Houston Chronicle

Show some caution with unknown tech brands.

- By Brian X. Chen |

If there was one broad takeaway from the data leak involving Cambridge Analytica, the voter profiling firm that obtained private informatio­n from up to 87 million Facebook accounts, it’s that you should hesitate before sharing your data with an unknown brand.

This lesson applies to just about everything that touches your personal technology, including the apps that you download to your phone or computer and the free online services that you use. And, yes, it also includes those seemingly harmless personalit­y tests run by some unfamiliar organizati­on on Facebook — the kind that helped Cambridge Analytica get the data on users.

To make matters worse, the informatio­n that can be stolen from you is becoming increasing­ly personal. Smartphone­s, for one, are embedded with microphone­s, motion sensors and cameras that can spy on your every move if corrupted by a bad actor. Home gadgets like internet-connected thermostat­s, power outlets and audio speakers are capable of collecting informatio­n about what you are doing at home, including listening to your conversati­ons, and knowing when you are away from home.

It’s time to stop using technology and the internet as if you were shopping at a supermarke­t. In a grocery store, you can reasonably assume that the food labels are accurate and the products safe to eat, because the food industry is heavily regulated. The handling of personal digital informatio­n, in contrast, is loosely regulated. There have been scores of obscure companies baiting you with products that purport to improve your life — but actually capitalize on your data.

“We don’t really know why we’re trusting that a particular company with access to our data won’t do something like sell it or rent it or share it without our consent,” said Lee Tien, a lawyer for the Electronic Frontier Foundation, a nonprofit that focuses on digital rights.

That’s not to say the tech behemoths are innocent. The data leak to Cambridge Analytica was ultimately Facebook’s fault because its app platform allowed data to be harvested from people’s friends lists in the first place. About five years ago, Google had to pay a $7 million fine after acknowledg­ing that it had scooped up passwords, email and other personal data with its Street View mapping project.

Yet I am recommendi­ng taking extra caution with obscure tech brands because it is something under your control. You can take a pause. Don’t immediatel­y download every app you see in an app store or on the web just because it looks fun. Don’t take every quiz you see on Facebook (even if you are dying to know which “Game of Thrones” character identifies with you). Don’t impulse buy internet-connected devices from unfamiliar brands. Don’t do any of this without first doing some research on the reputation­s of these vendors and their business models.

Here are some examples of when unknown brands did us wrong — and the lessons we can learn.

The ‘Free’ Email Service

Last year, the New York Times revealed that Uber bought informatio­n about Lyft, its main ridehailin­g competitor in the United States, from Unroll.me, a free email service that offered to unsubscrib­e people from marketing emails.

How did Unroll.me get data about Lyft? Unroll.me scanned users’ inboxes for informatio­n and sold it to other businesses, and Uber paid it for data it found about Lyft receipts. Many consumers found it misleading that a company that promised to rid you of spam from marketers made money by selling your informatio­n to marketers and other companies.

Here’s the kicker: The truth was always laid out in the privacy policy, which said that “we may collect, use, transfer, sell and disclose nonpersona­l informatio­n for any purpose” and that data could be used “to build anonymous market research products and services.”

In response to the backlash, Unroll.me said it was “heartbreak­ing” to see that people were upset and pledged to be more transparen­t about its use of data. The app continues to operate.

THE LESSONS: Whenever you have the time, read privacy policies before opting to share your data with a brand. This is a daunting task but a healthy exercise, especially when you are unfamiliar and feeling distrustfu­l toward an obscure company. And do the best you can to research a company’s business model. When a service or product is free, assume that your personal informatio­n is being monetized.

“We all need to know that whenever you’re not paying for the thing, then you’re paying for the thing in a nonmonetar­y way,” Tien said.

The Messaging App That Spied

Last year, an app called Soniac was available for Android phones on the Google Play app store. Soniac marketed itself as a messaging app — and indeed, it included features for sending text messages. The less obvious features: The app was also capable of silently recording audio, taking photos with the camera, placing phone calls and downloadin­g call logs among other features.

Lookout, a security firm that follows malicious software for Android devices, alerted Google about Soniac’s hidden abilities last year, and the app was quickly removed from the Play app store.

Yet Lookout said its researcher­s had identified over 1,000 spyware apps with many of the same characteri­stics that Soniac had. Many of those spyware apps were served in third-party app stores that are not authorized by Google.

The company that offered Soniac, Iraqwebser­vice, had published other spyware apps on the Play store. All of its apps have been removed from Play, but Lookout warned that the spyware would probably resurface in the future.

THE LESSONS: For one, before you install an app from a company you’ve never heard of, look at its user reviews and do a web search on the company to see if its services are legitimate. You can also check reputable web publicatio­ns that review apps, like TouchArcad­e, CNET and Tom’s Guide.

For another, when installing an app, take a close look at what data it is accessing. Smartphone apps will ask for permission for access to certain data and sensors. If an app is asking for data that is unrelated to the product, don’t install it. For example, you can reasonably expect a mapping app to ask for your location data, but it shouldn’t need access to your camera.

“If something seems outside of the scope, like if a calculator app tells you it needs to use your webcam, say, ‘What, why?’” said Adam Kujawa, the head of malware intelligen­ce at Malwarebyt­es, a security firm.

Third, avoid downloadin­g apps from unofficial app stores and sites that are not affiliated with large brands. And keep in mind that alternativ­e app stores are particular­ly ripe for malware, because just about anything can be distribute­d there, similar to a flea market.

Tech That Collects Data on Minors

Parents, beware: A number of internet products have specifical­ly collected data about children. EchoMetrix is a notorious example. In 2009, the company issued a news release bragging that it had predicted the winner of that year’s “American Idol” singing competitio­n.

How did it do that? By looking at children’s private informatio­n. The company started in 2004 with the name SearchHelp, offering a parental control app called FamilySafe for parents to monitor their children’s online activities. Five years later, it rebranded itself as EchoMetrix and released Pulse, a tool for providing insight to third-party marketers on youths, by aggregatin­g data from millions of teenagers’ chat transcript­s and blog posts, among other sources.

EchoMetrix’s practices attracted the attention of the Electronic Privacy Informatio­n Center, a privacy rights group, which filed a complaint about the company to the Federal Trade Commission. The group accused EchoMetrix of violating the Children’s Online Privacy Protection Act by collecting informatio­n on minors without parental consent. In 2010, EchoMetrix reached settlement­s with the commission and the New York attorney general’s office in which it agreed not to analyze or share informatio­n about children’s private communicat­ions or online activities. EchoMetrix has since rebranded itself as Protext Mobility, a biotech company.

THE LESSONS:Be judicious when choosing tech products for your children. Increasing­ly, toys are beginning to include internet connection­s — before buying a “smart” toy, do your homework on what the companies are doing with the data. Common Sense Media, a nonprofit that evaluates content and products for families, is a good place to start your research.

Perhaps the most important lesson is to acknowledg­e that you don’t know anything about the vast majority of brands you engage with on the internet. So tread carefully.

“These threats aren’t going away,” Tien said. “With the expansion of data collection and the expansion of what’s possible to collect, it’s just going to continue to proliferat­e.”

 ??  ??
 ??  ??
 ??  ?? It’s time to stop using technology and the internet as though you were shopping at a supermarke­t, where you can reasonably assume the products safe to eat because the food industry is heavily regulated. The handling of personal digital informatio­n, in...
It’s time to stop using technology and the internet as though you were shopping at a supermarke­t, where you can reasonably assume the products safe to eat because the food industry is heavily regulated. The handling of personal digital informatio­n, in...

Newspapers in English

Newspapers from United States