Friday, July 30, 2010

Google steps up for Android users

Spencer Ante at the Wall Street Journal tells us that Google has disabled apps caught spying on users by gathering information and sending it as cleartext to a server. According to security researchers there were 80 apps that were gathering user data, but all were from one developer.

Google and Apple both require users be notified before apps collect personal data, but many people don't pay enough attention to what phone apps tell them is being gathered. Do you know what information is being gathered from your phone?

Thursday, July 29, 2010

Court ok's privacy advocate publishing social security numbers on line

At Wired's Threatlevel blog David Kravets reports that BJ Ostergren has won her fight with the Virginia Attorney General, at least for now. Ostergren posted the Social Security numbers of elected officials on her site, The Virginia Watchdog. Ordinarily I would be against publishing privacy information, but there was a purpose - getting officials to begin redacting personal information from public records online. The information she posted was obtained from online public records, no laws were broken obtaining it. Posting it, on the other hand, ran afoul of a Virginia law prohibiting publishing private information.

An appeals court ruled in favor of Ostergren, saying that her first amendment rights and the purpose of her site outweighed the state law:

“We find particularly significant just how Ostergren communicates SSNs. She does not simply list them beside people’s names but rather provides copies of entire documents maintained by government officials,” the court said Monday. “Given her criticism about how public records are managed, (.pdf) we cannot see how drawing attention to the problem by displaying those very documents could be considered unprotected speech.”

Sometimes the subtle approach works, other times a brick to the head is required. Virginia is now in the process of redacting millions of online records.

Wednesday, July 28, 2010

How secure is your wireless network?

Thanks, Kenny for pointing me to WPA Cracker, an online tool that will help you test your wireless network's security/find your lost network password for a marginal fee.The service is operated by Moxie Marlinspike, an independent security researcher and The Institute for Disruptive Studies.

This is an interesting service. They don't seem to care much who they are "helping" - they don't ask for more than an email address, network capture and the ESSID. You have to pay them using an Amazon account - but if you use a pre-loaded "credit card" and a generic email account, you can protect yourself from casual scrutiny.

WPA Cracker will hit a network with either dictionary or brute force attacks. Dictionary attacks are exactly what they sound like. The attacker has a file - the "dictionary" - that contains any words, phrases, leet-speak, etc that might be used as a password. Dictionary attacks can be very successful because many people use the same passwords. Password, for instance, is one of the most common passwords.

But as successful as dictionary attacks can be, they may not get you access to the account you want because the person is a little more aware, or just plain paranoid, and uses a password generator or creates their own random passwords. While dictionaries can be extensive, they can't cover every possible combination of characters, especially if the password is very long (6 or more characters, at least). To cover those types of passwords, WPA Cracker uses brute force attacks. Brute force attacks will try every possible combination of characters for as long or as short a password as you specify. It can start with single characters and work up to as many as needed. Brute force attacks can take a very long time, depending on the length and complexity of the passwords.

It doesn't matter how complex your password is if someone is willing to put unlimited time into brute forcing it, but security is never about making a position impenetrable, it's about making penetration so hard the enemy decides it's not worth the effort required.

When it comes to passwords, which is going to be harder to discover, whether using dictionary or brute force attacks:

password

Dr_Livingston_I_Presume

a3Ket9P3s*!k--i2@1)*k#cs?

Of course, that last is almost impossible to remember, so try to find a happy medium with your passwords. That will make you more secure than 98% of the rest of the world.

Need secure data storage accessible to your Mac's & PC's?

 

I was looking at MacMerc today and saw that 1Password, has integrated with Dropbox to provide secure data synchronization between Macs. 1Password is a password manager and more. To quote Rick at MacMerc:

"As you can see, 1Password is a highly secure database for keeping track of web site logins, but it also handles notes, credit cards, bank accounts, and software registration information."

