Web Meets World: Privacy and the Future of the Cloud
-
Upload
gnat -
Category
News & Politics
-
view
14.210 -
download
1
description
Transcript of Web Meets World: Privacy and the Future of the Cloud
![Page 2: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/2.jpg)
Stories About The Present
Thank you. Hello, everyone. Before I talk about the future of the cloud, I’d like to begin with a few stories about the present.
![Page 3: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/3.jpg)
(1)
First story.
![Page 4: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/4.jpg)
AOL
America OnLine. In August 2006, AOL released
![Page 5: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/5.jpg)
20,000,000650,000
20M web queries from 650k users, sampled over three months, to help researchers improve the state of search technology. AOL claimed that the data had been
![Page 6: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/6.jpg)
anonymized
anonymized by turning usernames into unique IDs. However many searches contained identifying information such as
![Page 7: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/7.jpg)
addresses
addresses,
![Page 8: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/8.jpg)
names
names,
![Page 9: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/9.jpg)
e-mail messages
and even e-mail messages. The New York Times was able to identify, for example, user
![Page 10: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/10.jpg)
4417749
4417749 as
![Page 11: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/11.jpg)
4417749Thelma Arnold
Thelma Arnold of
![Page 12: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/12.jpg)
4417749Thelma ArnoldLilburn, Georgia
Lilburn Georgia, who has an interest in
![Page 13: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/13.jpg)
4417749Thelma ArnoldLilburn, Georgianumb fingers
numb fingers
![Page 14: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/14.jpg)
4417749Thelma ArnoldLilburn, Georgianumb fingers60 single men
60-ish single men, and
![Page 15: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/15.jpg)
4417749Thelma ArnoldLilburn, Georgianumb fingers60 single men
dog that urinates on everything
dogs that urinate on everything. The Times went to visit her and ran a great caption to the photo accompanying the story:
![Page 16: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/16.jpg)
On the subject of AOL, remember that they
![Page 17: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/17.jpg)
tried
tried to anonymize. The privacy loss, while you and I might think it was predictable, wasn’t
![Page 18: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/18.jpg)
deliberate
deliberate. Shit, as they say, happened.
![Page 19: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/19.jpg)
(2)
Second story
![Page 20: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/20.jpg)
Google. They collect a lot of data about people:
![Page 21: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/21.jpg)
searches
searches,
![Page 22: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/22.jpg)
ad impressions
ad impressions,
![Page 23: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/23.jpg)
clickthroughs
clickthroughs,
![Page 24: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/24.jpg)
![Page 25: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/25.jpg)
chat messages
chat messages
![Page 26: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/26.jpg)
documents
documents
![Page 27: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/27.jpg)
spreadsheets
spreadsheets
![Page 28: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/28.jpg)
presentations
presentations,
![Page 29: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/29.jpg)
addresses
addresess
![Page 30: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/30.jpg)
medical records
medical records, and more.Fortunately Google know that all this data can be dangerous, and take steps to safeguard the
![Page 31: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/31.jpg)
privacy
privacy of their users. In February 08 they posted to the Google Blog saying they would
![Page 32: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/32.jpg)
cookie
shorten cookie lifetimes
![Page 33: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/33.jpg)
two years
to a mere two years, and
![Page 34: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/34.jpg)
anonymize
anonymize their search logs
![Page 35: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/35.jpg)
two years
after 18-24 months. It didn’t take long for these steps to be shown up as
![Page 36: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/36.jpg)
good enough
not good enough. You see, another Google property,
![Page 37: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/37.jpg)
YouTube
YouTube, which serves
![Page 38: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/38.jpg)
1,000,000+
more than a million videos every day, came under attack.
![Page 39: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/39.jpg)
Viacom v Google
by Viacom, parent company of Paramount, Dreamworks, MTV, and Nickelodeon. In March 2007, Viacom sued Google over YouTube claiming that its copyrighted TV shows were available on YouTube and that Google wasn’t doing enough to prevent this unauthorised copying and distribution.
