nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
July 2020
- 34 participants
- 165 messages
The Guardian view on Facebook and democracy: real and present danger | Editorial | Opinion | The Guardian
by Alberto Cammozzo
<https://www.theguardian.com/commentisfree/2020/jul/05/the-guardian-view-on-…>
In every political debate since Facebook began to dominate democracy, the company has placed itself on the wrong side of history. The social media firm cannot be reformed from within because its business model profits from hosting bomb-throwing circuses of hate, humbug and hogwash. The platform harvests users’ personal data to algorithmically recommend content but can’t seem to help steering people towards vilifying one another while keeping their attention. It is not good for society, but it is good for Facebook.
That apparently is fine for the company’s founder, Mark Zuckerberg, who is worth $85bn. Consider the latest ugly episode in the firm’s life. After some of the world’s biggest brands boycotted Facebook over its refusal to ban racist and violent content, the company reached for the usual bromide of reassurance that the matter was being taken seriously. Internally it was a very different story. The boycotters, Mr Zuckerberg said, would be back and his company was “not going to change our policies … because of a threat to a small percent of our revenue”.
In America there is a view that capitalism fixes things. In Britain, government usually acts. The Lords select committee on democracy and digital technologies last week was correct to say it was a mistake to allow social media firms to grow unimpeded by regulation. This, the peers said, had “become acutely obvious in the current Covid-19 pandemic where online misinformation poses not only a real and present danger to our democracy but also to our lives”. Facebook cannot be allowed to remain beyond the restraints applied to the rest of society. This message has been received by the UK’s competition authority, which has proposed forcing Facebook to give consumers a choice over whether to accept targeted advertising and even suggested breaking it up.
The Lords select committee was right to praise the UK government for putting forward an online harms framework, requiring social media platforms to protect users and sanctioning those that fail to do so by, for example, taking too long to remove offensive material. However, ministers have been tardy in bringing forward legislation and there’s no sign the platforms’ duty of care will shield voters from misinformation campaigns.
Such a move would be in necessary conflict with Facebook’s “neutrality”. The firm’s hands-off approach means it won’t drain its swamp of racism, misogyny and conspiracy. In a speech last October, Mr Zuckerberg had controversially signalled that Facebook’s interests aligned with Donald Trump’s. The Facebook founder said it’s not right to censor politicians. Mr Trump has been notably softer on Facebook than its rivals.
This bargain is unravelling. Faced with a growing backlash over Mr Trump’s inflammatory rhetoric, the social network removed a Trump ad that used a Nazi-era symbol. Facebook will also start allowing US users to opt out of seeing political ads. Yet in Britain Facebook is used to spread false political advertising. It does so knowing that the network’s algorithms spit out, in the words of its own research, “more and more divisive content in an effort to gain user attention and increase time on the platform”. There is an easy solution. The UK bans all political advertising from being broadcast on television or radio. Unless firms like Facebook change radically, it may be time to extend this prohibition to social media.
July 6, 2020
Disuguaglianze digitali (numero speciale della rivista universitaria First Monday)
by Antonio Casilli
Per ben cominciare la settimana, vi segnalo questo numero "di riferimento" della rivista First Monday al quale ho contribuito assieme a un collettivo di colleghi nord- e sud-americani, europei e africani.
Il numéro, in open access, è stato valorosamente capitanato da Laura Robinson.
