Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, February 26, 2026

Discord Backs Down: Age Verification Delayed

 
Earlier this month, Discord announced that it's users would need to submit to age verification. Either they would need to show some ID proving their age, or they would need to show a picture or short video of themselves. The result was numerous users complaining. Part of the backlash were concerns about the safety of data collected as in October hackers had stolen the information of 700,000 government IDs owned by the platform via a third party service it was working with at the time. There were further concerns when other hackers discovered "the frontend code for their partner Persona was publicly accessible on the open internet," and the code "compares your selfie to watchlist photos using facial recognition, screens you against 14 categories of adverse media (from mentions of terrorism to espionage), and tags reports with codenames from active intelligence programs consisting of public-private partnerships."

So on Tuesday February 24, Discord announced a change of plans. They were delaying age-verification checks. Discord's co-founder Stanislav Vishnevskiy would explain:
 
In hindsight, we should have provided more detail about our intentions and how the process works. The way this landed, many of you walked away thinking we're requiring face scans and ID uploads from everyone just to use Discord. That's not what's happening, but the fact that so many people believe it tells us we failed at our most basic job: clearly explaining what we're doing and why. That's on us.
 
Our goal is straightforward: keep the Discord experience completely unchanged for the vast majority of people while ensuring an age-appropriate experience for everyone. Over 90% of users will never need to verify their age to continue using Discord exactly as they do today. This is powered in part by our internal safety systems, which can already make an age determination for many adult users without any user action. We'll publish the methodology behind this in a technical blog post before we launch globally.

Vishnevskiy would go on to say the age-verification was "being shaped by legislation already in effect in the UK and Australia, with Brazil quick to follow, and Europe and multiple US states close behind." They were also no longer in a partnership with Persona, the platform they were working with when the hacking breach happened. 

So Discord users can relax a little, though perhaps not for very long. An article by "The Verge" stated, "Age verification is a reality on a growing number of social media platforms, requiring an ID or facial scan for full access to everything from YouTube to Roblox. The age-gating wave is coming along with calls for stronger child safety measures online, despite concerns about privacy, security, and censorship. In the US, lawmakers are pushing forward bills like the App Store Accountability Act and Parents Over Platforms Act to have app stores themselves verify users’ ages." So users of platforms valuing privacy will likely be needing to be very watchful for a while
 
 
Bixyl Shuftan 
 

Monday, February 6, 2023

Linden Lab Speaks About The Bots

 
With all the talk about the Bonniebots, and Linden Lab having to suspend comments on several threads on the official forums about them as well as talking to the staff behind the bots, it was no surprise they would eventually say something. And on Friday afternoon, February 3, they did, posting a statement in the official blog under "Balancing Initiative and Privacy."

We know there has been quite a bit of discussion about Scripted Agents/NPCs lately.  Linden Lab is committed to continuing its excellent track record of keeping your personally identifiable information safe and secure.  We understand that there is a certain amount of information a “bot” service has been collecting and displaying on their third party website that is causing unease in our community, and we’re working on the best way to address these concerns.

Linden Lab is having conversations with the parties involved, however this should not be taken as an endorsement of any sort. We have spoken several times in an attempt to get a full picture of the situation. These discussions have been mutually beneficial, and will help us as we look to update our policy on Scripted Agent/NPC operation in Second Life.

We recognize the need for improvements in specific areas, so in the near future we will be making adjustments to policies where needed.  We have seen many requests from the community with a wide array of suggestions, and we appreciate all earnest and civil engagement. Internal discussions will continue beyond the Scripted Agent/NPC Policy, and any programmatic changes will be communicated as those roll out.

Thank you to everyone who engaged in this topic and added your voice.  While we have had to shut down several discussions that became unproductive, we have welcomed feedback through support contacts and have been using this feedback to inform our decision-making. We are listening, and are working to make sure that Second Life is a welcoming and engaging world for all our Residents (and their automata). 

 
The parts "as we look to update our policy on Scripted Agent/NPC operation in Second Life," and "in the near future we will be making adjustments to policies where needed," suggests there *may* be some changes as to what information bots can collect in the future. But this is not a sure thing.

Friday, January 27, 2023

Bonniebots and The Debate About Them

 
In the past few days, a new controversy has come up in the Second Life forums: the Bonniebots. Some say they provide a useful service. Others call them a privacy threat and a violation of the Terms of Service. The topic was a hot one in the Second Life forums with four threads on the topic shut down by the Lindens. In the last one, Patch Linden stated they would soon be meeting up with the bots' team.
 
