Showing posts with label Personal Privacy. Show all posts
Showing posts with label Personal Privacy. Show all posts

Wednesday, March 28, 2018

Your Facebook Data Can Be Used Against You


It turns out that Facebook keeps a shipload of data about you.  That stands to reason, since Facebook's business model is to snarf up as much data as possible so you can be targeted for ads that Facebook and its real customers (i.e., the advertisers) hope you click on.  And Facebook would want to keep every scrap of data it has about you (subject to your ability to delete it under Facebook's terms and conditions), no matter how old or seemingly trivial it may be because the more Facebook knows, the greater its ability to target you.  So the information it keeps is pretty extensive, including among other things your facial image (kept through its facial recognition software), all contacts in your phone book, all your Facebook friends (including those that were unfriended), location data (as in where you were at a particular time on a particular day), all the videos you watched, your timeline, all photos you uploaded to Facebook, message traffic, and life events (such as your birth date, graduations, marriages, and so on).  (See https://www.cnbc.com/2018/03/27/facebook-knows-a-lot-about-me.html.)

But all that information can be used against you.  There are probably quite a few possible ways.  Here are a few.  Let's say you have a job that doesn't require you to show up at the office all the time.  Your employer thinks you haven't been putting in a full 40 hours a week and demands that you download and hand over a copy of your Facebook data, so they can check up on what you've doing during the workweek.  You refuse, saying that would be an outrageous invasion of your privacy.  Your employer then tells you to pursue your career elsewhere.  And if you sue?  Your employer might try to use court rules called "discovery" to get a copy of your Facebook data to prove you were goofing off.

So you lost your job and apply for another.  Your prospective new employer says, "we really like you but we'd like to see a copy of your Facebook data, just as part of our due diligence on job applicants."  You suddenly remember all those videos you watched ten years ago, when you were younger and more impulsive and watched a lot of weird stuff, which you wouldn't want a future employer to know about.  You decline to provide your Facebook data, and all of a sudden the prospective job evaporates.  

So you try again with another potential employer, this time a contractor for the federal government.  But this job requires a security clearance, and you are asked to provide a copy of your Facebook data so the contractor can evaluate whether or not you'd get a clearance.  You then recall those stupid videos that you uploaded in college during Spring Break--you know, the ones in which you and your pals were rip-roaring drunk and . . .  well, the streaking was the least of it.  WTF do you do now?  How do you respond to this request?

Let's say you're involved in a divorce--half of all married people get divorced, so this sadly is a pretty common event.  Your spouse suspects you've cheated and tries to use those court discovery rules to get a copy of your Facebook data to see where you've been and who you were with.  What if your spouse succeeds?  What will he or she find out?

Perhaps you're a stock market aficionado, and want to get as much information about a company as you can.  You have a friend who works at the company and you traded the company's stock very profitably.  A government official investigating whether or not you got illegal inside information could subpoena your Facebook data to see if you met with or communicated with your friend who works at the company at a time when your friend might have tipped you off.

Let's assume you've been lucky in life and make a gratifying income.   But you find the demands of the IRS insufferable.  So you take a flight to Panama or some other place that has banking secrecy laws you think might keep the Feds at bay.  The IRS gets nosy and subpoenas your Facebook data.  Would they find out you were in Panama or some other place not mentioned in your tax returns?

There are some people who have lived entirely blameless lives--they hewed to the straight and narrow, never told a lie, never smoked, drank, or took illegal drugs, never had dinner alone with anyone other than their spouses, always helped old ladies across the street, and never said a cuss word.   All three of these people have nothing to worry about.  As for the rest of us, that vast pool of data Facebook may have on you is something to bear in mind.  It ain't going nowhere, and you'll have to live with its consequences.

