SlideShare a Scribd company logo
z
Designing for
Privacy
Skott Klebe
Platform Security Architect
EBSCO Information Services
z
EBSCO Information Services
§ About EBSCO
§ Because EBSCO Information Services is a part of the information
technology community, our needs are those of our customers.
We’re dedicated to developing customizable services, supporting
the technology needs of our customers and creating strong user
experiences to help libraries and other institutions support their end
users and improve access to information.
z
Intro
§ Skott Klebe
§ Platform Security Architect
§ More than twenty years’ experience in security and compliance in
academic publishing
z
Importance of Privacy
§ Safety in ourselves
§ The identity trade – it’s forever
§ You may trust the first recipient, but you can’t trust everyone they
trust
§ Example: Facebook
§ Accumulated a valuable asset: our online lives
§ Exposed it to any partner that signed an agreement
§ Seems to have made no attempt to enforce the agreement for years
§ Partner allegedly breached the agreement
z
Attitudes toward personal information
§ US – personaldata is property*
§ You contract away use of it on
almost every web page you look at
§ To the site owner
§ to partners of the site owner
§ to partners’ partners
* SpecialCOPPA exception for
children under 13
§ EU – personaldata is like your body
§ Can’t contract it away –
it’s always yours
§ GDPR forces processing information
in ways that the owners continue to
control it
§ Report
§ Correct
§ Forget
§ Sentiment derives from recent
experience with repressive regimes
z
Privacy in the News
z
z
How do we do
better?
Software doesn’t
meet requirements
without design,
implementation,and
testing
Security and privacy
are requirements
Therefore, we must
design, implement,
and test for them
z
z
Designing
Identity
z
z
Identity concerns
Authentication
Authorization
Audit
Personalization
Enrichment
Interaction
Lifecycle
z
Identification
§ Must be globally unique
§ Not my name
§ Must be able to be presented by me
§ A string I know – “skott” or “dude1879”
§ An object, like my computer or my phone
§ My fingerprint, face, or DNA
§ An IP address from a range associated
with my institution
§ A cookie stored in my browser’s database
Institutional
identity
z
Authentication
§ Something that only I can present
§ A secret
§ My fingerprint, retina, face, or DNA
§ My unlocked phone
§ Address from my institution’s IP range
Institutional
authentication
z
Interaction
§ How a service communicates with me
§ Phone numbers
§ Email addresses
§ Screen name
§ Real name
§ How I communicate with other people who use the service
§ Screen name
§ Real name
§ E-mail address
z
Personalization
§ My favorite…
§ Color scheme
§ Background image
§ My stored…
§ Shopping cart
§ Bookmarks
§ Saved searches
§ Folders
zz
Enrichment
§ Search improvements
§ What do I mean by
“apache”?
§ Recommendations
§ Books by which Stephen
King?
zz
Enrichment
§ History
§ What was I looking at
yesterday?
§ Who said that to me?
z
z
z
Real Product, By the Way
z
z
Designing for
Privacy
z
Identity – the Tripartite Identity Pattern
§ 2008 design codified at Yahoo
§ Separation of concerns
§ Don’t display login ID’s as a name
§ Don’t use the login ID as the root key of
every part of identity
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
z
Why We Try
#1:
The Buzz
Disclosures
§ Before Google Plus, there was Google Buzz
§ If you had GMail, Google offered you a public
Buzz identity
§ If you declined, they still turned parts of Buzz
on for you
§ E.g., your friend graph
§ It you accepted, your e-mail contacts became
your public social network
z
Why We Try
#1:
The Buzz
Disclosures
§ Private became Public
§ Your relationship to your therapist
§ Your current contact information to your ex or
stalker
§ FTC consent order
https://www.ftc.gov/news-
events/press-releases/2011/10/ftc-
gives-final-approval-settlement-
google-over-buzz-rollout
z
TIP in Practice – the core
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Must be optional
Session
Token
f123ab456fde
Institution
ID
159
Must be optional
Demographics
Home address, e.g.
In libraries, we’re
usually adding one or
more layers of
institution, and also
authenticating the
institution via IP.
z
TIP in Practice:
other associations
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Institution
ID
159
Demographics
Home address, e.g.
We tie a number of other kinds of data to the identity as well.
z
TIP in Practice:
other associations
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Demographics
Home address, e.g.
We tie a number of other kinds of data to the identity as well.
z
TIP in Practice:
other associations
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Demographics
Home address, e.g.
We tie a number of other kinds of data to the identity as well.
z
TIP in Practice:
other associations
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Demographics
Home address, e.g.
We tie a number of other kinds of data to the identity as well.
z
TIP in Practice:
other associations
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Demographics
Home address, e.g.
Published
Usage reports
Journal 1 5 unique readers
Journal 2 15 unique readers
We tie a number of other kinds of data to the identity as well.
z
TIP in Practice:
forget me!
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Demographics
Home address, e.g.
Usage reports
Journal 1 5 unique readers
Journal 2 15 unique readers
Published
z
TIP in Practice:
forget me!
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Demographics
Home address, e.g.
Usage reports
Journal 1 5 unique readers
Journal 2 15 unique readers
Published
z
TIP in Practice:
forget me!
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Internal
Identifier
5271009
Usage reports
Journal 1 5 unique readers
Journal 2 15 unique readers
Published
z
TIP in Practice:
forget me!
Institution
ID
159
Shopping cart
5271009 Toothbrush
Toothpaste
…
Search
History
5271009 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Internal
Identifier
5271009
Usage reports
Journal 1 5 unique readers
Journal 2 15 unique readers
Published
We may want to avoid
tying the cart and the
search results
z TIP in Practice:
additional diligence
Internal
Identifier
5271009
Login
ID
sklebe
Screen Name
“Skott from MA”
Session
Token
f123ab456fde
Institution
ID
159
Shopping cart
330bd811f Toothbrush
Toothpaste
…
Search
History
0aef18542 helicopters
web servers
…
Patron usage
logs
5271009 Article 1
Article 2
…
6655321 Article 21
Article 22
…
… Article 1
Article 2
…
Demographics
Home address, e.g.
Published
Usage reports
Journal 1 5 unique readers
Journal 2 15 unique readers
hash(“cart-5271009”)
hash(“search-5271009”)
Mathematically
impossible to tie to
each other or the key
Do we need to be concerned about the
sensitivity of this kind of data?
z
§ AOL released a large set of anonymized user search history
§ Intended for researchers to improve understanding of
search behaviors
§ Solving the ”Apache” problem, e.g.
§ The New York Times easily identified individuals
§ https://www.nytimes.com/2006/08/09/technolo
gy/09aol.html
§ AOL apologized, deleted the data within days
§ Defended a class action lawsuit
§ The data is still available online
Why We Try
#2:
z
z
Takeaways
zObligations of System Design
Understand the data
• Could it harm the user?
• When combined with
something else?
• When shared with a
partner?
1
Think about privacy
from the start
• Can we delete this data
without breaking?
• Can we minimize retention?
• Can we confine it in one
place?
• Can we involve a partner?
2
Don’t forget costs &
risks of retention
• Compliance
• Liability
• Keeping that data may be
more expensive than
deleting it
3
Klebe Designing for Privacy

