Tracker di posta, nuovo sistema li individua e li elimina prima del recapito

Un sistema di posta elettronica all’insegna della scurezza quello messo a punto da DuckDuckGo, che offre agli utenti una casella “@duck.com” gratuita come indirizzo di posta. Il servizio inoltrerà la posta all’indirizzo ufficiale del destinatario soltanto dopo un’approfondita analisi dei contenuti, bloccando eventuali tracker.

Indirizzi di posta anche usa e getta

DuckDuckGo sta inoltre estendendo questa funzionalità con indirizzi di inoltro univoci e usa e getta, che possono essere generati facilmente nel browser mobile di DuckDuckGo o tramite le estensioni del browser desktop.

L’e-mail personale DuckDuckGo è pensata per essere distribuita ad amici e contatti che conosci, mentre gli indirizzi usa e getta sono più indicati quando ti iscrivi per prove gratuite, newsletter o ovunque sospetti possa vendere il tuo indirizzo e-mail. Se l’indirizzo email è compromesso, puoi facilmente disattivarlo.

Questi strumenti sono simili alle funzionalità anti-tracking implementate da Apple in iOS 14 e iOS 15, ma l’approccio di DuckDuckGo si integra in iOS, Android e in tutti i principali browser web. DuckDuckGo semplificherà anche la creazione di indirizzi e-mail usa e getta al volo, per le newsletter o ovunque tu possa condividere la tua e-mail.

Tracker di posta nel 70% delle mailing list

Contrastare l’invasione della privacy della posta elettronica è uno degli obiettivi principali di DuckDuckGo. La società è principalmente conosciuta per il suo omonimo motore di ricerca DuckDuckGo e più recentemente ha introdotto il proprio browser mobile e le estensioni del browser desktop per rimuovere i tracker durante la navigazione sul Web.

I tracker di posta elettronica esistono in oltre il 70% delle mailing list, secondo uno studio del 2017 molto citato. Una volta implementati, consentono agli inserzionisti di capire quando apri la posta elettronica, dove ti trovi quando la apri e quale dispositivo stai utilizzando. La rimozione dei tracker dalle e-mail rimuove i punti dati dagli elenchi che creano profili pubblicitari nascosti su di te, che negli ultimi anni sono diventati una priorità per i sostenitori della privacy.

https://www.key4biz.it/tracker-di-posta-nuovo-sistema-li-individua-e-li-elimina-prima-del-recapito/369369/




Now that machines can learn, can they unlearn?

Now that machines can learn, can they unlearn?
Andriy Onufriyenko | Getty Images

Companies of all kinds use machine learning to analyze people’s desires, dislikes, or faces. Some researchers are now asking a different question: How can we make machines forget?

A nascent area of computer science dubbed machine unlearning seeks ways to induce selective amnesia in artificial intelligence software. The goal is to remove all trace of a particular person or data point from a machine learning system, without affecting its performance.

If made practical, the concept could give people more control over their data and the value derived from it. Although users can already ask some companies to delete personal data, they are generally in the dark about what algorithms their information helped tune or train. Machine unlearning could make it possible for a person to withdraw both their data and a company’s ability to profit from it.

Although intuitive to anyone who has rued what they shared online, that notion of artificial amnesia requires some new ideas in computer science. Companies spend millions of dollars training machine-learning algorithms to recognize faces or rank social posts, because the algorithms often can solve a problem more quickly than human coders alone. But once trained, a machine-learning system is not easily altered, or even understood. The conventional way to remove the influence of a particular data point is to rebuild a system from the beginning, a potentially costly exercise. “This research aims to find some middle ground,” says Aaron Roth, a professor at the University of Pennsylvania who is working on machine unlearning. “Can we remove all influence of someone’s data when they ask to delete it, but avoid the full cost of retraining from scratch?”

Work on machine unlearning is motivated in part by growing attention to the ways artificial intelligence can erode privacy. Data regulators around the world have long had the power to force companies to delete ill-gotten information. Citizens of some locales, like the EU and California, even have the right to request that a company delete their data if they have a change of heart about what they disclosed. More recently, US and European regulators have said the owners of AI systems must sometimes go a step further: deleting a system that was trained on sensitive data.

Last year, the UK’s data regulator warned companies that some machine-learning software could be subject to GDPR rights such as data deletion, because an AI system can contain personal data. Security researchers have shown that algorithms can sometimes be forced to leak sensitive data used in their creation. Early this year, the US Federal Trade Commission forced facial recognition startup Paravision to delete a collection of improperly obtained face photos and machine-learning algorithms trained with them. FTC commissioner Rohit Chopra praised that new enforcement tactic as a way to force a company breaching data rules to “forfeit the fruits of its deception.”

The small field of machine unlearning research grapples with some of the practical and mathematical questions raised by those regulatory shifts. Researchers have shown they can make machine-learning algorithms forget under certain conditions, but the technique is not yet ready for prime time. “As is common for a young field, there’s a gap between what this area aspires to do and what we know how to do now,” says Roth.

One promising approach proposed in 2019 by researchers from the universities of Toronto and Wisconsin-Madison involves segregating the source data for a new machine-learning project into multiple pieces. Each is then processed separately, before the results are combined into the final machine-learning model. If one data point later needs to be forgotten, only a fraction of the original input data needs to be reprocessed. The approach was shown to work on data of online purchases and a collection of more than a million photos.

Roth and collaborators from Penn, Harvard, and Stanford recently demonstrated a flaw in that approach, showing that the unlearning system would break down if submitted deletion requests came in a particular sequence, either through chance or from a malicious actor. They also showed how the problem could be mitigated.

Gautam Kamath, a professor at the University of Waterloo also working on unlearning, says the problem that project found and fixed is an example of the many open questions remaining about how to make machine unlearning more than just a lab curiosity. His own research group has been exploring how much a system’s accuracy is reduced by making it successively unlearn multiple data points.

Kamath is also interested in finding ways for a company to prove—or a regulator to check—that a system really has forgotten what it was supposed to unlearn. “It feels like it’s a little way down the road, but maybe they’ll eventually have auditors for this sort of thing,” he says.

