Saturday, July 31, 2010

Context Deficit Disorder


Worried that there might be too much information about you online? Microsoft researcher and social media expert danah boyd says it's better to worry that there may not be enough. "The material that is being put up online is searchable by anyone, and it is being constantly accessed -- out of context and without any level of nuance," boyd told attendees of the Supernova conference in Philadelphia on Friday. "That kind of spotlight on people can be deeply devastating, and a type of exposure that may not be beneficial to society."

Put simply, boyd said, "we can't divorce information from interpretation ... or we risk grave inaccuracy." Example: the online record of a woman that lists her arrest on charges of sodomy against a minor. "I think everybody would think, just by seeing this bit of information, that this person is not somebody we would want anywhere near us," boyd said. "But when I tell the story about a 17-year-old in Georgia who was arrested because she was forced into having sex with a 15-year-old classmate in the school and now has a permanent record of sodomy against a minor, we then have a very different image of what's going on."

Okay, so who gets to decide whether the information we see about ourselves and others online is (or isn't) complete? That's where it gets really uncomfortable, boyd says. We don't have complete control. [According to algorithmic data, boyd said, some data profiles of her list her as a truck driver, presumably "because of all the Motel 8s I stay at" as she travels across country doing field research, she says.] "(Anyone) can put together massive amounts of dossiers on people, but where are the ethics and responsibilities around doing this? Journalists have had an interesting and long-standing discussion about ethics and privacy but that same concern doesn't necessary pervade the blogging culture. People who don't see themselves as journalists now have the same rights and the technology to speak really loudly."

A big part of the problem, boyd says, is that people can't agree on a definition of privacy. [Author Jeff Jarvis (What Would Google Do?), who joined boyd on stage to talk about privacy, agreed.] "We don't know what we're talking about (when we use the term privacy)," boyd said. "Companies don't know and the media don't know." But boyd took a stab at it:

"What I have found from talking to a lot of people is that privacy is about understanding a social situation and how information will flow -- and then making decisions that will recognize this. ... People scream 'privacy fail' when they feel they've lost control of the context of what is being said; when they feel as though the system has told them the information will flow one way but then they find out it will flow differently ... and it's also important to realize that people see privacy as something related to the different actors they care about -- or don't (such as parents or other local authority figures like teachers, college admissions officers, employers and social influencers.) I promise you that come fall, we will be debating what notions of privacy we care about as we think about regulation."

Jarvis agreed. "What forces our fears about privacy are very important to deal with," he said. "...but the social Web is (triggering) Gutenberg-like changes here, so we don't know where this is all headed."

For more on the evolving privacy debate, see Radical Shock on this blog, along with Machine Rule and Google Oogled.


-- Marcia Stepanek

(Illustration by Joaquin Croxatto for istock.com)

Labels: , , , , ,

Wednesday, June 16, 2010

Bill of Rights for Social Networks?


Reacting to the Facebook privacy uproar and Google Buzz's recent release of users' top email contacts, an influential group of social media activists is meeting this week in Silicon Valley to hammer out a Web-wide Bill of Rights for social network users.

The goal: to catalyze a user movement that will compel social network owners and operators to give users more say over their personal information -- including a right that lets users quit a site (leave it) and take every trace of their data with them.

The group, meeting through Friday at the 2010 Computers, Freedom & Privacy conference in San Jose, is livestreaming and posting its deliberations, as well as conducting some of its conversations on Facebook and Twitter so as to involve as many interested users and viewpoints as possible. (Those interested may follow the deliberations at #BillofRights and #cfpconf.)

"We're not the first people to have the idea of a social network users' bill of rights," said conference chair Jon Pincus. "In fact, we decided to make the creation of a user Bill of Rights a main focus of our gathering because people all across the country are starting to push for a set of principles to define best practices for social networks. We thought it was time to combine inputs and produce one such document that embodied the sentiments of as many social network users as possible."

Being used as a basis for the discussion is the Electronic Frontier Foundation's recent framework, which proposes that any rights manifesto should contain three broad categories of rights: the right to informed decision-making (compel social network owners to tell users what they are doing with user data); the right to control (giving users ownership of their information and control over who can view that information), and the right to leave (letting people quit Facebook or any other social networking service with the ability to take their personal information with them.)

