Wednesday, 7 August 2019

Twitter ‘fesses up to more adtech leaks

Twitter has disclosed more bugs related to how it uses personal data for ad targeting that means it may have shared users data with advertising partners even when a user had expressly told it not to.

Back in May the social network disclosed a bug that in certain conditions resulted in an account’s location data being shared with a Twitter ad partner, during real-time bidding (RTB) auctions.

In a blog post on its Help Center about the latest “issues” Twitter says it “recently” found, it admits to finding two problems with users’ ad settings choices that mean they “may not have worked as intended”.

It claims both problems were fixed on August 5. Though it does not specify when it realized it was processing user data without their consent.

The first bug relates to tracking ad conversions. This meant that if a Twitter user clicked or viewed an ad for a mobile application on the platform and subsequently interacted with the mobile app Twitter says it “may have shared certain data (e.g., country code; if you engaged with the ad and when; information about the ad, etc)” with its ad measurement and advertising partners — regardless of whether the user had agreed their personal data could be shared in this way.

It suggests this leak of data has been happening since May 2018 — which is also the day when Europe’s updated privacy framework, GDPR, came into force. The regulation mandates disclosure of data breaches (which explains why you’re hearing about all these issues from Twitter) — and means that quite a lot is riding on how “recently” Twitter found these latest bugs. Because GDPR also includes a supersized regime of fines for confirmed data protection violations.

Though it remains to be seen whether Twitter’s now repeatedly leaky adtech will attract regulatory attention…

Twitter specifies that it does not share users’ names, Twitter handles, email or phone number with ad partners. However it does share a user’s mobile device identifier, which GDPR treats as personal data as it acts as a unique identifier. Using this identifier, Twitter and Twitter’s ad partners can work together to link a device identifier to other pieces of identity-linked personal data they collectively hold on the same user to track their use of the wider Internet, thereby allowing user profiling and creepy ad targeting to take place in the background.

The second issue Twitter discloses in the blog post also relates to tracking users’ wider web browsing to serve them targeted ads.

Here Twitter admits that, since September 2018, it may have served targeted ads that used inferences made about the user’s interests based on tracking their wider use of the Internet — even when the user had not given permission to be tracked.

This sounds like another breach of GDPR, given that in cases where the user did not consent to being tracked for ad targeting Twitter would lack a legal basis for processing their personal data. But it’s saying it processed it anyway — albeit, it claims accidentally.

This type of creepy ad targeting — based on so-called ‘inferences’ — is made possible because Twitter associates the devices you use (including mobile and browsers) when you’re logged in to its service with your Twitter account, and then receives information linked to these same device identifiers (IP addresses and potentially browser fingerprinting) back from its ad partners, likely gathered via tracking cookies (including Twitter’s own social plug-ins) which are larded all over the mainstream Internet for the purpose of tracking what you look at online.

These third party ad cookies link individuals’ browsing data (which gets turned into inferred interests) with unique device/browser identifiers (linked to individuals) to enable the adtech industry (platforms, data brokers, ad exchanges and so on) to track web users across the web and serve them “relevant” (aka creepy) ads.

“As part of a process we use to try and serve more relevant advertising on Twitter and other services since September 2018, we may have shown you ads based on inferences we made about the devices you use, even if you did not give us permission to do so,” it how Twitter explains this second ‘issue’.

“The data involved stayed within Twitter and did not contain things like passwords, email accounts, etc.,” it adds. Although the key point here is one of a lack of consent, not where the data ended up.

(Also, the users’ wider Internet browsing activity linked to their devices via cookie tracking did not originate with Twitter — even if it’s claiming the surveillance files it received from its “trusted” partners stayed on its servers. Bits and pieces of that tracked data would, in any case, exist all over the place.)

In an explainer on its website on “personalization based on your inferred identity” Twitter seeks to reassure users that it will not track them without their consent, writing:

We are committed to providing you meaningful privacy choices. You can control whether we operate and personalize your experience based on browsers or devices other than the ones you use to log in to Twitter (or if you’re logged out, browsers or devices other than the one you’re currently using), or email addresses and phone numbers similar to those linked to your Twitter account. You can do this by visiting your Personalization and data settings and adjusting the Personalize based on your inferred identity setting.

The problem in this case is that users’ privacy choices were simply overridden. Twitter says it did not do so intentionally. But either way it’s not consent. Ergo, a breach.

“We know you will want to know if you were personally affected, and how many people in total were involved. We are still conducting our investigation to determine who may have been impacted and If we discover more information that is useful we will share it,” Twitter goes on. “What is there for you to do? Aside from checking your settings, we don’t believe there is anything for you to do.

