Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Friday, May 25, 2018

More GDPR





If you are like me, you have likely seen more notices about privacy policy updates during recent days and weeks than the entire time you have been on the Internet.  Although, I must admit that I particularly enjoyed the "First message from deep space", that I saw on Twitter via Marcin Kleczynski.









Even after all the privacy policy notices I have seen, I was surprised when opening my blog account this morning to find the the information below that Google placed in my account:



Following the "Learn more" link which redirects to Cookies notification in European Union countries - Blogger Help, I discovered that visitors to Security Garden from the EU should be seeing the following notice:

Google Added Cookie Notice

 "LEARN MORE" from the notice leads to How Google uses cookies – Privacy & Terms – Google.

 Since I have confirmed that the notice works and displays, do not use AdSense and am not aware of any functionality from other providers, I gather that GDR requirements have been fulfilled with respect to this blog.  However, that may not be the case with Google as indicated in Google and Facebook accused of breaking GDPR laws - BBC News and Facebook and Google hit with $8.8 billion in GDPR lawsuits - The Verge.



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, October 03, 2017

Cycber Security Awareness Month


October is National Cyber Security Awareness Month (NCSAM).  The 2017 Cyber Security Awareness Month marks the seventh anniversary of the campaign.  It is also European Cyber Security Awareness Month (ECSM) https://cybersecuritymonth.eu/  and in Canada, https://www.getcybersafe.gc.ca/index-eng.aspx 

  Stop | Think | Connect

With that in mind, consider the following suggestions not only during Cyber Security Awareness month but every day:

    Stop:  Before you click that formatted link in your email, search results or social media account, mouse over the link to ensure the URL matches the description.

    Think:  Whether it is email, Facebook, Twitter, an online forum or other online media, instead of spouting off the first reply that comes to mind when you disagree, think before you click the send button.  Remember that your online reputation can follow you in "real life".

    Connect:  When you connect to the Internet, ensure your device software as well as any apps or third-party software are up to date.

Each week, Malwarebytes Labs will focus on a theme and provide helpful articles, useful tips, and valuable analysis so that you can increase awareness and spread the word. This week’s theme: simple steps to online safety. The first:  National cybersecurity awareness month: simple steps to online safety | Malwarebytes Labs


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, January 28, 2017

Data Privacy Day #PrivacyAware



January 28 is recognized as Data Privacy Day, a day established annually to promote information on privacy awareness.  However, we all need to be concerned with protecting their privacy not only on Data Privacy Day but every day.

I have posted about Data Privacy Day since 2011, covering a variety of suggestions to protect privacy.  This year, let's consider privacy and Windows 10.

With the release of Windows 10, there were people who didn't take advantage of the free update due to scaremonger articles about privacy and "reporting back" to Microsoft. 

One of the first things people hear about is "telemetry".  What is telemetry?  From Wikipedia:

"Telemetry is an automated communications process by which measurements are made and other data collected at remote or inaccessible points and transmitted to receiving equipment for monitoring. The word is derived from Greek roots: tele = remote, and metron = measure. Systems that need external instructions and data to operate require the counterpart of telemetry, telecommand."
It is important to realize that the use of telemetry is not unique to Microsoft and is employed by other companies as well to identify and analyze issues that need to be fixed.  If this really bothers you, it can be set in Settings under Feedback and diagnostics to Basic.

More importantly, Microsoft has heard users' requests for more control over privacy in Windows 10.  As a result, the next update to Windows 10, referred to as the "Creators Update" will include the changes to privacy outlined by Terry Myerson, Executive Vice President, Windows and Devices Group, in Our continuing commitment to your privacy with Windows 10.

In the meantime, there are numerous journalists who have written about privacy settings in Windows 10.  One of my favorites is Ed Bott.  If you have concerns about the information you may be sharing, I suggest you read Ed Bott's recent article, Take control of your privacy in Windows 10 and Microsoft tries to soothe regulators and critics with new privacy controls.

For previous Security Garden articles about Privacy, check the Privacy label.

_______________

Data Privacy Day Information and Resources:



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Thursday, January 28, 2016

Data Privacy Day Is Today and Every Day! #PrivacyAware

Data Privacy Day

The official Data Privacy Day theme is Respecting Privacy, Safeguarding Data and Enabling Trust.  Everyone needs to be concerned with protecting their privacy not only on Data Privacy Day but every day.

Below is an update of information I have provided previously on protecting your data privacy, with additional references included.  Take a closer look at why you would want to safeguard your data and steps we can all take for keeping our data safe.

Data

What information do you store on your computer?

Home computers have rapidly become the storage place not only for personal correspondence but also for financial data, including bank records and government tax return forms.  This information in the wrong hands can, and does, result in identity theft.  Learn how to encrypt folders on your computer that contain sensitive information from Windows Help, Encrypt or decrypt a folder or file.

What information do you share on social network sites?

Facebook is one of the largest social network sites where people connect with not only friends and family but also acquaintances.  These acquaintances may be people they "met" at other sites, forums or through friends and family.  However, they are only known virtually.

Not only is the information you share on sites like Facebook data, so is your home town, where you went to school, when you graduated, your birth date, address and telephone number as well as names and birth dates of family members.  If this information is public, it is the very information that identity thieves can use.