"A networking Bill of Rights is a tool that users can use for education and empowerment," Jack Lerner, director of the USC Intellectual Property and Technology Law Clinic, told conferees yesterday. Lerner added:

"Facebook is the 800-pound gorilla right now but that won't necessarily be the case forever. Our purpose this week is to galvanize users of all social networking sites and educate them, not just on what they ought to be looking for in a social network but about how some of their rights are being subverted. Some networking companies have been reckless and irresponsible and not a lot of people yet realize what all is at stake here. There are complaints now from people who say their Facebook pages are disappearing if they're critical of the company. I think it's time for clear guidelines about what is acceptable company behavior and what is not. This is not just about privacy and social media but whether users are being treated fairly by the companies that depend on their information."

What do you think? What rights should users of social networks have? Are user rights a value that social media entrepreneurs can build new businesses around?

-- Marcia Stepanek

(Illustration: istock.com)

Labels: , , , , , ,

Saturday, February 6, 2010

Radical Shock

Make no mistake: the privacy debate is hotter than ever. The recent uproar over Facebook’s new Terms of Service – and then, even more recently, Twitter’s new service terms – is all about privacy, says privacy scholar Helen Nissenbaum. The Internet, she says, has introduced a "radical shock" to our notions of privacy in society, disrupting our long-held distinctions between what is private and what is not.

But what do people mean in today's world of YouTube and Facebook and email when they say their privacy has been violated? They don't care so much that their personal information has been shared, Nissenbaum says—but whether it's been shared appropriately. That's why personal information, she says, ought to be distributed and protected according to social context—what’s appropriate, say, in the workplace, or a medical clinic, or a social network, or a school, or among family and friends.

Today’s privacy policies and rules are not nuanced enough, Nissenbaum says. We've got “one size fits all” protections that either go too far by ignoring these distinctions or fail to go far enough.

“The rapid adoption and infiltration of digital information technologies into virtually all aspects of life, to my mind, have resulted in a schism — many schisms — between our experience of and expectations for privacy today,” says Nissenbaum, the author of the just-published Privacy in Context: Technology, Policy, and the Integrity of Social Life. These gaps, she says, are producing in society “a kind of radical shock, and we need some new ways to talk about privacy.”

I caught up with Nissenbaum earlier this week at her NYU office just off Manhattan’s Washington Square. She is an associate professor in NYU’s Department of Culture and Communication and a Senior Fellow of the NYU Information Law Institute. What follows is an edited transcript of our conversation:

Last week in Davos, social media company CEOs met at the World Economic Forum to talk about the impact of social networks like Facebook and MySpace on society. Reid Hoffman, the LinkedIn CEO, told the group that “all these concerns about privacy tend to be old people’s issues.” He said the value of being connected and transparent is so great, that privacy is not so much a concern any more. What do you think? Is it an “old people’s issue?”

Nissenbaum: [Laughs.] Reid, actually, was one of my students at Stanford, years ago. But no, I totally disagree with those kinds of critiques that say young people don’t care about privacy. Some people say privacy involves withholding information or is the right to control information. But when I see people getting into a flap over privacy, I don’t think that’s what they’re really after. People want to share information; what they care about is the appropriate flow of information. They want the right information to go to the right people and under the right circumstances. They want this “contextual integrity” for the information going around about them. Everybody is interested in privacy under that definition.

Teenagers yell if their parents read their diaries; I have 18- and 20-year-olds in college coming to me all the time, saying, “Oh my god, my 12-year-old sister wants to friend me on Facebook! That’s awful.” I think these are all expressions of a desire for privacy. A number of years ago, at Princeton, where I used to work, I had an alumni event, with an audience of all different ages. I asked those assembled, “How would you feel if you were in a job interview and as a condition of that, you had to yield your medical records?” There was a huge difference in the responses. Older people were much more indignant about that request but many of the younger people said they wouldn’t mind. Does that mean they don’t care about privacy?

You say that individuals shouldn’t be able to control the flow of information.

That’s right. The nuts-and-bolts of my theory says that privacy depends on the social context of information being shared and what’s appropriate for those contexts. Right now, we take information and divvy it up into public information and private information, sensitive or non-sensitive – and then have two different ways of dealing with it. I think that’s problematic. People then get all wrapped up in knots trying to figure out if their IP address is personal or not. I know the EU is struggling with questions like these right now, and it’s a non-starter. Privacy isn’t ‘one-size-fits-all.’

