Showing posts with label privacy policies. Show all posts
Showing posts with label privacy policies. Show all posts

11 September 2018

Want To Color Your Hair? Try #VR First @LOrealParisUSA Next Week Perhaps #AR Too!

I like it when companies use tech creatively to their benefit and in turn to the benefit of customers. For instance, I received an email today from L'Oreal Paris USA touting a new Virtual Reality (VR) tool that allows you to virtually try on different hair shades to see what you like and what you will look like before you dye. (You take a selfie and then apply filters matching shade colors to the image.)

While I wasn't planning to dye my hair anytime soon, I still paused to check out the creative use of tech and to appreciate that a company was working to use tech tools to its advantage. If Virtual Reality (or Augmented Reality) allows me to try on clothes, dye my hair, tour locations around the world, etc. all from the comfort of my own home then this is a win for me, especially because I'm a homebody.

There are few things which require my physical presence, in my opinion. I much prefer sending my telepresence wherever possible. Luckily for me, this is also the direction in which many routine chores, tasks and services are also moving. I hate being photographed, but for a service that saves me trouble and hassle I'd consider the trade-off (providing there are appropriate privacy/usage/copyright controls, of course).

Check the L'Oreal VR tool: Take a Selfie With Our Virtual Hair Color Try-On Tool! (Click "Try It On" on the hair color product image.)

L'Oreal is also developing Augmented Reality (AR) tools in partnership with Facebook. See the news release: https://www.loreal.com/media/news/2018/august/modiface.

09 May 2017

#InformedDelivery: @USPS Employs #Tech to Combat #Mail Theft! #HomeSecurity #MailCall #ImageCapture #Photography #House101

Roughly a month ago, I received an email from the United States Postal Service (USPS) touting a new home delivery service enhancement called Informed Delivery that would allow participants to "see their mail before it arrives" and thereby know what mail is expected. (Greyscale front side images of letter-sized mail destined for a registered address are captured during the normal USPS sorting process and made available for viewing to the registered party.) If you've ever had any cause for concern that your mail is going AWOL, whether due to mail theft or rogue postal employees, then signing up for Informed Delivery may offer some peace of mind. The service is free and currently covers machine sorted letter-sized mail. At the moment, Informed Delivery is only available in limited ZIP Codes, but is expanding. Service registration requires proof of identity/address (as it should).

Since receiving the initial email from the USPS back in April, I have received a couple other emails and at least one piece of direct mail touting Informed Delivery. It's obvious the USPS is showcasing (and even pushing) this new service. While Informed Delivery is an example of the notoriously "left-footed" USPS using modern technology in an ostensibly beneficial manner, there are some things to consider. Namely, that the USPS is a government agency and giving it leave to photograph your mail (and store those photos) may indeed provide enhanced security for your residential mail delivery, but it might also open up a new can of worms. (NOTE: The USPS already photographs the front side of automatically sorted mail, Informed Delivery service provides an alternate usage for these images.) Ask yourself: How long are mail images stored? Who has legal access to these images? How secure is the USPS website (and servers) which store these images? Is "proof of address" enough of a standard for service registration? (At the very least, read the USPS privacy policy and be aware of exactly to what you are agreeing.)

Questions such as these are important because mail can often be of a sensitive nature. The USPS is bound by law to protect the privacy of your information due to it being a government agency which deals with sensitive personal information, but you should still be aware of both sides of the coin. If images of your "private mail" are being stored on third party servers it WILL become the target of hackers ...and of law enforcement, because let's face it, a good deal of information can be gleaned merely from examining return addresses and addressees. The average person may not care if a third party is keeping a log of his mail (the postal service can, of course, do this already, it's how mail fraud investigations are undertaken). The average person may aver the oft repeated "I have nothing to hide" catchphrase that is doggedly put forth to counter any Big Brother arguments against more surveillance, but whether you personally fear government misuse of your potentially sensitive personal data does not exempt the government from needing to establish rules to secure such data collection. You may think you have nothing to hide, but the mere thought does not protect you from law enforcement subpoena or from criminals who might seek to hack your mail images and use any information gleaned from them in an attempt to blackmail you.

Informed Delivery could provide a valuable home service, it could prove a useful home security tool, but it needs to be rigorously secured (and regulated) to guard against exploitation. Just food for thought.

Visit https://informeddelivery.usps.com for more information or to signup for service.

