iOS 14 privacy settings will tank ad targeting business, Facebook warns

iOS 14 privacy settings will tank ad targeting business, Facebook warns

Facebook is warning developers that privacy changes in an upcoming iOS update will severely curtail its ability to track users’ activity across the entire Internet and app ecosystem and prevent the social media platform from serving targeted ads to users inside other, non-Facebook apps on iPhones.

The next version of Apple’s mobile operating system, iOS 14, is expected to hit an iPhone near you this fall. Along with its many new consumer-facing features, iOS 14 requires app developers to notify users if their app collects a unique device code, known as an IDFA (ID for Advertisers).

The IDFA is a randomly generated code that Apple assigns to a device. (Google assigns similar numbers to Android devices.) Apps can then use those codes to tie together user activity. For example, Facebook, a local shopping app, and a local weather app might all access that identifier. Facebook and other advertising businesses can then use that cross-app use data to place targeted ads for advertisers on other apps, which is what Facebook does with its Audience Network program.

The changes requiring users to opt in make the IDFA essentially useless, Facebook warned developers today. Facebook apps on iOS 14—which includes Facebook, WhatsApp, Instagram, Messenger, and a host of others—will no longer collect users’ IDFA.

“Despite our best efforts, [the changes] may render Audience Network so ineffective on iOS 14 that it may not make sense to offer it on iOS 14 in the future,” Facebook further explained in a blog post. “Our ability to deliver targeted ads on iOS 14 will be limited… as a result, some iOS 14 users may not see any ads from Audience Network, while others may still see ads from us, but they’ll be less relevant.”

Less advertising means less money, Facebook added, saying, “Because of advertisers’ reduced ability to accurately target and measure their campaigns, app developers and publishers should expect lower CPMs [i.e., views of their ads] on Audience Network and likely other ad networks on iOS.”

“These updates have a far-reaching impact on the developer ecosystem,” Facebook noted, which is likely to be true. Facebook also seemed to indicate displeasure that Apple acted without first consulting Facebook about its preferences, saying, “We believe that industry consultation is critical for changes to platform policies… We look forward to continuing to engage” with industry and trade groups “to get this right for people and small businesses.”

The stakes

The company is almost certainly correct that users will not opt in to having their identifier tracked when presented with the option, and that absolutely will harm Facebook’s Audience Network business. Regulators and privacy advocates, however, may disagree with Facebook over whether that’s a bad thing.

Facebook is almost constantly under fire for how it handles different aspects of user privacy and user data. Last year it settled with the Federal Trade Commission for a record $5 billion penalty over a collection of allegations relating to users’ privacy.

Facebook’s ability to track anyone’s online activity, anywhere, and tie it together across software and platforms has been a large part of its advertising strategy since 2013, when it acquired a product called Atlas from Microsoft for around $100 million.

As Facebook described it at the time, the acquisition provided an “opportunity” for “marketers and agencies” to get “a holistic view of campaign performance” across “different channels.” In short, acquiring and building out that toolset—which has long since been fully integrated into Facebook’s advertiser platform—was Facebook’s key to finding the holy grail of online advertising. The company could finally track its effectiveness everywhere.

Meanwhile, the relationship between Facebook and Apple also appears to be growing more tense. Facebook last week followed in Epic Games’ footsteps to take a public swipe at Apple over the 30 percent fee Apple takes of any digital purchase made through an iOS app.

https://arstechnica.com/?p=1701438




La figlia 13enne di Totti in copertina, il Garante privacy ai media: “Evitare dannose esposizioni”

Interviene il Garante privacy sulle foto di Chanel Totti – in costume e con il volto pixelato sulla spiaggia assieme a papà pubblicate in copertina sul periodico Gente – che hanno fatto infuriare i genitori, Francesco Totti e Ilary Blasi.

Il Garante per la protezione dei dati personali ricorda a tutti i mezzi di informazione che la normativa sulla protezione delle informazioni personali in ambito giornalistico pone specifiche garanzie a tutela dei minori.

In particolare, al fine di tutelarne la personalità, il Garante ricorda che è richiesta l’adozione di particolari cautele volte ad evitare di esporre i minori alla diffusione delle informazioni che li riguardano, compresa la loro immagine, con conseguenze negative che possono riverberarsi sul loro sviluppo sereno all’interno del proprio contesto di vita. 

Il diritto del minore alla riservatezza deve essere sempre considerato come primario rispetto al diritto di critica e di cronaca

Il diritto del minore alla riservatezza, spiega il Garante, deve essere sempre considerato come primario rispetto al diritto di critica e di cronaca. Anche qualora, per motivi di rilevante interesse pubblico e fermo restando i limiti di legge, il giornalista decida di diffondere notizie o immagini riguardanti minori, dovrà farsi carico della responsabilità di valutare se la pubblicazione sia davvero nell’interesse oggettivo del minore, secondo i principi e i limiti stabiliti dalla “Carta di Treviso” (art. 7 – Regole deontologiche relative al trattamento di dati personali nell’esercizio dell’attività giornalistica pubblicate sulla Gazzetta Ufficiale n. 3 del 4 gennaio 2019).

