In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Face Book.. Show all posts
Showing posts with label Face Book.. Show all posts

Thursday, April 26, 2018

13359 - 'Very loose rules' led to Facebook data leak, says SAS chief - New Indian Express

By PTI  |   Published: 24th April 2018 07:26 PM  |  


DENVER: Data analytics major SAS Institute chief Jim Goodnight has blamed "very very loose rules and regulations" at Facebook for the breach of personal data of millions of users.
Amid a global furore over breach of personal data of tens of millions of Facebook users, including in India, Goodnight said although all technology companies have obligation to protect personal information they have collected on their consumers, most of them are careless about it.

A pioneer in data analytics, the North Carolina-based SAS Institute has annual revenue of over USD 3.2 billion. "I think Facebook just had very, very loose rules and regulations about what they would permit and what they don't, because that is how they are making money. "...in short, technology companies have been very loose with the data they have collected on individuals," Goodnight, who is the company's co-founder and chief executive, told PTI in an interview here.

He was speaking on the sidelines of the SAS Global Forum here, which was held from April 8-11.

At SAS, he said they always make sure that all any personalised data is completely encrypted so that none can break in. However, he said he is against any government interference or regulations.

"I would hate to see the European Union's general data privacy protection-type regulations imposed in the US because I don't like any kind of regulations. I hope it does not get us to wrestle like in Europe," the septuagenarian said.

About India's biometric identification system Aadhaar, Goodnight said the country would have to ensure that individual's data is not breached and cited the example of the US where there is a lot of regulation to protect data related to social security numbers.

Regarding SAS India business, he said the Indian arm continues to grow. "We have done very well in India so far. Banks are getting bigger, companies are getting bigger and it is still a growing market for us". He also said the company would continue to increase its R&D staff at Pune.

SAS has offices in New Delhi, Pune, Mumbai and Bengaluru. Defending artificial intelligence, amidst concerns that the technology might impact jobs, Goodnight said, "I think people skilled at or familiar with AI will be preferred over others. So hiring will continue to happen but of those with better tech capabilities".

Goodnight also predicted that when it comes to mobility, the future would be in self-driving cars. "We will see more development in the area of self-driving cars. Within 10 years every car will be self-driven. I hope there will be official requirement that there has to be some specific number of self-driving cars.

"After all we all would be safer than we are now. With distracted humans driving, I think, I would rather prefer a computer that is not distracted while driving. There is still some glitches to work out but they are making a lot of progress," the SAS chief concluded.


At the forum, the company had announced creation of a new division to fight frauds and cybercrimes globally, using artificial intelligence and advanced analytics.

Friday, April 20, 2018

13315 - Google, Facebook, Twitter can't be compared with Aadhaar, clarifies UIDAI - Times of India


TIMESOFINDIA.COM | Updated: Apr 18, 2018, 22:35 IST

HIGHLIGHTS
  • The nature of information and the algorithms being used by global companies like Google and Aadhaar is different, UIDAI counsel Rakesh Dwivedi told the SC
  • Unlike Google, UIDAI does not plan on using data analytics and learning tools to analyse Aadhaar data, Dwivedi had said
NEW DELHI: Unique Identification Authority of India (UIDAI) has clarified that media reports quoting UIDAI’s Counsel Rakesh Dwivedi’s argument yesterday in the Supreme Court that Google is trying to fail Aadhaar are inaccurate. 

Senior advocate Rakesh Dwivedi had submitted before a CJI-headed Constitution bench that as far as Google, Facebook and Twitter are concerned, they cannot be compared with Aadhaar due to the nature of information being different and also due to difference in the nature of algorithms being used. While Aadhaar is only matching biometrics, the other global companies are using learning tools for analysis of data, which creates knowledge. 


Further, UIDAI is prohibited under the law to do any such data analysis and therefore cannot conduct surveillance of any kind. He further said that UIDAI does not permit any Requesting Entity (RE) to collect and analyse Aadhaar data and use the same for any commercial purposes. 

Monday, April 2, 2018

13166 - Living with the incoming tide: Aadhaar, Facebook and the end of privacy - Scroll.In

Living with the incoming tide: Aadhaar, Facebook and the end of privacy
Consent may be irrelevant as India’s digital tsunami grows in strength.

Published 12 hours ago

The basic difference between being forced to sign up for Aadhaar and signing up for Facebook – I have often been told by many friends, especially those who value privacy and agency – is a matter of consent. 

If the government has its way, residents of India will not be able to use their bank accounts, their phones, get pension, access provident fund, buy an airplane ticket, a flat or diamonds if they do not register with the world’s largest biometric database, which had enrolled 1.2 billion Indians by this week.