![Page 40: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/40.jpg)
U.S. District JudgeLouis L. Stanton
In July this year, five months after Google announced their “anonymize after two years” policy, U.S. District Judge Louis L. Stanton granted a motion to give Viacom
![Page 41: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/41.jpg)
“the motion to compel production of all data from
the Logging database concerning each time a YouTube video has been viewed on the YouTube
website or through embedding on a third-party
website is granted”a copy of the YouTube access logs. This information includes:
![Page 42: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/42.jpg)
IP addresses
your IP address
![Page 43: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/43.jpg)
YouTube username
your YouTube user name
![Page 44: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/44.jpg)
time of day
the time of day you
![Page 45: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/45.jpg)
which videos
watched a particular video.While you and I might be as horrified as Google was, the Judge said
![Page 46: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/46.jpg)
“privacy concerns are speculative”
privacy concerns are
![Page 47: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/47.jpg)
“privacy concerns are speculative”
Speculative.
And he quoted a line from that blog post made back in February ’08, where Google said that an IP address
![Page 48: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/48.jpg)
“The reality is though that in most cases, an IP
address without additional information cannot [identify you]”
- Google Blog, Feb ‘08
alone isn’t identifying information.
Fortunately Viacom are on top of the privacy concerns raised by their request for YouTube logs. They say they will limit access to the data
![Page 49: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/49.jpg)
“is going to be limited to outside advisers who can
use it solely for the purpose of enforcing our rights against YouTube and
Google”- Michael D. Fricklas, Viacom’s general counsel
to Viacom’s advisers. Whew, thank you Viacom. And thank you, Google, for choosing to retain that data and only anonymize after two years!
![Page 50: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/50.jpg)
(3)
Now let’s look at Europe.
![Page 51: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/51.jpg)
Directive 2006/24/EC
On March 15, 2006, the EU adopted Directive 2006/24/EC. This mandates
![Page 52: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/52.jpg)
“the retention of data generated or processed in
connection with the provision of publicly available electronic
communications services or of public communications
networks”the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks.
![Page 53: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/53.jpg)
6 months-
2 years
For anywhere between 6 months and 2 years, depending on the type of data. Fortunately it only covers
![Page 54: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/54.jpg)
telephony, mobile telephony, Internet access, Internet email and Internet
telephony.
telephony, mobile telephony, Internet access, Internet email and Internet telephony. Member states have the option to delay the Internet bits until March 2009 and most have opted to delay. Member states also have the option to go beyond the EU recommendations, as
![Page 55: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/55.jpg)
.dk
Denmark has chosen to do. Their draft provision enacting the EU order would require ISPs to log the
![Page 56: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/56.jpg)
source
source
![Page 57: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/57.jpg)
time
time, and
![Page 58: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/58.jpg)
destination
destination of
![Page 59: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/59.jpg)
every single internet data packet
every single Internet data packet. I’m reasonably confident this is impossible, but it does show the ambitions of the states here. The states are all confident that the data won’t be
![Page 60: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/60.jpg)
“misused”
misused, but don’t defined “misuse”.I won’t define “misuse” either, but will simply note that Germany makes their logs available for prosecutions under
![Page 61: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/61.jpg)
©
civil copyright law so that Disney will be able see when you logged in and who you spoke to.
![Page 62: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/62.jpg)
Ok, that’s the end of the stories.
![Page 63: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/63.jpg)
common
What did they all have in common?
![Page 64: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/64.jpg)
Cloud
They’re all about the cloud. Or, rather, the
![Page 65: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/65.jpg)
“Cloud”
“the cloud” (air quotes). It’s a broad and popular term, and like all broad popular terms it’s become more of a buzzword to get venture funding, or to sound like you know what you’re talking about than a useful marker of technological progress.
![Page 66: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/66.jpg)
“Cloud” = On Demand + Utility Computing + SOA
+ ASP + SaaS + ...
It covers a multitude of sins. We talked about Software As A Service (YouTube), and that’s a real trend. Lots of different types of software are moving into “the cloud”.
![Page 67: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/67.jpg)
Meet Google Healthcare. Patients upload their medical records and get a friendly useful interface for checking drug interactions, etc. The privacy aspect to this is a little odd, though.
