Stuff that occurs to me

All of my 'how to' posts are tagged here. The most popular posts are about blocking and private accounts on Twitter, also the science communication jobs list. None of the science or medical information I might post to this blog should be taken as medical advice (I'm not medically trained).

Think of this blog as a sort of nursery for my half-baked ideas hence 'stuff that occurs to me'.

Contact: @JoBrodie Email: jo DOT brodie AT gmail DOT com

Science in London: The 2018/19 scientific society talks in London blog post

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, 9 July 2014

How does Google's 'right to be forgotten' work? Actual question, not rhetorical trope :) #R2BF

Possibly this will be solved by 'reading more around the topic' but I've not spotted the answer yet and someone must know.

How does Google's "right to be forgotten" info removal service actually work?

If there is a web page that says stuff you don't like do you ask Google to
(a) stop indexing that page / those pages in the searches (ie provide Google with a list of pages for it to hide)
(b) not show in its search results any pages that mention specific keywords
or
(c) some other method

If (a) then presumably this can easily be thwarted by reposting the content onto a new page with a new address.

Also Google indexes most things on Twitter (admittedly transiently) so if someone was determined they could keep posting stuff there and it would show up in Google (as well as, obviously, on Twitter).

I can see (b) being mildly more successful but Google would have to throttle at the level of search, to prevent each new page with those words showing up. This seems like a lot of hard work.

Also, aren't there sites that monitor the requests made (similar to the ChillingEffects.org site that monitors requests for material under copyright to be removed). They've written on the right to be forgotten but I've not spotted the method Google's using.

If there are, don't bother looking in Google, just go to the relevant site and search there. Eg a Telegraph article I read this morning on R2BF suggests that Google has removed some of the Telegraph's links (suggesting method [a]...) on its search results about someone after they requested it, but searching on the Telegraph's site for the person mentioned in the article brings up other information, whether or not it's indexed on Google.

I'm sure the ethics, privacy, free speech aspects of this are all very interesting but what I'm actually intrigued by is just the practicalities.




Saturday, 24 May 2014

Changing your name on Twitter doesn't stop people from finding you

Summary: changing your Twitter name to increase your anonymity doesn't work as people can always find you thanks to (a) the way Twitter threads conversations and (b) because you'll presumably still chat to the same people after the name change.

You'd need to create a new account from scratch (and uncheck the Security/Privacy - Discoverability option that lets people find you from your email address). It's Twitter's threading functionality (where clicking on a tweet brings up the whole conversation) that makes it so easy to uncover you by the conversations other people are having / have had with you.



You can change your Twitter name at any time and for any reason. Sometimes people do so because they want to use their real name, or to match their blog name, or just fancy a change.

Some choose to change their name to increase their anonymity. From what I can tell it probably doesn't work - and I've no idea if this is something that's widely known, but I think it might be useful to be aware of.

I only know of a handful of people who've changed their name so I don't have a wide pool of experience to draw on, but here's what I've found.

Recently someone in one of my Twitter circles "disappeared", by changing their name, locking their account and blocking some of their followers (including me). I've no idea why they did this and didn't know what their new name was.

To confirm that they'd 'gone' I tried searching for an older tweet that I'd sent to their original name by searching for

from:jobrodie @TheirOldName

and, sure enough, when I found an example tweet it was clear that their old name was no longer hyperlinked (physically it was plain black text instead of the usual clickable blue that active account names have).

However when I clicked on my tweet it opened up a thread with two tweets in it. The one they'd sent me* and my reply. Their reply now told me what their new name was and that their account was now protected, *so I couldn't see what they'd said. While I can't see any of their tweets I can see what anyone has said in reply to them by searching for tweets sent to their new name

@TheirNewName

Remember that protected tweets are not all that private because people tweeting to you can give you away.

I then tried searching for tweets I'd sent to another friend who'd changed their name (but whom I'm still following, under their new name). Exactly the same thing occurred - I found my old tweet which contained the text that had @TheirOldName in it. That name was no longer hyperlinked meaning the account doesn't exist, but clicking on the tweet brought up the thread and showed me their new name (which of course I already knew anyway). 

Twitter's threading functionality (I still think of it as relatively new but it's been around for a few years) means that tweets sent to an account can give away as much information as tweets sent from an account.