Sunday, March 25, 2018

Your Facebook Data Will Never Be Safe


Unless you've been locked into a backyard bunker waiting for President Trump to start a nuclear war, you know that Facebook is having some rather serious problems with the confidentiality of its users' data.  Data for some 50 million users somehow wound up in the hands of a UK data analysis firm called Cambridge Analytica, which then reportedly used it to assist Donald Trump get elected President of the United States.  Needless to say, the 50 or so million users weren't aware this happened.  Government investigations have started.  A search warrant was executed at Cambridge Analytica and calls have been made for Mark Zuckerberg, Facebook's CEO, to testify before Congress.  But, no matter what happens--Facebook takes more protective measures, government regulation increases, people are tossed in jail--your Facebook data will never be safe.

According to an apocryphal story, bank robber Willie Sutton was asked why he robbed banks and replied, "Because that's where the money is." Facebook's problem is it is where the data is.  Facebook has the best data on the Internet.  It insists on users using their true identities, and it operates a social forum, where it learns who is in a user's social circles, what they think, what they like, what they do, what they want, what they own, where they live, where they work, where they play, with whom they play, what illness and injuries they have, what medications they take, what treatments they get, what music they like, what television and video entertainment they like, where they go on vacation and with whom, what they eat, where they eat, who they like, who they dislike, who they date, who they want to date, who they marry, who they divorce, maybe even who they cheat on their spouses with, how they vote, who they vote for, why they vote a particular way, what their political views are, what their cultural values are, what their religious views are, where they worship, what prejudices and biases they have, what ethnic and racial groups they like or dislike, how they feel about gays, lesbians, transgender people or anyone else, how they feel about this sexual activity or that, etc., etc., etc., so on and so forth.  In other words, Facebook knows AN AWFUL LOT about its users, more than any other website or Internet company. 

Facebook is where the data is--the absolutely best data.  That's why hackers, unscrupulous foreign governments, shady political operators, and all manner of scoundrels and riff raff will continue to swarm around Facebook like a pack of hyenas, snatching whatever data they can get.  As we repeatedly learn just about every week, no repository of data is safe.  Neither governments, military or intelligence organizations, the most sophisticated Internet companies, nor anyone else can keep data safe.  Everyone who has valuable data has been hacked or probably will be hacked some day.  The architecture of the Internet is open, not closed, and true security is simply impossible.  Because Facebook has the crown jewels when it comes to data, the wolves will perennially attack and hack.  And even as Facebook puts up more defenses, the jackals will relentlessly prowl and find new ways to slip through and feed. 

Don't be naive when Facebook tells you they'll find ways to fix the problem.  They've been hoodwinked before, and, being human, they'll be hoodwinked again.  If you're on Facebook, you have a choice to make--have no expectation of privacy at all, or get the hell off of Facebook.

Monday, October 9, 2017

Freeze Your Credit and Make 'Em Change

Of all the massive hacks of recent years, the Equifax hack may be the worst.  Some 145 million persons had their personal information stolen.  Even though other hacks may involve larger numbers (the Yahoo hack may have victimized 3 billion--yes, billion--accounts), Equifax had the crown jewels:  Social Security numbers, birth dates, home addresses and phone numbers, and some credit card account numbers and drivers license numbers.  Bad guys can use this information to open phony credit card and other loan accounts in your name, steal your tax refund, grab your Social Security check and get prescription drugs in your name (which could interfere with your ability to get medications and maybe even implicate you in police investigations). 

What to do?  The best thing is to freeze your credit accounts.  These freezes, called security freezes, prevent new creditors and other persons from getting access to your credit information unless you specifically authorize it.  It doesn't stop existing creditors and their collection agents, or the government from getting access.  But it puts a substantial barrier in the way of fraudsters.  It's not perfect--the bad guys might still try to use your stolen personal information to snare your tax refund or your Social Security benefits, or snag some opiods in your name.  But a credit freeze is a lot better than the alternatives.  Forget about credit monitoring and fraud alerts--they aren't great protection.  And a credit lock isn't as good as a credit freeze.  Credit freezes give you legal protection under state law, while a credit lock is just a contract with the credit reporting agency that may be difficult to enforce.  Credit locks may also cost you more in fees (which is one reason the credit reporting agencies might want to sell you a credit lock). 