“You trust us to follow your choices and we failed here. We’re sorry this happened, and are taking steps to make sure we don’t make a mistake like this again. If you have any questions, you may contact Twitter’s Office of Data Protection through this form.”

While the company may “believe” there is nothing Twitter users can do — aside from accept its apology for screwing up — European Twitter users who believe it processed their data without their consent do have a course of action they can take: They can complain to their local data protection watchdog.

Zooming out, there are also major legal question marks hanging over behaviourally targeted ads in Europe.

The UK’s privacy regulator warned in June that systematic profiling of web users via invasive tracking technologies such as cookies is in breach of pan-EU privacy laws — following multiple complaints filed in the region that argue RTB is in breach of the GDPR.

While, back in May Google’s lead regulator in Europe, the Irish Data Protection Commission, confirmed it has opened a formal investigation into use of personal data in the context of its online Ad Exchange.

So the wider point here is that the whole leaky business of creepy ads looks to be operating on borrowed time.



source https://techcrunch.com/2019/08/07/twitter-fesses-up-to-more-adtech-leaks/

Tuesday, 6 August 2019

Google’s Advice for Surviving Algorithm Changes

google

In case you missed it, Google just published advice for SEOs on how to continually do well throughout their algorithm changes.

Now, what most people don’t know is Google doesn’t just push out a handful of algorithm changes per year.

They publish substantially more.

Just to give you an idea of how often Google changes, they had 3,200 algorithm changes in just 1 year.

You heard me right, 3,200 changes.

That’s a lot!

So instead of focusing on one algorithm update that you may read about, you need to focus on making your site compatible with Google’s core goal.

First I’ll go over the advice they are telling us all to follow… and then I’ll break down what it really means.

Google’s advice to SEOs

Just like most of their announcements, Google tends to be vague. But of course, they did mention that you should focus on content.

What’s interesting, though, is they did give a list of questions that you should ask yourself with your existing and new content.

But as I mentioned they are vague… so I decided to do something a bit unique. Next to each question that Google provides (in the color black), you’ll find my thoughts on what I think Google is trying to tell you (in the color orange).

Here goes:

Content and quality questions

  • Does the content provide original information, reporting, research, or analysis? – Although Google doesn’t penalize for duplicate content, they are looking for new, fresh content. With over a billion blogs on the Internet, there is a lot of regurgitated content out there these days.
  • Does the content provide a substantial, complete, or comprehensive description of the topic? – When a user performs a search, Google wants to give them what they are looking for with the least amount of work. They don’t want to have the user go to multiple sites to get their answer. Pages that are thorough and answer all parts of the user’s search query are more likely to rank. In other words, if you write thin content, it probably isn’t satisfactory for the searcher, which means you may not rank as high as you want.
  • Does the content provide insightful analysis or interesting information that is beyond obvious? – Does your content have more to offer than what your competition is producing? Go above and beyond by providing additional analysis or drawing your own conclusions using additional data that may be helpful to the reader.
  • If the content draws on other sources, does it avoid simply copying or rewriting those sources and instead provide substantial additional value and originality? – Don’t just copy and paste someone else’s content then link to them and provide a few lines of commentary. If you are going to reference someone else’s content, make sure you draw your own conclusions and the majority of the text on that page is unique and useful.
  • Does the headline and/or page title provide a descriptive, helpful summary of the content? – 8 out of 10 people read a headline and only 2 out of 10 people click through to read the rest. Your headlines not only need to be appealing, but they need to summarize the content. Don’t just focus on keywords or clickbait, focus on user experience with your headlines.
  • Does the headline and/or page title avoid being exaggerating or shocking in nature? – Google can tell if you are using clickbait as that typically causes a high bounce rate. If they see that people are going back to the SERP listing, it means that your content wasn’t up to par and you just used clickbait to trick searchers.
  • Is this the sort of page you’d want to bookmark, share with a friend, or recommend? – As Eric Schmidt, the ex-CEO of Google, once said, brands are the solution. Google prefers ranking brands, so don’t prioritize SEO. Focus first on your user. Make them love your content, your product, and your service.
  • Would you expect to see this content in or referenced by a printed magazine, encyclopedia, or book? – If you think your content is so great you are willing to print it out and hang it up on your wall, you have done a great job. If you are just creating content for the sake of it, people will be able to tell.

