Showing posts with label Privacy and Security. Show all posts
Showing posts with label Privacy and Security. Show all posts

Wednesday, July 6, 2011

The Google+ (Social Network) Project

In the age of social networking where Facebook and Twitter rule network relationships, multi-billion dollar conglomerate Google refuses to sit this one out.

Just last week I received an invite for Google+ project. My initial thought was, "It's like Facebook, only Google-fied!"

Photo from plus.google.com
While quite late it at, Google launched on June 28, the Google+ project --a social networking service aimed at "sharing the right stuff, with the right people" while integrating the wide range of Google products and services, such as GoogleBuzz (microblogging), Youtube (video hosting) and Picasa (photo sharing), just to name a few. Currently, the service is still in it's invite-only testing phase. It boasts of five features, generating mixed reactions from netizens all over:
  • Circles -a place where you can sort out their contacts into respective groups via drag and drop method 
  • Hangouts - a platform for Video Chats 
  • Huddle - a communication tool for your circles (contacts); works like BBM groups or group IM chats 
  • Instant Upload - for sharing pictures and videos directly from your mobile phone (Android only) 
  • Sparks - a recommendation interface based on ones listed interests
It appears that this is just the beginning of grand plan to take over the social network business. It is reported that in the next six weeks, Google plans to rebrand Picasa and Blogger as "Google Photos" and "Google Blogs" respectively in order to tie it up with the major roll out of Google+.

Google+ indeed looks promising. However, it is highly unlikely that it would surpass Facebook's 11-year lead in the social networking game anytime soon. In terms of users and site use, Golden Sachs estimated that as of January 2011, Facebook has 600 million users. Furthermore, the features offered by Google+ is not new. In fact most of them are already contained in Facebook as well as other services albeit in a different setting.

Just looking at the odds, Google has a lot of convincing to do in order to lure users to switch sides. As Business Insider's Steve Kovach puts it, "A social network is no good unless your friends are on it too."

But then again, it's still early in the game. A lot of developments (and surprises!) can still take place considering that the site is still on beta testing and Facebook just might fight back. Let's just wait and see what happens when it finally gets mass released in the market.

For more information regarding the service, please visit the Google+ Homepage or watch the video below.



Sorry but I don't have invites. :)
3rd Entry
Soleil Flores

Wednesday, June 22, 2011

Collateral Damage

For the past two months, it seems a new major website or web service has gotten hacked on a weekly basis. May saw the PlayStation Network fall prey to a hacker attack that compromised the credit card information, email addresses and passwords of a sizable portion of its customers. What followed was a storm of hacker attacks, which included targets such as the CIA, the US Senate, Bethesda Softworks, Nintendo, Sega, and PBS, among others.

What interests this blogger is not the hacking itself, but the recent news that the accounts of XBOX Live members have also apparently been compromised, notwithstanding the fact that Microsoft claims it was never hacked. Apparently, some of the email and password combinations compromised in the earlier attacks on Sony’s PSN, Sega, et al, also worked on XBOX Live accounts. Reports have also surfaced of similar incidents happening with Facebook accounts.

It’s pretty amazing how much collateral damage a single hacking incident could have. A perfectly secure web service can find its customers inconvenienced by the delinquency of a completely unrelated web service that happens to have the same customers, using the same passwords and email addresses. It’s easy to pin the blame on the end user for being sloppy in reusing the same email and password combinations. But in actual practice, human memory is fickle and can barely remember a single password. Let’s face it, multiple passwords by end users will be the exception, not the rule, for the foreseeable future.

This all serves to dampen the spirits of those who push for greater integration of web services. It’s bad enough that two totally rival services with absolutely no hope of integration (PSN and XBOX Live) have ably demonstrated that a security breach on one service can have dire consequences on the customers of the other. What more for services that go out of their way to integrate, like Google, Youtube, and Blogger? What of Facebook and Digg, which have been integrated into practically every website?