La reazione dei genitori

Le foto hanno scatenato una dura polemica da parte della famiglia Totti. “Ringrazio il direttore Monica Mosca – hanno scritto su Instagram Francesco Totti e Ilary Blasi – per la sensibilità dimostrata mettendo in copertina il lato B di mia figlia minorenne senza curarsi del problema sempre più evidente della sessualizzazione e mercificazione del corpo delle adolescenti”.
Risponde parlando con l’ANSA la stessa Monica Mosca, che ha ricevuto dei riconoscimento nella sua carriera per il suo impegno per le donne, non nascondendo il suo rammarico: “Sono molto dispiaciuta e amareggiata per le reazioni generate dalla pubblicazione sulla copertina di Gente numero 34 della foto di Francesco Totti e della figlia Chanel, scattate in spiaggia. Come direttore ho sempre inteso valorizzare le donne e più in generale sostenere i valori della famiglia: era l’intento anche di questa pubblicazione, in cui si è voluto semplicemente ritrarre la famiglia Totti in un momento di normalità. In alcun modo, ovviamente, abbiamo mai inteso uscire da questo obiettivo”.
Il presidente dell’Ordine dei giornalisti Carlo Verna, in accordo con il segretario Guido D’Ubaldo, ha deciso di procedere con la segnalazione al collegio di disciplina territoriale competente per di valutare la sussistenza di eventuali violazioni della Carta di Treviso.

https://www.key4biz.it/la-figlia-13enne-di-totti-in-copertina-il-garante-privacy-ai-media-evitare-dannose-esposizioni/318607/




Un anno senza Giovanni Buttarelli. L’inedito ricordo dei suoi più stretti collaboratori “Il leader visionario dell’Ue”

Non era stato incluso, inizialmente, nella rosa dei candidati a Garante europeo per la protezione dei dati personali. Ad un anno dalla scomparsa di Giovanni Buttarelli, racconta questo episodio Leonardo Cervera Navas, che ha “lavorato con Giovanni o per Giovanni negli ultimi vent’anni”. 

Poi Buttarelli il 4 dicembre 2014 venne nominato Garante europeo della protezione dei dati (GEPD) dal Parlamento europeo e dal Consiglio dell’Unione Europea. “Ma”, scrive Cervera Navas, “le settimane e i mesi che hanno preceduto questo voto sono stati molto difficili per lui perché, in una di quelle decisioni inspiegabili della giuria prese dalla Commissione per le libertà civili, la giustizia e gli affari interni del Parlamento europeo, Giovanni, che era l’assistente supervisore del Garante, non era stato incluso nella rosa dei candidati (la procedura di selezione è stata successivamente annullata e ripubblicato il bando). 

Riesce a trovare poche parole, oggi, per ricordare Buttarelli chi ha preso il suo testimone.

“Il 20 agosto segna il primo anniversario del giorno più triste nella storia della nostra istituzione: è ancora difficile per me trovare le parole per descrivere i miei sentimenti provati quel giorno e per riassumere in qualche modo la nostra lunga amicizia con Giovanni.

Ho riletto il post che ho scritto un anno fa e continuo a sottoscrivere ogni parola”, così Wojciech Wiewiórowski, ex assistente supervisore di Buttarelli, nominato Garante europeo per la protezione dei dati il 6 dicembre scorso. 

“Il leader visionario dell’UE”

“Giovanni Buttarelli era e sarà, per me, il leader visionario dell’UE che ha sempre usato il motto ‘Thing Big!’, scrive Xanthi Kapsosideri dello staff legale dell’EDPS (European Data Protection Supervisor).

“Ha avuto il coraggio”, continua, “di portare Tim Cook (CEO di Apple) e Koen Lenaerts (Presidente della Corte di giustizia di UE) allo stesso tavolo e con il suo fascino e il suo sorriso umano, ha fatto loro riconoscere che la protezione dei dati è una preoccupazione primaria sia per le imprese sia per la giurisprudenza. L’apoteosi della sua ambiziosa e coraggiosa agenda visionaria è stata l’organizzazione della Conferenza internazionale Data Protection and Privacy Commissioners (ICDPPC) a Bruxelles. All’inizio di questa grande idea, nessuno ci credeva e nessuno lo incoraggiava. Fu così commosso ed emotivamente orgoglioso quando i suoi omologhi e altri collaboratori riconobbero l’enorme successo: alla conferenza presero parte più di 1.000 partecipanti e relatori prestigiosi”.

“Era richiesto ovunque sulla scena tecnologica”

“Il mio primo viaggio con lui fuori dall’Europa è stato a Washington, dove ho capito subito che poteva adattarsi a tutti i pubblici e le culture. Era richiesto ovunque sulla scena tecnologica e aveva un’opinione su tutto ciò che gli veniva chiesto”, è il ricordo di Olivier Rossignol, Responsabile dell’informazione e della comunicazione del Garante europeo della protezione dei dati.