I used the search facility to find the handful of people I know of who've changed their names by looking for tweets I'd sent them, but it's just as easy to find people by searching from tweets sent by others, if you know who they've been talking to.

Deleting all your old tweets could help but I doubt it. To be absolutely certain you'd probably have to get everyone else to delete their old tweets to your previously-named account, which is probably a bit unlikely (particularly if you're changing your name to avoid an annoying person)!

You might also like:




Saturday, 4 August 2012

Fun with paranoia: ways in which data give you away - a collection


This morning I read Tom Morris' post on a new (to me) feature in Quora which shares with other users which questions you've been reading. Being a social tool there's an argument to be made that Quora's behaving quite normally in doing this. Some people have apparently been in uproar about this and have quit Quora - which as Tom points out is a bit of an overreaction given that you can just switch off this setting. I checked to see what setting I had on mine and found it was already off (presumably by default as I'd not known anything about it until I saw Tom's post).

But Tom's clear point is that without knowing about this setting someone could actually be giving away information about themselves that they might not want to. He gives some good examples of situations where that really might not be what someone would want.

4 August 2012

I retweeted this and cc'd Ben Goldacre who's previously written about Spotify which has been keen to share your playlists and songs you've been listening to (Ben wrote his post in January 2012 and the ease with which someone can find and amend options may have changed since then). A few commenters on his post didn't see that this was a big deal and weren't "embarrassed" by their taste in music, but I think you could conceive of situations where someone might not want to have their listenings shared. People might just feel a bit icky that it was happening without their having fully understood what it was doing (you can argue that it's their fault for not reading the sign up instructions of course but I'd rather software undershared by default than overshared).

25 January 2012

I've also been interested in other ways that data, or software settings might give information away and have written three blogposts on different aspects of this.

26 July 2012 
This is about two separate things: (1) redaction of information within documents and in the document's "wrapper" (eg information about who has edited it, and how long they spent on it) and (2) mobile phone keyclicks that could give away  what number you're dialling.

22 July 2012
Twitter and Facebook (and other platforms) allow other people to find your accounts via the email address that you used to sign up with them. You can definitely switch this off in Twitter, not sure about Facebook but worth being aware of this.

1 June 2012
I wrote this after searching a volunteering site. I wanted to share on Twitter a volunteering option I'd found that was of no interest to me, but likely of interest to quite a lot of people that follow me. However the link I was about to share had additional information attached to it. It didn't contain just the web address for the job description but also included my postcode, because I'd used that to search for information near to me. Had I blithely copied and pasted that link without checking what it contained I'd have given away my street address and (I believe) which part of the street I live on.


Edit: 14 August - I've just spotted an option in LinkedIn which jobhunters might want to be aware of, "Activity broadcasts":

By selecting this option, your activity updates will be shared in your activity feed.

    Let people know when you change your profile, make recommendations, or follow companies

    Note: You may want to turn this option off if you're looking for a job and don't want your present employer to see that you're updating your profile.

Sunday, 22 July 2012

Ways in which your email address can 'give you away'

Update: For Twitter at least there's a way to stop people from finding your Twitter account based on your email address, see details in the image below - thanks to Aerliss who commented below.
"You can keep your email private on Twitter though. If you go to settings, under your email is a little tick box that says "Let others find me by my email address". Unticking that should solve the problem, as long as Twitter plays nice." - Aerliss
-----------------------------------------------

Not 'give you away' in the 'you've something to hide' sense but I'm quite interested in the way the internet and social media allow already public things to surface in a way that people might not be aware of. A while back I created a spare Twitter account with one of my umpteen email accounts so that I could give it to my mum to follow me. She didn't want to sign up to anything herself but was curious to play around with it. Sadly she died before she had much opportunity to use it but the account lies fairly dormant and is locked.

I was a bit surprised later to get an automated request to follow me from a friend who'd signed up to Twitter. After they'd signed up they authorised Twitter to access the contacts list that lives in their email account - and my email address was among them. This then let them decide which people they either wanted to follow directly on Twitter or, if they're not on Twitter, to send them an invite by email to join. Had my account not been locked then my friend would have just been able to start following me.

Twitter already had my email address and knew which account I had and was able to share this information with my friend. This seems a little bit like oversharing to me...


