Europe and the United States will use a thaw in ties to strike a pact that would allow for the exchange of private data across the Atlantic, replacing previous agreements struck down by an EU court.
Facebook, Google, Microsoft and thousands of other companies want such a deal to keep the internet traffic flowing without facing significant legal jeopardy over European privacy laws.
Last year, the European Court of Justice “raised important questions on how to ensure protection of privacy when data crosses the Atlantic,” EU Justice Commissioner Didier Reynders said in a speech to the American Chamber of Commerce to the EU.
“Finding this solution is a priority in Brussels and in Washington DC,” he added a day after stepping up talks with US Commerce Secretary Gina Raimondo.
As “like-minded partners” the two sides “should be able to find appropriate solutions on principles that are cherished on both sides of the Atlantic,” he said.
The third attempt for a new data arrangement would succeed deals that were invalidated after succesful lawsuits arguing that US security laws violated the fundamental rights of EU citizens.
The legal onslaught was led by Max Schrems, an Austrian activist and lawyer who began his campaign after the revelations by Edward Snowden of mass digital spying by US agencies.
Businesses have since resorted to legally uncertain workarounds to keep the data flow moving, with hope that the two sides could come up with something stronger in the long term.
Reynders said a deal would require that “complex and sensitive” issues are solved “that relate to the delicate balance between national security and privacy”.
The deal would have to cover important issues, including guarantees of access to courts and clearly enforceable individual rights.
“The only way to achieve this is to develop a new arrangement that is fully compliant with the (EU court’s) Schrems II judgement. This is in our mutual interest,” Reynders added.
The EU has concluded similar agreements with 12 entities and countries, including Japan, Switzerland, Canada, Israel, and is in the process of concluding negotiations with South Korea.
In February, Brussels gave an initial green light to the transfer of personal data to the UK, which left the EU’s direct jurisdiction this year after a post-Brexit transition period.
Facebook finally explains its mysterious new wrist wearable
Enlarge/ Facebook is developing a wrist-worn wearable that senses nerve activity that controls your hands and fingers. The design could enable new types of human-computer interactions.
It first appeared on March 9 as a tweet on Andrew Bosworth’s timeline, the tiny corner of the Internet that offers a rare glimpse into the mind of a Facebook executive these days. Bosworth, who leads Facebook’s augmented and virtual reality research labs, had just shared a blog post outlining the company’s 10-year vision for the future of human-computer interaction. Then, in a follow-up tweet, he shared a photo of an as yet unseen wearable device. Facebook’s vision for the future of interacting with computers apparently would involve strapping something that looks like an iPod Mini to your wrist.
Facebook already owns our social experience and some of the world’s most popular messaging apps—for better or notably worse. Anytime the company dips into hardware, then, whether that’s a very good VR headset or a video chatting device that follows your every move, it gets noticed. And it not only sparks intrigue, but questions too: why does Facebook want to own this new computing paradigm?
In this case, the unanswered questions are less about the hardware itself and more about the research behind it—and whether the new interactions Facebook envisions will only deepen our ties to Facebook. (Answer: probably.) In a media briefing earlier this week, Facebook executives and researchers offered an overview of this tech. In simplest terms, Facebook has been testing new computing inputs using a sensor-filled wrist wearable.
It’s an electromyography device, which means it translates electrical motor nerve signals into digital commands. When it’s on your wrist, you can just flick your fingers in space to control virtual inputs, whether you’re wearing a VR headset or interacting with the real world. You can also “train” it to sense the intention of your fingers, so that actions happen even when your hands are totally still.
Enlarge/ Facebook’s vision for its wrist-worn device includes being able to type on a virtual desktop keyboard.
This wrist wearable doesn’t have a name. It’s just a concept, and there are different versions of it, some of which include haptic feedback. Bosworth says it could be five to 10 years before the technology becomes widely available.
