Comments to the NTIA on Drones

On April 20, 2015, the Future of Privacy Forum submitted comments to the NTIA on unmanned aircraft systems or “drones.” FPF’s comments emphasize the need for further accountability and transparency measures in deploying commercial drones.

You can read our full comments here.

Quick Security Tips for Vendors

As part of our on-going support to vendors, especially start-ups and small business providers in the ed tech market, we have recently published our “Quick Security Tips for Vendors” on FERPA|Sherpa.  This tool, a companion to our “Quick Privacy Tips for Vendors,” is designed to provide a simple baseline of security principles and practices as an ed tech business grows its products and services.  Of course, this list of tips does not constitute a complete security policy, but if followed, it will ensure that vendors have taken the best, first steps toward responsible protection of student data, as these tips flag many of the common key concerns. A company that implements student data privacy and security policies and procedures in compliance with these 2 checklists will have a strong foundation moving forward.

Peter Swire on Encryption and Mandated Access

Senate Committee on the Judiciary

Questions for the Record from Senator Grassley

To: Peter Swire

Huang Professor of Law and Ethics

Scheller College of Business

Georgia Institute of Technology

  1. Global Competitiveness

In my opening statement, one of the concerns I expressed was that, in considering solutions to the “Going Dark” problem, we carefully consider the impact on the global competitiveness of American technology companies. You testified that if U.S. companies were required to give U.S. law enforcement access to encrypted communications and devices, U.S. companies find themselves at a disadvantage in the global marketplace. Yet it appears that countries like the United Kingdom, France and China are considering laws that would move in this direction.

  1. Do you agree that these foreign governments may be moving in this direction? If so, how would the global competitiveness of U.S. companies be damaged if foreign governments mandate the same sort of access?

 

Swire: I agree that other countries have been considering laws concerning mandated access. My view is that the position of the United States government is highly relevant to the likelihood of other countries adopting such laws, especially for close allies such as the United Kingdom and France. If the United States were to mandate access legally, which I hope it will not, my view is that the U.S. decision would substantially increase the likelihood of such laws being enacted by our allies. By contrast, if the United States maintains the status quo of no such mandates, then that fact becomes an important and relevant precedent against enactment of such measures by our allies.

I believe the U.S. position would also have a large impact on other countries around the world, especially for authoritarian or dictatorial regimes that would like to use mandated access to clamp down on political dissent, religious activity, and other activities. If the U.S. resists mandates, then the U.S. based technology companies have a much greater ability to resist demands for mandated access in such countries. Being able to resist such demands will protect devices and sensitive data of Americans and American businesses in those countries. By contrast, if the U.S. requires access, then it will be much for difficult for U.S. based technology companies to push back against requests from China or other foreign governments.

My initial point, therefore, is that the U.S. actions in this area have a very important impact on whether other countries adopt mandated access. As I stated during the hearing, I also believe that mandates in the U.S. would harm U.S. based technology companies because of the suspicion around the world that their products and services are not secure and information is shared with U.S. government agencies.

In terms of mandates in another country, such as a U.S. ally, there would be multiple effects and the overall outcome depends on the circumstances. For instance, if a small market country mandates access, then that might aid local companies that comply with the local law while U.S. companies may decide not to take the reputational risk of doing business in that jurisdiction. In that event, U.S. companies might lose access to a small market but face less competition from companies based in there in other markets. If the country is seen globally as having a weak human rights record, mandated access may push the U.S. companies, consistent with the Global Network Initiative principles, not to continue doing business there, thus losing market access. Such company decisions to eschew a market, however, may send a strong signal globally about the importance of customer security to the U.S. based companies, with offsetting gains in other markets.

In addition, there is a crucial dynamic aspect to such mandates. The small country, or country with weak human rights, might find the consequences negative if they lose access to cutting edge technology from U.S. based companies. They thus might reconsider their decision to mandate access, in order to bring U.S. based companies back into the jurisdiction. In such an event, a clear U.S. policy of not requiring access is crucial – the good long-term outcome of U.S. company participation and no mandates occurs only if the U.S. retains its policy where no mandates are imposed.