Regulatory reasons to investigate the possibility of machine unlearning are likely to grow as the FTC and others take a closer look at the power of algorithms. Reuben Binns, a professor at Oxford University who studies data protection, says the notion that individuals should have some say over the fate and fruits of their data has grown in recent years in both the US and Europe.

It will take virtuoso technical work before tech companies can actually implement machine unlearning as a way to offer people more control over the algorithmic fate of their data. Even then, the technology might not change much about the privacy risks of the AI age.

Differential privacy, a clever technique for putting mathematical bounds on what a system can leak about a person, provides a useful comparison. Apple, Google, and Microsoft all fete the technology, but it is used relatively rarely, and privacy dangers are still plentiful.

Binns says that while it can be genuinely useful, “in other cases it’s more something a company does to show that it’s innovating.” He suspects machine unlearning may prove to be similar, more a demonstration of technical acumen than a major shift in data protection. Even if machines learn to forget, users will have to remember to be careful who they share data with.

This story originally appeared on wired.com.

https://arstechnica.com/?p=1788910




A simple software fix could limit location data sharing

Pretty Good Phone Privacy wants to minimize how much your wireless provider knows about your location.
Enlarge / Pretty Good Phone Privacy wants to minimize how much your wireless provider knows about your location.
Noam Galai | Getty Images

Location data sharing from wireless carriers has been a major privacy issue in recent years. Marketers, salespeople, and even bounty hunters were able to pay shadowy third-party companies to track where people have been, using information that carriers gathered from interactions between your phone and nearby cell towers. Even after promising to stop selling the data, the major carriers—AT&T, T-Mobile, and Verizon—reportedly continued the practice in the US until the Federal Communications Commission proposed nearly $200 million in combined fines. Carriers remain perennially hungry to know as much about you as they can. Now, researchers are proposing a simple plan to limit how much bulk location data they can get from cell towers.

Much of the third-party location data industry is fueled by apps that gain permission to access your GPS information, but the location data that carriers can collect from cell towers has often provided an alternative pipeline. For years, it’s seemed like little could be done about this leakage because cutting off access to this data would likely require the sort of systemic upgrades that carriers are loath to make.

At the Usenix security conference on Thursday, though, network security researchers Paul Schmitt of Princeton University and Barath Raghavan of the University of Southern California are presenting a scheme called Pretty Good Phone Privacy that can mask wireless users’ locations from carriers with a simple software upgrade that any carrier can adopt—no tectonic infrastructure shifts required.

“The primary problem we’re trying to address is bulk data collection and the sale of it,” Raghavan says. “We see it as a user privacy issue that carriers can amass this location data whether or not they are currently actively selling it. And our goal here was backward compatibility. We didn’t want the telecoms to have to roll out anything because we knew they weren’t going to.”

The opportunity to collect bulk location data from wireless networks arises from the fact that each SIM card has a permanent ID number, known as an “international mobile subscriber identity,” or IMSI number. When your device reboots, has been inactive for a while, or just needs to establish a fresh connection, it reaches out to the nearest cell tower and presents an IMSI number. This allows carriers to check whether you’ve paid your phone bill and should be allowed access to service, and it also tells the network which cell towers you’re close to. Surveillance tools known as “stingrays” or “IMSI catchers” take advantage of this same interaction to grab your physical location and even eavesdrop on your calls and texts.

To make it more difficult to track you all the time, wireless standards already assign each device a random, rotating ID after the initial IMSI exchange. This means that there are already some protections built into the system; making that first IMSI step more private would have far-reaching benefits for users.

Pretty Good Phone Privacy, whose name is a nod to the groundbreaking 1991 communication encryption program Pretty Good Privacy, aims to achieve just that by reimagining the billing check that networks perform. The researchers propose installing portals on every device—using an app or operating system function—that run regular checks with a billing server to confirm that a user is in good standing. The system would hand out digital tokens that don’t identify the specific device but simply indicate whether the attached wireless account is paid up. When the device attempts to connect to a cell tower, the exchange would funnel through this portal for a “yes” or “no” on whether to provide service. The researchers further realized that if the system has an alternate method of confirming billing status, it can accept the same IMSI number or any random ID for each user.

“When you attach to the network, you offer the IMSI number to show the backend database that you are a paying customer, and here are the services that you have subscribed to,” Schmitt says. “The system then informs the rest of the core to allow you onto the network. But what we do with PGPP changes the calculus. The subscriber database can verify that you’re a paying user without knowing who you are. We’ve decoupled and shifted billing and authentication.”

Reworking some billing systems and distributing an app to users would be far more manageable for carriers than deeper network overhauls. Raghavan and Schmitt are in the process of turning their research into a startup to make promoting the project easier among United States telecoms. They acknowledge that even with the ease of adoption, it’s still a long shot that the whole industry would shift to PGPP anytime soon. But getting only a few carriers, they say, could still make a big difference. That’s because bulk location data becomes much less reliable if any significant portion of the total set is tainted. If 9 million Boost Mobile subscribers, for instance, were to broadcast identical or randomized IMSI numbers, that would undermine the accuracy and usefulness of the entire data set.

The fact that small, virtual providers who don’t even operate their own cell towers—known as MVNOs—could implement this scheme independently is significant, says cryptographer Bruce Schneier, who originally learned about PGPP in January and has recently become a project adviser.

“One carrier can do it on their own without anybody’s permission and without anybody else changing anything,” Schneier says. “I can imagine one of these smaller companies saying they’re going to offer this as a value-add because they want to differentiate. This is privacy at very little cost. That’s the neat thing.”

In the competitive, monolithic wireless market, standing apart on privacy could be appealing as a marketing tactic. It’s possible that the big three carriers could attempt to block MVNOs from adopting something like PGPP through contractual moratoria. But the researchers say that some MVNOs have expressed interest in the proposal.

Between potential pressure from law enforcement and loss of data access—plus the need to distribute an app or get mobile operating systems to participate—carriers could have little incentive to adopt PGPP. To the extent that law enforcement might oppose such a scheme, Schmitt notes that it would still be possible for carriers to perform targeted location history lookups for specific phone numbers. And the researchers say they believe the approach would be legal in the US under the Communications Assistance for Law Enforcement Act. This is because one caveat of PGPP is that it only adds privacy protections for cell tower interactions that involve data networks like 4G or 5G. It doesn’t attempt to interoperate with the historic telephony protocols that facilitate traditional phone calls and SMS text messages. Users would need to rely on VoIP calling and data-based messaging for maximum privacy.