All of this is tied to Facebook’s plans for virtual and augmented reality, technologies that can sometimes leave the user feeling a distinct lack of agency when it comes to their hands. Slip on a VR headset and your hands disappear completely. By picking up a pair of hand controllers, you can play games or grasp virtual objects, but then you lose the ability to take notes or draw with precision. Some AR or “mixed reality” headsets like Microsoft’s HoloLens have cameras that track spatial gestures, so you can use certain hand signals and the headset will interpret those signals … which sometimes works. So Facebook has been using this EMG wearable in its virtual reality lab to see if such a device might enable more precise hand-computer interactions.
But Facebook has visions for this wrist tech beyond AR and VR, Bosworth says. “If you really had access to an interface that allowed you to type or use a mouse—without having to physically type or use a mouse, you could use this all over the place.” The keyboard is a prime example, he says; this wrist computer is just another means of intentional input, except you can carry it with you everywhere.
Bosworth also suggested the kitchen microwave as a use case—while clarifying that Facebook is not, in fact, building a microwave. Home appliance interfaces are all different, so why not program a device like this to understand, simply, when you want to cook something for 10 minutes on medium power?
In the virtual demo Facebook gave earlier this week, a gamer was shown wearing the wrist device and controlling a character in a rudimentary video game on a flat screen, all without having to move his fingers at all. These kinds of demos tend to (pardon the pun) gesture toward mind-reading technology, which Bosworth insisted this is not. In this case, he said, the mind is generating signals identical to the ones that would make the thumb move, but the thumb isn’t moving. The device is recording an expressed intention to move the thumb. “We don’t know what’s happening in the brain, which is full of thoughts, ideas, and notions. We don’t know what happens until someone sends a signal down the wire.”
Bosworth also emphasized that this wrist wearable is different from the invasive implants that were used in a 2019 brain-computer interface study that Facebook worked on with the University of California at San Francisco; and it’s different from Elon Musk’s Neuralink, a wireless implant that could theoretically allow people to send neuroelectrical signals from their brains directly to digital devices. In other words, Facebook isn’t reading our minds, even if it already knows a heck of a lot about what’s going on in our heads.
Researchers say there’s still a lot of work to be done in the area of using EMG sensors as virtual input devices. Precision is a big challenge. Chris Harrison, the director of the Future Interfaces Group in the Human-Computer Interaction Lab at Carnegie Mellon University, points out that each individual human’s nerves are a little bit different, as are the shapes of our arms and wrists. “There’s always a calibration process that has to happen with any muscle-sensing system or BCI system. It really depends on where the computing intelligence is,” Harrison says.
And even with haptic feedback built into these devices, as Facebook is doing with some of its prototypes, there’s the risk of visuo-haptic mismatches, where the user’s visual experience—whether in AR, VR, or real space—does not correlate to the haptic response. These points of friction can make these human-computer interactions all feel frustratingly unreal.
Even if Facebook can overcome these obstacles in its research labs, there’s still the question of why Facebook—largely a software company—wants to own this new computing paradigm. And should we trust it? This hugely powerful tech company that has a track record of sharing user data in “exchange for other equally or more valuable things,” as WIRED’s Fred Vogelstein wrote in 2018? A more recent report in MIT Technology Review highlights how a team at Facebook assembled to tackle “responsible AI” was undermined by leadership’s relentless quest for growth.
Facebook executives said this week that these new human-computer interaction devices will perform as much computing as possible “on device,” which means the information isn’t shared to the cloud; but Bosworth won’t commit to how much data ultimately might be shared to Facebook or how that data will be used. The whole thing is a prototype, so there’s nothing substantive to tease apart yet, he says.
“Sometimes these companies have cash piles large enough to basically invest in these huge R&D projects, and they’ll take a loss on such things if it means they can be front-runners in the future,” says Michelle Richardson, director of the Data and Privacy Project at the nonprofit Center for Democracy and Technology. “But with companies of any size, any product, once it’s built, it’s so difficult to overhaul it. So anything that can start the conversation on this before the devices are built is a good thing.”