More Related Content

Similar to Klebe Designing for Privacy

Netlog Developer Day
Netlog Developer DayNetlog Developer Day
Netlog Developer Day
Folke Lemaitre
 
Proxy : effective logs for tracking down usage trends
Proxy : effective logs for tracking down usage trendsProxy : effective logs for tracking down usage trends
Proxy : effective logs for tracking down usage trends
Proxies Rent
 
Patterns to Bring Enterprise and Social Identity to the Cloud
Patterns to Bring Enterprise and Social Identity to the Cloud Patterns to Bring Enterprise and Social Identity to the Cloud
Patterns to Bring Enterprise and Social Identity to the Cloud
CA API Management
 
Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...
Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...
Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...
Attacat Internet Marketing
 
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael BoydStreetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
SSIMeetup
 
FELDMAN & FELDMAN
 FELDMAN & FELDMAN FELDMAN & FELDMAN
FELDMAN & FELDMAN
Chante Peeler
 
Collaboration between LINE, Microsoft and AI by the developers, for the devel...
Collaboration between LINE, Microsoft and AI by the developers, for the devel...Collaboration between LINE, Microsoft and AI by the developers, for the devel...
Collaboration between LINE, Microsoft and AI by the developers, for the devel...
LINE Corporation
 
Proxy server
Proxy serverProxy server
Proxy server
Proxies Rent
 
10 online privacy module samedit1
10 online privacy  module samedit110 online privacy  module samedit1
10 online privacy module samedit1
ConnectYourCommunity
 
