Showing posts with label data mining. Show all posts
Showing posts with label data mining. Show all posts

Wednesday, February 29, 2012

STILL THINK ONLINE DATING IS OK? READ THIS!

DATING Pictures, Images and Photos

Warning sounded over 'flirting robots'

Those entering online dating forums risk having more than their hearts stolen.


A program that can mimic online flirtation and then extract personal information from its unsuspecting conversation partners is making the rounds in chat forums, according to security software firm PC Tools.

The artificial intelligence of CyberLover's automated chats is good enough that victims have a tough time distinguishing the "bot" from a real potential suitor, PC Tools said. The software can work quickly too, establishing up to 10 relationships in 30 minutes, PC Tools said. It compiles a report on every person it meets complete with name, contact information, and photos.

"As a tool that can be used by hackers to conduct identity fraud, CyberLover demonstrates an unprecedented level of social engineering," PC Tools senior malware analyst Sergei Shevchenko said in a statement.


Among CyberLover's creepy features is its ability to offer a range of different profiles from "romantic lover" to "sexual predator." It can also lead victims to a "personal" Web site, which could be used to deliver malware,
PC Tools said.

Although the program is currently targeting Russian Web sites, PC Tools is urging people in chat rooms and social networks elsewhere to be on the alert for such attacks. Their recommendations amount to just good sense in general, such as avoiding giving out personal information and using an alias when chatting online. The software company believes that CyberLover's creators plan to make it available worldwide in February.

Robot chatters are just one type of social-engineering attack that uses trickery rather than a software flaw to access victim's valuable information. Such attacks have been on the rise and are predicted to continue to grow.

Mike Greene, vice president of product strategy at PC Tools, said that the company learned of CyberLover's existence earlier this week as part of its regular monitoring of IRC chat rooms and other places where talk about malware takes place.

Greene said that it is hard to tell how prevalent use of the program is.

"We don't have exact statistics, but I think it's early on," he said.

Greene said that the perceived anonymity of the Internet has desensitized people to the fact that information disclosed in an online chat can cause real-world damage.
"People are used to not opening attachments or maybe not clicking on a link that shows up in their IM," he said. "But this emulates a real conversation, so you more are likely to give over personal information, click on a link or send your photograph."


Friday, August 19, 2011

Facebook - Not So Private!



By Daniel Emery Technology reporter, BBC News



(CANADA) The man who harvested and published the personal details of 100m Facebook users has spoken out about his motives.



Ron Bowes, a Canadian security consultant, used a piece of code to scan Facebook profiles, collecting data not hidden by users' privacy settings.



The list, which contains the URL of every searchable Facebook user's profile, name and unique ID, has been shared as a downloadable file.



Mr Bowes told BBC News that he did it as part of his work on a security tool.



"I'm a developer for the Nmap Security Scanner and one of our recent tools is called Ncrack," he said. "It is designed to test password policies of organisations by using brute force attacks; in other words, guessing every username and password combination."



By downloading the data from Facebook, and compiling a user's first initial and surname, he was able to make a list of the most common probable usernames to use in the tool.



The three most common names, he found, were jsmith, ssmith and skhan.



In theory, researchers could then combine this list with a catalogue of the most commonly used passwords to test the security of sites. Similar techniques could be used by criminals for more nefarious means.



Mr Bowes said his original plan was to "collect a good list of human names that could be used for these tests".



"Once I had the data, though, I realised that it could be of interest to the community if I released it, so I did," he added. I am of the belief that, if I can do something then there are about 1,000 bad guys that can do it too”



Mr Bowes confirmed that all the data he harvested was already publicly available but acknowledged that if anyone now changed their privacy settings, their information would still be accessible.



"If 100,000 Facebook users decide that they no longer want to be in Facebook's directory, I would still have their name and URL but it would no longer, technically, be public," he said.



Mr Bowes said that collecting the data was in no way irresponsible and likened it to a telephone directory.



"All I've done is compile public information into a nice format for statistical analysis," he said



Simon Davies from the watchdog Privacy International told BBC News it was an "ethical attack" and that more personal information had not been included in the trawl.



"This is a reputational and business issue for Facebook, for now," he said



"They can continue to ride the risk and hope nothing cataclysmic occurs, but I would argue that Facebook has a special responsibility to go beyond doing the bare minimum," he added.



Snowball effect

Mr Bowes' file has spread rapidly across the net.



On the Pirate Bay, the world's biggest file-sharing website, the list was being distributed and downloaded by thousands of users.



One user said that the list showed "why people need to read the privacy agreements and everything they click through".