“Nel mio lavoro della comunicazione esterna”, ha aggiunto, “Giovanni ha consentito all’EDPS di raggiungere nuove dimensioni. Il cielo era il limite. Abbiamo cambiato tutto, dal logo dell’istituto all’organizzazione della Conferenza internazionale dei Commissari per la protezione dei dati e la privacy (ICDPPC), compresa la creazione di un’app GDPR e di un nuovo sito web. Giovanni ha persino chiesto di contattare il cantante Stromae quando ha pubblicato la sua hit ‘Carmen’ sul lato oscuro dei social media“.

L’omaggio a Giovanni Buttarelli da parte dell’EDPS

[embedded content]

Un anno senza Giovanni Buttarelli. L’inedito ricordo dei suoi più stretti collaboratori “Il leader visionario dell’Ue”




College contact-tracing app readily leaked personal data, report finds

A surveillance camera mounted on a wall on a sunny day.
Enlarge / A surveillance camera mounted on a wall on a sunny day.
Thomas Winz / Getty

In an attempt to mitigate the potential spread of COVID-19, one Michigan college is requiring all students to install an app that will track their live locations at all times. Unfortunately, researchers have already found two major vulnerabilities in the app that can expose students’ personal and health data.

Albion College informed students two weeks before the start of the fall term that they would be required to install and run the contact tracing app, called Aura.

Exposure notification apps being deployed by states, based on the iOS and Android framework that Apple and Google announced earlier this year, are designed to minimize harms to privacy. That framework basically uses a phone’s Bluetooth capabilities as a proximity sensor, to see if the phone it’s installed on has been near a phone of someone who reports having tested positive for COVID-19.

Aura, however, goes all in on real-time location-tracking instead, as TechCrunch reports. The app collects students’ names, location, and COVID-19 status, then generates a QR code containing that information. The code either comes up “certified” if the data indicates a student has tested negative, or “denied” if the student has a positive test or no test data. In addition to tracking students’ COVID-19 status, the app will also lock a student’s ID card and revoke access to campus buildings if it detects that a student has left campus “without permission.”

TechCrunch used a network analysis tool to discover that the code was not generated on a device but rather on a hidden Aura website—and that TechCrunch could then easily change the account number in the URL to generate new QR codes for other accounts and receive access to other individuals’ personal data.

A student at Albion, looking into the app’s source code, also found hard-coded security keys for the app’s backend servers. A researcher took a look and verified that those keys gave access to “patient data, including COVID-19 test results with names, addresses, and dates of birth,” TechCrunch reports.

Aura’s developer, Nucleus Careers, fixed both vulnerabilities after the researchers and TechCrunch contacted them about the vulnerabilities. Students and parents, however, are still not enthusiastic. “I think it’s more creepy than anything and has caused me a lot of anxiety about going back,” one Albion student told the site.

Campus complications

Colleges and universities around the nation are struggling desperately to find ways to manage the fall 2020 semester. Many are only offering online education this fall. Some tried opening as usual this month but quickly had to abandon their plans and switch to distance learning after clusters of COVID-19 cases popped up among the student body. Others are trying cautiously to find in-between paths that allow students to return to classrooms more safely.

Oakland University, also in Michigan, plans to deploy wearable health-tracking tech—a BioButton—to track symptoms and the potential spread of COVID-19 among the campus population. Initially the university planned to make the BioButton mandatory for all students living on-campus, but school leadership walked that back following a petition from students.

College campuses are an ideal test ground for an array of COVID contact-tracing efforts. Schools can require students to download and install apps in a way that health officials cannot with the general population—although, as Politico notes, students’ participation and compliance may be less than full and enthusiastic, particularly when it comes to disclosing contacts who may have been drinking while underage.

College surveillance

COVID-19 lends an aura of urgency to the matter, but invasive location tracking on college campuses is not new. Schools around the country have been building out tracking systems for several years.

In 2019, for example, the University of Alabama began using location-tracking technology to see which students were leaving football games early. Students who remained through the fourth quarter were more likely to be able to get tickets for championship games.

Other schools rely on Bluetooth beacons and campus WiFi networks to track students around campus, as The Washington Post reported last year. The data not only thoroughly tracks students and compares their behavior to “norms” generated by peers in their cohorts but also may be used for grading and attendance purposes. Students can’t opt out by, for example, leaving their phones turned off because then they are marked absent and face penalties. One student from Temple University also told the Post that the app his school tracked him with didn’t work, and administrators would not believe his word over the faulty data.

Facial recognition, too, is coming to higher education. Advocacy group Fight For the Future identified 10 campuses, out of a list of about 100, that are already using facial recognition technology on campus, with another 30 or so indicating they may choose to deploy it in the future.

