CarlosOrdonezDavidMatusevich

Page 2: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

OutlineI. Overview

– WhatisaSocialnetwork?– Prominentsocialnetworks– WhatisPrivacy?

II. PrivacyIssues– Social;Legal– Differenceswithdatasecurity– Commercialadvantage

III. Controllingprivacy– WhatDataisCollected– ManagingPrivacySettings

IV. StrategiesforSafeSharing:– Protectingyouronline“brand”I. SafeOnlineSocializing

Page 3: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

I- Overview

Page 4: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

WhatisaSocialNetwork?

• ASocialNetworkSiteisaWeb-basedservicethatallowsindividualsto“constructapublicorsemi-publicprofilewithinaboundedsystem;articulatealistofotheruserswithwhomtheyshareaconnection;andviewandtraversetheirlistofconnectionsandthosemadebyotherswithinthesystem”,thereforeincreasingtheirsocialcapital.

• Wewillnotconsiderotherkindsofsocialnetworksthatdon’trelyonasocialnetworkprovider.

Page 5: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SocialNetworkDataStorage

• USA/CanadaandEurope– Local– External

• Atmultiplesites• Transferredandshared

Page 6: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

DisseminationofinformationShapeoffriendsgraph

• Star• Tree• Interconnectedcircles• Cliques

Page 7: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SocialNetwork

• ASocialnetworkisacentralplacethatcombines– Entertainment– Socialinteractions– Communicationfacilities

• Socialnetworkoperators(users)buildprofilesthatcanbeseenbyotherusers.Theusermanagestheamountofinformationotherscansee.

• Personaldataisnowconsideredthenew“oil”,andcompaniesareeagertocashinonthisnewresource.

Page 8: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SocialNetworkElements

• Aboundedsetofusers• Publicorsemipublicpersonalprofiles• Definitionofasetofpeoplerelatedtoaperson(friends,relatives)

• Freedomtotraverselistsofconnections(theirownandothers)

• SocialNetworkCapital:Theexpectedcollectiveoreconomicbenefitsderivedfromthepreferentialtreatmentandcooperationbetweenindividualsandgroups

Page 9: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SocialNetworksvs.InternetCommunities

• InternetCommunities:Similartosocialnetworksbuttherearenoexplicitinteractionsbetweenusersandnoconnections.

• YouTube,Amazon,eBayarecommunities,butsincethereisnosetofconnections,theycannotbeconsiderednetworks.

• Astimegoesby,thelinesbetweencommunitiesandnetworksarebecomingmoreblurred.

Page 10: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheSocialAspect

• Socialnetworksareusedtoconnectwithpeoplemetofflineoronline

• Toalesserextentinvestigatepeople(asaprimitivebackgroundcheck)

• Colleagues,classmatesandfriendsingeneral,mayshareconnectionsonline,butnotnecessarilyoffline

Page 11: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

MotivationsforJoiningaSocialNetwork

Peoplejoinsocialnetworksto:• Createandsharecontentaboutthemselves• Toconnectwithothers(eitheroldacquaintancesornew)

• Tomeetpeoplewithsimilarinterests• FinancialMotivations

Inordertoachievethesegoals,theremustbeameasureofvoluntarydisclosureamongmultipleusers

Page 12: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Rank Name Activeuseraccounts

SiteCountryoforigin

1 Facebook 1billion[1] UnitedStates

2 TencentQQ 712million[3] China

3 Qzone 400+million[5] China

4 SinaWeibo 300+million[7] China

5 Google+ 235million[8] UnitedStates

6 Twitter 200+million[10] UnitedStates

7 VK 190+million[11] Russia

8 LinkedIn 160million[12] UnitedStates

9 Renren 160+million[13] China

10 Skype 145+million[14] Estonia

TopTenSocialNetworksbyUsers

Page 13: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Socialnetsbecomingmorecommon

• SocialnetworksareanincreasinglyubiquitouspartofAmericans'dailylives;

• Recentdatashowsthat65%ofInternet-usingU.S.adultsmaintainaprofileonanSNS

• Thisfigureisincreasedto81%whenconsideringteens

Page 14: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Facebookphenomenon

• Morethan1Billionactiveusers.• 50%percentofuserslogindaily.• Theaverageuserhas130friends,• Averageuserisamemberof12groups,andspendsmorethan55minutesperdayonthesite

Page 15: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Facebookinmoredetail

• 2.5billionphotosuploadedeachmonth,withmorethan

• 3.5billionpiecesofcontentsharedeachweek• Therearecurrentlymorethan70translationsofthesiteavailable

• 70%ofFacebookuserscomingfromoutsideoftheUnitedStates(Facebook,2010).