Perhaps it’s time to propose legislation that would mandate the major web services and websites provide adequate security measures against hacking, not just for their own benefit but for the whole internet in general. Hacking isn’t going away any time soon, and as this debacle shows, a single hack is a stone thrown into a calm, serene pond—it ripples, and shatters the serenity for all.

Monday, February 14, 2011

Password Puzzles

Are you the type of person who uses the same 5 letter password for all your accounts? Or the type to just use the first 6 letters of the alphabet, or even your keyboard? Or perhaps your name plus birth year? Or perhaps something with sentimental value, like maybe your pet's name (e.g. Blackie, Doggy, Mingming etc.)? Bloomberg Businessweek recently came up with password problem statistics that will alarm even the most apathetic among us:

Most-used passwords: 123456, password, 12345678, qwerty, abc123

Time it takes a hacker's computer to randomly guess your password:

image from bookofjoe

See the table above and check if your password is susceptible to brute force attacks. Not sure what this is exactly? Wikipedia provides a great definition:

In cryptography, a brute force attack or exhaustive key search is a strategy that can in theory be used against any encrypted data by an attacker who is unable to take advantage of any weakness in an encryption system that would otherwise make his task easier. It involves systematically checking all possible keys until the correct key is found. In the worst case, this would involve traversing the entire search space.
Of course, there are countermeasures. As the old adage goes: "an ounce of prevention is worth a pound of cure." So here are some tips to prevent being being victimized by hackers:

1. 9-digit passwords or higher are harder to crack. The resources required for a brute force attack scale exponentially with increasing key size. Unless, of course, you decide on 123456789.

2. Keep your email password safe and secure. Most sites send passwords back to your email, so once this is breached, consider nothing safe. NOTHING!

3. Use KeePass Password Safe. It's a free, open source, light-weight and easy-to-use password manager that is generally resistant to password-cracking utilities.


Wednesday, December 8, 2010

I do mind being mined, Facebook.


The rule on information about me is based on the "Rigalian Doctrine." Under this principle, the rule provides:

"All data about me in the public domain, records, documents, papers, and other posted and tagged photos, birthday information, contact information, relationships, education and work, philosophy, interests, activities, and other data are owned by me." It follows that the exploration, development and utilization of all data concerning me fall under my supervision and control. I have the option to directly undertake data mining activities or to enter into the different modes of data mining agreements with any friends and relatives. Preference is given to friends of the 1st degree in respect of rights and privileges to access, explore and develop various inferences concerning the data about me. For large-scale data mining, I have the option to enter into an agreement for financial compensation from other online entities."


I wish it's as simple as that.

I hate the idea that I'm a marketing target and Facebook is off to earn cash from my personal information. Especially with the new profile they've just introduced. I just posted now "I don't like the new profile!!!!!! I wanna go back! no no no no!" My reason? "It looks weird if you don't put all the info they're asking, yet I don't wanna give out the info! hrmpf!"

I dunno. I get the idea that they designed the "new profile" in a way that forces a user to put in all the information they're asking. I know they're mining the data about users. I do notice that most ads seem to match my recent searches, my interests, my course, blah blah blah. Right after I gave birth there are all these baby ads. There shouldn't be anything wrong about relevant ads, right? They're certainly better than porn or smiley pop-up ads.

I simply don't like the idea of being mined. I don't like being a statistic. Maybe I'm greedy. Maybe I want a fair share of the deal. Or maybe I just want my privacy. Please don't ask me why I'm in Facebook in the first place, and why I post those photos, and interests, etc.

Data mining is not always "wrong" or illegal. Generally, it's legal, but there's this really thin line between being a marketing target and then being a suspected terrorist. Do you know that the U.S. uses data mining to do just that? And you do know how the Philippines has its own share of terrorists, and its "shared" military ops with the U.S. Well, I'm a Muslim, and I just can't go on posting about ... well you get the idea. I'm not about to let myself get mined now for this post.

That's the worst downside I guess. Between the "proper" and the "heinous" data mining continuum, there's this gray, fuzzy area concerning privacy and data protection. And businesses don't always realize they're crossing the line. Take for instance the recent lawsuit featured in a blog, entitled Hamburg DPA Files Bank €200,000 For Accessing Customer Data and Customer Profiling.