The approach also focuses on IMSI numbers, along with their 5G counterparts known as Subscription Permanent Identifiers, or SUPI, and it doesn’t protect or occlude static hardware identifiers like International Mobile Equipment Identity (IMEI) numbers or media access control (MAC) addresses. These aren’t used in the cell tower interactions the researchers are trying to anonymize, but they could provide other avenues for tracking.

Having a simple and straightforward option to address one major location data exposure is still significant, though, after years of data misuse and rising privacy concerns.

“Just to be totally frank, the feeling for me now is, how did we not see this before?” Raghavan says. “It’s not, ‘Wow, this was so difficult to figure out.’ It’s obvious in retrospect.”

“That actually made us feel better as systems researchers,” Schmitt adds. “Ultimately, the simpler the system, the better the system.”

This story originally appeared on wired.com.

https://arstechnica.com/?p=1787083




Today’s Firefox 91 release adds new site-wide cookie-clearing action

This menacing firefox seems to be on the prowl for unwanted third-party cookies.
Enlarge / This menacing firefox seems to be on the prowl for unwanted third-party cookies.

Mozilla’s Firefox 91, released this morning, includes a new privacy management feature called Enhanced Cookie Clearing. The feature allows users to manage all cookies and locally stored data generated by a website—regardless of whether they’re cookies tagged to that site’s domain or cookies placed from that site but belonging to a third-party domain, e.g., Facebook or Google.

Building on Total Cookie Protection

Mozilla isn't being delicate about which tech giant is first in its crosshairs.
Enlarge / Mozilla isn’t being delicate about which tech giant is first in its crosshairs.

The new feature builds and depends upon Total Cookie Protection, introduced in February with Firefox 86. Total Cookie Protection partitions cookies by the site that placed them rather than the domain that owns them—which means that if a hypothetical third party we’ll call “Forkbook” places tracking (or authentication) cookies on both momscookies.com and grandmascookies.com, it can’t reliably tie the two together.

Without cookie partitioning, a single Forkbook cookie would contain the site data for both momscookies.com and grandmascookies.com. With cookie partitioning, Forkbook must set two separate cookies—one for each site—and can’t necessarily relate one to the other.

Even if the cookies are used for a third-party Forkbook login, tying the two together would need to be done on the back end—since both are presumably for the same Forkbook account—rather than Forkbook being able to simply, cheaply, and easily read all tracking data from a single cookie. If the sites don’t use Forkbook for authentication, the two probably can’t be tied together at all—because even if the user is logged in to Forkbook in a different tab, that cookie is split apart from the ones used on mom’s and grandma’s cookie sites.

Clearing data site-wide

The updated Cookies and Site Data management dialog displays all locally stored resources set at a particular site, whether owned by that site or by a third party.
Enlarge / The updated Cookies and Site Data management dialog displays all locally stored resources set at a particular site, whether owned by that site or by a third party.

Once you understand that websites routinely place cookies that belong to third-party domains, it becomes obvious why it might be difficult to clear all traces of data stored by that site—returning to our “Forkbook” example above, clearing all data belonging directly to momscookies.com wouldn’t clear the Forkbook cookie, and clearing a universal Forkbook cookie would necessarily log the user out of all websites using Forkbook authentication.

However, when each site has its own individual cookie jar—meaning Forkbook needs to place separate cookies, separate copies of embedded javascript libraries, separate copies of images, and so forth between momscookies.com and grandmascookies.com and forkbook.com itself—it becomes possible to easily manage all data stored locally by that individual site.

When using Total Cookie Protection, you can empty the entire bucket for momscookies.com, including its own cookies, Forkbook’s cookies, and anything else. This breaks Forkbook’s record of your browsing activities on momscookies.com—because although it will set a new cookie the next time you visit, it won’t have a reliable way to tie that cookie to the previous cookie you deleted or to other Forkbook cookies set by other sites.

Fuhgeddaboudit

The new "Forget about this site" option in History allows you to clear all site data, as well as your history of visiting it in the first place.
Enlarge / The new “Forget about this site” option in History allows you to clear all site data, as well as your history of visiting it in the first place.

In addition to organizing locally stored data by the website that placed it rather than the domain that owns it, Firefox 91 gives users the ability to quickly and easily remove all local traces of visiting a site. When browsing your own History timeline in Firefox 91, you can right-click a site’s entry and select Forget About This Site. Doing so removes both the entry in History and all cookies, images, cached scripts, and so forth set during visits to that site.

Get strict

In order to use the new privacy management features, you’ll first have to make sure that Strict Tracking Protection is enabled. Without Strict Tracking Protection, cookies aren’t separated by the site that sets them in the first place.

To enable Strict Tracking Protection, click the shield to the left of the address bar and select Protection Settings. This opens Privacy and Security in a new tab—from there, just make sure the radio-button option for Enhanced Tracking Protection is set to Strict, not Standard.

Although Firefox’s Privacy and Security dialog warns you—accurately—that Strict protection may cause some sites or content to break, those breakages have so far been few and minor in our own testing. The majority of the web—including the bits using third-party authentication and tracking—should continue to work just fine.

https://arstechnica.com/?p=1785945




Uber asked contractor to allow video surveillance in employee homes, bedrooms

Uber asked contractor to allow video surveillance in employee homes, bedrooms

For years, employers have used surveillance to keep tabs on their employees on the job. Cameras have watched as workers moved cash in and out of registers, GPS has reported on the movements of employees driving company vehicles, and software has been monitoring people’s work email.

Now, with more work being done remotely, many of those same surveillance tools are entering people’s homes. A marketing company in Minnesota forced employees to install software that would record videos of employee’s screens and even cut their hours if they took a bathroom break that was too long. A New York e-commerce company told employees that they would have to install monitoring software on their personal computers that would log keystrokes and mouse movements—and they’d have to install an app on their phones that would track their movements throughout the workday.