Credit freezes can be a little inconvenient, because you have to lift them any time you want to apply for credit.  But that is a lot less bother than the aggravation of cleaning up your credit after the bad guys have impersonated you (a process that can take months or years).

One more reason to freeze your credit is to make the idiots (the ones that got hacked) change things.  The credit reporting agencies and banks and other lenders don't like freezes.  They interfere with business and revenue flow.  The credit reporting agencies and lenders have a harder time making money if a lot of people freeze their accounts.  And that is the point.  The current system using Social Security numbers as universal identification numbers has just been blown up by the Equifax hack.  For all practical purposes, you have to assume that your Social Security number is publicly available.  You have no privacy any more.  You're not safe, and your finances are not safe.  The SSN system of personal identification is now completely kaput.

Make 'em change.  Freeze your credit and take profit opportunities away from the credit reporting agencies, and the banks and other lenders.  Faced with a business downturn, these massive institutions will lead the way to change.  With the potential loss of who knows how many millions of dollars of profit, they will implement posthaste new and improved systems of personal identification.  Either that, or their senior executives' stock options will belly flop.  And that they won't allow.  So freeze your credit.  It might be the best thing you can do right now for your financial privacy.

Wednesday, November 19, 2014

Uber Shows Us Why Privacy Matters

It appears that a senior vice president at Uber, the online taxi service, suggested that the company ought to investigate journalists who offend the company.  In particular, Emil Michael, the SVP in question, seems to have directed his remarks at a BuzzFeed reporter named Sarah Lacy, who evidently has been critical of the company. 

Although Uber has repudiated Michael's remarks and pledged not to investigate journalists, let's think hypothetically about what a nasty corporation might do in order to dig up dirt on an individual.  There is the company's own database.  In the case of an online taxi service, that would include name, credit card information, and perhaps a lot of addresses.  Some you might not want your significant other to know about if you've been less than a paragon of fidelity.  Others you might not want your employer to know about if you've been interviewing discreetly for a new job.  Of course, there could be the address of the only abortion clinic in your city or a seedy hotel where the only things you could get are services from sex workers or illegal drugs. 

In addition, businesses corporations have access to commercial databases created by shadowy companies that vacuum up everything about you they can find on the Internet and sell it for a fee.  These databases might well include archived pages from social networking and other sites that you thought you deleted years ago (shiploads of stuff on the Internet have been archived, and a deletion on the active website doesn't necessarily mean all the archived stuff is gone).  Businesses can also hire snoops to snoop around online and otherwise.  They can get the name of the driver from the online taxi service, interview him, and find out that you were getting mighty friendly with someone in the back seat when you told your spouse you were going alone to a client dinner.  Or they can find out the name of the restaurant where you were taken, and interview the bartender to learn there was someone waiting for you who whisked you away after spending five minutes at the bar. 

No one is perfect.  For many, their imperfections can be uncovered online or through information available online.  Private interests can be bad.  Some can be evil.  There are fewer legal constraints on private interests digging up dirt online than there are on the government.  It's creepy to think that NSA or some other government agency might be sneaking peaks at our e-mail accounts.  But, ultimately, the government is subject to a variety of constraints that, at least sometimes, can be invoked.  A business corporation or other private interest that wants to do evil is much harder to rein in because of the paucity of rules.

Privacy laws are like locks on doors.  You lock your doors to keep undesired people out of the privacy of your home.  Privacy rules keep undesired people out of the privacy of your data.  Everyone wants a nonpublic place where they aren't subject to prying eyes.  Even the Uber SVP, Emil Michael, who reportedly claims that his inflammatory remarks were meant to be off the record.  (See http://www.cnbc.com/id/102199538). From the vantage point of his petard, Michael acknowledges the desirability of privacy.