Congrats to National Student Clearinghouse!

Exciting news to share from today’s press release from iKeepSafe.  We extend our congratulations to FPF Advisory Board Member National Student Clearinghouse for this recognition.

National Student Clearinghouse’s program: StudentTracker for High Schools

Earns iKeepSafe FERPA Badge

July 22, 2015 – iKeepSafe.org, a leading digital safety and privacy nonprofit, announced today that it has awarded its first privacy protection badge to StudentTrackerSM for High Schools from the National Student Clearinghouse, the largest provider of electronic student record exchanges in the U.S. Its selection as the first recipient of the new badge reflects the ongoing efforts of the Clearinghouse, which performs more than one billion secure electronic student data transactions each year, to protect student data privacy.

A nonprofit organization founded by the higher education community in 1993, the Clearinghouse provides educational reporting, verification, and research services to more than 3,600 colleges and universities and more than 9,000 high schools. Its services are also used by school districts and state education offices nationwide.

Earlier this year, iKeepSafe launched the first independent assessment program for the Family Educational Rights and Privacy Act (FERPA) to help educators and parents identify edtech services and tools that protect student data privacy.

“The National Student Clearinghouse is as committed to K12 learners as we are to those pursuing postsecondary education, and that also means we’re committed to protecting their data and educational records,” said Ricardo Torres, President and CEO of the Clearinghouse. “So many aspects of education are moving into the digital realm, and we’re focused on providing students with the privacy and protection they deserve in a rapidly changing digital environment.”

The Clearinghouse became the first organization to receive the iKeepSafe FERPA badge by completing a rigorous assessment of its StudentTrackerSM for High Schools product, privacy policy and practices. “As the first company to earn the iKeepSafe FERPA badge, the National Student Clearinghouse has demonstrated its dedication to K12 students and their families, and to the privacy and security of their data,” said iKeepSafe CEO Marsali Hancock.

Products participating in the iKeepSafe FERPA assessment must undergo annual re-evaluation to continue displaying the iKeepSafe FERPA badge. For the evaluation, an independent privacy expert reviewed the StudentTrackerSM for High Schools product, its privacy policy and practices, as well as its data security practices.

For more information, please visit http://ikeepsafe.org/educational-issues/clearinghouses/

Tackling Privacy, One Carnegie Mellon Project at a Time

CMU Event

CMU Privacy Researchers Norman Sadeh, Lorrie Cranor, Lujo Bauer, Travis Breaux, and Jason Hong (l-r). Photo by JC Cannon.

Last Thursday, the Future of Privacy Forum hosted a conversation among five of CMU’s leading privacy researchers. While the panelists discussed a number of their leading privacy projects, I wanted to highlight some of the interesting takeaways I took from the presentation.

Many of the researchers focused on how subtle nudges can be used to change people’s behaviors. While this is frequently done to encourage users to share more data, the CMU researchers expressed in interest in exploring how nudges can be “used for good.” Discussing efforts by hotels to get patrons to reuse wash towels, Jason Hong explained how subtle changes in wording reminders — from “please recycle” to “75% of guests in this room” — could have significant impacts on patron recycling behaviors.

Lujo Bauer explained how these sorts of nudges could be applied to password composition meters. Increasingly, online services detail password requirements to users and show either colored bars or outright classify a user’s proposed password as “weak” or “strong.” According to Bauer, people typically do not try very hard to get to the point where a meter tells them the password is excellent, but “they will avoid it if a meter tells them their password sucks.” His takeaway: when it comes to security measures, avoid giving users too much positive feedback.