We really need to be much more nuanced and descriptive, and to open ourselves up to the diversity of categories of all types of information and the range of social contexts for that information – and then act appropriately in each situation.

You and I are in structured situation at the moment. I know, more or less, what you expect of me in this interview and you know what I expect of you. These things are governed by social norms. So much of what privacy is depends on the nature of the information at issue and what our roles are as individuals within a certain social context. And then there’s something called the constraints on the flow of information. You could check out my Web site, for example. And then you could ask a whole lot of people to give you some information about me. And then you could go to ChoicePoint and pay them to write up a whole long report on me. In each of these cases, the way you’re getting information about me is governed by certain information flows and different constraints on the flow of that information. You could ask me some questions directly about myself, and I could choose not to answer some of those questions.

So there are circumstances in which people should control the information about them. But in other instances, this may not be appropriate. Let’s say you’re under investigation for having committed a murder and the police are investigating you, and they want to find out where you were on Friday night at 8 p.m. They may ask you, but ultimately, they must — behind your back — verify where you were at that time. And in this society, we’re not going to allow you to control that piece of information. We want the police to actually ferret out that information by any means. Nobody would say the police violated your privacy in this case, because we understand their need to get it independently of you. I think it’s intuitive.

Why did you write this book?

Too much time has been wasted deciding whether this or that piece of information – or this or that place – is private or public. What people really care about is whether information is shared appropriately, within the social context of any given situation.

You say some of this is intuitive. But do we need a set of rules that would lead to public policies that could more intelligently codify these distinctions – to honor what you call this “contextual integrity” of information?

Yes and no. We depend on entrenched social norms for guidance, so there are a lot of people who know already what should be public and private, particularly in the realms of the family. In the workplace, on the other hand, we need to be told what the rules are, and this is where information technology has been a radical shock. There, it’s not good enough just to have implicit behavioral norms, like those which tell you how you should behave at a cocktail party. If you screw up there, it’s not so terrible. But if you’re a doctor, it’s probably a good idea to be required to write down what your responsibilities are when it comes to somebody else’s information.

What is contextual integrity – the theory you put forward in this book?

There are two parts to it. The first asks us to identify the places where people are getting freaked out about information flow and privacy issues and recognize the kinds of challenges that we’re confronting with technology. And then, the second part, is the moral part of the theory that says that not all change is bad. The first part says here’s how we recognize the nature of the change on our expectations about the flow of information. The second part says look, we have much better medical monitoring devices and using them, we can now save lives, so that’s fabulous.

There are a lot of ways that we’re being monitored that are good and all to our benefit, and there are other ways that aren’t so great. Information that previously was available to your doctor is now being made available to entire consortiums of research institutions and insurance companies and so forth. We need to map these flows and how they’re changing. We need a way of looking at what types of information flows are appropriate so that we can start talking as a society about what works and what doesn’t – or what should. We need to be talking about all of this more intelligently.

Why now?

There are now things we can do with technology that we couldn’t do before – but that we, as a society, never really stopped to think about whether we should.

When suddenly we become confronted with something like Google Street View, we now have the possibility of surveillance cameras, if you will. Back in the day, it was considered okay if I saw you, so long as you could see me. But now, with Street View, we now have a surveillance image that gets posted on the Web and suddenly, this completely challenges our expectations of how some information flows, and is supposed to flow. Suddenly, there are people who can view you and you have no clue.

So my theory of contextual integrity really pushes for society to map out these technology changes, these points of radical shock where suddenly, information flows in highly unexpected ways and it challenges us. We freak out because it’s so unexpected. And no matter what you say about being in a public place so you should have no expectations, the truth is that you do have expectations – because that’s how life and (information) flow were governed for years and years. My book seeks to acknowledge the changes that information technology brings to our expectations, characterize the changes, and then advocate for us all to get on to discussing whether these changes are good or bad. Who are the winners and losers? Can we regulate the flow of information, or should we?

I mean, first you recognize the changes – such as the massive databases that can be aggregated from distinct sources, and then be used to mine different kinds of information and create profiles that can be used to make decisions about an individual. These are the types of radical, unexpected shifts in the flow of information that my theory seeks to address.

Hasn’t the legal environment been able to help add clarity to some of this already?