Expertise questions

  • Does the content present information in a way that makes you want to trust it, such as clear sourcing, evidence of the expertise involved, background about the author or the site that publishes it, such as through links to an author page or a site’s About page? – The best way to position yourself as an expert is to use data and cite your sources. In addition, if you are going to be an expert, make sure you have your name on the page and even link to your bio.
  • If you researched the site producing the content, would you come away with an impression that it is well-trusted or widely-recognized as an authority on its topic? – Compared to your competition how are you seen? If you are more respected and more popular, it shows that you are potentially an expert. You should work on your brand queries as it will help get you more visibility.
  • Is this content written by an expert or enthusiast who demonstrably knows the topic well? – Are you faking it or are you clearly an expert on this topic? Sure, I can research the law and write content about the law, but I am not a lawyer and it would be obvious. Write about what you know, and if you don’t know it, go learn it really well first before writing about it.
  • Is the content free from easily-verified factual errors? – Creating fake news will hurt you. Don’t contribute false information to the web. If you write a few pieces with false information and Google catches on, it could potentially damage your whole site.
  • Would you feel comfortable trusting this content for issues relating to your money or your life? – If someone does a search on Google and lands on your site, what will happen if they read your content? If they continue on to another site and continually researches, it means that they don’t trust you enough yet. Not only is it important for you to create amazing content, but you need to show the reader why you are a credible source and why they should pay attention to you instead of someone else in the space.

Presentation and production questions

  • Is the content free from spelling or stylistic issues? – Check your content for grammar and spelling errors. Once you do that, make sure your content is easy to read. For example, having a neon font color on a white background is hard to read.
  • Was the content produced well, or does it appear sloppy or hastily produced? – Spend time making sure the content you put out on the web is polished. From custom graphics and videos to images and podcasts, make sure the overall experience is great. Write good content isn’t enough as everyone is doing that these days.
  • Is the content mass-produced by or outsourced to a large number of creators, or spread across a large network of sites, so that individual pages or sites don’t get as much attention or care? – Google wants individual pages to fully answer searchers questions. If someone is looking for an answer and you link out to a lot of other sites to explain your answer, then you aren’t creating the best experience. Focus on creating an amazing experience not only from a site level but from an individual page level too.
  • Does the content have an excessive amount of ads that distract from or interfere with the main content? – Your website needs to load fast. Ads slow down a site and can ruin the user experience. Monetizing shouldn’t be the core focus of your site, instead, it should be to educate and help visitors.
  • Does content display well for mobile devices when viewed on them? – Roughly 60% of searches on Google happen on mobile devices. Your content needs to be mobile and tablet friendly.

Comparative questions

  • Does the content provide substantial value when compared to other pages in search results? – If you are trying to rank for a keyword, look at the top 10 pages that currently take up page 1 and make sure your content is better and more thorough than what is already ranking. If you don’t create something that is superior in quality, there is no reason for Google to place your site above the competition.
  • Does the content seem to be serving the genuine interests of visitors to the site or does it seem to exist solely by someone attempting to guess what might rank well in search engines? – Don’t write content for search engines. Write for humans first as Google’s goal is to satisfy humans. Even in the short run if this means you won’t rank as high, that’s fine. Eventually, Google will figure it out and your content will rank higher over time as long as you are focusing on the end-user.

Conclusion

There were a few other things Google mentioned, such their quality guidelines, but there was one really important thing that they mentioned.

It’s also important to understand that search engines like Google do not understand content the way human beings do. Instead, we look for signals we can gather about content and understand how those correlate with how humans assess relevance.

Google’s wants to please you, not the version of you that is a marketer or an entrepreneur, but the version of you that uses Google on a daily basis.

When you perform a Google search, are you happy with the results?

If you aren’t, you aren’t going to tell Google with your words as there isn’t an easy way to do that. That’s why they look at signals, such as click-through-rates or how many people hit the back button so they can go back to Google and click on the next listing.

Instead of focusing on SEO, the real trick to winning is to focus on the user.

Go above and beyond and do what is best for them even if you feel it will hurt your rankings in the short run. Because in the long run, Google will figure it out and you should rank better if you are genuinely putting the user first and doing a better job than your competition.

So, what do you think of Google’s advice to SEOs?

The post Google’s Advice for Surviving Algorithm Changes appeared first on Neil Patel.



source https://neilpatel.com/blog/googles-advice-for-seo/

Snap looks to raise $1 billion in private debt offering

Snap, the parent company of Snapchat, is looking to add some cash to its coffers via a new proposed private offering of $1 billion in convertible senior notes, with a due date for maturation of August 1, 2026. The debt offering will be used to cover the cost of general operating expenditures involved in running the business, Snap says, but also potentially to “acquire complementary businesses, products, services or technologies,” as well as possibly for future stock repurchase plans, though no such plans exist currently.