When friends (or business contacts or anyone that has your email address) authorise a social media tool to access their contacts list your use of that tool (or not) is 'surfaced' and your email address becomes available to said tool. A number of people have been fantastically peeved to receive repeated email requests from LinkedIn to join the service - these arose from precisely this sort of 'invite all contacts' and for a while it was difficult to persuade LinkedIn to make it possible to block this sort of thing. I think it's all sorted now.


Of course this is exactly the sort of thing you'd expect from tools where sharing is the default - there's really nothing wrong with it and I've signed up to things after email invites. I just think it's helpful to be aware that your email address leaks information in this way.


Here's what I wrote (as section 35) in my guide for celebrities who are thinking about using Twitter. I hope they have social media managers to tell them this sort of thing anyway!


---------------------------------------------------

35. Your email address can give you away

Be careful (or at least aware) what email address you use to create your Twitter account
If other people (friends, agents, lawyers) have your email address in their contacts then they can find your Twitter account if you used that email address to create your account.

If your friend is on Twitter then s/he can authorise Twitter to access his/her email contact list and so can find out which of their chums / clients is also using the service. If you're in there, you'll show up. You may or may not want this. If you don't like this, and would prefer to be under the radar, then consider using a disposable email address.

A commenter on another post I wrote about this pointed out that on Twitter at least you can protect against this by unticking an option to 'let people find you by email' - click on the image below to enlarge it and follow the steps.

















The picture below shows what your friend sees when they authorise Twitter to access their contacts information. Note that the email systems (Yahoo, Gmail. Hotmail and AOL listed on the right) have nothing to do with YOUR email account but relate to the type of email they're using.

If someone lets Twitter read their Yahoo contacts and my academic email address happens to be there then they'll find my Twitter account.



Friday, 1 June 2012

The perils of sharing URLs - be aware

[Edit 14 June 2012: now with Guardian Facebook app info (below)]

I recently wrote a post about 'what is all this crap Google adds to my search URL' referring to the alphanumeric text that Google appends to the web address that results from doing a search. I can share this URL with other people and when they click on it they'll get more or less the same search results too. Since I'm not sure what information is shared by the alphanumeric gibberish I tend to clip all URLs (or at least check them in notepad) before sharing.

While on a local volunteering site I typed in my postcode to see what's available (I'm interested in being a Digital Champion and helping people get online) and came across an opening for a freelance journalist living in Tower Hamlets. Since I know lots of journalists and writers I thought I'd share this on Twitter but it would have been rather unwise to copy and paste the URL as it is, as you'll see below:
http://www.do-it.org.uk/search/opportunities/1682771/Journalist?unit=mile&distance=5&location=SE3+[redacted]&activitiesSome=47

While I've no problem with people knowing I live or work in Blackheath the last three digits of my postcode can narrow things down quite a bit - I can't help thinking this isn't something I want to share.

Many URLs now have extra information at the end of them that tell you how the person sharing them came by them in the first place, eg through a search (quite possibly what they searched for), via Twitter (look out for something like utm=twitter at the end of the URL), or through a newsletter when you click on a link that arrives in your email inbox and is used to track your visits to the website. Not that long ago I received an email from an organisation to say that they were no longer going to send me newsletters because they'd noticed that I never clicked on any of the links.

I think it's worth paying a little attention to these URLs just to see what you might be unwittingly sharing. You can hover over an URL and right-click, copy 'location' and then paste it into notepad (for PC users: Start > type 'notepad' into 'Search all programs and files') to inspect it before sharing :) 

I have to say I do this pretty much constantly for any link that's longer that I can see in the status bar at the bottom of the screen (when you hover over an URL the full details show up in the taskbar - you can toggle this on or off in the View menu). The only URLs that don't yield this info are t.co - anyone know of a way to see where it's going to take you (eg with bit.ly URLs just add a + at the end to see what the page is before visiting it).

To make the above URL 'safe' all I need to do is delete everything after Journalist and all will be well. Note also though that if I paste it here then Blogger will turn it into an active link and deleting part of the visible URL is insufficient as the information in the full URL is embedded / hidden within the text - caveat linkor.

My philosophy, unless the faff of tweaking outweighs the 'risk', is to share only the minimum amount of URL text that will take a reader straight to the relevant page.