School administrators are not the only ones desperate to follow students’ movement on, off, and around campus. Some worried parents have also turned to location tracking to keep a remote eye on their kids when those kids become adults and leave for college.

https://arstechnica.com/?p=1700210




Bonus 600 euro Inps e privacy. La vicenda spiegata

Privacy e bonus Covid da 600 € in questi giorni sono stati al centro delle cronache per la richiesta avanzata da alcuni parlamentari e amministratori pubblici al fine di ottenere il bonus erogato dall’Inps per l’emergenza causata dalla pandemia.

La vicenda ha suscitato polemiche e critiche pesanti, anche dal punto di vista etico e morale, essendo il bonus finalizzato al sostegno dei titolari di partita IVA duramente colpiti dal lockdown e dalle ripercussioni economiche derivanti da quest’ultimo sulle rispettive attività lavorative.

L’indignazione suscitata dalla notizia e la richiesta, da più parti, di rendere noti i nomi di chi avrebbe presentato la domanda, ha determinato un intervento del Garante per la protezione dei dati personali il quale, al fine di evitare che la privacy possa essere invocata a sproposito, nel proprio comunicato dell’11 agosto 2020 ha precisato due importanti aspetti.

In primo luogo la privacy non è d’ostacolo alla pubblicità dei dati relativi ai beneficiari del contributo laddove, come nel caso di specie, da questo non si possa desumere una condizione di disagio economico-sociale dell’interessato.

In secondo luogo il principio vale, a maggior ragione, nei confronti di tutti coloro per i quali, a causa della funzione pubblica svolta, le aspettative di riservatezza si affievoliscono, anche per effetto dei più incisivi obblighi di pubblicità della condizione patrimoniale cui sono soggetti gli stessi.

Il Garante poi, con il comunicato stampa del 17 agosto 2020 ha inviato all’Inps alcuni chiarimenti sulla pubblicazione e comunicazione dei dati dei beneficiari del bonus che ricoprono cariche elettive pubbliche.

In sintesi non esiste alcun obbligo di pubblicazione dei dati personali dell’intera lista dei beneficiari di contributi economici, che riguardano diversi milioni di cittadini.

Il Garante ribadisce infatti le indicazioni già fornite alle pubbliche amministrazioni con le proprie Linee guida in materia di trasparenza. Esse prevedono l’obbligo di pubblicazione degli atti di concessione di vantaggi economici, di qualunque genere, a persone ed enti pubblici e privati, qualora l’importo dell’erogazione sia superiore a mille euro.

In ogni caso non possono essere pubblicati i dati identificativi delle persone fisiche destinatarie di qualsiasi emolumento e a prescindere dall’importo di quest’ultimo, nel caso in cui questi dati possano rivelare informazioni relative allo stato di salute ovvero alla situazione di disagio economico-sociale degli interessati.

È quindi compito dell’amministrazione destinataria dell’obbligo di pubblicazione valutare le condizioni di disagio e, nel caso di sussistenza, provvedere all’erogazione del contributo, senza tuttavia, per quanto già detto, pubblicare i dati personali dei destinatari.

Questa attività valutativa è stata a tutti gli effetti effettuata dall’Inps che, in base al Decreto Cura Italia, ha classificato il bonus dei 600 euro come “ammortizzatore sociale”, ossia una prestazione a sostegno del reddito e, in quanto tale, idonea a rivelare una situazione di disagio economico del destinatario.

Il comunicato prosegue poi indicando che, con riferimento alle richieste di accesso civico generalizzato ricevute dall’Inps riguardo ai dati dei beneficiari del bonus, il Garante non possa adottare un parere formale non ricorrendone i presupposti. Ha in ogni caso richiamato le indicazioni contenute nelle Linee guida dell’Autorità Nazione Anticorruzione, che precisano che per valutare l’esistenza di un reale pregiudizio concreto alla riservatezza degli interessati, in base al quale decidere se rifiutare o meno l’accesso civico ai loro dati, l’ente destinatario della richiesta deve far riferimento a diversi parametri che devono essere valutati caso per caso. È quindi compito dell’Inps verificare, nel singolo caso concreto, la possibilità di rendere noti tramite l’accesso civico i dati personali richiesti.

I nomi dei beneficiari, quindi, a determinate condizioni, possono essere resi pubblici, aspetto, questo, che ha destato clamore e interesse da parte dell’opinione pubblica per i risvolti politici connessi.

Dal punto di vista giuridico, tuttavia, il nodo della vicenda riguarda anche altri elementi, ossia le modalità con le quali l’INPS sia giunto alla individuazione degli interessati e quali criteri abbia utilizzato.

In pratica, com’è stato possibile risalire alla identificazione dei parlamentari e degli altri amministratori pubblici? 