 Read the story in Design.

Tuesday, June 1, 2021

Amazon To Link Users of Alexa, Other Devices, To One Another

 

For those who own an Alexa, or other devices by Amazon that you use, an article in Ars Technica has some troubling news for those who value their privacy, and don't like the company getting them into something without their okay. According to the e-zine, Amazon plans to launch "Amazon Sidewalk." The service will link those who use Amazon products to their neighbors who also use them and share their bandwith for the purpose of helping those without a connection. But instead of asking users if they want in, people have to actively opt out of it before the date of Tuesday June 8, one week from now.

Amazon Sidewalk helps your devices get connected and stay connected. For example, if your Echo device loses its wifi connection, Sidewalk can simplify reconnecting to your router. For select Ring devices, you can continue to receive motion alerts from your Ring Security Cams and customer support can still troubleshoot problems even if your devices lose their wifi connection. Sidewalk can also extend the working range for your Sidewalk-enabled devices, such as Ring smart lights, pet locators or smart locks, so they can stay connected and continue to work over longer distances. Amazon does not charge any fees to join Sidewalk.

Amazon insists the service is to help the users of it's devices. They also released a report to address security and privacy matters.  But as Ars Technia put it, "But there are enough theoretical risks to give users pause. Wireless technologies like Wi-Fi and Bluetooth have a history of being insecure. ... If industry-standard wireless technologies have such a poor track record, why are we to believe a proprietary wireless scheme will have one that’s any better? ... Extending the reach of all this encrypted data to the sidewalk and living rooms of neighbors requires a level of confidence that’s not warranted for a technology that’s never seen widespread testing. ... Amazon’s decision to make Sidewalk an opt-out service rather than an opt-in one is also telling. The company knows the only chance of the service gaining critical mass is to turn it on by default, so that’s what it’s doing."

The good news, users can opt out of "Sidewalk." The steps are:

Open the Alexa app.
Open "More" and select "Settings."
Select "Account Settings."
Select "Amazon Sidewalk."
Turn Amazon Sidewalk "Off."

Ars Technica stated they contacted Amazon representatives to comment on the matter, but got none.

Bixyl Shuftan
 

Tuesday, February 18, 2020

"EARN IT" Bill In Congress Could Mean Bad News For Internet Freedom


By Bixyl Shuftan

There's another Internet bill in Congress that could have potentially dire consequences for privacy expectations people online take for granted. Introduced "to establish a National Commission on Online Child Exploitation Prevention, and for other purposes," the "Eliminating Abusive and Rampant Neglect of  Interactive Technologies" Act, or EARN IT, "opens the door for the government to require new measures to screen users’ speech and even backdoors to read your private communications."

According to an article in Bloomberg, "The bipartisan measure, ... would affect a wide range of social media companies, cloud service providers, email and text platforms and other technology services. It could put Facebook in the government’s crosshairs for its plans to encrypt all of its messaging apps and undercut Apple’s refusal to create back doors into its devices and services." The article would go on to say, "The Justice Department has tentatively scheduled a Feb. 19 meeting on the future of the immunity known as Section 230 of the Communications Decency Act ... The provision protects platforms from responsibility for content posted by third parties. Although the measure doesn’t directly mention encryption, it would require that companies work with law enforcement to identify, remove, report and preserve evidence related to child exploitation -- which critics said would be impossible to do for services such as WhatsApp that are encrypted from end-to-end."

Companies would have to "certify that they are following the best practices set by the 15-member commission." If they don't to its satisfaction, "they would lose the legal immunity they currently enjoy under Section 230 relating to child exploitation and abuse laws. That would open the door to lawsuits for 'reckless' violations of those laws ..."

Supporters of the bill insist the ability to read encrypted messages is necessary, saying efforts to protect encryption, “will make it harder to detect -- and stop -- child abuse and similar crimes." Elliot Harmon of the Electronic Frontier Foundation retorted that if the bill became law, "the Attorney General could unilaterally dictate how online platforms and services must operate. If those companies don’t follow the Attorney General’s rules, they could be on the hook for millions of dollars in civil damages and even state criminal penalties. ... It opens the door for the government to require new measures to screen users’ speech and even backdoors to read your private communications.