The situation isn’t limited to the US, either. One multinational company appears to be testing the boundaries of what’s an acceptable level of surveillance for remote workers. Teleperformance, one of the world’s largest call center companies, is reportedly requiring some employees to consent to video monitoring in their homes. Employees in Colombia told NBC News that their new contract granted the company the right to use AI-powered cameras to observe and record their workspaces. The contract also requires employees to share biometric data like fingerprints and photos of themselves, and workers have to agree to share data and images that may include children under 18.

Teleperformance employs over 380,000 people in 83 countries to provide call center services for a range of companies, including Amazon, Apple, and Uber. A company spokesperson told NBC  that it is “constantly looking for ways to enhance the Teleperformance Colombia experience for both our employees and our customers, with privacy and respect as key factors in everything we do.”

Amazon and Apple said that they did not ask Teleperformance for this extra monitoring, and an Apple spokesperson said the company forbids video monitoring of employees by suppliers. A recent Apple audit reportedly found Teleperformance in compliance with this requirement.

But Uber apparently requested the ability to monitor some workers. Uber said it wouldn’t observe the entire workforce, but the company did not specify which employees would be subject to the new policies. The ride sharing company asked for the monitoring of Teleperformance’s remote employees because call center staff have access to customers credit cards and trip details, an Uber spokesperson told NBC News.

Like many remote workers in the US, Colombians have had to make do with the space they have available to them. In many cases, that’s meant putting their work equipment in otherwise private spaces like their bedrooms. “The contract allows constant monitoring of what we are doing, but also our family,” one worker told NBC. “I think it’s really bad. We don’t work in an office. I work in my bedroom. I don’t want to have a camera in my bedroom.”

Another Teleperformance worker said the only room quiet enough to take customer calls is her bedroom, and at night, during her shifts, it’s also where her husband sleeps. “It’s a violation of my privacy rights, and the rights of my husband and mother-in-law who live with me,” she said.

Boom time for surveillance

Many companies (though not all) were forced to implement remote work a year and a half ago when the pandemic began, and since then, interest in employee monitoring software has boomed. There’s concern that, when the pandemic ends, digital surveillance will follow employees back to the office.

The tools and policies vary in their degrees of invasiveness. Some monitor which apps or websites are open and active, while others log keystrokes or take screenshots to allow managers to snoop on their employees’ desktops. Some will keep tabs on general activity, posting a pop-up window if the person appears to be inactive for too long. If the user doesn’t dismiss it in time, it’ll pause their time clock, effectively docking their pay if their bathroom break stretches too long. Other employers skip specialized apps entirely and ask their employees to stay on video chat all day long.

Employees don’t have many options. They can organize to push back against snooping employers—which many of Teleperformance’s Colombian employees appear to be doing—but many countries, including the US, don’t have laws to prevent companies from surveilling their workers. While the Fourth Amendment in the US may protect against unreasonable search and seizure by the government, it doesn’t apply to private companies in these cases.

“There’s not a constitutional issue here,” Paul Stephens, director of policy and advocacy with Privacy Rights Clearinghouse, told NPR last year. “There aren’t a whole lot of legal protections for employees who are being monitored.”

https://arstechnica.com/?p=1785847




Apple says it will refuse gov’t demands to expand photo-scanning beyond CSAM

Illustration of a padlock over a glowing digital data panel.
Getty Images | Yuichiro Chino

Apple today said it will refuse any government demands to expand its new photo-scanning technology beyond the current plan of using it only to detect CSAM (child sexual abuse material).

Apple has faced days of criticism from security experts, privacy advocates, and privacy-minded users over the plan it announced Thursday, in which iPhones and other Apple devices will scan photos before they are uploaded to iCloud. Many critics pointed out that once the technology is on consumer devices, it won’t be difficult for Apple to expand it beyond the detection of CSAM in response to government demands for broader surveillance. We covered how the program will work in detail in an article Thursday night.

Governments have been pressuring Apple to install backdoors into its end-to-end encryption system for years, and Apple acknowledged that governments are likely to make the exact demands that security experts and privacy advocates have been warning about. In a FAQ released today with the title, “Expanded Protections for Children,” there is a question that asks, “Could governments force Apple to add non-CSAM images to the hash list?”

Apple answers the question as follows:

Apple will refuse any such demands. Apple’s CSAM detection capability is built solely to detect known CSAM images stored in iCloud Photos that have been identified by experts at NCMEC (National Center for Missing and Exploited Children) and other child safety groups. We have faced demands to build and deploy government-mandated changes that degrade the privacy of users before, and have steadfastly refused those demands. We will continue to refuse them in the future. Let us be clear, this technology is limited to detecting CSAM stored in iCloud and we will not accede to any government’s request to expand it. Furthermore, Apple conducts human review before making a report to NCMEC. In a case where the system flags photos that do not match known CSAM images, the account would not be disabled and no report would be filed to NCMEC.

None of this means that Apple lacks the ability to expand the technology’s uses, of course. Answering the question of whether its photo-scanning system can be used to detect things other than CSAM, Apple said that it “is designed to prevent that from happening.”

“CSAM detection for iCloud Photos is built so that the system only works with CSAM image hashes provided by NCMEC and other child safety organizations,” Apple said. “There is no automated reporting to law enforcement, and Apple conducts human review before making a report to NCMEC. As a result, the system is only designed to report photos that are known CSAM in iCloud Photos.”

Apple says it won’t inject other photos into database

But the system’s current design doesn’t prevent it from being redesigned and used for other purposes in the future. The new photo-scanning technology itself is a major change for a company that has used privacy as a selling point for years and calls privacy a “fundamental human right.”

Apple said the new system will be rolled out later this year in updates to iOS 15, iPadOS 15, watchOS 8, and macOS Monterey, and will initially be deployed in the US only. The current plan is for Apple devices to scan user photos and report those that match a database of known CSAM image hashes. The Apple FAQ implicitly acknowledges that hashes of other types of images could be added to the list, but the document says Apple won’t do that.

“Can non-CSAM images be ‘injected’ into the system to flag accounts for things other than CSAM? Our process is designed to prevent that from happening,” Apple wrote. “The set of image hashes used for matching are from known, existing images of CSAM that have been acquired and validated by child safety organizations. Apple does not add to the set of known CSAM image hashes.”