Al sommario:
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10840 | Global perspectives on digital inequalities and solutions to them ]
Laura Robinson, Jeremy Schulz, Noah McClain, Timothy Hale, Heloisa Pait, Massimo Ragnedda, Joseph D. Straubhaar, Aneka Khilnani, Natalia Tolentino
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10842 | Digital inequalities 2.0: Legacy inequalities in the information age ]
Laura Robinson, Jeremy Schulz, Grant Blank, Massimo Ragnedda, Hiroshi Ono, Bernie Hogan, Gustavo S. Mesch, Shelia R. Cotten, Susan B. Kretchmer, Timothy M. Hale, Tomasz Drabowicz, Pu Yan, Barry Wellman, Molly-Gloria Harper, Anabel Quan-Haase, Hopeton S. Dunn, Antonio A. Casilli, Paola Tubaro, Rod Carvath, Wenhong Chen, Julie B. Wiest, Matías Dodel, Michael J. Stern, Christopher Ball, Kuo-Ting Huang, Aneka Khilnani
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10844 | Digital inequalities 3.0: Emergent inequalities in the information age ]
Laura Robinson, Jeremy Schulz, Hopeton S. Dunn, Antonio A. Casilli, Paola Tubaro, Rod Carvath, Wenhong Chen, Julie B. Wiest, Matías Dodel, Michael J. Stern, Christopher Ball, Kuo-Ting Huang, Grant Blank, Massimo Ragnedda, Hiroshi Ono, Bernie Hogan, Gustavo S. Mesch, Shelia R. Cotten, Susan B. Kretchmer, Timothy M. Hale, Tomasz Drabowicz, Pu Yan, Barry Wellman, Molly-Gloria Harper, Anabel Quan-Haase, Aneka Khilnani
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10847 | Who are the limited users of digital systems and media? An examination of U.K. evidence ]
Simeon J. Yates, Elinor Carmi, Eleanor Lockley, Alicja Pawluczuk, Tom French, Stephanie Vincent
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10830 | Determinants of cyber-safety behaviors in a developing economy The role of socioeconomic inequalities, digital skills and perception of cyber-threats ]
Matías Dodel, Daniela Kaiser, Gustavo Mesch
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10854 | Digital skills and political participation in northeast Anatolia, Turkey ]
Duygu Özsoy, Eyyup Akbulut, Sait Sinan Atılgan, Glenn Muschert
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10855 | Digital capital and online activities: An empirical analysis of the second level of digital divide ]
Maria Laura Ruiu, Massimo Ragnedda
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10839 | Building online skills in off-line realities The SolarSPELL Initiative (Solar Powered Educational Learning Library) ]
Laura Hosman, Coreen Walsh, Martín Pérez Comisso, Jared Sidman
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10860 | Digital inequalities: Homework gap and techno-capital in Austin, Texas ]
Melissa Santillana, Joe Sraubhaar, Alexis Schrubbe, Jaewon Choi, Sharon Strover
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10865 | ICT policies in Latin America: Long-term inequalities and the role of globalized policy-making ]
Eduardo Villanueva-Mansilla
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10866 | Connecting research to policy: Understanding macro and micro policy-makers and their processes ]
Lloyd Levine
*
[ https://firstmonday.org/ojs/index.php/fm/article/view/10845 | Digital inequalities in time of pandemic: COVID-19 exposure risk profiles and new forms of vulnerability ]
Laura Robinson, Jeremy Schulz, Aneka Khilnani, Hiroshi Ono, Shelia R. Cotten, Noah McClain, Lloyd Levine, Wenhong Chen, Gejun Huang, Antonio A. Casilli, Paola Tubaro, Matías Dodel, Anabel Quan-Haase, Maria Laura Ruiu, Massimo Ragnedda, Deb Aikat, Natalia Tolentino
--
Antonio A. Casilli
Professor, Telecom Paris, Institut Polytechnique de Paris
Member, Interdisciplinary Institute for Innovation (i3 UMR 9217 CNRS)
Associate Member, LACI-IIAC (EHESS)
Faculty Fellow, Nexa Center for Internet & Society
*We respect your right to disconnect. This email send time is due to my own workflow efficiency. You are in no obligation to take action or reply to it outside your office hours.*
July 6, 2020
Defund Facial Recognition Before It's Too Late - The Atlantic
by J.C. DE MARTIN
Defund Facial Recognition
I’m a second-generation Black activist, and I’m tired of being spied on by the police.
MALKIA DEVICH-CYRIL
12:00 PM ET
https://www.theatlantic.com/technology/archive/2020/07/defund-facial-recogn…
(Sent from my wireless device; please excuse brevity and typos (if any))
July 5, 2020
AI Watch - Artificial Intelligence in public services | EU Science Hub
by J.C. DE MARTIN
https://ec.europa.eu/jrc/en/publication/eur-scientific-and-technical-resear…
(Sent from my wireless device; please excuse brevity and typos (if any))
July 5, 2020
Re: [nexa] Michael Veale (DP3T) sul potere di chi controlla il digitale
by Giovanni Biscuolo
Buongiorno Roberto,
«It all starts from realising that deflating digital power isn’t just
about governing data: it’s the walls of the underlying systems we have
to tear down.»
