nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
July 2022
- 24 participants
- 60 messages
Garante danese: Google Workspace (nelle scuole) non è compliant GDPR!
by Damiano Verzulli
"... Denmark is effectively banning Google’s services in schools, after
officials in the municipality of Helsingør were last year ordered
<https://www.datatilsynet.dk/afgoerelser/afgoerelser/2021/sep/afgoerelse-ved…>
to carry out a risk assessment around the processing of personal data by
Google. In a verdict published last week
<https://www.datatilsynet.dk/afgoerelser/afgoerelser/2022/jul/datatilsynet-n…>,
Denmark’s data protection agency, Datatilsynet, revealed that data
processing involving students using Google’s cloud-based Workspace
software suite
<https://techcrunch.com/2021/06/14/google-opens-workspace-to-everyone/>
— which includes Gmail, Google Docs, Calendar and Google Drive — “does
not meet the requirements” of the European Union’s GDPR data privacy
regulations <https://techcrunch.com/2018/01/20/wtf-is-gdpr/>."
L'articolo completo è in:
https://techcrunch.com/2022/07/18/denmark-bans-chromebooks-and-google-works…
A scanso di equivoci, segnalo che la soluzione tecnologica di cui si
parla è adottata da un buon 50% degli Atenei del Paese, e da un buon
70/80% di Istituzioni scolastiche...
Quello che piu' mi amareggia, pero', non è tanto la notizia in sé...
quanto il fatto che a piu' di due anni da inizio pandemia, non siamo
(Italiani / Europei) stati in grado di sviluppare una soluzione che
consentisse --esattamente in questa situazione-- di poter offrire una
alternativa sensata a tutti coloro che vorranno valutarla.
Tutto cio' è veramente triste...
Bye,
DV
--
Damiano Verzulli
e-mail:damiano@verzulli.it
---
possible?ok:while(!possible){open_mindedness++}
---
"...I realized that free software would not generate the kind of
income that was needed. Maybe in USA or Europe, you may be able
to get a well paying job as a free software developer, but not
here [in Africa]..." -- Guido Sohne - 1973-2008
http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
July 19, 2022
Mathew D. Rose – Uber Files: Another victory for EU corruption
by J.C. DE MARTIN
*Mathew D. Rose – Uber Files: Another victory for EU corruption**
*
July 15, 2022
/The Uber Files have once again shown that mainstream media is not there
to protect democracy, but to participate in its sell out.//
//Mathew D. Rose is an Investigative Journalist specialised in Organised
Political Crime in Germany and an editor of BRAVE NEW EUROPE//
/
The recent case of the Uber Files has reconfirmed my decision to leave
investigative journalism. As one titillating scandal detail follows hot
on the heels of the other, the big picture – the systemic picture – is
suppressed or simply ignored as always.
First of all, what were the strategic elements of Uber’s lobbying
campaign? As far as we have seen up to now they were politicians at EU,
national, and municipal level; corporate media; and academics. What they
all have in common, maybe with exceptions, is that these people were
bribed to act in the interests of Uber. However the words bribe and
corruption have not appeared in a single article, NGO statement, or
tweet. These were however quid pro quo deals, money for influence:
business as usual in the EU.
What one has to understand with corruption is that quid pro quo does not
mean an immediate exchange. One can deliver one’s own part of the
bargain and collect the reciprocal fee later. Former EU commissioner
Neeli Kroes is a typical example. As she was EU commissioner Uber
promised her a generously remunerated position on its board later. For
her part, while in office and afterwards she used her power and
influence to further the financial interests of Uber. Once she had left
the EU she waited until the official so-called “cooling off period of 18
months (although during this period she was energetically active for
Uber) before officially joining Uber’s advisory board. Records show Uber
offered her $200,000 a year to chair the board.
[...]
continua qui:
https://braveneweurope.com/mathew-d-rose-uber-files-another-victory-for-eu-…
July 19, 2022
I media digitali, un potente mezzo di dialogo da usare con senso critico
by Antonio Iacono
Venerdì scorso il Papa ha inviato un messaggio ai partecipanti al
Congresso Mondiale di SIGNIS (Seoul, 15-18 agosto 2022).
Il testo completo, poco meno di 4000 caratteri, è sul sito della sala
stampa del Vaticano [1]
Il messaggio è stato reso pubblico stamattina ed immediatamente
riportato dalle varie agenzie di stampa e organi di informazione varia.
Eccone una rassegna di ... titoli.