Su questo aspetto il Garante ha aperto una specifica istruttoria chiedendo in particolare all’Inps di conoscere diversi elementi che riguardano:

  • quale sia la base giuridica del trattamento effettuato sui dati personali dei soggetti interessati; 
  • l’origine e tipi di dati personali trattati, riferiti alla carica di parlamentare e amministratore locale e regionale; 
  • le modalità con cui è stato effettuato il trattamento, con specifico riguardo all’operazione di “raffronto” dei dati personali dei soggetti richiedenti o beneficiari del bonus, con quelli riferiti alla carica di parlamentare e amministratore locale e regionale; 
  • l’ambito del trattamento ed eventuali comunicazioni a terzi di tali dati.

Se dunque è necessario aspettare l’esito dell’istruttoria avviata dal Garante, è indubbio che vi sia più di qualche perplessità sul rispetto delle norme in materia di protezione dei dati personali. Ciò che colpisce è senza dubbio il clamore suscitato dalla vicenda dal lato politico, mentre in pochi, e soprattutto quasi esclusivamente “addetti ai lavori”, si siano posti il problema delle modalità con le quali l’Inps sia giunto ad individuare questi nominativi.

Il sospetto, purtroppo, è che ad oggi la privacy resti ancora un terreno (quasi) inesplorato per molti.

https://www.key4biz.it/bonus-600-euro-inps-e-privacy-la-vicenda-spiegata/318254/




Secret Service buys location data that would otherwise need a warrant

Stock photo of hands using smartphones against white background.
Enlarge / Dozens of apps on your phone know where you are, whether you’re home, at a doctor’s appointment, at the airport, or sitting still in a blank white room to pose artfully for a photo shoot.

An increasing number of law enforcement agencies, including the US Secret Service, are simply buying their way into data that would ordinarily require a warrant, a new report has found, and at least one US senator wants to put a stop to it.

The Secret Service paid about $2 million in 2017-2018 to a firm called Babel Street to use its service Locate X, according to a document (PDF) Vice Motherboard obtained. The contract outlines what kind of content, training, and customer support Babel Street is required to provide to the Secret Service.

Locate X provides location data harvested and collated from a wide variety of other apps, tech site Protocol reported earlier this year. Users can “draw a digital fence around an address or area, pinpoint mobile devices that were within that area, and see where else those devices have traveled” in the past several months, Protocol explained.

Agencies under the Department of Homeland Security—including Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP)—have purchased access to cellphone location activity for investigations, The Wall Street Journal reported in February. In June, the WSJ also reported that the IRS purchased access to location data through commercial databases.

Easier than a warrant

Private companies can gather up, buy, sell, and trade all kinds of sensitive user data more or less however they want, with very few limitations—and they do.

All kinds of mobile apps collect location data, both legitimately and illegitimately, and then sell it to data brokers. The data brokers then pass on is theoretically anonymized—but in practice, easily identifiable.

The New York Times in 2018 demonstrated in a multimedia feature how easy it is to follow an individual around her whole daily life using a snapshot obtained from just one data aggregation firm. “The database reviewed by The Times—a sample of information gathered in 2017 and held by one company—reveals people’s travels in startling detail, accurate to within a few yards and in some cases updated more than 14,000 times a day,” the paper wrote at the time.

Apps are not the only ones collecting and selling that information. All four national mobile carriers—Verizon, AT&T, and the now-combined Sprint and T-Mobile—were caught selling customers’ location data without consent in 2018 and 2019.

Law enforcement agencies are required to get a warrant to obtain an individual’s mobile phone location data, the Supreme Court ruled in 2018. Investigators have several times sought warrants to gather information for all phones that travel within a certain boundary during a certain period of time, known as geofencing.

But there are currently no rules on the books preventing law enforcement from simply purchasing whatever information they want from the existing market. Sen. Ron Wyden (D-Ore.) told Vice that needs to change.

“It is clear that multiple federal agencies have turned to purchasing Americans’ data to buy their way around Americans’ Fourth Amendment Rights,” Wyden told Motherboard. “I’m drafting legislation to close this loophole, and ensure the Fourth Amendment isn’t for sale.”

https://arstechnica.com/?p=1699476




Police use of facial recognition violates human rights, UK court rules

Vaguely menacing camera atop an outdoor metal post.
Enlarge / A close-up of a police facial recognition camera in use at the Cardiff City Stadium on January 12, 2020 in Cardiff, Wales. Police used the technology to identify individuals who were issued with football banning orders in an attempt to prevent disorder. Critics argued that the use of such technology is invasive and discriminatory.

Privacy advocates in the UK are claiming victory as an appeals court ruled today that police use of facial recognition technology in that country has “fundamental deficiencies” and violates several laws.

South Wales Police began using automated facial recognition technology on a trial basis in 2017, deploying a system called AFR Locate overtly at several dozen major events such as soccer matches. Police matched the scans against watchlists of known individuals to identify persons who were wanted by the police, had open warrants against them, or were in some other way persons of interest.

In 2019, Cardiff resident Ed Bridges filed suit against the police, alleging that having his face scanned in 2017 and 2018 was a violation of his legal rights. Although he was backed by UK civil rights organization Liberty, Bridges lost his suit in 2019, but the Court of Appeal today overturned that ruling, finding that the South Wales Police facial recognition program was unlawful.