U.S. law has been heavily critiqued because it’s sectoral; it’s based on different sectors. You have, for example, financial privacy and communications privacy and video privacy, and so forth. People have said this is problematic, but I think the U.S. approach has merit because it has in mind particular contexts in which the information flow is occurring. I’m not saying that U.S. law is perfect: Choicepoint and Lexis-Nexis, for example, are out of control and highly problematic because they bring information from all different kinds of places, take it out of context and fail to respect the norms out of which it was shared with other actors – and then make that information available in contexts and under constraints that are inappropriate. This is an area in which the law, hopefully, will catch up. But I think we can do better.

It’s not hopeless. When the FTC, for example, was asked to create privacy rules for the financial industry, I think they did a pretty good job because they were able to focus on very specific types of information relevant to different contexts. For instance, there was an argument about whether your name and address, shown above the line in a credit report, should be public. Credit companies argued that it should be because it’s not financial information. But the FTC said it should be private, because it appears in the context of a financial action. The FTC went to court over it and won, and I thought that was fabulous. When laws are made correctly – with information flows and social contexts in mind – I think it could serve us all well.

Wouldn’t this all be easier if we simply put limits on what data could be archived, an approach raised by Viktor Mayer-Schonberger in his recent book, Delete? Should all the information about us be allowed to exist in digital perpetuity?

I do think information should be deleted, but again, to argue for deletion, you could say even that is a sort of arbitrary move. To restrict access to information may, in some cases, require deletion but the word that a lot of legal scholars use is that we’d want to tailor that deletion appropriately. There may be some instances where we decide there’s a whole lot of information being kept somewhere that should just be wiped out. But we want those constraints to be subject to the specific individuals and the context of given situations.

Some of the new mobile devices – from PDAs to the new iPad — are creating completely new contexts for the flow of personal information. Does the mapping of real-time, geographically-specific behaviors demand a new definition of privacy?

There’s an interesting re-configuration going on about what we think of as social space. People see their social space differently as a result of social networks and location-aware devices. I think we’re just now being forced to confront the question of geo-location. It’s now becoming a new aspect of information available about people that’s going to force us to start asking these same sets of questions around.

On Foursquare, for example, some people feel that by playing, they’ve already given their implicit permission to give up their personal information.

Nonsense. I think that before we start going around saying that anything is implicit in this way, we ought to explore whether it should be. What should the rules be? If you had to sit down and read every privacy policy on the Web or for every device that you bought, it would take you – and I’m making this up – two and half years, right? [Laughter] Ultimately, a lot of great work in privacy has been written about constraining the flow of information one way or another. But what I want to add to the mix of our discussion about privacy in society is the notion that we have to look at the contexts, themselves, to determine what’s appropriate, and under which circumstances. Thinking about privacy in this way leads us to ask much bigger questions.

I like working with computer scientists. Together with them, I’ve created a bit of subversive software, such as TrackMeNot, which is committed to privacy in Web search terms.

We’ve also created something called Adnostic, which is supposed to help against online behavioral targeting. And there’s another project we’re working on about court records and placing them online in certain circumstances.

So many of our questions about privacy and what’s appropriate when we’re creating this software takes us back and forces us to ask what are the functions of our institutions in society. Because of technology’s challenge to previous flows of personal information, we find ourselves almost having to go back to these first principles, even saying, what are the purposes of the court? What are records? That sort of thing.

For example, with the courts, if you don’t take care and dump everything onto the Web, including the names and addresses of jurors, for example, maybe the next time you get asked to serve on a jury, you will struggle hard to avoid it, and that won’t promote the values of the court. It will make the courts function worse, forcing us to reach back all the way to consider the roles of the institutions, themselves.

Very delicate considerations need to be embedded in these technologies.

Where has technology changed the traditional flow of information most radically, to what you refer to as “shock status?”

One is in monitoring and tracking. This isn’t visual anymore. It’s online and it can happen when you’re interacting with your supermarket. Second is this arena of aggregating information and analyzing it. It’s all behind-the-scenes and it’s driving a lot of the monitoring, so people are not so obviously aware of it. Sometimes, some little surprising thing happens and you think, hmmmm, I wonder how they knew that? And then, if you’re thoughtful, you realize that somebody has a database somewhere. But it’s not in your face.