That's pretty good, but using Dropbox sync data between computers is just cool. Dropbox is a secure online backup solution similar to Carbonite, but free for up to two gigs of data. To make things even better, Dropbox is cross-platform with Windows, Mac, and Linux. And 1Password for Windows is now in public beta. 

1Password is a commercial product that runs you $39.95 (Windows beta is free), but that's a one time cost, and Dropbox is free unless you go over 2 gigs data. So in the sub-2gig zone 1Password + Dropbox does more and is a bargain compared to Carbonite with it's annual fee.


 

Monday, July 26, 2010

Yahoo operates using 'situational rights'

David Kravets of the 'Threat Level' blog at Wired.com reports that Yahoo is "arguing out of both sides of its web portal" in it's response to a suit filed by Chinese dissidents whose information was surrendered to Chinese authorities by Yahoo - resulting in their arrest and torture.

Yahoo is claiming that all it did is follow Chinese law - and that the First Amendment protects its right to deal with the Chinese government. Yahoo further argues that U.S. courts are not the proper place for the case, despite a U.S. statute allowing exactly this type of case. Kravets quotes Yahoo as saying:

"This is a lawsuit by citizens of China imprisoned for using the Internet in China to express political views in violation of China law. It is a political case challenging the laws and actions of the Chinese government," Yahoo told the court. "It has no place in the American courts."

That sounds legitimate, I suppose, from a corporate standpoint. If you ignore the fact that they would not have been imprisoned, or at least not as soon, if Yahoo hadn't ratted, er, provided the Chinese government with the information needed to locate them. It looks worse when Kravets provides a little background info on Yahoo's fress speech claims:

Yet two years ago, while citing the First Amendment, Yahoo went to the U.S. courts in a bid to prevent it from having to pay millions in fines levied by a French court for allowing French citizens to barter Nazi paraphernalia on its auction site _ a practice against French law.

That sounds like Yahoo wants to argue that free speech should be protected if you're selling stuff on their site, but not if you're complaining against your repressive government. Ignoring problems I have with the idea that selling = free speech, it sounds to me like Yahoo is having a serious case of corporate double standard. What do you think?


Friday, July 23, 2010

Lying is protected First Amendment speech (don't tell the kids)

In a decision filed on July 16th (pdf - p1, p2 etc refer to the pdf pages) US District Judge Robert E. Blackburn stated:

The matter before me is defendant’s Motion To Dismiss Information [#13] 1 filed December 2, 2009. Having considered the motion and response and their supplements, as well as the arguments and authorities presented by amicus curiae, 2 I find and conclude that the statute under which defendant is charged is unconstitutional as a content-based restriction on First Amendment speech that is not narrowly tailored to serve a compelling government interest. Accordingly, I grant the motion. (p1)

Sounds fair. Let's see just what this protected speech is:

The Amended Information charges defendant with falsely representing himself to have been awarded a Purple Heart on four different occasions in 2006 and 2009, and falsely representing that he had been awarded a Silver Star on one occasion in 2009. By the instant motion, defendant seeks to dismiss these charges, arguing that the Act is facially invalid as a content-based restriction on free speech. (p2)

So the judge is dismissing the charges because the statute the defendant is charged under violates the First Amendment. Without even looking at what the statute says, based on the above paragraph, the judge appears to be saying that lies are protected free speech. What is the statute, and what does it say? It's Section 18 Section 704 of the United States Code. Part 'a' states:

(a) In General.— Whoever knowingly wears, purchases, attempts to purchase, solicits for purchase, mails, ships, imports, exports, produces blank certificates of receipt for, manufactures, sells, attempts to sell, advertises for sale, trades, barters, or exchanges for anything of value any decoration or medal authorized by Congress for the armed forces of the United States, or any of the service medals or badges awarded to the members of such forces, or the ribbon, button, or rosette of any such badge, decoration or medal, or any colorable imitation thereof, except when authorized under regulations made pursuant to law, shall be fined under this title or imprisoned not more than six months, or both. (from US code at Cornell Legal Information Institute)

Sections 'b' and 'c' covers specific fake medals. This law says that it is illegal to pass yourself as a member of the armed services, and to pass yourself off as having earned awards you have not.

