Privacy Business and Social Sectors CSC 301 Spring 2018 ... · CSC 301 Spring 2018 Howard Rosenthal...

Post on 03-Jun-2020

2 views 0 download

Transcript of Privacy Business and Social Sectors CSC 301 Spring 2018 ... · CSC 301 Spring 2018 Howard Rosenthal...

PrivacyBusinessandSocialSectors

CSC301Spring2018

HowardRosenthal

CourseNotes:

� Muchofthematerialintheslidescomesfromthebooksandtheirassociatedsupportmaterials,belowaswellasmanyofthereferencesattheclasswebsite

Baase,SaraandHenry,Timothy,AGiftofFire:Social,Legal,andEthicalIssuesforComputingTechnology(5thEdition)Pearson,March9,2017,ISBN-13:978-0134615271Quinn,Michael,EthicsfortheInformationAge(7thEdition),Pearson,Feb.21,2016,ISBN-13978-0134296548

2

LessonGoals

� Personalizedmarketing�  Informedconsent�  SocialNetworks

�  Theirresponsibilities�  Yourresponsibilities

�  Lifeinthecloud�  Locationtracking� Parentandtheinternet� Therighttobeforgotten

3

4

PersonalizedMarketing

�  Everyclickyoumakeandwebsiteyouvisitleavesatrace�  SearchAmazonforabookandyou’llgetmultiplee-mailsaboutthebook

�  Donatetoonecharityandyou’llhearfromtensimilarcharities

�  Subscribetoonemagazineandtenmorewillbeaskingyoutosubscribe

�  Youwillbemarketedbasedonyourpreferences�  Yourpreferenceswillbeusedandaddedtolargedatabasesofpreferencesbasedonage,gender,race,education,cartype,homelocation,buyinghabits(supermarketsknowwhatyoubuy)….

5

InformedConsent

�  Informedconsentincludesthefollowingelements�  Theuseristoldthatdatawillbecollectedandaskedtoaffirmativelyallowthatdatatobecollectedanddistributed

�  Theuserhastheopportunitytooptoutatanytime�  Sometimestheuserisinducedtooptinwithpaymentsorotherrewards

�  Ifyouneedtospecificallyoptout,thisisnotinformedconsent�  Yourbrowsingistrackedunlessyouspecificallyoptout

6

SocialNetworks

� Therearenumeroussocialnetworkingsites�  Facebook�  LinkedIn�  GoogleCircles�  Professionalorganizationsthatallow“friending”�  Tweetingwithfollowers

� Bothweandtheprovidingcompanieshaveresponsibilitiesinpreservingourprivacy

7

SocialMediaAnalytics

�  SocialMediaAnalyticsisthepracticeofgatheringdatafromblogsandsocialmediawebsitesandanalyzingthatdatatomakebusinessdecisions.Themostcommonuseofsocialmediaanalyticsistominecustomersentimentinordertosupportmarketingandcustomerserviceactivities.�  Thefirststepinasocialmediaanalyticsinitiativeistodetermine

whichbusinessgoalsthedatathatisgatheredandanalyzedwillbenefit.�  Typicalobjectivesincludeincreasingrevenues,reducingcustomerservicecosts,

gettingfeedbackonproductsandservicesandimprovingpublicopinionofaparticularproductorbusinessdivision.

�  Oncethebusinessgoalshavebeenidentified,keyperformanceindicators(KPIs)forobjectivelyevaluatingthedatashouldbedefined.�  Forexample,customerengagementmightbemeasuredbythenumbersof

followersforaTwitteraccountandnumbersofre-tweetsandmentionsofacompany'sname.

�  ThereareanumberoftypesofsoftwaretoolsforanalyzingunstructureddatafoundintweetsandFacebookposts.Inadditiontototextanalysis,manyenterprise-levelsocialmediatoolswillharvestandstorethedata.

8

SocialNetworks–OurResponsibilities�  Whenwepostinformationonasiteitbecomesvisibleatmanylevels

�  Maybelimitedtofriends–beproactive�  Canbeavailablegloballyifnotprotected�  Evenapicturewithyouinitmaybetransmittedtoallyourfriends

andacquaintances�  Informationonanysitemaybecomeavailabletoemployers–some

employersaskforyourFacebooksitewhenyouapplyforajob�  Somerulestoprotectyourprivacy

�  Proactivelysetupyoursecurityprofileonasite�  Don’tpostanythingembarrassing�  Becarefulaboutpostingcontroversialopinionsforpublic

consumption�  Nothinglewd–soundsobviousbutithappensallthetime�  Don’tpostpicturesaboutyourvacationuntilyoureturnhome–its

likeputtingupa“PleaseRobMe”sign�  Don’tmakeanyonewhoasksyourfriend–havingthousandsof

unknownfriendsdoesn’tmakeyoumorepopular�  DiscussionQuestion:

�  IsthereinformationthatyouhavepostedtotheWebthatyoulaterremoved?Doyouthinkitisallreallygone?