"Il Papa: i media digitali, un potente mezzo per promuovere la pace" [2]
Il Papa dice che i siti di alcuni media “sono diventati luoghi di
tossicità e fake news” [3]
Papa Francesco: “i media digitali possono unirci” [4]
Il Papa: "Basta fake news e social media tossici, proteggiamo i più
giovani" [5]
Papa ai comunicatori cattolici: educate al senso critico contro chi
inquina i media [6]
Papa Francesco elogia i media digitali: ‘Uno strumento potente che può
sostenere la pace’ [7]
Il Papa: i media digitali, un potente mezzo di dialogo da usare con
senso critico [8]
"Luoghi di tossicità". Papa Francesco contro i siti web [9]
Insomma, tutte le "echo chambers" sono accontentate.
A.
[1]
https://press.vatican.va/content/salastampa/it/bollettino/pubblico/2022/07/…
[2]
https://www.vaticannews.va/it/papa/news/2022-07/papa-messaggio-congresso-mo…
[3]
https://www.askanews.it/cronaca/2022/07/18/il-papa-dice-che-i-siti-di-alcun…
[4]
https://www.agensir.it/quotidiano/2022/7/18/papa-francesco-i-media-digitali…
[5] https://www.ilgiorno.it/cronaca/papa-fake-news-social-1.7895219
[6]
https://www.asianews.it/notizie-it/Papa-ai-comunicatori-cattolici:-educate-…
[7]
https://www.papaboys.org/papa-francesco-elogia-i-media-digitali-uno-strumen…
[8]
https://www.chiesa-cattolica.it/il-papa-i-media-digitali-un-potente-mezzo-d…
[9]
https://www.ilgiornale.it/news/tecnologia/luoghi-tossicit-papa-francesco-co…
July 18, 2022
Articolo di Romano Prodi su politica industriale da Il Messaggero di ieri, 17 luglio 2022
by Luigi Scorca
July 18, 2022
Facial Recognition Search Engine Pulls Up “Potentially Explicit” Photos of Kids
by Alberto Cammozzo
<https://theintercept.com/2022/07/16/facial-recognition-search-children-phot…>
Abusive parents searching for kids who have fled to shelters.
Governments targeting the sons and daughters of political dissidents.
Pedophiles stalking the victims they encounter in illicit child sexual
abuse material.
The online facial recognition search engine PimEyes allows anyone to
search for images of children scraped from across the internet, raising
a host of alarming possible uses, an Intercept investigation has found.
Often called the Google of facial recognition, PimEyes search results
include images that the site labels as “potentially explicit,” which
could lead to further exploitation of children at a time when the dark
web has sparked an explosion of images of abuse.
“There are privacy issues raised by the use of facial recognition
technology writ large,” said Jeramie Scott, director of the Surveillance
Oversight Project at the Electronic Privacy Information Center. “But
it’s particularly dangerous when we’re talking about children, when
someone may use that to identify a child and to track them down.”
Over the past few years, several child victim advocacy groups have
pushed for police use of surveillance technologies to fight trafficking,
arguing that facial recognition can help authorities locate victims. One
child abuse prevention nonprofit, Ashton Kutcher and Demi Moore’s Thorn,
has even developed its own facial recognition tool. But searches on
PimEyes for 30 AI-generated children’s faces yielded dozens of pages of
results, showing how easily those same tools can be turned against the
people they’re designed to help.
While The Intercept searched for fake faces due to privacy concerns, the
results contained many images of actual children pulled from a wide
range of sources, including charity groups and educational sites.
PimEyes previously came under fire for including photos scraped from
major social media platforms. It no longer includes those images in
search results. Instead, searches churn up a welter of images that feel
plucked from the depths of the internet. Some come from personal
websites that parents created anonymously or semi-anonymously to feature
photos of their children, likely not anticipating that they could one
day be pulled up by strangers taking snapshots of kids on the street.
One search for an AI-generated child turned up images of a real boy in
Delaware, where a photographer had taken portraits of his family on a
sunny spring day. When she posted the portraits in her online portfolio,
the photographer omitted the boy’s name and other identifying details.
But a determined person might theoretically be able to find such
information. (The photographer did not respond to requests to comment
for this article.)
Another search turned up a girl displaying a craft project at an
after-school program in Kyiv, Ukraine, in a photo taken just before the
war. A second page on the same website showed the girl at home this
spring; by then, Kyiv was under siege, the program had gone remote, and
teachers were assigning kids craft projects to complete from their
kitchen tables.
A third search turned up a photo of a 14-year-old British boy that had
been featured in a video about the U.K. educational system. The
commentator gave the boy’s first name and details about the school he
attended.
Still another search turned up a photo of a toddler from an American
home-schooling blog, where the girl’s mother had revealed her first name
and, when the family was traveling, rough whereabouts.
PimEyes is the brainchild of two Polish developers who created the site
in 2017 on a whim. It reportedly passed through the hands of an
anonymous owner who moved the headquarters to the Seychelles and then in
December 2021 was purchased by Georgian international relations scholar
Giorgi Gobronidze, who had met the site’s creators while lecturing in
Poland.