“Too much discretion is currently left to individual police officers,” the court ruled. “It is not clear who can be placed on the watchlist, nor is it clear that there are any criteria for determining where AFR can be deployed.” The police did not sufficiently investigate if the software in use exhibited race or gender bias, the court added.

The South Wales Police in 2018 released data admitting that about 2,300 of nearly 2,500 matches—roughly 92 percent—the software made at an event in 2017 were false positives.

“I’m delighted that the Court has agreed that facial recognition clearly threatens our rights,” Bridges said in a written statement after the ruling. “This technology is an intrusive and discriminatory mass surveillance tool… We should all be able to use our public spaces without being subjected to oppressive surveillance.”

The ruling did not completely ban the use of facial recognition tech inside the UK, but does narrow the scope of what is permissible and what law enforcement agencies have to do to be in compliance with human rights law.

“I am confident this is a judgment that we can work with,” a spokesperson for the South Wales Police said, confirming that the agency does not plan to challenge the ruling.

Widespread impact?

Other police inside the UK who deploy facial recognition technology will have to meet the standard set by today’s ruling. That includes the Metropolitan Police in London, who deployed a similar type of system earlier this year.

Liberty hailed the victory as “the world’s first legal challenge” to police use of facial recognition tech, but it’s almost certainly not going to be the last. Police use of facial recognition technology here in the United States has come under increased scrutiny against the backdrop of this year’s nationwide civil rights protest movement in support of Black communities and against police brutality.

The ACLU in June filed a formal complaint, though not a lawsuit, against police in Detroit after they arrested the wrong man based on a false-positive match from a facial ID system. That system, the Detroit police chief later admitted, misidentifies suspects a whopping 96 percent of the time.

The US companies that manufacture facial recognition systems have also tried to distance themselves from police in recent months. IBM left the business entirely in June; CEO Arvind Krishna said at the time, “vendors and users of AI systems have a shared responsibility to ensure that AI is tested for bias, particularly when used in law enforcement, and that such bias testing is audited and reported.” A few days later, Amazon followed suit with a one-year moratorium on allowing police to use its facial recognition platform, Rekognition.

https://arstechnica.com/?p=1698159




NJ Supreme Court: No 5th Amendment right not to unlock your phone

NJ Supreme Court: No 5th Amendment right not to unlock your phone
ymgerman / Getty

New Jersey’s Supreme Court has ruled that compelling a suspect to unlock his or her cell phone doesn’t violate the Fifth Amendment. The courts continue to be deeply split on this question. Back in June, Indiana’s Supreme Court reached the opposite conclusion, and several other state and federal courts have reached divergent positions on the issue over the last few years.

This case focuses on an allegedly corrupt cop named Robert Andrews. Andrews is a former Essex County Sheriff who allegedly tipped off a suspect named Quincy Lowery about a pending police investigation. Under police questioning, Lowery testified that Andrews had advised him to get a new phone to avoid a police wiretap. He also said Andrews helped Lowery identify an undercover police officer and an unmarked police vehicle. These allegations were corroborated by data from Lowery’s phone.

The police seized two iPhones belonging to Andrews, but investigators were unable to unlock them. Andrews refused to unlock the phones based on the Fifth Amendment, which protects against self-incrimination.

On Monday, the New Jersey Supreme Court rejected that Fifth Amendment claim. The Fifth Amendment only protects defendants against self-incriminating testimony, not the production of incriminating documents. While “testimony” usually refers to speech, that’s not always the case. Sometimes, a defendant can reveal information by his or her actions. For example, if the government doesn’t already know who owns a phone, then forcing a defendant to unlock it amounts to forced testimony that the defendant is the owner.

But that reasoning doesn’t apply in this case. The phones were registered in Andrews’ name and were in his possession. There’s little doubt that Andrews knows the passcodes. So if he’s forced to enter the passcodes to his own phones, the New Jersey Supreme Court reasoned, he’s not revealing any information that the government doesn’t already know.

Of course, the information on the phone may be incriminating. But the courts have long held that forced production of documents—even incriminating ones—is not a violation of the Fifth Amendment. The government can order a defendant to unlock a safe even if the safe might have incriminating documents inside of it.

The other side

As we mentioned before, the Indiana Supreme Court took the opposite view just two months ago. And as I wrote at the time, that was just the latest example of a deep divide among courts on this issue:

Earlier this year, a Philadelphia man was released from jail after four years of being held in contempt in connection with a child-pornography case. A federal appeals court rejected his argument that the Fifth Amendment gave him the right to refuse to unlock hard drives found in his possession. A Vermont federal court reached the same conclusion in 2009—as did a Colorado federal court in 2012, a Virginia state court in 2014, and the Massachusetts Supreme Judicial Court in 2014.

But other courts in Florida, Wisconsin, and Pennsylvania have reached the opposite conclusion, holding that forcing people to provide computer or smartphone passwords would violate the Fifth Amendment.