What about your smart phone?

Do you check in at every location as you go about your daily travels and share it on Twitter or Facebook?  Do you announce and document business or family trips?

Is your browser tracking your activities?

Check the settings in your browser of choice.

Information stored on your computer or shared on social networking sites includes data that needs to be safeguarded to protect your privacy.

Safeguarding Data

The message about having an up-to-date antivirus software and firewall has been well received by home computer users.  When helping with malware removal, it is has been a very long time since I have seen a computer without antivirus software and a firewall.  Computer users are also getting much more conscientious about installing security updates and keeping third-party software updated.

This is all good news, but malware writers are very clever and manage to find a way to infect computers.  In addition to the standard antivirus, firewall, updating what else can you do to safeguard your data?

In addition to keeping your computer and software programs updated, following are a some general suggestions for protecting the data on your computer:
  1. Protect your wireless router with a strong password.
  2. Don't open e-mail, instant message or Facebook attachments you are not expecting.
  3. Do not click anywhere on a pop-up or warning from a program you did not install.  Use the keyboard shortcut Alt + F4 to close the window.
  4. Pay close attention when installing software.  Do not blindly click through the screens or you may end up with more than you expected.
  5. Whenever possible, only download software programs from the vendor site.  Keep in mind that free is not always free.
  6. Always scan any file you download from the Internet.
  7. Have a back-up plan in place, particularly for documents, pictures and other files that cannot be replaced. 
  8. Use a complex password, not a "dictionary word" or family name.
What about safeguarding the data you share on social networking sites like Facebook?  

Facebook makes it easy to connect and share information with friends and family.  However, it is critical to ensure that you are not openly sharing personal information that could make you a target of identity theft.

See this excellent guide by Sophos, Facebook Security Best Practice, which not only covers information and setting recommendations but also explains the reasoning for the recommendations. 

Another resource that is helpful for Facebook users is Facecrooks, a source for not only privacy information but also the latest hoaxes that regularly circulate on Facebook. 

A few easy steps will keep both the data on your computer as well as the information you share both secure and private.

Resources



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...



Thursday, October 01, 2015

October -- Cyber Security Awareness Month


#NCSAM
Each year additional organizations join in the effort to spread information on cyber security awareness.

The 2015 Cyber Security Awareness Month marks the fifth anniversary of the campaign

  Stop | Think | Connect


With that in mind, consider the following suggestions not only during Cyber Security Awareness month but every day:

Stop:  Before you click that formatted link in your email, search results or social media account, mouse over the link to ensure the URL matches the description.

Think:  Whether it is email, Facebook, Twitter, an online forum or other online media, instead of spouting off the first reply that comes to mind when you disagree, think before you click the send button.  Remember that your online reputation can follow you in "real life".

Connect:  When you connect to the Internet, ensure your device software as well as any apps or third-party software are up to date.

Cyber Security Awareness Month Resources

The United States isn't the only country supporting cyber security awareness.  Canada and the European Union are also involved in promoting cyber security awareness month.  Visit their sites along with the others listed.

Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Monday, October 06, 2014

Cyber Security Awareness Month


With the release of the Windows 10 Technical Preview, Cyber Security Awareness Month almost lost focus.  Well, I've set Windows 10 Technical Preview aside for now to share some of the many security resources available not only during October but year round.

First, however, let's focus on protecting your digital life.

#NCSAM

Two-Factor Authentication

Two-factor Authentication (2FA) or Multi-factor Authentication (MVA) is a method of providing two forms of identification in order to obtain access.  It is comprised of something you know (password, passphrase, pin) and something you have (SMF code, RSA SecurID).  A third means is something you are such as your fingerprint or other biometric.

Why the concern?  It isn't only your email, Facebook or Twitter account that you need to be concerned about protecting.  A more grave concern is protection from identity theft which can occur when someone steals your personal information and uses it without your permission.  Identity theft can result in loss of finances and destroy both your credit history and reputation and is not easy to recover from.

It is the very information that is accessible from in your email account and shared in social media sites that, if compromised, can result in identity theft.  Two-factor authentication is a means protecting that information.
  1. Although you've heard this before, it bears repeating.  Start with a strong password and use a different password for each site.  (See Tips for creating a strong password.)  This becomes the something you know.

  2. The next step in enabling two-factor authentication requires setting up your account for the something you have, a code sent to your cell phone or to an alternate email address. 

    With your Microsoft Account used not only for email but also other Microsoft apps and services, it is one of the first places to start.  Fortunately, setting up two-factor authentication for your Microsoft Account is easy.Numerous references are available from my earlier blog post here.  
For sites that still use the archaic "challenge question" method to verify your identity, please see this advice in Bits from Bill, Your Email Password is a Target.

It is equally important to protect any files stored in the cloud.  If you use a Microsoft or Google account, Office 365, Dropbox, Facebook, or Twitter, see Ed Bott's step-by-step instructions in Make your cloud safer: How to enable two-factor authentication for the most popular cloud services.  Also check the Two Factor Auth List to find out which sites support two-factor authentication.