Bosworth says Facebook wants to lead this next paradigm shift in computing because the company sees tech like this as fundamental to connecting people. If anything, this past year has shown us the importance of connecting—of feeling like you’re in person, Bosworth says. He also seems to believe he can earn the required trust by not “surprising” customers. “You say what you do, you set expectations, and you deliver on those expectations over time” he says. “Trust arrives on foot and leaves on horseback.” Rose-colored AR glasses, activated.
Zuckerberg: Facebook could be in “stronger position” after Apple tracking change
Apple CEO Tim Cook on stage during an Apple event in September 2018.
With Apple’s big app-tracking policy change just around the corner, Chinese companies drew a warning from Cupertino that their efforts to circumvent the change will not be successful. At the same time, Facebook CEO Mark Zuckerberg appeared to shift his messaging about the change.
Several months ago, Apple announced that it will require user opt-in for IDFA (Identifier for Advertisers), a tool that advertisers use to identify and track users across apps and websites. If users opt in, it will be business as usual. But if they decline, the app in question will not be able to use that tracking method. The change will apply to all iPhone and iPad apps, and it will take full effect in iOS 14.5, which is due out sometime in the next few weeks.
ByteDance, Baidu, and others push back
Press coverage so far has focused on US and European countries grappling with the change, particularly Facebook, which ran ads and looked into the possibility of an antitrust lawsuit to battle Apple’s decision. Several reports over the past few days have indicated that some major Chinese tech companies are no less determined to fight or get around Apple’s new policy.
Baidu, Tencent, and ByteDance are among the Chinese tech companies seeking workarounds. Bloomberg reports that these companies have sought multiple ways to collect data and track users despite Apple’s policy, including fingerprinting, “which uses device-specific information such as the IMEI number and location to create a unique identifier.” And they are also testing a system called CAID. Developed by a government think tank and the China Advertising Association, this system can be used “as a substitute if the user’s IDFA is unavailable.”
The companies’ efforts led Apple to release a statement clarifying that the upcoming changes apply to all apps from companies around the world, not just those developed and maintained in the United States:
The App Store terms and guidelines apply equally to all developers around the world, including Apple. We believe strongly that users should be asked for their permission before being tracked. Apps that are found to disregard the user’s choice will be rejected.
The actions of these companies nonetheless threaten to put Apple in a difficult position. China accounts for at least 15 percent of Apple’s business. Although it’s too early to make absolute predictions and it depends on the role the Chinese government chooses to play here, it is plausible that this situation could escalate to the point where Apple would have to make a decision about continuing to do business there or changing course to make special ad tracking rules for that country that differ from those in place in other regions.
Zuckerberg changes tune
Speaking in a Clubhouse chat on Thursday, Zuckerberg took a more positive stance regarding Facebook’s ability to thrive with the upcoming change. “We’ll be in a good position,” he said. “We’ll be able to manage through.”
Facebook had previously run full-page newspaper ads suggesting Apple’s change could mortally wound countless small businesses, and Facebook CFO David Wehner posited last year that the change would lead to a 50% drop for its lucrative Audience Network advertising business.
Zuckerberg also took an aggressive initial stance against the change in the company’s last quarterly earnings call, and The Information reported that he was working with legal counsel to build an antitrust case against Apple as a way to battle the policy shift.
But yesterday, Zuckerberg went so far as to say:
It’s possible that we may even be in a stronger position if Apple’s changes encourage more businesses to conduct more commerce on our platforms by making it harder for them to use their data in order to find the customers that would want to use their products outside of our platforms.
While the messaging differs, the companies’ planned actions don’t seem likely to change. Apple will still begin requiring Facebook’s apps ask users for permission to track them, and Facebook still plans on acquiescing to the change so it can keep making its apps and services available to iOS users.
https://arstechnica.com/?p=1750949
One company wants to sell the feds location data from every car on Earth
Enlarge/ Cars driving down I-80 in Berkeley, California, in May, 2018 when there were still places to go.
There is a strange sort of symmetry in the world of personal data this week: one new report has identified a company that wants to sell the US government granular car location data from basically every vehicle in the world, while a group of privacy advocates is suing another company for providing customer data to the feds.
A surveillance contractor called Ulysses can “remotely geolocate vehicles in nearly every country except for North Korea and Cuba on a near real-time basis,” Vice Motherboard reports.
