Categories
Links

Canada asks app stores to mandate privacy policies

Canada asks app stores to mandate privacy policies:

“Developers are asking for information they have no real business accessing,” said Christopher Parsons, a post-doctoral fellow at the University of Toronto’s Citizen Lab. “If a flashlight app is asking to read your SMS messages, that’s a step too far.”

According to Parsons, many app developers participate in a “grey market” of personal information.

“The value is not in selling apps,” he said. “The value is in collecting information about individuals and then turning around and selling it to third parties.”

Requiring developers to include privacy plans alongside their apps “is a step in the right direction,” Parsons said, but many policies are written in “boilerplate legalese,” meaning even if they’re available, many consumers won’t be able to interpret them.

“What commissioners could do is say that if you’re going to develop a privacy policy… you should be providing a simple, accessible version of what you’re doing,” he said.

However, making privacy policies mandatory could allow agencies like the privacy commissioner’s office to better target companies who violate their own terms of service.

“What it means is that when and if a company says something in its privacy policy that’s not true, there’s an actionable legal case against them,” Parsons said.

Categories
Links

Social Media Privacy – Part I

Social Media Privacy – Part I:

One in three anglophone Canadians say that not a single day goes by without checking into their social media feeds. Use of such applications has increased. On top of that, there is growing concern over how much information is being shared online and who may have access to it. Has the government been doing enough to protect Canadians? Is the social media industry being proactive or reactive? Will government institutions such as CSIS and CSES increase their monitoring of users in light of recent events? We will explore the current situation, what the future holds and what social media users can do to protect their information.

This week’s expert guests are:

  • Christopher Parsons, Postdoctoral Fellow at the Citizen Lab in the Munk School of Global Affairs at the University of Toronto and a Principal at Block G Privacy and Security Consulting
  • Avner Levin, Director of the Privacy and Cyber Crime Institute at Ryerson University, Associate Professor at the Ted Rogers School of Management, and Chair of the Law & Business Department
  • Sharon Polsky, President of the Privacy and Access Council of Canada

 

Categories
Links

Cyber-security in 2014: What we learned from the Heartbleed bug

Cyber-security in 2014: What we learned from the Heartbleed bug:

Parsons warned that the fallout from Heartbleed may not be over for web users.

We still don’t know just how much information was stolen or accessed as a result of the bug. Stolen login credentials and user information is likely to be leaked by hackers, putting users at risk for additional hacks.

The problem is hackers could leak this information at any time.

“If logins and passwords were successfully extracted – and I’m willing to say 99.9 per cent of people haven’t changed all of their passwords – people still could be affected,” he said.

“Always expect at some point, possibly through no fault of your own, you will be compromised,” Parsons warned.

“Then think, ‘What would I do if my personal information was leaked?’ Thinking before these things happen can help you come up with a recovery strategy.”

 

Categories
Links

Should you worry about social media surveillance?

Should you worry about social media surveillance?

 

Categories
Links

Is Uber’s rider database a sitting duck for hackers?

Is Uber’s rider database a sitting duck for hackers?:

Imagine for a second that your job is to gather intelligence on government officials in Washington, or financiers in London, or entrepreneurs in San Francisco. Imagine further that there existed a database that collected daily travel information on such people with GPS-quality precision– where they went, when they went there and who else went to those same places at the same times.

Now add that all this location data was not held by a battle-hardened company with tons of lawyers and security experts, such as Google. Instead, this data was held by a start-up that was growing with viral exuberance – and with so few privacy protections that it created a “God View” to display the movements of riders in real-time and at least once projected such information on a screen for entertainment at a company party.

“It’s a huge trove of data that could be used for a whole number of uses,” said Christopher Parsons, a digital privacy expert at Citizen Lab, a research center at the University of Toronto.

 

Categories
Links Writing

FFS SSL

FFS SSL:

I just set up SSLTLS on my web site. Everything can be had via https://wingolog.org/, and things appear to work. However the process of transitioning even a simple web site to SSL is so clownshoes bad that it’s amazing anyone ever does it. So here’s an incomplete list of things that can go wrong when you set up TLS on a web site.