29 March 2017

New #CastleDoctrine: Protect Your #Home From #Virtual Intruders #BroadbandPrivacy Block #ISP #Spying #Vote Against #Slavery

Congress sold you to your ISP. If that sounds a lot like virtual slavery, that's because it is what it is. ISPs do NOT have the right to your data without your consent regardless of what Congress rubber stamped. Take action! If you value your privacy, if you believe in the sanctity of your home (and that what you do behind closed doors is your business and not the purview of BIG business), protect your data NOW.

This is the new American frontier. Your home is your castle. You have a right to protect your home from intruders, including the virtual kind. Block ISP (and third party) spying, use a Virtual Private Network or VPN to encrypt all data whenever you go online AS A DEFAULT. Trust no-one and look out for you and yours.

Congress sold you to the highest bidder (the cable and telecom lobby) in what is the new standard for bad customer service and a new low for a promise to "serve the people." Refuse to be enslaved. Fight back. Escape from bondage. Protect your data NOW.

And then, vote the spineless bastards who approved this anti-privacy bill out.

25 March 2017

Fight for Your Right to ... #Privacy Your Home is Your #Castle

The United States Senate recently voted to pass a bill that would allow ISPs (you know the people who control the internet pipes and can see all the data flowing through them) to track you, package you and sell you to advertisers --- all without your consent. Apparently, the senators voting for this bill have forgotten that privacy is an inalienable right. If any internet businesses should be bound by strictures it is ISPs due to their (mostly) unfettered access to everything their users do online. With privilege comes responsibility and giving ISPs free reign with customers data is not a good idea any way you slice it. There is nothing wrong with being tracked with consent, there is plenty wrong with trying to say that a consumer does not "own" his own data and its OK for companies to use said data (including browsing history) without asking. If you can't be transparent about data collection, then it's likely shady. Just saying. If you don't want ISPs "tapping your wires" call Congress and give them an earful. Tell them, "I am not your product, so stop trying to sell me."* (As a staunch privacy advocate this crap makes my blood boil.)

*My slogan. Order your T-Shirt now! (Kidding about the Tee. But this is my slogan.)

22 February 2017

Estate #IntellectualProperty: #WhoisPrivacy #DomainRegistrars #IoT + #Gardening #Composting

I spent a good part of yesterday registering, transferring and setting up domain names. What should be seamless and simple invariably turns into a hassle, because each registrar has its own matrix. But I've finally gotten all my domains with a registrar that includes Whois database privacy as a default service (i.e., free). It's patently ridiculous to expect one to pay extra fees to keep his information private. (And yes, I hate the telephone directory, too, for this very reason.)

Privacy is an inalienable right. It should not be something for which one has to barter or pay a fee. Yes, I understand "privacy guard" registrars provide generic contact data for the Whois database and forward inquiries to the actual domain registrant, but big whoop! This should take almost no effort on their part. Charging for keeping domain registration contact data private is like charging for air. At any rate, all my estate or household domains are now setup.

As it rained a bit last night, the ground should be easier to breakup today. This afternoon, I'm hoping to finish expanding my compost pile which sits in a slightly recessed pit. I'm widening and deepening the pit, so I can turn the compost more easily and keep it well separate from any surrounding growth.

Once all this is done, there will be more cowbell er, milkshakes!


NOTE: With the ongoing IOT explosion in home market products, consider that it may be helpful to employ a household domain name/s (think thejoneseshome.com). This will allow one to setup everything from email to IPs per device, if necessary, and keep everything uniform, organized & connected.

08 February 2017

Why #AlwaysOn #HomeAutomation Needs an [OFF] Button: #IoT #Wiretapping #PrivacyPolicies #DataMining #DoNotTrack #Supercookies

As commercial entities rush to Internet-enable everything (can the smartflush toilet be far away?) consumers should hit the [PAUSE] button and examine the cost of all this "convenience". One should always remember that technology often outpaces legality (and unfortunately, ethics); if something can be achieved with technology, it likely will be, with or without license.

When the Internet first became the domain of commerce, online shopping early adopters were the first to test the waters and bear a share of the cost. As more and more people --- across various socio-economic strata --- went online, businesses realized that potential consumers could be drawn in by offering something for "free." There is no such thing as a free lunch; the exchange always consists of the consumer giving over some detail/s in order to obtain said freebie. Sometimes it's merely a name and address, but increasingly it's become a request for more and more extensive demographic information. (Fill out this survey, get a free pack of gum. Oh, did we forget to mention the gum is extra sticky and will track you for the rest of your life?)

