patron privacy in a surveillance state adam chandler electronic resources and libraries 2014 march...

73
Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Upload: jeffry-barton

Post on 16-Jan-2016

213 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Patron Privacy in a Surveillance State

Adam Chandler

Electronic Resources and Libraries 2014March 18, 2014

Page 2: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

2

July 5, 1993

Page 3: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

3

“They are intent on making every conversation and every form of behaviour in the world known to them” - July 2, 2013

Page 4: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Post-Snowden reality

4

Page 5: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

5

Page 6: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

6

Page 7: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

7

Page 8: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

8

Gellman, Barton, and Ashkan Soltani. “NSA Infiltrates Links to Yahoo, Google Data Centers Worldwide, Snowden Documents Say.” The Washington Post, November 1, 2013,

Page 9: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

9

Page 10: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

10

Page 11: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

11

Page 12: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

12

Page 13: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

13

Page 14: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

“First half of 2013, American authorities made 12,444 requests of 40,322 accounts. Yahoo handed over content in 37 percent of cases, whereas in 55 percent of the cases, the company handed over only ‘non-content data’ (NCD).”*

*Basic subscriber information including the information captured at the time of registration such as an alternate e-mail address, name, location, and IP address, login details, billing information, and other transactional information (e.g., “to,” “from,” and “date” fields from e-mail headers).

14

Page 15: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

321,000 legal orders for user data in 2013. Of those, over 6,000 were court orders to provide metadata in real time.”

15

Page 16: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

16

“State and federal agencies made 301,816 separate demands for data from AT&T in 2013.

“Governments asked for location-related data 37,839 times”

Page 17: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

17

“Sprint Accused of Overcharging US for Spying Assistance.” Network World, March 4, 2014. http://www.networkworld.com/news/2014/030414-sprint-accused-of-overcharging-us-279362.html.

Page 18: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

“What eludes Mr. Snowden – along with most of his detractors and supporters – is that we might be living through a transformation in how capitalism works, with personal data emerging as an alternative payment regime. The benefits to consumers are already obvious; the potential costs to citizens are not. As markets in personal information proliferate, so do the externalities – with democracy the main victim.”

18

Evgeny Morozov

Page 19: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

19

Page 20: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

“With little or no revenue from its users, Google still manages to turn a healthy profit by selling advertisements within its products that rely in substantial part on users’ personal identification information … in this model, the users are the real product.“

- after dismissing a class action lawsuit brought by Google users who claimed the search giant broke the law when it combined the privacy policies of Gmail, YouTube and a variety of other services. 20

US Magistrate Judge Paul Grewal

Page 21: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

“Surveillance is the business model of the

Internet.”

21

Bruce Schneier

Page 22: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

22

"We have a stalker

economy."

Page 23: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Um. Since we work in libraries… what does all this mean for patron privacy?

23

Page 24: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Statement on Access to Personally Identifiable Information in Historical Records

Librarians should recognize an obligation to monitor their governments’ legislation in regard to confidentiality of data records. In particular, librarians should support the need for privacy laws to protect library users from such abuses as government agencies monitoring their reading and research habits. - IFLA Governing Board

24

Page 25: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

ALA Code of Ethics

III. We protect each library user's right to privacy and confidentiality with respect to information sought or received and resources consulted, borrowed, acquired or transmitted. - American Library Association

25

Page 26: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

26

Page 27: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

27

Page 28: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

28

Page 29: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

29

Page 30: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

30

Page 31: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

David Weinberger, co-director of the Harvard Library Innovation Lab.

"The privacy that libraries traditionally have been preserving is not always valued by their patrons, especially in an age of social networking."

Page 32: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Library 2.0

32

Page 33: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

33

“Librarian 2.0 is the guru of the information age.”

Stephen Abram

Page 34: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

34

Page 35: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

35

Page 36: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

36

Page 37: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

37

Zimmer, Michael. “Patron Privacy in the ‘2.0’ Era: Avoiding the Faustian Bargain of Library 2.0.” Journal of Information Ethics 22, no. 1 (April 1, 2013): 44–59. doi:10.3172/JIE.22.1.44.

7.5%

Page 38: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

38

Zimmer, Michael. “Patron Privacy in the ‘2.0’ Era: Avoiding the Faustian Bargain of Library 2.0.” Journal of Information Ethics 22, no. 1 (April 1, 2013): 44–59. doi:10.3172/JIE.22.1.44.