What in the world does this case have to do with free speech? It has to do with lying and misrepresenting yourself. According to this decision I can pass myself off as a cop. Or a doctor. Do I even have to worry about committing perjury?

To make matters worse, the judge admits that he can find only one other case that examines the First Amendment implications of this act - and that case upheld it:

The only other court that appears to have addressed the constitutionality of the Stolen Valor Act relied on a similar rationale in rejecting a defendant’s First Amendment challenge to the statute. (See id. App, Exh. A (Order Denying Defendant’s Motion To Dismiss, United States v. Alvarez, CR 07-1035(A)-RGK).)

I am not so sanguine. The government’s argument, which invites it to determine what topics of speech “matter” enough for the citizenry to hear, is troubling...  (p3)

Judge Blackburn goes on to mention a few First Amendment cases that really don't relate. He quotes from Riley v. National Federation of the Blind of North Carolina:

The very purpose of the First Amendment is to foreclose public authority from assuming a guardianship of the public mind through regulating the press, speech, and religion. To this end, the government, even with the purest of motives, may not substitute its judgment as to how best to speak for that of speakers and listeners. (p3-4)

This case is not about guarding the public mind or regulating any aspect of press, speech or religion. It's about people committing fraud, pretending to be decorated service men and women to gain benefits they would not otherwise gain from the people around them.

Well, I'm not going to go through the entire 14 page pdf here. He goes on to quote other cases and talks about what he considers the biggest weakness of the law:

The principal difficulty I perceive in trying to shoehorn the Stolen Valor Act into the First Amendment fraud exception is that the Act, although addressing potentially fraudulent statements, does not further require that anyone have been actually mislead, defrauded, or deceived by such misrepresentations. (p6)

Ok, we're not talking about a guy staging a play. We're talking about Rick Glen Strandlof. According to the Denver Post he is a man used an alias and made false claims about being at the Pentagon on 9/11 and in Iraq. Apparently he never served at all. Somehow, despite the fact that he misled hundreds, if not thousands, of people and solicited money from them under false pretenses - damaging the image of anyone coming after him trying to raise awareness of and/or money for veterans issues - the ACLU and this judge have decided that he harmed no one by falsely claim to be a decorated veteran.

An article in the Huffington Post ends with a wonderful quote from ACLU attorney Christopher P. Beall:

The government position was that any speech that's false is not protected by the First Amendment. That proposition is very dangerous," Beall said.

Ok, I guess I can see why he says that, but it still ranks as one of the most ridiculous on-the-face-of-it quotes I've seen in a while. Especially when used in defense of someone who undertook to commit a long term, detailed and potentially very lucrative fraud.

If you'd like to read the rest of the decision, you can download the pdf here.

Student sued for dissin' company on Facebook

Meaghan M. Norman of WILX News 10, Lansing, MI reports that Justin Kurtz, a 21 year old student is being sued because he put up a Facebook page complaining about the business practices of T&J towing. They allegedly towed his car when it was properly parked, tried to scrape off the parking sticker, and then made him pay for the illegal tow.

Justin created the page because he wondered if anyone else had problems with the towing company. 14,000 fans later T&J towing decided they should do something and sued him for defamation.

Justin isn't cowed, and refuses to take down the page. He believes the suit is an attempt to intimidate him.

I don't know who's going to win, but it's good to see another way Facebook can be used to improve the world (one little step at a time) and to see someone who will stand up for what's right.

Wednesday, July 21, 2010

Security, like all things, best in moderation

The Washington Post is publishing a series on the state of the United States Security Community, and it's pretty interesting. For example:

* Many security and intelligence agencies do the same work, creating redundancy and waste. For example, 51 federal organizations and military commands, operating in 15 U.S. cities, track the flow of money to and from terrorist networks.

