Scrupuli

blunt essays with sharp points

Privacy Risks of Facebook Applications

by Scrvpvlvs
Jan 8, 2009 6:54 PM–I was just asked about the privacy risks of what are called Facebook applications. It is well worth looking at, and I had given it only superficial attention.

I will begin with what a Facebook application is. Then I will present the personal data that is at stake. I will share my beliefs about how far you can trust a Facebook application with this data. Finally, I will suggest Facebook settings that I think are safe.

  1. What is a Facebook application?

    A Facebook application is an add-on to Facebook. Facebook offers a few of its own, such as Marketplace. The rest are contributed by web programmers all over the world. Whenever you get the message:

    Allow Access?
    Allowing (application name) access will let it pull your profile information, photos, your friends' info, and other content that it requires to work.
    Allow or cancel

    That is a Facebook application wanting your personal data.

  2. What information can a Facebook application get from Facebook?

    Almost everything you were willing to tell Facebook.

    According to Facebook, when you “Allow” an application, the application sees the same personal data that your friends do, except contact data (your address, phone, e-mail, IM, or website). It does not see unshared data such as your password.

    When a friend of yours “Allows” a Facebook application, the application sees limited data about you, too. This limited data can be extensive or it can be nothing at all, depending on your preference.

  3. How far can you trust a Facebook application?

    You might as well trust Facebook’s own applications, since you were willing to give the information to Facebook. But what about contributed applications? BBC looked into this in 2008. A BBC web programmer created an innocent looking Facebook application which secretly skimmed personal data from any user who allowed it, plus their friends. (This is called a Trojan horse attack.) It was three hours of effort. I looked into Facebook programming, and saw for myself how easy it would be.

    But BBC knows of no badly behaving Facebook applications (other than theirs). They say Facebook has a team that monitors the site for bad applications. If it is so easy to do, why isn’t Facebook overrun with bad applications? One possibility is that Facebook’s team is doing its job: when a bad application is released into the wild, it is detected and removed. A more grim possibility is that there are bad applications in the wild, but they have avoided detection. BBC did not release their bad application into the wild, so we don’t know if it was detectable.

    I think you can trust contributed applications to keep your personal data private only if you think Facebook is policing them perfectly, and I don’t think that’s been proven.

  4. So what do I do about Facebook applications?

    I treat anything I post to Facebook (other than my password and contact information) as if it might be available for anyone in the world to see. If I would be uncomfortable with that, I don’t post it.

    However, that does not work for your birthdate. Facebook requires you to supply it, and it is potentially useful for identity theft. Nevertheless, it is part of the personal data that applications can see.

    For that reason, when an application asks to be allowed, I check it out first. And until I feel pretty sure that it is not more than what it seems to be, I don’t allow it. Also, I have denied my “Basic Info” to applications allowed by friends, because that protects my birthdate from applications which I have not checked out personally.

    Another way to secure your birthdate is to supply the wrong date. The Facebook terms of service only require you to say truthfully whether you are 13+ or 18+. As long as the date you supply does not misrepresent your age category, you are not violating the terms of service. You could save your friends some confusion by supplying the true month and date, and changing only the year.

You control which applications you allow to access your personal data on these pages:

http://www.facebook.com/editapps.php?v=allowed
http://www.facebook.com/editapps.php?v=additional

You control what personal data your friends’ applications can access on this page:

http://www.facebook.com/privacy/?view=platform&tab=other

Facebook keeps a list of all applications on this page:

http://www.facebook.com/apps/

Facebook documents the personal data available to applications on this page:

http://wiki.developers.facebook.com/index.php/FQL_Tables

Here is the BBC article.

http://news.bbc.co.uk/2/hi/programmes/click_online/7375772.stm

Please comment if you have anything to add or correct in this article. I would like it to be as accurate and useful for Facebook users as possible.

