Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Friday, January 31, 2025

Understanding DeepSeek's AI Breakthrough: 5 Videos to Get You Up to Speed!

With the seismic impact of DeepSeek on AI, the stock market, and geopolitics, we wanted to follow-up our previous post with a deeper exploration of the topic. In this post, we found 5 videos that will help you get up to speed on the unfolding drama.  

Vid1: CNBC Covers the Ensuing Market Meltdown

CNBC discusses the impact of China's new AI model, DeepSeek, on the global tech industry. DeepSeek's superior efficiency and performance, even surpassing some American models, is causing a major sell-off in AI-related stocks, particularly impacting companies like Nvidia. The video explores concerns about DeepSeek's potential access to advanced technology and the implications for US technological dominance. The discussion also touches upon the shift towards open-source AI models and the uncertainty surrounding future investments in AI development. Finally, the video highlights the rapid advancement of AI technology and its potential societal impact, comparing the situation to the Sputnik moment of the space race.

Vid2: AI Enthusiast, Matt Wolfe, Gives His Take

Matt Wolfe, who closely follows the AI space, discusses DeepSeek R1, a new Chinese open-source AI model that has caused significant market reactions. DeepSeek's impressive performance, achieved with significantly less computing power than comparable models like GPT-4, is attributed to its efficient training methods and innovative design. Controversy surrounds DeepSeek's claims regarding its resource usage, with some suggesting the company downplayed the actual computational resources employed. Despite this, the video argues the model's impact may be positive, possibly lowering the barrier to entry for AI development and increasing overall demand for GPUs. The video also covers DeepSeek's image generation model, Janice Pro 7B, and provides instructions on how to access and utilize DeepSeek.

Vid3: A Geopolitical Perspective on the DeepSeek Saga

Here is Cold Fusion’s take on the DeepSeek story. He discusses the sudden emergence of DeepSeek R1, a free, open-source Chinese AI model that rivals—and in some ways surpasses—leading American AI models. Its unexpectedly low development cost and superior efficiency have sent shockwaves through the US stock market and prompted a reassessment of AI development strategies. Concerns about intellectual property theft are raised, alongside geopolitical implications of this technological advancement. The narrative explores the innovative techniques behind DeepSeek R1's performance and the competitive landscape it has created, highlighting the resulting cost reductions and potential for rapid AI progress globally.

Vid4: If you are using DeepSeek, Your Data is Going to China!

Skill Leap AI discusses serious privacy concerns regarding the DeepSeek website and app, highlighting issues like vague data retention policies, data storage in China raising compliance issues with international laws, lack of transparency in data usage, and insufficient age verification. The creator outlines these issues after reviewing the platform's privacy policy and terms of service using ChatGPT. To mitigate these risks, the video suggests using locally installed versions of DeepSeek R1 or utilizing DeepSeek's integration within the PerplexityAI search engine, a US-based service. Finally, the video promises a future comparison of DeepSeek R1 and ChatGPT's 01 model.

Vid5: A Video Walkthrough of Dario Amodei's take on DeepSeek's Capabilities

In this video, Matt Berman takes a look at Dario Amodei's take on the DeepSeek saga. Amodei, the current CEO of OpenAI’s chief rival Anthropic, wrote an essay discussing the implications of DeepSeek's AI model, R1, particularly concerning its potential data acquisition from OpenAI and the resulting impact on the AI industry and geopolitical landscape. The essay analyzes the three key dynamics of AI development: scaling laws, the shifting curve, and paradigm shifts, emphasizing the escalating costs and exponential advancements in AI capabilities. Concerns about China's access to advanced GPUs and their potential to achieve artificial general intelligence (AGI) are also highlighted, underscoring the importance of export controls. Finally, the essay argues that DeepSeek's cost-effective model, while impressive, does not represent a fundamental shift in AI economics and that the market's overreaction was unwarranted.

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a Sr. AI Product Manager who is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else. This post was written with the assistance of an AI language model. The model provided suggestions and completions to help me write, but the final content and opinions are my own.


Monday, March 11, 2024

Five Top Tech Takeaways: Google Faces an Unexpected AI Competitor, AI Overreach at Work, Sam's Back, SEC's Climate Disclosure Rules, and Apple $2 billion Fine

From Oversight to Overreach? AI's Expanding Role in Monitoring Employees

Robo-Surveillance


In Canada, the rapid advancement of artificial intelligence (AI) has significantly increased the capabilities for workplace surveillance, including tracking employees' locations, monitoring their computer activities, and even assessing their moods during shifts. Despite the growing prevalence of such technologies, experts highlight a concerning lag in Canadian laws to adequately address these changes. Current legislation, such as Ontario's requirement for employers to disclose their electronic monitoring policies, provides limited protections for employees against intrusive monitoring practices. Critics argue that while AI can streamline hiring processes and offer career assistance, its use in employee surveillance often lacks transparency and can be excessively invasive. The federal government's Bill C-27 aims to regulate "high-impact" AI systems but is criticized for not specifically addressing worker protections. As AI technology becomes more entrenched in workplace practices, there is a pressing need for comprehensive legal frameworks that protect employees' privacy and rights in the face of pervasive monitoring.

Key Takeaways:
  • AI-driven workplace surveillance is increasing in Canada, with technologies capable of tracking and analyzing employees' activities in unprecedented ways.
  • Existing Canadian laws fall short in protecting employees from the potential overreach of these surveillance technologies.
  • Calls for more robust legislation and clearer guidelines on the use of AI in workplace monitoring are growing, amid concerns over privacy and the invasive nature of such practices.
(Source: CTV News)

SEC Finalizes Climate Disclosure Rules for Public Companies

The Securities and Exchange Commission (SEC) has finalized new regulations that mandate public companies to disclose their direct greenhouse gas emissions and the climate-related risks that might significantly affect their financial health. This decision, emerging from a protracted two-year review and intense lobbying from various sectors, marks a significant but contentious step towards enhancing investor access to crucial climate-related information. While the SEC has opted to exclude the requirement for businesses to report their indirect (Scope 3) emissions—citing concerns over the complexity and burden of such disclosures—this move has attracted criticism from environmental advocates who argue that it significantly underrepresents the total emissions footprint of companies. Nevertheless, the rule aims to provide investors with consistent, reliable climate risk disclosures, encompassing direct operations and energy purchases (Scope 1 and Scope 2 emissions), and necessitates reporting on how climate-related events like wildfires and floods could materially impact companies.