Page 16: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

PrivacyOverview:PrivacyDefinition

• Privacy istheabilityofanindividualorgrouptosecludethemselvesorinformationaboutthemselvesandtherebyrevealthemselvesselectively.

• Westin1967:“theclaimofindividuals,groups,orinstitutionstodetermineforthemselveswhen,howandtowhatextentinformationaboutthemiscommunicatedtoothers’’

• Altman1975:selectivecontrolofaccesstotheself

Page 17: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

ThereisNOprivacyanymore!• InessencetheEuropeanCommunityconsidersprivacyaHuman

Right,notsomethingthatisgrantedbythegovernment.• Article8ofthe EuropeanConventiononHumanRights providesa

righttorespectforone's"privateandfamilylife,hishomeandhis correspondence",subjecttocertainrestrictionsthatare"inaccordancewithlaw"and"necessaryinademocraticsociety".

• Thisviewisnotuniversallyaccepted.In1999SunMicrosystemsCEOScottMcNealycalledprivacya“redherring”.“Youhavezeroprivacy,getoverit!”,hesaid.

• GoogleCEOEricSchmidtsaidthat“Ifyouhavesomethingthatyoudon'twantanyonetoknow,maybeyoushouldn'tbedoingitinthefirstplace”,whenaskedifusersshouldbesharingtheirinformationwithGoogle.

Page 18: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Principlesgoverningthe EuropeanCommunity(OECD)recommendationsforprotectionofpersonaldata

1. Notice—datasubjectsshouldbegivennoticewhentheirdataisbeingcollected;

2. Purpose—datashouldonlybeusedforthepurposestatedandnotforanyotherpurposes;

3. Consent—datashouldnotbedisclosedwithoutthedatasubject’sconsent;

4. Security—collecteddatashouldbekeptsecurefromanypotentialabuses;

5. Disclosure—datasubjectsshouldbeinformedastowhoiscollectingtheirdata;

6. Access—datasubjectsshouldbeallowedtoaccesstheirdataandmakecorrectionstoanyinaccuratedata;and

7. Accountability—datasubjectsshouldhaveamethodavailabletothemtoholddatacollectorsaccountableforfollowingtheaboveprinciples

Page 19: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Onlinevs.offlineprivacy

• Wearewearyofpeoplethatmightapproachusinourdailylife,butwereactdifferenttostrangerswemeetonline.

• Thisbehaviorisseenonpeoplefromallages,fromchildrentoadults.

• Thereisarealdisconnectbetweenonlineandofflinenotionsofprivacy.

Page 20: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Hardware

• Socialnetworkscanbeaccessedbyalargenumberofdifferentdevices.

• Laptopanddesktopcomputersgiveaccesstobetter“views”ofthenetworksite,butlimitthespontaneityofsharing.

• Cellphonesandtabletsprovideeasyaccesstothesocialnetworksandenablequicksharingofphotosandgeo-location.

Page 21: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

PrivacyInvasionExperiment

Page 22: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Informationprivacy

• Informationprivacy,or dataprivacy(ordataprotection),istherelationshipbetweencollectionanddisseminationof data,technology,thepublic expectationofprivacy,andthe legal andpolitical issuessurroundingthem.

Page 23: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Privacytypes

• Socialprivacy:howpeopleprotectthemselvesfromotherusers

• Institutionalprivacy:howthecompanythatrunsthesocialnetworkusespeople’sdata

• Concern:theheightenedvisibilitythatistheresultofhavingalargenumberoffriends,includingpeopleindifferentages→socialsurveillanceandsocialcontrol

Page 24: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Privacyissuesofsocialnetworkingsites

• Socialnetworks keeptrackofallinteractionsusedontheirsitesandsavethemforlateruse.