In a wide-ranging video interview that stretched to nearly two hours,
Gobronidze offered a vague and sometimes contradictory account of the
site’s privacy protections.
He said that PimEyes was working to develop better safeguards for
children, though he offered varying responses when asked what those
might entail. “It’s a task that was given already to our technical
group, and they have to bring me a solution,” he said. “I gave them
several options.”
At the same time, he dismissed the argument that parents who post
anonymous photos of their children have any expectation of privacy.
“Parents should be more responsible,” he said. “I have never posted a
photo of my child on social media or on a public website.”
“Designed for Stalkers”
On its website, PimEyes maintains that people should only use the tool
to search for their own faces, claiming that the service is “not
intended for the surveillance of others and is not designed for that
purpose.” But the company offers subscriptions that allow people to
perform dozens of unique searches a day; the least expensive package, at
$29.99 a month, offers 25 daily searches. People who shell out for the
premium service can set alerts for up to 500 different images or
combinations of images, so that they are notified when a particular face
shows up on a new site.
Gobronidze claimed that many of PimEyes’s subscribers are women and
girls searching for revenge porn images of themselves, and that the site
allows multiple searches so that such users can get more robust results.
“With one photo, you can get one set of results, and with another photo
you can get a totally different set of results, because the index
combination is different on every photo,” he said. Sometimes, he added,
people find new illicit images of themselves and need to set additional
alerts to search for those images. He acknowledged that 500 unique
alerts is a lot, though he said that, as of Thursday, 97.7 percent of
PimEyes subscribers had a lighter account.
Following criticism, the company pivoted to claiming that the
search engine was a privacy tool.
PimEyes’s previous owners marketed it as a way to pry into celebrities’
lives, the German digital rights site Netzpolitik reported in 2020.
Following criticism, the company pivoted to claiming that the search
engine was a privacy tool. Gobronidze said that fraught features were
being overhauled under his ownership. “Previously, I can say that
PimEyes was tailor-designed for stalkers, [in that] it used to crawl
social media,” he said. “Once you dropped a photo, you could find the
social media profiles for everyone. Now it is limited only to public
searches.”
But many people clearly do not see PimEyes as an aid to privacy. The
site has already been used to identify adults in a wide variety of
cases, from so-called sedition hunters working to find perpetrators
after the January 6 insurrection, to users of the notorious site 4chan
seeking to harass women.
Nor do PimEyes’s marketing materials suggest much concern for privacy or
ethics. In a version of the “people kill people” argument favored by the
U.S. gun lobby, a blog post on the site blithely alludes to its many
uses: “PimEyes just provides a tool, and the user is obliged to use the
tool with responsibility. Everyone can buy a hammer, and everyone can
either craft with this tool, or kill.”
“These things should only be instrumentalized with the clear and
knowledgeable consent of users,” said Daly Barnett, a staff technologist
at the Electronic Frontier Foundation. “This is just another example of
the large overarching problem within technology, surveillance-built or
not. There isn’t privacy built from the get-go with it, and users have
to opt out of having their privacy compromised.”
“We Do Not Want to Be a Monster Machine”
Alarmingly, search results for AI-generated kids also include images
that PimEyes labels as “potentially explicit.” The backgrounds in the
labeled images are blurred, and since clicking through to the source
URLs could contribute to the exploitation of children, The Intercept
could not confirm whether they are, in fact, explicit. Gobronidze said
that the labels are assigned in part based on images’ source URLs, and
that often the photos are harmless. When PimEyes representatives do run
across child sexual abuse images, he said, representatives report it to
law enforcement.
But one example he gave shows how easily the site can be used to unearth
abusive or illegal content. A 16-year-old girl had used her parents’
credit card to open an account, Gobronidze said. She soon found revenge
porn videos that had been uploaded by an ex-boyfriend — images that
likely fit the legal definition of child pornography. (He said PimEyes
issued takedown notices for the websites and advised the girl to talk
with authorities, her parents, and psychologists.)
Gobronidze was vague on how he might limit abuse of children on the
site. Subscribing requires a credit card, PayPal, or Amazon Pay account,
and users upload their IDs only when asking PimEyes to perform takedown
notices on their behalf. By design, he said, the search engine only
seeks matches in photos and does not guess at age, gender, race, or
ethnicity. “We do not want to be a monster machine,” he said, dubbing a
more heavy-handed approach “Big Brother.” But at another point in the
interview, he said he was planning to exclude images of children from
search results. Still later, he said that his technical team was
figuring out how to balance these two conflicting goals.