Key Takeaways:

  • The SEC has implemented new rules requiring public companies to disclose their direct greenhouse gas emissions and climate-related risks that could materially impact their financials.
  • Indirect emissions reporting (Scope 3) has been excluded from the requirements, sparking criticism for underrepresenting companies' total emissions.
  • Despite the controversy, the rule aims to enhance transparency and reliability in climate risk disclosures for investors.
(Source: The Wall Street Journal)

Apple's Antitrust Awakening: A $2 Billion Fine for Restricting Music Streaming Competition

The European Union has imposed a €1.84 billion ($2 billion) antitrust fine on Apple, marking its first-ever penalty against the US tech giant for anti-competitive practices. This historic fine was levied due to Apple's restrictions that prevented rival music streaming services, like Spotify, from informing iPhone users about cheaper subscription options available outside of the Apple App Store. The EU's competition and digital chief, Margrethe Vestager, criticized Apple for abusing its dominant market position, thereby denying European consumers the freedom to choose their music streaming services under fair terms. Apple countered the EU's decision, claiming it was made without credible evidence of consumer harm and stressed the competitive nature of the app market. Apple plans to appeal the fine, which constitutes 0.5% of its global annual turnover, arguing that it ensures a level playing field for all app developers on its platform. The fine includes a significant lump sum intended to deter not only Apple but other large tech firms from future violations of EU antitrust laws.

Key Takeaways:
  • Apple has been fined €1.84 billion by the EU for antitrust violations related to its App Store practices.
  • The fine targets Apple's restrictions on music streaming services, which hindered competitors from offering cheaper subscription options outside of the App Store.
  • Apple disputes the EU's findings, citing a lack of evidence for consumer harm and plans to appeal the decision.
Et Tu, Walmart? The Unexpected AI Challenger to Google's Search Dominance

Walmart's introduction of generative AI search capabilities marks a significant move in the retail industry, potentially challenging Google's dominance in the search engine market. Walmart CEO Doug McMillon highlighted the rapid improvement and customer-focused enhancement of the search experience within Walmart's app, powered by generative AI. This innovation not only streamlines shopping for events by providing comprehensive, theme-based recommendations but also establishes Walmart as a technological frontrunner in retail. The shift towards AI-enhanced searches by retailers like Walmart and others suggests a changing landscape where traditional search engines may lose their grip on the initial stages of the consumer shopping journey, as these platforms can offer more targeted, efficient, and intuitive shopping experiences directly within their ecosystems.

Key takeaways:
  • Walmart's generative AI search feature aims to simplify event planning and shopping, challenging traditional search engine models.
  • This move reflects Walmart's strategic emphasis on technology and innovation to stay ahead in the retail sector.
  • The evolving AI search capabilities among online retailers could diminish Google's role in the initial steps of consumer shopping, potentially altering the search and shopping ecosystem.
(Source: CNBC)

Sam's on Board: OpenAI Announces Board Expansion and Enhanced Oversight Measures
OpenAI has announced the integration of three new board members and the reinstatement of CEO Sam Altman following an independent review by WilmerHale, which concluded that Altman's previous firing was unjustified. The investigation revealed no concerns over product safety, OpenAI's financials, or development pace but highlighted a trust breakdown between Altman and the former board. The review criticized the board's hasty decision-making process and lack of full inquiry. Altman, acknowledging his missteps in handling disagreements, has committed to improving his approach. The board's decision to reappoint Altman is accompanied by governance enhancements, including new guidelines and a whistleblower hotline, aiming to strengthen accountability and oversight within the organization.

Key takeaways:
  • An independent review found Sam Altman's firing by the previous OpenAI board was unwarranted, attributing it to a trust breakdown rather than product or financial concerns.
  • OpenAI reinstated Sam (as a Board Member) and has introduced three new board members and implemented governance enhancements, including new guidelines and a whistleblower hotline. Per Ars Technica, they include: "The newly appointed board members are Dr. Sue Desmond-Hellmann, former CEO of the Bill and Melinda Gates Foundation; Nicole Seligman, former EVP and global general counsel of Sony; and Fidji Simo, CEO and chair of Instacart."
  • Sam Altman has acknowledged his mistakes in dealing with board disagreements and committed to handling such situations with more grace in the future.
(Source: Ars Technica)

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist who is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else. This post was written with the assistance of an AI language model. The model provided suggestions and completions to help me write, but the final content and opinions are my own.



Tuesday, February 6, 2024

Five Top Tech Takeaways: Apple Vision Pro Review, Bitcoin's Transparent Reality, Bard get a Makeover, €2 Billion Bitcoin Seized and Robots Need Humans After All

Et tu bitcoin?

The New Workforce: Humans Managing Robotic Teammates

As robots increasingly fill roles in warehouses and other work environments, companies are finding that these automatons often require human intervention, leading to the emergence of "robot wranglers." These individuals, such as Caroline Rutenberg at an Amazon warehouse and Scott Samples at a GE Appliances subsidiary, are tasked with managing robots that, despite their programmed efficiency, occasionally act with a degree of naiveté, wandering off course or mishandling tasks. This new workforce dynamic underscores the necessity of human oversight in automated systems, with robots not only requiring routine maintenance but also guidance to navigate real-world challenges. Despite the push towards automation, the relationship between robots and humans in the workplace evolves into a collaborative one, where each plays a vital role in operational efficiency and innovation.

Key Takeaways:
  • The rise of robot wranglers highlights the ongoing need for human oversight in increasingly automated work environments.
  • Despite their technological advancements, robots often require human intervention to correct errors and guide their actions.
  • The interaction between human workers and robots is evolving into a collaborative dynamic, emphasizing the importance of both in achieving operational success.
(Source: The Wall Street Journal)

Google's Assistant Rebrand: From Bard to Gemini

Google is contemplating a rebrand of its forthcoming Assistant, previously linked with Bard, to "Gemini," as identified in a recent teardown of the Google app by 9to5Google. This analysis revealed changes in the app's code, suggesting a shift in naming from "Assistant with Bard" to "Gemini." This rebranding effort reflects Google's exploration of names for its large language model (LLM) technologies, despite potential confusion among users accustomed to the Bard designation. Gemini, which encompasses several variants including Nano, Pro, and Ultra, represents Google's new LLM, and the rebranding to "Gemini" could lead to complexities, especially with the introduction of a subscription service named "Gemini Advanced," initially known as "Bard Advanced." The potential for confusion extends to future iterations of Google's LLM, raising questions about the sustainability of the "Gemini" brand name.

Key Takeaways:
  • Google may rename its upcoming Assistant from "Bard" to "Gemini," based on code changes spotted in a Google app teardown.
  • The rebranding introduces "Gemini" as the new face of Google's large language model technologies, with variations like Nano, Pro, and Ultra.
  • The change might confuse users, especially with the launch of "Gemini Advanced" subscription service, and raises questions about future branding consistency.
(Source: MobileSyrup)

Germany's €2 Billion Bitcoin Seizure: A Landmark in Cyber Law Enforcement

German authorities have confiscated approximately €2 billion worth of bitcoins, marking potentially the largest seizure of its kind in the nation's history. The operation in the eastern state of Saxony led to the seizure of 50,000 bitcoins linked to two individuals suspected of operating a piracy website up until the end of 2013. These suspects, aged 40 and 37, are believed to have acquired the bitcoins through revenues generated from their illicit website, engaging in unauthorized commercial exploitation of copyrighted works and subsequent commercial money laundering. The bitcoins were voluntarily transferred to an official wallet of the Federal Criminal Police Office (BKA), signaling a significant step in the ongoing investigation, though no charges have yet been filed. The case highlights the intersection of digital currency and criminal activity, underscoring the challenges and complexities faced by law enforcement in tracing and managing digital assets.