Grazie per questo articolo, è un ottimo riassunto dell'ENORME problema
riguardo la sovranità digitale, un problema che il mercato non risolverà
mai da solo e QUINDI rischia di determinare un conflitto durissimo per
il controllo delle tecnologie digitali (truccate).
La soluzione NON è cercare di regolamentare come viene distrubuito il
software truccato o costruito l'hardware con software truccato
incorporato. Men che meno cercare di rappezzare Internet con illusori
protocolli o cercare di mettere una toppa giuridica a come questa sia
abusata per raccogliere dati a strascico.
La sola e unica soluzione c'è, è complessa ma non complicata: liberare
il digitale fino all'ultimo granello di silicio; software libero e
hardware design libero per ogni dispositivo digitale, dall'orologio in
su... c'è QUASI tutto per farlo :-D
Roberto Resoli <roberto(a)resolutions.it> writes:
> Sul potere delle aziende informatiche, ormai superiore a quello degli stati.
>
> "One key lesson requires distinguishing the problem of privacy from
> that of platform power. It is possible to be strongly in favour of a
> decentralised approach, as I am (as a co-developer of the open-source
> DP-3T system that Apple and Google adapted),
Scusa se faccio il pignolo ma abbiamo già verificato che il componente
principale del sistema di exposure notification, quello che fornisce le
API alle App, è distribuito in forma binaria e SOLO attraverso la
piattaforma proprietaria Google Play (e la relativa di iOS che non so
come si chiama)
http://server-nexa.polito.it/pipermail/nexa/2020-May/018003.html
Non vorrei che passasse il messaggio che il sistema (non la singola App)
sia open source :-)
A parte questo il resto dell'articolo è pieno di cose interessanti (e di
un paio di chicche in merito alla storia del passaporto e dello strano
intervento di Cédric O al parlamento francese)
> while being seriously concerned about the centralised control of
> computing infrastructure these firms have amassed."
>
> https://amp.theguardian.com/commentisfree/2020/jul/01/apple-google-contact-…
Link non AMP ;-)
https://web.archive.org/save/https://www.theguardian.com/commentisfree/2020…
--8<---------------cut here---------------start------------->8---
[...] The history of passports – which were introduced as a seemingly
temporary measure during the first world war, but were retained in
response to fears about spreading the Spanish flu – shows that pandemics
can significantly influence our social infrastructure.
[...] In the French parliament, O stated that it was no coincidence that
the UK and France were going against the grain, given that they were
“the only two European states with their own nuclear deterrent”.
[...] they continued the bizarre path, seen in recent years from
politicians around the world, of treating these firms like sovereign
nations, hoping that they recognised each other’s legitimacy and that
their “officials” could come to some agreement.
[...] Data is just a means to an end, and new, cryptographic tools are
emerging that let those firms’ same potentially problematic ends be
reached without privacy-invasive means. These tools give those
controlling and co-ordinating millions or even billions of computers the
monopolistic power to analyse or shape communities or countries, or even
to change individual behaviour, such as to privately target ads based on
their most sensitive data — without any single individual’s data leaving
their phone.
[...] This approach is effectively what underpins the Apple-Google
contact-tracing system. It’s great for individual privacy, but the kind
of infrastructural power it enables should give us sleepless nights.
Countries that expect to deal a mortal wound to tech giants by stopping
them building data mountains are bulls charging at a red rag. In all the
global crises, pandemics and social upheavals that may yet come, those
in control of the computers, not those with the largest datasets, have
the best visibility and the best – and perhaps the scariest — ability to
change the world.
Law should be puncturing and distributing this power, and giving it to
individuals, communities and, with appropriate and improved human-rights
protections, to governments. To do so, we need new digital rights. Data
protection and privacy laws are easily dodged or circumvented by
technical assurances of confidentiality: we need something more
ambitious to escape the giants’ walled gardens.