In a statement to BBC News, Facebook confirmed that the information in the list was already freely available online.



"No private data is available or has been compromised," the statement added.



That view is shared by Mr Bowes, who added that harvesting this data highlighted the possible risks users put themselves in.



"I am of the belief that, if I can do something then there are about 1,000 bad guys that can do it too.



"For that reason, I believe in open disclosure of issues like this, especially when there's minimal potential for anybody to get hurt.



"Since this is already public information, I see very little harm in disclosing it."



Digital trends


However, he said, it also highlighted a new trend that was emerging in the digital age.



"With traditional paper media, it wasn't possible to compile 170 million records in a searchable format and distribute it, but now we can," he said.



"Having the name of one person means nothing, and having the name of a hundred people means nothing; it isn't statistically significant.



"But when you start scaling to 170 million, statistical data emerges that we have never seen in the past."



A spokesperson for Facebook said the list was "similar to the white pages of the phone book.



"This is the information available to enable people to find each other, which is the reason people join Facebook."



"If someone does not want to be found, we also offer a number of controls to enable people not to appear in search on Facebook, in search engines, or share any information with applications."



Earlier this year there was a storm of protest from users of the site over the complexity of Facebook's privacy settings. As a result, the site rolled out simplified privacy controls.



Facebook has a default setting for privacy that makes some user information publicly available. People have to make a conscious choice to opt-out of the defaults.





original article here

Wednesday, December 8, 2010

Browser Flaw Can Pick Up Your Porn Site Visits

Dozens of websites have been secretly harvesting lists of places that their users previously visited online, everything from news articles to bank sites to pornography, a team of computer scientists found.

The information is valuable for con artists to learn more about their targets and send them personalized attacks. It also allows e-commerce companies to adjust ads or prices — for instance, if the site knows you've just come from a competitor that is offering a lower price.

Although passwords aren't at risk, in harvesting a detailed list of where you've been online, sites can create thorough profiles on its users.

The technique the University of California, San Diego researchers investigated is called "history sniffing" and is a result of the way browsers interact with websites and record where they've been. A few lines of programming code are all a site needs to pull it off.

Although security experts have known for nearly a decade that such snooping is possible, the latest findings offer some of the first public evidence of sites exploiting the problem. Current versions of the Firefox and Internet Explorer browsers still allow this, as do older versions of Chrome and Safari, the researchers said.

The report adds to growing worry about surreptitious surveillance by Internet companies and comes as federal regulators in the U.S. are proposing a "Do Not Track" tool that would prevent advertisers from following consumers around online to sell them more products.

The researchers found 46 sites, ranging from smutty to staid, that tried to pry loose their visitors browsing histories using this technique, sometimes with homegrown tracking code. Nearly half of the 46 sites, including financial research site Morningstar.com and news site Newsmax.com, used an ad-targeting company, Interclick, which says its code was responsible for the tracking.

Interclick said the tracking was part of an eight-month experiment that the sites weren't aware of. The New York company said it stopped using the technique in October because it wasn't successful in helping match advertisers to groups of Internet users. Interclick emphasized that it didn't store the browser histories.

Morningstar said it ended its relationship with Interclick when it found out about the program, and NewsMax said it didn't know that history sniffing had been used on its users until AP called. NewsMax said it is investigating.

The researchers studied far more sites — a total of the world's 50,000 most popular sites — and said many more behaved suspiciously, but couldn't be proven to use history sniffing. Nearly 500 of the sites studied had characteristics that suggested they could infer browsers' histories, and more than 60 transferred browser histories to the network. But the researchers said they could only prove that 46 had done actual "history hijacking."

"Browser vendors should have fixed this a long time ago," said Jeremiah Grossman, an Internet security expert at WhiteHat Security Inc., which wasn't involved in the study. "It's more evidence that we not only needed the fix, but that people really should upgrade their browsers. Most people wouldn't know this is possible."

The latest versions of Google Inc.'s Chrome and Apple Inc.'s Safari have automatic protections for this kind of snooping, researchers said. Mozilla Corp. said the next version of Firefox will have the same feature, adding that a workaround exists for some older versions as well.

Microsoft Corp. noted that Internet Explorer users can enable a private browsing mode that prevents the browser from logging the user's history, which prevents this kind of spying. But private browsing also strips away important benefits of the browser knowing its own history, such as displaying Google links you've visited in different colors than those you haven't.

"It's surprising, the lifetime that this fundamental a privacy violation can stick around," said Hovav Shacham, an assistant professor of computer science and engineering at UC San Diego and one of the paper's authors.