Once businesses realized that consumers were willing to trade all sorts of data in exchange for a perceived "freebie," commercial exploitation of the Internet commenced in full measure. The Age of Freemium Enterprise was born. A entire global enterprise ecosystem has sprung up based upon the repackaging and selling of you (your data). Some of the biggest Internet tech companies make most of their money from advertising and advertising is lucrative for these companies because they take the Freemium Model to extremes: Offer a consumer a free service, get reams of personal information in return; tack on another free service, get more data; rinse and repeat. And because they realize that the average user is either too lazy or too ill-informed to bother to "unjoin" something included at signup, these companies use opt-in as the default --- you have to take action to opt-out --- automatically gaining access to tons of data, often from unwitting consumers.

The Freemium Model soon evolved into the Convenience Factor Model: Consumers were willing to pay for a service or gadget with perceived convenience for everyday life tasks and still give access to their data in return. (Yes, we literally buy into being spied upon with the advent of smart devices.) And the big boys took notice. Companies like Google, Apple, Facebook and Amazon have expanded into the home automation market because it's a most hallowed step, an open doorway into your most private space, granting access to information that previously might have been off limits. All via a consumer invitation to come on in.

Companies can now get real-time stats on your security setup (smart doorbells and smart cameras), your energy consumption (smart thermostats and smart meters), your entertainment choices (smart TVs, radios and gaming systems), your food consumption (smart refrigerators and smart crock pots) and even your linguistic patterns, random ruminations, shopping habits, and personal preferences (smart hubs or smart assistants) and much more --- all attached to location data and to a person or household. (There's a reason you're encouraged to sign-in with your often long-standing personal account to use all these new home automation tools and services offered by the behemoth tech firms.) Consumers are being quantified at every level and on every front.

Previously, much of this data could be intimated by tracking web search and online browsing habits, but it was an incomplete picture. IoT devices deployed in the home are allowing businesses to fill in those data gaps --- currently with little to no oversight as the arena is so new. For advertising and consumer sales dependent businesses, this is much better than the ill-advised supercookie Verizon used. (I'm paying you for what?) Better than stating "websites are not required to adhere to a Do Not Track request." Not only are many of these smart devices designed to be "Always On" but consumers are being sold on the idea that this is for the sake of our convenience, for our benefit, to help make our lives easier. Yes, it's a great boon for advertisers, vendors, and the data miners who feed them.

Think about it. Not only is an "Always On" smart device with an omnidirectional microphone and/or camera essentially an unhidden wiretap or voyeuristic eavesdropping box that can potentially record everything, but we're being told to think it's merely a cute toy or a dead helpful essential gadget. The convenience of getting on demand answers and actions, is supposed to blind us to the IoT connected home trade off. Namely, that "All Your Base Are Belong to Us." I would caution anyone to be aware to what data you are granting access when using any so-called smart device. (I've touched on this subject before, but the IoT consumer market is so new that the learning curve is still expanding.)

This can be difficult because some companies do not disclose how their device/s tracks your information or the disclosure is limited or buried in reams of other jargon. (Vizio is currently all over the news for surreptitiously tracking the viewing habits of its Smart TV users for years and selling the data, all without consumer consent. Samsung pulled a similar stunt several years ago with its early Smart TVs and so did LG to mention but a few cases.) Recall what I said earlier about technology often outpacing legality and ethics? It is apparently too tempting for a commercial entity to gain near unfettered access to you in the intimate setting of your home and not go overboard. Any web camera or Internet-connected Mic not only presents a potential security risk from hackers but also from the very purveyors of the devices. You would do well to never trust any device that is programmed to automatically phone home.

I'm not telling you to abstain. (Though certainly that is a choice, the ultimate opt-out. While it may keep you relatively safe at home, the outside world is now rife with Internet-connected devices. Cameras and microphones are everywhere in the public sphere. Short of moving to Mars, it helps to have an auxiliary plan.) I'm not saying these devices have no use. We all like convenience and the idea of tasks being accomplished for us effortlessly. I'm a techie, a tech geek and an engineer. I love my tech toys, too. I'm simply saying be aware, be educated, be proactive, especially when allowing any device with its own brain into your castle. (I'm an AI advocate, not a patsy.) As a consumer, the responsibility assuredly rests upon the individual to safeguard his own information. Do not count on a "business that depends on access to as much of your data as possible in order to insure its bottom line" being altruistic. Do not count on human decency. Better safe, than sorry.