“Among the thousands of other data points, vehicle location data is transmitted on a constant and near real-time basis while the vehicle is operating,” the company wrote in a sales pitch document obtained by Vice. As roughly 100 million new cars are manufactured worldwide each year that are “increasingly connected to the manufacturer, other vehicles, infrastructure, and their owners, it becomes apparent that telematics will revolutionize intelligence,” the document adds. Ulysses claims it can currently access more than 15 billion vehicle locations around the world every month, and it estimates that by 2025, 100 percent of new cars will be connected and transmitting gigabytes of collectible data per hour.
Vice said the office of Sen. Ron Wyden (D-Ore.), who serves on the Senate Intelligence Committee and often advocates for privacy issues, provided it with the document. “Sen. Wyden is conducting an ongoing investigation into the sale of personal data, particularly via data brokers, to put some sunlight on this shady industry,” Keith Chu, a representative for Wyden’s office, told Vice. “Our office is continuing to perform oversight into where data brokers are acquiring Americans’ information and who they’re selling it to.”
Ulysses does not currently have any contracts with the US government but has worked in the past with US Special Operations Command (SOCOM), Vice reports. That contract, which ran from 2016-2017, involved data SOCOM used “to deepen our understanding on how foreign competitors used economic and financial tools against US interests” in Central and South America and in Africa.
Meanwhile, in California…
If Ulysses does snag a federal contract, it would be joining a long line of other firms that sell personal user data to the government.
The Washington Post reported last month that ICE also purchased access to a database chock-full of consumer information to track immigrants. The database ICE used, CLEAR, includes more than 400 million phone, water, electricity, and other utility documents the agency would otherwise not have been able to access on its own, according to the Post.
A coalition of privacy advocates in California is now suing Thomson Reuters, which operates CLEAR, alleging that it violates state privacy law by collecting and sharing personal information without individuals’ consent.
“When we look at the ways that these data brokers are remaking our country, the Fourth Amendment concerns are terrifying,” Surveillance Technology Oversight Project Executive Director Albert Fox Cahn, who is participating in the suit, told the Post. “But the way that they’re allowing companies to track millions without the most basic consent is deeply alarming as well.”
Sen. Wyden also told the Post he plans to introduce federal legislation soon to close the loopholes that allow such data sales. “I do think that there’s going to be a new focus on privacy in this session,” Wyden said. “I think as more and more states pass privacy legislation, pressure builds for Congress to finally pass federal legislation.”
https://arstechnica.com/?p=1750420
Research: Security Agencies Expose Information via Improperly Sanitized PDFs
Most security agencies fail to properly sanitize Portable Document Format (PDF) files before publishing them, thus exposing potentially sensitive information and opening the door for attacks, researchers have discovered.
An analysis of roughly 40,000 PDFs published by 75 security agencies in 47 countries has revealed that these files can be used to identify employees who use outdated software, according to Supriya Adhatarao and Cédric Lauradoux, two researchers with the University Grenoble Alpes and France’s National Institute for Research in Computer Science and Automation (Inria).
The analysis also revealed that the adoption of sanitization within security agencies is rather low, as only 7 of them used it to remove hidden sensitive information from some of their published PDF files. What’s more, 65% of the sanitized files still contained hidden data.
“Some agencies are using weak sanitization techniques: it requires to remove all the hidden sensitive information from the file and not just to remove the data at the surface. Security agencies need to change their sanitization methods,” the academic researchers say.
PDF files, the researchers note, represent collections of indirect objects (eight types of objects: arrays, boolean, dictionaries, names, numbers, streams, strings, and the null object) that are used to store data. These objects may include hidden data not visible when viewing the PDF.
Per the NSA, there are 11 main types of hidden data in PDF files, namely metadata; embedded content and attached files; scripts; hidden layers; embedded search index; stored interactive form data; reviewing and commenting; hidden page, image and update data; obscured text and images; PDF comments that are not displayed; and unreferenced data.