Internet companies are obsessed with tracking users' behavior so they can target their ads better. Uproar has prompted the Federal Trade Commission to propose rules that would limit advertisers' ability to track Internet users to show them advertisements. The "Do Not Track" tool the commission is proposing could eventually take the form of a browser setting that tells advertisers which visitors are off limits; such a setting, though, wouldn't necessarily block history sniffing.

History sniffing is essentially a side-by-side comparison of Web pages you've already visited with Web pages that a particular site wants to see if you've visited. If there's a match, users likely would never know, but the site administrators would learn a lot about their audiences.

For instance, a popular porn site was checking its visitors' histories to see if they'd visited 23 other pornography sites, and the code used on the Morningstar and NewsMax.com sites looked for matches against 48 specific Web pages, all related to Ford automobiles.

Sites can carry on this kind of inspection very quickly. Grossman said modern programs can check as many as 20,000 Internet addresses per second.

Browser Flaw Can Pick Up Your Porn Site Visits

Dozens of websites have been secretly harvesting lists of places that their users previously visited online, everything from news articles to bank sites to pornography, a team of computer scientists found.

The information is valuable for con artists to learn more about their targets and send them personalized attacks. It also allows e-commerce companies to adjust ads or prices — for instance, if the site knows you've just come from a competitor that is offering a lower price.

Although passwords aren't at risk, in harvesting a detailed list of where you've been online, sites can create thorough profiles on its users.

The technique the University of California, San Diego researchers investigated is called "history sniffing" and is a result of the way browsers interact with websites and record where they've been. A few lines of programming code are all a site needs to pull it off.

Although security experts have known for nearly a decade that such snooping is possible, the latest findings offer some of the first public evidence of sites exploiting the problem. Current versions of the Firefox and Internet Explorer browsers still allow this, as do older versions of Chrome and Safari, the researchers said.

The report adds to growing worry about surreptitious surveillance by Internet companies and comes as federal regulators in the U.S. are proposing a "Do Not Track" tool that would prevent advertisers from following consumers around online to sell them more products.

The researchers found 46 sites, ranging from smutty to staid, that tried to pry loose their visitors browsing histories using this technique, sometimes with homegrown tracking code. Nearly half of the 46 sites, including financial research site Morningstar.com and news site Newsmax.com, used an ad-targeting company, Interclick, which says its code was responsible for the tracking.

Interclick said the tracking was part of an eight-month experiment that the sites weren't aware of. The New York company said it stopped using the technique in October because it wasn't successful in helping match advertisers to groups of Internet users. Interclick emphasized that it didn't store the browser histories.

Morningstar said it ended its relationship with Interclick when it found out about the program, and NewsMax said it didn't know that history sniffing had been used on its users until AP called. NewsMax said it is investigating.

The researchers studied far more sites — a total of the world's 50,000 most popular sites — and said many more behaved suspiciously, but couldn't be proven to use history sniffing. Nearly 500 of the sites studied had characteristics that suggested they could infer browsers' histories, and more than 60 transferred browser histories to the network. But the researchers said they could only prove that 46 had done actual "history hijacking."

"Browser vendors should have fixed this a long time ago," said Jeremiah Grossman, an Internet security expert at WhiteHat Security Inc., which wasn't involved in the study. "It's more evidence that we not only needed the fix, but that people really should upgrade their browsers. Most people wouldn't know this is possible."

The latest versions of Google Inc.'s Chrome and Apple Inc.'s Safari have automatic protections for this kind of snooping, researchers said. Mozilla Corp. said the next version of Firefox will have the same feature, adding that a workaround exists for some older versions as well.

Microsoft Corp. noted that Internet Explorer users can enable a private browsing mode that prevents the browser from logging the user's history, which prevents this kind of spying. But private browsing also strips away important benefits of the browser knowing its own history, such as displaying Google links you've visited in different colors than those you haven't.

"It's surprising, the lifetime that this fundamental a privacy violation can stick around," said Hovav Shacham, an assistant professor of computer science and engineering at UC San Diego and one of the paper's authors.

Internet companies are obsessed with tracking users' behavior so they can target their ads better. Uproar has prompted the Federal Trade Commission to propose rules that would limit advertisers' ability to track Internet users to show them advertisements. The "Do Not Track" tool the commission is proposing could eventually take the form of a browser setting that tells advertisers which visitors are off limits; such a setting, though, wouldn't necessarily block history sniffing.