Courts that have found the Fifth Amendment does shield defendants against unlocking their phones have focused not on the passcodes but on the information contained in the phone. They point to a 2000 ruling in the prosecution of Bill Clinton business associate Webster Hubbell for tax fraud. Prosecutors had ordered Hubbell to provide documents in several broad categories. The Supreme Court ruled that this violated the Fifth Amendment because Hubbell wasn’t just being asked to turn over particular documents—he was using his own judgment to decide which documents fell into the broad categories the government asked about.

Courts like the Indiana Supreme Court have concluded that similar reasoning applies in cell phone unlocking cases. Governments aren’t seeking specific files on a suspect’s device, they’re seeking unfettered access to a suspect’s cell phone, giving them access to information they might not have known existed previously. Some courts have held that this kind of fishing expedition is analogous to the broad document requests in the Hubbell case.

But in Monday’s ruling, the New Jersey supreme courts pointed out a key difference: Hubbell was required to use his own knowledge and judgments to decide which documents to turn over. That compelled exercise of judgment—not just the fact that the government might get incriminating documents it didn’t know about before—was what made Hubbell’s response self-incriminating testimony. By contrast, unlocking a cell phone doesn’t require a suspect to make any judgments about the information on the cell phone.

The New Jersey Supreme Court points out that there’s a different constitutional provision that’s supposed to protect the privacy of people’s private data. That’s the Fourth Amendment, which protects “papers” against “unreasonable searches and seizures.” The New Jersey Supreme Court argues that focusing on the phone’s contents, rather than on the production of the passcode itself, “imports Fourth Amendment privacy principles into a Fifth Amendment inquiry.” If the police are engaging in improper fishing expeditions, the way to deal with that is by challenging the search warrant on Fourth Amendment grounds.

Ultimately, the only way to resolve this dispute is for the US Supreme Court to get involved. The high court hasn’t ruled on the legality of compelled decryptions of smartphones or other digital devices. Indeed, most of the Fifth Amendment caselaw in this era predates smartphones—and in many cases the personal computer, too. It would be helpful for the nation’s highest court to take this issue on and provide clarity to courts that are struggling with how to apply these decades-old precedents.

https://arstechnica.com/?p=1698156




Beware of find-my-phone, Wi-Fi, and Bluetooth, NSA tells mobile users

Photograph of a map app on a smartphone.

The National Security Agency is recommending that some government workers and people generally concerned about privacy turn off find-my-phone, Wi-Fi, and Bluetooth whenever those services are not needed, as well as limit location data usage by apps.

“Location data can be extremely valuable and must be protected,” an advisory published on Tuesday stated. “It can reveal details about the number of users in a location, user and supply movements, daily routines (user and organizational), and can expose otherwise unknown associations between users and locations.”

NSA officials acknowledged that geolocation functions are enabled by design and are essential to mobile communications. The officials also admit that the recommended safeguards are impractical for most users. Mapping, location tracking of lost or stolen phones, automatically connecting to Wi-Fi networks, and fitness trackers and apps are just a few of the things that require fine-grained locations to work at all.

The cost of convenience

But these features come at a cost. Adversaries may be able to tap into location data that app developers, advertising services, and other third parties receive from apps and then store in massive databases. Adversaries may also subscribe to services such as those offered by Securus and LocationSmart, two services that The New York Times and KrebsOnSecurity documented, respectively. Both companies either tracked or sold locations of customers collected by the cell towers of major cellular carriers.

Not only did LocationSmart leak this data to anyone who knew a simple trick for exploiting a common class of website bug, but a Vice reporter was able to obtain the real-time location of a phone by paying $300 to a different service. The New York Times also published this sobering feature outlining services that use mobile location data to track the histories of millions of people over extended periods.

The advisory also warns that tracking often happens even when cellular service is turned off, since both Wi-Fi and Bluetooth can also track locations and beam them to third parties connected to the Internet or with a sensor that’s within radio range.

To prevent these types of privacy invasions, the NSA recommends the following:

  • Disable location services settings on the device.
  • Disable radios when they are not actively in use: disable BT and turn off Wi-Fi if these capabilities are not needed. Use Airplane Mode when the device is not in use. Ensure BT and Wi-Fi are disabled when Airplane Mode is engaged.
  • Apps should be given as few permissions as possible:
    • Set privacy settings to ensure apps are not using or sharing location data.
    • Avoid using apps related to location if possible, since these apps inherently expose user location data. If used, location privacy/permission settings for such apps should be set to either not allow location data usage or, at most, allow location data usage only while using the app. Examples of apps that relate to location are maps, compasses, traffic apps, fitness apps, apps for finding local restaurants, and shopping apps.
  • Disable advertising permissions to the greatest extent possible:
    • Set privacy settings to limit ad tracking, noting that these restrictions are at the vendor’s discretion.
    • Reset the advertising ID for the device on a regular basis. At a minimum, this should be on a weekly basis.
  • Turn off settings (typically known as FindMy or Find My Device settings) that allow a lost, stolen, or misplaced device to be tracked.
  • Minimize Web browsing on the device as much as possible, and set browser privacy/permission location settings to not allow location data usage.
  • Use an anonymizing Virtual Private Network (VPN) to help obscure location.
  • Minimize the amount of data with location information that is stored in the cloud, if possible.