It's unlikely Congress will do anything useful in the foreseeable future.  But if it wanted to shock us with a pleasant surprise, it could enact a strong set of privacy rules for online data and the use of online data.  After all, privacy matters.

Sunday, February 23, 2014

The WhatsApp Deal: Did Zuckerberg Just Blink?

WhatsApp is the antithesis of Facebook.  It doesn't collect personal information.  Messages aren't stored in WhatsApp's servers.  There are no ads on WhatsApp.  As a messaging service, there's nothing on WhatsApp for strangers (or parents) to find via search engines.  It offers the one thing that's almost impossible to obtain on the Internet:  privacy.  No wonder it's growing by a million users a day, many of them in the young adult cohort coveted by commercial websites.

It's unclear what Mark Zuckerberg hopes to achieve by having Facebook buy WhatsApp.  If he engrafts WhatsApp onto Facebook, or makes it semi-clone of Facebook (i.e., has it run ads), it will surely lose much of the privacy it offers.  Facebook's business model, after all, is to vacuum up as much personal information as possible in order to cram advertising into users' faces.  But that could drain away much of WhatsApp's attractiveness to its current user base, and they could easily flee to any of a number of competitors offering private communications. 

If Zuckerberg keeps WhatsApp independent, he'll have to find some way of generating revenue--a shipload of it, since Facebook is paying $19 billion for WhatsApp and the only justification for such a Brobdingnagian price would be freight cars full of revenue.  But you can't charge users much for instant messaging services (the phone companies tried that with text messaging and users are moving away from them).  So there is a big question about what kind of rabbit Zuckerberg will pull out of the hat as a business strategy for WhatsApp.

One thing that seems apparent is that he's blinked.  Zuckerberg evidently has come to realize that Facebook isn't going to be the platform for all users all the time.  He's jumping onto one of the new, hot things on the Internet.  Diversifying Facebook's corporate profile may be a prudent move.  But the company now has two conflicting business models under its corporate roof, and it will have to sort out how to handle these conflicts.  History does not suggest success is assured by any means.  Microsoft entered various lines of business that were potential threats to its basic MS-DOS/Windows business--search engines, portals, mobile software, etc.  It didn't managed them very well, because boosting a newer technology could mean undermining its cash cow.  Newer, nimbler competitors, unburdened by these conflicts, ran circles around Microsoft.  Facebook is one of them.  But now it has taken in-house a conflict between the old (yes, Facebook is getting old) and the new on the Internet.  How Facebook handles that conflict could dictate the future arc of its growth.

Saturday, January 18, 2014

Privacy Rights: Obama's Last Big Moment

Throughout his Presidency, Barack Obama seems to have been on a quest for greatness, something that would mark him as an exceptional President.  He apparently isn't satisfied with being the first African American President, which is understandable.  We all want to be judged as individuals, not as an ethnicity or a race.  He tried to construct a program for federal stimulus for economic recovery, but got tangled up in the politics of government borrowing. He failed to achieve a grand bargain on the federal budget (which was a misguided tilt with a windmill from the get go). He managed, after almost failing, to get national health insurance legislation passed.  But then he and his administration thoroughly botched the launch.  His foreign policy accomplishments--getting us out of Iraq, and moving forward with withdrawal from Afghanistan--have been under-appreciated.  Ending a war without a clear victory isn't seen as a mark of greatness, even if it is the right thing to do.  And the prospects for anything really positive to happen with Iran, North Korea, Israel and the Palestinians, and the war on terror are problematic, at best.

But Obama now has a really big opportunity to achieve greatness.  Edward Snowden's revelations about the NSA have blown wide open the increasingly pressing issue of privacy.  With the Internet now ubiquitous, privacy is the most important civil liberties issue in the world.  In a democratic nation, the relationship of citizens to their government is the essential dynamic.  The process of electing the government, the notion of a government of limited powers defined in a national charter, the rights of individuals to speak out, worship, assemble, petition the government for redress of grievances, and publish, the protection of individual rights by an independent judiciary, the limitation of the government's authority to investigate (allowing search and seizure, wiretaps and other intrusions into the lives of citizens only with the approval of a court), and, at least in America, the right to keep and bear arms, all work to establish the individual citizen as the foundational component of society.  The government is supposed to be of the people, by the people and for the people.  The people aren't supposed to be subservient to the government.