PimEyes flags people who “systematically” use the engine to search for
children’s faces, he said. Users who plug in one or two faces of
children are typically assumed to be family members. If a PimEyes
representative gets suspicious, he said, they might ask a subscriber for
a document like a birth certificate that would prove that a user is a
parent.
When asked how a birth certificate would rule out abuse or stalking by
noncustodial parents, Gobronidze said that PimEyes might instead request
a signed form, similar to what parents and legal guardians provide in
some countries when crossing borders with a child, to show they have any
other parent’s consent. In a later email, he said that PimEyes had twice
asked for “documents + verbal explanation” for people who uploaded
images of children, and that the site had subsequently banned one of the
accounts.
“The fact that PimEyes doesn’t have safeguards in place for children and
apparently is not sure how to provide safeguards for children only
underlines the risks of this kind of facial recognition service,” said
Scott, of EPIC. “Participating in public, whether online or offline,
should not mean subjecting yourself to privacy-invasive services like
PimEyes.”
The inclusion of children’s faces in PimEyes search results
underscores just how fraught the facial recognition landscape has become.
The inclusion of children’s faces in PimEyes search results underscores
just how fraught the facial recognition landscape has become. For years,
victim advocacy groups have pushed for expanded use of the technology by
law enforcement. The Kutcher-Moore nonprofit, Thorn, has developed a
facial recognition tool called Spotlight that it provides to
investigators working on sex trafficking cases, as well as to the
National Center for Missing and Exploited Children. In a recent report,
the center said that in 2021, Spotlight helped it identify over 400
missing children in online sex trafficking advertisements.
Commercial providers of facial recognition have also gotten into
trafficking prevention. The controversial facial recognition company
Clearview AI sells its tools to police for identifying child victims.
But those same tools can also be used to target the vulnerable.
Clearview AI promoted the use of its database for child trafficking
after being sued by the American Civil Liberties Union for endangering
survivors of domestic violence and undocumented immigrants, among
others. Prostasia Foundation, a child protection group that supports sex
workers rights and internet freedom, contends that an earlier Thorn tool
sometimes flagged images of adults, leading to the arrest of sex workers.
This tension is even more extreme with PimEyes, which has virtually no
guardrails and smashes long-standing expectations of privacy for both
adults and children.
Gobronidze said that PimEyes had talked to Thorn about using its tool
Safer to detect child sexual abuse material using image hashing
technology — a potentially odd relationship given that PimEyes makes
images of children searchable to the general public, while Thorn aims to
protect children from stalkers and abusers.
“There has been one exploratory call between our Safer team and PimEyes
to show how Safer helps platforms detect, report and remove CSAM,” a
Thorn spokesperson said, using the acronym for child sexual abuse
material. “No partnership materialized after that single call and they
are not users of Safer or any tools built by Thorn.”
When asked about concerns about its facial recognition tool, Thorn sent
a statement through a spokesperson. “Spotlight is a highly targeted tool
that was built specifically to identify child victims of sex trafficking
and is only available to law enforcement officers who investigate child
sex trafficking.”
In the United States, PimEyes could run up against a 1998 law requiring
the Federal Trade Commission to protect children’s online privacy. But
so far, U.S. regulators have homed in on sites that store images or
information, said Emma Llansó, director of the Free Expression Project
at the Center for Democracy and Technology. PimEyes crawls images hosted
on other sites. “PimEyes is just scraping whatever they can get their
hands on on the web and isn’t making promises to users about what it
will and won’t do with that data,” Llansó said. “So it’s something of a
gray area.”
Gobronidze is keenly aware of the distinction. “We don’t store any
photos,” he claimed. “We don’t have any.”
That is not entirely true. PimEyes’s privacy policy holds that for
unregistered users — anyone who uses the site without a paid account —
it retains facial images, along with the “fingerprint” of a face, for 48
hours and that data from the photos indexed in results is stored for two
years. A sample PimEyes search showed thumbnail images of faces — photos
returned in search queries that the site has edited to blur their
backgrounds. A network traffic analysis showed that those photos are
hosted on a PimEyes subdomain called “collectors.”
In an email, Gobronidze said he had not previously heard or read about
that subdomain and was “intrigued” to learn of it. He noted that he had
forwarded the results of The Intercept’s analysis to PimEyes’s tech and
data security units, adding that he could not “disclose [the] full
technological cycle” because it is proprietary.
Scott, of EPIC, would rather not wait around for courts and regulators
to consider the storage question. “Congress needs to act to not only
protect our children, but all of us from the dangers of facial
recognition technology,” he said. “Services like this should be banned.
That’s how you should regulate it.”
--
PimEyes è interessante perché sfida le attuali regolazioni: non
memorizza foto, ma è solo un crawler che indicizza le URL pubbliche alle
quali trova i volti.