• Issuesinclude:– Cyber-stalking,– locationdisclosure,– socialprofiling,– dataleakageandinformationintegration,– 3rdpartypersonalinformationdisclosure,– government useofsocialnetworkwebsitesininvestigationswithoutthesafeguardofa searchwarrant.

Page 25: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Impact

• Theprivacyimpactofsocialnetworksshouldnotbeunderestimated.

• Manyusersdonotseemtorealizethattheirfreeuseofsocialnetworkshasanindirectbutsteepeffectthroughtheexposureoftheirownpersonaldata.

• Inaddition,manyusersdonotrealizewhichimpacttheyhaveontheprivacyoftheirfriendsandfamilieswhentheypublishinformationaboutthem.

Page 26: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

UnboundedaudienceMarwickandBoyd(2011)

“WemayunderstandthattheTwitterorFacebookaudienceispotentiallylimitless,but

weoftenactasifitwerebounded”

Page 27: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

PrivacyAwareness

• Privacyissuesoftenonlybecomeapparentwhenitisalreadytoolate.

• Itispracticallyimpossibletopredict(all)negativeconsequencesoftheuseofpersonaldata.

• Evenifonecanforeseeafew,theyareveryabstract,distantanduncertain.

Page 28: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Example:ConsequencesforCollegeApplications

• Collegescurrentlyusesocialmediasitestorecruitnewstudents.

• OfthoseadmissionofficersthatvisitedapplicantsSNS,35%discoveredsomethingnegativeabouttheapplicant.

(Kaplan’sCollegeAdmissionsSurvey)

Page 29: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Example:ConsequencesintheJobHunting

• 93%ofrecruitersreviewacandidate’sonlinepresenceaspartofthescreeningprocess.

• 42%havereconsideredcandidatesbasedontheironlinepresence(bothnegativelyandpositively)

• Evenspellingandgrammaticalerrorsinfluencerecruitersnegatively(61%)

• Posts/Tweetsaboutvolunteeringandcharitydonationsinfluencerecruiterspositively(65%)

(Jobvite SocialRecruitingSurvey,2013)

Page 30: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Meanstoachieveprivacy

• Withdrawalfromsocietyactivities• Withphysicalorpsychologicalmeans,insolitudeorinasmallgroupofpeople

• Anonymity:theDarkWeb;disablecookies;IPhiding.

• Live“off-line”

Page 31: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

LessprivacyintheFuture

• Evenifanindividualmightknowintellectuallythattheusagemighthavenegativeconsequences,thisisnotgoingtochangebehaviorthatmuch.

• Oursearch-history,location-data,browsing-habits,reading-behaviorandmuchmore,iscollectedand/orusedtoadegreewecanbarelyimagine.

• Technology,nowadays,allowsforunprecedentedformsofdata-matching,de-anonimizationanddatamining,allcontributingtoextensive‘digitaldossiers’.

Page 32: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

II- PrivacyIssues

Page 33: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheEconomicsofPrivacy

• Companiescandeterminewhataddsyouseeonline,whatproductstorecommendyou,evenwhatarticlestoread,basedonyourpreviousbehavior.

• Companiesadopta“collectfirst,askquestionslater”policy.

• Somearesellingconsumer-specificdataforpurposesthatfallrightontheboundariesoftheFairCreditReportingActandotherlaws.

Page 34: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheEconomicsofPrivacy

• CampaignGrid(Republicans)andPrecisionNetwork(Democrats)havepoliticalinformationon150millionAmericanInternetusers,orroughly80percentofthenation'sregisteredvoters.

Page 35: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Maincausesofprivacyissues

• Datapublicallyavailable• Blurredornopersonalboundaries• Userhaslimitedcontroloverinformationdisseminationortransfer

• Foralongperiodoftime;forever?• Hardtoremoveaderogatorypostorcomment• Netetiquettedifferentfromfacetofaceetiquette• Newcasesnotconsideredbyexistinglaw

Page 36: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

InformationLeakageandLinkage

• Informationleakage happenswheneverasystemthatisdesignedtobeclosedtoan eavesdropper revealssomeinformationtounauthorizedpartiesnonetheless.