Raising debt to fund operations and acquisitions is not unusual for a publicly traded company – Netflix does this regularly to pick up more money to fund its increasingly expensive production budget for content, for instance. So far, the market seems to be reacting negatively to the news of Snap’s decision to seek this chunk of debt funding, however, as it’s down in pre-market trading.

Snap has generally been on a positive path in terms of its relationship with stockholders, however – its stock price rose on the back of a strong quarterly earnings report at the end of July, closing above its IPO price for the first time. It’s now dipped south of that mark again, but it’s still much-improved on a year-to-date timeline measure.



source https://techcrunch.com/2019/08/06/snap-looks-to-raise-1-billion-in-private-debt-offering/

Squad, the ‘anti-bro startup,’ is creating a safe space for teenage girls online

When we go online to communicate, hang out or play, we’re typically logging on to platforms conceived of and built by men.

Mark Zuckerberg famously created Facebook in his Harvard dorm room. Evan Spiegel and his frat brother Bobby Murphy devised a plan for the ephemeral messaging app Snapchat while the pair were still students at Stanford. Working out of a co-working space, Kevin Systrom and Mike Krieger built Instagram and yes, they also went to Stanford.

Seldom have social tools created by women climbed the latter to mainstream success. Instead, women and girls have battled the lion’s share of digital harassment on popular social platforms — most of which failed early-on to incorporate security features tailored to minority user’s needs — and struggled to find a protected corner of the internet.

Squad, an app that allows you to video chat and share your phone screen with a friend in real-time, has tapped into a demographic clamoring for a safe space to gather online. Without any marketing, the startup has collected 450,000 registered users in eight months, 70% of which are teenage girls. So far this year, users have clocked in 1 million hours inside Squad calls.

“Completely accidentally we’ve developed this global audience of users and it’s girls all over the world,” Squad co-founder and chief executive officer Esther Crawford tells TechCrunch. “In India, it’s girls. In Saudia Arabia, it’s girls. In the U.S., it’s girls. Even without us localizing it, girls all over the world are finding it.”

Squad screens

Squad, the social screen sharing and group video chat app, has pulled together a $5 million investment led by First Round Capital.

Learn from the best but get rid of the shit

A remote team of six people led by Crawford, who’s a graduate of Oregon State University, Squad’s compelling founding story and organic growth helped them close a $5 million seed round led by First Round Capital general partner Hayley Barna, the only female partner at the historically all-male early-stage investment fund known for being the first institutional check in Uber.

Betaworks, Alpha Bridge Ventures, Day One Ventures, Jane VC, Mighty Networks CEO Gina Bianchini, early Snapchat employee Sebastian Gil and Y Combinator, the startup accelerator program Squad completed in the winter of 2018, have also participated in the funding round.

“We want to be a place where girls can come and hang out,” -Squad co-founder and CEO Esther Crawford.

Crawford describes Squad, which she’s built alongside her co-founder and chief technology officer Ethan Sutin, as the “anti-bro startup.” Not only because it’s led by a woman and boasts a cap table that’s 30% women and 30% people of color, but because she’s completely rewriting the consumer social startup playbook.

“We are trying to learn from the best in what they did but get rid of the shit,” Crawford said, referring to Snap, WhatsApp, Twitch and others. Twitch, a live-streaming platform for gamers, has become a social gathering place for Gen Z, she explains, but like many other communities on the internet, it’s failed its female users.

“Girls have been completely pushed off of Twitch,” she said. “The Twitch community didn’t want them there and they weren’t friendly to them. For boys, there are places you can go to consume content with other people, like Fortnite, but for girls there hasn’t been a place that’s really broken out. We want to be a place where girls can come and hang out.”

What Crawford and the small team at Squad have realized is that you don’t have to sacrifice growth for user safety and comfort. From the beginning, Squad has made sure users could easily block and report inappropriate behaviors and users, a feature that was an afterthought on many other social tools. They also made users unsearchable unless another user knows their exact username. By prioritizing the security of its primarily female audience, Squad is betting girls will continue coming back to the app and telling their friends about it.

“It’s possible to make girls feel safe and still have growth as a consumer product,” she said. “If people don’t feel safe on your app, they won’t stick around long-term.”

A new playbook

Squad quietly launched in January after pivoting away from building an information-sharing tool called Molly, which was backed with $1.5 million from BBG, Betaworks, CrunchFund and Halogen Ventures. Crawford’s now 14-year-old daughter unintentionally inspired the transition, when she proposed her mom create an app where she could peer into her best friend’s phones from afar.

IMG 2588

This reporter and Squad CEO Esther Crawford discuss the startup’s growth via Squad video chat.