Cyber Security Awareness Month Resources

The United States isn't the only country supporting cyber security awareness.   Canada and the European Union are also involved in promoting cyber security awareness month.  Visit their sites along with the others listed below and



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Tuesday, January 28, 2014

Data Privacy Day #DPD14

Data Privacy Day


Although January 28 is the date officially set aside annually as Data Privacy Day, privacy needs to be an every day concern.

The official Data Privacy Day theme is: Respecting Privacy, Safeguarding Data and Enabling Trust.

Following is an update of information I have provided previously on protecting your data privacy, with additional references included.  Take a closer look at why we would want to safeguard our data and steps we can all take for keeping our data safe.

Data

What information do you store on your computer?

Home computers have rapidly become the storage place not only for personal correspondence but also for financial data, including bank records and government tax return forms.  This information in the wrong hands can, and does, result in identity theft

What information do you share on social network sites?


Facebook is one of the largest social network sites where people connect with not only friends and family but also acquaintances.  These acquaintances may be people they "met" at other sites, forums or through friends and family.  However, they are only known virtually.

Not only is the information you share on sites like Facebook data, so is your home town, where you went to school, when you graduated, your birth date, address and telephone number as well as names and birth dates of family members.  If this information is public, it is the very information that identity thieves can use.

What about your smart phone?

Do you check in at every location as you go about your daily travels and share it on Twitter or Facebook?  Do you announce and document business or family trips?

Is your browser tracking your activities?

Check the settings in your browser of choice.


Information stored on your computer or shared on social networking sites includes data that needs to be safeguarded to protect your privacy.

Safeguarding Data

The message about having an up-to-date antivirus software and firewall has been well received by home computer users.  When helping with malware removal, it is has been a very long time since I have seen a computer without antivirus software and a firewall.  Computer users are also getting much more conscientious about installing security updates and keeping third-party software updated.

This is all good news, but malware writers are very clever and manage to find a way to infect computers.  In addition to the standard antivirus, firewall, updating what else can you do to safeguard your data?

In addition to keeping your computer and software programs updated, following are a some general suggestions for protecting the data on your computer:
  1. Protect your wireless router with a strong password.
  2. Don't open e-mail, instant message or Facebook attachments you are not expecting.
  3. Do not click anywhere on a pop-up or warning from a program you did not install.  Use the keyboard shortcut Alt + F4 to close the window.
  4. Pay close attention when installing software.  Do not blindly click through the screens or you may end up with more than you expected.
  5. Whenever possible, only download software programs from the vendor site.  Keep in mind that free is not always free.
  6. Always scan any file you download from the Internet.
  7. Have a back-up plan in place, particularly for documents, pictures and other files that cannot be replaced. 
  8. Use a complex password, not a "dictionary word" or family name.
What about safeguarding the data you share on social networking sites like Facebook?  

Facebook makes it easy to connect and share information with friends and family.  However, it is critical to ensure that you are not openly sharing personal information that could make you a target of identity theft.

See this excellent guide by Sophos, Facebook Security Best Practice, which not only covers information and setting recommendations but also explains the reasoning for the recommendations. 

Another resource that is helpful for Facebook users is Facecrooks, a source for not only privacy information but also the latest hoaxes that regularly circulate on Facebook.

A few easy steps will keep both the data on your computer as well as the information you share both secure and private.

Resources




Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Tuesday, October 01, 2013

2013 U.S. and Canadian Cyber Security Awareness Month #NCSAM

#NCSAM

Cyber Security Awareness Month is observed in the United States and Canada.  The purpose is to increase public awareness of cyber security.  The theme for the 2013 National Cyber Security Awareness Month (NCSAM) is Our Shared Responsibility.

There are many areas to consider when discussing cyber security.  The area I consider most dangerous is Identity Theft.  Identity Theft occurs when someone uses your personal information without your knowledge.  With your personal information, thieves are able to open credit cards and bank accounts, set up mobile service, make online purchases and more, destroying your credit in the process.

Let's examine what we can do to protect ourselves from Identity Theft.

Prevent Identity Theft

A few items to consider to protect your personal information include:
  • Only provide your Social Security Number when absolutely necessary.  
  • Never publicly post your address, phone number, driver’s license number, social security number (SSN) or student ID number.
  • Shred documents that contain personal information.
  • Use a strong password to protect your banking, credit card as well as accounts where you make online purchases or make payments.
  • Use a unique password at each site.
  • Don’t give out personal information on the phone, through the mail or over the Internet unless you initiated the contact.
  • Keep your computer updated with both Microsoft Security Updates as well as third-party software such as Adobe and Oracle Java products.

What cyber security tips do you have?  Share your favorites in the comments and be sure to check the additional resources provided below.

Resources:


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Monday, January 28, 2013

Data Privacy Day

Data Privacy Day


January 28 is the date set aside annually as Data Privacy Day.  The official Data Privacy Day theme is: Respecting Privacy, Safeguarding Data and Enabling Trust.

 Let us take a closer look at why we would want to safeguard our data and steps we can all take for keeping our data safe.

Data

What information do you store on your computer?
Home computers have rapidly become the storage place not only for personal correspondence but also for financial data, including bank records and government tax return forms.  This information in the wrong hands can, and does, result in identity theft.
What information do you share on social network sites?