• Informationlinkage isjoiningtogetheroftwodatasetstoproduceonesingledataset.Inshortitispossibletouseinformationleakedfromsocialnetworkstosniffoutinformationprivatetotheuser,suchasemailaddresses,IDnumbers,etc.

• LinkagecannothappenwithoutLeakage.Somemeasureofleakageisunavoidable.

Page 37: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Identityinsocialnetworks

• True• Partiallyconcealed• Anonymous• 2nd life;alterego

Page 38: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

AppsandInformationLeakage

• Appswithinsocialnetworks(games,messengers,utilities,musicapps,etc.)areanimportantsourceofleakage.

• Peoplewillshareaddressbooks,phonenumbers,creditcardnumbers,etc.withapplicationsthathavelittleornosecurityandmayevenbemalicious.

• Thisbehaviouristhesameinphoneapps.

Page 39: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheInternetdoesnotforget.

• ‘RighttobeForgotten’:Therightofindividualstohavetheirdatanolongerprocessedanddeletedwhentheyarenolongerneededforlegitimatepurposes.

• The‘righttobeforgotten’clearlytakesaproprietaryapproachtoprivacyprotection.Itsscope,therefore,stronglydependsonaclearandconsistentdefinitionof‘personaldata’.

Page 40: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

CompromisedPrivacy:Findinguseridentity

• GenericSearches(Google,Yahoo,etc.)• Fromuserpublicprofile• Matchingdataacrosssites• Exploitphotosandvideotagsandgeo-tags.

Page 41: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SecurityThreatsofunsecuredaccess

• Hackers• Identitythieves• Governmentglobalknowledge

SecureList.comKapersky.com

Page 42: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Cookies

• CookiesareawayofstoringpersistentclientdatasothatasitecanmaintaininformationonauseracrossHTTPconnections(textfiles).

• Informationstoredrangesfrom– ShoppingCarts,– Forms,AddressesandPersonalinformation(usernamesandpasswords),

– Logininformation

• Mainculpritofinformationleakage.

Page 43: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Issuesbeyondsecurity

• Baduserbehavior(badlanguage,cyberbullying,anonymousthreats)

• Inabilitytocontrolsocialspheres• Blurredboundariesbetweenacquaintances,friends,relatives

• Theuserisresponsibleformanagingwhatisdisclosed,notanorganization

Page 44: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Furtherprivacyissuesevenwhenuserwillinglyagreestodisclosure

• Opendiscussionofpersonalinformationamongcontacts,

• Thepostingandtaggingofphotographsthatidentifyotherusers,

• Disclosureofdemographicdata,• Postingpersonalinformationonprofilepagesthatimplicatesotherusers

Page 45: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Whocandisclosedata?

• Personhimself/herself• Afriendorrelative• A3rd party

Page 46: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Socialaspects

SocialNetworksarearecentphenomenonandassuchtherearenoexisting,clearsocialconventionsabouttheiruse.Example:ignore“friend”requests.

Otherusersconsiderthenumberoffriendsasastatussymbol,effectivelycausingtheboundariesbetweenprivatelifeandprofessionallifetobecomeincreasinglyblurred.

Page 47: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SocialContextCollapse

• Socialnetworkcollapseistheflatteningoutofmultipledistinctaudiencesinone'ssocialnetwork.

• Peoplefromdifferentcontextsbecomepartofasingulargroupofmessagerecipients.Userscanquicklydiffuseinformationacrosstheirentirenetworkandfacilitateinteractionacrossdiversegroupsofindividualswhowouldotherwisebeunlikelytocommunicate.

Page 48: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

LegalCausePrivacyPoliciesandUsersRights

• Writteninvaguelegalese• Peopledonotreadthem• Networkexternalities,lock-inandthelackofvalidalternativesoftenforcepeopleintoconsenting.