10 online privacy module samedit1
10 online privacy  module samedit110 online privacy  module samedit1
10 online privacy module samedit1
Rozell Sneede
 
Welcome to ZOCCAM 6.0
Welcome to ZOCCAM 6.0Welcome to ZOCCAM 6.0
Welcome to ZOCCAM 6.0
JoleneVickers
 
Welcome to ZOCCAM
Welcome to ZOCCAMWelcome to ZOCCAM
Welcome to ZOCCAM
JoleneVickers
 
Cyber security macau
Cyber security macau Cyber security macau
Cyber security macau
OMNIRISC SECURITY SERVICES
 
7740279_SCPDRecordofCompletion
7740279_SCPDRecordofCompletion7740279_SCPDRecordofCompletion
7740279_SCPDRecordofCompletion
Tranquilino G Ortega Jr
 
SLA CI Division Webinar: Using the Internet to Research Private Companies
SLA CI Division Webinar: Using the Internet to Research Private CompaniesSLA CI Division Webinar: Using the Internet to Research Private Companies
SLA CI Division Webinar: Using the Internet to Research Private Companies
August Jackson
 
How to Leverage LinkedIn - What Every Financial Planner and IFA Needs to Know
How to Leverage LinkedIn - What Every Financial Planner and IFA Needs to KnowHow to Leverage LinkedIn - What Every Financial Planner and IFA Needs to Know
How to Leverage LinkedIn - What Every Financial Planner and IFA Needs to Know
Philip Calvert
 
Building Next Generation Cybersecurity with Today's Machine Learning Solutions
Building Next Generation Cybersecurity with Today's Machine Learning SolutionsBuilding Next Generation Cybersecurity with Today's Machine Learning Solutions
Building Next Generation Cybersecurity with Today's Machine Learning Solutions
Amazon Web Services
 
An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...
An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...
An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...
Brian Campbell
 
Crawling and Processing the Italian Corporate Web
Crawling and Processing the Italian Corporate WebCrawling and Processing the Italian Corporate Web
Crawling and Processing the Italian Corporate Web
Speck&Tech
 
10 SEO Tips for Communications & PR
10 SEO Tips for Communications & PR10 SEO Tips for Communications & PR
10 SEO Tips for Communications & PR
TopRank Marketing Agency
 

Similar to Klebe Designing for Privacy (20)

Netlog Developer Day
Netlog Developer DayNetlog Developer Day
Netlog Developer Day
 
Proxy : effective logs for tracking down usage trends
Proxy : effective logs for tracking down usage trendsProxy : effective logs for tracking down usage trends
Proxy : effective logs for tracking down usage trends
 
Patterns to Bring Enterprise and Social Identity to the Cloud
Patterns to Bring Enterprise and Social Identity to the Cloud Patterns to Bring Enterprise and Social Identity to the Cloud
Patterns to Bring Enterprise and Social Identity to the Cloud
 
Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...
Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...
Actionable Insights with Google Analytics - Ben Rogers - Attacat Internet Mar...
 
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael BoydStreetcred: Improving the Developer Experience in SSI – Michael Boyd
Streetcred: Improving the Developer Experience in SSI – Michael Boyd
 
FELDMAN & FELDMAN
 FELDMAN & FELDMAN FELDMAN & FELDMAN
FELDMAN & FELDMAN
 
Collaboration between LINE, Microsoft and AI by the developers, for the devel...
Collaboration between LINE, Microsoft and AI by the developers, for the devel...Collaboration between LINE, Microsoft and AI by the developers, for the devel...
Collaboration between LINE, Microsoft and AI by the developers, for the devel...
 