Apple also said the new “feature only impacts users who have chosen to use iCloud Photos to store their photos. It does not impact users who have not chosen to use iCloud Photos.” Apple’s FAQ didn’t say how many people use iCloud Photos, but it is a widely used feature. There are over 1 billion iPhones actively used worldwide, and a 2018 estimate by Barclays analysts found that iCloud (including all services, not just iCloud Photos) had 850 million users.

Apple memo called privacy advocates “screeching voices”

Apple does not seem to have anticipated the level of criticism its decision to scan user photos would receive. On Thursday night, Apple distributed an internal memo that acknowledged criticism but dismissed it as “screeching voices of the minority.”

That portion of the memo was written by NCMEC Executive Director of Strategic Partnerships Marita Rodriguez. “I know it’s been a long day and that many of you probably haven’t slept in 24 hours. We know that the days to come will be filled with the screeching voices of the minority. Our voices will be louder. Our commitment to lift up kids who have lived through the most unimaginable abuse and victimizations will be stronger,” Rodriguez wrote.

The memo was obtained and published by 9to5Mac. The Apple-written portion of the memo said, “We’ve seen many positive responses today. We know some people have misunderstandings, and more than a few are worried about the implications, but we will continue to explain and detail the features so people understand what we’ve built.”

Open letter warns of expanding surveillance uses

Over 6,000 people signed an open letter urging Apple to reverse course, saying, “Apple’s current path threatens to undermine decades of work by technologists, academics and policy advocates towards strong privacy-preserving measures being the norm across a majority of consumer electronic devices and use cases.”

The letter quoted several security experts, including researcher Nadim Kobeissi, who wrote, “Reminder: Apple sells iPhones without FaceTime in Saudi Arabia, because local regulation prohibits encrypted phone calls. That’s just one example of many where Apple’s bent to local pressure. What happens when local regulation mandates that messages be scanned for homosexuality?”

The letter also quotes Johns Hopkins University cryptography professor Matthew Green, who told Wired, “The pressure is going to come from the UK, from the US, from India, from China. I’m terrified about what that’s going to look like. Why would Apple want to tell the world, ‘Hey, we’ve got this tool’?”

https://arstechnica.com/?p=1785740




The privacy battle Apple isn’t fighting

The privacy battle Apple isn’t fighting
Elena Lacey, Getty Images

For at least a decade, privacy advocates dreamed of a universal, legally enforceable “do not track” setting. Now, at least in the most populous state in the US, that dream has become a reality. So why isn’t Apple—a company that increasingly uses privacy as a selling point—helping its customers take advantage of it?

When California passed the California Consumer Privacy Act (CCPA) in 2018, the law came with a large asterisk. In theory, the CCPA gives California residents the right to tell websites not to sell their personal data. In practice, exercising that right means clicking through an interminable number of privacy policies and cookie notices, one by one, on every site you visit. Only a masochist or a die-hard privacy enthusiast would go to the trouble of clicking through to the cookie settings every time they’re looking up a menu or buying a vacuum. Privacy will remain, for most people, a right that exists only on paper until there’s a simple one-click way to opt out of tracking across the whole Internet.

The good news is that this ideal is inching closer and closer to reality. While the CCPA doesn’t explicitly mention a global opt-out, the regulations interpreting the law issued by the California attorney general in 2020 specified that businesses would have to honor one, just as they do individual requests. The technology for a universal opt-out didn’t actually exist yet, but last fall, a coalition of companies, nonprofits, and publishers unveiled a technical specification for a global privacy control that can send a CCPA-enforceable “do not track” signal at the browser or device level.

Today, if you live in California, you can enable the global privacy control by using a privacy browser like Brave or downloading a privacy extension, like DuckDuckGo or Privacy Badger, in whatever browser you already use. (Seriously, go do it. The full list of options is here.) Once you do, you’ll automatically tell sites you visit, “Do not sell my personal information” without having to click anything—and, unlike with previous efforts to create a universal opt-out, any decent-size company that does business in California will be legally obligated to comply, which requires adding just a few lines of code to their website.

The state of CCPA enforcement remains murky because some businesses object to the attorney general’s broad interpretation of the law. But California’s government has begun making clear that it intends to enforce the global privacy control requirement. (The more recently passed California Privacy Rights Act, which goes into full effect in 2023, makes this requirement more explicit.)

In mid-July, Digiday reported that Attorney General Rob Bonta’s office had “sent at least 10 and possibly more than 20 companies letters that call on them to honor the GPC.” And an item appeared on a recent list of CCPA enforcement actions on the attorney general’s website noting that a company had been forced to start honoring the signal.

Now, the bad news. While it’s a lot easier to install a privacy extension or browser than click through a million privacy pages, the vast majority of people are still unlikely to do so. (It remains to be seen whether DuckDuckGo papering America’s highways and cities with billboards will inspire a new wave of privacy connoisseurs.)

This matters quite a bit because online privacy rights are collective, not individual. The trouble with pervasive tracking is not merely that it can allow someone to access your personal location data and use it to ruin your life, as recently happened to a Catholic priest whose commercially available Grindr data revealed a pattern of frequenting gay bars. Even if you personally opt out of tracking, you’re still living in a world shaped by surveillance. Tracking-based advertising contributes to the decline of quality publications by eating away at the premium that advertisers pay to reach their audiences. Cheaper to find those readers on social media or even on bottom-feeding extremist news sites. It turbocharges the incentive to relentlessly maximize engagement on social media platforms. None of that will go away until a critical mass of people opt out of being tracked across the board.

That’s why one absence from the list of companies supporting the global privacy control is so conspicuous. Apple burnished its already strong reputation on privacy earlier this year by introducing App Tracking Transparency, a setting that flips the privacy default on iOS devices by forcing apps to get a user’s permission before sharing their data. That is a genuinely big step forward for privacy, since the difference between being opted out by default and opted in is enormous—and indeed, early reports suggest that most iPhone users are declining to give apps permission to track them.

But Apple, despite its stated (and heavily advertised) commitment to privacy, has not incorporated the global privacy control into Safari, the most popular mobile browser in the US and the second-most-popular desktop browser. Nor has it built it into iOS, which accounts for more than half of the US mobile operating system market. That means it’s not doing as much as it could to protect tens of millions of users from having their data sold and shared. The App Tracking Transparency framework is important, but it relies on Apple catching app developers who violate the policy. Safari’s tracking-prevention feature, meanwhile, relies on a technical approach to blocking cookies and other trackers that can often be circumvented.