Page 49: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

LegalIssuesRegulation

• Low:3rd worldcountries• Medium:US• High:Europe

Page 50: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Legalissuesboundaryblurred

• Personal• Business• Government

Personal

CommercialLegal

Page 51: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Commercialadvantage

• Targetedadvertising• Userprofiling

350 525775

1100

1700

2700

4400

0500

100015002000250030003500400045005000

2006 2007 2008 2009 2010 2011 2012

Spen

dinginM

illionsofD

ollars

Year

USSpendingsinOnlineTargetedAdvertising

Jansen, Bernard, et al. "To what degree can log data profile a web searcher?. "Proceedings of the American Society for Information Science and Technology46.1 (2009): 1-19.

Page 52: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Commercialadvantage:Facebook

• Sellingtargetedadvertising• Virtualcurrency(Facebookcredits)• Facebookappsandgamescollectinformationaboutyourhabitsandaboutyourfriends,withoutyourknowledgeorconsent.

Page 53: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheSituationinUSA

Thereiscurrentlynofederalonlineprivacylaw,whichmakesitessentiallyimpossibleforgovernmentagenciesliketheFederalTradeCommissiontogoafterInternetcompaniesunlesstheyviolatetheirownpublishedprivacypolicies.

Page 54: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheSituationinUSA

• TherearesomerulesinplacetodealwithPrivacyinregardstochildrenundertheageof13.

• TheChildren'sOnlinePrivacyProtectionAct(orCOPPA)waspassedin1998.

• AnewsetofruleswaspublishedbytheFTC(Dec2012)clarifyingwhatisorisn’tallowed.

Page 55: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

NewFTCRules

• Makeclearthatthe"personalinformation"thatcan'tbecollectedwithoutparentalconsentincludesgeo-locationinformation,photographs,andvideos

• Makeclearthatthirdparties(likeadvertisingnetworks)mustalsocomplywithCOPPA

• Closealoopholethatallowedkids'informationtobecollectedviaplug-inswithoutparentalnotice

• Clarifythat"persistentidentifiers"arealsoprotectedinformation,likeIPaddressesandmobiledeviceIDs

• Requirethatwebsitesaimedatkidshave"reasonableprocedures"fordataretentionanddeletion

Page 56: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

TheSituationinUSA(Cont)

• Legislationhasbeenproposedtoinclude“DoNotTrack”optionsonwebbrowsers.

• Thislegislationisnotpoliticallyviableduetooppositionfromthebusinesscommunity.

Page 57: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

III- ControllingPrivacy

Page 58: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

AutomaticallyCollectedComputerData

• IPaddress• Computername• Linkingdataacrossdifferentsites• Time,date• Location• Mechanism:Cookies

Page 59: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Informationcollectedwithcookies

• GeographicalLocation• Detaileddate/time• Computername,id• IPaddress,MAC• Loggedinusername• Otherwebpagesvisited• Formdata

Page 60: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

ComputerDataManuallyEntered

• Personalinformation• Comments• Photos,Video

Page 61: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Socialnetworks:usersanddata

• Parties– Socialnetworkoperators– Users– Applicationproviders

• Rolestomanagedata– Datacontroller– Dataprocessor– Dataprovider

Page 62: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Palliative:PrivacySettings

• Extensivesetsofprivacycontrolsdifferentlevelsofsociability

• Shieldcontentsharing• Potentialproblem:usersarenotabletoproperlyutilizetheprivacysettingsprovidedbySNSs• Controlsaredifficulttounderstandandmostusersjust

leavetherecommendedsettings(preferredbytheSSN)

Page 63: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Privacycontrol

• WhointhenetworkcanaccessinformationinyourpersonalFacebookprofile?

• CanyoufindtheminimumageforusingFacebook?

• HowcanyouchangeyourFacebooksettingstorestrictvisibilitytoyourprofile?

• HowcanyouchangeyourFacebooksettingssothatyouarealertedwhenyouaretaggedinaphoto?

Page 64: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Controllingaccesstodata

• Limited• Site-dependent• Difficulttounderstandlegallanguage• Impossibletoknowifotherpersondisclosesdata

• Transferrable

Page 65: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Dilemma

• Ineithercasebelow,theconsequenceisundesirable:– ifprivacyisprotected,thensociabilityandcontentsharingwillbecompromised,

– whereasifsociabilityandcontentsharingarepromoted,thenprivacywillsuffer.