E' quanto avevo in mente nel 2012 scrivendo "Do we need an open face
recognition search engine?" <http://sedici.unlp.edu.ar/handle/10915/23870>
L'unica differenza è che PimEyes è a pagamento ed è pensato per volumi
di ricerche superiori a un solo volto, mentre io immaginavo un servizio
pubblico eventualmente collegato a una procedura di take-down nel caso
le immagini siano pubblicate illegittimamente.
July 17, 2022
China's Surveillance State Hits Rare Resistance From Its Own Subjects - Forbes India
by Alberto Cammozzo
<https://www.forbesindia.com/article/news/chinas-surveillance-state-hits-rar…>
Chinese artists have staged performances to highlight the ubiquity of
surveillance cameras. Privacy activists have filed lawsuits against the
collection of facial recognition data. Ordinary citizens and
establishment intellectuals alike have pushed back against the abuse of
COVID tracking apps by authorities to curb protests. Internet users have
shared tips on how to evade digital monitoring.
As China builds up its vast surveillance and security apparatus, it is
running up against growing public unease about the lack of safeguards to
prevent the theft or misuse of personal data. The ruling Communist Party
is keenly aware of the cost to its credibility of any major security
lapses: Last week, it moved systematically to squelch news about what
was probably the largest known breach of a Chinese government computer
system, involving the personal information of as many as 1 billion citizens.
The breach dealt a blow to Beijing, exposing the risks of its expansive
efforts to vacuum up enormous amounts of digital and biological
information on the daily activities and social connections of its people
from social media posts, biometric data, phone records and surveillance
videos. The government says these efforts are necessary for public
safety: to limit the spread of COVID, for instance, or to catch
criminals. But its failure to protect the data exposes citizens to
problems like fraud and extortion and threatens to erode people’s
willingness to comply with surveillance.
“You never know who is going to sell or leak your information,” said
Jewel Liao, a Shanghai resident whose details were among those released
in the leak. “It’s just a bit unusual to see that even the police are
vulnerable too.”
China, which has been racing to implement one of the world’s toughest
data privacy regimes, frequently excoriates companies for mishandling
data. But authorities rarely point fingers at the country’s other top
collector of personal information: the government itself.
Security researchers say the leaked database, apparently used by the
police in Shanghai, had been left online and unsecured for months. It
was exposed after an anonymous user posted in an online forum offering
to sell the vast trove of data for 10 Bitcoin, or about $200,000. The
New York Times confirmed parts of a sample of the database released by
the anonymous user, who posted under the name ChinaDan.
The government’s efforts to institute safeguards have lagged behind its
own push to collect information. In recent years, The Times has reviewed
other leaked databases used by the police in China that were left online
with little to no protection; some contained facial recognition records
and ID scans of people in a Muslim ethnic minority region.
Now there are signs that people are growing wary of the government and
public institutions, too, as they see how their own data is being used
against them. Last month, a nationwide outcry erupted over the apparent
abuse of COVID-19 tracking technology by local authorities.
Protesters fighting to recover their savings from four rural banks in
the central Chinese city of Zhengzhou found that the mobile apps used to
identify and isolate people who might be spreading COVID-19 had turned
from green — meaning safe — to red, a designation that would prevent
them from moving freely.
“There is no privacy in China,” said Silvia Si, 30, a protester whose
health code had turned red.
Authorities in Zhengzhou, under pressure to account for the episode,
later punished five officials for changing the codes of more than 1,300
customers.
Even when the COVID-19 tracking technologies are used for their stated
purpose, more people seem willing to ask if the surveillance is
excessive. On Wednesday, a blogger in Beijing posted on Weibo that he
was refusing to wear an electronic bracelet to track his movements while
in isolation, saying that the device was an “electronic shackle” and an
infringement on his privacy. The post was liked around 60,000 times, and
users flooded his post with responses. Many said it reminded them of the
treatment of criminals; others called it a ploy to surreptitiously
collect personal information. The post was later taken down by censors,
the blogger said.
In recent years, individuals have sought to draw attention to privacy
concerns. In 2019, a law professor in Hangzhou, a prominent tech hub in
eastern China, sued a local zoo for forcing him to submit facial
recognition data to enter, the first such lawsuit in China. He won the case.
Starting in late 2020, several Chinese cities began banning neighborhood
committees from forcing residents to undergo biometric monitoring to
enter their compounds. Around the same time, toilet paper dispensers
using facial recognition were removed from public bathrooms in the
southern Chinese city of Dongguan following public outrage.
In online forums like Zhihu, a Quora-like platform, Chinese users trade
advice on how to evade surveillance (tips include wearing hats and masks
and pointing flashlights at security cameras). More than 60% of Chinese
people say facial recognition technology has been abused, according to a
study of more than 20,000 Chinese jointly conducted in late 2020 by a
Chinese think tank and a government task force. More than 80% expressed
concern about whether and how facial recognition data would be stored.