Labels: , , , , , , , , , , , , , , , , , , ,

(go to complete article)

Share:

0 comments

A Thirty Year History Of Google Chrome … Continued

by Scrvpvlvs
Oct 17, 2008 11:33 PM–

Evolution of Personal Computers

When I talked yesterday about thirty years of personal computers, I did not mean IBM compatibles. I meant all PCs (including, for example, the Mac, the TRS-80, and the Amiga.) I did not make that clear, and I apologize.

Here is a time-line of major events in the evolution of PC reliability. Technically speaking, I mean protected memory, preemptive scheduling, and allied protection features which keep an error in one application from crashing other applications or the whole system.

1982. P/OS, Digital Equipment Corporation
DEC miniaturized an existing data center architecture having protection features (RSX-11M), to compete with the IBM PC.
1987. OS/2, IBM
IBM developed this Windows competitor from the ground up, incorporating protection features they knew to be important from their data center experience.
1993. Windows NT, Microsoft
Microsoft started to catch up in 1990, with limited memory protection in Windows 3.0. They only really got it right when they released Windows NT 3.1. NT was a rewrite of Windows by ex DEC developers.
2001. Mac OS, Apple
Apple tried to rewrite their own operating system, but what ended up working well for them was a merger of their original Mac OS with the UNIX operating system.

(It is hard to know if and when to put Linux on the time-line. Linux had protection features from its inception in 1991 because its design was based on UNIX, but it only now beginning to make any inroads into the personal computer mass market.)

The time-line is based on a bit of research and what remains of my memory, so please correct me if you know better.

Advantages Of The Data Center

A family computer is used for business and personal records. On a family PC you will find a whole lot of correspondence in the form of saved e-mail. There will be various kinds of record keeping, from family histories to monthly budgets. Many people are storing photos and music collections on the computer. Any number of personal projects—greeting cards, posters, newsletters.

People put too much faith in PC hard drives, discs, and memory cards to preserve their family records. These devices break, and they get stolen. Migrating away from local applications is advantageous. Data center equipment breaks too, but data centers have parallel secondary systems that take over until the primary systems are restored, with no loss of data and little or no interruption of service. Security against physical theft of the storage devices is much better.

How Risky Is It to Migrate?

On the other hand there are some new things to worry about. What is the risk of unauthorized, undetected use of family records by data center personnel or by the government? Google has a strict privacy policy, but what enforces it, and, for that matter, what keeps Google from changing its mind? The risk is not easy for the mass market to assess. This fact leads them to imagine that it might be a high risk, and avoid it. Similarly, they find it hard to assess the risk that Google will close its facilities unexpectedly. And the very fact that Google provides free service creates a fear that Google has no incentive to provide a reliable service.

There are real risks here, but I think they are often hugely overestimated. The incentives to Google are being looked at the wrong way. Google is like television in an important respect.

You (the user) are not the customer.
Google is not your supplier.
The advertiser is the customer.
You are the product.

Google earned $1.35 billion in the last quarter and has $14.4 billion in cash. There is plenty of incentive to continue attracting users by creating and maintaining a reputation for ethical behavior and reliability. If Google offends its users, they will go elsewhere and Google’s revenue will go with them.

Google doesn’t only run public services. It also runs the same services at private data centers for paying corporate customers. But corporate demand for high availability causes improvements which carry over to the public services.

When a bank goes bankrupt, its operations do not stop. Another bank buys its operations and its customers. My login screen for WaMu now mentions JPMorgan Chase in passing; it’s the same bank under new management. If Google goes bankrupt, its operations and its user base are too valuable to be discarded. Another player in the cloud computing market will buy them, add their name, and go on. The real risk is that at that point I will be offended by a logo reading “Microsoft Google”, and take my files and go elsewhere.

Supposing I am wrong, and one day Google is simply not there. How will I get my family records back? Well, Google actually stores my documents in an open, non-proprietary format. Google also keeps copies of all my documents on my personal computer if I wish. (And, of course, I have opted to do this.) Google offers this option so that I can continue working if my network connection goes down, but I can actually continue working if Google goes down and stays down, until the open source community takes over for them. I think this is really why Google does so much to support open source software. By making themselves non-proprietary, they eliminate risks that I would otherwise be taking by using them.