With the recent disclosures of the NSA's seemingly insatiable appetite for, it would seem, every piece of information about everyone, citizens are threatened with a reversal of their relationship to their government.  The government's interests seem to take precedent over the individual's historic right to be left alone in the absence of clear and demonstrable need for government intrusion.  We won't have a government of limited power if the government knows everything there is to know about you.  Democracy as we have historically understood the term would cease to exist.

Obama today made a speech, promising to rein in the NSA, and more strongly safeguard the privacy of Americans (and also some foreigners).  His proposals are rather general, and, when it comes to privacy, the devil is decidedly in the details.  When the details come out, we'll find out how much of a change he is really proposing.  The privacy issue may well be Barack Obama's last chance to achieve greatness as a President.  If he succeeds in upholding primacy of the individual citizen, he will be remembered well for decades and even centuries to come.

And while he's at it, he might as well tackle the problem of individual's rights against the Internet giants.  The relationship of individuals, as consumers and workers, to giant corporations has been one of the great commercial and employment law problems of the industrialized world.  Without strong protections for those buying the products and services of the titans of the economies, and those working for them, the raw economic power of these gargantuan organizations would leave individuals helpless to be victimized early and often.  The Internet giants threaten to abscond with the privacy of all Internet users, and attain vast informational power over them.  Just as GM, Ford, Chrysler and the other automotive manufacturers weren't allowed to sell dangerous products to consumers without legal liability for product defects, the Internet giants shouldn't be allowed to treat Internet users as sheep to be fleeced in order to boost ad revenues and executive bonuses.  A Presidential initiative to significantly protect online privacy would bolster Obama's chances for greatness.

Saturday, January 11, 2014

Learning From the Data Scandals

It's obvious that there is too much data being stored, and the biggest problem is that even more data is being accumulated.  The NSA scandal reveals what happens when a very large, secretive government agency with a big, but probably unverifiable budget decides it wants to know everything there is to know about everyone--it accumulates the Brobdingnagian pile of data that would allow it to do just that.  And Edward Snowden's revelations prove that whoever you might be, even if you're the NSA, your data isn't secure.

The Target data hack shows what happens when a private sector organization accumulates massive amounts of valuable data--someone figures out how to get it.  And much of the fallout falls on the most innocent of all--Target's customers.

These examples are only the beginning.  By all indications, Google and Facebook want to gather and store all the data on the Internet about you for ever and ever, so they can sell it to the highest bidding advertiser closest to your GPS coordinates.  But in accumulating these massive amounts of data, they make themselves tempting targets for hackers--and perhaps the NSA.  Remember what Willie Sutton supposedly said when asked why he robbed banks:  "Because that's where the money is."  Wherever there is a big pile of data, someone will go after it.  No person or organization has completely secure systems; not Google, not Facebook; not anyone.  The value inhering in these huge databases will motivate somebody somewhere to put in the effort it takes to find the flaw.

How can we get this data based nightmare under control?  By doing what banks do to limit the impact of robberies--keep less around.  Banks generally keep only limited amounts of cash on hand. If they are robbed, the bad guys don't get that much.  The damage is limited by the fact that there simply isn't a lot of cash to steal.

The same thing can be done with data.  The big accumulators should be forced to stop hoarding.  Private organizations like Google and Facebook should be allowed to hold most types of data for only short periods of time.  For example, perhaps they could be allowed to keep location data for a few seconds.  That would be long enough to sell an ad to the restaurant you're walking or driving by.  But the data should not be added to a profile of you or other long term records that they could keep forever and forever so that it would be available for hackers to steal.  Your web browsing activities could be similarly retained for just seconds, to accommodate the sale of advertising, but not to be incorporated into your profile or other long term records.  Of course, information that you voluntarily post on your Facebook page or your blog could be retained for as long as you choose to keep it there (although you should be allowed to delete whatever you post and thereby prevent Facebook, Google or whoever from retaining it thereafter). 