History sniffing is essentially a side-by-side comparison of Web pages you've already visited with Web pages that a particular site wants to see if you've visited. If there's a match, users likely would never know, but the site administrators would learn a lot about their audiences.

For instance, a popular porn site was checking its visitors' histories to see if they'd visited 23 other pornography sites, and the code used on the Morningstar and NewsMax.com sites looked for matches against 48 specific Web pages, all related to Ford automobiles.

Sites can carry on this kind of inspection very quickly. Grossman said modern programs can check as many as 20,000 Internet addresses per second.

Saturday, October 16, 2010

Is Your Private Phone Number on Facebook?


Probably.

So are your friends' numbers.

If you have a friend on Facebook who has used the iPhone app version to access the site, then it's very possible that your private phone numbers - and those of lots of your and their friends - are on the site.

The reason: Facebook's "Contact Sync" feature, which synchronises your friends' Facebook profile pictures with the contacts in your phone.

Except that it doesn't do that on your phone. Oh no. Because that would be wrong, to pull the photos down from Facebook and put them on your phone. That would breach Facebook's terms of service. Update: A more recent version of the app shows that it does download "your friends' profile photos and other info from Facebook" to add to your iPhone address book.

Instead, what What Facebook's app does it that it imports all the names and phone numbers you have on your (smart)phone, uploads them to Facebook's Phonebook app (got a Facebook account? Here's your Phonebook). (Update: Rhodri Marsden says that you'll now get a big warning sign saying that the numbers are imported into Facebook. That's above.)

Pause for a moment and go and look at it. Did you know those numbers? Did you collect them? Despite the reassuring phrase there - "Facebook Phonebook displays contacts you have imported from your phone, as well as your Facebook friends" - it's absolutely not true. I know because there are numbers there which I don't have. OK, perhaps the people who own them added them; but that's not clear either. So how did they get there? Because it only takes one person to upload another person's number, and the implication is that it's going to be shared around everywhere.

Update: that's the implication of "all contacts from your device... will be sent to Facebook and be subject to Facebook's Privacy Policy". Note, not just your friends - but everyone on your device.

The implications are huge, and extremely worrying. All it takes is for someone's Facebook account to be hacked (perhaps via their phone being stolen) and lots of personal details are revealed. Or, as Craig noted in the comments, you get your phonebook record of "Steve Car" (which was for his garage mechanic) somehow linked to someone called "Steve Carlton" - who he doesn't know.

Update: Facebook says, in a statement: "Facebook never shares personally identifiable information with third parties – advertisers are only given anonymised and aggregated data." It also adds: "Facebook is a free service and something that many people find adds value to their day-to-day lives. As with any service, users do need to invest some time in order to use it properly and we encourage people to use their privacy settings to do this and to access the Help Centre for support."

Kurt von Moos, who first wrote about this earlier this year (since when Facebook has revised its privacy statement, but not altered what goes on in this way) says that there are a number of reasons to be concerned. As he puts it:
"1) Facebook doesn't warn users that they are uploading their phone's adress book to Facebook. In fact, because Facebook doesn't sync contact numbers or email addresses TO your phone, most users wrongly assume that Facebook Contact Sync only syncs user pictures. In reality though, they are pumping your address book, without your consent." [Since then the Facebook app has clearly been updated with a warning.]

Facebook says you can remove your mobile contacts, but it's not clear that that will remove your mobile if someone else uploads it.

von Moos continues:
"2) Phone numbers are private and valuable. Most people who have entrusted you with their phone numbers assume you will keep them private and safe. If you were to ask your friends, family or co-workers if they are ok with you uploading their private phone numbers to be cross-referenced with other Facebook users, how many of them do you think would be ok with it?"

He also points to even more egregious problems: (a) can you be sure how Facebook, or its advertisers or partners or whatever it becomes down the line, will use that data? (b) why is it that Facebook takes all your mobile numbers, rather than matching names of contacts with names of friends? (c) sometimes, it gets the matches wrong - and incorrect (or faked) data that people have given to Facebook as their "contact" details (such as hotels or businesses) gets linked as being a "friend", or the lack of an international dialling prefix messes up the match, and means again that someone who you don't know is identified as a "friend" or contact.

von Moos concludes: "There are some contacts and phone numbers who's privacy I simply refuse to risk on the Web. Facebook has taken and continues to take liberties on behalf of their users. Their perception of privacy and their users perception of privacy is often very different. I don't think this is maliciousness on Facebook's part, but it does show me that Facebook is painfully out of touch with the needs and beliefs of their CORE users, who are still wary of the openness that a Web 2.0 lifestyle entails."