Proxy server
Proxy serverProxy server
Proxy server
 
10 online privacy module samedit1
10 online privacy  module samedit110 online privacy  module samedit1
10 online privacy module samedit1
 
10 online privacy module samedit1
10 online privacy  module samedit110 online privacy  module samedit1
10 online privacy module samedit1
 
Welcome to ZOCCAM 6.0
Welcome to ZOCCAM 6.0Welcome to ZOCCAM 6.0
Welcome to ZOCCAM 6.0
 
Welcome to ZOCCAM
Welcome to ZOCCAMWelcome to ZOCCAM
Welcome to ZOCCAM
 
Cyber security macau
Cyber security macau Cyber security macau
Cyber security macau
 
7740279_SCPDRecordofCompletion
7740279_SCPDRecordofCompletion7740279_SCPDRecordofCompletion
7740279_SCPDRecordofCompletion
 
SLA CI Division Webinar: Using the Internet to Research Private Companies
SLA CI Division Webinar: Using the Internet to Research Private CompaniesSLA CI Division Webinar: Using the Internet to Research Private Companies
SLA CI Division Webinar: Using the Internet to Research Private Companies
 
How to Leverage LinkedIn - What Every Financial Planner and IFA Needs to Know
How to Leverage LinkedIn - What Every Financial Planner and IFA Needs to KnowHow to Leverage LinkedIn - What Every Financial Planner and IFA Needs to Know
How to Leverage LinkedIn - What Every Financial Planner and IFA Needs to Know
 
Building Next Generation Cybersecurity with Today's Machine Learning Solutions
Building Next Generation Cybersecurity with Today's Machine Learning SolutionsBuilding Next Generation Cybersecurity with Today's Machine Learning Solutions
Building Next Generation Cybersecurity with Today's Machine Learning Solutions
 
An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...
An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...
An Introduction to the Emerging JSON-Based Identity and Security Protocols (O...
 
Crawling and Processing the Italian Corporate Web
Crawling and Processing the Italian Corporate WebCrawling and Processing the Italian Corporate Web
Crawling and Processing the Italian Corporate Web
 
10 SEO Tips for Communications & PR
10 SEO Tips for Communications & PR10 SEO Tips for Communications & PR
10 SEO Tips for Communications & PR
 

More from National Information Standards Organization (NISO)

Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
National Information Standards Organization (NISO)
 
Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"
National Information Standards Organization (NISO)
 
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
National Information Standards Organization (NISO)
 
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
National Information Standards Organization (NISO)
 
Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
National Information Standards Organization (NISO)
 
Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"
National Information Standards Organization (NISO)
 
Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"
National Information Standards Organization (NISO)
 
Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"
National Information Standards Organization (NISO)
 
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
National Information Standards Organization (NISO)
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
National Information Standards Organization (NISO)
 
Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"
National Information Standards Organization (NISO)
 
Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"
National Information Standards Organization (NISO)
 
Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"
National Information Standards Organization (NISO)
 
Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"
National Information Standards Organization (NISO)
 
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
National Information Standards Organization (NISO)
 

More from National Information Standards Organization (NISO) (20)

Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
Jemison, MacLaughlin, and Majumder "Broadening Pathways for Editors and Authors"
 
Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"Benner "Expanding Pathways to Publishing Careers"
Benner "Expanding Pathways to Publishing Careers"
 
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
Pollock and Snow "DEIA in the Scholarly Landscape, Session One: Setting Expec...
 
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
Mattingly "AI & Prompt Design: Limitations and Solutions with LLMs"
 
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
 
Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"Mattingly "AI and Prompt Design: LLMs with NER"
Mattingly "AI and Prompt Design: LLMs with NER"
 
Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"Mattingly "AI & Prompt Design: Named Entity Recognition"
Mattingly "AI & Prompt Design: Named Entity Recognition"
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"Bazargan "NISO Webinar, Sustainability in Publishing"
Bazargan "NISO Webinar, Sustainability in Publishing"
 
Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"Rapple "Scholarly Communications and the Sustainable Development Goals"
Rapple "Scholarly Communications and the Sustainable Development Goals"
 
Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"Compton "NISO Webinar, Sustainability in Publishing"
Compton "NISO Webinar, Sustainability in Publishing"
 
Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"Mattingly "AI & Prompt Design: Large Language Models"
Mattingly "AI & Prompt Design: Large Language Models"
 
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
Hazen, Morse, and Varnum "Spring 2024 ODI Conformance Statement Workshop for ...
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
 
Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"Mattingly "Text and Data Mining: Building Data Driven Applications"
Mattingly "Text and Data Mining: Building Data Driven Applications"
 
Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"Mattingly "Text and Data Mining: Searching Vectors"
Mattingly "Text and Data Mining: Searching Vectors"
 
Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"Mattingly "Text Mining Techniques"
Mattingly "Text Mining Techniques"
 
Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"Mattingly "Text Processing for Library Data: Representing Text as Data"
Mattingly "Text Processing for Library Data: Representing Text as Data"
 