* Analysts who make sense of documents and conversations obtained by foreign and domestic spying share their judgment by publishing 50,000 intelligence reports each year - a volume so large that many are routinely ignored.

Wow. 51 agencies tracking money. 50,000 intelligence reports a year. I've been saying for a long time that the biggest problems leading up to 9/11 weren't lack of information, but too much information and too little communication. In the 9 years since then we have only added to the problem.  In describing their data gathering, the Post said;

The Post's online database of government organizations and private companies was built entirely on public records. The investigation focused on top-secret work because the amount classified at the secret level is too large to accurately track.

That's scary. The article quotes several sources who say there is no process in place to keep track of all of the inter-agency information, even for the few people who are in a position to try. What's scarier is that means we can't know if all that manpower, information gathering, and money tracking is doing any good. Add to those the fact that we've had recent near miss terrorist attacks in the U.S. and you realize that there is going to be another successful attack. The only question is, how severe will it be?

I recommend checking the Top Secret America website and reading the entire series as it comes out this week, although I admit it will be a bear. The first installment Monday was 17 screens long.

Wednesday, May 19, 2010

Hacking pacemakers

It was reported by the New York Times in March that a wireless security flaw had been discovered in a defibrilator-pacemaker. The researchers who disovered it used a device in a laboratory, not one implanted in a real person. They were able to deliver potentially fatal shocks and even received patient data from the unit over the wireless transmitter.

There's not really any risk of your pacemaker getting hacked at this point. But it is a growing concern among security experts who try to see where the risk is 2, 5, 10 or more years from now. It's a very low risk concern right now, that could change.

As computers become more intertwined in our day to day lives, even into our bodies in the form of things like pacemakers and insulin pumps, and even prosthetic limbs the possibility of malware being written for them increases. If anyone can find a way to make money doing it.

In April ABCnews.com's Lauren Cox took a deeper look at the possibility of taking over implantable medical devices. She brings up one very interesting point - a point that's also a little frightening:

"What's more, people with ICDs often are public about them. Former Vice President Dick Cheney is one example of a high-profile American with a device."

It's way to early to say there ever will be assassins using implanted devices to kill. But can we afford to wait for it to happen before we take steps to protect against it?

Tuesday, May 18, 2010

Federal high tech security boondoggles

In an article by Ken Dilanian, swamppolitics.com - the Washingtom Bureau of the Chicago Tribune - reports that a number of high tech security programs initiated by the Bush administration have flopped. The biggest reason for the failure? Failure to properly test the technologies before implementation. A weakness shared by the current technical bandaid, full body scanners.

Technology is an important tool in the war against terror. But according to Brian Jenkins of the Rand Corp the Department of Homeland Security is overly reliant on technology. There is no silver bullet, but new technologies are treated as the final solutions to our national security problems.

From the "virtual fence" aka Project 28, on our southern border to the Real ID Act that Homeland Security Secretary Janet Napolitano has called for Congress to repeal, U.S. high tech anti-terrorism initiatives aren't working as advertised.

In fact, recently the majority, if not all, of the terrorist that have been caught before attempting terrorist acts have, to the best of our knowledge, not been caught through new, high tech gadgetry but through old fashioned investigation and surviellance techniques. Techniques that employ technology, but as a tool, rather than as the lynchpin of the procedure. Maybe it's time we started focusing on the things we know work, and take the time to do proper testing of new technologies before entrusting the lives of our citizens and the security of our nation to them.

Monday, May 17, 2010

Google accidentally spys on open WiFi

Ben Rooney of cnnmoney.com reports that the Google has admitted that it's Streetview cars have been collecting data from open WiFi hotspots. Google first admitted to collecting the publicly broadcast information of open hotspots, things like the network names and router numbers, on April 27th. But after being asked for more information, Google says that they discovered more data was being collected - private data in the packets being transmitted across the network. Supposedly the code that gathered data packets was accidentally entered into software used to gather public information on WiFi.