![Page 68: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/68.jpg)
Google Healthcare slips through a crack in the medical record legislation in the USA--because they’re not holding records on behalf of providers, no security is mandated. The expectation is that the market will determine an appropriate level of security. Hoorah for the market!And as we all know, markets immediately find the appropriate level of security with no incentive to provide too little. And fortunately there can be no privacy problems flowing from an inadequate level of security. Right? Right?
![Page 69: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/69.jpg)
Salesforce.com is Customer Relationship Management--salespeople and their managers can keep track of contacts, accounts, etc. online. You know, “Joe at IBM buys widgets, here’s his name and address and a record of every conversation that anyone in the company has had with him”.
![Page 70: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/70.jpg)
Google Mail.
![Page 71: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/71.jpg)
Here’s mint.com, one of several web-based apps playing in Quicken’s back yard. They fetch your bank statements from your bank, process them, and tell you where you’re spending your money.
![Page 72: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/72.jpg)
Utility Computing
That was software as a service.Another aspect to the cloud is utility computing, such as
![Page 73: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/73.jpg)
Amazon Web Services
Amazon’s web services. They offer many services over the web that have nothing to do with books, including
![Page 74: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/74.jpg)
Amazon EC2
their “Elastic Compute Cloud”, EC2. You upload a virtual machine image (think: copy of a hard drive) and Amazon runs it for you. No longer do you have to worry about managing bandwidth, installing operating systems on servers, replacing hard drives, and all the stuff that IT departments used to have to do. Consequently
![Page 75: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/75.jpg)
many people have build their companies on EC2 and its sister storage service, S3. Many of these are startups, attracted because it lets them scale without substantial investment, but many EC2 customers (Eli Lilly, for example) are sizable. Amazon’s services are getting a lot of use,
![Page 76: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/76.jpg)
as this graph shows. Amazon’s Web Services overtook Amazon.com, in amount of traffic, in mid-2007, just 18 months after launch.
![Page 77: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/77.jpg)
Google also have a utility computing play: you write your program to run on their environment and away you go, all of Google’s more than 2 million servers are yours for the using. Like Amazon, you’re charged by the CPU-hour.
![Page 78: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/78.jpg)
Microsoft are getting into the game as well, with their Live platform. According to a recent Economist article, they’re rolling out.
![Page 79: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/79.jpg)
35,000/month2,500/container
$500M/data centre
35,000 new servers every month in data centers. They’re building the data centers from 40-foot shipping containers that each house 2,500 servers. The new data center in Chicago cost $500M. These numbers aren’t unusual for the industry.
![Page 80: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/80.jpg)
“Cloud”
What does Utility Computing and Software as a Service have in common? What unites Google Apps, your ISP, Amazon EC2, and Salesforce.com?
![Page 81: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/81.jpg)
SEP
They all add up to the same thing: they make computing
![Page 82: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/82.jpg)
Someone Else’s Problem
someone else’s problem. It’s
![Page 83: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/83.jpg)
Outsourced IT
Outsourced IT. Every program on every machine is a pain in someone’s ass. IT departments must keep the versions up to date, deal with bitrot (when Windows stops working and everything has to be reinstalled), etc. Using Google Docs means all the administrative hassle of Microsoft Office has become Google’s problem. And part and parcel of outsourced IT is
![Page 84: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/84.jpg)
Outsourced Security
outsourced security. It’s a pain in the bum locking down machines and applications against
![Page 85: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/85.jpg)
Hackers, Viruses, et al.
bad guys. Every IT department asks itself “can Google do a better job of this than I can?” and probably answers, correctly, “yes”.
![Page 86: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/86.jpg)
Privacy & Security
But because there’s a strong relationship between privacy and security, namely it’s impossible to have privacy without good security,
![Page 87: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/87.jpg)
Outsourced Privacy
using Google Docs means that we’ve outsourced privacy as well.
![Page 88: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/88.jpg)
Where’s the problem?
Many people ask “so what?” when you tell them that they’ve outsourced their privacy. “Google will look after me, right?” they say. There are two reasons why this isn’t necessarily true.