Now you start to add secure features to your web app, safe with the idea you have SSL. But better not forget to mark your cookies as secure, otherwise they could be leaked in the clear, and better not forget that your website might also be served over HTTP. And better check up on when your cert expires, and better have a plan for embedded browsers that don’t have useful feedback to the user about certificate status, and what about your CA’s audit trail, and better stay on top of the new developments in security! Did you read it? Did you read it? Did you read it?

It’s a wonder anything works. Indeed I wonder if anything does.

Without any doubt this is one of the better(?) rants about SSL/TLS that I’ve read recently. And given my own recent experiences in setting up SSL/TLS on another site I entirely empathize: it was a horrible experience that involved tracking down what was causing things to break, when they were breaking, and how to remedy them. It was a non-trivial learning experience and that was a very simple site. Large sites….well, I shudder to consider the work entailed in securing them.

(As a sidenote: yes, SSL/TLS is broken. But it adds friction to mass surveillance processes and at little cost to the visitor of websites/users of web services. It’s a pain for those delivering content, but that’s a pain that it’s arguably appropriate for those content providers to bear.)

Categories
Aside Links

Christopher Parsons weighs in on privacy concerns in Canada

A roundup of what I’ve said, to whom, and that was published this month.

Christopher Parsons weighs in on privacy concerns in Canada

Categories
Links

Caught on Camera?

Caught on Camera?:

According to Christopher Parsons, a post-doctoral fellow and the managing director of the telecommunications transparency project at the University of Toronto’s Citizen Lab, the broadest applications to date [of facial recognition technologies] involve tranches of official photos maintained by government agencies that issue identification documents, such as passports and driver’s licenses.

In recent years, he adds, facial recognition software has become substantially more sophisticated. The advent of so-called 3-D recognition techniques allows the software to make matches between official posed photos and informal, un-posed ones—e.g., images posted on social media sites. What’s more, these biometric algorithms, which can “learn” to recognize faces based on composites developed from multiple images, are no longer restricted to government security. Facebook has a facial recognition app, and at least two developers have built apps for Google Glass that purport to be able to run facial images through picture databases from dating sites or sex offender registries, Forbes reported earlier this year.

To date, this kind of cross-referencing hasn’t produced great results, says Parsons, although he adds that the latest generation “is better than it used to be.”

And in Canada? Police in Vancouver successfully used facial recognition technology to identify looters during the Stanley Cup riot in 2011, drawing from videos submitted by bystanders as well as CCTV images. The technology was also deployed during the G8/G20 in Toronto. But Parsons points out that at date, there’s not enough data on general law enforcement applications to determine whether this sort of facial recognition is effective.

 

Categories
Links

Alberta Primetime – Increased surveillance powers in Canada

Alberta Primetime – Increased surveillance powers in Canada:

 

Categories
Links

Uber’s ‘God View’ Was Once Available to Drivers

Uber’s ‘God View’ Was Once Available to Drivers:

I reached out to Chris Parsons, a cybersurveillance researcher at the University of Toronto’s Citizen Lab, to discuss Uber’s God View and the ramifications for users.

“Uber understandably has infrastructure in place to monitor where its drivers are and a business case can be made for some degree of monitoring of how, and how often, their clients use the service,“ he said. “However, such data must be carefully controlled with strict security, privacy, and access safeguards. At this point it doesn’t appear that such have been stringently developed or applied.”

“We know that national security and intelligence agencies are deeply interested in where people travel to, and in understanding the movement patterns of individuals regardless of their being identified as ‘targets’ of government surveillance,” Parsons continued. “And Uber’s seeming failure to secure its data—to the point where developers have already found ways of querying the data by reverse-engineering Uber’s mobile client software—would suggest that an intelligence or security service that was sufficiently motivated could do the same.”

“There’s no evidence that such a security or intelligence service has ‘cracked’ Uber but past Snowden revelations have revealed that the NSA and its partners are voracious collectors of all kinds of tracking data,” Parsons concluded. “There’s no reason why these agencies wouldn’t be as interested in Uber’s data as other services’ data that could identify where, and how often, people travel around their cities and around the world.”