Even for data accumulated from sources other than the Internet--possibly much of Target's data was accumulated from activity of customers at bricks and mortars stores--could be subject to time limits on retention.  Why does it matter who was buying what brand of diapers two years ago?  Kids grow older and stop needing diapers, and the customer isn't going to buy any brand of diapers no matter how badly bombarded with advertising.  And if a person stops by at a Target store a few times a year, would the store's extremely limited information about that person's buying habits really justify keeping information about the person?  Why put that person at risk of being victimized by hackers when the store's knowledge of the person has little commercial value?  The bottom line is much less information should be accumulated, and the justifications for keeping whatever is kept should be much stronger than they now are.

Some of the proposals for reform of the NSA reportedly take a similar approach.  Data accumulation may be taken out of the hands of the NSA and placed with service providers or other third parties.  While such non-NSA accumulations would present tempting targets for the bad guys, they could be spread out among more places (and therefore be more difficult to attack).  In addition, time limits should be set on the retention of such data.  Yes, any such time limits might make detection of terrorists and other bad guys harder.  But there isn't much evidence that NSA's Big Gulp of data has detected a lot of terrorists anyway, so what we lose from time limits could be pretty theoretical.

Time limits on data retention would mean potentially big changes for the business models of some major companies.  So be it.  Our personal data and personal lives don't exist to serve the needs of soulless corporations.  The surging appeal of SnapChat, with its limited half-life for posted photographs, shows that people want time limits on data about themselves.  One of the most appealing aspects of American life is that you can re-invent yourself.  No need to be weighed down by what you were years ago.  And you shouldn't have to be weighed down by data stored by Internet or retailing giants years ago.  Live free.  Power to the Delete key.  Death to personal data. 

Sunday, June 16, 2013

How to Improve NSA Surveillance

Despite the uproar, there's little chance of changing the scope and extent of NSA surveillance of Americans.  No politician wants to be blamed if there's another Boston Marathon-type bombing.  So they'll hide behind the usual gridlock and do nothing. 

That being the case, we might as well make the most of NSA's surveillance.  After all, it's being done on the taxpayer's dime, and taxpayers ought to get their money's worth.  Here are some ways NSA can make 'round the clock surveillance a better experience for all of us.

Package Delivery.  Since NSA knows where you are at all times, it could run a great delivery service.  Let's say you're on the road and forgot to bring your cellphone recharger.  An NSA courier could be dispatched with a new recharger in a flash.  And they'd want to make this delivery.  After all, it's harder to keep track of you if your cell phone battery is dead. 

And if you're traveling with a small child and need is a package of disposable diapers and some wipes, NSA could deliver them for a modest fee, even to the highway rest stop where you discovered what you forgot to pack.  This would not only please many a distressed parental taxpayer, it would also give NSA a stream of fee revenue that could supplement its multi-billion dollar budget. 

Chatline.  There are many lonely people, and NSA may be among the few that care to listen in on their phone calls.  Perhaps NSA could operate chatlines, to help the lonely find companionship.  Maybe NSA will get lucky and a frustrated terrorist will unburden himself on a chatline, confessing to having fantasies about pressure cookers. 

Dating Service.  If you're single, NSA already knows how bad your personal life is.  They know everything about you--and everyone else.  Since they know so much, they might as well operate a dating service.  With all that they know, they should be able to find the perfect match for you in only three nanoseconds of processing time on their massive supercomputers.

