Showing posts with label software. Show all posts
Showing posts with label software. Show all posts

Thursday, June 16, 2011

Latest Creepy Facebook Scheme: Facial Recognition Technology

By Beth Wellington, Comment Is Free
Posted on June 16, 2011
Remember the uproar when Facebook made your list of friends, pages you are a fan of, gender, geographic region and networks publicly available to everyone? Now, the social networking behemoth has silently enabled facial recognition software without your permission under the rather benign tag "Suggest photos of me to friends." Even if you choose to disable the option, Facebook still will have the technical ability to connect your name with your image. 

Mark Zuckerberg might say his company is just evolving on privacy – witness his comments in this video interview that:
"We view it as our role in the system to constantly be innovating and be updating what our system is to reflect what the current social norms are."
Contrast this with his former claims that privacy is "the vector around which Facebook operates".

Imagine if, in the name this vector, his company had labelled the new feature "facial recognition photo tags" and required users to opt in, rather than disable it after the fact. Methinks Zuckerberg would have had fewer takers.

But already, the deck is stacked against privacy. As media activist Cory Doctorow noted in a TED lecture, Facebook employs "very powerful game-like mechanisms to reward to disclosure – it embodies BF's Skinner's famous thought experiment, the notion of the Skinner box … lavish[ing] you with attention from the people that you love … in service to a business model that cashes in the precious material of our social lives." Is this new feature really designed to make the site more useful to users or to boost its commercial value as it nears an initial public stock offering?

As Joan Goodchild, senior editor of CSO (chief security officer) Online, noted to me:
"Many privacy advocates feel Facebook needs to do a better job of educating folks about what the new feature is, what it does, and how to opt in or out. Many also feel a user should always be opted out of new features automatically, and should then have to opt in themselves. But it is often the other way around when Facebook rolls out these features."
My concerns go deeper: once data is available to third parties, however temporarily, the cat is out of the bag and beyond retrieval. And it's not just this constant meddling with our settings that's releasing our information – there are also security holes, not to mention scams and release of our data by third-party apps, which the Wall Street Journal found "were sending Facebook ID numbers to at least 25 advertising and data firms, several of which build profiles of internet users by tracking their online activities". More recently, Facebook was adding apps to our profiles that we hadn't requested and which we were unable to permanently disable.

And these front doors – and also back doors – are available for governments, including our own, which has been surveilling such security "risks" as the Quakers and calling Virginia opponents of mountaintop removal "terrorists" (pdf) (while excluding the Ku Klux Klan).

There are already huge government-controlled facial databases: your photo on your driver's licence, government-issued identity card, travel visa and passport ends up in a government office. If the government wants to see a photo of your face, it often wouldn't need Facebook to get it. But Facebook's facial recognition feature certainly adds data points and a social graph. 

As Bruce Schneier, chief security technology officer of BT wrote me:
"Right now, Facebook has the largest collection of identified photos outside of governments. I don't think we know what the ramifications of that will be."
All this reminds me of Steven Spielberg's Minority Report: the 2002 film, based on a 1958 short story by Philip K Dick, featured law enforcement preventing "precrimes" and corporations bombarding passersby with holographic advertisements which crawled up the sides of walls, addressing them by name.

Goodchild recently listed some of the hidden dangers of Facebook. And this is nothing new. As early as 2005 (the year after Facebook's rollout), MIT students were already detailing (pdf) what they saw as Facebook's threats to privacy:
"Users disclose too much, Facebook does not take adequate steps to protect user privacy, and third parties are actively seeking out end-user information using Facebook."
Facial recognition on Facebook arrived with no notice in the US, unless you kept up with the social network's blog last December. The feature came to general light last week, when Facebook extended the feature to other countries and European regulators started investigating.

"Requiring users to disable this feature after they've already been included by Facebook is no substitute for an opt-in process … If this new feature is as useful as Facebook claims, it should be able to stand on its own, without an automatic sign-up that changes users' privacy settings without their permission."
Marc Rotenberg, executive director of the Electronic Privacy Information Centre (Epic), spearheaded a complaint with the Federal Trade Commission on 10 June that Facebook's deployment of facial recognition software rises to the level of "unfair and deceptive trade practices". Joining Epic were the Centre for Digital Democracy, Consumer Watchdog and the Privacy Rights Clearinghouse, all of which asked (pdf) "the commission to investigate Facebook, determine the extent of the harm to consumer privacy and safety, require Facebook to cease collection and use of users' biometric data without their affirmative opt-in consent, require Facebook to give users meaningful control over their personal information, establish appropriate security safeguards, limit the disclosure of user information to third parties, and seek appropriate injunctive and compensatory relief."
 