This is a good time to disclose that not only was I an early adopter of Aadhaar, I also linked my bank account and phone number much before the threatening emails and texts arrived. I admit that data leaks from third parties, such as gas and phone companies, that use the Aadhaar database sound quite frightening, even to me, the Aadhaar enthusiast (I’ll explain why later), and it is hard to trust a government that plays fast and loose with civil liberties and laws and boasts that my data is secure behind walls 13 feet high and 5 feet thick. Oh alright, it also uses 2048-bit encryption, but that is pretty standard worldwide, and data experts say that it sounds like so much jargon because it is not clear how much data is so encrypted and how.

In any case, the Supreme Court will soon decide the extent of Aadhaar’s empire, but who exactly is going to resolve the growing dispute over the power wielded by Facebook?

The age of privacy leaks
Every day, we learn that Facebook’s power and influence over our lives is greater than we ever imagined. Of course, it was our decision to sign up for Facebook, to share cuddly photos, feelings and opinions with friends, family and acquaintances. But we did not know, did we, that in doing so we have also laid bare not just the patterns of our lives – patterns that we ourselves may not have realised – but feelings that we may or may not have expressed?

We just found out that a rogue operation by a British company with access to the profiles of just 2,50,000 Facebook users was enough to let it gain insight into millions more. More than anything, the shock delivered by Cambridge Analytica reveals just how easy it is to filch personal data, how much of it is out there, and how vulnerable the world’s social networks are to abuse in an age of mass manipulation of mind and behaviour. People on any of these networks are either susceptible to exploitation – emotional or criminal – or have already been exploited in some way or the other.

I am on Facebook – and Twitter, Tumblr and WhatsApp. And wait, didn’t I sign up and once share articles on LinkedIn and Google something-or-the-other? There are a few of us still without a digital signature, for example, Sunil Gavaskar, India’s cricketing legend. He is not on any social network and shrugs off anything anyone might say about him there, but Gavaskar does use an old-fashioned mobile phone that is not smart, so he has a digital vulnerability, however diminished.

People do not even have to be on Facebook to have bits of their lives revealed. Someone may have posted a photo of them or shared something they may have written. That is enough for someone to know who that person’s friends are, what they think and where they have been.

It is not my case that the digital tsunami washing over our personal lives justifies the government’s determined efforts to make Aadhaar ubiquitous. It is not enough for the government to say, trust us – I would not. It is not enough for the CEO of Aadhaar’s implementing agency, the Unique Identification Authority of India, to say the database has suffered no leaks in eight years and refuse to acknowledge leaks from client networks – and harass or ignore those who reveal these chinks. Rhetoric is no substitute for robustness and trust. That trust currently does not exist in adequate measure, and without it, justifying the spread of Aadhaar is difficult.

Aadhaar ahead
Yet, there are two reasons I support Aadhaar. One, because I witnessed its founding idealism and knew many of the idealists who built India’s new digital foundation, and two, a robust, secure national database can help provide an identity and carry many benefits to millions of poor Indians who do not have one and have been left stranded by the rising tide of development.

Indeed, Aadhaar has been the prime enabler of the government’s success in getting bank accounts to more than 60% of Indians, up from 35% in 2011, with so-called zero-balance or unused accounts steadily falling. The enabling factor has been an army of banking correspondents, fanning out into the hinterland enrolling people and verifying identities, in large part through Aadhaar. Could it have been done through scores of bank databases? Possibly, but the logistical difficulties, apart from being considerable, may not have been overcome by the general Indian inability to work cooperatively.

The rush to now shove Aadhaar down everyone’s throats without ensuring that a host of institutions are seamlessly networked and safeguards are in place is unconscionable and dangerous. It is the poorest and weakest who are most affected by the leaks and chinks in the Aadhar ecosystem – denied rations, pensions and salaries because their fingerprints are worn out from a lifetime of manual labour, accidents or other misfortunes. They run from bureaucratic pillar to post, trying to regain their lost identities. They are exceptions, stray cases, the government argues, an argument that betrays its obsession with compliance, a refusal to see Aadhaar’s considerable problems and disregard for the caring society it claims to strive for. 

The folks at Aadhaar point out that the lack of biometric authentication is no reason to deny benefits due – the laws on this are clear – but that does not wash in a country riven by red tape and graft, where many officials will grab at any straw to make people’s life more difficult. And Aadhar is considerably more than a straw.

But it is also hard to justify stopping Aadhaar in its tracks because it has weaknesses. Every social network that we use has loopholes. There is no such thing as a perfect Facebook – answerable to national governments, laws and social concerns – and there never will be. Its founder Mark Zuckerberg says sorry and insists his social network will do better. He may find these promises difficult to honour.