It's not clear whether the official Facebook for Android app does the same. We'd be interested to hear from you if you've noticed this with the app. Update: people in the comments seem to be saying that it does.

So - beware: Facebook quite probably has your details. More of them, in fact, than you might have thought.

SEE PHONE NUMBERS ON FACEBOOK!

Is Your Private Phone Number on Facebook?


Probably.

So are your friends' numbers.

If you have a friend on Facebook who has used the iPhone app version to access the site, then it's very possible that your private phone numbers - and those of lots of your and their friends - are on the site.

The reason: Facebook's "Contact Sync" feature, which synchronises your friends' Facebook profile pictures with the contacts in your phone.

Except that it doesn't do that on your phone. Oh no. Because that would be wrong, to pull the photos down from Facebook and put them on your phone. That would breach Facebook's terms of service. Update: A more recent version of the app shows that it does download "your friends' profile photos and other info from Facebook" to add to your iPhone address book.

Instead, what What Facebook's app does it that it imports all the names and phone numbers you have on your (smart)phone, uploads them to Facebook's Phonebook app (got a Facebook account? Here's your Phonebook). (Update: Rhodri Marsden says that you'll now get a big warning sign saying that the numbers are imported into Facebook. That's above.)

Pause for a moment and go and look at it. Did you know those numbers? Did you collect them? Despite the reassuring phrase there - "Facebook Phonebook displays contacts you have imported from your phone, as well as your Facebook friends" - it's absolutely not true. I know because there are numbers there which I don't have. OK, perhaps the people who own them added them; but that's not clear either. So how did they get there? Because it only takes one person to upload another person's number, and the implication is that it's going to be shared around everywhere.

Update: that's the implication of "all contacts from your device... will be sent to Facebook and be subject to Facebook's Privacy Policy". Note, not just your friends - but everyone on your device.

The implications are huge, and extremely worrying. All it takes is for someone's Facebook account to be hacked (perhaps via their phone being stolen) and lots of personal details are revealed. Or, as Craig noted in the comments, you get your phonebook record of "Steve Car" (which was for his garage mechanic) somehow linked to someone called "Steve Carlton" - who he doesn't know.

Update: Facebook says, in a statement: "Facebook never shares personally identifiable information with third parties – advertisers are only given anonymised and aggregated data." It also adds: "Facebook is a free service and something that many people find adds value to their day-to-day lives. As with any service, users do need to invest some time in order to use it properly and we encourage people to use their privacy settings to do this and to access the Help Centre for support."

Kurt von Moos, who first wrote about this earlier this year (since when Facebook has revised its privacy statement, but not altered what goes on in this way) says that there are a number of reasons to be concerned. As he puts it:
"1) Facebook doesn't warn users that they are uploading their phone's adress book to Facebook. In fact, because Facebook doesn't sync contact numbers or email addresses TO your phone, most users wrongly assume that Facebook Contact Sync only syncs user pictures. In reality though, they are pumping your address book, without your consent." [Since then the Facebook app has clearly been updated with a warning.]

Facebook says you can remove your mobile contacts, but it's not clear that that will remove your mobile if someone else uploads it.

von Moos continues:
"2) Phone numbers are private and valuable. Most people who have entrusted you with their phone numbers assume you will keep them private and safe. If you were to ask your friends, family or co-workers if they are ok with you uploading their private phone numbers to be cross-referenced with other Facebook users, how many of them do you think would be ok with it?"

He also points to even more egregious problems: (a) can you be sure how Facebook, or its advertisers or partners or whatever it becomes down the line, will use that data? (b) why is it that Facebook takes all your mobile numbers, rather than matching names of contacts with names of friends? (c) sometimes, it gets the matches wrong - and incorrect (or faked) data that people have given to Facebook as their "contact" details (such as hotels or businesses) gets linked as being a "friend", or the lack of an international dialling prefix messes up the match, and means again that someone who you don't know is identified as a "friend" or contact.

von Moos concludes: "There are some contacts and phone numbers who's privacy I simply refuse to risk on the Web. Facebook has taken and continues to take liberties on behalf of their users. Their perception of privacy and their users perception of privacy is often very different. I don't think this is maliciousness on Facebook's part, but it does show me that Facebook is painfully out of touch with the needs and beliefs of their CORE users, who are still wary of the openness that a Web 2.0 lifestyle entails."

It's not clear whether the official Facebook for Android app does the same. We'd be interested to hear from you if you've noticed this with the app. Update: people in the comments seem to be saying that it does.

So - beware: Facebook quite probably has your details. More of them, in fact, than you might have thought.