This is not to say that people should not keep their critical family records in printed form. Nobody should think of keeping their will in Google Docs. And even paper has its problems. We have a printer with archival quality, pigment based ink. The family photos we print with it ought to last many, many years, long after the plastic compact discs gas out enough plasticizer to self-destruct. But it is still true that a fire, a flood, or a plague of insects can destroy them, and I am glad enough to have copies of them stored in digital form at a data center.

Labels: , , , , , , , , , , , , , , , , , ,

(go to complete article)

Share:

0 comments

A Thirty Year History of Google Chrome, Plus How To Share Chrome Settings Between PCs

by Scrvpvlvs
Oct 16, 2008 2:47 PM–Google announced Gmail on April 1, 2004, according to the press release. Gmail was followed by other web based applications: word processor, spreadsheet, slide show. These applications have delighted people who use Office, OpenOffice, WordPerfect, or Lotus.

No errors caused by opening a document created with the wrong version of software. No confusing differences in menus, features, or settings between the home computer, the office computer, the laptop.

No schlepping documents around on floppies or discs. No huge e-mail attachments.

No important documents lost to hard drive crashes or stolen laptops. No embarrassing failures to make frequent, time consuming backups.

Just sign in, and the application and the document are ready to work for you—and you can collaborate with anyone else that you give access to. Specialists at the data center keep the system in order, and you get more actual work done.

It comes as a surprise to many people that, thirty years ago, this is how we used computers. You just signed in from wherever you were, and there were your applications and documents, lovingly maintained on the mainframe computer at the data center.

The personal computer devolution.

Around that time, electronics got small and cheap enough that a family or a small business could buy one and make room for it on a desk. By 1980, over a million had been sold worldwide. At the time, we called it the personal computer (PC) revolution. That was when it began to be easy to work at a computer outside a data center.

A computer that didn’t slow down considerably in the afternoon. That you could update yourself when there was an application you needed. That had a printer that was never busy with someone else’s project.

But a cheap PC, with cheap software, that would frequently eat your disk or crash after you had entered an hour’s worth of work or fail to boot after you installed an application.

That wrote disks that another PC would not read. That could call another PC on the phone and transfer a 20 page document from it in about 20 minutes (and maybe fail to open it).

High speed networks bridge the gap.

Thirty years later, PCs have gotten much better, and the network has gotten fast and cheap. The family and the small business have a high speed link from the PC to data centers all over the world. And the new network made it possible to unify the two models of computing.

Enter Google. The Google applications and documentss are stored and kept up to date at the data center, and used from any PC. The application and the document are flash-transfered to and from the PC automatically, over the new high speed network.

The PC, not the mainframe computer, actually powers the application. If the application is underpowered (or when the PC fails, because they all fail—it is only a question of when) you replace the PC without the pain of migrating documents or restoring them from a backup that you made six months ago.

A new browser makes it better.

Finally, enter Chrome, a new browser released by Google in September.

Despite the limitations of the first release, I immediately abandoned Mozilla Firefox for Chrome. Chrome is the next step in the evolution of the PC. Chrome is designed to run network applications differently than other browsers in three ways which I shall call Better, Stronger, and Faster.

Better.

The Chrome developers did not make a more complicated, feature-heavy browser. They made the browser controls simpler and less intrusive than in other browsers. They learned from Firefox and Opera, and added some good ideas of their own.

Stronger.

Mainframe computers were shared by many users running many applications. Barriers had to be erected between applications and between users. These made it impossible for one user to access another user’s private documents. They also made it impossible for one application to crash another application. If an error occurred, it was contained. One bad actor could not bring the whole system down.

These barriers were not originally available on the cheap PCs. It took more than ten years for them to appear. But they did, and PCs crash a lot less. But web browsers have not taken full advantage of this—until Chrome.

Chrome has put these barriers around each browser tab. If an error occurs on a page, it is contained. One bad web based application cannot bring the whole browser down, or interfere with another tab, or access another tab’s private data.