Facebook is one of the largest social network sites where people connect with not only friends and family but also acquaintances.  These acquaintances may be people they "met" at other sites, forums or through friends and family.  However, they are only known virtually.

Not only is the information you share on sites like Facebook data, so is your home town, where you went to school, when you graduated, your birth date, address and telephone number as well as names and birth dates of family members.  If this information is public, it is the very information that identity thieves can use.

What about your smart phone?  Do you check in at every location as you go about your daily travels and share it on Twitter or Facebook?  Do you announce and document business or family trips?

Information stored on your computer or shared on social networking sites includes data that needs to be safeguarded to protect your privacy.

Safeguarding Data

The message about having an up-to-date antivirus software and firewall has been well received by home computer users.  When helping with malware removal, it is has been a very long time since I have seen a computer without antivirus software and a firewall.  Computer users are also getting much more conscientious about installing security updates and keeping third-party software updated.

This is all good news, but malware writers are very clever and manage to find a way to infect computers.  In addition to the standard antivirus, firewall, updating what else can you do to safeguard your data?

In addition to keeping your computer and software programs updated, following are a some general suggestions for protecting the data on your computer:
  1. Protect your wireless router with a password.
  2. Don't open e-mail, instant message or Facebook attachments you are not expecting.
  3. Do not click anywhere on a pop-up or warning from a program you did not install.  Use the keyboard shortcut Alt + F4 to close the window.
  4. Pay close attention when installing software.  Do not blindly click through the screens or you may end up with more than you expected.
  5. Whenever possible, only download software programs from the vendor site.  Keep in mind that free is not always free.
  6. Always scan any file you download from the Internet.
  7. Have a back-up plan in place, particularly for documents, pictures and other files that cannot be replaced. 
  8. Use a complex password, not a "dictionary word" or family name.
What about safeguarding the data you share on social networking sites like Facebook?  

Facebook makes it easy to connect and share information with friends and family.  However, it is critical to ensure that you are not openly sharing personal information that could make you a target of identity theft. 

See this excellent guide by Sophos, Facebook Security Best Practice, which not only covers information and setting recommendations but also explains the reasoning for the recommendations. 

Another resource that is helpful for Facebook users is Facecrooks, a source for not only privacy information but also the latest hoaxes that regularly circulate on Facebook.

A few easy steps will keep both the data on your computer as well as the information you share both secure and private.



Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Wednesday, January 25, 2012

Data Privacy Day 2012

Data Privacy Day is an annual international celebration designed to promote awareness about privacy and education about best privacy practices.

The 2012 international celebration of Data Privacy Day is scheduled for January 28. 


Why the concern about privacy?


What may begin as a casual Facebook update or an innocuous tweet could easily come back to haunt you down the road.  Unlike writing something on the bathroom wall, which can be easily painted over, what we do online is permanent.  This includes status updates or comments on a friend's wall in Facebook, tweets, e-mail and online chats.

All of these on-line activities contribute to your online reputation -- a reputation that can impact being accepted to the college or university of your choice or a future employment opportunity.

Disclosing too much information online can also lead to identity theft, resulting in the loss of personal data, such as passwords, user names, banking information, or credit card numbers.

Protect Your Privacy

Take steps now to protect your privacy.  

Don't share too much personal information online.  Having your date of birth, address, where you went to school, mother's maiden name, and other personal information available to the public is the first step to identity theft.

The public does not need to know every location you "check-in" to via your smart phone and neither do the burglars! 

Take advantage of the enhanced security and privacy features available in the browser you use.  (See my article, Internet Explorer 9, Privacy and Security Enhancements, for tips on protecting your privacy and security.) 

Use caution accepting friend requests in social media venues such as Facebook.  Just because someone sends a friend request, it is not necessary to accept it.  Be certain the person is someone known to you.

Parents need to monitor the online activities of their children.

Resources

Take advantage of the helpful resources below which include information on privacy settings for Microsoft products and excellent advice from Sophos on Facebook privacy.

Related:  Data Privacy



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Tuesday, May 10, 2011

Facebook User Credentials Exposed

Regardless of the numerous guides to Facebook members on maintaining privacy, caution is thrown to the wind when yet a new Farm-ish game, a cause to support or some other enticing Facebook application comes along.

Unfortunately, it has been discovered by Symantec that in certain cases, Facebook IFRAME applications have inadvertently leaked access tokens to third parties.  According to the analysis completed by Symantec, as of last month there were almost 100,000 applications enabling the leakage of access tokens. 

The referenced "access token" leakage means that the keys containing permissions; such as, accessing your friend's list, posting on your wall, and seeing any personal information you allowed the application have likely been provided to advertisers or analytic programs.

According to the Facebook Developer Blog, steps are being taken to transition Facebook applications from the old Facebook authentication system and HTTP to OAuth 2.0.  (OAuth 2.0 is a process of providing third-party applications limited access and HTTPS.)

Recommendations

  1. Change your Facebook password since this step automatically clears all previously issued access tokens.
  2. Turn on Security Browsing (HTTPS):
  • Navigate to your Account Settings page. 
  • Click the "Change" link next to Account Security
  • Check the box under "Secure Browsing (https)" and then click the "Save" button.