A “right to repair” would stop planned obsolescence in phones, or firms
buying up competitors just to cut them off from the cloud they need to
run. A “right to interoperate” would force systems from different
providers, including online platforms, to talk to each other in real
time, allowing people to leave a social network without leaving their
friends. These interventions need strong accompanying oversight to
maintain security and privacy, and stop unwanted side-effects or
government abuse, such as the outlawing of end-to-end encryption to
oppress dissidents and whistle-blowers. It all starts from realising
that deflating digital power isn’t just about governing data: it’s the
walls of the underlying systems we have to tear down.
--8<---------------cut here---------------end--------------->8---
Saluti, Giovanni
--
Giovanni Biscuolo
July 4, 2020
Privacy is not the problem with the Apple-Google contact-tracing toolkit
by Giacomo Tesio
New tools give tech giants the power to shape communities and change
behaviour, all without any data leaving our phones
https://www.theguardian.com/commentisfree/2020/jul/01/apple-google-contact-…
In April, Apple and Google announced a partnership. They would take
research into how to undertake Bluetooth-powered Covid-19 contact
tracing in a privacy-preserving manner, with no central database, and
make it available as a toolkit inside their operating systems for
public health authority–sanctioned apps. Before they did this, all
such apps had effectively been doomed to fail. At least on iPhones,
they were crippled by the same baked-in Bluetooth restrictions that
stop normal apps secretly tracking you.
The firms’ contact-tracing toolkit has been both praised and
condemned. Its “decentralised” approach, with no sensitive central
database of who-saw-who, has been supported by hundreds of privacy,
security and human rights scholars. The concerns are understandable.
The history of passports – which were introduced as a seemingly
temporary measure during the first world war, but were retained in
response to fears about spreading the Spanish flu – shows that
pandemics can significantly influence our social infrastructure. And
so they should be designed to minimise future misuse.
Through a software update, Apple and Google loosened privacy
restrictions enough to allow public health authorities to run
decentralised contact-tracing apps, but did not engineer new
functionality to let apps send the unique Bluetooth identities of
phones they encountered to a central server. Data had to remain
secretly on phones: which was not a problem for decentralised systems,
but left centralised apps – such as those favoured by France and the
tech wing of NHS England, NHSX – continuing to struggle to use
Bluetooth.
Reasons for preferring centralised systems differed. NHSX wanted
individuals to trigger self-isolation alerts based on self-reported
symptoms, and said it needed centralised fraud analysis to weed out
the inevitable hypochondriacs and trolls. The French minister for the
digital sector, Cédric O, said that self-reporting was a no-no, and
instead wanted to use centralisation to try to lower the risk of a
particular snooping attack from a tech-savvy neighbour. (This is a
risk that can never be fully removed from any Bluetooth
contact-tracing system.)
Tensions grew as it became clear that the firms did not intend to
engineer a further global change to their operating systems to
specifically accommodate these countries. In the French parliament, O
stated that it was no coincidence that the UK and France were going
against the grain, given that they were “the only two European states
with their own nuclear deterrent”. However, it is worth noting that no
country, nuclear-armed or not, even attempted to use the first tool of
a sovereign nation against the firms — the ability to make binding
laws. Instead, they continued the bizarre path, seen in recent years
from politicians around the world, of treating these firms like
sovereign nations, hoping that they recognised each other’s legitimacy
and that their “officials” could come to some agreement.
They did not, and the saga of the demise of NHSX’s centralised app in
a mid-June U-turn is well-documented. NHSX piloted an app relying on
fragile workarounds to avoid the privacy restrictions built into
operating systems, despite warnings from many outside the project —
myself included — that it was likely to encounter problems. In June,
the government admitted that its workarounds left its system
unacceptably poor at detecting either iPhones or Androids at all.
What can we learn from NHSX’s encounter with these tech giants? One
key lesson requires distinguishing the problem of privacy from that of
platform power. It is possible to be strongly in favour of a
decentralised approach, as I am (as a co-developer of the open-source
DP-3T system that Apple and Google adapted), while being seriously
concerned about the centralised control of computing infrastructure
these firms have amassed.
It’s commonly said that in the digital world, data is power. This
simple view might apply to a company collecting data through an app or
a website, such as a supermarket, but doesn’t faithfully capture the
source of power of the firms controlling the hardware and software
platforms these apps and websites run on. Using privacy technologies,
such as “federated” or “edge” computing, Apple and Google can
understand and intervene in the world, while truthfully saying they
never saw anybody’s personal data.
