e dot dot dot
a mostly about the Internet blog by

August 2017
Sun Mon Tue Wed Thu Fri Sat
   
   


Once Again With Feeling: 'Anonymized' Data Isn't Really Anonymous

Furnished content.


For years, the companies that hoover up your internet browsing and other data have proclaimed that you don't really have anything to worry about, because the data collected on you is "anonymized." In other words, because the data collected about you is assigned a random number and not your name, you should be entirely comfortable with everything from your car to your smart toaster hoovering up your daily habits and selling them to the highest bidder. But studies have repeatedly shown that it only takes a few additional contextual clues to flesh out individual identities. So in an era of cellular location, GPS, and even smart electricity data collection, it doesn't take much work to build a pretty reliable profile on who you are and what you've been up to.The latest case in point: German journalist Svea Eckert and data scientist Andreas Dewes recently descended upon Defcon to once again make this point, releasing a new report highlighting how "anonymous" browsing data is anything but. The duo found it relatively trivial to obtain clickstream browsing data from numerous companies simply by posing as a fake marketing company, replete with a website filled with many nice pictures and some marketing buzzwords." Ironically, some of this data was gleaned from companies that profess to offer you additional layers of privacy, including safe surfing tool Web of Trust.It didn't take long before the pair was able to obtain a database containing more than 3 billion URLs from roughly three million German internet users, spread across roughly 9 million different websites. However easy obtaining the "private" and "anonymous" browsing data was, using this data to quickly and easily identify individual users was even easier:

"Dewes described some methods by which a canny broker can find an individual in the noise, just from a long list of URLs and timestamps. Some make things very easy: for instance, anyone who visits their own analytics page on Twitter ends up with a URL in their browsing record which contains their Twitter username, and is only visible to them. Find that URL, and you've linked the anonymous data to an actual person. A similar trick works for German social networking site Xing."
The pair also highlighted how repetitive visitation of websites specific to you (your bank, your hobbies, your neighborhood) help further narrow down your identity:
"For other users, a more probabilistic approach can deanonymise them. For instance, a mere 10 URLs can be enough to uniquely identify someone - just think, for instance, of how few people there are at your company, with your bank, your hobby, your preferred newspaper and your mobile phone provider. By creating fingerprints from the data, it's possible to compare it to other, more public, sources of what URLs people have visited, such as social media accounts, or public YouTube playlists."
Of course this is nothing new, and researchers have been making this precise point for several years now. Princeton researcher Arvind Narayanan in particular has been warning that anonymous data isn't really anonymous for the better part of the last decade, yet somehow the message never seems to resonate, and everyone from broadband providers to internet of things companies continue to pretend that "anonymization" of data is some kind of impenetrable, mystical firewall preventing companies or hackers from identifying you.

Permalink | Comments | Email This Story


Read more here

posted at: 12:00am on 05-Aug-2017
path: /Policy | permalink | edit (requires password)

0 comments, click here to add the first



Jeff Sessions Suggests He's Steering The DOJ Towards Prosecuting More Journalists

Furnished content.


Jeff Sessions and the DOJ are back to threatening leakers again. It seems counterproductive, considering each new threat of leak investigations does little to stem the steady flow of leaks. But the new DOJ boss seems ready to go further than his predecessors.Having already expressed an interest in taking care of Obama's unfinished business by going after Wikileaks, Sessions now appears to be headed towards threatening journalism and the First Amendment itself. This would be a new direction for the Justice Department. A 2013 report by the DOJ stated it was unwilling to consider the punishment of journalists during leak investigations, except as a last resort.

As an initial matter, it bears emphasis that it has been and remains the Department's policy that members of the news media will not be subject to prosecution based solely on newsgathering activities. Furthermore, in light of the importance of the constitutionally protected newsgathering process, the Department views the use of tools to seek evidence from or involving the news media as an extraordinary measure.
Journalists have been subpoenaed before in leak investigations, but the DOJ has generally been unwilling to jail journalists for refusing to hand over information on their sources. Jeff Sessions, however, seems less concerned about using the weight of the law against members of the press.In his written remarks before a press briefing on national security leaks, Sessions said this:
I have listened to career investigators and prosecutors about how to most successfully investigate and prosecute these matters. At their suggestion, one of the things we are doing is reviewing policies affecting media subpoenas. We respect the important role that the press plays and will give them respect, but it is not unlimited. They cannot place lives at risk with impunity. We must balance their role with protecting our national security and the lives of those who serve in our intelligence community, the armed forces, and all law abiding Americans.
This strongly suggests the 2013 guidelines on "new media" will be rewritten by Sessions' DOJ to justify increased prosecutions of journalists. This is a dangerous step forward, especially in an era where leaks seem to be coming faster than journalists can publish them. Throwing a few journalists in jail for contempt creates a severe chilling effect. Even the enhanced threat of prosecution may be enough to discourage journalists from publishing leaked docs or working with government sources.Sessions was asked directly if this administration would prosecute journalists. He refused to answer the question before ending the briefing. This would be the second time Sessions has dodged this question -- the first being Sen. Klobluchar's question along the same lines during his confirmation hearing. What better way to send a chilling message to journalists then telling them their freedom might be at stake as they attend a press briefing.

Permalink | Comments | Email This Story


Read more here

posted at: 12:00am on 05-Aug-2017
path: /Policy | permalink | edit (requires password)

0 comments, click here to add the first



August 2017
Sun Mon Tue Wed Thu Fri Sat
   
   







RSS (site)  RSS (path)

ATOM (site)  ATOM (path)

Categories
 - blog home

 - Announcements  (0)
 - Annoyances  (0)
 - Career_Advice  (0)
 - Domains  (0)
 - Downloads  (3)
 - Ecommerce  (0)
 - Fitness  (0)
 - Home_and_Garden  (0)
     - Cooking  (0)
     - Tools  (0)
 - Humor  (0)
 - Notices  (0)
 - Observations  (1)
 - Oddities  (2)
 - Online_Marketing  (0)
     - Affiliates  (1)
     - Merchants  (1)
 - Policy  (3743)
 - Programming  (0)
     - Bookmarklets  (1)
     - Browsers  (1)
     - DHTML  (0)
     - Javascript  (3)
     - PHP  (0)
     - PayPal  (1)
     - Perl  (37)
          - blosxom  (0)
     - Unidata_Universe  (22)
 - Random_Advice  (1)
 - Reading  (0)
     - Books  (0)
     - Ebooks  (0)
     - Magazines  (0)
     - Online_Articles  (5)
 - Resume_or_CV  (1)
 - Reviews  (2)
 - Rhode_Island_USA  (0)
     - Providence  (1)
 - Shop  (0)
 - Sports  (0)
     - Football  (0)
          - Cowboys  (0)
          - Patriots  (0)
     - Futbol  (0)
          - The_Rest  (0)
          - USA  (0)
 - Technology  (1167)
 - Windows  (1)
 - Woodworking  (0)


Archives
 -2024  April  (103)
 -2024  March  (179)
 -2024  February  (168)
 -2024  January  (146)
 -2023  December  (140)
 -2023  November  (174)
 -2023  October  (156)
 -2023  September  (161)
 -2023  August  (49)
 -2023  July  (40)
 -2023  June  (44)
 -2023  May  (45)
 -2023  April  (45)
 -2023  March  (53)


My Sites

 - Millennium3Publishing.com

 - SponsorWorks.net

 - ListBug.com

 - TextEx.net

 - FindAdsHere.com

 - VisitLater.com