Using Squad, people can browse memes, pore through DMs, plan a trip on Airbnb, peruse Tinder or a photo album with a friend via its video chat and screen share features. As Crawford describes it, it’s all the stuff you don’t want to post to Snap or Instagram but want to show your best friends. An app that may seem frivolous or non-essential seems to have quickly become a space online where girls can are opting to spend hours intimately engaged with their friends — without fear of stumbling into a troll.

“People can use this digital tech to hang out together instead of it being so performative,” Crawford said.

The downside of Squad’s screen sharing capabilities is a user can view another user’s Facebook friend’s profile, even if, say, they themselves were blocked from viewing that content. Most apps are available for viewing through screen share aside from premium video streaming apps like Netflix or Amazon Prime Video, so its entirely possible someone could use Squad solely for the purpose of viewing social content they are otherwise barred from seeing. In response to this possibility, Crawford says they are considering alerting users when their Squad chat’s been screen-shotted. To avoid additional privacy issues, Squad users can’t record or save anything from their calls or replay what happened on Squad.

Like many early-stage startups, the company isn’t making any money yet because the app is free and without ads. As soon as next year, however, Squad plans to monetize the product with in-app purchasing, scraping another rule from the consumer social playbook that has long encouraged companies to expand their user base first before trying to profit off users at all. (See: The Snapchat Monetization Problem).

Techno-optimism

Crawford, a product marketing veteran, grew up in a cult in Oregon where girls were barred from wearing makeup and from watching television or listening to music. But because the internet was so early, the dangers of it were yet to be discovered and miraculously, she was allowed to go online. Quickly, she made connections with people all over the world thanks to everyone’s favorite messaging tool at the time, AOL Instant Messenger.

The experience planted in her a deep love for the internet and a desire to share her life online. After developing a community through AIM, Crawford became one of the very first original content creators on YouTube and garnered millions of views on her videos. Without trying, she became an influencer, long before the term entered the zeitgeist.

Squad Screensharing1

She used her newfound digital prowess to launch one of the first social marketing agencies, where her clients included Weight Watchers and K-Mart, legacy brands that had no idea how to tap into her native digital communities. Ultimately, Crawford landed in the tech startup world, hopping from Series A startup to Series A startup, offering up her product marketing skills before her daughter’s idea prompted her to go into business on her own again.

“I’m a techno-optimist and yet, so many of these tech companies we thought were going to connect people turned out to have accidentally made people more lonely,” she said. “With a different lense and approach, I thought there could be an app that built bridges.”

Now with a new bout of funding, Squad can implement strategic marketing campaigns, continue adding integrations with complementary platforms (the startup has just announced a new integration with YouTube) and hire product designers. The next few years will be critical to Squad’s success as it looks to young people to give them a permanent spot on their home screen.

For Crawford, what’s most important, aside from growing group of teenagers using Squad, is to make sure only good people see a big payday thanks to her great idea: “I am ready to do everything I can to make Squad successful and make sure our success has a positive downstream effect so that we have great people on our team that get rich off our success.”



source https://techcrunch.com/2019/08/06/squad-the-anti-bro-startup/

Facebook still full of groups trading fake reviews, says consumer group

Facebook has failed to clean up the brisk trade in fake product reviews taking place on its platform, an investigation by the consumer association Which? has found.

In June both Facebook and eBay were warned by the UK’s Competition and Markets Authority (CMA) they needed to do more to tackle the sale of fake product reviews. On eBay sellers were offering batches of five-star product reviews in exchange for cash, while Facebook’s platform was found hosting multiple groups were members solicited writers of fake reviews in exchange for free products or cash (or both).

A follow-up look at the two platforms by Which? has found a “significant improvement” in the number of eBay listings selling five-star reviews — with the group saying it found just one listing selling five-star reviews after the CMA’s intervention.

But little appears to have been done to prevent Facebook groups trading in fake reviews — with Which? finding dozens of Facebook groups that it said “continue to encourage incentivised reviews on a huge scale”.

Here’s a sample ad we found doing a ten-second search of Facebook groups… (one of a few we saw that specify they’re after US reviewers)

Screenshot 2019 08 06 at 09.53.19

Which? says it found more than 55,000 new posts across just nine Facebook groups trading fake reviews in July, which it said were generating hundreds “or even thousands” of posts per day.

It points out the true figure is likely to be higher because Facebook caps the number of posts it quantifies at 10,000 (and three of the ten groups had hit that ceiling).

Which? also found Facebook groups trading fake reviews that had sharply increased their membership over a 30-day period, adding that it was “disconcertingly easy to find dozens of suspicious-looking groups in minutes”.