Bauer lamented that the online ecosystem is forcing users to engage in insecure behaviors. Of course, while nudges could be used to reinforce positive behaviors, it begs the question what is defined as “positive” behavior. When it comes to security issues like passwords, promoting better security may be a no brainer, but things are much less binary when it comes to privacy. Privacy-protective nudges can push towards privacy paternalism, which may be no more ethical than the alternative.

Travis Breaux highlighted the continuing challenge of communicating privacy policy into engineering objectives. He noted that many mobile app developers still do not understand the privacy implications that can come with connecting their apps through outside services and social networks, which calls for the need to further detail the entire data supply chain. Breaux explored the potential behind establishing rich data collection/use descriptions that could be more detailed and useful than generic privacy policies, and describing a case study involving applications on Facebook, explained how these sorts of tools could help developers understand more accurately how they are collecting, using, and repurposing information.

Lorrie Cranor discussed the difficulties with communicating data use in the Internet of Things whether through visual, auditory, or haptic channels, or make information “machine readable (if you remember P3P and DNT).” She also highlighted one study that looked at the timing dimension of providing users with notice.  A student developed a simple history quiz app that displayed a privacy notices in different places: (1) in the app store, (2) as soon as the app was opening, (3) in the middle of the history quiz, (4) at the quiz’s end or (5) never at all. “We invited people to take our quiz, but didn’t tell them it was about privacy,” she explained.

When users where then asked about the contents of that privacy notice, the study found that people who “saw” the policy in the app store could not recall it any better than people who did not see it at all. According to Cranor, at the time a user is downloading an app, they are not paying attention to other information in the app store. This “doesn’t suggest you don’t put that info in the app store . . . but suggests that sort of timing may not be sufficient. Also suggests it’s really important to test these things.”

Norman Sadeh further criticized the state of our overly-complicated privacy policies. “It’s not the case that every single sentence in a privacy policy matters,” he stated, discussing his effort to try to extract the key points of interest to users from privacy policies.

Last but not least, the group described its Bank Privacy Project. The researchers described how larger banks tend to collect more information and use it for more purposes, while smaller banks do the exact opposite. “If you don’t want your bank sharing,” Cranor explained, “you need to find a bank you’ve never heard of.” Because this is nigh-impossible for an average consumer to do, enter the Bank Privacy Project.

-Joseph Jerome, Policy Counsel

Practical De-Identification Workshop

“Practical De-Identification” was held on July 9, 2015. The event was attended by industry and policy leaders from a range of sectors, who joined in a lively and in-depth discussion about what it means for data to be de-identified. Expert panelists discussed the current regulatory framework, how to understand identifiers and pseudonymous data, the role of controls, and sector-specific applications of de–identification.

You can download the speakers’ presentations by clicking HERE. For more information and a summary of the proceedings, please reach out to [email protected].

Building on the success of this event, EY and FPF will be kicking off an effort to provide guidance on what steps are needed to provide effective controls, as well as to support the policy arguments for the relevancy of controls to the de–identification process.

DSC_0756

 

DSC_0755  DSC_0765

Peter Swire Testifies on Encryption and "Going Dark"

This morning, FPF Senior Fellow Peter Swire presented testimony before the Senate Judiciary Committee on encryption and the balance between public safety and privacy. Swire highlights the concerns raised by a diverse coalition of cybersecurity and privacy experts, tech companies, and human rights activists about law enforcement’s “going dark” argument.

“We can respect the heartfelt concerns of law enforcement officials facing new challenges while respectfully disagreeing with proposed policies,” he concludes. You can read his full testimony here.

Altimeter Offers Up Privacy Lessons for IoT

A new report today from Altimeter explores what brands can learn about consumer privacy perceptions in the booming Internet of Things. The group warns of the “massive gulf between consumer awareness and industry practices when it comes to practice,” and suggests that companies could respond to consumer anxiety by pursing more trusted customer relationships. At present, Altimeter found that trust and understanding of new connected technologies trail far behind consumer interest in these products.