Third, there’s the worry about communications and media because this is not just about information that sits in a database somewhere. It’s about distribution. This is Twitter and Facebook and blogs and email. In information science, this whole notion of aggregating information from different sources and then using it to profile people – to see if they’re terrorists or good mortgage prospects – it’s very cutting-edge stuff, involving statistical techniques and operations research. But here’s the problem. It’s not directly experienced except in the ways your bank will reply to you.

Are you hopeful about the future of privacy?

My hope level is in constant flux. When I think of the vast back end of information aggregators interacting directly and indirectly with personal information, such as Google, Choicepoint, ISPs, government agencies, and financial conglomerates, I fear the worst. I worry that the landscape of incentives will swamp just about any moral consideration we might bring to bear. At the same time, I’m buoyed by the growth in size and quality of privacy scholarship and practice, the guile, brilliance, and insubordination of computer hackers and NGO players. And sometimes, watershed events can be enormously important; grim as it is, the Google/China debacle may turn a few heads.


-- Marcia Stepanek

[Editor's Note: This interview was originally published on PopTech.com and is being reposted here with permission]

Labels: , , , , , , , , ,

Thursday, January 28, 2010

Privacy, Revisited


Today is Data Privacy Day; Congress voted quietly last year to have the United States join Europe in designating January 28 as an annual, international holiday to raise awareness about the importance of data privacy protection.

Make no mistake: the privacy debate is hotter (and louder) than ever. The recent uproar over Facebook's new Terms of Service—and then, even more recently, Twitter's new service terms—"is all about privacy," says Georgetown University law professor Marc Rotenberg. "It's not the old-fashioned parchment scroll, carried by courier on horseback from the castle to the king's army notion of privacy," says Rotenberg, the director of the Electronic Privacy Information Center, a nonprofit he founded in 1994 to address the Internet's impact on society's traditional notions of privacy. "This is "modern-day privacy, about digital identity, the control of personal information, and the brewing battle between what we post and its commercial value." [For more on Rotenberg's views, see his essay that ran recently in The Huffington Post, suggesting that "we give up personal information all the time but that doesn't (nor should) end the discussion over privacy." That, says Rotenberg, is where the discussion begins.]

Just don't tell the social media executives meeting in Davos this week. There, halfway 'round the world from Rotenberg's Washington, D.C., office—and while Rotenberg was commemorating Data Privacy Day in press briefings and other talks elsewhere—the chiefs of Twitter, Facebook, MySpace, Ning and LinkedIn squeezed into a small, packed anteroom at the World Economic Forum to share their predictions for social networks, discuss their impact on society (for better or worse) and ponder why their companies hadn't yet figured out a way to make big money off their subscriber's digital social connections.

Tim Berners-Lee, the British physicist who invented the World Wide Web, told the Davos gathering that "little changes in how your treat privacy can dramatically affect the way a social network works." He said that in eBay's case, for example, the site has increased privacy in some areas as the online auction site has matured. The site now hides the identity of people bidding against each other. Younger users, though, seem far more open to revealing personal details about themselves.

Then it was Reid Hoffman's turn. The executive chairman and founder of LinkedIn told the group: "All these concerns about privacy tend to be old people's issues." Transparency and accessibility are two reasons, he said, that so many younger users—teenagers and young adults—put their mobile phones on Facebook or MySpace. "The value of being connected and transparent is so great," Hoffman said, that privacy is not a concern but a hindrance.

Rotenberg wasn't present. But Don Tapscott, author of books on the so-called Net Generation and the need for corporate transparency in the Digital Age, took Hoffman on. Social networking, Tapscott said, would become what "we want it to be" over time, meaning that if we wish to build civic values into social network sites, we will—and should. "[The Internet] has an awesome neutrality and we need to build into it basic human values," Tapscott said. "...And one of those values is the right to informational privacy and the right to be left alone. I completely reject this view that privacy is dead. It's in deep trouble, it needs to be saved and everyone needs to get involved to protect their own information."

Indeed. [Says Rotenberg: "I smile every time someone says privacy is dead or the Facebook generation doesn't care about privacy. If there is one issue that people feel passioantely about today, that literally unites everyone who goes on line, it is the interest in privacy. And the battle is just beginning."]

What do you think? Is privacy an "old people's issue" or more about civil liberties in the 21st century? Let us hear from you.

—Marcia Stepanek

(Illustration: istock.com)

Labels: , , , , , , , , , , ,