PrivacySociability

Page 66: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Implications

• Increasedsocialutilityandagrowingsocialdiversityoftheuserpopulation,whichhelpuserstobereadilyavailableandvisibletoalotofpeople:“allfriendsinone-placesolution.”

• SNSprofilesmixfriends,family,co-workers,andbusinesscontacts

• Nosimpleandadequatewaytoseparatethemandkeepsomepartsoftheinformationprivate

Page 67: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”
Page 68: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

ComparisonoftheYoungerAdultSampleandtheOlderAdultSampleinRegardtoSocialPractices

YoungAdult• UsesSNSforshortperiodsof

time,butmanytimesaday• Mainlycontactswithfriends

thattheyseeeveryday• UsesSNSforcoordinationwith

friends,flirtingandphotosharing

• Usuallysharelargeamountsofphotosandvideosfromsocialgatherings

• Infrequentstatusupdates

OlderAdult• UsesSNSforfewerlonger

sessions• Mainlycontactwithfamilyand

oldfriendsthatarenotseenoften

• Usesthemforgettingintouchwitholdfriends,nostalgia

• Sharesphotoslessoften(rarelyvideos)mainlyofvacations

• Frequentstatusupdates

Page 69: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

ComparisonoftheYoungerAdultSampleandtheOlderAdultSampleinRegardtoPrivacy

YoungAdult• Confidentintheusageand

knowledgeofprivacycontrols

• Thinksotherpeoplearemorelikelytohaveproblemswithprivacy

• Concernedaboutprivacyinthecontextofjobhunting.NotconcernedwiththeuseofinformationbytheSNS

OlderAdult• Lessconfident.Usuallyask

forhelpfromtheyoungeradultsinthehousehold

• Manyprivacyconcerns,inparticularregardingtheyoungergenerations

• Concernedbutlessawareofprivacyissue.MaythinkthatburglarsmightuseSNStocasetheirhomes,forinstance

Page 70: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

LowestCommonDenominatorStrategy

• Individualsforwhomamessageisnotintendedbutwouldreceivethemessagenonetheless.

• Erronthesideofcaution:Ifanyoftheseindividualswouldfindthemessageproblematic,itshouldnotbeposted.

Page 71: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

PrivacyPreservationCosts

• Requiredfromtheuserinordertomakeuseofthesite'sprivacyfeatures:– Timerequiredtounderstandandoperatethemyriadofdifferentusersettings.

– Knowledgeoftheintricaciesoftheparticularsocialnetwork.

– Thetimeandknowledgeinvestedinonenetworkisnottransferrabletoanother.

Page 72: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Limitationprinciple

• Confiningdataprocessingtoapreviouslydefinedscope:mightseemtorestricttheamountofpotentialharmintheory.

• Butinanever-increasingpersonalizedweb(whereeverypieceofpersonaldatacanbeconsideredas‘useful’),thevalueofthisprinciplehasbecomequestionabletoo.

Page 73: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Settings

• Usersmaynotbewell-versedinprivacysettingsorunwillingtotakethetimetochangesettings.

• Distributingcontenttoone'sentirenetworkappearstocarryalowercostintermsoftime,knowledge,andskills.However,suchstrategiesmaynegativelyimpactrelationshipsonthesite,especiallyifthemajorityofpostsarerelevanttoaminorityofFriends.

• Whileindividualschoosingalowestcommondenominatorapproachmayavoidalienatingfriendswithirrelevantcontent,theymayalsomissthebenefitsderivedfrominteractionswithallmembersoftheirnetworks.

Page 74: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Additionalautomatedsourcesofinformation

• Recognition– face– voice

• “sway”userintotagging

Page 75: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Concern:StatusPublicChannels

• Statusupdatesprovidethequickestmethodthroughwhichonecandistributemessagestoawideaudience

• ItmaybemorelikelytobeusedevenwhenthemessageisonlyrelevanttoasubsetofFriends.

Page 76: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

ControlDataTransfer

• Request‘personaldata’tobedeletedononesite

• Deletionmayimplyjusthidingdata;notshreddingit

• Meanwhiletheinformationmighthavebeencopiedand/or‘anonymized’already.