Key Takeaways:
  • German police have seized 50,000 bitcoins worth around €2 billion in Saxony, possibly the largest seizure of its kind in Germany.
  • The bitcoins were linked to two men suspected of running a piracy website and engaging in commercial money laundering.
  • The seized bitcoins were voluntarily transferred to a wallet of the Federal Criminal Police Office, with the investigation still ongoing and no charges filed yet.
(Source: DW)

Bitcoin Unveiled: The Surprising Traceability of Cryptocurrency Transactions

The narrative of Bitcoin's anonymity was significantly challenged by the work of Sarah Meiklejohn, a young mathematician whose research revealed the cryptocurrency's transactions to be far more traceable than previously believed. Meiklejohn's investigation into Bitcoin's blockchain technology uncovered that, contrary to the crypto-anarchist ideal of a fully anonymous digital currency, the public ledger of Bitcoin transactions provides a tool for researchers, tech companies, and law enforcement to trace and identify users' activities. This revelation has had profound implications for the world of cybercrime, aiding in solving major crimes, including the takedown of dark-web drug markets, and leading to significant law enforcement seizures. Meiklejohn's approach, combining meticulous transaction tracking with innovative clustering techniques, showcased the blockchain's transparency and the potential to undermine the privacy of those who misuse the currency for illicit purposes.

Key Takeaways:
  • Sarah Meiklejohn's research unveiled the traceability of Bitcoin transactions, challenging the perception of the cryptocurrency as an anonymous digital currency.
  • The investigation into the blockchain technology led to significant breakthroughs in cybercrime investigations, including major drug market takedowns and law enforcement seizures.
  • Meiklejohn's methods demonstrate the potential for transparency within the blockchain, highlighting the risks for users involved in illicit activities.
(Source: Wired)

Apple Vision Pro: Matt Wolfe's Review

Matt Wolfe is a popular AI developer and educator known for sharing his insights on AI, no-code technologies, tech, and futurism through various platforms such as YouTube and his website, FutureTools.io. He curates lists of AI tools for different needs and shares his expertise to help others navigate the evolving landscape of digital tools and technologies. Below is a summary of his review of the Apple Vision Pro. For his full review, watch this video:


The Apple Vision Pro has stirred considerable excitement, offering an immersive experience that is notably distinct from other virtual reality headsets. With a price tag of nearly $44,000 after taxes for the 512 GB model, it represents a significant investment into the future of VR and AR technologies. The unboxing experience aligns with Apple's high standards, presenting a product that exudes quality. The device comes with a range of accessories, including a cleaning cloth, an extra padded light seal, an alternate band, a power brick, and a USB-C cable, ensuring users have everything they need for an optimal experience.

Key Takeaways:

  • The pass-through quality is impressive, although not as flawless as some early reviews suggested, with minor issues like LED light distortion.
  • Despite concerns about its weight, the Apple Vision Pro is surprisingly comfortable for extended use, with less eye fatigue compared to other VR headsets like the Meta Quest.
  • The device offers unparalleled immersion, especially with realistic environments and detailed hand tracking, which enhances the overall user experience.
  • Multitasking capabilities are a standout feature, allowing users to manage multiple screens and applications effortlessly within their field of view.
  • However, the device has its drawbacks, including limitations in low-light conditions, a somewhat restricted field of view, and a lack of a substantial app selection at launch.
Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else. This post was written with the assistance of an AI language model. The model provided suggestions and completions to help me write, but the final content and opinions are my own.


Monday, September 18, 2023

Five Top Tech Takeaways: Apple's Carbon Neutrality Questioned, Fairphone 5 Launches, Binance US's CEO Leaves and a Privacy Nightmare on Wheels

E-Waste: A Smoldering Problem (Pic Link) (Article Link)

"Carbon Neutral" Apple Watch: What Does It Really Mean?

Apple's recent launch of its "carbon neutral" 9th-generation Apple Watch has stirred both interest and skepticism in the tech community. While Apple has certainly made strides in cleaning up its supply chain and investing in renewable energy, experts like climate scientist David Ho question whether any product can genuinely be carbon neutral. The phrase "carbon neutral" is seen by some as misleading when companies use carbon credits to offset their emissions, a practice that has drawn scrutiny from regulators. Apple's "carbon neutral" watch relies heavily on these credits, which are tied to nature-based offset projects that are themselves subject to criticism. As noted in the article:

"Part of the problem is the slipperiness of attempting to tie a carbon credit—an abstract financial instrument—to any particular product in Apple’s armada of product offerings or the wider global economy. The Watch doesn’t have any role in creating those credits. They’re only brought together by an accountant’s sleight of hand."

The company's ambitious goal to have its entire product lineup carbon neutral by 2030 might sound good on paper, but given the complexity of global supply chains and the limitations of current carbon offset systems, it raises the question: how 'neutral' can a consumer product really be? (Source: Wired)

iPhone 15 Launch: Analyzing Apple’s Eco-Friendly Claims Amid New Product Launches

In case you missed it, we examined Apple's annual iPhone launch last week. Amid the spectacle of technology and innovation, Apple's environmental initiatives were in the spotlight. The tech giant unveiled four new iPhone models and two Apple Watches, all with improved features and performance. At the same time, Apple made significant claims about their Environmental, Social, and Governance (ESG) efforts, such as a 95% reduction in transportation emissions and a carbon-neutral Series 9 Apple Watch—a claim that has been questioned, as noted in a previous Wired article. Check out our post where we assess Apple's eco-claims in the context of their past green initiatives. (Source: UWCISA)

Fairphone 5: A More Sustainable and Repairable Smartphone?

The Fairphone 5, released by Dutch smartphone company Fairphone, aims to be a game-changer in the smartphone industry by offering up to 10 years of software support, a first in the industry. It also has built-in eco-sustainability, unlike the competition. The previous model, the Fairphone 4, got an industry-leading iFixit Score of 10 out 10 for its repairability. Designed with longevity, repairability, and eco-human-friendly-sourcing in mind, the phone retails at £619 (€699). It features a 6.46-inch QHD+ OLED screen, a Qualcomm QCM6490 processor, and an array of recycled and sustainable materials. While it may not lead in performance, it offers other unique benefits such as a removable battery, a five-year warranty, and modular spare parts for easy repairs. Fairphone is setting new standards for manufacturing and tech waste reduction, although compromises include a less impressive camera and mid-range performance. (Source: The Guardian, Fairphone)

Driving into the Privacy Abyss: The Dark Side of Modern Cars

Modern cars are becoming more like computers on wheels, boasting advanced tech features that unfortunately come with a price—your privacy. An exhaustive research study into 25 car brands revealed that every brand collects more personal data than necessary, and 84% admit to sharing or selling your data to third parties. Only two brands, available only in Europe, give drivers the right to have their personal data deleted. Surprisingly, car manufacturers perform worse in terms of security and privacy practices compared to other tech products like dating apps or mental health apps. The study also exposes how these companies manipulate "consent," forcing drivers and even passengers to give away their privacy. Given that every brand reviewed was flagged for privacy issues, the situation paints a grim picture for consumer choice and control over personal data. (Source: Mozilla)

Turmoil in Crypto Continues: Binance.US CEO's Departure and the SEC Crackdown

Brian Shroder, CEO of Binance's U.S. arm, has stepped down and will be temporarily succeeded by the firm's Chief Legal Officer, Norman Reed. Amid regulatory scrutiny, the company is also reducing its workforce by approximately one-third. This move follows allegations from the SEC that Binance.US has been operating an illegal trading platform. These organizational changes are part of a larger trend affecting the crypto industry, as U.S. regulatory bodies ramp up enforcement measures. (Source: WSJ)

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist who is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else. This post was written with the assistance of an AI language model. The model provided suggestions and completions to help me write, but the final content and opinions are my own.