“For years, companies have found ways to circumvent technical privacy protections. It’s basically an arms race,” says Ashkan Soltani, a privacy researcher who helped develop the global privacy control. “Technical tools are not enough. You need to have the force of law behind it.” That’s where the global privacy control is crucially different from existing tracking prevention. If a business disregards it, it isn’t just violating terms of service or evading some code—it’s breaking the law and risks being slapped with major fines or penalties.

So far, however, none of the biggest browsers have incorporated the feature, keeping it from widespread adoption. This is not shocking in the case of Google, which hasn’t added it to Chrome or Android: The world’s biggest surveillance advertising company is not exactly known for caring much about user privacy. (Google declined to comment for this story.) A Mozilla spokesperson said the company is “looking into the global privacy control and actively considering next steps in Firefox.” It isn’t clear why Apple hasn’t yet joined the party or whether it plans to in the future. The company didn’t respond to multiple requests for comment over the past week.

In the past, Apple has used software design and App Store policies to protect users, stepping into the vacuum created by the lack of comprehensive privacy legislation. Now, in California and any other states that follow its lead—Colorado, for example, will require businesses to honor the global privacy control starting in 2024—the law has finally gotten ahead of the technology. The public won’t start seeing the full benefits until the private sector catches up. If even a privacy-centric company like Apple isn’t interested, though, the wait might be longer than you’d think.

This story originally appeared on wired.com.

https://arstechnica.com/?p=1784258




Quanto conta il fattore umano nella protezione dei dati personali?

Il diritto alla protezione dei dati personali – come del resto anche il diritto alla privacy –  non gode a tutt’oggi di buona fama, almeno in una parte della popolazione. Sta difatti acquisendo consenso una certa narrazione che vede tali garanzie quali intoppi burocratici senza i quali le cose in Italia andrebbero più spedite e, perché no, molte ataviche inefficienze sarebbero risolte, tralasciando – poco importa se con dolo o con colpa – la loro natura di distinti diritti fondamentali dell’uomo (cfr. a titolo di esempio gli Artt. 7 e 8 della Carta dei Diritti Fondamentali dell’Unione Europea).

Per intenderci, è come se il sentire comune non pensasse a Madame Curie come ad una delle più grandi menti della storia dell’umanità, ma la ritenesse la responsabile diretta delle conseguenze dei disastri di Chernobyl e Fukushima e per questo meritoria di unanime riprovazione.

Il paragone è iperbolico, ma penso renda bene la distonia di questa visione. Raramente, infatti, si osservano campagne tanto ampie e condivise volte allo sminuire altri diritti fondamentali dell’uomo.

Diritti fondamentali dell’uomo. Una perifrasi che dovrebbe incutere un senso di sacro rispetto laico al solo scriverla o pronunciarla, e non già far pensare a perversioni amministrative o lenti ideologiche con le quali inquadrare le dinamiche sociali. Questo tipo di fallacia interpretativa, che sia cosciente o meno, investe una parte sempre più ampia della popolazione e rappresenta una leggerezza non tollerabile ad alcun livello sociale.

E tuttavia, purtroppo, sempre più spesso si osservano commenti da parte di personalità politiche, industriali o sociali che additano la protezione dei dati personali quale vacuo bizantinismo che ingessa il paese rallentandone una crescita che, nella visione degli stessi, paga un conto troppo alto a tali tematiche e ad una quasi miope loro declinazione pratica. In questo contesto, il Garante della privacy sta portando avanti una pregevolissima iniziativa culturale attraverso multiformi canali mediatici, ma sarebbe auspicabile che anche da altri settori della società civile, meno direttamente coinvolti, giungessero analoghe manifestazioni per corroborarne l’efficacia. In un ambiente sociale ormai totalmente dipendente dal valore aggiunto dato dall’elaborazione di dati ed informazioni e nel quale le persone, adulti o bambini che siano, sono sempre più permeabili ai rischi insiti nella disponibilità di strumenti tecnologici che celano un funzionamento ipercomplesso dietro ad una estrema semplicità di utilizzo, i diritti in gioco dovrebbero assurgere – come tutti i diritti, del resto, ma questa è un’altra storia – ad un valore non contaminabile dalla propaganda politica; eppure questo è quello che ormai quotidianamente osserviamo…

Clicca qui per continuare a leggere l’articolo su Cybersecurity Italia su cui è stato originariamente pubblicato.

https://www.key4biz.it/quanto-conta-il-fattore-umano-nella-protezione-dei-dati-personali/370546/




Certificazione e accreditamento nell’ottica del GDPR. I requisiti del Garante Privacy

Il 14 luglio 2021 il Garante per la Protezione dei Dati Personali (GPDP) e l’Ente Italiano di Accreditamento (Accredia) hanno pubblicato le Frequently Asked Questions (FAQ) in materia di “Accreditamento e Certificazione ai sensi del GDPR, elaborate nell’ambito di una convenzione finalizzata allo scambio di informazioni riguardanti le attività di certificazione e accreditamento previste dal Regolamento UE 679/2016 relativo alla protezione delle persone fisiche con riguardo al trattamento dei dati personali, nonché alla libera circolazione di tali dati.

Prima di entrare nel merito dei principali chiarimenti forniti dai due enti è necessario differenziare i concetti di accreditamento e certificazione, spesso ritenuti interscambiabili, ma sostanzialmente differenti in termini di risultati e credibilità dei soggetti che li ottengono.

Certificazione e accreditamento nell’ottica del GDPR: cosa significa

La certificazione è una attestazione rilasciata da una parte terza, l’organismo di certificazione (OdC), relativa a un oggetto (prodotto, processo, servizio, persona o sistema) sottoposto a valutazione della conformità rispetto a requisiti contenuti in una norma tecnica (standard). Con essa una terza parte indipendente attesta “per iscritto” che un prodotto, una procedura o un servizio soddisfa i requisiti prescritti.

Ad esempio, la certificazione ISO 9001 di un’azienda esprime la conformità ai requisiti della norma internazionale riguardante la gestione generale, i processi ed il trattamento dei dati.