Some of the numbers the report cites about consumer understanding are problematic: 40% of consumers still have little understanding of how, when, where, or with whom tracking involving HTTP cookies occurs. With regards to the “Internet of Things,” 87% of surveyed consumers had never even heard of the term. While the IoT is still in early days, the juxtaposition of these two numbers suggests that exposure to these technologies alone will not solve the public’s perceived privacy anxieties.

Altimeter found significant percentages of the public concerned about both company use of their data and their data being sold or shared:

Yet consumers are also worried about how companies are using their information. Altimeter reports that consumers are worried about where and how long their data is stored, and even how personally identifiable their information may be. Most important, sensitivity to data use is not exclusive to older populations. Even for the survey’s youngest segment, aged 18-24, well over 40% of those survey indicated high levels of concerns about typical data uses.

The report cautions that industry is facing a trust deficit and has “an existential imperative to foster trust with consumers, for risk of failure, security compromise, customer safety, and ethical responsibility.” It argues that this dynamic calls for a transformation is not just privacy and security and compliance but in the design of consumer experiences. In other words, industry needs to provide a clearer value exchange in the Internet of Things:

Whether in the form of money, time, or energy, consumers are most incentivized to share their data by gains in efficiency. Indeed not all ‘value exchange’ is created equal; this study finds that consumers with higher trust place higher value on information to aid with decision-making, where as those with lower trust are more compelled to share their data for customer support needs. These particular findings address a deeper question: are coupons really enough?

Coupons may indeed not be enough. For the Internet of Things, successful brands will do better at communication, education, and consumer engagement.

-Joseph Jerome, Policy Counsel

Android M and Privacy: Giving Users Control over App Permissions

Android M and Privacy: Giving Users Control over App Permissions

Android M promises to deliver several new user-control features built to advance transparency, choice, and predictability. The new App Permissions system allows users to select permissions specific to each app and device feature. The granular system requires apps to request user permissions individually as the features are needed, opposed to the former all-or-nothing prompt at install. Once installed, users can modify the app’s access to device features at any time.

Android System Settings

App Permissions simplifies the device-feature access, while providing greater user control.

Android M’s App Permissions model creates eight controllable device-feature groups: Calendar, Camera, Contacts, Location, Microphone, Phone, SMS, and Sensors. Access to each of these features may be selectively denied at the user’s leisure throughout the lifecycle of the app. Lower risk permissions, such as access to the alarm clock and internet, are automatically granted to a requesting app at install. Users can still review these permissions prior to installing, but the current build hides these permissions later.

How to adjust your apps’ permissions.

The Android M Preview build provides users with two methods of accessing and changing permissions to the eight permission groups. First, users can access all permissions that an app has sought by selecting Settings => Apps => [The App] => Permissions. Second, users can view all apps that have sought permissions based on the eight feature categories by selecting Settings => Apps => [3-Dot Menu] => Advanced => App permissions. Whether a user is concerned with the permissions of a specific app or for a distinct device feature, the two methods of access give users a quick and clear means to modify either. Furthermore, users will still have separate access to location requests made by apps via the Settings page.

Users can limit access to the features they want.

Google will no longer allow developers to present users with an all-or-nothing list of permissions. This will address the issue of apps seeking permission for device features unnecessary to the app’s operation, forcing users into undesired permissions if they accept the app. By giving individual-feature choices, users can opt-in to only the permissions – and the associated functionality – that they desire. And the full list of permissions that each app seeks will still be available to users before downloading.

Developers are encouraged to prove the value for users granting apps permissions.

Once an app is installed, users will be able to modify their permission preferences at any time. Permissions may be granted initially. But failing to provide users with an immediate return on investment for their data will lead many to adjust their settings accordingly. At-will modifications provide users with a workaround for use-specific access. For rarely needed features, users can allow access to device features only when they need them.

Developers are rewarded for disclosing the purpose of the app’s feature request.