Page 77: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Solutionstocontroldatasharingandtransfer

• awareness-raising,• transparency,• clearerprivacynotices,• data-minimization,• strictercontrolonthepurposelimitationprinciple,‘anonymisation’,

• transparency,• encryption,

Page 78: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Anonymization• Majorlineofdefense.• Therightdoesnotofferany

solution.• Individualsmaybe

profiled/targetedextensivelyandtheirdatamight(in)directlybeusedforcomprehensivedata-mining,

• Theindividualcannothavea‘righttobeforgotten’withregardtothisinformation.

• AnExtremeExample:TheTorNetwork:TheDeepWeb.

Page 79: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

AnonymizationSolutions:Catch22

• Anonymizationmeasuresprevent(potentiallyharmful)informationtobeshared

• But,inanever-increasingsocialInternet,manyfeaturesdependondisclosingpersonaldata.

Page 80: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Examples:PrivacyControlFeatures

• Facebook• Twitter• Snapchat• Foursquare

Page 81: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Facebook

• Overwhelming• 5groups• Finegrained• Constantlychanging• Pre-definedoptions:Friends,Public,Custom• Learningcurve

Page 82: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”
Page 83: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”
Page 84: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Twitter

• Theprivacysettingsarebasic• MuchsimplerthanFB.• Profilescanbepublicorprivate.• YourBio,nameandTwitterhandlealwaysvisible

• Emailaddressisprivate• Guardsagainstidentitytheft

Page 85: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Snapchat

Snapchat isa photomessagingapplication.Usingtheapp,userscantakephotos,recordvideos,addtextanddrawings,andsendthemtoacontrolledlistofrecipients.Thesesentphotographsandvideosareknownas"Snaps".UserssetatimelimitforhowlongrecipientscanviewtheirSnaps(asofDecember2013,therangeisfrom1to10seconds), afterwhichtheywillbehiddenfromtherecipient'sdeviceandkeptonSnapchat'sserversforever

Page 86: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Snapchat

• Snapchat hastwoprivacysettings,oneforwhocansendyouSnapsandanotherforwhocanseeyourStories.Bothhavetwooptions"Everyone"and"MyFriends."

• Bydefault,onlyusersyouaddtoyourfriendslistcansendyouSnaps.IfaSnapchatter youhaven'taddedasafriendtriestosendyouaSnap,you'llreceiveanotificationthattheyaddedyou,butyouwillnotreceivetheSnaptheysentunlessyouaddthemtoyourfriendslist.

• UsernamesandpersonalphonenumbersofmillionsofusershavebeenstolenandpostedonlinethroughawebsiteentitledSnapchatDB.

Page 87: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Foursquare

Therearecertaindatathatwillalwaysbepublic.Thisincludesyourname,yourhometown(i.e.“location”inyourprofile),yourbio,yourprofilepictureandotherpublicphotos,yourlikes,yourtips,yourlists,andyourfriends.Theonlywaytohidethisinfoistoeithernotincludeit,ortochangeitsoitdoesn’tactuallyrevealanypersonalinformationaboutyou.Ifyoudon’t,thisinformationcaneasilybefoundthroughasimpleGoogle searchforyourname,orotheronlineoutlets.

Page 88: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Your“OnlineBrand”

• Inbusinessterms,abrandcomprisesallofthethingsthatmakeupacompany’sidentitytocustomers,fromitscorporatelogotothenamesforitsproducts.Becauseastrongbrandissoimportanttoacompany’sreputationandsuccess,executivestakegreatpainstoprotecttheirbrand

• Withhigh-poweredsearchengineslikeGoogleandBing,findinginformationaboutapotentialjobapplicant,businesspartner,ordate,iseasierthanever.Byapplyingtheprinciplesofbusinessbrandingandonlinereputationmanagementtoyourself,youcanmakesurethatyournamelooksgoodinsearchresults.