Metadata associated with images within a PDF file can be used to gather information about the author, the same as comments and annotations that haven’t been removed before publishing, and PDF metadata.
There are several tools that can be used for sanitizing PDF files, including Adobe’s Acrobat, and there are four levels of sanitization: Level-0: full metadata (no sanitization), Level-1: partial metadata, Level-2: no metadata, and Level-3: properly cleaned files (full sanitization, with all objects having been removed).
For their research, the academics used a set of 39,664 PDF files. Of these, 1,783 (4%) were found to include author name, 30,155 (76%) contained metadata on the PDF producer tool, and 16,805 (42%) revealed the operating system used.
The files also leaked email addresses – including official ones – (in 52 files), hardware brand (581 files), and paths (1,814 PDFs).
“During our analysis we observed that many agencies include more than one author publishing the PDF files. It is possible to download all the PDF files published on a security agency’s website and observe the author habits, OS trends,” the researchers note.
The analysis also allowed for the identification of 159 employees at 19 agencies that haven’t updated tools over a period of two years, which could be abused by threat actors in targeted attacks, especially since nearly half of the PDF files leaked operating system data.
While 9,509 (24%) of the analyzed PDF files have been sanitized before publishing, only 3,313 (8%) were sanitized with Level-3. The researchers note that only 3 agencies out of 7 that appear to care about sanitization are doing it properly.
“The issue is that popular PDF producer tools are keeping metadata by default with many other information while creating a PDF file. They provide no option for sanitization or it can only be achieved by following a complex procedure. Software producing PDF files need to enforce sanitization by default. The user should be able to add metadata only as an option,” the academics conclude.
Sorveglianza di massa per gli utenti di internet, sotto accusa gli Affari Interni britannici
La navigazione di internet non è mai davvero in solitaria, abbiamo imparato nel tempo che ci può sempre essere qualcuno che ci spia, che ci segue più o meno di nascosto. Sappiamo anche, in linea di massima, chi può essere questo qualcuno e a volte è lo Stato.
Sorveglianza di massa su internet
Negli ultimi due anni, nel Regno Unito, l’Home Office, il ministero degli Affari Interni (omologo del nostro ministero dell’Interno), sta sperimentando diversi sistemi e strumenti di raccolta dati sulle attività dei cittadini online, per quello che le associazioni di attivisti per i diritti di internet e per la difesa della privacy hanno chiamato senza mezzi termini: “un sistema di sorveglianza di massa statale”.
<!-- LARGE RECTANGLE POST - CORPO TESTO
-->
Sostanzialmente, secondo l’accusa, lo Stato avrebbe costruito e testato silenziosamente una tecnologia di sorveglianza in grado di registrare e memorizzare la navigazione web di ogni singola persona in tutto il Paese per poi dare vita a dei “record di dati segreti”.
I primi test sarebbero partiti nel 2019.
L’accusa
Gli attivisti dell’Open Rights Group denunciano una campagna governativa di “raccolta e conservazione di massa di dati su quello che i cittadini fanno su internet”, in piena violazione delle leggi sulla privacy, senza la minima trasparenza necessaria in questo tipo di operazioni, almeno per non destare sospetti e timori tra la popolazione.
Tutto è nato da un Rapporto esclusivo pubblicato su Wired UK, in cui si delinea un piano dell’Home Office di monitoraggio di massa sull’utilizzo di internet, finalizzato al miglioramento dei livelli di sicurezza nazionale e di operatività delle Forze dell’Ordine nella lotta al crimine organizzato e al terrorismo interno ed internazionale.
Secondo il documento, gli Affari Interni stanno collaborando con la National Crime Agency per raccogliere numerosi “record di connessione Internet” (o ICR), che contengono informazioni sui siti web visitati da parte degli utenti, su cosa è stato visto e scaricato.
La difesa
Sull’argomento, l’Home Office ha dichiarato pubblicamente che si tratta di una raccolta di metadati, non riferibili a nessuno in particolare, neanche riferibili a contenuti specifici che si sono selezionati nella ricerca, o alle stesse pagine web navigate.