Wednesday, March 28, 2018

Audit, Audit, Audit harked Mark: Can CPAs come to Facebook's rescue?

In an investigation by the Guardian and the New York Times, the alleged misdeeds of Cambridge Analytica were revealed.

As noted in the Guardian article:

"Christopher Wylie, who worked with a Cambridge University academic to obtain the data, told the Observer: “We exploited Facebook to harvest millions of people’s profiles. And built models to exploit what we knew about them and target their inner demons. That was the basis the entire company was built on.”... Documents seen by the Observer, and confirmed by a Facebook statement, show that by late 2015 the company had found out that information had been harvested on an unprecedented scale. However, at the time it failed to alert users and took only limited steps to recover and secure the private information of more than 50 million individuals."

The following video from TheVerge sums up the issue:



Although such allegations have received attention (in my opinion due to the association with Trump's campaign), the reality is that these allegations against Facebook are actually not new and reported in both the Intercept in early 2017 and the Guardian way back in 2015. 

There was an ensuing backlash (as noted in the video above and here) that forced Facebook CEO, Mark Zuckerberg to respond. He both had a written response and gave the following interview on CNN:



During the CNN interview, he mentioned the word "audit" 3 times[emphasis added]:
  • "So we're going to go now and investigate every app that has access to a large amount of information from before we locked down our platform. And if we detect any suspicious activity, we're going to do a full forensic audit"
  • "And we're now not just going to take people's word for it when they give us a legal certification, but if we see anything suspicious, which I think there probably were signs in this case that we could have looked into, we're going to do a full forensic audit."
  • "We know how much -- how many people were using those services, and we can look at the patterns of their data requests. And based on that, we think we'll have a pretty clear sense of whether anyone was doing anything abnormal, and we'll be able to do a full audit of anyone who is questionable."
Can CPAs come to Mark's rescue? 
Zuckerberg's repetitive use of the word audit should be read in conjunction with his "welcoming" of regulation:

"I actually am not sure we shouldn't be regulated. You know, I think in general, technology is an increasingly important trend in the world, and I actually think the question is more what is the right regulation rather than yes or no, should it be regulated?"

Zuckerberg would not be the first tech giant to opt for regulation as a business strategy.

In Tim Wu's Master Switch, Theodore Veil also advocated for the concept of a regulated monopoly in the arena of telephones:

"[Theodore] Vail died in 1920 at age 74, shortly after resigning as AT&T's president, but by that time, his life's work was done. The Bell system had uncontested domination of American telephony, and long-distance communication was unified according to his vision. The idea of an open, competitive system had lost out to AT&T's conception of an enlightened, licensed, and regulated monopoly. AT&T would remain in this form until the 1980s, and it would return in not so substantially different form in the 2000s. As historian Milton Mueller writes, Vail had completed the "political and ideological victory of the regulated monopoly paradigm, advanced under the banner of universal service."" [emphasis added]

As Tim points out in his book, the move enabled AT&T didn't always use their monopolistic powers for good. They charged high long distance rates and even stifled innovation suppressing the answering machine due to potential conflict with its main business.

Regardless, it shows that Facebook could be an early advocate for CPAs offering privacy related assurance services around its algorithms.

AlgoTrust: A new service offering for CPAs? 
The concept of AlgoTrust is something I have previously discussed in this post.

The idea actually has support from multiple angles not least of which of comes from information security expert, Bruce Schneier:

"...it is also worth noting that there are other experts who hold that algorithms - from a privacy perspective - need to be regulated. Bruce Schneier, a well-known information security expert who helped review the Snowden documents, in his latest book, Data and Goliath ... also calls for "auditing algorithms for fairness". He also notes that such audits don't need to make the algorithms public, which is it the same way financial statements of public companies are audited today. This keeps a balance between confidentiality and public confidence in the company's use of our data."

Big Data versus Privacy: The monetization paradox
Such an algo-audit could leverage the work done by AICPA and CPA Canada in the realm of privacy, specifically the Generally Accepted Privacy Principles. That being said, privacy audits have been a hard sell in the past. But what distinguishes the service here is that it would be auditing the algorithm for compliance with privacy "regulations".The reason regulations need to be put in quotes is that in substance privacy legislation is effectively eliminated if the consumer consents to use the service.  

The challenge, therefore, is balancing the drive to monetize big data with the privacy needs of the people who use the service. For example, people who identify with the "left" may not want Steve Bannon or Trump accessing their data. Similarly, people who identify with the "right" may not want Obama accessing their social media data. The end result is that no one can access meaningful data due to privacy restrictions - resulting in a standard so restrictive that it eliminates that ability of companies like Facebook to monetize the treasure trove of data that they have collected.

As noted in an earlier post, there is an inherent highlight the conflict between privacy and profiting from big data. The value of big data emerges from the secondary uses of big data. However, privacy policies require the user to consent to a specific use of data at the time they sign up for the service. This means future big data analytics are essentially limited by what uses the user agreed upon sign-up. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service.

There is a lot of potential in attempting to create an assurance service to address Facebook's predicament, but as they say, the devil is in the details. 

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else

Wednesday, July 27, 2016

Reflections on the demise of Yahoo!

By now we've all heard that Yahoo!'s web assets were bought by Verizon. According to the Wall Street Journal, Verizon paid $4.83 billion in cash for the assets. Yahoo itself will continue to hold the remaining assets but will eventually change its name and become an investment company. In total, the company was rumoured to be worth $6 billion.

For us Gen Xers this is an interesting day: we witnessed the end of a company we saw as innovative and fresh just a "few" (i.e. read ~20) years ago.

I was recently explaining to a young lad in his early 20s about life before the Internet: you had to find books at the library and it was almost impossible to connect socially with people beyond your classmates. So to use Yahoo or other search engines to access information or people was a completely new and mind-blowing concept.

As I noted in this post commemorating Google's 17th anniversary:

"It's especially memorable for those of us who were in university in the late 90s because we had access to high speed internet on campus unlike the painfully slow dial-up at home. 