We also found a quick search of Facebook’s platform instantly serves a selection of groups soliciting product reviews…

Screenshot 2019 08 06 at 09.51.09

Which? says looked in detail at ten groups (it doesn’t name the groups), all of which contained the word ‘Amazon’ in their group name, finding that all of them had seen their membership rise over a 30-day period — with some seeing big spikes in members.

“One Facebook group tripled its membership over a 30-day period, while another (which was first started in April 2018) saw member numbers double to more than 5,000,” it writes. “One group had more than 10,000 members after 4,300 people joined it in a month — a 75% increase, despite the group existing since April 2017.”

Which? speculates that the surge in Facebook group members could be a direct result of eBay cracking down on fake reviews sellers on its own platform.

“In total, the 10 [Facebook] groups had a staggering 105,669 members on 1 August, compared with a membership of 85,647 just 30 days prior to that — representing an increase of nearly 19%,” it adds.

Across the ten groups it says there were more than 3,500 new posts promoting inventivised reviews in a single day. Which? also notes that Facebook’s algorithm regularly recommended similar groups to those that appeared to be trading in fake reviews — on the ‘suggested for you’ page.

It also says it found admins of groups it joined listing alternative groups to join in case the original is shut down.

Commenting in a statement, Natalie Hitchins, Which?’s head of products and services, said: ‘Our latest findings demonstrate that Facebook has systematically failed to take action while its platform continues to be plagued with fake review groups generating thousands of posts a day.

“It is deeply concerning that the company continues to leave customers exposed to poor-quality or unsafe products boosted by misleading and disingenuous reviews. Facebook must immediately take steps to not only address the groups that are reported to it, but also proactively identify and shut down other groups, and put measures in place to prevent more from appearing in the future.”

“The CMA must now consider enforcement action to ensure that more is being done to protect people from being misled online. Which? will be monitoring the situation closely and piling on the pressure to banish these fake review groups,” she added.

Responding to Which?‘s findings in a statement, CMA senior director George Lusty said: “It is unacceptable that Facebook groups promoting fake reviews seem to be reappearing. Facebook must take effective steps to deal with this problem by quickly removing the material and stop it from resurfacing.”

“This is just the start – we’ll be doing more to tackle fake and misleading online reviews,” he added. “Lots of us rely on reviews when shopping online to decide what to buy. It is important that people are able to trust they are genuine, rather than something someone has been paid to write.”

In a statement Facebook claimed it has removed 9 out of ten of the groups Which? reported to it and claimed to be “investigating the remaining group”.

“We don’t allow people to use Facebook to facilitate or encourage false reviews,” it added. “We continue to improve our tools to proactively prevent this kind of abuse, including investing in technology and increasing the size of our safety and security team to 30,000.”



source https://techcrunch.com/2019/08/06/facebook-still-full-of-groups-trading-fake-reviews-says-consumer-group/

Monday, 5 August 2019

8chan’s new internet host was kicked off its own host just hours later

The bottom-feeding forum 8chan, which grew popular by embracing fringe hateful internet cultures, is having trouble staying online. After Cloudflare dropped its protection of the site yesterday, 8chan adopted the services of Bitmitigate, but soon lost that too as the company providing Bitmitigate with services dropped them. Deplatforming works, but it can be complicated, so here’s a quick explanation of what these pieces are and why we’re witnessing this hot-potato act in the wake of the latest tragic mass shootings.

To put a website online, people generally need three things.

First, a name registrar. This is the company that officially owns and licenses to you the specific series of letters and numbers that make up your website’s name, like techcrunch.com.

Second, a domain name service. These do work in the background to turn requests, like putting facebook.com into their browser bar, into actions: finding the IP address where Facebook is and establishing a connection between that one and the user’s.

Third, an actual server. Your data has to physically be stored somewhere with a fat pipe to the internet so others can access it. Servers are usually “virtualized” in that you don’t really rent five computers somewhere but rather a certain amount of capacity on a huge shared server farm.

Increasingly a fourth piece is necessary: caching and denial-of-service attack protection. This is a service like Cloudflare’s, which sits in front of the website and sort of sifts the traffic so attacks are turned away and the website stays up even during other kinds of outages. It’s not required, but is highly recommended.

When 8chan lost Cloudflare, it was exposed to the full force of the internet, likely including DDoS and other attacks, and was brought offline. But it soon found a new caching service in Bitmitigate.

Bitmitigate is one of several related businesses that provide various hosting services, all flying under the banner of one Rob Monster. In a statement to TechCrunch, Monster said that his companies “fill the ever growing need for a neutral service provider that will not arbitrarily terminate accounts based on social or political pressure.”