La sperimentazione portata avanti dal Governo ha coinvolto due provider nazionali e si fa scudo dell’Investigatory Powers Act 2016, con l’obiettivo di capire come raccogliere i dati sull’utilizzo di internet da parte dei cittadini, quali dati raccogliere e come poterli usare nelle indagini di polizia.
Dei principali provider internet del Regno Unito, solo Vodafone ha confermato di non essere coinvolta in alcun test che implichi l’archiviazione dei dati di navigazione riferibili a singoli cittadini. I portavoce di BT, Tre e Virgin Media, invece, si sono rifiutati di fornire commenti su qualsiasi tipo di azione riferibile all’IPA.
Data Privacy Management Firm DataGrail Raises $30 Million
California-based data privacy management company DataGrail this week announced that it raised $30 million in a Series B funding round.
The company previously raised $5.2 million in a Series A round in 2019. The latest funding round was led by Felicis Ventures, with participation from HubSpot, Okta, Next47 (venture firm backed by Siemens), Basis Set Ventures, Operator Collective, and previous investors.
DataGrail provides a platform designed to help organizations simplify, automate and scale their privacy programs. The platform, which automates data subject requests, is powered by a live data map that enables customers to know exactly where data lives on their systems, with any changes being automatically reflected.
DataGrail provides integration with more than 900 apps and infrastructure, and integrations are maintained by the company itself.
The company says its services are used by millions of consumers through firms such as Overstock, RH, Databricks and Outreach.
“Privacy laws, like CCPA and GDPR, give people the right to have their data deleted, or refuse its sale, but modern organizations are ill-prepared for the Privacy Era,” said Daniel Barber, CEO and co-founder of DataGrail. “To combat the massive privacy challenges businesses face today, we’ve built a platform that makes it remarkably easy to untangle what’s become a spider web of data across the entire tech stack. DataGrail elegantly solves this near-impossible task for organizations that want to do right by their customers.”
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Facial Recognition Company Sued by California Activists
Civil liberties activists are suing a company that provides facial recognition services to law enforcement agencies and private companies around the world, contending that Clearview AI illegally stockpiled data on 3 billion people without their knowledge or permission.
The lawsuit, filed Tuesday in Alameda County Superior Court in the San Francisco Bay Area, contends that the New York-based firm violates California’s constitution and seeks an injunction to bar it from collecting biometric information in California and requiring it to delete data on Californians.
The lawsuit says the company has built “the most dangerous” facial recognition database in the nation, has fielded requests from more than 2,000 law enforcement agencies and private companies, and has amassed a database nearly seven times larger than the FBI’s.
The lawsuit was filed by four activists and the groups Mijente and Norcal Resist, who have supported causes such as Black Lives Matter and have been critical of the policies of U.S. Immigration and Customs Enforcement, which has a contract with Clearview AI.
“Clearview has provided thousands of governments, government agencies, and private entities access to its database, which they can use to identify people with dissident views, monitor their associations, and track their speech,” the lawsuit contends.
The lawsuit said Clearview AI scrapes dozens of internet sites, such as Facebook, Twitter, Google and Venmo, to gather facial photos. Scraping involves the use of computer programs to automatically scan and copy data, which the lawsuit says is analyzed by Clearview AI to identify individual biometrics such as eye shape and size that are then put into a “faceprint” database that clients can use to ID people.
The images scraped include those posted not only by individuals and their family and friends but also those of people who are inadvertently captured in the background of strangers’ photos, according to the lawsuit.
The company also offers its services to law enforcement even in cities that ban the use of facial recognition, the lawsuit alleges.
Several cities around the country, including the Bay Area cities of Alameda, San Francisco, Oakland and Berkeley, have limited or banned the use of facial recognition technology by local law enforcement.
“Clearview AI complies with all applicable law and its conduct is fully protected by the First Amendment,” said a statement from attorney Floyd Abrams, representing the company.
The company has said it saw law enforcement use of its technology jump 26% following January’s deadly riot at the U.S. Capitol.