References



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, January 27, 2011

Data Privacy

Data Privacy Day is "an international celebration of the dignity of the individual expressed through personal information."

There is no doubt that we have evolved into a digital society. Whether it is via a traditional laptop or desktop computer or a mobile device, we are seldom far from being connected to the Internet.

Computers surround our everyday lives. When we make a credit card purchase, the information is transmitted over the Internet.  Computers are an integral part of the airline reservation services we use to schedule a family holiday.  If we need to contact our local police or fire department, they access directions to our home via a computer.

Much of our personal information is stored on computers.  The information contained in our medical, insurance, pharmacy, employment and school records, bank and credit reports, tax and government data provide not only a story of our life but also a key to our identity. 

There is more to online privacy than personal records.  Consider the following activities:
  • Information searches
  • Browsing online for products and services
  • Information shared with friends on social networking sites
  • Travel and location information with location-enabled Smartphone applications

As any of the above online activities are conducted, information is stored on your computer. This information is potentially available for data collection and manipulation, resulting in targeted advertisements. Advertisements are a “necessary evil”. Maintaining websites is not cost free.  Thus, the need for the subsidy provided website owners by advertisers. Although many free and licensed applications and browser add-ons have been created to block or remove what is commonly referred to as tracking cookies, other means of tracking website visits have evolved.


The Future

Particularly due to a year-long study by the Federal Trade Commission (FTC), a lot of attention has been devoted to online privacy. On December 1, 2010, the FTC released a preliminary report entitled "Protecting Consumer Privacy in an Era of Rapid Change". The one hundred twenty-two (122) page PDF file is available for download at http://www.ftc.gov/os/2010/12/101201privacyreport.pdf ). Briefly, the FTC report provides a broad framework centered on three concepts: privacy by design, simplified choice, and greater transparency.

Within days of the FTC report, the Microsoft Internet Explorer 9 team announced tracking protection for inclusion in the Internet Explorer 9 Release Candidate. Both privacy advocates and consumers alike will see this as a major step forward to providing additional online privacy.

IE9 and Privacy: Introducing Tracking Protection
  • Opt-in “Tracking Protection” to identify and block many forms of undesired tracking.
  • “Tracking Protection Lists” to enable control of the third-party site content that can be tracked when online.

clip_image001With Tracking Protection in Internet Explorer 9 (IE9), you will have control of what data is shared as you navigate from one website to another.  This is accomplished by adding Tracking Protection Lists (TPL) to Internet Explorer. Anyone, and any organization, on the Web can create and publish Tracking Protection Lists. 

Although the default installation of IE9 will not include Tracking Protection lists (TPL), the option will be available to add lists created by others.  In effect, the lists provide a “Do Not Call” indicator for external content, unless you visit those sites directly. The TPL will also include the ability to include “OK to Call” addresses.  This is to ensure you can access these sites even if one of their lists has the site identified as “Do Not Call.”  Tracking Protection is not on by default. Thus, after turning on Tracking Protection, it will remain on until you turn it off.

The process of change is not simple.  Realize that it will be ongoing.  As a postscript to the IE Blog article, IE9 and Privacy: Introducing Tracking Protection Dean Hachamovitch, Corporate Vice President, Internet Explorer, added:
"One aspect of the larger tracking discussion involves a change to “HTTP headers.” The key thing to note is that such a change is the start but only part of delivering tracking protection. It is a signal to the web site of the consumer’s preferences. The rest of that solution (defining what that signal from the consumer means, what to do with it, verification, enforcement, etc.) is still under construction."
Mozilla Firefox "Do Not Track"


Last week, Mozilla announced “Do Not Track”.  The concept is to provide a way for people to opt-out of online behavioral advertising (OBA) by transmitting a Do Not Track HTTP header every time their data is requested from the Web. This header will notify the website that the visitor wants to opt-out of third-party tracking for behavioral advertising.  When the feature is enabled, advertising networks will be told by Firefox that the user has asked to opt-out of behavioral advertising.

As indicated in the Mozilla announcement, the "initial proposal does not represent a complete solution" but rather is one step to see if the header approach can work.  The goal is to provide a more nuanced, persistent tool for communicating privacy choices on the web.  Do Not Track (DNT) is expected to be introduced in version 4.1.

More information is available in the MozillaWiki FAQ: Privacy/Jan2011 DoNotTrack FAQ


Today

The Internet Explorer 9 tracking protection will provide a viable option for protecting your privacy. I expect that the other browsers will provide similar methods of providing tracking protection in future releases. In the meantime, there are other options available for protecting your privacy. In the following segments are instructions for restricting tracking cookies as well as examples of options and a few of the available browser extensions for managing DOM Storage and Flash Cookies. Also included are browser settings for private browsing sessions.

Cookies


There are considerations when blocking cookies.  Keep in mind that not all cookies are tracking your every move.  As a simple example, website logon cookies remember pages read. Also, note that cookies cannot be used to run code (run programs) or to deliver viruses to your computer.