![Page 89: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/89.jpg)
(a) Google decides
First, Google’s gets to decide how much security to put around your data, and have no doubt--it is a decision. There’s always
![Page 90: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/90.jpg)
the next threat
another threat to defend against. If you’re looking for
![Page 91: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/91.jpg)
perfect security
perfect security, then
![Page 92: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/92.jpg)
perfect security
you might as well look for perfect happiness. There is no such thing as perfect security, just acceptable levels of risk. Your company makes decides upon that acceptable level every time they decide not to train their IT staff in the latest security practices, every time they choose between one antivirus product and another, every time they decide not to buy a $75,000 network security appliance. That’s perfectly normal. What’s different in the world of the cloud, though, is that
![Page 93: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/93.jpg)
decide
you don’t get to decide. Your vendor does. And no vendor will tell you all the security precautions and procedures they have. Their security is
![Page 94: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/94.jpg)
opaque
opaque. Few vendors even report incidents, and even fewer countries have mandatory reporting laws. So you’re asked to make a security (and thus privacy) decision on the basis of imperfect, or even absent, information. That’s the first reason that outsourced privacy isn’t all good.
![Page 95: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/95.jpg)
(b) Gubmint = Black Hats
The second reason is that it’s not just rogue teenagers hellbent on getting your credit card details that you have to worry about. As the EU directive clearly show, governments are black hats, bad guys. They just have
![Page 96: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/96.jpg)
subpoena / court order / search warrant / request
different attack vectors from those of your average 21 year old Ukrainian virus writer. And as
![Page 97: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/97.jpg)
YouTube ViacomusernamesIP addresses
Viacom’s logfile data grab shows, many private companies have learned to piggyback on the judicial and legislative’s attack vectors.
![Page 98: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/98.jpg)
Warshak v USA
The situation’s even worse in the USA. Until now there have been two standards for searching your records:
![Page 99: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/99.jpg)
constitutional
Constitutional, preventing unreasonable search and seizure, which covers stuff in your home. Constitutional protections are hard to circumvent, as they were written by angry 18th century revolutionaries and tend to be quite explicit in their distrust of government. The other protection is
![Page 100: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/100.jpg)
statutory
statutory, the laws that fill the gaps in the Constitution. Statutory protections guard your data outside the home
![Page 101: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/101.jpg)
statutory = weaker
and generally require law enforcement to have less justification than do the constitutional standards. This difference between two standards means law enforcement can more easily intercept your data outside the home than in it -- bad news for hosted apps like Google Docs, Mail, etc. Let me go over this again:
![Page 102: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/102.jpg)
data in the home
if you download your mail to your laptop and keep it there,
![Page 103: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/103.jpg)
data in the home
SAFE!
the police need a search warrant to get to it, and the burden of probable cause that goes with it. But if you use Gmail and
![Page 104: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/104.jpg)
data in the cloud
keep your mail on Google’s servers,
![Page 105: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/105.jpg)
data in the cloud
PWNED!
and the police need only a court order, which has a much lower hurdle to clear. A recent lawsuit,
![Page 106: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/106.jpg)
Warshak v USA
Warshak v USA has lead to a ruling that the two should be treated the same (and Constitutional standards should apply to getting data from ISPs). It’s bouncing around appeals at the moment, and the double standard will continue until and unless it’s resolved in Warshak’s favour.
![Page 107: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/107.jpg)
“Relying on the Government to ensure
your privacy is like asking a peeping Tom to install your window blinds.”
- John Perry Barlow
In short, security and privacy are as much threatened by legal and regulatory means as by viral and Trojan.
![Page 108: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/108.jpg)
But that’s enough about the past. Let’s get back to the Future of the Cloud.
![Page 109: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/109.jpg)
Future of the Cloud
Did you hear those capitals? Futurism needs capital letters. I don’t plan to make predictions about
![Page 110: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/110.jpg)
CO2-burning flying cars we’ll all be driving, or
![Page 111: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/111.jpg)
the silver robots that will do our bidding. All I do is identify
![Page 112: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/112.jpg)
trends
trends, growing numbers of similar things done by people who live on the cutting edge of what’s possible with today’s technology, because Alan Kay knew how to do futurism:
![Page 113: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/113.jpg)
“The best way to predict the future is to invent it.”