"EARN IT undermines Section 230, the most important law protecting free speech online. Section 230 enforces the common-sense principle that if you say something illegal online, you should be the one held responsible, not the website or platform where you said it. Section 230 has played a crucial role in creating the modern Internet. Without it, social media as we know it today wouldn’t exist, and neither would the Internet Archive, Wikimedia, and many other essential educational and community resources. And it doesn’t just protect tech platforms either: if you’ve ever forwarded an email, thank Section 230 that you could do that without inviting legal risk on yourself." Harmon would call the bill an attack on Internet Security, entrepreneur innovation, and just plain unnecessary.

Facebook's CEO Mark Zuckerburg has stated his company will continue to be “standing up for encryption, against those who say that privacy mostly helps bad people.” Senator Ron Wyden has openly spoken in protest about the bill, "a tired, debunked plan to blow a hole in one of the most important security features protecting digital lives of the American people."

The website fightforthefuture.org/ has a petition calling on Congress to reject the bill. As of the writing of this article, it has over 8660 of the 12,800 signatures it set as a goal.

The Justice Department is currently led by Attorney General William Barr, whom lately has been the target of calls to resign for interfering with the trial of an ally of President Trump.

Sources: Electronic Frontier Foundation, Fight for the Future, Reuters, Bloomberg, Ron Wyden

Bixyl Shuftan

Monday, July 22, 2019

Eye On The Blog: "Information About Privacy and Security in Tilia"


Last Friday, Soft Linden, Linden Lab's Information Security Manager, posted in the Tools and Technology blog, "Information About Privacy and Security in Tilia."

A large number of you attended the Tilia Town Hall  last week. Aside from the many questions you had about how Tilia affects Second Life L$ and monetary activity, privacy was a common concern. Grumpity asked if I would answer a few of the questions about Tilia privacy and security which surfaced in the town hall and in our forums.

There were four sample questions and four lengthy answers.

Where did the Tilia team come from? And why should I trust Tilia with my personal information?
 
Soft answered, "The Tilia team is made up of people you previously knew as Linden Lab employees." He called the team "passionate about privacy and security," and that many had alts in Second Life and knew many of the residents there. They also promised, "the information you store with Tilia is never provided to third parties for purposes such as marketing, " and We won’t even provide that information to the US government unless we are compelled to do so through a legal process such as a subpoena or a search warrant."
 
Does Tilia change how my information is secured?
 
In short, yes. Soft stated, "Figuratively speaking, we locked the old vault inside a bigger, stronger vault." Of the 'new vault,' it "uses modern algorithms to encrypt sensitive information in a way that would require both enormous computing power and an enormous amount of memory for an attacker to crack… if they could even get a copy of the encrypted data. These algorithms are specifically tuned to defeat expensive decryption acceleration hardware." Their existing encryption technology was called "industry standard at the time."

It sounds like a lot has changed at once. Aren’t large changes risky?

Soft answered, "Tilia was designed with security and privacy as its primary considerations." They had people, "some of our key privacy and security practices and procedures," and that they pay a security company to attempt to hack into their servers to test the m.

What does Tilia mean for Second Life privacy and security in the future?

"We have many plans for Tilia," Soft stated. They are in the process of moving "additional forms of information ... Now that we have a new privacy and security foundation, we can extend the amount of information that enjoys this level of protection. If it pertains to your real life identity, we believe in leveraging Tilia protection wherever possible." It also mentioned their goals were ensuring, "compliance with upcoming privacy and security regulations."

To check the blogpost in it's entirely, Click Here.

Bixyl Shuftan

Friday, July 31, 2015

Commentary: Windows 10's Dark Secret


Microsoft is releasing their latest version of Windows: Windows 10. In development for over two years, Microsoft calls it, "the best Windows ever." And the company is giving it out for free. So what's the catch? It seems the Operating System collects quite a bit of your data that gets sent to Microsoft. Nydia Tungsten had a few things to say about it.

Read more in Extra.

Wednesday, June 19, 2013

Real Life News and Commentary: PRISM and Internet Surveillance


As we in Second Life celebrate a decade of being online, in real life news have come some unwelcome developments for those who value computer privacy. First the NSA was found to be spying on American citizens through Verizon. Then a whistleblower exposed a once secret NSA data-collection program: PRISM.