Grocery Shopping.  NSA could doing your grocery shopping and bill your bank account, all without you having to do more than tell them your grocery list.  You can pick up the phone and say what you need.  No need to dial because NSA's monitors will pick up your request anyway, and they can send one of their personnel to the supermarket.  Billing your bank account will be a breeze, since they already know the number and track everything that goes on in it.  Indeed, there's no reason for NSA to stop with groceries.  It could keep you well-stocked with beer and wine, pick up and return your dry cleaning, and arrange for pizza to be delivered in time for dinner.  You'd have to pay fees for these services, but think of the convenience.

Concierge Services.  There's more.  NSA could offer the full range of concierge services.  They could get you movie tickets, make dinner reservations, call cabs, send personnel out to be your personal shopper, and so on.  They already monitor your credit card and banking activity, so they know what movies you see, where you have dinner, and what your personal shopping consists of.  Might as well make the situation a win-win by offering citizens some conveniences now available mostly to the 1%.

Rebranding NSA.  NSA has an image problem.  It's portrayed by its detractors as an intrusive ogre that laughs derisively while steam rolling over civil liberties.  A common strategy in the business world for such a problem is to rebrand oneself.  NSA could leverage its massive knowledge of every intimate detail of your life by offering services like those described above, and change its name to, say, NSA Deluxe Lifestyle Services.  After all, nothing pleases citizens more than seeing government work for them.

Monday, January 17, 2011

A Key to Facebook's Valuation

Recent press reports indicate that Facebook may go public in a year or so. Its recently reported private placement deal with Goldman Sachs supposedly put a $50 billion valuation on Facebook. Many think this is an optimistic number. Conventional measures of value are hard to apply to Facebook because it doesn't publicly disclose its finances. Uncertainties about its business model add to the problem. One wild card is the continued evolution of online privacy policies.

In many respects, online privacy is an oxymoron. Every day brings news of yet more security breakdowns and thefts of personal information. There doesn't seem to be a website that can't be hacked into, one way or another.

But online crime isn't the most important factor affecting online privacy. The commercialization of the Internet is far more significant. Businesses that want to sell your personal information will do much more to reduce online privacy than pimply kids eating junk food in front of computer screens.

Banks are starting to place targeted ads in your online statements. If your bank account shows, say, several recent debit card charges for fast food breakfasts, you may be offered a discount on your next Egg McMuffin. Some bank customers may like the idea of getting a discount while they review their account activity. Others will be creeped out by the idea that the most confidential financial information they have is being mined for the further profitability of purveyors of salt, sugar and fat. Many customers would be outraged at the possibility that insurance companies might pay to know about their slovenly eating habits and charge them higher life, health or disability insurance premiums. Actual insurance company access to your bank account hasn't been reported in the news, but don't think insurers--and the websites that are collecting your personal information--aren't pondering the possibility.

Banks have a lot of ways to make money, yet they are trying to profit from selling your personal information. Think of the pressures on Facebook, which has far fewer potential revenue streams than a bank. The most valuable thing Facebook has is the personal information it gathers about its members. If it can't find a way to monetize that data, its future could be difficult.

The FTC is proposing guidelines about online privacy. Members of Congress are getting interested in the issue and may offer legislation. One way or another, the law in this area will evolve and soon. When it does, Facebook's stock market value could rise or fall, depending on what rules are imposed. Indeed, since the monetization of personal information is likely to be Facebook's biggest potential revenue stream, online privacy laws could be crucial to determining the company's valuation.

Friday, October 5, 2007

Financial and Personal Privacy

As the use of the Internet extends farther and farther, more information about you becomes available on the world’s largest communications medium. Consequently, the less privacy you have. Personal privacy was once defined by property lines: your home was your castle. Today, privacy is much more a matter of your personal information, and who knows it.

Technology won’t entirely solve the problem. The Internet was designed for communicating information, not protecting it. While legitimate and responsible organizations will constantly strive to improve privacy protections for their customers and constituents, there’s bound to be somebody somewhere who can hack through any technological solution. Identity theft has become rampant.