SEE PHONE NUMBERS ON FACEBOOK!

Saturday, July 17, 2010

Minimize What People Can Find Out About You Online

People Search Engines: They Know Your Dark Secrets … and Tell Anyone
By JR Raphael, PC World
Privacy Pictures, Images and Photos

Social search engines can turn up your Amazon Wish List, photos of your kids, where your kids go to school, your address, your business, where you went to school, your musical tastes, your medical problems, all about your breakups & divorces, your mental health status and much, much more. What else is out there that you don't want everyone to know, and what can you do to protect yourself?


I know things about my lawyer I absolutely should not know. He's 55 years old, listens to the music of the band Creed, and screams like a little girl when riding roller coasters. He also relaxes with New Age spa treatments and is thinking about getting an electronic nose-hair trimmer. And that's just the start.

Now, let me be clear: I've never spent a single moment outside the office with this guy (and for what it's worth, I'd just as soon not be privy to his personal grooming habits). I learned all of these details by tracking his social footprint across the Web -- and he probably has no idea that he has left such a vivid trail behind.

In our age of social sharing, we expect some of our thoughts to be public. But as we slowly put more and more pieces of ourselves online, specialized search engines are making it easier than ever to pull them together into a highly detailed (and potentially invasive) profile of our virtual lives (read "Online Stalking Made Easy").

I'll let you in on a little secret: The picture isn't always pretty. And even if no rap sheet turns up, do you really want the world to know that you look at bad-breath cures online or post awful "Star Trek" fan fiction?

The depths of the Deep Web
You hear a lot of terms bounced around when you talk about this growing breed of search engines. Some services like to be called "social search" utilities, while others prefer the phrase "people search." Many boast of their ability to delve through the "Deep Web" that even Google doesn't touch.

"Even though most people think the size of the Web is basically the Google crawl index, there's actually a lot of information that Google doesn't crawl," says Harrison Tang, founder and CEO of Spokeo -- which, taking a mash-up approach to its identification, describes itself as a "social people search engine" service.

People search engine Spokeo is upfront about what it thinks it can find on anyone.

Spokeo, like its competitors Pipl and CVGadget, is designed to let you dig up information on friends, foes and anyone in between. Spokeo goes a step further than many of the other services, though, by importing your entire e-mail address book.

Then, for a few bucks a month, it continually monitors your contacts and lets you know whenever anyone has done anything new, anywhere online. (The site's home page promises to help you "uncover personal photos, videos and secrets," including "juicy" and "mouth-watering news about friends and co-workers.")


Each individual bit of information may seem insignificant, but the cumulative effect of seeing it assembled in a neatly packaged portfolio is enough to give almost anyone pause.


"Aggregated identity is actually a new type of identity," Tang says, theorizing about why so many people seem to use the word "spooky" when describing his service. "A lot of people know that they have a public MySpace page, a lot of people know that they have a public Twitter album. But, when combined together, it's not one plus one equals two -- you actually create a new identity."


How Spokeo works
Spokeo's system uses your contacts' e-mail addresses to track their activity on a few dozen services, ranging from basic blogs and social networks to a slew of photo- and video-sharing sites. That means the random photos of your kids you shared on Flickr two years ago (or perhaps those less innocent images from your spring-break trip a decade earlier) will pop up right under your name, seconds after someone searches for you.
Less obvious sources such as Amazon Wish Lists, Pandora playlists and movie rating sites fill in the colorful details that you may not have realized were out there at all -- things like (in my lawyer's case) an affinity for New Age jams and nasal maintenance.

I found Mr. Attorney's age on an old MySpace profile and his roller coaster behavior on a personal YouTube video, but Pandora divulged his cravings for Creed and his suggested usages for the "Spa Radio" station he had created. As for the nose-hair trimmer, he can thank his Amazon Wish List for sending that factoid my way.

For sale: Your information

Rapleaf gathers information from the Deep Web -- often posted by you -- and sells it to marketers.

Other services access the same data and then sell the information under the banner of marketing research. One highly visible example is Rapleaf, a company that describes its services as "data and people lookup." Clients pay thousands of dollars to have detailed social profiles of individuals compiled in their own customer databases. As is the case with the data that Spokeo assembles, the information is all publicly available -- Rapleaf just brings it together. "Things that people have posted are out there for anyone to come and see," says Joel Jewitt, Rapleaf's vice president of business development. "As long as you're not going beyond that, that's within the privacy norms today."