The Android M permissions model incentivizes developers to explain their reasons for requesting permission to use features. When an app seeks permission to use a feature for the first time, users will be prompted with a choice to allow or deny access. If the user denies access, developers are allowed an opportunity to explain their reasons for seeking access. On the second request for access, the user will be additionally offered the choice “never ask again.” Because users can opt-out of repeated requests, Android M blocks the app from irritating users into submission. Developers must convince users of the permission’s necessity or lose access to the feature.

Android Permissions Never Ask Again

User decisions are respected by increasing the difficulty of hassling them to change their settings.

Once the user stops future requests, apps will be prohibited from directly linking the user to the app’s permissions. While it may increase the difficulty of adjusting the permission settings, Google took this affirmative step to keep apps from repeatedly questioning the user’s privacy decisions.

Apps should not request permission for one-off features.

Often, apps only need to use a device feature sparingly. But the all-or-nothing model lacked sufficient deterrence to developers seeking unlimited access for these one-off features. Users would have to weigh their concern for this granting disproportionate access against the entire value of the app. Now, not only can users disable access when these one-off features are not in use, but Google provides a simple solution for developers seeking this type of access. Instead of requesting permission for the app to use a feature, the developer can direct the user to an app that has permission and retrieve the information from there. This method gives the user peace of mind and promotes transparency and trust in the app developer, because users know that the app does not seek unlimited access to features which are rarely used.

Android Legacy Permissions

Users can opt-out of specific permissions for older apps.

Despite early reports to the contrary, App Permissions will give users the same access and choice to device features for apps built using older Android platforms. Because these apps lack the framework to handle granular permissions, Google has chosen to send blocked requests an empty set. Thus, an app seeking contacts from a user who has denied this permission will display that the user has no contacts. While not the cleanest method for handling a denial, retroactively applying granular permissions will encourage developers to embrace the new selective-privacy system.

Summary

In line with Google’s recently announced redesign of their accounts-page privacy settings, Android M creates a simpler and more transparent interface for user control of private information. The feature-specific opt-in approach of the new App Permissions model will provide users with greater transparency, protection, and control over their personal information.

For iOS app permissions, see our post, iOS 8 and Privacy: Major New Privacy Features. Information for developers is also available at our Application Privacy hub.

Framing the "Big Data Industry"

For all its hype, discussions about Big Data often still devolve into debates about buzzwords and concepts like business intelligence, data analytics, and machine learning. Hidden in each of these terms are important privacy and ethical considerations. A recent article by Kirsten Martin in MIS Quarterly Executive attempts to bring these considerations to the surface by moving past framing Big Data as merely some business asset or computational technique. Instead, Martin suggests analyzing risks and rewards at a macro-level by looking at the entire Big Data ecosystem, which she terms the Big Data Industry (BDI).

Yes, her paper still largely focuses on the negative impacts of Big Data, but instead of a general sense of doom-and-gloom, her focus is on a systemic analysis of where the data industry faces specific challenges. Though the article is peppered with examples of privacy-invading headlines, like Target’s purported ability to predict pregnancy, her framing is particularly helpful because it largely divorces the “risks” posed by Big Data from individualized company practices, anecdotes, and hypotheticals. Instead, she describes the entire Big Data information supply chain from upstream data sources to downstream data uses. Consumer-facing firms, tracking companies, and data aggregators — or data brokers — work together to exchange information and add more value to different data sources.

Martin breaks down the different negative effects that can impact individuals at different points in the supply chain. She highlights some of the existing concerns around downstream uses of Big Data. For example, she notes that both incorrect and correct inferences about individuals could limit individual’s opportunities, encourage consumer manipulation, and ultimately be viewed as being disrespectful to individual concerns. While these sorts of Big Data harms have been long debated, Martin places them on a spectrum alongside concerns raised by upstream suppliers of data, including poor data quality, biases in the data, and privacy issues in the collection and sharing of information. Analogizing to how food providers have become responsible for everything from labor conditions to how products are farmed, she argues that Big Data Industry players, by choosing and creating supply chains, similarly become “responsible for the conduct and treatment of users throughout the chain.”