Anyway, the Supreme Court, under the stewardship of former Justice Puno, promulgated the rule on the writ of habeas data which is supposedly a remedy for every Filipino, whose right to privacy in life, liberty and security is compromised by data gathered by individuals, public and/or private. Very promising, but I don't see it being used to actually prevent data mining by Facebook. Very unlikely, considering the user agreement, blah blah blah. Besides, it's almost flimsy to sue facebook for it. Or is it? There are lot of Facebook paranoia articles out there, and here are few of them:

1 ) Facebook Data Mining: Truth in Association?
2) Facebook's plans to sell user data
3) Facebook Conspiracy: Data Mining for the CIA
4) Facebook Data Reveals Secrets of American Culture
5) Facebook mining your Wall posts for more marketing data

And there's also a video (if you like listening to audio-codals, you'll love this video. the voice is very uhmmm soothing(?) hahahaha!):





Yes, I know I clicked "yes" a few years ago. But if I knew Facebook would be like this ... If I had imagined the net would be like this today ... Well if I did, I'd be the billionaire, not them. So gimme a break and let me give my own stipulations to a new user agreement again. And if I don't agree with their terms, well... I'd still use Facebook.
Salma F. Angkaya
Entry #4

Thursday, September 9, 2010

Pricetag to Information.


How much does information actually cost?

This question can be analyzed from various viewpoints. But I want to focus on those information that are freely given. Those that are personal but can be acquired through underhanded ways.

The other day, I was doing my regular banking transactions when the teller gave me a flyer on their friend-referral-program promo. It required me to give out contact details of THREE persons to entitle me to a 32" LCD TV (first place), Sony Vaio laptop (second place), or a Sony Ericsson phone (third place). They had to be non-clients of the bank who might be interested in opening their own accounts. Incomplete details would invalidate such raffle coupon - so I had to give the email address, mobile number, office number or home number of EACH person.

Ingenious, I thought. The financial institution seeking to expand its reach of collections, would now be able to build on its database "banking" on people's desire to win freebies. And since most people wouldn't think twice about this seemingly "harmless" promotion, they'd gladly give out the information.

We've all heard/witnessed this practice in other companies also. I have nothing against giving out your OWN information since it's yours to give. However, it's completely different if it's the phone number of another. Sometimes we focus on the perks too much, we forget that we're risking our own security, our friends' security or even encroaching upon their privacy. Sometimes, too, there are no obvious perks, but the helpful Filipinos we are, we volunteer the information.

And yes, I stopped myself from giving out details of my friends. Just for TV? No way :D But if it's a car, or an all-expense paid trip somewhere, then I just might consider it.. (To my friends who are reading this: I'm kidding, of course!)


Entry No. 12
Rachelle Mayuga

Thursday, September 2, 2010

Privacy in the Workplace.


The concept of SURVEILLANCE automatically seems to give out the impression that PRIVACY has been violated. There’s someone watching; there’s someone being watched. Many questions and potential issues would then arise out of this situation, i.e. purpose of surveillance, manner by which it was undertaken, scope of surveillance, among others. Wikipedia defines surveillance as the “monitoring of the behaviour of a person or a group of people, often in a surreptitious manner.” In a work setting, employees would almost always be monitored so as to assess their output, productivity and efficiency owing to the fact that having been logged in to work for a certain number of hours, therefore, they are expected to well, work.


I understand the pros and cons of employee surveillance. However, we could also all agree that it should be done within limits. There are essentially two rights involved here: the employee’s right to dignity and privacy and the employer’s proprietary right to monitor his workers. Given the rate at which work surveillance is being used on an international scope, as well as here in the Philippines, it might be proper to take another look at our existing legislation and determine the next steps that would have to be done. At present, we have no definite bill addressing this situation; there also seems to be no widespread clamour for Congress to act.


Entry No. 11

Rachelle Mayuga