Most of Rapleaf's clients, Jewitt says, are simply trying to understand how to use social media more effectively for marketing. An auto manufacturer, for example, might want to know which car models its customers are checking out and discussing on social Internet services. Armed with the company's list of customer e-mail addresses, Rapleaf would crawl the Web and track down the information, person by person.

"It's pretty standard Web spidering," Jewitt says. "We re-create in an automatic way what someone from the general public would be able to do if they were looking."

Electronic exposure

Whether they target businesses or individuals, the services have one thing in common: Unlike the public-record-driven search tools of the past, the new people-tracking utilities build a highly detailed dossier about you solely from information that you yourself published -- a circumstance that may give you a distinct feeling of discomfort.

"What it does is make the ubiquity of the Internet and the sheer openness of the world tangible," says Internet privacy expert Kevin B. McDonald, executive vice president of Alvaka Networks, a network management firm. "It makes the whole concept of the world sharing of information and the 'no-walls' approach that the Internet was designed for very real to people."

The reality can be chilling if the information is going to certain interested individuals: a curious client, a boss big on background checks or an obsessive ex, say. A recent study reported that half of all British Internet users surveyed admitted to having used the Internet to look up information on a former flame. The ease with which someone can arrange to monitor your every electronic move certainly adds a new dimension to the idea of fixation.

"It is a little 'stalkery,'" says Marc Rotenberg, executive director of the Electronic Privacy Information Center. "If the information is distributed, that's actually a form of privacy. When it's gathered up in one place, it creates some new risks."

Rotenberg is no fan of companies that assemble nuggets of personal but public information to turn a profit. "The fact that someone's made something public doesn't mean that someone else can sell it," he contends. "I would say even with affirmative consent, if there's going to be a market for personal data, the user should get some percentage of whatever value the data has."

Taking control
The thing to remember, of course, is that these services aren't doing anything illegal. The information they gather is information that anyone who knew where to look -- and had the time to do it -- could find. So rather than ignoring the king-size file that may have been collected on you, McDonald suggests, you should try to use it as a tool to understand and control your online identity.

"I've come to the point where rather than be driven by the Internet, I intend to drive it to the degree that I can," he says.

"All you can do is learn to live with it," McDonald says. "That's the confines of the world that we live in."


For suggestions on concrete steps you can take to reduce your online exposure, see
"People Search Engines: Slam the Door on What Info They Can Collect."

ORIGINAL

Minimize What People Can Find Out About You Online

People Search Engines: They Know Your Dark Secrets … and Tell Anyone
By JR Raphael, PC World
Privacy Pictures, Images and Photos

Social search engines can turn up your Amazon Wish List, photos of your kids, where your kids go to school, your address, your business, where you went to school, your musical tastes, your medical problems, all about your breakups & divorces, your mental health status and much, much more. What else is out there that you don't want everyone to know, and what can you do to protect yourself?


I know things about my lawyer I absolutely should not know. He's 55 years old, listens to the music of the band Creed, and screams like a little girl when riding roller coasters. He also relaxes with New Age spa treatments and is thinking about getting an electronic nose-hair trimmer. And that's just the start.

Now, let me be clear: I've never spent a single moment outside the office with this guy (and for what it's worth, I'd just as soon not be privy to his personal grooming habits). I learned all of these details by tracking his social footprint across the Web -- and he probably has no idea that he has left such a vivid trail behind.

In our age of social sharing, we expect some of our thoughts to be public. But as we slowly put more and more pieces of ourselves online, specialized search engines are making it easier than ever to pull them together into a highly detailed (and potentially invasive) profile of our virtual lives (read "Online Stalking Made Easy").

I'll let you in on a little secret: The picture isn't always pretty. And even if no rap sheet turns up, do you really want the world to know that you look at bad-breath cures online or post awful "Star Trek" fan fiction?

The depths of the Deep Web
You hear a lot of terms bounced around when you talk about this growing breed of search engines. Some services like to be called "social search" utilities, while others prefer the phrase "people search." Many boast of their ability to delve through the "Deep Web" that even Google doesn't touch.

"Even though most people think the size of the Web is basically the Google crawl index, there's actually a lot of information that Google doesn't crawl," says Harrison Tang, founder and CEO of Spokeo -- which, taking a mash-up approach to its identification, describes itself as a "social people search engine" service.

People search engine Spokeo is upfront about what it thinks it can find on anyone.

Spokeo, like its competitors Pipl and CVGadget, is designed to let you dig up information on friends, foes and anyone in between. Spokeo goes a step further than many of the other services, though, by importing your entire e-mail address book.