Facial recognition systems have faced criticism because of their mass surveillance capabilities, which raise privacy concerns, and because some studies have shown that the technology is far more likely to misidentify Blacks and other people of color than whites, which has resulted in mistaken arrests.
However, Clearview AI’s CEO, Hoan Ton-That, said in a statement that “an independent study has indicated the Clearview AI has no racial bias.”
“As a person of mixed race, having non-biased technology is important to me,” he said.
He also argued that the use of accurate facial recognition technology can reduce the chance of wrongful arrests.
The lawsuit said Facebook, Twitter, Google and other social media firms have asked Clearview AI to stop scraping images because it violated their terms of service with users.
Clearview AI also is facing other challenges. A lawsuit filed in Illinois alleges the company violates that state’s biometric privacy act, while privacy watchdogs in both Canada and the European Union have issued statements of concern.
Clearview stopped operations in Canada last year. But privacy commissioners this year asked the firm to remove data on Canadian citizens, with one commissioner arguing that the system puts all Canadians “continually in a police lineup.”
Patient data protection provider Tausight this week announced that it has raised $20 million in Series A funding.
The new funding, Tausight says, will help expand the go-to-market team and invest in a healthcare-specific solution designed to identify security flaws in clinical workflows.
The new funding round was co-led by existing investors Polaris Partners and Flare Capital Partners. New investor .406 Ventures also participated.
Founded in 2018 and based in Boston, Mass., Tausight aims to help organizations ensure the confidentiality, integrity, and availability of patients’ protected health information (PHI).
Tausight’s offerings help healthcare provider CIOs, CISOs, and IT organizations understand the risk associated with the manner in which PHI is used, and help them secure access to clinical workflows and PHI.
“Existing cybersecurity solutions address critical aspects of securing the healthcare IT system but are not adequately addressing hidden vulnerabilities found in clinical workflows – Tausight was created to close this gap and solve this vital problem,” Tausight CEO Dave Dickinson said.
Chrome, i cookie di terze parti e il gioco delle tre carte di Google
La rubrica “Digital & Law” è curata da D&L Net e offre una lettura delle materie dell’innovazione digitale da una prospettiva che sia in grado di offrire piena padronanza degli strumenti e dei diritti digitali, anche ai non addetti ai lavori. Per consultare tutti gli articoli clicca qui.
Articolo dell’avv. Mario Montano di Studio Legale Lisi- Componente del D&L Net
Il così chiacchierato addio di Chrome ai cookies di terze parti a partire dal 2022 non è una novità assoluta. Infatti era un’azione già conosciuta da anni, basti pensare a Safari di Apple e Firefox Focus della Mozilla Foundation che bloccano di default i cookies di terze parti.
<!-- LARGE RECTANGLE POST - CORPO TESTO
-->
Google e l’addio ai cookie di terze parti su Chrome
La vera notizia è semmai che la società che detiene il monopolio delle attività di advertising, Google, ha deciso di rinunciare allo strumento più utilizzato dalle società pubblicitarie per tracciare gli utenti, profilarli e scambiare la loro esperienza sul web, le loro impression, nei Real Time Bidding (RTB), le aste in tempo reale degli spazi pubblicitari online. Bisogna chiarire che i cookie sono solo uno degli strumenti utilizzati per tracciare e profilare gli utenti e che oggi, con un po’ di esperienza, è possibile bloccare quasi del tutto. Inoltre, altri e più sofisticati strumenti sono stati sviluppati negli ultimi anni, come: local storage; indexedDB; webSQL; Service worker.
Quest’ultimo merita un breve approfondimento.
Service worker
È uno script eseguito in background dal browser, integratosi con le Progressive Web App (PWA), un ibrido a metà strada tra una pagina web e un’applicazione nativa. Questo permette di gestire le notifiche push, la sincronizzazione in background e il salvataggio dei dati in locale, che consente la navigazione offline. Fra non molto il service worker permetterà di implementare nelle PWA nuove e più pervasive funzionalità, come la geofencing e la sincronizzazione periodica.