- Alan Kay
He invented object-oriented programming, the the windowing system, pulldown menus, GUIs and computer interfaces as we know them today basically. So I look for people or projects that seem to be to be inventing the future. Here are a few.
![Page 114: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/114.jpg)
Let’s start in an unlikely place: the foot. The Nike+ is a shoe with a accelerometer that counts steps. It communicates with an iPod and syncs your running record to a web site. People who use it report a new way of thinking about their run: it’s become a
![Page 115: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/115.jpg)
“My run is now a videogame, and I want you to play with me.”
- Jane McGonigal
video game. You can have collaborative and competitive challenges and you get virtual trophies. Now many pieces of gym equipment can also report to the iPod, so people can track their treadmill, cross-trainer, and bike miles on the same web site as they keep track of their running.
![Page 116: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/116.jpg)
Or take the Amazon Kindle. This is an electronic book reader--super high resolution screen, keyboard, and all that but the main innovation behind it is cellular connectivity. You don’t buy a network contract when you buy the Kindle, but the books you buy (from Amazon.com, naturally) arrive via the cellular data network. Introduced a year ago, Amazon will have sold 380,000 of them by the end of this year.
![Page 117: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/117.jpg)
This is the Wattson. It’s a power meter that reports the information to you, not just the power company. This is the display, there’s also a transmitter that clips onto a mains cables. There’s companion software, Holmes, that uploads your energy usage to the Holmes web site and lets you track and compare over time.
![Page 118: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/118.jpg)
This is Botanicalls, a gizmo that sends Twitter updates when your plants need watering. What you see is a sensor that clips into the potplant’s soil and a network cable to send the updates.
![Page 119: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/119.jpg)
Andy Stanford-Clark, an IBM “Master Inventor”, has instrumented his house and hooked it up to Twitter. You can follow his house and see his power consumption, when the phone rings, when the motion-sensitive lights turn on and off, etc.These people use Twitter, by the way, because Twitter runs a free SMS gateway in the USA and so it has become a cheap and easy way for programs to send SMS. For example,
![Page 120: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/120.jpg)
Former Apple engineer Gordon Meyer hooked his doorbell up to Twitter. Now, no matter where he is, he knows if his doorbell is ringing.
![Page 121: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/121.jpg)
This is the Availabot by Matt Webb and Jack Schulze. It’s a little toy that plugs into your USB port and stands to attention whenever a particular instant message buddy comes online.
![Page 122: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/122.jpg)
These researchers from Iowa State University are holding sensors that will help farmers understand nutrient and water flow in their soil. They’re 2 inches by 4 inches at the moment and will live underground, communicating wirelessly with a central computer.
![Page 123: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/123.jpg)
WineM is a prototype of a smart wine rack: a reader senses the RFID tags on bottles and uses lights to display the type of wine so you don’t have to turn the bottle to check the label. When you add a new bottle to your collection, the hardware scans the UPC code and uses public databases to translate that into a variety of wine--no keyboard necessary.
![Page 124: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/124.jpg)
This is a MobileTEEN GPS unit. AIG, before they needed bailing out, offered a Teen GPS insurance. In exchange for lower premiums (anyone here tried to insure a teenage driver lately? You know what I’m talking about) your teen (or their car) must carry this GPS device around, which reports their location back to AIG. You can tell AIG’s web site to SMS you if your teenager speeds, and you can even set up a GeoFENCE (that’s a registered service mark, by the way) and it’ll SMS you if they leave that area.
![Page 125: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/125.jpg)
This is the Dash mobile GPS unit for your car. It has a cellular network card in it, and uploads your location to the Dash servers. In return, you get incredibly accurate up-to-the-second traffic information as reported by the Dash units of the other cars in the city.