Then, for a few bucks a month, it continually monitors your contacts and lets you know whenever anyone has done anything new, anywhere online. (The site's home page promises to help you "uncover personal photos, videos and secrets," including "juicy" and "mouth-watering news about friends and co-workers.")


Each individual bit of information may seem insignificant, but the cumulative effect of seeing it assembled in a neatly packaged portfolio is enough to give almost anyone pause.


"Aggregated identity is actually a new type of identity," Tang says, theorizing about why so many people seem to use the word "spooky" when describing his service. "A lot of people know that they have a public MySpace page, a lot of people know that they have a public Twitter album. But, when combined together, it's not one plus one equals two -- you actually create a new identity."


How Spokeo works
Spokeo's system uses your contacts' e-mail addresses to track their activity on a few dozen services, ranging from basic blogs and social networks to a slew of photo- and video-sharing sites. That means the random photos of your kids you shared on Flickr two years ago (or perhaps those less innocent images from your spring-break trip a decade earlier) will pop up right under your name, seconds after someone searches for you.
Less obvious sources such as Amazon Wish Lists, Pandora playlists and movie rating sites fill in the colorful details that you may not have realized were out there at all -- things like (in my lawyer's case) an affinity for New Age jams and nasal maintenance.

I found Mr. Attorney's age on an old MySpace profile and his roller coaster behavior on a personal YouTube video, but Pandora divulged his cravings for Creed and his suggested usages for the "Spa Radio" station he had created. As for the nose-hair trimmer, he can thank his Amazon Wish List for sending that factoid my way.

For sale: Your information

Rapleaf gathers information from the Deep Web -- often posted by you -- and sells it to marketers.

Other services access the same data and then sell the information under the banner of marketing research. One highly visible example is Rapleaf, a company that describes its services as "data and people lookup." Clients pay thousands of dollars to have detailed social profiles of individuals compiled in their own customer databases. As is the case with the data that Spokeo assembles, the information is all publicly available -- Rapleaf just brings it together. "Things that people have posted are out there for anyone to come and see," says Joel Jewitt, Rapleaf's vice president of business development. "As long as you're not going beyond that, that's within the privacy norms today."

Most of Rapleaf's clients, Jewitt says, are simply trying to understand how to use social media more effectively for marketing. An auto manufacturer, for example, might want to know which car models its customers are checking out and discussing on social Internet services. Armed with the company's list of customer e-mail addresses, Rapleaf would crawl the Web and track down the information, person by person.

"It's pretty standard Web spidering," Jewitt says. "We re-create in an automatic way what someone from the general public would be able to do if they were looking."

Electronic exposure

Whether they target businesses or individuals, the services have one thing in common: Unlike the public-record-driven search tools of the past, the new people-tracking utilities build a highly detailed dossier about you solely from information that you yourself published -- a circumstance that may give you a distinct feeling of discomfort.

"What it does is make the ubiquity of the Internet and the sheer openness of the world tangible," says Internet privacy expert Kevin B. McDonald, executive vice president of Alvaka Networks, a network management firm. "It makes the whole concept of the world sharing of information and the 'no-walls' approach that the Internet was designed for very real to people."

The reality can be chilling if the information is going to certain interested individuals: a curious client, a boss big on background checks or an obsessive ex, say. A recent study reported that half of all British Internet users surveyed admitted to having used the Internet to look up information on a former flame. The ease with which someone can arrange to monitor your every electronic move certainly adds a new dimension to the idea of fixation.

"It is a little 'stalkery,'" says Marc Rotenberg, executive director of the Electronic Privacy Information Center. "If the information is distributed, that's actually a form of privacy. When it's gathered up in one place, it creates some new risks."

Rotenberg is no fan of companies that assemble nuggets of personal but public information to turn a profit. "The fact that someone's made something public doesn't mean that someone else can sell it," he contends. "I would say even with affirmative consent, if there's going to be a market for personal data, the user should get some percentage of whatever value the data has."

Taking control
The thing to remember, of course, is that these services aren't doing anything illegal. The information they gather is information that anyone who knew where to look -- and had the time to do it -- could find. So rather than ignoring the king-size file that may have been collected on you, McDonald suggests, you should try to use it as a tool to understand and control your online identity.

"I've come to the point where rather than be driven by the Internet, I intend to drive it to the degree that I can," he says.

"All you can do is learn to live with it," McDonald says. "That's the confines of the world that we live in."


For suggestions on concrete steps you can take to reduce your online exposure, see
"People Search Engines: Slam the Door on What Info They Can Collect."

ORIGINAL

Popular Posts

Blog Archive