“The rise of the public’s awareness of data privacy is an inevitable
trend,” said Dragon Zheng, an artist based in the southern province of
Guangxi whose practice explores the interaction of technology and
governance.
In 2016, Zheng installed security cameras inside a large exhibition
hall, which streamed live footage to a monitoring room set up in the
center of the hall. Visitors were invited to enter the room, where they
could manipulate the cameras and experience what Zheng called the
feeling of “monitoring and being monitored, controlling and being
controlled.”
Still, he emphasized that the risks and advantages of technology were
not unique to China.
“Technology is like Pandora’s box,” Zheng said. “Once it’s open, how it
is used depends on whose hands it falls into.”
Few Chinese citizens have publicly questioned the government about its
collection of personal data. Part of that could be a result of the
government’s thorough censorship and the threats to personal safety of
criticizing the government. But many residents also see the handover of
data as a necessary trade-off for security and convenience.
“There’s always been this split identity when it comes to privacy
awareness in China,” said Samm Sacks, a researcher on technology policy
at Yale Law School and New America. “People are far more trusting
overall in how government entities handle their personal information and
far more suspicious about the corporate sector.”
July 16, 2022
Borse di partecipazione per studenti al Festival di Informatici Senza Frontiere (Rovereto, 20-22 Ottobre 2022)
by Patrignani Norberto
Carissim*,
segnalo e invito a far circolare il bando in allegato
per 15 borse di partecipazione per altrettanti studenti e studentesse delle scuole superiori, studenti e studentesse universitarie e dottorandi/e,
le borse coprono le spese di viaggio, vitto ed alloggio a Rovereto durante il periodo di svolgimento del Festival di Informatici Senza Frontiere
(Rovereto, 20-22 ottobre 2022).
Grazie!
Norberto
Le borse copriranno le spese di viaggio, vitto ed alloggio a Roveretodurante il periodo di svolgimento del Festival.
July 15, 2022
A proposito del SSN [era: Google Analytics 4, GDPR...]
by Damiano Verzulli
Il 14/07/22 16:40, vincenzo.giorgino ha scritto:
> [...]
> Aggiungo una nota di colore. Partendo dal presupposto che i dati
> sanitari sono dei singoli cittadini, - si, mi son dato una risposta
> provvisoria - mi sono chiesto quanti erano gli iscritti al SSN per
> fare due conti grezzi sulla scia di un Rapporto di E&Y sul NHS
> inglese. Nn trovando la risposta sui siti del Minisan e di
> epidemiologia ho scritto all'URP del Minisan che mi ha risposto
> girandola all'ufficio competente. Da esso mi han risposto di guardare
> nella pagina Open Data del MiniSan ... in cui però nn c'è alcun dato.
Morso (io) dalla curiosità, sono andato a spulciare. Il punto di
partenza è stato questo:
https://www.dati.salute.gov.it/dati/homeDataset.jsp
non il migliore dei siti del mondo, ma comunque meglio di un pugno nello
stomaco.
Un click su "> vai all'elenco" e si presenta una pagina con sopra
scritto: "Sono disponibili 60 dataset".
Non sapendo cosa cercare, ho preferito fare una scansione sequenziale
(leggerli tutti, uno per uno).
Dopo pochi minuti, sono arrivato qui:
=> "Corrispondenze ASL-Comuni e popolazione residente - anno 2020"
https://www.dati.salute.gov.it/dati/dettaglioDataset.jsp?menu=dati&idPag=3
"Per ciascuna ASL è riportato l’elenco dei comuni che afferiscono alla
ASL; inoltre per ogni comune viene fornita la popolazione residente
distinta per genere. Per i comuni articolati su più ASL, sono riportati
gli ambiti territoriali subcomunali (circoscrizioni/municipi) che
afferiscono alla ASL. Dall’anno 2017, la stima della popolazione
residente delle ASL del comune di Roma è più accurata rispetto a quella
fornita per gli anni precedenti. I dettagli relativi alla nuova
procedura di stima sono riportati nel dizionario. Per le informazioni
sul dataset è possibile far riferimento al dizionario
<https://www.dati.salute.gov.it/dati/documenti/Dataset_ASL_comuni_popolazion…>."
L'ho scaricato, aperto e... visionato.