Session Cookies
are also useful. Some websites require session cookies to track your movements on the site. Without the session cookies, you would repeatedly be asked for the same information already provided.  As an example, session cookies are used when shopping online to remember items placed in a shopping cart.  Without the session cookies, the shopping basket would disappear before you reach the checkout.  Session cookies are stored in memory not on the hard drive. They expire when the browser is closed.

Third-party Cookies
are cookies that are set by one site, but can be read by another site.  This enables advertisers that use third-party cookies to track your visits to the websites on which they advertise. With third-party cookies, your web surfing habits are logged, allowing advertisers to tailor advertisements to your interests.

What if you do not want to be tracked?


The Network Advertising Initiative (NAI) provides a system for opting out of popular ad networks. The Network Advertising Initiative tool identifies the member companies that have placed an advertising cookie on your computer. Using the NAI tool is simple. Merely choose the provided option to Select All member companies or check specific boxes that correspond to the company(s) from which you wish to opt out. After you click the Submit button, the tool will automatically replace the selected advertising cookie(s) and verify your opt-out status.

TrackBlocker
is a Firefox extension provided by PrivacyChoice.org. The extension not only blocks cookie tracking by over 200 ad companies it also deletes Flash cookies from these companies.
Most web browsers have a feature in their settings that lets you disable cookies from third-party websites. Shown below are the instructions for the setting to block tracking cookies for the major web browsers.

To block third-party cookies in Internet Explorer, do the following steps:
  • Launch Internet Explorer and select the Tools menu
  • Click Internet Options, click Privacy, and then click Advanced.
  • Check the box next to Override automatic cookie handling
  • Check the option to Block in the Third-party Cookies column.
  • Click OK.
clip_image002

Firefox
also has the option to block third-party cookies.  The steps include:
  • Launch Firefox and click the Tools menu
  • Select Options and Privacy
  • Uncheck the option to Accept third-party cookies.
clip_image003

Google Chrome
allows all cookies by default.  Below are the steps for changing the default settings:
  • Launch Google Chrome and click the Tools menu
  • Select Options.
  • Click the Under the Bonnet tab and locate the Privacy section
  • Choose the Content settings button.
  • Click the Cookie settings tab and choose your preferred settings.
  • Click Close.
clip_image004

Google Chrome now also has available the recently announced Keep My Opt-Outs.  The extension provides users to out of cookies that are related to personalized online ads. Note, however, that a small percentage of personalized ads also come from companies who do not yet participate in self-regulatory efforts. Thus, do not expect perfection.

Safari has similar instructions as the other browsers:
  • Launch Safari and go to Preferences and then click the Security tab
  • Click the Show Cookies button
  • Click the radio button for the option Only from sites I visit (Block cookies from third parties and advertisers).

The terminology used by Opera is similar to Safari.
  • Launch Opera and press CTRL+F12 to open the Opera Preferences menu.
  • Select the Advanced Tab
  • Select Cookies from the left sidebar menu.
  • Select Accept cookies only from the site I visit to disable third-party cookies.
clip_image005

Opera also has the option to disable “referrer logging”, which allows a website to know what site you were previously visiting. Some sites depend on referrer logging to work correctly. If you elect to disable referrer logging in Opera, it can be done through Settings > Preferences > Advanced > Network. Uncheck Send referrer information.

DOM Storage


Although we generally associate the term cookie with data stored by websites we visit, DOM Storage does not store cookies per se. Rather, DOM storage is per-session or domain-specific data. It is easier to control how information stored in one window is visible to another with DOM Storage. (According to W3C, officially, the term is Web Storage but the common term is DOM for Document Object Model.)

DOM Storage is comprised of two primary parts, Session Storage and Local Storage. In Session Storage, any data input is stored for the duration of the session. Thus, if a new tab is opened, the data from the Session in the original tab is stored for the new tab. Conversely, Local Storage spans multiple windows and persists beyond the current session. Local Storage allows Web applications to store up to 10 MB of user data. This could include data stored offline for later reading.

Disable DOM Storage

It is easy to disable DOM storage cookies in both Internet Explorer and Firefox browsers by following the simple instructions below. It is important to note, however, that some sites (i.e., CNN) may not work correctly with DOM storage disabled.

Internet Explorer
  • Launch Internet Explorer and open the Tools Menu
  • Select Internet Options
  • Click the Advanced tab
  • Scroll down until you reach Security
  • Uncheck the box for Enable DOM Storage
  • Click Ok

Firefox


A simple way to disable DOM Storage in Firefox is with the extension, Better Privacy. To make the change manually, do the following:
  • Launch Firefox and type about:config in the address bar
  • In response to the warning, click I'll be careful, I promise!
  • Scroll down until you reach dom.storage.enabled or copy/paste dom.storage.enabled in the filter
  • Double-click the dom.storage.enabled line item and it will change from its default value True to False
  • Close the about:config tab

To undo the change to Internet Explorer or Firefox, simply reverse the above steps.

Recently, Google NotScripts extension was released. It is currently necessary to create a password when using the extension and also make other settings changes back to default. The Opera and Safari browsers use DOM storage but, at this point, it does not appear that either provides a means for disabling it.