Gizmodo's described PRISM as, "a secret Government  program that gives the NSA unprecedented access to the servers of major tech companies, which may or may not be 'direct,' so that the agency can spy on unwitting US citizens, with terrifying granularity, which is both different from and more aggressive than the Verizon scandal, and has the full (but contested) cooperation of tech giants, and which is, shockingly enough, totally legal." Why would the Internet Service Providers coooperate? Gizmodo commented, "they have no choice. Failure to hand over server data leaves them subject to a government lawsuit, which can be expensive and incredibly harmful in less quantifiable ways."

The responses from the Internet companies have been mostly varying degrees of denial that they cooperated. Apple (one of the last to submit according to the whistleblower) also claimed not only did they not store data related to company location, but that communications over iMessages and Facetime were encrypted so that not even they could read them, "Apple cannot decrypt that data."

The reaction from the public appears to be mostly negative, with some expressions of support. It is worth noting in this day of age of political warfare, some conservatives have expressed support for the President they oppose on other issues, while some liberals have come out to oppose him on this issue. The New York Times responded with an editorial, commenting "The administration has now lost all credibility on this issue." Supposedly when first aired, it read "The administration has now lost all credibility," and then was edited. That the President when a candidate opposed the surveillance programs of his predecessor and once in office not only continued to run them but expanded them, was not seen well by more than a few. Recent polls show him at an all time low.

Among the responses was this animation "United States of Surveillance" by Mark Fiore.

"The government … is so far completely unapologetic. And why wouldn't they be? It's easy enough to follow the letter of the law when you're the one writing it."

Bixyl Shuftan

Source: Wikipedia, The Guardian, Forbes, New York Times, Gizmodo,

Wednesday, April 24, 2013

CISPA Passes US House, Stalling in Senate


While the nation's attention has been on the Boston bombers and questions about their links to Islamic terrorism, computer users faced some other worries. On Thursday April 18th, the CISPA Bill passed the US House of Representatives by a vote of 288-127.

CISPA, officially named the Cyber Intelligence Sharing and Protection Act, was introduced supposedly as to help the government "investigate cyber threats and ensure the security of networks against cyberattacks." But it has been heavily criticized for being a threat to the public's right to privacy. This includes permitting authorities to search databases without warrants, and Internet service providers would be banned from making "legally binding" promises to protect users' privacy.

Fortunately for privacy activists, the bill's future is iffy, at least for the short term. The Senate has been preoccupied with other issues such as immigration and the right to buy firearms. The White House has also threatened to veto the bill if concerns about privacy issues were unanswered, "Citizens have a right to know that corporations will be held accountable, and not granted immunity, for failing to safeguard personal information adequately … " This is a similar course to what happened in 2012, and the bill was never taken up by the Senate that year.


Sources: ABC News (Chicago) , CNet, Wikipedia

Bixyl Shuftan

Wednesday, February 27, 2013

"Six Strikes" Internet Rule Likely Installed Monday


By Bixyl Shuftan

Internet Privacy activists expressed worry when on Monday February 26, the "Six Strikes" rule was set to go into effect. Devised last year, the rules involve the "Copyright Alert System" set up by the following Internet Service Providers: AT&T, Cablevision, Comcast, Time Warner Cable, and Verizon.

Under the system, copyright owners are supposedly alerted to people downloading their content without permission, and they can alert the ISPs to the people targeted by the system. The first alerts are warnings. After a few warnings come "mitigation alerts" which depending on the ISP results in temporary reductions in Internet speed, a downgrade in the service tier, redirection to a page for a period of time, or other measures. After six alerts, there are no more, but each supposed violation is recorded in case the matter is taken to court.





Critics point out that the system is imperfect, that in wireless Internet "hot spots" that an innocent user could potentially be tagged as illegally downloading even if he/she wasn't as open wi-fi signals allow for their IP address to be used by others. Also, there are methods for determined pirates to avoid the system, such as cyberlockers, streaming sites, offline swapping, and others. Then there are privacy issues. Electronic Frontier Foundation director Corynne McSherry called Six Strikes, "just a great big expensive system to snoop on and intimidate people" whom she felt were mostly behaving themselves. She called it's recording of violations, "a private copyright system, and it doesn't have the protections and balances that the public copyright system has." It has also been noted that the system's software to identify copyright violations was inspected and approved by a former lobbyist of the Recording Industry Association of America (RIAA).

In early 2012, RIAA was among those trying to get the US Congress to pass the SOPA bill, which alarmed critics who stated it's vague language threatened to shut down the Internet as we know it. It was in the months following it's defeat that the Copyright Alert System and Six Strikes was set up. It was supposedly to be enacted in late 2012, but was delayed by the damage from Hurricane Sandy.