I remember my first job as a coop student at the UW Federation of Students (I can't believe this quote is still hanging around from that time!) when a co-worker was explaining to me how OpenText was the best search engine (of course using my NetScape Browser). Of course back then there was a number of search engines including, Yahoo, Lyco, Alta Vista, etc. However, I stuck to OpenText for a while then eventually switched, along with everyone else, to Google...Well Lycos, OpenText (as a search engine) and AltaVista may be long gone, but it looks like plaid is back!"

So now we can add Yahoo! to the pile of "has beens" search engine.

Beyond nostalgia, I had the following reflections on the Verizon of Yahoo based on the WSJ article above:
  • Verizon is no longer just pipes: Verizon has a strategy to move beyond just serving mobile and broadband services. Verizon is adding Yahoo to its existing portfolio of content plays, such as AOL. For Verizon, it's an overall strategy to make billions through content and advertising. Net neutrality can potentially limit their ability to use this vertical integration to undermine competition, but regardless it shows how being a "pipes-only" company is not enough. Of course it is a bit ironic that former rivals, Yahoo and AOL, are now sitting in the same tent.  
  • Big Data is monetized at the expense of privacy: The ability of Verizon to combine the data plays between its various content plays is a great illustration of a point that I have noted before: for big data achieve value it must water down privacy. Since there are synergistic values (i.e. instead of just being additive) of combining the data, it could be argued that it's something that a user should explicitly consent because a user may simply not want Verizon to use their Yahoo data this way.  
  • Remember the Internet Bubble? Yahoo! had a market capitalization of "more than $125 billion at the height of the dot-com boom in early 2000", which is quite a steep decline to $6 billion. I wonder if it ever produced the cash flows to justify that valuation. 
  • Algorithms win over people: WSJ today published a good read comparing the algorithmic approach of Google, in contrast manual effort required to index the Internet. This is similar to Amazon's who found that the algorithms to better than humans in getting people to buy things: "Amabot replaced the personable, handcrafted sections of the site with automatically generated recommendations in a standardized layout," according to The Everything Store, a new book exploring the history of Amazon. "The system handily won a series of tests and demonstrated it could sell as many products as the human editors."
  • Innovation and exponential thinking: On a separate note, but related note Yahoo could have bought Google for $3B in 2002 but it didn't. It's a great example of how Google embraced leading-edge technology to deal with the exponential growth of the Internet and Yahoo's inability to recognize Google's approach as the winning approach led to its demise.

Yahoo! is now literally a shell of its former self - both in structure and the assets it holds. However, it's a good case study of how failing to identify exponential trends - and acting on them - can ultimately lead to disaster.

Wednesday, July 20, 2016

Passwords: How's that still a thing?

Passwords.

How is this topic still a thing? 

In two words: Mark Zuckerberg. 

In June 2016, Mark Zuckerberg got hacked and his secret password was revealed for all to see. Did it meet all those wonderful rules we learn in information security school? Was it ISO27001/2 compliant? 

Well his password was "dadada" - so I'll let you decide. 

The Wall Street Journal's Nathan Olivarez-Giles had a great article on hacking/passwords. 



The article refers to a site where you can check to see if you've been hacked https://haveibeenpwned.com/ - definitely worth checking out. 

Of course the next step is to then change the password on the 7 million devices you own, but who says hackers make your life boring? 

Passwords are the best illustration of trade-off between convenience and security: you don't want the bad guys getting but at the same time you want to make it easy to use your email and the other services that you use.

One possible antidote to this unending saga of deal with hackings - managing the convenience versus security divide - is the use of password manager services. 

WSJ's Geoffrey Fowler had an article which reviewed "1Password, Dashlane, LastPass and PasswordBox"; giving the win to Dashlane.

Of course two factor authentication, as Oliveraz-Giles points out, is a key control that we all need to implement in our lives - especially since many popular services are making it easier two use such a feature. 

The fact passwords continue to be an issue reminds us that the most challenging aspect of a system is not the technology, but the people that use them.





Monday, July 18, 2016

Big Data and Predictive Policing: Can algorithms become racists?

Interesting article on Forbes by Thomas Davenport on Big Data. The articles discusses how various government, including Canadian Public Safety Operations Organization (CanOps), have used big data tools for "situational awareness". These systems draw on myriad sources of data to give users (e.g. law enforcement) the information they need to deal with a particular situation.

Here are a few points that I thought were worth noting:

Government is making strides in big data: We often think of Amazon, Google and other tech-giants as key users of this data. However, as the Davenport points out that the government is using this technology to assist with decision making. However, whether this is something that should be celebrated remains to be seen (see predictive policing below)

Privacy versus Value trade-off: He talks about how CanOps use of MASAS, the Multi-Agency Situational Awareness System, is limited by the filtering of sensitive information: "breadth of MASAS is noble, but it seems to limit its value. For example, as the CanOps website notes, because agencies are reticent to share sensitive information with other agencies, all the information shared was non-sensitive (i.e. not terribly useful)." It seems that this continues to be a theme that we had noted in back a couple years when discussing a similar trade-off the companies face when dealing with big data. As I noted in this post:

"privacy policies require the user to consent to a specific uses of data at the time they sign up for the service. This means future big data analytics are essentially limited by what uses the user agreed upon sign-up. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service."

Consequently, there still needs to be a solution as to how privacy can be respected but organizations can use the data they have collected to make better decisions.

Predictive Policing is an emerging reality: The sci-fi movie, Minority Report, paints a future where law enforcement arrests people before they commit crimes.


That future seems to be well on its.  Davenport mentions how "predictive policing" was introduced in 2014 to the NYPD.  He also mentions how much data is being collected by the police:

"It collects and analyzes data from sensors—including 9,000 closed circuit TV cameras, 500 license plate readers with over 2 billion plate reads, 600 fixed and mobile radiation and chemical sensors, and a network of ShotSpotter audio gunshot detectors covering 24 square miles—as well as 54 million 911 calls from citizens. The system also can draw from NYPD crime records, including 100 million summonses."

The idea of predictive policing was also raised in the book,  Big Data: A Revolution That Will Transform How We Live, Work, and Think, which I had explored in a multi-blog post series (click here for the first installment).

Andrew Guthrie Ferguson, Law professor UDC David A. Clarke School of Law, wrote an article on how that predictive policing is something that has not be really sorted in out in terms of legality. He notes:

"The open question is whether this big-data information combined with predictive technologies will create “predictive reasonable suspicion“ undermining Fourth Amendment protections in ways quite similar to the stop-and-frisk practices challenged in federal court.

In two law review articles I have detailed the distorting effects of predictive policing and big data on the Fourth Amendment and have come to the conclusion that insufficient attention has been given at the front end to these constitutional questions. New York has the chance now to address these issues before the adoption of the technology and should be encouraged by the same civil libertarians and ordinary citizens who challenged the stop and frisk policies."