L’accreditamento, diversamente, consiste nel riconoscimento formale, da parte di un organismo autorevole, che un’organizzazione o un singolo individuo sono competenti nell’eseguire uno specifico servizio come descritto nello scopo dell’accreditamento.

Ad esempio, l’accreditamento ISO/IEC 17065 stabilisce i requisiti che un organismo di certificazione deve soddisfare per dimostrare di operare in modo competente, coerente e imparziale. Un documento normativo fondamentale, quindi, per chi opera nel settore perché rappresenta un efficace strumento per il riconoscimento degli organismi e per l’accettazione dei prodotti, processi e servizi.

La certificazione è “accreditata”, infine, quando, attraverso un’attività di ispezione e verifica, viene data dimostrazione dell’imparzialità, completezza ed adeguatezza dell’organismo di certificazione (OdC) da parte dell’ente unico nazionale di accreditamento a ciò deputato (in Italia, Accredia, istituito ai sensi del Regolamento CE n. 765/2008).

Lo scopo dell’accreditamento consiste nel fornire una dichiarazione autorevole in ordine alla competenza ed efficienza di un determinato organismo a svolgere un’attività di certificazione.

Ottenere la certificazione da parte di un organismo accreditato da Accredia permette alle persone fisiche e alle aziende di acquisire una serie di benefici, che così possono essere sintetizzati:

  • godere di una competenza attestata in modo oggettivo da un organismo indipendente e imparziale;
  • vedersi riconosciuta l’affidabilità della prestazione;
  • ottenere un notevole accrescimento della reputazione agli occhi dei propri clienti.

Ciò premesso, con riferimento alla certificazione nell’ambito del GDPR e, quindi, nell’ambito del trattamento dei dati personali, l’art. 42 del Regolamento Europeo (ed altre norme collegate) stabilisce che: “Gli Stati membri, le autorità di controllo, il comitato e la Commissione incoraggiano … l’istituzione di meccanismi di certificazione della protezione dei dati nonché di sigilli e marchi di protezione dei dati allo scopo di dimostrare la conformità al presente regolamento dei trattamenti effettuati dai titolari del trattamento e dai responsabili del trattamento …” specificando al paragrafo 5 che “la certificazione ai sensi del presente articolo è rilasciata dagli organismi di certificazione … o dall’autorità di controllo competente …”.

Il Regolamento, quindi, prevede e incoraggia l’istituzione di meccanismi di certificazione della protezione dei dati personali allo scopo di dimostrare la conformità al GDPR dei trattamenti effettuati dai titolari del trattamento e dai responsabili del trattamento; la certificazione, quindi, viene intesa come uno strumento utile per il titolare e i responsabili del trattamento a dimostrare il rispetto degli obblighi, le garanzie sufficienti e la conformità ai requisiti di protezione dei dati.

L’adesione a un meccanismo di certificazione rilasciato a norma dell’art. 42 del Regolamento può costituire, infatti, un elemento di responsabilizzazione (c.d. accountability), in quanto consente ai titolari e/o responsabili del trattamento che vi aderiscono di dimostrare la conformità dei medesimi trattamenti ad alcune disposizioni o principi del Regolamento o al Regolamento nel suo insieme.

Inoltre, il paragrafo 5 del richiamato art. 42 stabilisce che, nell’ambito dell’istituzione di meccanismi di certificazione, è previsto che gli organismi di certificazione debbano essere accreditati dall’autorità di controllo competente o dall’organismo nazionale di accreditamento o da entrambi.

Sul punto, le FAQ pubblicate dall’Autorità Garante per la Protezione dei Dati Personali chiariscono  che quest’ultima non rilascia certificazioni. I soggetti deputati a rilasciare le certificazioni della protezione dei dati ad aziende, enti ed altri soggetti che ne facciano richiesta in qualità di titolari o responsabili del trattamento saranno gli organismi di certificazione, una volta riconosciuti da Accredia. L’art. 2-septiesdecies del d.lgs. 30 giugno 2003, n. 196 (Codice Privacy), infatti, attribuisce proprio ad Accredia le funzioni di accreditamento degli organismi di certificazione, ovvero il potere di attestare che un determinato Organismo di Certificazione sia qualificato a rilasciare le certificazioni ai sensi dell’art. 42, par. 5 del GDPR in conformità a quanto previsto dall’art. 43, par. 1, lett. b) dello stesso, fatto salvo il potere dell’Autorità di controllo di assumere direttamente l’esercizio di tali funzioni con riferimento a una o più categorie di trattamenti.

Ma quali sono i requisiti di accreditamento fissati dal Garante per la Protezione dei Dati Personali?

Il Garante per la Protezione dei Dati Personali, con proprio provvedimento ha approvato i “requisiti di accreditamento aggiuntivi” con riguardo alla norma EN-ISO/IEC di riferimento e in conformità all’articolo 43, paragrafi 1, lettera b) e all’art. 3 del GDPR, corredati da alcune note esplicative volte a fornire indicazioni pratiche ed esempi che possono agevolare l’applicazione dei medesimi requisiti sia per la predisposizione della richiesta di accreditamento sia per il mantenimento dell’accreditamento stesso.

I requisiti aggiuntivi riguardano:

  • requisiti generali in materia di accreditamento;
  • requisiti per le risorse umane;
  • requisiti di processo;
  • requisiti del sistema di gestione.

L’Organismo di Certificazione accreditato cosa può certificare in ambito protezione dati dei dati personali?

L’art. 4 del Regolamento Europeo definisce il trattamento come “qualsiasi operazione o insieme di operazioni, compiute con o senza l’ausilio di processi automatizzati e applicate a dati personali o insiemi di dati personali”.

Ed è proprio il trattamento di dati personali, così come definito dalla norma, a costituire l’oggetto della certificazione, potendo quest’ultimo variare in maniera più o meno considerevole a seconda che si tratti di più o meno operazioni di trattamento.

Ciò è quanto si ricava altresì alla luce dei provvedimenti assunti dall’EDPB (European Data Protection Board), che chiariscono i limiti connessi ad una valutazione affidabile e significativa della conformità: “devono essere descritti chiaramente i trattamenti inclusi nell’oggetto della certificazione e quindi gli elementi chiave, ossia quali dati, processi e infrastrutture tecniche saranno sottoposti alla valutazione e quali no”.

