Gulf News

How data breach can track you down

‘Stravagate’ shows that the confidenti­ality of informatio­n is a public good that cannot be regulated by millions of individual choices

-

id you make a New Year’s resolution to exercise more? Perhaps you downloaded a fitness app to help track your workouts, maybe one that allows you to share that data online with your exercise buddies?

If so, you probably checked a box to accept the app’s privacy policy. For most apps, the default setting is to share data with at least the company; for many apps the default is to share data with the public. But you probably didn’t even notice or care. After all, what do you have to hide?

For users of the exercise app Strava, the answer turns out to be a lot more than they realised. Since November, Strava has featured a global “heat map” showing where its users jogged or walked or otherwise travelled while the app was on. The map includes some three trillion GPS data points, covering more than 5 per cent of the earth. Over the weekend, a number of security analysts showed that because many American military service members are Strava users, the map inadverten­tly reveals the locations of military bases and the movements of their personnel.

Perhaps more alarming for the military, similar patterns of movement appear to possibly identify stations or airstrips in locations where the United States is not known to have such operations, as well as their supply and logistics routes. Analysts noted that with Strava’s interface, it is relatively easy to identify the movements of individual soldiers not just abroad, but also when they are back at home, especially if combined with other public or social media data.

Apart from chastening the cybersecur­ity experts in the Pentagon, the Strava debacle underscore­s a crucial misconcept­ion at the heart of the system of privacy protection in the US. The privacy of data cannot be managed person-by-person through a system of individual­ised informed consent. Data privacy is not like a consumer good, where you click “I accept” and all is well. Data privacy is more like air quality or safe drinking water, a public good that cannot be effectivel­y regulated by trusting in the wisdom of millions of individual choices. A more collective response is needed.

Part of the problem with the ideal of individual­ised informed consent is that it assumes companies have the ability to inform us about the risks we are consenting to. They don’t. Strava surely did not intend to reveal the GPS coordinate­s of a possible Central Intelligen­ce Agency annex in Mogadishu, Somalia — but it may have done just that. Even if all technology companies meant well and acted in good faith, they would not be in a position to let you know what exactly you were signing up for.

Dangers of machine learning

Another part of the problem is the increasing­ly powerful computatio­nal methods called machine learning, which can take seemingly inconseque­ntial data about you and, combining them with other data, can discover facts about you that you never intended to reveal. For example, research shows that data as minor as your Facebook “likes” can be used to infer your sexual orientatio­n, whether you use addictive substances, your race and your views on many political issues. This kind of computatio­nal statistica­l inference is not 100 per cent accurate, but it can be fairly close.

What can be done? There must be strict controls and regulation­s concerning how all the data about us — not just the obviously sensitive bits — is collected, stored and sold. With the implicatio­ns of our current data practices unknown, and with future uses of our data unknowable, data storage must move from being the default procedure to a step that is taken only when it is of demonstrab­le benefit to the user, with explicit consent and with clear warnings about what the company does and does not know. And there should also be significan­t penalties for data breaches.

Companies often argue that privacy is what we sacrifice for the supercompu­ters in our pockets and their highly personalis­ed services. This is not true. While a perfect system with no trade-offs may not exist, there are technologi­cal avenues that remain underexplo­red, or even actively resisted by big companies, that could allow many of the advantages of the digital world without this kind of senseless assault on our privacy.

With luck, stricter regulation­s and a true consumer backlash will force our technologi­cal overlords to take this issue seriously and let us take back what should be ours: True and meaningful informed consent, and the right to be let alone. Zeynep Tufekci, an associate professor at the School of Informatio­n and Library Science at the University of North Carolina.

www.gulfnews.com/opinions

Newspapers in English

Newspapers from United Arab Emirates