Page 89: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

IV- StrategiesforSafeSharingTipsandadvice

Page 90: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Howtoprotectyour“OnlineBrand”

• Takechargeofyour“onlinereputation”– FindoutwhatisontheInternetaboutyou

• Usesearchengines• Searchblogsandsocialnetworks

– Evaluateyouronlinereputation• Doestheinformationaboutyoureflecthowyouwantotherstoperceiveyou?

– Protectyouronlinereputation• Thinkbeforeyoushare• Treatothersasyouwouldliketobetreated• StayvigilantaboutwhattheInternetissayingaboutyou

Page 91: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

RestoreyourOnlineReputation

• Ifyoufindinformationaboutyourselfthatdoesnotfitthereputationyouwant,actquickly.Thelongeritstayspublic,thegreaterthechancethatitwillbespreadorarchived.

• Inarespectfulway,askthepersonwhopostedittoremoveitorcorrectanerror.Ifitisacorrection,askhimorhertoincludeanotice(CORRECTIONorUPDATED)rightnexttotheoriginal(incorrect)material.

• Ifthepersondoesnotrespondorrefusestohelp,askthewebsiteadministratortoremovethedigitaldamage.

• Ifyoufeelapubliccorrectionisnecessary,presentyourcasesimplyandpolitelywithoutattackingtheperson.

(http://www.microsoft.com/security/online-privacy/reputation.aspx)

Page 92: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SaferOnlineSocializing

• Setyourboundaries:– Thinkcarefullyabouthowpublicyouwantyourprofileorblogtobe

– Evaluatethesocialsitebeforeyouuseit

• Beselectiveaboutfriends:– Thinktwiceaboutwhoyouacceptasafriend– Periodicallyreassesswhohasaccess– Reviewwhatyourfriendswriteaboutyou

Page 93: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SaferOnlineSocializing

• Thinkbeforeyoupost– Chooseausernamethatdoesn’tattractunwantedattentionorhelpsomeonefindyou

– Donotovershare– Treatothersasyouwouldliketobetreated– Thinkaboutthefutureofyourinformationontheweb

• Defendyourcomputeragainstonlinethreats– Bewaryaboutclickinglinks– Buildupyourcomputer’sdefencesandkeepthemuptodate

– Becarefulaboutinstallingadd-onapps

Page 94: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SaferOnlineSocializing

• ReportIssues:Noonehastherighttothreatenorupsetyou.Report:

– AnynegativeincidentstotheWebservice,includingcontentthatexploitsminors,obsceneorhatefulmaterial,inappropriatebehaviour,ortheftofyouraccount.

– Continuedharassmentorphysicalthreatstolocallawenforcement.– IdentitythefttotheU.S.FederalTradeCommission(FTC)at

ftc.gov/idtheft orcalltollfree:(877)438-4338.– ScamsorfraudtotheFTC.Gotoftc.gov/bcp/consumer.shtm andclick

FileaComplaint,orcalltollfree:(877)382-4357.(http://go.microsoft.com/?linkid=9708812)

Page 95: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SocialNetworksandGaming

• Socialgamingnetworksareaproofofthat:– Socialnetworksfosteredbythegamingcompanies:XboxLive,PlaystationNetwork,NintendoNetwork,etc.

– Socialnetworksmaintainedbyusers:Raptr,Playfire,Duxter,etc.

Page 96: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

SafeGaming

• Educateyourselfandyourkidsabouttherisks:– Kidsplayalone,withothersintheroom,oronline.Theyplayagainstthegameitselforanotherperson,withateamofseveralplayers,oringameswhichmayhavehundredsofthousandsplayingatanyonetime.

– Thebadmaydownloadwiththegood:some“free”gamesrequireextensiveprofiles,thenillegallysellyourdata.

– Onlinebullying:Somegamersplaysimplytoharassandtauntotherplayers.

– Badpeoplemaybefriendkids,andthroughthesesocialgamingsitesobtainpersonalinformationthatmightleadtoharm.

Page 97: Privacy in Social Networks - GitHub Pages · •Social networks can be accessed by a large number of different devices. •Laptop and desktop computers give access to better “views”

Conclusions

• Privacynolongerviable• Companieshungryfordata• Weshouldbecomeawareofprivacyissues• Goal:safety+privacy,preserving“personalbrand”