Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, April 2, 2012

Privacy vs. Service

I posted a text scrap from an article about Google's invasion of privacy, which at first seemed a bit disturbing - but as I thought about it, it makes perfect sense that, in order to provide good answers to a search query, it's necessary to know not merely the question, but the querent.

The specific example the author provided was searching for "restaurant between San Francisco and Lake Tahoe." The chief problem with search is that it very often gives you a long list of results that are entirely satisfactory. Considering this very example, a raw list of every restaurant between two points on a map is all you could get based on the question - and you would then need to filter through them yourself, guessing by the names which might be satisfactory, then clicking through to read more to discover whether they are acceptable. It takes a lot of work - which may be OK for some things, but using a mobile device to get a restaurant reservation shouldn't result in a list that gives you a 30-minute chore of sifting through "matches" that don't really match.

And so, to provide a specific answer to that question, Google needs to know what route you're driving, when you'll set out, what kinds of restaurants/cuisine you prefer, whether you have any religious or medical dietary restrictions, how much you prefer to spend on a meal, and the tastes/preferences of other people in your vehicle. This means snooping into your behavior, your medical records, your religious beliefs, your finances, and your associations to other people.

It's a bit disturbing ... at first. But pause to consider this: if someone were to ask you that same question, would you not need the same information to give them a good answer?
  • What route are you driving and when will you set out? If you do not know this, you might suggest restaurants that are not along the way, or that they would pass at an inconvenient time or a t a time a given place is closed.
  • What cuisines do you prefer? If you do not know this, you might suggest restaurants that the querent would not consider because he doesn't like the food they serve.
  • Do you have any religious/medical dietary restrictions? If you do not know this, you might suggest restaurants that don't serve anything the querent can eat for these very reasons.
  • How much do you prefer to spend on a meal? If you do not know this, you might suggest restaurants that the querent would not consider because he feels they are too expensive.
  • What are the preferences of your fellow travellers? If you do not ask this, you might suggest a restaurant that the querent likes, but that would be objectionable
If you can think of a way to give an unknown person a good recommendation without all of this information, I'm sure Google (and many others) would love to hear from you - but I don't think it can be done. Leave out any of these details, and you're going to give a bad answer.

Arguably, it's because the querent asked you a vague question. An alternate solution would be for people to learn to ask more specific questions that provide the information that the system needs to give them a specific and appropriate answer. So rather than seeking a "restaurant between San Francisco and Lake Tahoe," the querent would have to ask for a "restaurant near Roseville CA that is open for lunch that serves anything except Mexican or Vietnamese cuisine and has Kosher, vegetarian, and gluten-free options and costs under $15 per person."

Search engines have tried, unsuccessfully, to get people to do that for years, using long queries and Boolean flags to ask a very specific question in order to get an appropriate answer - and the long list of results is the user's fault. But most people can't be bothered to do that, and even those that do tend to forget details that they do not realize were relevant until they get a bad answer and end up searching multiple times to get to a list of appropriate options - and because they didn't get a specific answer to a vague question, it's the search engine's fault.

A lot of work is being done, and will continue to be done, to find a solution. It is, as with many issues, a matter of balance between having enough information to give a good answer (how much does a given person spend on lunch art a restaurant) without being too intrusive (upload your tax returns for the past five years so I can figure out how much you're likely to be willing to spend).

The path to arriving at that happy place is not to stop everything immediately, but to continue the trial-and-error process until both sides get it right.

Sunday, July 3, 2011

When Gadgets Betray Us

I've added reading notes on When Gadgets Betray Us, which addresses a handful of topics concerning the way in which the use of technology, particularly mobile communications and sensors, gather an increasing amount of very granular data about people that is stored for an indefinite amount of time and used for various purposes that may in some instances be invasive, objectionable, or even dangerous.

The book was written as a cautionary tale for consumers, and as such it seems to be skewed toward aggrandizing incidents to create the perception that our use of technology leaves us in a highly vulnerable position in a world of hackers, thieves, fraudsters, and others who would seek to do us harm for their own profit and entertainment. And yet, latter chapters swing to the opposite extreme, dismissing the concern over privacy as being as silly as the tribal fear of photography stealing your soul.

This doesn't really add up to a balanced perspective, and calls to mind the metaphor that suggests that if you put one foot in lava and the other in liquid nitrogen, you should be comfortable on average. But to be fair, while the author did touch upon the extremes, the majority of the book finds a fairly reasonable position in between them - and it's likely my discomfort is the result of having a differing opinion about what level of security a person should accept, or advocate that others should accept.

Even so, I muddled through in spite of periodic malaise: the author does bring to light a number of considerations for the use of technology that are worth considering. It's a sensitive issue for customers to decide how much privacy they will sacrifice and how much risk they will accept for the sake of convenience, and important to consider a for those who work in technology professions and in industries where significant amounts of highly sensitive personal data are handled - as ultimately, those who design the technology are providing the options that customers must consider in making their choice.