1.6%

Page 39: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Contextual integrity

39

Nissenbaum, Helen Fay. Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford, Calif.: Stanford Law Books, 2010.

Page 40: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Case study: How are these competing paradigms playing out

in Cornell University Library?

40

Page 41: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Library systems that collect patron usage data inside Cornell campus

Page 42: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

42

Page 43: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

43

Page 44: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

44

Page 45: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

45

Page 46: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

46

Page 47: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

47

Page 48: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

48

Page 49: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Library systems that collect patron usage data outside Cornell campus

Page 50: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

50

Page 51: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

51

Page 52: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

52

Page 53: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

53

Page 54: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

54

Page 55: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

55

Page 56: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

56

Page 57: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

57

4. Postings to Question Point Services

You acknowledge and agree that OCLC may store all electronic transactions carried out between you and the library on this service and any information provided by you on this web form, as described in the Privacy Statement, for an indefinite period, with this exception: your name and all but the domain of your e-mail address will be deleted after 90 days. As such, OCLC may disclose the data in its possession only as described in the Privacy Statement and if required to do so by law.

You hereby grant to OCLC the perpetual, nonexclusive, world-wide right to edit, compile, and make searchable by libraries and the public all completed question-and-answer pairs

Page 58: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

58

How many of you negotiate for content or software?

Page 59: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

59

Of those who raised your hand, what demands, if any, do you make of vendors to protect user privacy?

Page 60: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

60

“This study used content analysis to determine the degree to which the privacy policies of 27 major vendors meet standards articulated by the library profession and information technology industry. While most vendors have privacy policies, the policy provisions fall short on many library profession standards and show little support for the library Code of Ethics” (Magi, 2010).

Magi, Trina J. “A Content Analysis of Library Vendor Privacy Policies: Do They Meet Our Standards?” College & Research Libraries 71, no. 3 (May 1, 2010): 254–272.

Page 61: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

61

Page 62: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

62

Page 63: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Percentage polled who trust the following organizations “not at all”

63

“For Privacy, Americans Trust Facebook Less Than The NSA.” BuzzFeed. Accessed October 9, 2013. http://www.buzzfeed.com/charliewarzel/survey-for-privacy-americans-trust-facebook-less-than-the-ns.

Page 64: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Privacy online is still valued

64

Page 65: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

86%65

Rainie, Lee, Sara Kiesler, Ruogu Kang, and Mary Madden. Anonymity, Privacy, and Security Online. Pew Research Center’s Internet & American Life Project, September 5, 2013. http://pewinternet.org/Reports/2013/Anonymity-online.aspx.

Page 66: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

66

Rainie, Lee, Sara Kiesler, Ruogu Kang, and Mary Madden. Anonymity, Privacy, and Security Online. Pew Research Center’s Internet & American Life Project, September 5, 2013. http://pewinternet.org/Reports/2013/Anonymity-online.aspx.

55%

Page 67: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

67

Kiss, Jemima. “Privacy Tools Used by 28% of the Online World, Research Finds.” The Guardian, January 21, 2014, sec. Technology. http://www.theguardian.com/technology/2014/jan/21/privacy-tools-censorship-online-anonymity-tools.

56% say Internet is eroding their personal privacy

Page 68: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

68

Kiss, Jemima. “Privacy Tools Used by 28% of the Online World, Research Finds.” The Guardian, January 21, 2014, sec. Technology. http://www.theguardian.com/technology/2014/jan/21/privacy-tools-censorship-online-anonymity-tools.

28% (415 million) use tools to disguise their identity or location

Page 69: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

69

Page 70: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

70

Page 71: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Recommendations

• Conduct a privacy audit.

• Educate library technologists and marketing staff about patron privacy

• Weigh the pros and cons of adding social network features

• Find alternative to Google Analytics (or at least activate the IP address anonymization switch)

• Pressure vendors to implement SSL encryption

• Advocate for a log file/usage data anonymization best practice for library eresource vendors

• Consider teaching data encryption in your library

Page 72: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

72

http://youtu.be/8wa_4G0_xi0

Page 73: Patron Privacy in a Surveillance State Adam Chandler Electronic Resources and Libraries 2014 March 18, 2014

Discussion

Adam [email protected] twitter.com/alc28

73