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
Carpenter "Designing NISO's New Strategic Plan: 2023-2026"
 

Recently uploaded

Stack Memory Organization of 8086 Microprocessor
Stack Memory Organization of 8086 MicroprocessorStack Memory Organization of 8086 Microprocessor
Stack Memory Organization of 8086 Microprocessor
JomonJoseph58
 
Temple of Asclepius in Thrace. Excavation results
Temple of Asclepius in Thrace. Excavation resultsTemple of Asclepius in Thrace. Excavation results
Temple of Asclepius in Thrace. Excavation results
Krassimira Luka
 
RESULTS OF THE EVALUATION QUESTIONNAIRE.pptx
RESULTS OF THE EVALUATION QUESTIONNAIRE.pptxRESULTS OF THE EVALUATION QUESTIONNAIRE.pptx
RESULTS OF THE EVALUATION QUESTIONNAIRE.pptx
zuzanka
 
skeleton System.pdf (skeleton system wow)
skeleton System.pdf (skeleton system wow)skeleton System.pdf (skeleton system wow)
skeleton System.pdf (skeleton system wow)
Mohammad Al-Dhahabi
 
Beyond Degrees - Empowering the Workforce in the Context of Skills-First.pptx
Beyond Degrees - Empowering the Workforce in the Context of Skills-First.pptxBeyond Degrees - Empowering the Workforce in the Context of Skills-First.pptx
Beyond Degrees - Empowering the Workforce in the Context of Skills-First.pptx
EduSkills OECD
 
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skillsspot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
haiqairshad
 
Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47
MysoreMuleSoftMeetup
 
How to Predict Vendor Bill Product in Odoo 17
How to Predict Vendor Bill Product in Odoo 17How to Predict Vendor Bill Product in Odoo 17
How to Predict Vendor Bill Product in Odoo 17
Celine George
 
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptxNEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
iammrhaywood
 
Oliver Asks for More by Charles Dickens (9)
Oliver Asks for More by Charles Dickens (9)Oliver Asks for More by Charles Dickens (9)
Oliver Asks for More by Charles Dickens (9)
nitinpv4ai
 
Skimbleshanks-The-Railway-Cat by T S Eliot
Skimbleshanks-The-Railway-Cat by T S EliotSkimbleshanks-The-Railway-Cat by T S Eliot
Skimbleshanks-The-Railway-Cat by T S Eliot
nitinpv4ai
 
Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...
Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...
Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...
ImMuslim
 
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdfمصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
سمير بسيوني
 
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem studentsRHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
Himanshu Rai
 
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptxPrésentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
siemaillard
 
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
GeorgeMilliken2
 
BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...
BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...
BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...
Nguyen Thanh Tu Collection
 
REASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdf
REASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdfREASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdf
REASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdf
giancarloi8888
 
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
imrankhan141184
 
BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...
BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...
BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...
Nguyen Thanh Tu Collection
 

Recently uploaded (20)

Stack Memory Organization of 8086 Microprocessor
Stack Memory Organization of 8086 MicroprocessorStack Memory Organization of 8086 Microprocessor
Stack Memory Organization of 8086 Microprocessor
 
Temple of Asclepius in Thrace. Excavation results
Temple of Asclepius in Thrace. Excavation resultsTemple of Asclepius in Thrace. Excavation results
Temple of Asclepius in Thrace. Excavation results
 
RESULTS OF THE EVALUATION QUESTIONNAIRE.pptx
RESULTS OF THE EVALUATION QUESTIONNAIRE.pptxRESULTS OF THE EVALUATION QUESTIONNAIRE.pptx
RESULTS OF THE EVALUATION QUESTIONNAIRE.pptx
 
skeleton System.pdf (skeleton system wow)
skeleton System.pdf (skeleton system wow)skeleton System.pdf (skeleton system wow)
skeleton System.pdf (skeleton system wow)
 
Beyond Degrees - Empowering the Workforce in the Context of Skills-First.pptx
Beyond Degrees - Empowering the Workforce in the Context of Skills-First.pptxBeyond Degrees - Empowering the Workforce in the Context of Skills-First.pptx
Beyond Degrees - Empowering the Workforce in the Context of Skills-First.pptx
 
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skillsspot a liar (Haiqa 146).pptx Technical writhing and presentation skills
spot a liar (Haiqa 146).pptx Technical writhing and presentation skills
 
Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47Mule event processing models | MuleSoft Mysore Meetup #47
Mule event processing models | MuleSoft Mysore Meetup #47
 
How to Predict Vendor Bill Product in Odoo 17
How to Predict Vendor Bill Product in Odoo 17How to Predict Vendor Bill Product in Odoo 17
How to Predict Vendor Bill Product in Odoo 17
 
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptxNEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
NEWSPAPERS - QUESTION 1 - REVISION POWERPOINT.pptx
 
Oliver Asks for More by Charles Dickens (9)
Oliver Asks for More by Charles Dickens (9)Oliver Asks for More by Charles Dickens (9)
Oliver Asks for More by Charles Dickens (9)
 
Skimbleshanks-The-Railway-Cat by T S Eliot
Skimbleshanks-The-Railway-Cat by T S EliotSkimbleshanks-The-Railway-Cat by T S Eliot
Skimbleshanks-The-Railway-Cat by T S Eliot
 
Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...
Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...
Geography as a Discipline Chapter 1 __ Class 11 Geography NCERT _ Class Notes...
 
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdfمصحف القراءات العشر   أعد أحرف الخلاف سمير بسيوني.pdf
مصحف القراءات العشر أعد أحرف الخلاف سمير بسيوني.pdf
 
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem studentsRHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
RHEOLOGY Physical pharmaceutics-II notes for B.pharm 4th sem students
 
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptxPrésentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
Présentationvvvvvvvvvvvvvvvvvvvvvvvvvvvv2.pptx
 
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
What is Digital Literacy? A guest blog from Andy McLaughlin, University of Ab...
 
BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...
BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...
BÀI TẬP BỔ TRỢ TIẾNG ANH LỚP 9 CẢ NĂM - GLOBAL SUCCESS - NĂM HỌC 2024-2025 - ...
 
REASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdf
REASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdfREASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdf
REASIGNACION 2024 UGEL CHUPACA 2024 UGEL CHUPACA.pdf
 
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
Traditional Musical Instruments of Arunachal Pradesh and Uttar Pradesh - RAYH...
 
BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...
BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...
BÀI TẬP DẠY THÊM TIẾNG ANH LỚP 7 CẢ NĂM FRIENDS PLUS SÁCH CHÂN TRỜI SÁNG TẠO ...
 