Flash Cookies


Blocking all or just third-party cookies and clearing browser history does not remove another form of cookies -- Flash cookies. Flash cookies are also known as local shared objects (LSO) or Super Cookies. Because Flash cookies are not as well known as HTTP cookies, they provide the additional advantage for advertisers for tracking and providing targeted advertising. As a result, Flash cookies also jeopardize your online privacy. The same advantages of Flash cookies over HTTP cookies for advertisers are disadvantageous in maintaining privacy.

A partial list of Flash Cookie/LSO properties includes:
  • Unlike HTTP cookies, Flash Cookies are never expiring
  • HTTP cookies are 4 KB, compared to the default storage availability of 100 KB of storage for LSO’s.
  • Browsers provide control mechanisms for HTTP Cookies, which is not generally the case for LSO's.
  • Highly specific personal and technical information (including system and user name) can be stored via Flash.
  • The stored information can be sent to the appropriate server without permission.
  • There is no easy way to monitor sites following you with flash-cookies.
  • LSO’s work in every flash-enabled application, thus allowing cross-browser tracking via the shared folders.

Considering the complexity of Flash Cookies, the question in your mind most likely is how to control or remove them from your computer. Below are few options for consideration.

clip_image006Adobe provides an On-line Settings Manager, illustrated below, to configure Flash Player settings. To use the tool, you need to go to the Adobe Website Storage Settings panel to make the changes to the settings. Although the changes are made via the on-line manager, the settings are only stored on your computer. I have discovered that the Adobe On-line Settings Manager version has changed several times. As a result, it has been necessary after a Flash Player update to revisit the site to verify the settings.


For on-line game players, note that Flash cookies are used to save a game in progress. In that case, you will want to add an exception to the on-line game site.

The Taco plug-in is available for both Internet Explorer and Firefox. It helps manage and delete standard cookies as well as Flash and DOM Storage Cookies. The plug-in also lets you see who is trying to follow your online movements and helps you decline targeted ads from more than 100 ad networks.
Firefox users have the option of using the BetterPrivacy or Flashblock extension.

Flashblock blocks all Flash content from loading. It then leaves placeholders on the webpage. With that method, if you wish to view the Flash content, you can click to download and then view it.
The BetterPrivacy extension manages Flash Cookies by removing them on every browser exit. It also provides the capability of reviewing, protecting or deleting new Flash-cookies individually. If desired, the automatic functions can be disabled. BetterPrivacy also protects against the previously discussed DOM Storage.

Private Browsing


Private browsing options are available for occasions when you do not want to leave evidence of your browsing or search history. When surfing at an Internet Café or unsecured Wi-Fi location this feature is recommended to protect not only your privacy but also security should it be necessary to access a banking or similar secure site.


Internet Explorer
Internet Explorer 8 and Internet Explorer 9 provide several easy ways to start InPrivate Browsing. The feature is available from the Safety menu, by pressing CTRL+Shift+P, or from the New Tab page. Any of those actions will result in launching a new browser session that will not record any information, including searches or website visits. Closing the browser window will end the InPrivate Browsing session.
Note: InPrivate Browsing is not available in earlier versions of Internet Explorer.

Firefox


To access Private Browsing in Firefox, click on the Tools menu and select Start Private Browsing or key CTRL+Shift+P. To end Private Browsing, reverse the process by clicking on the Tools menu and selecting Stop Private Browsing.

Google Chrome

Private browsing in Google Chrome is called Incognito mode. To turn on Incognito mode, from the Tools menu, select New incognito window or key CTRL+SHIFT+N. To stop browsing in Incognito mode, close the Chrome window.

Opera

Opera provides the option of launching either a private tab or window. Any new tab opened in a private window is a Private Tab. Browsing history is removed when the tab or window is closed. Click the red O in the upper, left corner and select Tabs and Windows | New Private Tab or Tabs and Windows | New Private Window. This feature is also available from the File menu on the menu bar.

Finally

clip_image007 It is apparent that there is a long way to go toward online privacy before the tenants proposed in the FTA draft report are accomplished.  Internet Explorer 9 is taking a step forward in design with tracking protection as is Mozilla Firefox.  I anticipate that the other browsers will follow with something similar. A simplified choice and an easier method of changing the settings is needed. Beyond that, and more importantly, a clear understanding of the information advertisers are collecting is needed in order to make informed decisions about what information to allow or block.



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Tuesday, January 25, 2011

Facebook Privacy "Instant Personalization"

You may not realize information you are sharing from Facebook when you visit current partner sites Bing, TripAdvisor, Clicker, Rotten Tomatoes, Docs, Pandora, Yelp, and Scribd.  The information includes your name, profile picture, gender, networks, and other information shared with everyone.  The concept is to provide a "personalized experience" at the partner sites; i.e., results targeted at public information in Facebook.

Facebook assures members that with "instant personalization"
  • Participating sites will provide a notification and a way to turn off the customized experience in one click.
  • Your information can only be used to present you with a more personalized experience and cannot be transferred to advertisers or used for any other purposes.
What happens when you allow "instant personalization"?  According to the Facebook description, you will see your Facebook friends reviews (favorites) first when you search for a movie or your favorite songs will play automatically when you visit a music site.  I don't consider that "personalization" but rather an invasion of privacy. 