His commentary highlights another limitation: big data predictions are biased based on how the data is collected. The stop and frisk policies he refers to disproportionately targeted minorities. Furthermore, policing is more focused on poor, black/hispanic neighbourhoods. Michelle Alexander documents in her book, The New Jim Crow, how this happens:

"Alexander explains how the criminal justice system functions as a new system of racial control by targeting black men through the “War on Drugs.” The Anti-Drug Abuse Act of 1986, for example, included far more severe punishment for distribution of crack (associated with blacks) than powder cocaine (associated with whites). Civil penalties, such as not being able to live in public housing and not being able to get student loans, have been added to the already harsh prison sentences."

Consequently, if the data by law enforcement is used to predict crime that essentially the targeting of minorities will continue to target such groups given that it is based on biased data. 

Technology often is seen to be a silver bullet for problems. However, we need to keep in mind that it is vulnerable to the human element that makes it. Given Microsoft's recent faux pas of accidentally allowing an AI avatar to become a Nazi, it is something that should actively be considered in the systems that are built to police and govern. 


Wednesday, November 4, 2015

Did WSJ go too far in exposing Apple employee home purchasing habits?

The WSJ published an article discussing the cost of houses in the Bay Area. As per the title of the article, "Apple Paychecks—One Reason for High Home Prices", the key culprit they highlight are the significant salaries that the Apple employees are allegedly paid.

The the data for the findings were based on the work done by Zillow completed "at the request of The Wall Street Journal" who "used census data to track down where workers in the census tract that is dominated by Apple’s Cupertino, Calif., headquarters live—primarily neighborhoods in the San Jose and San Francisco metropolitan areas". It's not clear if they relied on their own data to complete this analysis. As per the graph below, Zillow tied the rising house prices to iPhone sales.



To be fair, and abide by full disclosure principles, the article does also blame "[z]oning laws and regulatory red tape are key factors as well". However, would it be the WSJ if it didn't lay such a charge?

Where to begin? The article raises a lot of issues in terms of the role of publicly available data - regardless if it is only the census data, data gathered by aggregators such as Zillow or social media sites.

As I had written a couple of years ago, the article actually is the promise of social media to "return us to the village". In the village privacy was limited because people knew each other and any deeds or misdeeds made by the individual were quickly found out by the community. A good example of how social media accomplishes this was role of public in identifying the rioters involved in the post-Stanley cup "celebrations". If such a riot had happened in the village, the rioters would be have been held accountable in a similar manner.

The Zillow-WSJ effort is really along similar lines: if employees of a company or members of a particular guild were buying up houses and driving up prices in particular area; wouldn't people in the village know?

Furthermore, it actually is village business. We need to understand how we will live with one another how we are going to make the most of living together in this shared space called community, which requires an understanding of how the actions of one group within the community will impact others especially when it relates to a basic need like housing.

That being said, it opens up the issue of big data and its ramifications on privacy.  Although the above rationale translates well into issues relating to communal benefit it doesn't translate well into issues relating to how private entities can handle the information they were given for a specific purposes. This of course refers to the concept of "consent" well-established within privacy parlance.

The authors of  Big Data: A Revolution That Will Transform How We Live, Work, and Think raised this issue in there book. As I had noted in a previous post:

"The authors, however, raise a much more interesting point when discussing privacy in the era of big data. They highlight the conflict between privacy and profiting from big data. They note how the value of big data emerges from the secondary uses of big data. However, privacy policies require the user to consent to a specific use of data at the time they sign up ahead. This would prohibit companies from big data. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service. What the authors propose is an accountability framework. Similar to how stock issuing companies are accountable to the security regulators, the idea is that organizations would be accountable to a privacy body of sorts that reviews the use of the big data and ensures that companies are accountable for the negative consequences of the data.

For those of use that have been involved in privacy compliance, such an approach would make it real for companies to deal with the privacy issues in proactive manner. We saw how companies attitudes towards controls over financial reporting shifted from mild interest (or indifference) to active concern with the passage of Sarbanes-Oxley. In contrast, no similar fervour could be found the business landscape when addressing privacy issues. Although the solution is not obvious, the reality is that companies will make their privacy notices meaningless in order to reap the ROI from investments made in big data."












Wednesday, September 23, 2015

Google Glass: Where is it at?

Ever wondered what happened to Google Glass?

Well wonder no longer!

According to recode, Google glass has been re-branded as project Aura. As noted in this Fortune article, the company decided to focus on the business potential of the project as the consumer oriented device had lackluster demand. According to Fortune, Google glass is being used by industries such as healthcare, energy and manufacturing.


What does this mean?

It yet again gives credence to the trend that IT is being repatriated to the enterprise, as predicted Deloitte's 2015 TMT predictions. On a previous post, I had noted that the Intel's growth area was in support of data centres instead of consumer products - giving kudos to Duncan Stewart and team. But this serves as another evidence of their prediction being right.

Interestingly, Google has been able to procure the services of employees used to work on Amazon's Kindle tablets. Will this breathe in the consumer savvy that Amazon has been bringing to US customers?

Although the sources cited earlier say that this will be hitting the consumers some time in the near future, I still think that the privacy concerns I raised on a previous post on Glass still exist. Specifically:

"The issue, however, with Google Glass is that it is integrated into one's person's physical body and, unlike a smartphone, video camera or that ancient camera with smoke and all,  it inherently lacks the social mechanism to communicate that the interaction is being recorded. Even with social media, it is well understood that the communication is occurring in a medium that can be easily shared, so those that engage in such a communication understand there is a possibility that their conversation is not private and may not be kept confidential. In other words, precisely because Google Glass is integrated into the moment, it inherently lacks the ability to gather:
  • "Notice. The entity provides notice about its privacy policies and procedures and identifies the purposes for which personal information is collected, used, retained, and disclosed."
  • "Choice and consent. The entity describes the choices available to the individual and obtains implicit or explicit consent with respect to the collection, use, and disclosure of personal information."
(This was taken from AICPA-CICA Generally Accepted Privacy Principles, see page 7)"

Author: Malik Datardina, CPA, CA, CISA. Malik works at Auvenir as a GRC Strategist that is working to transform the engagement experience for accounting firms and their clients. The opinions expressed here do not necessarily represent UWCISA, UW, Auvenir (or its affiliates), CPA Canada or anyone else.

Tuesday, August 5, 2014

Had the Red Coats monitored Paul Revere's Facebook, would America be independent today?

The Globe and Mail reported  that Canadian intelligence captures private data without a warrant in its fight against Chinese hackers. As one would expect, the article discusses how there is calculation performed to determine whether the harm of invading privacy of Canadians is outweighed by preserving national security.

The privacy debate ranges between two camps. One camp, such as EPIC, work to shed light on how organizations and governments encroach on individual privacy and see encroachment as a threat to the individual's ability to express ideas and the like. The other camp is the likes of Jeff Jarvis, a professor at CUNY and self-admitted-Google-fanboy-extraordinaire, who often defends Google's encroachment on the lives of people by slamming people's fear of Google by forcing his opponents to quantify "what's the harm". He especially takes issue with the emotional response of how of people feel that Google's knowledge of them is "creepy".