![Page 126: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/126.jpg)
This is the next President of the United States of America, using his Blackberry. The Blackberry is a mobile phone with email, it lets you send and receive email no matter where you are. The latest news is that Obama will have to give up his Blackberry because the emails will be a matter of public record, and because it’s not a good idea for a cellphone company to have a database in which can be easily found the location of the President of the United States of America.
![Page 127: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/127.jpg)
Ok, enough examples.
![Page 128: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/128.jpg)
Common?
What do these devices have in common?
![Page 129: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/129.jpg)
Web meets World
They all connect the Internet to a physical device, whether it’s a potplant, a teenage driver, or a book. In some cases the devices are
![Page 130: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/130.jpg)
sensors
sensors, reporting back speeds, power consumption, Nitrogen concentration. In other cases the devices are
![Page 131: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/131.jpg)
displays
displays, reflecting the state of the networked data: whether your friend is online or which books you have paid for. But in none of these cases is
![Page 132: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/132.jpg)
dumb device
the device dumb. We’re entering an age of
![Page 133: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/133.jpg)
smart devices
smart devices, where
![Page 134: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/134.jpg)
everything
everything
![Page 135: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/135.jpg)
will be
will be
![Page 136: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/136.jpg)
networked
networked. Not because it’s cool and trendy but because
![Page 137: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/137.jpg)
the network
the network
![Page 138: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/138.jpg)
makes
makes
![Page 139: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/139.jpg)
the device
the device
![Page 140: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/140.jpg)
better
better,or because
![Page 141: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/141.jpg)
the device
the device
![Page 142: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/142.jpg)
makes
makes
![Page 143: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/143.jpg)
the network
the network
![Page 144: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/144.jpg)
better
better.You might be thinking this is all sounding a bit
![Page 145: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/145.jpg)
science fiction
science fiction. You’re right, there are a few science fiction authors who have done a great job of predicting the near future. One of them,
![Page 146: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/146.jpg)
William Gibson
William Gibson, was interviewed by Rolling Stone on their 40th anniversary. He was asked about the major challenges we faced, and he identified
![Page 147: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/147.jpg)
ubiquitous computing
ubiquitous computing, this idea that everything is connected all the time. He said:One of the things our grandchildren will find
![Page 148: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/148.jpg)
quaintest
quaintest about us is that we distinguish
![Page 149: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/149.jpg)
the digital
the digital from
![Page 150: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/150.jpg)
the real
the real,
![Page 151: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/151.jpg)
the virtual
the virtual, from
![Page 152: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/152.jpg)
the real
the real
![Page 153: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/153.jpg)
literally impossible
In the future, that will become literally impossible
![Page 154: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/154.jpg)
cyberspace
The distinction between cyberspace and
![Page 155: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/155.jpg)
! cyberspace
that which isn't cyberspace is going to be
![Page 156: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/156.jpg)
unimaginable
unimaginable.But you don’t have to look to science fiction to see that as we go through life today, we leave
![Page 157: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/157.jpg)
invisible traces
invisible traces of our presence,
![Page 158: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/158.jpg)
data trails
data trails that linger behind us like contrails in the air after the plane has disappeared from sight. You know we do it now: we leave trails in
![Page 159: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/159.jpg)
credit card
credit card databases,
![Page 160: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/160.jpg)
phone calls
phone company databases,
![Page 161: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/161.jpg)
ISPs
ISP databases. But when we pay cash, or visit someone in real life, or use a payphone, we can
![Page 162: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/162.jpg)
go off the grid
go off the grid, be
![Page 163: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/163.jpg)
anonymous
anonymous. But as the web meets the world, this will be harder and harder to do. Each new
![Page 164: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/164.jpg)
service = database
service is backed by a database, and that database is vulnerable to
![Page 165: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/165.jpg)
Viacom
bad guys,
![Page 166: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/166.jpg)
Directive 2006/24/EC
governments, and
![Page 167: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/167.jpg)
AOL
incompetence. I know it sounds grim, but it’s
![Page 168: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/168.jpg)
BADnot all bad.
![Page 169: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/169.jpg)
easy
It’s not easy, but it’s not bad.There are three things that would make a lot of these problems go away.