Facebook has responded to the FTC complaint, with the statement:
"We have heard the comments from some regulators about this product feature and we are providing them with additional information which we are confident will satisfy any concerns they will have."
Facebook provides valuable ways to stay in touch with our friends and families, to network with our colleagues and customers and to coordinate activism. But is hypervisibility really in our best interest, and shouldn't we be the ones making the decisions about what to disclose? Markey submitted legislation in May outlawing the tracking of children online. He might need to add something for adults.

Wheels of Steel (App)

Monday, February 21, 2011

US Gov. Software Creates 'Fake People' on Social Networks to Promote Propoganda

Sean Kerrigan * Social Media Examiner * February 18th, 2011

The US government is offering private intelligence companies contracts to create software to manage "fake people" on social media sites and create the illusion of consensus on controversial issues.
 
The contract calls for the development of "Persona Management Software" which would help the user create and manage a variety of distinct fake profiles online. The job listing was discussed in recently leaked emails from the private security firm HBGary after an attack by internet activist last week.



According to the contract, the software would "protect the identity of government agencies" by employing a number of false signals to convince users that the poster is in fact a real person. A single user could manage unique background information and status updates for up to 10 fake people from a single computer.

The software enables the government to shield its identity through a number of different methods including the ability to assign unique IP addresses to each persona and the ability to make it appear as though the user is posting from other locations around the world.

Included in HBGary's leaked emails was a government proposal for the government contract. The document describes how they would 'friend' real people on Facebook as a way to convey government messages. The document reads:
  • "Those names can be cross-referenced across Facebook, twitter, MySpace, and other social media services to collect information on each individual. Once enough information is collected this information can be used to gain access to these individuals social circles.
  • Even the most restrictive and security conscious of persons can be exploited. Through the targeting and information reconnaissance phase, a person’s hometown and high school will be revealed. An adversary can create a classmates.com account at the same high school and year and find out people you went to high school with that do not have Facebook accounts, then create the account and send a friend request. Under the mutual friend decision, which is where most people can be exploited, an adversary can look at a targets friend list if it is exposed and find a targets most socially promiscuous friends, the ones that have over 300-500 friends, friend them to develop mutual friends before sending a friend request to the target. To that end friend’s accounts can be compromised and used to post malicious material to a targets wall. When choosing to participate in social media an individual is only as protected as his/her weakest friend."
Other documents in the leaked emails include quotes from HBGary CEO Aaron Barr saying, "There are a variety of social media tricks we can use to add a level of realness to all fictitious personas... Using hashtags and gaming some location based check-in services we can make it appear as if a persona was actually at a conference and introduce himself/herself to key individuals as part of the exercise, as one example."

Additional emails between HBGary employees, usually originating from Barr, discuss the vulnerability social networking causes.

One employee wrote, "and now social networks are closing the gap between attacker and victim, to the point I just found (via linked-in) 112 females, wives of service men, all stationed at Hurlbert Field FL - in case you don't know this is where the CIA flies all their "private" airlines out of. What a damn joke - the U.S. is no longer the super power in cyber, and probably won't be in other areas soon."

Barr also predicted a steady rise in clandestine or secret government operations to stem the flow of sensitive information. "I would say there is going to be a resurgence of black ops in the coming year as decision makers settle with our inadequacies... Critical infrastructure, finance, defense industrial base, and government have rivers of unauthorized communications flowing from them and there are no real efforts to stop it."

The creation of internet propoganda software is only one of HBGary's controversial activities. According to Wikileaks competitor and occasional collaborator Cryptome.org, several other progressive organizations were intended to be targeted including anti-war activist, anti-torture organizations and groups opposed to the US Chamber of Commerce.

The emails also include a number of other embarrasing entries including the purchase of the book "The Multi-Orgasmic Man: Sexual Secrets Every Man Should Know" from Amazon for $6.76.