In a sense, I understand where Professor Jarvis is coming from: consumers want more customized services and they don't want to pay cash for them, so companies have to resort to advertising revenues to be paid. Google, Facebook, et al, are profit making companies and they want to be paid.

To me this is not the real cost in terms of privacy.

The real cost is how the government uses that data it gathers directly, or indirectly via Facebook (according to RT the mood study FB was performing was part of a gov't contract to deal with "civil unrest") , Google, et al,  to interact with the politically objectionable.

One way to look at the cost is being spied upon, deemed a threat to national security and then sent somewhere to be tortured. This is what happened to Maher Arar. He was allegedly fingered by 15-year old Omar Khadr to be a terrorist. Based on this information, the US sent him to Syria to be tortured. According to the Garvie Report, the RCMP gave sensitive information about Arar to the US government. Ultimately, Arar was exonerated and all charges were cleared. The Canadian government paid him 10.5 million + legal fees and apologized to him. But how do you put a price on torturing an innocent man?

And to be sure democratic government do actively monitor the political active within the countries. For example, this article in the New York Times goes to describe in great detail how the government captured this information. Ultimately, Occupy was defeated through by police actions resulting in 8,000 arrests as well as other means. If it hadn't, how would the government have used this information to interact with the protesters on a go-forward basis?

From another perspective, the harm is also political engagement. Although the Maher Arar case shows that the government can mishandle the data it gathers about people and put them in harms way, this happens to a few people (e.g. Ahmad El Maati, Muayyed Nureddin and Abdullah Almalki) and is not a commonly used approach with dealing with protesters. For example, it's not like the Occupy protesters were rounded in the 1,000s and sent to Syria.

But there is another cost. Such surveillance and the potential for being harmed, puts a chilling effect for those that want to speak out against the way things are running. Why protest when you will lose your job and can't pay the bills?  Think about the American War of Independence. If the British were able to spy on the "facebook" pages, email accounts and cell phones of  Sam Adams, Paul Revere and pro-separatist sympathizers in the colonial militias - would the British had been able to arrest these separatists in a timely manner? Or would have pre-colonial surveillance society taught the Founding Fathers to self-censor and tow the pro-British line?  It is pure speculation, but I think the Union Jack would still be flying in the land we now call America.

Wednesday, July 16, 2014

Privacy to be cast aside to make Big Data a reality?

This is the fourth and final instalment of a multi-part exploration of the audit, assurance, compliance and related concepts brought up in the book,  Big Data: A Revolution That Will Transform How We Live, Work, and Think (the book is also available as an audiobook and hey while I am at it, here's the link to the e-book ).  In the last two posts we explored the more tactical examples of how big data can assist auditors in executing audits resulting in a more efficient and effective audit. The book also examines the societal implications of big data. In this instalment, we look explore the privacy implications of big data.

What's are the privacy implications of Big Data?
In the past 3 instalments, we've explored the opportunities that big data affords to audit profession and society at large. In this article we look at the privacy implications raised by the book.

When we think of a totalitarian state we flash back to the regimes of world war II or the Soviet era. The book talks about how the East German Communist State invested vast amounts of resources on gathering data from its citizens in order to see who conformed with the state's ideology and who didn't. The book notes that East German secret police (the Ministerium für Staatssicherheit or "stasi") accumulated (amongst other things) 70 miles of documents. However, now big data analytics essentially enables corporations and governments to mine the digital exhaust people leave through social media, using their cell phones or logging into their email accounts and essentially eliminate the privacy people have.

Some may point to anonymization as a potential solution to the problem. However, the authors highlight how New York Times reporters were able to comb through anonymized data published by AOL to positively establish the identity of the users. This highlights that the powerful tools that have emerged from big data alter the privacy landscape. Consequently, privacy controls need to be rethought from this perspective.

The authors, however, raise a much more interesting point when discussing privacy in the era of big data. They highlight the conflict between privacy and profiting from big data. They note how the value of big data emerges from the secondary uses of big data. However, privacy policies require the user to consent to a specific uses of data at the time they sign up for the service. This means future big data analytics are essentially limited by what uses the user agreed upon sign-up. However, corporations in their drive to maximize profits will ultimately make privacy policies so loose (i.e. to cover secondary uses) that the user essentially has to give up all their privacy in order to use the service. What the authors propose is an accountability framework. Similar to how stock issuing companies are accountable to the security regulators, the idea is that organizations would be accountable to a privacy body of sorts that reviews the use of the big data and ensures that companies are accountable for the negative consequences of the data.

For those of use that have been involved in privacy compliance, such an approach would make it real for companies to deal with the privacy issues in proactive manner. We saw how companies attitudes towards controls over financial reporting shifted from mild interest (or indifference) to active concern with the passage of Sarbanes-Oxley. In contrast, no similar fervour could be found the business landscape when addressing privacy issues. Although the solution is not obvious, the reality is that companies will make their privacy notices meaningless in order to reap the ROI from investments made in big data.





Wednesday, September 4, 2013

Verizon Mobile Push into Canada Evaporates: The Data Privacy Angle

Canadians had been anxiously awaiting the entrance of American telecom giant into the Canadian mobile market. For years, Canadians have lived under the domination of a few giant players, which has resulted in Canadians paying one of the highest - if not the highest - cell phone rates in the world.

The government of Canada actually dedicated a website, which actually illustrates the level of concentration in the market. Apparently, to address the issue "Ottawa rolled out the red carpet to attract the U.S. mobile giant in the hopes of establishing a fourth mobile competitor in all provinces - not only in Quebec, where Quebecor’s Vidéotron is giving the Big Three a run for their money. "(see the Globe & Mail article for the full context of the quote). As this Globe & Mail article, suggests the hope was that Verizon would have entered the market and forced the incumbents to offer better prices.

However, Verizon announced that it has cancelled any plans to enter into the Canadian market and thus dashing these hopes.

An interesting point to note, however, is the data security and privacy angle that the incumbents took to bolster their case to the Canadian public. As per the FairForCanada website (which is supported by the Big 3 Telecoms), they claim:
"Who do you want to own your private data? 

Across the country, Canadians use their wireless devices to make calls, send text messages and emails, and browse the internet every day. That information should be safe, secure, and private. 

Will American companies say no to requests from U.S. government agencies, for customers’ personal data? 

Canadian wireless providers have a solid track record of protecting your data in compliance with Canadian laws. But what will happen with regard to the data of Canadians in the hands of foreign-owned wireless carriers? What laws will regulate the protection of your information? This is not a trivial issue. It is one that should be of concern to all Canadians."

It seems that the advocacy group was riding the fear of Canadians that the US will have access to their data.

It seems they have done their research.

As noted in this ZDNet article, "Since being signed into law in 2001, the Patriot Act has been cited as a viable reason for Canadian companies, government departments and universities to avoid the cloud due to the close proximity to the United States". In other words, fear of US surveillance has led to low demand for US-based cloud services. Applying the same logic, the incumbents were playing on this same fear that Canadians would stick to them.