Data is just a means to an end, and new, cryptographic tools are
emerging that let those firms’ same potentially problematic ends be
reached without privacy-invasive means. These tools give those
controlling and co-ordinating millions or even billions of computers
the monopolistic power to analyse or shape communities or countries,
or even to change individual behaviour, such as to privately target
ads based on their most sensitive data — without any single
individual’s data leaving their phone. It’s not just ad targeting:
privacy technologies could spotlight the roads where a protest is
planned, the areas or industries likely to harbour undocumented
migrants, or the spots in an oppressive country most likely to be
illegal LGBT clubs — not personal data, but data with serious
consequences nonetheless.
This approach is effectively what underpins the Apple-Google
contact-tracing system. It’s great for individual privacy, but the
kind of infrastructural power it enables should give us sleepless
nights. Countries that expect to deal a mortal wound to tech giants by
stopping them building data mountains are bulls charging at a red rag.
In all the global crises, pandemics and social upheavals that may yet
come, those in control of the computers, not those with the largest
datasets, have the best visibility and the best – and perhaps the
scariest — ability to change the world.
Law should be puncturing and distributing this power, and giving it to
individuals, communities and, with appropriate and improved
human-rights protections, to governments. To do so, we need new
digital rights. Data protection and privacy laws are easily dodged or
circumvented by technical assurances of confidentiality: we need
something more ambitious to escape the giants’ walled gardens.
A “right to repair” would stop planned obsolescence in phones, or
firms buying up competitors just to cut them off from the cloud they
need to run. A “right to interoperate” would force systems from
different providers, including online platforms, to talk to each other
in real time, allowing people to leave a social network without
leaving their friends. These interventions need strong accompanying
oversight to maintain security and privacy, and stop unwanted
side-effects or government abuse, such as the outlawing of end-to-end
encryption to oppress dissidents and whistle-blowers. It all starts
from realising that deflating digital power isn’t just about governing
data: it’s the walls of the underlying systems we have to tear down
July 4, 2020
Re: [nexa] Google's AMP, the Canonical Web, and the Importance of Web Standards
by Giacomo Tesio
Qui trovate una breve analisi tecnica e politica dell'articolo della EFF https://mastodon.social/@nyquildotorg/104452770877391416
È interessante perché evidenzia come Google abbia utilizzati il proprio potere commerciale imponendo di fatto ai giornali online di adottare AMP per finire nelle Top Stories (in evidenza).
Non esserci significava meno click e dunque un danno economico rilevante.
Poi, prima che qualcuno coinvolgesse l'anti-trust, ma dopo aver costretto i più grossi player ad adottare (e dunque supportare) la sua tecnologia, Google ha tolto questo vincolo facendo entrare di nuovo anche contenuti non AMP nelle Top Stories.
On a side note, è divertente che inizialmente JavaScript fosse vietato nella pagine AMP per ragioni di performance (oggi sono permessi fino a 150k di JS per pagina), mentre sempre Google (e la sua filiale geek-friendly Mozilla), non prende nemmeno in considerazione l'ipotesi di renderne Opt-in l'esecuzione per tutelare la sicurezza degli utenti.
D'altronde, fuori da AMP, JavaScript per loro è fondamentale: non possono rinunciare ai dati personali sottratti ad utenti inconsapevoli attraverso Google Analytics!
Giacomo
July 4, 2020
Re: [nexa] Michael Veale (DP3T) sul potere di chi controlla il digitale
by Giacomo Tesio
Link via Web (non AMP):
https://www.theguardian.com/commentisfree/2020/jul/01/apple-google-contact-…
Forse dovremmo passare dal concepire la privacy come un diritto individuale a considerarla una forma di tutela della collettività, e dunque un DOVERE individuale.
Un dovere che forse andrebbe reso obbligo di legge, con multe salate per chi diffonde le proprie informazioni personali danneggiando tutte le persone intorno nonché tutte quelle simili.
E magari con provvedimenti penali per chi diffonde e/o rende accessibili informazioni personali di terzi senza l'esplicito e consapevole consenso, da reiterare ad ogni accesso, del data subject.
Su questo però bisognerebbe distinguere chi accede a dati pubblici e chi li rende pubblici.