9

SocialNetworks–ProviderResponsibilities

�  Provideopt-outorpreferablyopt-infeatures�  Whenpeoplejoinasocialnetworktheyarelookingforaneasy

experienceandwilloftenjustagreetoeverything�  Providetheabilityforuserstocontroltheirsecurityprofiles

�  Generalnetworkshavearesponsibilitytomaketheseinstructionscleartothenon-technicaluser

�  Deletealldataaboutauserwhenauserdeletesanaccount�  FederalTradeCommissionrequiredthisofFacebook�  Sideeffect-Coulditleadtothedeletion/destructionofcriminal

evidence?�  Removecriminalsites

�  Sometimesthelinesbetweencensorshipandsocialresponsibilityareblurry

�  Somebehaviorislegalforadultsbutillegalforchildren–howdoyouverifytheageofsomeonewhologson

�  Keepyourpersonaldatathatisprivatesecurefromhackersandcriminals

10

LifeInTheCloud�  Ifyouposttoomuchpersonaldatayoumaygiveawaydatalinkedtothatinformation�  Don’tpostyourmother’smaidenname�  Evaluatethebenefitoftheposting

�  Blogsmaybepublic�  Evencloudservicescanbehacked

�  Doyouwanttostorepersonaldataandyourphysicalbackupsonthecloud

�  Whathappensifthedataisstolen,hackedorlost?�  Differentcloudsuppliershavedifferentlevelsofquality,reliability

andsecurity�  LegalandEthicalResponsibilityoftheCloudSupplier

�  Stillevolving�  Whoisresponsibleforhacks–thehackerorthesupplier?�  Securitylevelsinthecommercialworldaren’tfullydefined,sohow

canyoupromiseorenforcealevel�  Evenreliabilityisoftenmisunderstood

11

LocationTracking�  WeoftenthinkofGPSandmapapplicationswhenwethinkoflocation

tracking,buttherearemanyothertrackersoutthere�  WhenyoulogontoGooglefromanewlocationyouwillgetane-mailortext

askingyouifthislocationislegitimate�  Cellphonesandotherdevicesareusedforlocationtracking�  Banksdothesamething,andaskforevenmoreverificationbysendingacode

toyouviaanalternatemeanssuchascellphone�  FastPasscardsknowwhenyouareinacertainlaneonthefreeway�  LoJacktracksyourcar�  Ifyougoabroadthegovernmentandtheairlineknowalotaboutyourplans

�  TheairlineevenreportsonyourarrivaltotheTSAupondeparture�  Acriminalmayhaveatrackerattachedtoanankle�  Someparentsareinstallingtrackerchipsintheirchildren

�  Canhelpifyouryoungchildwandersoffinthemall,butcanhurtifothersstarttrackingyourchild

�  Thisinformationcanbeusedforgoodpurposes�  Findyourcar,oryourchild(viatheircellphone;Evenhelpfindalostcell

phone�  Sendyouinformationthatmaybeofgreatinterestoropportunityforyou

�  Orbadpurposes�  Informationcanbesubpoenaed�  Ifhackedinformationcanletthieves,opponentsorothersobtaininformation

thatisembarrassingorthatyoumightotherwisenotwantreleased12

PrivacyandTrackingToolsForParents�  YoucantrackyouchildviathephoneGPS�  Theautoclubofferedaservicefortrackingyourcat,andtherebyyourchild

�  Implantingchips�  Childhasasimpletrackingchipplantedinanarm�  Justanextensionofthetrackingbraceletssometimesusedfor

paroles,Alzheimer’spatientsetc.�  Thisisnewandstillcontroversial

�  Schoolsmaywanttousethistotrackfortruants�  Couldalsobeusedaapolicetool

�  NewerchipsmaybecomesignificantlysmarterandprovidedirectaccesstotheInternet,ourself-drivingcars,etc.

�  Therearedangers�  Canothersinterceptachild’ssignalsandusethesignalstotrack

thechild�  Anyoftheabovetoolscanalsobeusedtotrackadultsforavarietyofreasons�  Journalists,politicians,celebritieswouldloseevenmoreprivacy

13

TheRightToBeForgotten�  Socialnetworkswillremoveposteddata,butwhathappenswhenthatdatahasbeen

copiedandpostedbyothers�  Mostcompaniesthathaveyouonane-maillistallowyoutoopt-out–lookforthesmall

printattheendofthemessage�  Thirdpartiesmaybecollectingalltypesofdataaboutyou(perhapscollectedbyother

companies)�  Thereisnowayforyoutoknowallthedatathathasbeencollectedandwhohasit.�  Youcan’tgotoonesinglelocationtoseewhohasinformationonyouandtherefore

easilyselectwhoyouwanttohavedeletedataaboutyou�  Sometimesaskingfordatatoberemovedcanharmyou

�  Creditagenciescollectallkindsofdata�  Withoutacreditratingyouwillhaveahardtimegettingaloanoracreditcard.

�  Doyouwanttodeleteallyourhealthdataifyouswitchhealthproviders?�  Thismaynotbelegalandconflictwiththeprovider’sresponsibilitytosharethisdatawithyour

newprovider.�  WecanstayofftheInternet–thatisanegativeright(liberty)�  Thepositiveorclaimrighttohaveallinformationaboutus,eveninformationobtained

fromothersources,permanentlyeraseddoesnotyetexistlegallyortechnically�  Toeliminateallthisdatawouldrequirecollectingallthemetadataaboutyou–even

moredatacollection!�  Cleaningdata,avoidingdeletinginformationaboutotherswiththesamenames,etc.are

alsoissues�  Doyouthinkaclaimrighttobecompletely“forgotten”islegallyorethicallydesirable

orwarranted?�  Whatwouldyourresponsibilitybeifyouexercisedthisclaim?

14