However, this is only part of the truth. The reality is that Canadian companies have had to comply with similar legislation that requires them to divulge data to Canadian law enforcement. As noted by the Office of the Privacy Commissioner of Canada:

" In the national security and anti-terrorism context, Canadian organizations are subject to similar types of orders to disclose personal information held in Canada to Canadian authorities. Despite the objections of the Office of the Privacy Commissioner, the Personal Information Protection and Electronic Documents Act has been amended since the events of September 11th, 2001, so as to permit organizations to collect and use personal information without consent for the purpose of disclosing this information to government institutions, if the information relates to national security, the defence of Canada or the conduct of international affairs."

This is on top of the recent CSEC scandal (where the secretive agency is alleged to have illegally spied on Canadians), but one could argue that such surveillance was actually illegal. Ultimately, I had hoped Verizon would have entered into the market, but only to push down the rates. I would have ended sticking with the Canadian mobile carriers because the data is one way or another in one jurisdiction.

However, all is not lost in terms of lower rates in the cell phone market.

It seems the government is hoping to entice voters by tackling a problem, which does impact the productivity of Canadians (see this post which compares Canadian mobile access to access in India/China). For example, the CRTC has mandated a number of changes to the cell phone contracts that the wireless industry can legally offer, such as restricting the minimum contract length to two years.

But from a data privacy perspective, it seems the only way to get privacy these days is to live a technology-free lifestyle of yesteryear!

Monday, April 22, 2013

Facebook Home: Privacy fears or a sign of decline?

As reported across the tech news sites, Facebook Home hit 500,000 downloads in the first 5 days. However, techcrunch gave some perspective. It noted that Instagram (which is owned by Facebook) had "over 5 million downloads in six days". So what is holding people back?

One possible issue is privacy. As noted in this previous post, the younger generation is privacy savvy and is opting for apps like SnapChat that don't retain pics and other personal info. So it may be possible that the not-so-hidden-cost of privacy is too high a price to pay. And many commentators have noted that this issue with respect to Facebook Home. As noted in this blogpost by GigaOm's founder, Om Malik, fears Facebook's past privacy issues will be especially problematic if Facebook can capture (and monetize) one location data. As pointed out by CIO.com this can be turned off, but how many people are not going to use the map feature of their phones to keep this private?

On the other hand, is Facebook as popular as it used to be? Speaking to a colleague at work, he notes that his "tween" son is using... (drum roll please)... Google Plus! Yes, that's right Google Plus - the social network that people mocked as a possible Facebook competitor is now being picked up (anecdotally) by the youth. Although this may be anecdotal evidence, Facebook last redesign was viewed by some as an imitation of Google Plus. For Facebook's version of the story check here:

Overall, it's quite fascinating how the social media sites and tech companies wax and wane in popularity. Remember RIM? The company that could do wrong, now is on fighting (one could argue valiantly, but that could be the nostalgia in me talking.) for spot number 3 in the smartphone wars. Of course the biggest giant to fall from the public's favour is Apple with it's stock sliding from a height of $705 to a current price of just under $400.

However, as pointed out by Horace Dediu on this podcast, Facebook has effectively circumvented Google by making this the home screen on Google's real estate. He has good analysis of the whole supply chain, making an analogy of Facebook's strategy to Intel's strategy of "Intel Inside":


Furthermore, GM's back as an advertiser on Facebook. They made an exit last year, but has returned "and will take advantage of Facebook’s new mobile targeting features". So despite the slow number of downloads and potential privacy issues Facebook Home is hardly down and out.

Tuesday, April 9, 2013

Big Data, Facial Recognition and Privacy

In October of 2012, the FTC released these guidelines on dealing with the privacy issues of facial recognition. The publication begins with a scene from the movie Minority Report where the protagonist is offered a product based on facial recognition software. When the movie came out, this future seemed decades away. However, now it just seems around the corner. And this is primarily due to advances in data mining capabilities brought to you by the cloud and more specifically big data. One of key characteristics of Big Data (see here for IBM's definition) is being able to include data that is not just massive or fast moving, but also goes beyond the simple world of flat file - meaning it includes images.

And here comes the interesting part about privacy and big data. Think about the following scenario: you walk  into a store, the security cameras take your picture, it's uploaded to Google Images (see below for how this works), a second search is done to find out what you've posted publicly on the various social sites and then you are approached by a sales associate who has all this information about you and then can tailor its offerings to you.


Privacy regulations requires that users give consent before their information is collected. So could this simply be circumvented by posting a sign that states "By entering this premises, you consent to the store collecting your image and using that information to tailor offerings, services and the like to your online profile"?

I think so.

As I posted last week, TJX was effectively able to stop the Canadian privacy watchdog, by agreeing to encrypt the personal information it should not collect. So it does not take much for companies to persuade users (or the privacy regulators) to get what they want from their customers/users. At the end of they day, companies simply have to repeat the Capitalist mantra: "You are free to go somewhere else if you don't like our policies". Never mind that all the companies have the same policies, which means you don't have any choice except to wear a mask when you enter the store. And that is not advisable because it may be result in being billy clubbed or tazered by security guards! Or to be a little less dramatic, the store will simply offer to refuse you service if you wear a mask.


Friday, April 5, 2013

The Killing of Google Reader: Proof that Privacy Matters at Google?

Google announced last month that it was going to kill off Google Reader. According to the post, the reason that was given that there was a decline in the number of subscribers. For the past few years, Google has been consolidating its offerings and reducing the number of properties that it has out there. For example, it retired Google Wave, which was seen as a way to revolutionize the way people conversed with one another. The other trend in Google' s consolidation is to get its subscribers into its social network; Google Plus. So another theory is that Google killed Reader because it wants to drive more traffic to its social network - as they have done with things such as YouTube, Blogger, etc.

However, allthingsD reported that another factor that led to Google retiring reader was due to compliance with privacy. Citing "sources" the elimination of reader, "[w]asn’t just a matter of company culture and bigger priorities...Google is also trying to better orient itself so that it stops getting into trouble with repeated missteps around compliance issues, particularly privacy".

If what sources are saying are true, the factoring of privacy costs into its product releases represent a significant maturation from a privacy perspective. Google got in trouble with the FTC because it failed to comply with privacy procedures with Google Buzz and had to submit to biennial privacy audits for 20 years. In other words, Google can probably include the "kill decision" as "audit evidence" as proof that they are complying with their commitment to privacy.

So is this proof that the US overall approach to privacy creates a more privacy compliant nature than the one used in Canada? Although more research would be required to answer this question, we can contrast the proactive nature of Google with respect to privacy and how TJX reacted to its breach of privacy policy in Canada. The Privacy Commissioner of Canada's took issue with TJX's (which operates Winners in Canada) the use of driver's licenses during the returns process. In summary, TJX should not be collecting driver's license information because it has nothing to do with buying clothes, etc at the stores! However, instead of stopping the process, the company merely agreed to stop storing in an unencrypted format. In other words, they basically ignored PIPEDA and continued with business as usual.