personal privacy and the public internet john e. carter kennesaw state university it 3700

15
Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Upload: aron-mathews

Post on 06-Jan-2018

212 views

Category:

Documents


0 download

DESCRIPTION

How Did You Tell? Cookies Web Bugs

TRANSCRIPT

Page 1: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Personal Privacy and the Public Internet

John E. CarterKennesaw State University

IT 3700

Page 2: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

How Much Did You Tell?

• "Most privacy violations don't come from whopping big intrusions but from the aggregation of hundreds of small bits of knowledge, none of which individually seems important. Who cares if someone knows your ZIP code or your social security number? What about a tossed-out receipt from your ATM or an old credit card receipt? What's your mother's maiden name? But put those violations all together and you're well on your way to identity theft -- or worse."

• InfoWorld. March 20, 2001.

Page 3: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

How Did You Tell?

• Cookies• Web Bugs

Page 4: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

How Safe Are Cookies?• Cookies were intended to provide long-term

“state” information, such as user ID’s or site preferences.

• By design, only a Web server in the domain of the server that creates a cookie can read that cookie.

• Internet Explorer 5.5 and 6.0 have a “backdoor” that allows any Web server to read any cookie on the user’s PC.

Page 5: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

What’s in a Cookie?

• www.alphaworks.ibm.com FALSE / FALSE1104538901 awMember John_Carter

• www.alphaworks.ibm.com FALSE / FALSE1104538901 awMemberEmail [email protected]

• gserv.zdnet.co.uk FALSE / FALSE1016756726 Apache216.175.77.224.481801001031849261

Page 6: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

What’s in a Cookie?

• www.alphaworks.ibm.com FALSE / FALSE1104538901 awMember John_Carter

• www.alphaworks.ibm.com FALSE / FALSE1104538901 awMemberEmail [email protected]

• gserv.zdnet.co.uk FALSE / FALSE1016756726 Apache216.175.77.224.481801001031849261

Page 7: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Innocent Website?

Page 8: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Web Bugs - Invisible Invaders

Page 9: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

What Bugnosis Sees

Page 10: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

What Do The Links Mean?• As the “invisible” graphics are downloaded

from the specified server, some minimum information is being collected about the viewer by that server:

• Operating System• Browser Type and Version• IP Address• Previous Page Viewed

Page 11: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

How Is the Information Used?

• The intention is to track hits on pages and your page viewing to provide targeted advertising.

• If you visit two sites with digital camera information, the next ads you see will relate to digital cameras and accessories.

Page 12: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Do You Want Them to Know Where You’ve Been?

• The Network Advertising Initiative has a page that provides “opt-out” from most advertising data collection:

• http://www.networkadvertising.org/optout_nonppii.asp

Page 13: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Summary

• Do not reveal personal information inadvertently.• Turn on cookie notices in your Web browser,

and/or use cookie management software.• Keep a “clean” e-mail address.

• www.eff.org/Privacy/eff_privacy_top_12.html

Page 14: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Questions?

The original paper is on-line at

http://pigseye.kennesaw.edu/~jcarter3/3700paper.html

Page 15: Personal Privacy and the Public Internet John E. Carter Kennesaw State University IT 3700

Thank You