Don’t rely on the law. The legal system is behind the times in terms of defining and protecting personal and financial privacy in the Internet Age. A sales person cannot trespass on your property and bombard you with sales pitches. But businesses can buy your personal information and use it in a variety of annoying and unwanted ways, all the while increasing the risk that your identity will be stolen. Ten or twenty years from now, the legal system may have caught up with technology and business practices, and constructed strong protection for personal information. Until then, rely more on yourself than the law.

Here are some suggestions:

1. Leave Fewer Footprints. Internet banking and payment systems may be convenient for you. But the reason they’re so prevalent is that they are convenient for banks, utilities, credit card companies, and the other organizations providing them. A large part of the financial system involves bookkeeping, and it’s cheaper to keep books with a computer than with human beings. So the banks, credit card issuers, etc. want you online. The fact that it’s more convenient for you is just a marketing ploy to make you more convenient and profitable for them. But the more your financial life is online, the larger the number of your footprints for online predators to spot and track. Every fall, numerous deer fall prey to people wearing bright orange. It’s usually the incautious deer that end up decorating someone’s wall.

2. Read the Privacy Notices. Banks and credit card companies are required by law to disclose to you their privacy practices. These disclosures are usually made in slips of paper tucked into your monthly account statements, that have an annoying habit of falling out when you open the envelope. It’s almost as if someone wants you to be so annoyed you throw the slip of paper away without reading it. Don’t throw it away. Read it. The disclosures will tell you how much access the bank will provide to others about your account records. Especially important are the disclosures concerning access by third parties. That means the bank may provide your personal information to persons outside the bank. You may have the right to object to some of these third party disclosures, such as those made for marketing purposes. Make sure you object if you don’t like them. Limit the number of organizations that have personal information about you. Reduce the spam, junk mail and marketing telephone calls you get.

3. Don’t Go For 15 Minutes of Fame. Andy Warhol wasn’t talking about something good when he referred to everyone having 15 minutes of fame. Celebrity does more to entertain the audience than elevate the subject. Splattering your entire life on the Internet facilitates identity theft. It also can limit your options. Maybe once you were a beer-swilling gearhead, but today you’re pursuing an MBA with the hope of securing a job with an investment bank. There’s nothing wrong with your ambition. This is America, and it’s the inalienable right of all Americans to re-create themselves. But those photos posted online, showing you stumbling over empty quarter barrel kegs on your way to worship the porcelain goddess, may clash with the pinstriped image you now want to project.

4. Check Your Credit Reports. You’re entitled to a free copy of your credit report once a year from the three credit reporting agencies: Experian, TransUnion and Equifax. Checking your reports doesn’t directly protect your privacy. It just tells you who’s been poking around in your records. But finding that out is the first step toward dealing with improper or unwanted access to your records.

5. Freeze Your Credit History. If you’re a resident of most states, you can freeze your credit history, and make it inaccessible to third parties except with your express permission. We’ve discussed this before at http://blogger.uncleleosden.com/2007/06/protecting-your-credit-files-with-fraud.html. This is a very good idea, because you then control access to some of the most important of your personal information. It creates a little more work for you whenever you apply for credit (because you have to personally lift the freeze to let the potential creditor see your credit history). That can take a few days. But it’s a small price to pay for privacy.

6. Safeguard Your Paper Records. Have a locking mailbox. (A lot of identity theft today still begins with the theft from mailboxes.) Shred or at least tear up financial records you throw away. Have a home safe—you have people coming in to work on your house, clean it, repair the appliances and do a variety of other things; not all of them can necessarily be trusted. Keep the number of credit cards you have down to a minimum. Close out the credit cards you don’t use. This will reduce the quantity of paper records for someone else to steal.

Protecting your privacy takes work. But it's worth it. Repairing your credit history after your identity has been stolen is a veritable task of Sisyphus. Preventing an identity theft takes much less effort than repairing the damage from a theft.

Crime News: Using bugs as mules. http://www.wtop.com/?nid=456&sid=1261401.