![Page 170: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/170.jpg)
(0) Don’t collect it
The most obvious solution is simply not to collect the data in the first place. A lot of these advertising-driven companies are packrats--think of Google and the two year lifetime of unanonymized data (after the Viacom ruling, by the way, they announced they were changing those two-year lifetimes to nine months). They keep this data because it might be useful to their future selves and not for you or your future self.
![Page 171: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/171.jpg)
(1) Same goals
Next, vendors should have the same goals as you do. Amazon does: when you run your web site on EC2, you’re paying Amazon for that service. Amazon isn’t mining what you do and they’re not storing your data for later use. Google’s business model, however, is advertising. So you get GMail and it looks like it’s free, but the price you pay is Google’s data collection.
![Page 172: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/172.jpg)
(2) Cryptography
Finally, your data should be encrypted in such a way that the service provider can’t decrypt it without you. We can do this technically, but few companies do it in practice.
![Page 173: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/173.jpg)
problems
But there are problems with these solutions, and they cut to the heart of what’s so attractive about the very things that could threaten privacy:
![Page 174: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/174.jpg)
0) data makes services better
It’d be sad if Google weren’t to collect data because the data that Google collects makes its services better. And we benefit when this happens. Yes, it makes Google rich, but it also makes the Internet navigable, our email spam-free, and fills the world with unicorns and rainbows.
![Page 175: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/175.jpg)
1) free is cheap
Aligning interests is all very well, but advertising business models make services free that would otherwise be a direct cost. We can all host our domains and our email on Google without paying a cent, whereas ISPs typically charge for it. Aligning Google’s interests with our privacy interests may damage our pecuniary interests. And, finally,
![Page 176: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/176.jpg)
(3) shared data makes individual experiences
better
If you encrypt personally-identifying data, you make it very difficult to create those sites that crunch everyone’s data and make suggestions or recommendations. If the Holmes web site can’t see the power use of my Wattson, how can I compare myself to other people?
![Page 177: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/177.jpg)
impossible?
So is it impossible to do this right? To respect privacy yet have a cloud application?
![Page 178: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/178.jpg)
impossible?
No, there are companies trying hard to do it right. For example,
![Page 179: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/179.jpg)
Wesabe is a Quicken-like program on the web, like Mint. These guys get privacy right. First, they don’t hold the keys to your Internet banking to download them: you run an uploader on your PC that fetches your electronic statements from the bank and then sends them to Wesabe. Second, Wesabe encrypt your personal data so your records can’t be subpoena’d because your records can’t be tracked back to you. Third, it’s a commercial service and not advertising supported--your best interests are their best interests. And finally, Wesabe still manages to provide collective intelligence (you’re not saving as much as everyone else, for example). I contract to O’Reilly Media, who invested in Wesabe precisely because they get this so right.
![Page 180: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/180.jpg)
So here we are, nearly to the end. What did we learn?
![Page 181: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/181.jpg)
(1) Web meets World
Physical devices are being integrated with the Web, or “cloud” if you will
![Page 182: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/182.jpg)
(2) Data in the cloud can be a privacy problem
Data in the cloud can be a privacy problem, because
![Page 183: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/183.jpg)
(3) You’ve outsourced privacy
you’ve outsourced your privacy, so you’re vulnerable to attack not just from hackers but also from
![Page 184: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/184.jpg)
(4) Governments
governments,
![Page 185: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/185.jpg)
(5) Competitors
competitors, and
![Page 186: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/186.jpg)
(6) Incompetence
AOL. And while it is possible to build useful services while
![Page 187: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/187.jpg)
(7) Choose not to collect
choosing not to gather some data,
![Page 188: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/188.jpg)
(8) Cryptography
encrypting the data you do collect, and
![Page 189: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/189.jpg)
(9) Aligning interests
making sure that your service provider doesn’t have a motive to undermine your privacy ...
![Page 190: Web Meets World: Privacy and the Future of the Cloud](https://reader034.fdocuments.us/reader034/viewer/2022052617/54584d93b1af9f40378b50d3/html5/thumbnails/190.jpg)
easy
It’s not easy. Thank you, I’ll now take