Ultimately, I'd agree with the trust of his dissertation: that people are generally better off if they can make informed decisions - neither overly panicked about imaginary threats, nor soothed to ignoring the real ones that exist.

Thursday, September 16, 2010

Overexposed

It seems that panic is back in fashion, drummed up over yet another social networking site that aggregates information that is already in full view of the public, and users are being coaxed (by the media, as well as the company itself) to sign up and "claim" the profiles so that they can see what is being published about them, and perhaps exercise some modicum of control.

Like all fashions, panic goes away and comes back again a few years later. It's been going on ever since telephone directories went online and people were horrified by the notion that their name, address, and phone number were "on the Internet" for anyone to see (never mind that the same information is already in the phone book, and hundreds of public records.)

In truth, assembling intelligence on individuals is a practice that began long before the Internet. The gathering of "files" on individuals goes back decades, or centuries, or even millennia. Roman emperors gathered intelligence on their enemies, political rivals, and even private citizens that might support or oppose their will. It probably goes back even further than that - so it's not a new threat at all.

What's different now is that some of the information is now more readily accessible to more people than it was before. Those whom you'd least like to have it - government agencies, marketing firms, employers, and others that might use it to exploit you or deny you access to opportunities - have had the same kind of information, and much more, at their fingertips for years.

The advent of social media - Facebook, Twitter, WordPress, LinkedIn, and more - gives people the opportunity to push out even more information about themselves and others whom they know, with the illusion of being able to control who gets to see it. But after so many incidents in which a computer glitch or a change in terms of service have exposed information that was submitted under the auspices of a privacy policy, who can trust in them anymore?

All in all, the sues and abuses of personal information leave me unable to come to a firm conclusion over whether it's a good thing or a bad thing - but whichever way I find myself leaning, I have to conceded that the availability of our personal details is a thing - a fact - that we'll all have to live with, for better or for worse.

Friday, May 21, 2010

User Irresponsibility

I went off on a bit of a rant in my reaction to a blog posting about privacy issues and Facebook - which is getting to be rather a habit lately and I probably need to work on it - and am reposting it here to maintain the information in my own repository.

In the original post, the author seems to be implying that Facebook is to be held responsible for users who indiscreetly post information about themselves, and that they are purposefully trying to make things difficult by having an unnecessarily complex interface (he refers to the need to go into "advanced" settings) and an incomprehensible privacy policy (he indicates that it's longer than the U.S. Constitution).

That rankles a bit, because from a perspective of UX design, we go to great lengths to make things as easy an understandable as we can, yet users seem to bumble along without bothering to read instructions or heed warnings and, when they find they've made a mistake, seek to blame the site operator rather than learn from their own mistakes.

It's a side effect of our litigious culture, I suppose, but I sense that the long-term effects may be severely detrimental. But rather than paraphrase myself further or add to an already-lengthy rant, here was my response:

The question you ask – how many of users bother to check their settings – is the thorn in everyone’s side when technology is adopted by the masses.

It’s not just highly sophisticated technologies, but even simple ones: for the longest time, there was this running joke about people whose VCRs were constantly flashing “12:00″ because they never bothered to figure out how to set the clock … and 10% of the audience laughed at the notion that people could be so stupid, while the other 90% laughed because, back at home, their VCR was flashing, and they felt a little awkward and embarrassed by it.

And in most cases, it’s not because the manufacturers of VCRs made it difficult to set the clock – a child could figure out how to do it within half a minute – it was just that people didn’t bother. I don’t think the Facebook privacy “issues” are much different – the settings are easy to access and modify. But people don’t bother.
There are sites like lamebook.com and failbooking.com that provide thousands of instances where people indiscreetly posted information that they probably shouldn’t have – and much like the VCR joke, 10% are laughing at the carelessness of others and the other 90% are a bit nervous because they may be doing the same. But unlike the VCR joke, being careless with social media isn’t a private embarrassment, but a public one.

In the end, what disturbs me most of all is that the carelessness of the user has the potential to become a liability for those who provide these services. And it’s not that Facebook is evil or is trying to make things unnecessarily complex – it’s about as easy as it could possibly be, but people just don’t bother.

No matter what Facebook does, how easy or obvious they make things, there will be people who simply won’t bother – and Web usability will bear out that even if you give them a “big red warning,” they’ll just click OK without bothering to read it – and worse, will get litigious when they seek someone else to blame for the consequences of their own disregard.

If these problems continue, and if lawsuits side with the faction that wants to hold Facebook liable, the only choice is to shut down the service or disable it to the point where it’s not useful at all.

That may seem a bit melodramatic from a short-run perspective of specific complaints and incidents … but over the long term, it’s a serious threat to the availability of technology in general.

If it’s not feasible to provide a technology unless you can render it safe in the hands of users who won’t bother to read instructions or heed warnings without risking liability, than most companies won’t.

My hope is that incidents such as the one you describe are used to illustrate to users the importance of paying attention – but in the “not-my-fault” climate of our current culture, I despair that may not be the outcome.
This impromptu rant could probably use a bit more development, but I think that further consideration will uphold the fundamental theses of the argument.