The software changes channels five times a second, so only bits and pieces of data would be gathered. Encrypted data, like the communications between you and your bank account, cannot be read, so it won't have been compromised by Google's illicit scans.

Google is, of course saying that it was an accident. In response they have stopped all scanning of open WiFi by their streetview cars until they can repair and replace the faulty software. They have arranged for a third party to review the software and the data collected from public WiFi networks.

This is a major blunder by Google. Whether it was a case of pushing the envelope to see what the reaction would be or an honest mistake, it's going to hurt Google's reputation. This one I tend to believe was an accident. In many nations it is illegal to tamper with electronic communications. Google may want to gather and use information, but breaking the law to do it isn't good business.

Friday, May 14, 2010

Bye-Bye Farmville, hello, StreetFighter? (plus new security)

Facebook is offering new security features to make it harder for cybercrooks to hijack your account. Registered devices, login notifications and other features make your account more secure. That is a good thing, but until Facebook makes it easier to keep your data private it doesn't mean a whole lot. And I use very strong passwords, so the information that gets shared from my account is a much bigger concern than someone hacking into it.

The Zynga/Facebook marriage may soon be over. Apparently Facebooks new policies may actually be costing Zynga users, and Facebook supposedly tried strongarm tactics to force the Farmville creator to remain exclusive to Facebook in their last negotiations. Instead, there is talk of a Zynga live network - and a complete pullout from Facebook.

In a perhaps related story (or perhaps not) Capcom has announced they are preparing their first Facebook game.



“Gaming on social networks is poised to impact the traditional video game industry and is a presence that cannot be ignored,” Capcom President Haruhiro Tsujimoto said in an interview in Tokyo yesterday. “We have to make our move.”




Facebook as a game platform is growing, with more of the heavy hitters in gaming working Facebook into new releases in one way or another. In addition to Capcom, Electronic Arts and Blizzard have announced upcoming Facebook gaming presence. Facebook is working to become the internet, but they may become the gameworld without even trying.

Thursday, May 13, 2010

Does Arizona have the right idea?

I have to wonder if Arizona’s Jan Brewer doesn’t realize what she’s doing, or if she really believes so strongly in the importance of these racially charged bills that she is willing to sacrifice her political career. Just a few short weeks after passing the controversial immigration law, the Associated Press reports that, “Arizona gov. signs bill targeting ethnic studies". According to the story, “State schools chief Tom Horne, who has pushed the bill for years, said he believes the Tucson school district’s Mexican-American studies program teaches Latino students that they are oppressed by white people.”

Like the immigration bill before it, the purpose of the education bill as described in the story doesn’t seem that objectionable to me. I understand the concerns that the immigration bill could lead to racial profiling. That is a legitimate concern, but doesn’t change the fact that illegal immigrants are here illegally. I'm glad the immigration bill specifically prohibits stopping someone just to ask about their citizenship, but only time will tell if law enforcement abides by that.

I also understand that this education bill could be used as a reason to stop teaching about the contributions minorities have made to this country. It shouldn’t, and there is nothing in the bill to prevent classes on Hispanic (or any other minority) influences on U.S. history. It only prohibits classes intended to only be taught to a specific group. I'm not surprised - if it's illegal to have schools for specific groups, why would it be legal to have classes set up that way?

I do object to the prohibition against teaching “ethnic solidarity." Being proud of your heritage could be considered “ethnic solidarity.” Everyone should be proud of their heritage, and there’s nothing wrong with schools teaching that. But you should be proud of your entire heritage. Whether you are a recent immigrant or your family has lived here for generations (or centuries), whatever continent your ancestors hailed from you should be able to look to your entire history, both your ancestry and your nation, for a sense of pride in your heritage. Schools should promote that. To promote that they should be helping students realize that even though we are all different, we all share many things in common. Apparently the Tucson school districts ethnic studies program doesn’t always do that. According to the AP story:

"Horne, a Republican running for attorney general, said the program promotes "ethnic chauvinism" and racial resentment toward whites while segregating students by race. He's been trying to restrict it ever since he learned that Hispanic civil rights activist Dolores Huerta told students in 2006 that "Republicans hate Latinos."