As evidence of this, Monster’s Epik domain name and hosting service is the current refuge of Gab, the right-wing social network populated by those excommunicated from Facebook, Twitter and other services with robust hate speech and abuse rules. Same for Daily Stormer, the white supremacist news site and forum. If they aren’t breaking the law, Monster said, it’s up to the provider whether to host them, and he chose to host. That may change, though.

“We have also not made a definitive decision about whether to provide DDoS mitigation or Content Delivery services for them. We will evaluate this in the coming days,” Monster wrote.

So 8chan went to Bitmitigate, but it wasn’t long before the forum had that rug pulled out from under them as well. Turns out that Epik and Bitmitigate were purchasing services from a larger service provider called Voxility.

If this sounds over-complicated, just think of it this way: A cafe needs to provide internet to its customers, so it buys a high-speed connection from an ISP. Then it provides access to that connection to its customers using its own little portal or control method, maybe so you have to buy a coffee before you can get online. This is a bit like that: Epik was reselling the services of Voxility at a markup to a specific set of customers. It’s a common enough thing online, but as we saw today, a bit risky.

Turns out Voxility wants no part of hosting 8chan, and after being alerted (by former Facebook CSO Alex Stamos) that one of its clients had decided to do so, it simply pulled the plug on Epik’s services; right now Bitmitigate, Daily Stormer and 8chan are all down. They deplatformed the platform.

See, the problem with bigger service providers is they like to limit their exposure to things like 8chan, which are bad optics waiting to happen. If you’re the host of a service to which mass murderers frequently post their pre-shooting screeds to an adoring audience of conspiracy theorists and incels, people might just take their business elsewhere. There’s no shortage of options.

So the larger these services get, the more likely it is they will have something in place to give them carte blanche to kick off or refuse service to sites and actors they believe to be bad business. It’s a bit sad that deplatforming hate has to have a business case, but for now let’s just be happy that case exists.

A hate-promoting site doesn’t just have to find someone who will provide each of the critical services listed at the start, but will provide them to a high-risk client for a reasonable price. That’s getting to be rather difficult.

As of this writing, 8chan is still down and Bitmitigate is still recovering from having its services yanked by Voxility. Who will host the hosts? Increasingly few internet services companies want to be involved with toxic internet subcultures and even real-life toxic cultures like white supremacy.

While as many have pointed out this does create new problems, it also does a pretty good number on some of the problems we’ve already got. I’ll take that over inaction any day.



source https://techcrunch.com/2019/08/05/8chans-new-internet-host-was-kicked-off-its-own-host-just-hours-later/

Libra, Facebook’s global digital currency plan, is fuzzy on privacy, watchdogs warn

Privacy commissioners from the Americas, Europe, Africa and Australasia have put their names to a joint statement raising concerns about a lack of clarity from Facebook over how data protection safeguards will be baked into its planned cryptocurrency project, Libra.

Facebook officially unveiled its big bet to build a global digital currency using blockchain technology in June, steered by a Libra Association with Facebook as a founding member. Other founding members include payment and tech giants such as Mastercard, PayPal, Uber, Lyft, eBay, VC firms including Andreessen Horowitz, Thrive Capital and Union Square Ventures, and not-for-profits such as Kiva and Mercy Corps.

At the same time Facebook announced a new subsidiary of its own business, Calibra, which it said will create financial services for the Libra network, including offering a standalone wallet app that it expects to bake into its messaging apps, Messenger and WhatsApp, next year — raising concerns it could quickly gain a monopolistic hold over what’s being couched as an ‘open’ digital currency network, given the dominance of the associated social platforms where it intends to seed its own wallet.

In its official blog post hyping Calibra Facebook avoided any talk of how much market power it might wield via its ability to promote the wallet to its existing 2.2BN+ global users, but it did touch on privacy — writing “we’ll also take steps to protect your privacy” by claiming it would not share “account information or financial data with Facebook or any third party without customer consent”.

Except for when it admitted it would; the same paragraph states there will be “limited cases” when it may share user data. These cases will “reflect our need to keep people safe, comply with the law and provide basic functionality to the people who use Calibra”, the blog adds. (A Calibra Customer Commitment provides little more detail than a few sample instances, such as “preventing fraud and criminal activity”.)

All of that might sound reassuring enough on the surface but Facebook has used the fuzzy notion of needing to keep its users ‘safe’ as an umbrella justification for tracking non-Facebook users across the entire mainstream Internet, for example.

So the devil really is in the granular detail of anything the company claims it will and won’t do.

Hence the lack of comprehensive details about Libra’s approach to privacy and data protection is causing professional watchdogs around the world to worry.