You are the commodity. Realize this and act accordingly. Always check privacy policies and disclosures about how your information is collected and used (and if this isn't stated upfront contact the vendor), check the vendor reputation, keep abreast of the industry news and legislation that governs how companies can use your data (become active in lobbying for government regulations & consumer protections, if necessary), check device/s settings and controls (whether you're allowed to opt-out or limit data collection, turn off or limit device Internet access without affecting functionality), consider setting up a separate user account only for your device distinct from your personal account/s (I often do this) and if all else fails to stem the flow of your information remember to use the [OFF] button or simply unplug the thing when not in use.

Know that if a vendor, any vendor, tells you that having an "Always On" device in your home is not an invasion of your privacy, this vendor is full of it. It may not automatically be a nefarious intrusion, but it is still a third-party potentially gleaning access to things where previously the expectation of privacy was the default. Consumers should pause and come to terms with this before rushing head first into the coming dawn of data siphoning and purchasing the shop vac for it.


NOTE: I know that the popular refrain used by many folks whenever someone sounds an alarm regarding the potential for third-party observation in certain areas (police cameras in the streets, for instance) is "Doesn't bother me, I have nothing to hide" as if anyone concerned with personal privacy must be wanted by the law and on the lam. Instead, my concern is for the potential for misuse. Once your data is out there it's rather difficult to call it back, therefore any safeguard must occur prior. If you trust a third party with your data and later find out a fourth party hacked it, you may not have anything to hide per say, but you might still find yourself taken advantage of. But by all means, feel free to remain cavalier in your attitudes, it's what keeps unscrupulous businesses, identity thieves and other unsavory characters in the green. Just saying.

14 December 2016

Data Hog? #AmazonEcho on a Metered Connection? Without Internet Altogether? Not so fast...

As a new Amazon Echo owner, I have been debating whether I should embrace "always on". Beyond the Big Brother security and privacy concerns of having constant eavesdropping by Amazon and worse still personal recordings plumbed by unscrupulous third-party data-miners, I wondered how much data does Alexa eat? And the answer seems to be that she is a glutton.

Cursory research returned numerous complaints of users suddenly blowing through data caps. Apparently, learning a user's habits, predicting his likes, ordering items and checking the latest sports scores takes a unbelievable amount of bandwidth. I'm talking upwards of 50GBs IN A DAY, if reports are accurate.

Ridiculous! (I would NOT advise using Alexa on a metered connection. If you must try it, make certain to turn the unit off completely when not actively using it. As an alternative, consider using the Alexa app only, which you must select to activate in the case of the Amazon Fire Tablet.)

So far, I've only come across one mention of someone using an Echo sans Internet (as a Bluetooth speaker), but I want to know if Alexa can be employed strictly across a local intranet, without needing to phone home (i.e., report back to Amazon). I don't care about generating orders or asking random questions, my interest is in using Alexa to control "smart" things and this could be made an entirely localized activity, so I'm currently experimenting and testing limits, still early in the setup phase.

08 December 2016

No Need to Reinvent the Wheel #AlexaDev #AlexaSkills

Of course, now that I have an Amazon Echo (and the Alexa app on my Fire Tablet), I can't go two seconds without coming across an Alexa Skill. People send them to me, often unsolicited.
Alexa Can Learn: Skills are add-on code snippets that allow Alexa to do new things. Amazon opened the Alexa platform to third-party developers, so there have been a lot of skills created. As with any newly emerging tech, people play around with it. Some skills are mundane, some silly, and others are dead useful. Browse the Alexa app to see what's available. No need to reinvent the wheel. If you need Alexa to do a specific thing/s, chances are someone else might have needed that same ability and there may be a skill for it already in existence. Users can rate Alexa Skills that have been accepted to the platform, so check ratings to find out what others think. Be aware that using a third-party service could mean that Amazon will share your basic user data with said third-party. ALWAYS read privacy policies and terms of use and be aware to which conditions you're agreeing. No commercial entity is entirely altruistic despite catchy mottoes like "Don't Be Evil", so YOU must be the safeguard of your own data. Weigh the trade-offs and limit sharing, when necessary. (This includes what you share with Amazon.com.) Turn off the mic. It's hysterical that the idea of "Always On" is used as a selling point. 1984, much?
The other day I received an eNewsletter from some Purina brand that offered an Alexa Skill to determine "What dog breed is right for you?" My girl (a Rhodesian Ridgeback mix and former stray who rules the roost) looked at me and cocked her head to say, "As if." Guess we're not getting a puppy for Christmas!

Between skills and IFTTT triggers, Alexa will be able to help me run my household quite efficiently once I've configured everything to my liking. I'm still playing around with the litany of things I'll be able to do with Alexa, testing this and that and having a loads of fun in the process. Oh, the Places We'll Go....