It’s one thing to promote pride in your heritage. It’s another thing entirely to promote hatred, and that is what you are doing when you tell someone that an entire group of people hates them.

Both of these bills are controversial, although the neither bill should be. Not if they were really written and passed for the stated reasons. Enforcing the law is the duty of law enforcement officers. I believe the oath most of them take is to enforce laws of the community, state and country, not just the laws of whatever level of government (city, state or federal) happens to employ them. Schools are supposed to teach kids and to prepare them for life - and make them productive, loyal citizens. Like it or not, propaganda has always been one purpose of the public school system. It is a legitimate purpose. No modern society can survive if it's children are taught to hate and distrust people who are different - different people are part of our society.

Teaching the bad things that happened in the past does not have to be divisive or disruptive - and should not be. Enforcing legitimate laws - for instance, laws requiring visitors to our country to go through the same established legal channels our citizens have to go through to visit their countries - should not be divisive or disruptive. But sensational headlines and soundbites can cause them to be. So can poorly thought out or carelessly worded laws.

So does Arizona have the right idea? Should we be taking steps to enforce immigration laws? Before you answer, maybe you should cross illegaly into Mexico, Canada, or any European nation and see what happens if you get caught. Should we prohibit/monitor what is taught in classes to make sure it is for the common good? Should we make sure that classes that teach about the contributions of non-caucasions to our country are taught to everyone, so all students benefit from them? Better yet, should we make sure that those contributions are part of the standard classes - requiring that they be taught, not just that they appear in the textbooks?

Based on what I know of the two laws, I would say that they do have the right idea. If giving current illegals amnesty and a path to citizenship worked to discourage illegal immigration, we wouldn't be having this discussion. If an activist speaker was allowed to sat that Republicans (widely portrayed as all rich white people) "hate latinos," that's promoting racial tension, and should not be allowed in schools. Would she have said that if it was a class of all ethnicities? Would she have wanted to speak to such a class? I don't know. And I don't have a problem with her being asked to speak to a class. I do have a problem with classes being used to promote a particular political party or cause, and that's why I think Arizona has it right on the education bill, too.

Wednesday, May 12, 2010

Could Buzz become Facebook for education?

In his blog entry on ZDNet, "A social networking call to arms" Christopher Dawson looked at Google as the potential social networking provider for education and business. He makes some good points. In the past Google has been considered a nemesis of personal privacy for their retention of user search and email data long after the fact. But they have responded to their users concerns by limiting the time data is kept, and when they made the major blunder at the introduction of Buzz were quick to fix the problem. Facebook, on the other hand, is continually expanding what user information is considered public without consulting users or seeming to care about their wishes. Schools have to keep certain data private, and Facebook does not allow that.

There was a time when Facebook might have been useful as a tool for teachers. That time is long past. But a social network run by Google could work. Google does not make change their privacy policy every six months (or less) in an effort to make more of the user data public. And Google has experience providing secure services in the cloud to businesses already. They already have most of the ingredients of a successful social media site if they can find a way to tie them all together. Google Search, Google Reader, Youtube, Blogger and Google's handling of privacy issues are some pieces of the puzzle. All Google needs is a way to package them together that satisfies the privacy and security needs of educational institutions while providing the social experience people want.

Tuesday, May 11, 2010

Facebook users love sex!

Shira Lazar of CBSnews.com reports that Dan Zarella has written an algorithm that analyzes social media posts and create a psychological profile of the poster. And according to his analysis of 12,000 posts (posts, not users posts), Facebook users love sex. I have to wonder if his sample is large enough to be statistically significant, and how he selected them, but it still puts that English researchers conclusions about Facebook and syphilis in a new light.