If it is critical that location is not revealed for a particular mission, consider the following recommendations:

  • Determine a non-sensitive location where devices with wireless capabilities can be secured prior to the start of any activities. Ensure that the mission site cannot be predicted from this location.
  • Leave all devices with any wireless capabilities (including personal devices) at this non-sensitive location. Turning off the device may not be sufficient if a device has been compromised.
  • For mission transportation, use vehicles without built-in wireless communication capabilities, or turn off the capabilities, if possible.

Mobile phone use means being tracked

Patrick Wardle, a macOS and iOS security expert and a former hacker for the NSA, said the recommendations are a “great start” but that people who follow the recommendations shouldn’t consider them anything close to absolute protection.

“As long as your phone is connecting to cell towers, which it has to in order to use the cell network… AFAIK that’s going to reveal your location,” Wardle, who is a security researcher at the macOS and iOS enterprise management firm Jamf, told me. “It, as always, is a tradeoff between functionality/usability and security, but basically if you use a phone, assume that you can be tracked.”

He said that recent versions of iOS make it easy to follow many of the recommendations. The first time users open an app, they get a prompt asking if they want the app to receive location data. If the user says yes, the access can only happen when the app is open. That prevents apps from collecting data in the background over extended periods of time. iOS also does a good job of randomizing MAC addresses that, when static, provide a unique identifier for each device.

More recent versions of Android also allow the same location permissions and, when running on specific hardware (which usually come at a premium cost), also randomize MAC addresses.

Both OSes require users to manually turn off ad personalization and reset advertising IDs. In iOS, people can do this in Settings > Privacy > Advertising. The slider for Limit Ad Tracking should be turned on. Just below the slider is the Reset Advertising Identifier. Press it and choose Reset Identifier. While in the Privacy section, users should review which apps have access to location data. Make sure as few apps as possible have access.

Change some settings

In Android 10, users can limit ad tracking and reset advertising IDs by going to Settings > Privacy and clicking Ads. Both the Reset Advertising ID and Opt Out of Ads personalization are there. To review which apps have access to location data, go to Settings > Apps & notifications > Advanced > Permission Manager > Location. Android allows apps to collect data continuously or only when in use. Allow only apps that truly require location data to have access, and then try to limit that access to only when in use.

Tuesday’s advisory also recommends people limit sharing location information in social media and remote metadata showing sensitive locations before posting pictures. The NSA also warns about location data being leaked by car navigation systems, wearable devices such as fitness devices, and Internet-of-things devices.

The advice is aimed primarily at military personnel and contractors whose location data may compromise operations or put them at personal risk. But the information can be useful to others, as long as they consider their threat model and weigh the acceptable risks versus the benefits of various settings.

https://arstechnica.com/?p=1696452




Twitter faces FTC probe, likely fine over use of phone numbers for ads

Twitter faces FTC probe, likely fine over use of phone numbers for ads

Twitter is facing a Federal Trade Commission probe and believes it will likely owe a fine of up to $250 million after being caught using phone numbers intended for two-factor authentication for advertising purposes.

The company received a draft complaint from the FTC on July 28, it disclosed in its regular quarterly filing with the Securities and Exchange commission. The complaint alleges that Twitter is in violation of its 2011 settlement with the FTC over the company’s “failure to safeguard personal information.”

That agreement included a provision banning Twitter from “misleading consumers about the extent to which it protects the security, privacy, and confidentiality of nonpublic consumer information, including the measures it takes to prevent unauthorized access to nonpublic information and honor the privacy choices made by consumers.” In October 2019, however, Twitter admitted that phone numbers and email addresses users provided it with for the purpose of securing their accounts were also used “inadvertently” for advertising purposes between 2013 and 2019.

In the filing, Twitter estimates the “range of probable loss” it faces in the probe is between $150 million and $250 million, although it adds that “the matter remains unresolved, and there can be no assurance as to the timing or the terms of any final outcome.”

A common problem

Twitter is not the first social media firm to be investigated for exploiting personal information users provided for security reasons. Last year, the FTC levied a record $5 billion fine on Facebook for repeated privacy violations.

Facebook in 2018 not only started pushing notifications to the phone numbers users provided for 2FA purposes but also was found to be using those numbers for a shadow profile which was used to connect other individuals and advertisers to you.

The bulk of the fine related to Facebook’s actions in the Cambridge Analytica scandal, but the FTC also included in its settlement allegations of exactly the same actions Twitter is now accused of. Facebook also settled with the FTC in 2011 over allegations that it misused users’ data, and its use of personal information provided to it for security purposes was found to violate that agreement.

https://arstechnica.com/?p=1696306