Per esempio, crew come Lulzsec accedono sempre a dati già pubblici, accessibili e precedentemente acceduti da chiunque abbia un minimo (ma proprio minimo! talvolta basta saper inserire "admin" come username e password!) di competenze. In questi casi, invece di perseguire gli hacker che, di fatto, rendono pubblici i leak perpetrati per anni in precedenza da altri, bisognerebbe perseguire penalmente i responsabili delle aziende che li hanno resi pubblici.
Perché se posso ottenere una informazione attraverso un programma adatto e senza avere accesso fisico al disco che la contiene, allora quella informazione è già pubblica.
Fingere che non lo sia perché tutti quelli che vi accedono sono ben felici di non farlo sapere in giro, non la rende privata.
Giacomo
July 4, 2020
Inside the Invasive, Secretive “Bossware” Tracking Workers
by Giovanni Biscuolo
Buongiorno,
non fosse stato per la fonte (EFF) lo avrei scambiato per un articolo di
Lercio [1]... poi proseguendo la lettura il mio sorriso si è trasformato
in smorfia di disgusto.
Pare non ci sia proprio nessun pudore, nessuna vergogna, nessuna etica
che riesca ad evitare al genere umano di precipitare a simili livelli
(c'è di peggio, lo so!).
Ai giuristi in lista: *se* venisse fatta una cosa del genere in Italia
da una azienda qualsiasi, in particolare da una multinazionale, il
lavoratore potrebbe opporsi, sempre che abbia il coraggio di farlo e le
competenze per scoprirlo?
(Nota: la tabella "stralciata" dall'articolo e riportata più sotto viene
visualizzata bene solo se si usa un font "monospaced")
«Inside the Invasive, Secretive “Bossware” Tracking Workers»
Bennett Cyphers, Karen Gullo; 1 Jul 2020
https://www.eff.org/deeplinks/2020/06/inside-invasive-secretive-bossware-tr…
--8<---------------cut here---------------start------------->8---
COVID-19 has pushed millions of people to work from home, and a flock of
companies offering software for tracking workers has swooped in to pitch
their products to employers across the country.
[...] What can they do?
Bossware typically lives on a computer or smartphone and has privileges
to access data about everything that happens on that device. Most
bossware collects, more or less, everything that the user does. We
looked at marketing materials, demos, and customer reviews to get a
sense of how these tools work. There are too many individual types of
monitoring to list here, but we’ll try to break down the ways these
products can surveil into general categories.
[...] Every product we looked at has the ability to take frequent
screenshots of each worker’s device, and some provide direct, live video
feeds of their screens. This raw image data is often arrayed in a
timeline, so bosses can go back through a worker’s day and see what they
were doing at any given point. Several products also act as a keylogger,
recording every keystroke a worker makes, including unsent emails and
private passwords. A couple even let administrators jump in and take
over remote control of a user’s desktop. These products usually don’t
distinguish between work-related activity and personal account
credentials, bank data, or medical information.
[...] Some bossware goes even further, reaching into the physical world
around a worker’s device. Companies that offer software for mobile
devices nearly always include location tracking using GPS data. At least
two services—StaffCop Enterprise and CleverControl—let employers
secretly activate webcams and microphones on worker devices.
There are, broadly, two ways bossware can be deployed: as an app that’s
visible to (and maybe even controllable by) the worker, or as a secret
background process that workers can’t see. Most companies we looked at
give employers the option to install their software either way.
[...] Invisible monitoring
The majority of companies that build visible monitoring software also
make products that try to hide themselves from the people they’re
monitoring. Teramind, Time Doctor, StaffCop, and others make bossware
that’s designed to be as difficult to detect and remove as possible. At
a technical level, these products are indistinguishable from
stalkerware. In fact, some companies require employers to specifically
configure antivirus software before installing their products, so that
the worker’s antivirus won’t detect and block the monitoring software’s
activity.
[...] The table below shows the monitoring and control features
available from a small sample of bossware vendors. This isn’t a
comprehensive list, and may not be representative of the industry as a
whole; we looked at companies that were referred to in industry guides
and search results that had informative publicly-facing marketing
materials.
