Making privacy useable - wearecube.ch · EuroIA 2016 Philipp Murkowsky @pmurkowsky. A thought...

Post on 21-Jun-2020

0 views 0 download

Transcript of Making privacy useable - wearecube.ch · EuroIA 2016 Philipp Murkowsky @pmurkowsky. A thought...

Makingprivacyuseable

EuroIA2016PhilippMurkowsky@pmurkowsky

Athoughtexperiment

Whoknows,thatIamcurrentlyhere,inAmsterdam,atEuroIA,inthisveryroom?

Weliveinthegoldenageofinformation...

...butwealsoliveinthedarkageofomnipresent

surveillance.

Surveillanceenablespersonalization

TargetedAdvertisingTailoredSearchResultsFilteredContentDifferentialPricing

Aretheusersawareofthis?

Yes,theyare!

PublicPerceptionsofPrivacyandSecurityinthePost-

SnowdenEraPewResearchCenter,2014

91%ofAmericansbelievethatconsumershavelostcontroloverhowpersonalinformationiscollectedandusedbycompanies.

64%believethegovernmentshoulddomoretoregulateadvertisers.

80%areconcernedaboutthegovernment’smonitoringofphonecallsandinternetcommunications.

Morethan80%ofrespondentsfeelthattheydonothavecompletecontroloverthepersonaldatatheyprovideonline.

Two-thirdsoftheserespondentsareconcernedaboutthis.

Respondentsaremostconcernedabouttherecordingoftheiractivitiesviapaymentcardsandviamobilephones.

Butwhataretheusersdoing?

Theyagree!

Only20%oftherespondentsfullyreadprivacystatements.

Mostrespondentsdonotreadthesestatementsbecausetheyfindthemtoolongtoread,unclearortoodifficulttounderstand.

Source:PrivacyMatters,2015

The"HerodClause"Experiment

Source:F-Secure,2014

Thelieillusionof"informedconsent".

Manyprivacypoliciesprotectthecompanies,nottheusers.

Takeitorleaveit!

Providingpersonalinformationisanincreasingpartofmodernlife.

Lostintransaction

Iagree!

Lostintransaction

Getoutofmyway!

Convenienceisking!

AvailabilitySynchronizationIntegrationNetworkEffects

Userscareaboutdata,butnotaboutmetadata

Metadataisahidden,yetunavoidableby-productofanydigitaltransaction.

Metadataismucheasiertoprocessandanalyzethanthedataitself.

Surveillanceiscovert

Systemsaredesignedtoshowusthe"value",butnotthecostofit.

Whatcanwedotoincreaseprivacy?

1. Legislation2. Corporations3. Users

Surveillanceisnotinevitable

Weprobablycan'tgetprivacyonatechnicallevel,butwecangetitonalegallevel.

Betransparent

Alabelforprivacy?

Enableuserstoopt-out

Andwhatcantheusersdo?

Notmuch,becausetheydonotcontroltheirdata.

Tomakeprivacyconvenient,wehavetodoitbehindthescenes.

Observeanddebate

Image:thewebcamcovers.com

Thankyou!

@pmurkowsky

FurtherSourcesBruceSchneier(2015).DataandGoliath.W.W.Norton&Company

BruceSchneier:DataIsaToxicAsset

BruceSchneier:DataandGoliath-TalksatGoogle

https://www.schneier.com/blog/archives/2016/03/data_is_a_toxic

https://www.youtube.com/watch?v=GhWJTWUvc7E