“As representatives of the global community of data protection and privacy enforcement authorities, collectively responsible for promoting the privacy of many millions of people around the world, we are joining together to express our shared concerns about the privacy risks posed by the Libra digital currency and infrastructure,” they write. “Other authorities and democratic lawmakers have expressed concerns about this initiative. These risks are not limited to financial privacy, since the involvement of Facebook Inc., and its expansive categories of data collection on hundreds of millions of users, raises additional concerns. Data protection authorities will also work closely with other regulators.”

Among the commissioners signing the statement is the FTC’s Rohit Chopra: One of two commissioners at the US Federal Trade Commission who dissented from the $5BN settlement order that was passed by a 3:2 vote last month

Also raising concerns about Facebook’s transparency about how Libra will comply with privacy laws and expectations in multiple jurisdictions around the world are: Canada’s privacy commissioner Daniel Therrien; the European Union’s data protection supervisor, Giovanni Buttarelli; UK Information commissioner, Elizabeth Denham; Albania’s information and data protection commissioner, Besnik Dervishi; the president of the Commission for Information Technology and Civil Liberties for Burkina Faso, Marguerite Ouedraogo Bonane; and Australia’s information and privacy commissioner, Angelene Falk.

In the joint statement — on what they describe as “global privacy expectations of the Libra network” — they write:

In today’s digital age, it is critical that organisations are transparent and accountable for their personal information handling practices. Good privacy governance and privacy by design are key enablers for innovation and protecting data – they are not mutually exclusive. To date, while Facebook and Calibra have made broad public statements about privacy, they have failed to specifically address the information handling practices that will be in place to secure and protect personal information. Additionally, given the current plans for a rapid implementation of Libra and Calibra, we are surprised and concerned that this further detail is not yet available. The involvement of Facebook Inc. as a founding member of the Libra Association has the potential to drive rapid uptake by consumers around the globe, including in countries which may not yet have data protection laws in place. Once the Libra Network goes live, it may instantly become the custodian of millions of people’s personal information. This combination of vast reserves of personal information with financial information and cryptocurrency amplifies our privacy concerns about the Libra Network’s design and data sharing arrangements.

We’ve pasted the list of questions they’re putting to the Libra Network below — which they specify is “non-exhaustive”, saying individual agencies may follow up with more “as the proposals and service offering develops”.

Among the details they’re seeking answers to is clarity on what users personal data will be used for and how users will be able to control what their data is used for.

The risk of dark patterns being used to weaken and undermine users’ privacy is another stated concern.

Where user data is shared the commissioners are also seeking clarity on the types of data and the de-identification techniques that will be used — on the latter researchers have demonstrated for years that just a handful of data points can be used to re-identify credit card users from an ‘anonymous’ data-set of transactions, for example.

Here’s the full list of questions being put to the Libra Network:

  • 1. How can global data protection and privacy enforcement authorities be confident that the Libra Network has robust measures to protect the personal information of network users? In particular, how will the Libra Network ensure that its participants will:

    • a. provide clear information about how personal information will be used (including the use of profiling and algorithms, and the sharing of personal information between members of the Libra Network and any third parties) to allow users to provide specific and informed consent where appropriate;
    • b. create privacy-protective default settings that do not use nudge techniques or “dark patterns” to encourage people to share personal data with third parties or weaken their privacy protections;
    • c. ensure that privacy control settings are prominent and easy to use;
    • d. collect and process only the minimum amount of personal information necessary to achieve the identified purpose of the product or service, and ensure the lawfulness of the processing;
    • e. ensure that all personal data is adequately protected; and
    • f. give people simple procedures for exercising their privacy rights, including deleting their accounts, and honouring their requests in a timely way.
  • 2. How will the Libra Network incorporate privacy by design principles in the development of its infrastructure?

  • 3. How will the Libra Association ensure that all processors of data within the Libra Network are identified, and are compliant with their respective data protection obligations?

  • 4. How does the Libra Network plan to undertake data protection impact assessments, and how will the Libra Network ensure these assessments are considered on an ongoing basis?

  • 5. How will the Libra Network ensure that its data protection and privacy policies, standards and controls apply consistently across the Libra Network’s operations in all jurisdictions?

  • 6. Where data is shared amongst Libra Network members:

    • a. what data elements will be involved?

    • b. to what extent will it be de-identified, and what method will be used to achieve de-identification?
      c. how will Libra Network ensure that data is not re-identified, including by use of enforceable contractual commitments with those with whom data is shared?

We’ve reached out to Facebook for comment.



source https://techcrunch.com/2019/08/05/libra-facebooks-global-digital-currency-plan-is-fuzzy-on-privacy-watchdogs-warn/