Sources: The Guardian, Torrentfreak.com, Theverge.com

Bixyl Shuftan

Monday, April 30, 2012

CISPA Internet Bill Passed in US House

According to Forbes.com, the CISPA Internet bill, which sparked privacy worries among numerous Internet freedom advocates, was passed in Washington. "In an earlier-than-expected vote Thursday evening, the House of Representatives voted 248 to 168 in favor of the bill."

According to writer Andy Greenman, Trevor Timm, a lawyer and activist with the Electronic Frontier Foundation, felt, "the House’s early vote on CISPA as an attempt by its author, representative Mike Rogers, to squeeze the bill through before its opposition grew any stronger." The bill was also amended before passage, "the House voted to amend the bill to actually allow even more types of private sector information to be shared with government agencies, not merely in matters of cybersecurity or national security, but in the investigation of vaguely defined cybersecurity 'crimes,' 'protection of individuals from the danger of death or serious bodily harm,' and cases that involve the protection of minors from exploitation." It was a move that raised further concerns from opponents. Techdirt.com's Leigh Beadon called it "an absolutely terrible change."

"Somehow, incredibly, this was described as limiting CISPA, but it accomplishes the exact opposite," Beadon wrote, "CISPA is now a completely unsupportable bill that rewrites (and effectively eliminates) all privacy laws for any situation that involves a computer. Far from the defense against malevolent foreign entities that the bill was described as by its authors, it is now an explicit attack on the freedoms of every American."

The bill still has to be passed in the Senate before heading to the White House, which has come out against it recently. Timm saw hope it would be beaten, "We’ve seen an explosion of a variety of groups and congressmen coming out against the bill,” he says. “As the Senate debates this, it’s good that privacy and civil liberties will be front and center.”

Sources: Forbes.com, Techdirt.com

Bixyl Shuftan

Friday, April 27, 2012

SOPA Act Two? CISPA to be Decided in US House as Soon as Today


Remember the mess over SOPA in December and January? This proposed law had the potential for becoming "The Great Firewall of America," possibly meaning the end of favorite places online such as Youtube, Facebook, and Second Life. Despite a Congress seemingly poised to approve it, opposition to it and it's sister bill PIPA grew in numbers. The backers of SOPA eventually shelved it from a vote, and the opponents had seemingly won.

However, a new bill, H.R. 3523,  has made it through committee: the "Cyber Intelligence Sharing and Protection Act," or CISPA. Intended to "allow the voluntary sharing of attack and threat information between the U.S. government and security cleared technology and manufacturing companies to ensure the security of networks against patterns of attack," the bill "has been criticized by advocates of Internet privacy and neutrality, such as the Electronic Frontier Foundation … because they feel it contains too few limits on how and when the government may monitor private information when it might become collaterally entangled in the process of passing threat information, and too few safeguards with respect to how the data may be used; they fear that such new powers may be used to find and punish file sharers and copyright infringers rather than the stated foreign spies or hackers."

An article in Forbes.com describes opposition to the bill as mounting, "On Monday, a group of more than fifty professors, entrepreneurs and information security professionals published an open letter to Congress calling on lawmakers to oppose CISPA and other overbroad cybersecurity bills like the SECURE IT Act … CISPA has a very different focus from SOPA and PIPA, the much-loathed antipiracy bills killed by a similar groundswell of Internet anger in February. Whereas SOPA and PIPA raised fears of censorship, CISPA’s vague data-sharing statutes are largely seen as a threat to privacy, although some are also interpreting the bill as allowing site blocking. And whereas SOPA pitted Silicon Valley against Hollywood, CISPA seems to have the support of many technology and Web-based companies, including Facebook, Microsoft, Symantec, and IBM."

Tim Berners-Lee, the inventor of the Web, spoke last week the bill "is threatening the rights of people in America, and effectively rights everywhere." Senator Ron Paul spoke out against the bill, saying it would make "government spies of Facebook and Google." Eighteen House Representatives signed a letter opposing the bill, at least in its current form. The White House has also come out against CISPA. Avaaz.org has a petition against the bill with three-quarters of a million signatures, with the goal of making it a million. Reddit has a number of "anti-CISPA discussions."

CISPA is expected to be voted on in the House of Represenatives today.


Sources: Wikipedia, Forbes.com, Electronic Frontier Foundation, Avaaz.org, Reddit,

Bixyl Shuftan