I also have to wonder how many of those people posting about sex will have reason to regret it later.

Monday, May 10, 2010

More Homeland (in)Security

In a report on Yahoo News, EILEEN SULLIVAN and MATT APUZZO of the Associated press tell us why Faisal Shahzad was almost able to leave the country by plane after his alleged failed bombing attempt. It's a sad statement that just four months after dumb luck kept the crotchbomber from blowing himself and his fellow passengers out of the sky in a plane he shouldn't have been able to board, dumb luck again prevents a terrorist wannabe from igniting his bomb - and in this instance, escaping by boarding a plane he should never have been able to board.

This sad statement on U.S. security reminded me of an almost 4 year old blog post by Bruce Schneier on the arrests in July, 2006 of terrorists reportedly hoping to set off a so-called "binary explosive" - something apparently extremely difficult to do. Regardless of the likelihood of that scenario, Mr. Schneier makes some very good points:

"None of the airplane security measures implemented because of 9/11 -- no-fly lists, secondary screening, prohibitions against pocket knives and corkscrews -- had anything to do with last week's arrests. And they wouldn't have prevented the planned attacks, had the terrorists not been arrested. A national ID card wouldn't have made a difference, either.

Instead, the arrests are a victory for old-fashioned intelligence and investigation. Details are still secret, but police in at least two countries were watching the terrorists for a long time. They followed leads, figured out who was talking to whom, and slowly pieced together both the network and the plot."


Last Christmas's intelligence fiasco points out the same thing. In 2001 we had a massive intelligence failure - all the pieces were there, but inter-agency, even intra-agency, rivalry prevented the all the pieces being gathered to be put together. In December 2009 all the pieces were there, but were ignored, or not communicated in a timely manner. In the two incidents of the last 6 months the terrorist boarded an international flight despite being on the no-fly list. All of this shows that we don't need more ways for the government to monitor and spy on us. Adding new ways to gather information so it can be misused - or not used at all - is not an answer. We need to make proper use of the methods we already have in place. Then we can know what is working and what needs changing.

Friday, May 7, 2010

Facebook - Too big to regulate?

Robert Scoble of the Scobleiezer blog expressed the opinion last week that it is too late to regulate Facebook. He raises some good points, but I think he is missing a couple of things, too. He raises several points, covering both what Facebook has done, and what governments might do to regulate it (and why it's moot to try).

For his discussion of what Facebook has done and why it's shaking up internet businesses that never expected Facebook to have any impact on them, read his post. It's interesting (and troubling), but for my purposes, what he says about the futility of trying to regulate Facebook is more important.

So what exactly does Mr. Scoble think governments can do to Facebook? Effectively, not much, because anything they do will have either no effect or the opposite of the intended effect. But he does list three things governments can do - four reasons it won't matter if they do - along with my comments in italics:
Well, first of all, what can government do?

1. They can force Facebook to switch its defaults on its new Instant Personalization program. The government could force Facebook to turn that feature off by default and make me “opt in” for you to see my Pandora music.

2. They could fine Facebook for its behavior.

3. They could call Mark Zuckerberg in front of Congress and call him nasty names.

But what else could the government do? I don’t see too many options. Do you?

So, why is it too late to regulate Facebook?

1. The damage is done. Well, let’s assume they made them switch Instant Personalization to opt in. Who cares? The damage is done. My Pandora already has all your music shared with me. Most Facebook members won’t change their privacy settings from what they already are. So, old users will keep sharing their music and only new members will be asked to opt in to these new privacy-sharing features.

Like he says, most people will never change their privacy settings, so this could actually be very effective. It's better if done quickly so as few people as possible notice, but until more services join up changing the settings from default-share to default-private will go largely unnoticed.