Contiene 7905 righe, relative (credo!) a tutti i comuni italiani,
classificati per ASL e per Regione. Per ogni Comune c'e' il numero di
MASCHI e di FEMMINE. Il totale, rispettivamente, somma 28.866.226
(maschi) e 30.369.987 (femmine). Dato che parliamo di un totale
complessivo di 59.236.213 (ossia in linea alla popolazione italiana
residente), mi sorge il dubbio di non aver capito bene la domanda :-(
Un saluto,
DV
--
Damiano Verzulli
e-mail:damiano@verzulli.it
---
possible?ok:while(!possible){open_mindedness++}
---
"...I realized that free software would not generate the kind of
income that was needed. Maybe in USA or Europe, you may be able
to get a well paying job as a free software developer, but not
here [in Africa]..." -- Guido Sohne - 1973-2008
http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
July 14, 2022
Re: [nexa] Google Analytics 4, GDPR... e la società cibernetica che vogliamo costruire.
by Giacomo Tesio
Ciao Alberto,
sottoscrivo la tua domanda, ma nell'attesa che Diego risponda mi
permetto di aggiungerne una un po' meno ingenua.
Nella documentazione di supporto che Diego ha condiviso [1] Google
dichiara:
```
When collecting data, Google Analytics 4 does not log or store IP
addresses.
Analytics drops any IP addresses that it collects from EU users
before logging that data via EU domains and servers.
```
La mia domanda è: se Google riceve l'IP e lo scarta, cosa le impedisce
tecnicamente di inviarlo prima segretamente ad agenzie USA nei termini
della normativa applicabile?
Può sembrare un dettaglio tecnico di poco conto, ma in realtà è il cuore
del problema: è questa possibilità tecnica a rendere un qualsiasi
servizio fornito da aziende statunitensi incompatibile con i diritti
dei cittadini europei riconosciuti dal GDPR.
Giacomo
[1] https://support.google.com/analytics/answer/12017362
On Thu, 14 Jul 2022 15:19:28 +0200 Alberto Cammozzo via nexa wrote:
> Grazie a Diego Ciulli per la pronta risposta.
>
> Non sono un esperto di analytics ma se ho compreso bene ci sono dei
> parametri da configurare per chi usa GA, che richiedono competenze
> esperte, che renderebbero l'impiego sicuramente compatibile con il
> GDPR anche in assenza di accordi specifici.
>
> Mi sorge una domanda ingenua: per quale motivo dunque Google non
> protegge i propri clienti e gli utenti UE offrendo questi parametri
> come attivi di default ovunque siano investiti clienti ed utenti
> soggetti al GDPR e potenzialmente oggetto di una violazione?
>
> Questo consentirebbe di rispettare la legge in attesa di un nuovo
> accordo UE/US, o perlomeno obbligherebbe chi raccoglie dati in
> violazione a farlo scientemente, allontanandosi dai parametri di
> default sicuri.
>
> La configurazione attuale mi pare di "violation by default".
>
> Grazie, un saluto
>
> Alberto
>
>
> On 14/07/22 12:50, Diego Ciulli via nexa wrote:
> > Eccomi!
> > Presente, e leggo pure con interesse.
> >
> > In estrema sintesi, GA4 ha introdotto strumenti per gestire e
> > minimizzare i dati degli utenti raccolti - e lo abbiamo fatto per
> > andare incontro alle preoccupazioni sollevate. Dettagli qui
> > <https://support.google.com/analytics/answer/12017362> e qui
> > <https://blog.google/intl/it-it/notizie-aziendali/tecnologia/alcune-risposte…>
> > Dopodichè, è evidente che un quadro certo è possibile solo con la
> > definizione di un nuovo accordo per il trasferimento dati tra UE e
> > USA
> > - vedi qui
> > <https://blog.google/around-the-globe/google-europe/its-time-for-a-new-eu-us…>.
> >
> >
> >
> > On Thu, Jul 14, 2022 at 11:44 AM Damiano Verzulli
> > <damiano(a)verzulli.it> wrote:
> >
> > Il 14/07/22 11:29, Alberto Cammozzo via nexa ha scritto:
> > > [...]
> > > Sarebbe interessante sentire il parere, anche personale, dei
> > > dipendenti di Google presenti in lista.
> >
> > Esistono "dipendenti" di Google Italia, o di qualche branch
> > Google, iscritti a questa lista?
> >
> > ...per certi aspetti, mi meraviglierebbe molto. Per gli altri,
> > mi meraviglierebbe ancora di piu'.
> >
> > Bye,
> > DV
> >
> > --
> > Damiano Verzulli
> > e-mail: damiano(a)verzulli.it
> > ---
> > possible?ok:while(!possible){open_mindedness++}
> > ---
> > "...I realized that free software would not generate the kind of
> > income that was needed. Maybe in USA or Europe, you may be able
> > to get a well paying job as a free software developer, but not
> > here [in Africa]..." -- Guido Sohne - 1973-2008
> > http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
> >
> > _______________________________________________
> > nexa mailing list
> > nexa(a)server-nexa.polito.it
> > https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
> >
> >
> > _______________________________________________
> > nexa mailing list
> > nexa(a)server-nexa.polito.it
> > https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
July 14, 2022
Re: [nexa] Google Analytics 4, GDPR... e la società cibernetica che vogliamo costruire.
by Vincenzo Mario Bruno Giorgino
Ciao Giacomo,
sono d'accordo su cosa sono i dati personali e su come dovrebbe essere una
società futura, ma la domanda resta...