Let us admit it, we are beguiled by the possibilities, and we are willing to take the accompanying risks. We may finally figure out those Facebook controls, and we may hope that the Supreme Court allows us to keep our Aadhaar numbers from those banks and phone companies. But the fact is, as our private lives surrender ever more to the rising digital tide, our vulnerabilities will grow. 

Privacy will be the first casualty; it already is. India is only just facing this incoming tide. Is it irreversible? Indeed, should it be reversed? These are questions as applicable to Facebook as to Aadhar – and the next big thing.

Support our journalism by subscribing to Scroll+ here. We welcome your comments at letters@scroll.in.

Sunday, April 1, 2018

13163 - Tip of the Suckerberg - Outlook India

https://www.outlookindia.com/magazine/story/tip-of-the-suckerberg/299966
Tip Of The Suckerberg
ILLUSTRATION BY SAJITH KUMAR
Psychographics
  • Qualitative methodology to describe consumers’ psychological attributes.
  • Psychographic profile: profiles ­interests, activities, opinions, lifestyle.
  • Does this by looking at consumer behaviour, preferences, web surfing patterns, call records and purchases
  • All this is used to classify people.
  • Companies use profiles for targeted sales and marketing campaigns.
  • Trump presidential campaign used this to ­influence voters.
***
The revelation that Facebook had allowed personal infor­mation from 50 million user ­acc­ounts in the US to be used by British data analytics company Cambridge Analytica shook the world. It took a toll on the stock prices of many companies including Facebook, whose value tanked significantly, and cre­ated a trust deficit in social ­media worldwide. Facebook founder Mark Zuckerberg will face the US Congress next week to answer que­stions about how his social media beh­emoth ­has been sharing the confidential inf­ormation of its ­users for profit.
In India, this has led to a bitter debate and mudslinging between the BJP and the Congress over the latter employing the services of Cambridge Analytica to influence elections. While the slugfest between the two big parties ­continues, this has led to a larger question: how safe is ­personal information and data in the hands of social media companies such as Facebook and WhatsApp? Indians routinely open up their hearts on these sites to share ­information about themselves and their families—do the sites then sell this data to others to man­ipulate buying and, well, voting?
The Facebook problem began in 2014 when a Cambridge researcher, Alexander Kogan, developed an app with a personality quiz called “This is your Digital Life”, which was put up on Facebook. Through this, he collected data from 270,000 users. This then gave him access to data from those users’ friends, and ­ultimately he was able to harvest the data of 50 million people. All this was then given to Cambridge Analytica, who used it to influence Donald Trump’s US Presidential election campaign. The issue here for India is that whistleblower Christopher Wylie, who revealed the nexus between Cambridge Analytica and Facebook, also said that the data analytics company had worked in India with the Congress party. This brings up privacy issues relating to personal data in India and the ability of social media companies to ­potentially misuse such data.
What is of concern is that India currently lacks privacy protection laws and everything is out in the open for firms to misuse. Personal information and data are routinely sold by social media companies, credit card companies and telecom operators. The government has set up a committee led by Justice (retd) B.N. Srikrishna to look into privacy issues; this comm­itee has prepared a draft report but is yet to submit its final report. At the mom­ent, Section 43A of the IT Act and associated rules serve as India’s primary data protection provisions. Given that Facebook is a foreign company, the app­licablity of these provisions to the social media giant is unclear. Says Usha Ramanathan, privacy activist and legal expert, “Most people do not understand the nature of privacy policy. So they sign on everything when signing on to a ­social media app or website. As a result, personal data and information are sold and the user has ­become the product. You are the one being sold and so the service is free. We do not realise that, from being a consumer, we ourselves have become the product for these ­social media sites. Their business is only about using our data.”
Ramanathan explains that a high level of manipulation of data and information takes place through the social media sites, who not only make use of it themselves but also aggregate the data and sell it to others. “When the systems know you even better than you yourself, manipulation becomes inevitable. That is the tragedy of ­technology,” she says.
Amber Sinha, cyber analyst and senior programme manager at the Centre for Internet and Society (CIS) feels that there is a need to look at the various kinds of data one shares while engaging with a social media platform such as Facebook—volunteered data  (data that is ­actively provided by individuals, such as details in a form when they sign up for a service), observed data (behavioural data generated through an individual’s use of the service), and inferred data (which is neither actively nor passively provided by the individual, but arrived at through the analysis of ­collected data).
While individuals are aware of the first category, they are often unable to exercise meaningful control over the second, as it is continually and automatically collected. Observed data also includes the collection of data from other online behaviour of the individual through various tracking tools which are dep­loyed on the browser. 
Further, the third category is often outside the scope of regulation, as it is not directly collected from the user but is inf­erred by the controller based on other data collected. This loophole must be closed by regulation to cover data use as well as collection practices.
Just as there is no privacy for personal data, there is also no privacy for our ­onl­ine activity, which is con­­s­tantly mon­itored by companies such as Facebook and Google. Says K.K. Mookhey, founder and CEO at Global Cyber Security Service Pro­vider, Network Intelligence, “The Facebook model is inh­erently pro­­b­lematic. You and I are the producers and consumers of the content provided by companies like Facebook. Facebook tunes the content according to our habits. What we see on Facebook is according to our choices and general surfing habits. It tracks our general surfing habits on non-Facebook sites, analyses our online behaviour, and then tweaks our content accordingly on Facebook. This is gro­ss manipulation which is automated through algorithms.”
With the data in hand, marketers can choose specific parameters to provide content and do micro-targeting. Cam­bridge Analytica did psychogra­phical mapping of the preferences of voters in the US elections using this kind of data. The company started by looking at und­ecided voters, and kept pushing them tow­ards the Republican Party. According to Elonnai Hickok, COO with CIS, “Personalisation of ­content, be it advertising, news, a product on Amazon or your Facebook feed is a practice that is being used across the board. Per­­­­s­­o­n­alisation happens through algorithms and the data you feed into it. No alg­orithm is perfect and it is possible for manipulation to happen intrinsically. Manipulation of the type that has been attributed to Cam­bridge Analytica is an extension of personalising a message to influence, not buying habits, but larger choices.” Adds Sivarama Krishnan, leader, Cyber Security, with PwC, “There is a clear case of privacy violation from a principle standpoint. It is not a legal violation as users have signed up to it voluntarily. They are manipulating the behaviour of the user by suggesting ­options according to a user’s behaviour and surfing habits. This is what Cambridge Analytica has done. This is a big challenge.”
The public perception of all this is, however, quite different, and most people want their data to be secure. According to a survey done by ­online analytics company Local Circles, 86 per cent of people in a sample survey wanted a law that protected their ­private information and 84 per cent did not want their bank transaction details to be ­accessible after the linkage of Aadhaar and bank acc­ounts, while 75 per cent did not want their call records to be acc­essible after similar linkages. A who­pping 94 per cent wanted companies, particularly banks and telecoms operators, to face a penalty if information is leaked. Says Hic­kok, “Selling of data that allows for personalisation is one of the primary business drivers. Though Facebook all­ows for controlling who sees the data, the company itself has given access to the information as per its business needs. The selling of data does happen around the world on a routine basis. It is important that privacy regulation place a framework around how data can be collected and used, and the redress that individuals can seek if their privacy is violated.”
There is no doubt that there is gross vio­lation of privacy as social media ­companies use and manipulate content for users in order to mould the latter in a particular manner for the sake of ­business. While the European Union is ready to ­introduce the General Data Protection Regulations (GDPR) to ­protect personal information and data from May, India is still a long way from reaching this stage and does not have any legal way at all to safeguard personal data. The country needs to develop GDPR-like rules to  protect its citizens. Until that happens, Big Brothers like Facebook will continue to watch you and will continue to mine Big Data.