2. The regulation will come too slowly. Government never moves fast. Even when it’s motivated. So Zuckerberg has at least a few months to aggregate his power before Government slaps him on the hand. Government is not going to be able to prevent that top 50 website from putting Facebook’s new features into its service. Government will not keep me from using Pandora.

Unfortunately, this is very true. Governments act slow unless directly threatened (ie, Pearl Harbor or 9/11). Each month action is delayed action becomes more difficult.

3. The regulation will come after we get used to new privacy landscape. Already I’m finding I’m getting used to the fact that you all can see my data and that I can see yours. So, if Government comes along and tries to regulate that it will get pushback from me. Why? Well, I actually like the new Pandora features. I’m finding a ton of cool music because Zuckerberg forced you to give up some of your privacy. So what that I can see that you like Kenny G? Users will get addicted to these new features and they won’t take kindly to some government jerk taking away these new features.

Again, very true. The unfortunate truth is that users will decide they're willing to lose a little privacy for these nice features, but won't realize how much privacy they're giving up until it's too late.

4. Giving Zuckerberg a fine will not change Facebook’s behavior. If anything it will just push him to monetize these features more aggressively in order to pay the fine. Just wait until Cocacola icons show up next to all those Facebook like buttons. Government taxation, which really is what fines are, might have a negative effect long term.

Sadly, Mr Scoble knows what he's talking about. Fines will have as much effect as they did on Microsoft. The threat of being broken into three companies scared MS, not fines. And even that had little effect.

Robert is right. Of the three options he sees, only one has any chance of success. Government intervention could make some changes to the way Facebook handles user data, but unless it's done quickly, it will just be going through the motions. It's up to the users of Facebook to force Mark Zuckerberg to respect their privacy. Sadly, most don't realize the value of what they are giving up to him, so they are unlikely to do anything.

Thursday, May 6, 2010

Facebook exposes private chats

In the Bits blog Nick Boltin reports on the Facebook bug that exposed private chats to public scrutiny. Facebook claims the bug was only live a few hours, and has shut down chat until the bug can be fixed (perhaps by the time you read this). This can't help Facebooks reputation in the eyes of the Electronic Frontier Foundation or Senator Charles Schumer (D, NY). Senator Schumer is one of the Senators calling on the FTC to craft privacy guidelines for social networks.

I'm not sure this was really an accident. Yes, I'm being paranoid and cynical, but the Facebook business model is to push for users to make everything public. I wouldn't be surprised if this was a 'live test' to see what kind of reaction results from this "bug".

Wednesday, May 5, 2010

10 reasons to leave Facebook

This post is a direct copy of Dan Yoder's April 26th post on his rocket.ly blog used in accordance with his Creative Commons Attribution-Share Alike license.

Top Ten Reasons You Should Quit Facebook


DateMon Apr-26 2010 | AuthorDan Yoder




Ban FacebookLet's all ban Facebook!


Update: Due to the surprising popularity of this post, I feel I should be absolutely clear about my role as VP of Engineering for a Hollywood-based social media startup, BorderStylo. The opinions expressed here are purely my own and are not in any way endorsed by my employer. While I do not see our applications as directly competitive to Facebook, nor have I presented them as such, it would be disingenuous not to mention this.

Tuesday, May 4, 2010

Alcohol + camera + Facebook = no play

Greg Cergol from nbcnewyork.com reports that several lacrosse players at Ward Melville High School in New York were suspended when school officials saw pictures of them drinking on Facebook.

Fifteen lacrosse players were suspended because of the pictures - six of them indefinitely. This kind of occurrence isn't anything new, although this may be the largest group of high school students to hose themselves on Facebook to date. If I had any illusions about high school students thinking about how private Facebook really is, my favorite quote from the article would have disabused me:
"Maybe it's not the smartest move to have put the photos up," said senior Teddy Ouwerkerk. "I guess Facebook isn't the most private after all."