Table: Common surveillance features of bossware products
Activity Screenshots or Keylogging Webcam/ Can be made
monitoring screen microphone "invisible"
(apps, recordings activation
websites)
ActivTrak confirmed confirmed confirmed
CleverControl confirmed confirmed confirmed confirmed confirmed
(1, 2)
DeskTime confirmed confirmed confirmed
Hubstaff confirmed confirmed
Interguard confirmed confirmed confirmed confirmed
StaffCop confirmed confirmed confirmed confirmed confirmed
(1, 2)
Teramind confirmed confirmed confirmed confirmed
TimeDoctor confirmed confirmed confirmed
Work Examiner confirmed confirmed confirmed confirmed
WorkPuls confirmed confirmed confirmed
[...] Some of the biggest companies in the world use bossware. Hubstaff
customers include Instacart, Groupon, and Ring. Time Doctor claims
83,000 users; its customers include Allstate, Ericsson, Verizon, and
Re/Max. ActivTrak is used by more than 6,500 organizations, including
Arizona State University, Emory University, and the cities of Denver and
Malibu. Companies like StaffCop and Teramind do not disclose information
about their customers, but claim to serve clients in industries like
health care, banking, fashion, manufacturing, and call centers. Customer
reviews of monitoring software give more examples of how these tools are
used.
[...] Unfortunately, many use cases involve employers wielding excessive
power over workers. Perhaps the largest class of products we looked at
are designed for “productivity monitoring” or enhanced time
tracking—that is, recording everything that workers do to make sure
they’re working hard enough. Some companies frame their tools as
potential boons for both managers and workers. Collecting information
about every second of a worker’s day isn’t just good for bosses, they
claim—it supposedly helps the worker, too. Other vendors, like Work
Examiner and StaffCop, market themselves directly to managers who don’t
trust their staff. These companies often recommend tying layoffs or
bonuses to performance metrics derived from their products.
[...] Some firms also market their products as punitive tools, or as
ways to gather evidence for potential worker lawsuits. InterGuard
advertises that its software “can be silently and remotely installed, so
you can conduct covert investigations [of your workers] and bullet-proof
evidence gathering without alarming the suspected wrongdoer.” This
evidence, it continues, can be used to fight “wrongful termination
suits.” In other words, InterGuard can provide employers with an
astronomical amount of private, secretly-gathered information to try to
quash workers’ legal recourse against unfair treatment.
[...] Unfortunately, excessive information collection often isn’t an
accident, it’s a feature. Work Examiner specifically advertises its
product’s ability to capture private passwords. Another company,
Teramind, reports on every piece of information typed into an email
client—even if that information is subsequently deleted. Several
products also parse out strings of text from private messages on social
media so that employers can know the most intimate details of workers’
personal conversations.
[...] Companies that have adopted bossware must consider what their
goals are, and should try to accomplish them in less-intrusive
ways. Bossware often incentivizes the wrong kinds of productivity—for
example, forcing people to jiggle their mouse and type every few minutes
instead of reading or pausing to think. Constant monitoring can stifle
creativity, diminish trust, and contribute to burnout. If employers are
concerned about data security, they should consider tools that are
specifically tailored to real threats, and which minimize the personal
data caught up in the process.
[...] COVID-19 has put new stresses on us all, and it is likely to
fundamentally change the ways we work as well. However, we must not let
it usher in a new era of even-more-pervasive monitoring. We live more of
our lives through our devices than ever before. That makes it more
important than ever that we have a right to keep our digital lives
private—from governments, tech companies, and our employers.
--8<---------------cut here---------------end--------------->8---
Saluti, Giovanni.
[1]
https://www.lercio.it/stati-generali-renzi-propone-scudo-legale-anche-per-g…
--
Giovanni Biscuolo
July 4, 2020
Michael Veale (DP3T) sul potere di chi controlla il digitale
by Roberto Resoli
Sul potere delle aziende informatiche, ormai superiore a quello degli stati.
"One key lesson requires distinguishing the problem of privacy from that of platform power. It is possible to be strongly in favour of a decentralised approach, as I am (as a co-developer of the open-source DP-3T system that Apple and Google adapted), while being seriously concerned about the centralised control of computing infrastructure these firms have amassed."
https://amp.theguardian.com/commentisfree/2020/jul/01/apple-google-contact-…
rob
July 4, 2020