To check the settings for instant personalization, do the following:
  • When logged on to Facebook, click Account then click Privacy Settings.  
  • Under Apps and Websites, click the "Edit your settings" link.
  • Go down the list to Instant personalization and click the Edit Settings button.
  

  • Don't be surprised when presented with a video telling you about the Instant personalization features.  To access the page, click the close button on the video:

  • After closing the video, the option to manage the Instant personalization setting is at the bottom of the page.  The box next to Enable instant personalization on partner websites. should be UNchecked

Facebook Information:


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, December 27, 2010

Facebook Privacy Warning

A notice is showing up for Facebook users to update security settings for "Account Protection".  The options are provided to make it easier to log back in to Facebook in the event there is a problem with your account.  The first provided option is to provide a secondary e-mail address.  The second option includes providing your Mobile number to achieve "High" account control. 

Unfortunately, caution is needed in both instances to prevent forfeiting privacy.  Added alternate e-mail address(es) have a default setting of "Friends Only".  If you elect to add your mobile number, there is a pre-checked option to add the number to your Facebook profile.  Instructions for customizing the information shared is in the "Privacy Settings" section below.

Information on the notice, steps to add the information and recommendations are provided below.

Notice



The "Account Protection" notice appears in the right column.  The status changes from Low to Medium after adding an alternate e-mail address. 







Step 1

Multiple alternate e-mail addresses can be added.  

Each added address will receive a "Facebook Contact Email Confirmation" with a link to confirm the alternate address.


WARNING:  If you restrict access or do not share your e-mail address with others in Facebook or have customized settings, it is necessary to update the settings for any added e-mail address(es).  See the instructions below under "Privacy Settings"
 
After confirming any added alternate e-mail addresses, clicking the question mark (?) on the update screen explains how you can achieve "High" security:



Step 2

When you select the option under Mobile Phone to "Sign up for Facebook mobile" and reach "High" Account Control, the instructions are to select country and mobile carrier and then enter the code received after sending a text message to FBOOK from the mobile number.

Unfortunately, this is where caution is needed.  The option to add the phone number to your Facebook profile is pre-checked:

 WARNING: "Add this phone number to my profile" is pre-checked.

If you do not have your that information blocked in your profile, unless the option is unchecked, depending on your privacy settings, you will be providing your mobile number to anyone who has access to your profile information. 

Personally, considering the frequent manner in which Facebook changes settings, I prefer not to include that information in Facebook.  However, in the event you elect to include your mobile number, you can control who has access to that and other personal information.

Privacy Settings


To edit your Privacy Settings, select Account > Privacy Settings. 



In the "Choose Your Privacy Settings" window that opens, select Customize settings.  From there you can change the options as to who has access to your contact information.  The options include Everyone, Friends of Friends, Friends and Customize (edit).  




Although I have not provided my Mobile phone, I kept the "Only Me" setting.  If you opt to customize that setting, you can make selected information visible to specific people on your friends list by individually adding their name(s).  Information can also be hidden from specific individuals by adding the name(s) in the bottom section:



If you have not seen the "Account Protection" notice and wish to go ahead and add a backup e-mail address and/or mobile number, the steps are available at http://www.facebook.com/update_security_info.php.  Just be careful that you are not sharing more information than you want available.


Clubhouse Tags: Clubhouse, Security, Privacy, How-To, Information, Tutorial, Family Safety,



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, August 23, 2010

How to Disable DOM Storage "Cookies"

Many people are fanatic about managing the cookies stored on their computer to the extent of clearing the browsing history following each session. DOM Storage does not store "cookies" per se, but rather per-session or domain-specific data, the term cookie is generally associated by consumers with data stored by websites visited.

As described in the MSDN Library article, Introduction to DOM Storage:
"DOM Storage is often compared to HTTP cookies. Like cookies, Web developers can store per-session or domain-specific data as name/value pairs on the client using DOM Storage. However, unlike cookies, DOM Storage makes it easier to control how information stored by one window is visible to another."
DOM Storage is comprised of two primary parts

In Session Storage, any data input is stored for the duration of the session. Thus, if a new tab is opened, the data from the Session in the original tab is stored for the new tab.

Local Storage, spans multiple windows and persists beyond the current session. Local Storage allows Web applications to store up to 10 MB of user data. This could include data stored offline for later reading.

The referenced MSDN Library article provides examples more detailed information of both Session Storage and Local Storage.

Disable DOM Storage

It is easy to disable DOM storage "cookies" by following the simple instructions I obtained from Fred de Vries.

Internet Explorer
  • Launch Internet Explorer 8 and open the Tools Menu
  • Select 'Internet Options'
  • Click the 'Advanced' tab
  • Scroll down until you reach ‘Security’
  • Uncheck ‘Enable DOM Storage’
  • Click 'Ok'

Mozila Firefox
  • Launch Firefox and type about:config in the address bar
  • Click "I'll be careful, I promise!" to the warning
  • Scroll down until you reach ‘dom.storage.enabled’ or copy/paste dom.storage.enabled in the filter
  • Double-click the line item and it will change from its default value ‘True’ to ‘False’
  • Close the about:config tab
To undo the change, simply reverse the above steps.


References:

, Privacy, Information



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...