E nn riguarda solo GAFAM ma anche lo stato. Le GAFAM non sono onnipotenti.
A loro servono dei politici, degli studiosi e dei professionisti che
sostengano il loro potere. Vedi il caso Uberleaks rivelato dal Guardian in
questi giorni. BTW, In sociologia, qualcuno definisce l'insieme dei
rapporti economici come lavoro relazionale, senza separare i rapporti
sociali o le relazioni personali dal calcolo economico.... Tout se tient.
Tornando ai dati sanitari, essi hanno un alto valore conoscitivo (vedi
pandemia) ed economico, e sono in possesso del SSN - nn delle GAFAM. Va
riconosciuta la proprietà ai singoli iscritti al SSN?
Se sì, tecnicamente, come? Ad es. Alex Pentland offre una risposta. È
percorribile in Italia e in Europa?
Mi pongo domande pragmatiche, vale a dire che vanno idealmente nella
direzione da te auspicata, ma che possono avere una risposta ora, nella
sfera d'azione collettiva in cui abbiamo potere d'influenza. E non è
affatto piccola, secondo me. Molto dipende da dove ci porta la nostra
attenzione.
... Soprattutto se guardiamo un po' ai dati e abbandoniamo questa dominante
visione capitalocentrica... Dal 30 al 50% del PIL è prodotto dall'economia
familiare non dal mercato capitalista: ciò include i Paesi più "sviluppati"
ed oscilla in base ai vari criteri di calcolo.
Un saluto.
Vincenzo
Il Gio 14 Lug 2022, 17:41 Giacomo Tesio <giacomo(a)tesio.it> ha scritto:
> Ciao Vincenzo,
>
> On Thu, 14 Jul 2022 16:40:31 +0200 vincenzo.giorgino wrote:
>
> > I dati sono dunque di chi li possiede, un dato di fatto intoccabile,
> > per cui al massimo si proteggono i danneggiati?
>
> ragionando al di là della normativa presente ed in ottica di una piena
> emancipazione cibernetica futura dobbiamo distinguere i dati personali
> (emessi da persone fisiche) e tutti gli altri. [1]
>
> Sugli altri si potrebbe discutere anni su come riscrivere la normativa
> esistente per massimizzare il progresso dell'umanità invece che il
> profitto di pochi.
>
>
> Ma i dati personali sono qualcosa di completamente diverso: descrivono
> la persona ed il loro accumulo abilita una terribile riduzione della
> sua autonomia, la sua riduzione ad ingranaggio inconsapevole.
>
>
> I dati personali andranno dunque protetti in modo molto più efficace
> della normativa attuale. L'unico ad avere diritto di raccoglierli,
> elaborarli, persino alterarli ed eventualmente condividerli (in parte)
> con terzi per finalità specifiche, deve essere il soggetto cui
> riguardano.
>
> Solo quando tutti potranno elaborare autonomamente e liberamente i
> propri dati personali, saremo entrati finalmente in una società
> cibernetica civile.
>
>
> Quando ognuno di noi potrà decidere puntualmente quali dati personali
> (veri o falsi) condividere con la società, allora tale condivisione
> trasformerà quei dati da emissione inconsapevole abusata da terzi, in
> espressione consapevole della propria libertà.
>
>
> Ma siamo ancora lontani dalla consapevolezza necessaria.
> E purtroppo, la narrazione dei GAFAM è egemonica.
>
> Nessuno mette in discussione l'uso dei dati personali che di fatto è
> uso delle persone che li hanno emesse, ma solo le finalità o le modalità
> del loro utilizzo.
>
> L'idea che la persona abbia una propria sacralità, una dignità ed una
> unicità che vanno protette dagli smodati appetiti dell'economia
> capitalista è inconcepibile per moltissime persone.
>
> Ed anche quelle in buona fede, sono state convinte di poter usare i
> dati personali (aka le persone cui si riferiscono) a fin di bene.
>
> Mala tempora currunt.
>
>
> Giacomo
>
> [1]
> https://video.linuxtrent.it/w/p/ih87E19VKKsSTxAJYL6QhR?playlistPosition=2
>
> [2]
> https://video.linuxtrent.it/w/p/ih87E19VKKsSTxAJYL6QhR?playlistPosition=1
>
July 14, 2022