Klebe Designing for Privacy

  • 1. z Designing for Privacy Skott Klebe Platform Security Architect EBSCO Information Services
  • 2. z EBSCO Information Services § About EBSCO § Because EBSCO Information Services is a part of the information technology community, our needs are those of our customers. We’re dedicated to developing customizable services, supporting the technology needs of our customers and creating strong user experiences to help libraries and other institutions support their end users and improve access to information.
  • 3. z Intro § Skott Klebe § Platform Security Architect § More than twenty years’ experience in security and compliance in academic publishing
  • 4. z Importance of Privacy § Safety in ourselves § The identity trade – it’s forever § You may trust the first recipient, but you can’t trust everyone they trust § Example: Facebook § Accumulated a valuable asset: our online lives § Exposed it to any partner that signed an agreement § Seems to have made no attempt to enforce the agreement for years § Partner allegedly breached the agreement
  • 5. z Attitudes toward personal information § US – personaldata is property* § You contract away use of it on almost every web page you look at § To the site owner § to partners of the site owner § to partners’ partners * SpecialCOPPA exception for children under 13 § EU – personaldata is like your body § Can’t contract it away – it’s always yours § GDPR forces processing information in ways that the owners continue to control it § Report § Correct § Forget § Sentiment derives from recent experience with repressive regimes
  • 7. z z How do we do better? Software doesn’t meet requirements without design, implementation,and testing Security and privacy are requirements Therefore, we must design, implement, and test for them
  • 10. z Identification § Must be globally unique § Not my name § Must be able to be presented by me § A string I know – “skott” or “dude1879” § An object, like my computer or my phone § My fingerprint, face, or DNA § An IP address from a range associated with my institution § A cookie stored in my browser’s database Institutional identity
  • 11. z Authentication § Something that only I can present § A secret § My fingerprint, retina, face, or DNA § My unlocked phone § Address from my institution’s IP range Institutional authentication
  • 12. z Interaction § How a service communicates with me § Phone numbers § Email addresses § Screen name § Real name § How I communicate with other people who use the service § Screen name § Real name § E-mail address
  • 13. z Personalization § My favorite… § Color scheme § Background image § My stored… § Shopping cart § Bookmarks § Saved searches § Folders
  • 14. zz Enrichment § Search improvements § What do I mean by “apache”? § Recommendations § Books by which Stephen King?
  • 15. zz Enrichment § History § What was I looking at yesterday? § Who said that to me?
  • 18. z Identity – the Tripartite Identity Pattern § 2008 design codified at Yahoo § Separation of concerns § Don’t display login ID’s as a name § Don’t use the login ID as the root key of every part of identity Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA”
  • 19. z Why We Try #1: The Buzz Disclosures § Before Google Plus, there was Google Buzz § If you had GMail, Google offered you a public Buzz identity § If you declined, they still turned parts of Buzz on for you § E.g., your friend graph § It you accepted, your e-mail contacts became your public social network
  • 20. z Why We Try #1: The Buzz Disclosures § Private became Public § Your relationship to your therapist § Your current contact information to your ex or stalker § FTC consent order https://www.ftc.gov/news- events/press-releases/2011/10/ftc- gives-final-approval-settlement- google-over-buzz-rollout
  • 21. z TIP in Practice – the core Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Must be optional Session Token f123ab456fde Institution ID 159 Must be optional Demographics Home address, e.g. In libraries, we’re usually adding one or more layers of institution, and also authenticating the institution via IP.
  • 22. z TIP in Practice: other associations Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Institution ID 159 Demographics Home address, e.g. We tie a number of other kinds of data to the identity as well.
  • 23. z TIP in Practice: other associations Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Demographics Home address, e.g. We tie a number of other kinds of data to the identity as well.
  • 24. z TIP in Practice: other associations Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Demographics Home address, e.g. We tie a number of other kinds of data to the identity as well.
  • 25. z TIP in Practice: other associations Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Demographics Home address, e.g. We tie a number of other kinds of data to the identity as well.
  • 26. z TIP in Practice: other associations Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Demographics Home address, e.g. Published Usage reports Journal 1 5 unique readers Journal 2 15 unique readers We tie a number of other kinds of data to the identity as well.
  • 27. z TIP in Practice: forget me! Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Demographics Home address, e.g. Usage reports Journal 1 5 unique readers Journal 2 15 unique readers Published
  • 28. z TIP in Practice: forget me! Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Demographics Home address, e.g. Usage reports Journal 1 5 unique readers Journal 2 15 unique readers Published
  • 29. z TIP in Practice: forget me! Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Internal Identifier 5271009 Usage reports Journal 1 5 unique readers Journal 2 15 unique readers Published
  • 30. z TIP in Practice: forget me! Institution ID 159 Shopping cart 5271009 Toothbrush Toothpaste … Search History 5271009 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Internal Identifier 5271009 Usage reports Journal 1 5 unique readers Journal 2 15 unique readers Published We may want to avoid tying the cart and the search results
  • 31. z TIP in Practice: additional diligence Internal Identifier 5271009 Login ID sklebe Screen Name “Skott from MA” Session Token f123ab456fde Institution ID 159 Shopping cart 330bd811f Toothbrush Toothpaste … Search History 0aef18542 helicopters web servers … Patron usage logs 5271009 Article 1 Article 2 … 6655321 Article 21 Article 22 … … Article 1 Article 2 … Demographics Home address, e.g. Published Usage reports Journal 1 5 unique readers Journal 2 15 unique readers hash(“cart-5271009”) hash(“search-5271009”) Mathematically impossible to tie to each other or the key Do we need to be concerned about the sensitivity of this kind of data?
  • 32. z § AOL released a large set of anonymized user search history § Intended for researchers to improve understanding of search behaviors § Solving the ”Apache” problem, e.g. § The New York Times easily identified individuals § https://www.nytimes.com/2006/08/09/technolo gy/09aol.html § AOL apologized, deleted the data within days § Defended a class action lawsuit § The data is still available online Why We Try #2:
  • 34. zObligations of System Design Understand the data • Could it harm the user? • When combined with something else? • When shared with a partner? 1 Think about privacy from the start • Can we delete this data without breaking? • Can we minimize retention? • Can we confine it in one place? • Can we involve a partner? 2 Don’t forget costs & risks of retention • Compliance • Liability • Keeping that data may be more expensive than deleting it 3