By looking at Big Data as one complete supply chain, Martin appears to believe it will be easier for members of the Big Data Industry to identify and monitor economical and ethical issues with the supply chain. Yet problems also exist across this nascent industry. Even if we can effectively understand data supply chains, Martin is perhaps more concerned with the systemic issues she sees in the BDI. Specifically, the norms and practices currently being established throughout the entire data supply chain give rise to “everyone does it” ethical questions, and the BDI, in particular, poses two pivotal ethical considerations.

First, data supply chains may create negative externalities, especially in aggregate. Air pollution, for example, can become a generalized societal problem through global warming, and the harm from actions across the manufacturing industry can be considerably greater than the pollution caused by any individual company. Martin posits the Big Data Industry presents a similar dynamic, wherein every member that captures, aggregates, or uses information creates costs to society in the form of surveillance. By contributing to a “larger system of surveillance” and by frequently remaining invisible and out-of-sight to individuals, the BDI may be generating an informational power imbalance. Perhaps because individual companies that are part of the BDI fail to see themselves as part of a larger data ecosystem, few companies have been put in a position to take account of — or even to consider — that their data practices may give rise to such a negative externality.

Second, the Big Data Industry may foster “destructive demand” for consumer-facing companies to collect and sell increasing amounts of consumer data with lower standards. According to Martin, demand can become destructive (1) when a primary markets that promise a customer-facing relationship become a front for a secondary market, (2) when the standards and quality of the secondary market are less than the primary market, and (3) when those consumer-facing companies have limited accountability to consumers for their transactions and dealings in the secondary market. Martin sees a cautionary tale for the BDI in the recent mortgage crisis and the role that mortgage-backed securities played in warping the financial industry. She warns that problems are inevitable as the buying and selling of consumer data becomes more important than “selling an application or providing a service.” Invoking the specter of the data broker boogeyman, Martin argues that consumer-facing organizations lack accountability for their activities in the secondary data market, particularly so long as consumers remain in the dark as to what is going on behind the scenes in the greater BDI.

So how can the Big Data Industry address these concerns? She places much of her faith in the hope that organizations like the Census Bureau that have “unique influence” as well as “providers of key products within the Big Data Industry, such as Palantir, Microsoft, SAP, IBM” can help shape sustainable industry practices moving forward. These practices would embody a number of different solutions under the rubrics of data stewardship, data integrity, and data due process. Many of the proposals under the first two amount to endorsing additional transparency mechanisms. For example, publicly linking companies through a larger supply chain could create “a vested interest in ensuring others in the chain uphold data stewardship and data due process practices.”

Data due process, on the other hand, would help firms to “internalize the cost of surveillance.” Additional internal oversight and due process procedures would, according to Martin, “increase the cost of holding individualized yet comprehensive data and internalize the cost of contributing to surveillance.” As to what these mechanisms could look like, Martin points to ideas like consumer subject review boards, which was first popularized at a Future of Privacy Forum event two years ago and is an effort we have continued to expand upon. The call for data integrity professionals mirrors the notion of “algorithmists” that could monitor not just the quality of upstream data sources but downstream data uses. (As an aside, she chastises business schools, who, even as they race to train Big Data professionals, do not require business students to take courses in ethics.) Effective ethical reviews would require such professionals, which could potentially mitigate some of risks inherent in the data supply chain.

While Martin’s proposals are not a panacea, industry and regulators alike should take her suggestions seriously. Her framing of a greater Big Data Industry provides a path forward for companies — and regulators and watchdogs — to better target their efforts to promote public trust in Big Data. She has identified places in the information supply chain where certain industry segments may need to get “more skin in the game” so to speak. And, at the very least, Martin has moved Big Data from amorphous buzzword to a full-fledged ecosystem with some shape to it.

-Joseph Jerome, Policy Counsel