Conclusivamente, nel sistema delineato dal legislatore europeo, così come integrato dall’Autorità di controllo nazionale, emerga chiaramente l’importanza della certificazione e gli indiscutibili vantaggi che dalla stessa derivano in termini di reputation e affidabilità aziendale; basti pensare che lo stesso art. 83 GDPR prevede, nel caso di irrogazione di sanzioni amministrative, che le stesse siano mitigate nel caso di adesione, da parte del titolare del trattamento, ai meccanismi di certificazione adottati ai sensi dell’art. 42.

https://www.key4biz.it/certificazione-e-accreditamento-nellottica-del-gdpr/370309/




Venmo gets more private—but it’s still not fully safe

Venmo gets more private—but it’s still not fully safe
Getty Images

Venmo, the popular mobile payment service, has redesigned its app. That’s normally news you could safely ignore, but this announcement is worth a closer look. In addition to making some navigational tweaks and adding new purchase protections, the PayPal-owned platform is finally shutting down its global social feed, where the app published transactions from people around the world. It’s an important step toward resolving one of the most prominent privacy issues in the world of apps, but the work isn’t finished yet.

Venmo’s global feed has for years been a font of voyeuristic insights into the financial habits of total strangers. The feed doesn’t display amounts for a given transaction, but names and notes emoji and likes are included. Tapping on a name brings you to that user’s profile, and an enterprising busybody (or worse) could pretty quickly build a small dossier of that person’s friends, their hobbies, and anything else they’ve slipped into the stream—without, perhaps, realizing how public that info can be. In the time it took to write these paragraphs, relatives reimbursed each other for Phillies tickets, someone made a payment for “liquid gold 😍,” more than one set of roommates split their Internet bill.

The visibility of Venmo transactions and other user data has been criticized by privacy and consumer advocates for years. “This commitment to this weird corporate bit, this corporate DNA, of a social payment app is a huge liability,” says Gennie Gebhart, activism director at the Electronic Frontier Foundation, a digital rights group. “It’s not a disaster waiting to happen, it’s a disaster that’s already happened so many times to so many people.”

The most recent and most high-profile instance of where that openness can go wrong came in May, when a team of Buzzfeed reporters found President Joe Biden’s Venmo account, along with those of his family and close friends, simply by searching within the app. It took them 10 minutes.

At the time, even if your transaction history was locked down, your friends list was fair game for anyone to find. Which, again, seems a little unwise for an app built around the often sensitive business of sending and receiving money. Two weeks after the Buzzfeed report, however, Venmo added new privacy controls, letting you make your list of contacts on the app private for the first time.

The removal of the global feed extends that work by making it incrementally harder to snoop on total strangers. Soon, the social element of the app will be limited to what your Venmo contacts are up to. “This change allows customers to connect and share meaningful moments and experiences with the people who matter most,” the company said in a blog post announcing the redesign. While it certainly counts as progress, privacy advocates believe it doesn’t go far enough.

“Venmo’s finally getting the message that maximum publicity on a financial app is a terrible idea,” says Kaili Lambe, senior campaigner at the Mozilla Foundation, a nonprofit focused on Internet openness and accessibility. “However, from the beginning we have been calling on Venmo to be private by default, because so many Venmo users don’t actually know that their transactions are public to the world.”

After Venmo's impending redesign, the only feed will be that of transactions from your Friends list.
After Venmo’s impending redesign, the only feed will be that of transactions from your Friends list.

A Venmo spokesperson said the company has no plans at this time to consider making those transactions private by default. That means users will still need to go out of their way to make sure their every peer-to-peer transaction isn’t broadcast to the world. It’s hard to see the benefit of maintaining the status quo.

“You think of a lot of really sensitive use cases,” says Gebhart. “You think about therapists, you think about sex workers. You think about the president of the United States. It doesn’t take a big imagination to imagine places where these defaults could go horribly wrong and cause real harm to real people.”

The implications of Venmo’s public-by-default stance have played out beyond the discovery of Biden’s account. In 2018, privacy advocate and designer Hang Do Thi Duc used Venmo’s public API to sort through nearly 208 million transactions on the platform, piecing together alarmingly detailed portraits of five users based only on their activity in the app. The following year, programmer Dan Salmon wrote a 20-line Python script that let him scrape millions of Venmo payments in a matter of weeks.

Venmo has since placed restrictions on the rate at which you can access transaction data through the public API, but Salmon says the company hasn’t gone far enough. “Venmo basically had a firehose I could connect to of transaction data,” he says. “Now that that is cut off, the transactions are still out there; it will just take a few more steps to go get them.” He says it would take about an hour of work to build a new scraping tool.

“At Venmo, we routinely assess our technical protocols as part of our commitment to platform security and continually improving the Venmo experience for our customers. Scraping Venmo is a violation of our terms of service, and we actively work to limit and block activity that violate these policies,” Venmo spokesperson Jaymie Sinlao wrote in an emailed statement. “We continue to enable select access to our existing APIs for approved developers to continue innovating and building upon the Venmo platform.”

Venmo is far from the only app that makes you opt out of sharing rather than actively seeking it out. But because its use case is exclusively financial, the stakes are significantly higher, and the assumption of its users potentially misplaced. Venmo hasn’t made it especially easy for users to figure out what they are or are not sharing; in 2018 it reached a settlement with the Federal Trade Commissions related in part to its confusing privacy settings.

“Anecdotally, people are very surprised to find that a financial services app is public by default,” says the Mozilla Foundation’s Lambe. “Even people who’ve been using Venmo for years might not know that their settings are public.”

To make sure that yours aren’t going forward, head to Settings > Privacy and select Private. Then tap Past Transactions, and tap Change All to Private to lock things down retroactively. And while you’re at it, go ahead and tap Friends List, then tap Private and toggle off Appear in other users’ friends list. Otherwise, you’re sharing the digital equivalent of your credit card purchases with everyone you know, and lots of people you don’t. Or consider using something like Square’s Cash App instead, which is private by default.

Losing the global feed is an important step toward privacy for Venmo and its users. Hopefully, more steps are still to come.

This story originally appeared on wired.com.

https://arstechnica.com/?p=1782606