Google ha chiarito che se la pubblicità digitale non evolve verso un modello che tenga conto delle crescenti preoccupazioni degli utenti rispetto alla protezione dei dati personali, a rischio è il futuro stesso del web libero e gratuito così come si presenta oggi. Secondo Google, infatti, bloccare i cookie di terze parti favorisce l’uso opaco e fraudolento del fingerprinting, metodo che consente di creare un profilo unico dell’utente basato sull’hardware, il software, i componenti aggiuntivi e perfino le preferenze del browser, tracciando l’utente per mesi, anche dopo aver eliminato i dati del browser o aver scelto di navigare in modalità anonima, ignorando le indicazioni dell’utente sul fatto di non voler essere tracciato.
Per conservare la asserita gratuità, libertà del web e al contempo rispettare la privacy degli utenti, Google ha avviato Sandbox Privacy, un progetto aperto agli stakeholder e alle autorità di regolamentazione che si propone di sviluppare un ecosistema privacy-oriented.
Non solo Privacy
Uno dei componenti del SendBox è la Federated Learing Technology, tecnologia di IA basata sulla machine learning. L’intento è di utilizzare la cronologia di Chrome per creare dei raggruppamenti omogeni degli utenti, i quali vengono successivamente assegnati a un gruppo chiamato “flock”. Ogni utente sarà in seguito identificato con il proprio flock name, che lo colloca all’interno del gruppo di utenti con le medesime caratteristiche.
Il tentativo di Google di superare la profilazione fondata sui cookie di terze parti con un sistema di clusterizzazione degli utenti, se da una parte potrebbe garantire una maggiore protezione dei dati personali, dall’altra rischia di esacerbare le discriminazioni già presenti nella targhettizzazione. Non è, quindi, solo una questione di privacy: la profilazione per gruppi omogeni di utenti permetterebbe comunque agli inserzionisti di utilizzare le caratteristiche etniche, i convincimenti politici o religiosi, il genere o l’età per inviare pubblicità mirata e potenzialmente discriminatoria. Non solo, si rischierebbe di agevolare e potenziare tutte quelle attività tese a influenzare il pensiero politico delle masse, confinando in bolle sempre più omogenee e isolate gli utenti con caratteristiche simili, rappresentando un rischio concreto per i principi democratici.
Nella recente Risoluzione del Parlamento europeo del 20 ottobre 2020 recante “raccomandazioni alla Commissione concernenti il quadro relativo agli aspetti etici dell’intelligenza artificiale, della robotica e delle tecnologie correlate”, si ricorda che “l’analisi dei dati e l’IA influenzano sempre di più le informazioni rese accessibili ai cittadini” e che “tali tecnologie, se utilizzate impropriamente, possono mettere in pericolo i diritti fondamentali alla libertà di espressione e all’informazione, nonché la libertà e il pluralismo dei mezzi di comunicazione”[1]. Il Parlamento europeo auspica uno sviluppo antropocentrico delle soluzioni di IA, a tutela della dignità, dell’autonomia e della sicurezza umane.
Chrome: il gioco delle tre carte di Google
Quella di Google non è una crociata contro l’uso spregiudicato e disinvolto dei cookie di terze parti o il fingerprinting come vorrebbe farci credere, quanto, piuttosto, forse una strategia ben congegnata per continuare a fare profitti con l’advertising, settore nel quale è e vuole rimanere leader, sviluppando tecnologie, come le PWA e sistemi di IA in grado di offrire all’utente servizi più rapidi ed efficienti, ma, al contempo, raccogliendo in maniera sempre più opaca e insondabile i suoi dati, accrescendo, come detto, il rischio di discriminazioni.
Un gioco delle tre carte quello di Google che, di fronte a una maggiore consapevolezza degli utenti e una legislazione sempre più rigorosa sull’uso di cookie di terze parti e sulla profilazione in rete, “sceglie di cambiare rotta perché nulla cambi”, forte della posizione dominante di Chrome.
E se iniziassimo a scegliere servizi più rispettosi dei diritti degli utenti? Le alternative non mancano e alla fine una buona conoscenza ed informazione potrebbe far vacillare Big G.