Well... this is one reason why I think I might be good at teaching people how to get online and stay safe ;)

[Guardian Facebook app]
I have platform apps switched off on Facebook. While I don't truly believe that I can ever hide from Facebook I like to do what I can to thwart it. If a friend has OKed the Guardian Facebook app (or other newspaper apps, not to pick on The G in particular) every time they're logged in to Facebook and read something it's posted to their timeline unless they've disabled it. This means I'll see something and think "oh that looks interesting" and click on it - which is precisely what's meant to happen, Facebook being about sharing. However I don't get very far because of the app block I have in place.

Rather than let me just read the article it doesn't let me unless I sign up. To get to where I want I have to chop bits of the web address off so that I end up with a working URL to go to the article. Fiddly.

I must have recently tried to read a story about pro-choice and ended up with this URL. It seems that Facebook wants to share with The Guardian my email address, birthday and location - I don't particularly mind either having this info (wouldn't have shared it in the first place if it was secret) but I like to know when I click on something what I'm sharing. Even if it's information I'm happy to share it feels weird not to know when I've shared it.

https://www.facebook.com/dialog/oauth?client_id=[redacted numbers]&redirect_uri=http%3A%2F%2Fapps.facebook.com%2Ftheguardian%2Fworld%2F2012%2Fmar%2F21%2Fpro-choice-protest-anti-abortion&scope=publish_actions,email,user_birthday,user_location

To turn this into a working URL then you need to clip out everything that doesn't look like a regular Guardian web address and turn everything that says %2F into a forward s/l/a/s/h and %3A into a c:o:l:o:n

Clipping this bit out gives:
http%3A%2F%2Fapps.facebook.com%2Ftheguardian%2Fworld%2F2012%2Fmar%2F21%2Fpro-choice-protest-anti-abortion

Tidying up gives:
http://theguardian/world/2012/mar/21/pro-choice-protest-anti-abortion

This still isn't a proper recognisable web address so a bit of logic, guesswork, assumptions and tweakings (or you can just plug that URL into Google search and the right one will come out anyway) gives this, which works:

http://www.guardian.co.uk/world/2012/mar/21/pro-choice-protest-anti-abortion

Writing down the steps makes it seem like much more of an effort than it actually is. I like the chase ;)

Saturday, 3 September 2011

Facebook privacy, again

Facebook has tweaked its privacy settings again. You may want to block these options so that you're given a chance to OK anything in which you're tagged. Other than this it seems that Facebook has mostly improved its privacy settings of late. Still, best to keep your wits about you.

  • Click on Account > Privacy settings.
  • Scroll down to How tags work and click on Edit settings.
  • Edit settings to suit - most of these seems to be default to letting people tag you and check you in to places (which I'd originally had disabled I think, so check to make sure).

When I first went on this new page there was a little tour to tell me what each button does - I copied the text and added it below. In the picture the 'Friends' button is highlighted.


First button on the left that looks like a 'plus person' symbol
"Use this button to tag people to say who you're with. You can tag anyone. When you (or others) add tags, the people tagged and their friends may see the post too. You can choose to review tags others add to your stuff.
Note: we removed a setting that limited whether the friends of people you tagged could see a post. Now you control this by choosing who you tag and approving tags other people add to your content. Your old posts won't change."

Location button
"To easily say where you are, you can add your current city or neighborhood to your posts, or add a specific place. You can turn this on or off at any time."

Friends button (controls who can see this information)
"Use this to manage who can see and comment on posts you share, including ones with location, if you add it. When you change this setting, it will stay how you set it for future posts until you change it again. Posts (including check-ins) from old mobile Facebook apps will use your new default privacy setting.
Also, we've changed the label for "Everyone" to "Public," but your posts will still reach the same people."

Saturday, 30 July 2011

Why does Facebook disobey me?

Shortened link for this post is http://is.gd/PjL8DB

In my Facebook settings (think Fort Knox) I have switched off all platform applications so am a bit surprised to be presented with an opportunity, on other pages, to comment as me on Facebook and to simultaneously post to my wall. I'd have assumed this wasn't possible. When I log out of Facebook this option disappears from these pages (if I reload them post logout) - but I have never authorised these pages to know that I'm logged in to Facebook in the first place and I've told Facebook not to indicate that I am. What am I doing wrong?

Here's a pic of my settings - Blogger used to let me add images that were of a reasonable size, sorry it's so teeny (possibly Blogger's lying to me about my settings too!) - hopefully if you click on it the image will open up larger in Twitpic...


...and below is an example of the comment form, again sorry about its teenyness.