Faster.

By putting barriers around each tab, Chrome also recycles all the memory of a tab when you close it. I can’t tell you how often I have restarted Explorer, or Firefox, or (faugh!) AOL because poor recycling of memory had led to a memory shortage on the PC. I have never had to do this with Chrome.

Chrome even provides a task window that shows the size and activity of each tab and plug-in, so you can see any bad actors and close them.

Problems with Chrome.

Chrome is brand new, and there are still problems to be worked out. There are two problems that plague me in the first release.

One is a software glitch. Applications that rely on plugins such as Java, Flash, Adobe Reader, or Google Gears can still cause the entire browser to come to a halt. I tend to run into this with YouTube, Google Analytics, and National Weather Service radar loops.

Incredibly, the other is that Chrome—the very application that is helping unify the PC with the data center—stores its browser settings, bookmarks, history, and open tabs on each PC instead of at the data center! With Firefox there were add-ons available to do this (Google Browser Sync and then Mozilla Weave) which I sorely miss.

Being a data center kind of guy myself, I could not wait for Google to fix this. I added an application called SyncToy from Microsoft. It keeps my Chrome settings the same at work and at home, including bookmarks, history, and open tabs. It’s very easy to operate, but it took a little work to set it up.

Here’s how I set it up.

Both PCs run Microsoft Windows XP.

I installed WebDrive 8.2 on both PCs. This shareware app lets any other app on the PC see a remote file server as a local hard drive with its own drive letter such as Z:. I gave WebDrive a password to a public FTP file server that I already have an account on. (Before I selected WebDrive, I tried NetDrive and FTPDrive, which are freeware apps. They nearly worked, but they corrupted the files. WebDrive was reliable.)

I installed Microsoft .NET Framework 2.0 on both PCs. I did this because SyncToy needs it.

I installed SyncToy 2.0 on both PCs. I gave SyncToy the name of the Chrome user data directory on my PC:

C:\Documents and Settings\Edward\Local Settings\Application Data\Google\Chrome\User Data\Default

I created an empty directory on the Z: drive and gave that to SyncToy to sync with the Default directory. I told SyncToy not to copy the Thumbnails file or the Cache subdirectory, and for my peace of mind I told it to check file contents.

That was all. Now, before I start Chrome and after I stop it, I bring up SyncToy, preview the sync, and run it.

I expect I’ll have to work out a bug or two in this procedure, and then I hope to use SyncToy’s scheduling feature to make the extra steps automatic. If I accomplish that, I’ll post a followup article.

Labels: , , , , , , , , , , , , , , , , , , ,

(go to complete article)

Share:

1 comments

about.me

Follow

feed

E-mail: enter address

Project Euler competitor metaed

vs.

Project Euler competitor db8

profile for MetaEd on Stack Exchange, a network of free, community-driven Q&A sites

Recent Articles

Cataclysm

Open letter re: Grinnell College alumni “lifetime”...

Spybot – Search & Destroy interferes with Lync 201...

A moment of silence

Rondeau

Howard Schultz of Starbucks: firm on support for m...

In each of us, two natures are at war

Clorox does not understand how to measure bleach

This season’s pie recipe

Adamah

Archives

November 1999
June 2000
July 2000
September 2001
October 2001
February 2002
March 2002
June 2003
February 2004
June 2004
July 2004
August 2004
September 2004
February 2005
March 2005
November 2005
July 2007
March 2008
April 2008
May 2008
October 2008
November 2008
December 2008
January 2009
April 2009
September 2009
December 2009
February 2010
March 2010
May 2010
June 2010
September 2010
October 2010
November 2010
December 2010
January 2011
April 2011
June 2011
July 2011
August 2011
September 2011
December 2011
February 2012
April 2012
May 2012
June 2012
July 2012
August 2012
September 2012
November 2012
January 2013
February 2013
April 2013
February 2014
May 2014
October 2014
June 2017
February 2019