Tuesday, March 27, 2018

13119 - Facebook-Cambridge Analytica row: Whether on FB or Aadhaar, societal need for privacy trumps the individual - First Post



Mar 26, 2018 11:14 AM IST
Comment 3

After days of prodding by the media, Mark Zuckerberg offered a mea culpa, apologising for the “breach of trust between Facebook and the people who share their data with us and expect us to protect it”. The news that Facebook shared user data with a number of organisations including Cambridge Analytica seems to reflect the paradox of surveillance society — that our data is never safe, but share it we must.

So once again, in a Snowdenish moment, we are hit by the revelation that Cambridge Analytica conducted behavioural modeling and psychographic profiling (creating personality profiles by gauging motives, interests, attitudes, beliefs, values, etc) based on data it collected, to successfully (allegedly) target Americans prior to the recent presidential election.

File photo of Mark Zuckerberg. Image: AFP


Meanwhile, in India, political parties have accused each other of hiring Cambridge Analytica for their own election campaigns.

The soothsayer
Facebook collects all kinds of social data about its users, like their relationship status, place of work, colleagues, last time they visited their parents, songs they like listening to, as well as other kinds of information such as device data, websites visited from the platform, etc. This may be information that is shared by the user or what their friends may share about them on the platform.
That aside, let us not forget that Facebook has bought over WhatsApp and Instagram and can tap into data from those platforms as well, apart from the data it buys from data brokers!

Data that is collected is used to draw up the profile of users — a detailed picture of the persona that emerges by piecing together known activity and aptitude and generating predictions about possible proclivities and predispositions. The mechanics of big data thus recreate the sum total of user traits and attributes — without necessarily verifying them per user.

What follows then is the clustering of users into hyper segments with similar attributes for micro-targeting ads. You may merely be ‘liking’ an article on the last male white Rhino, but Facebook will use it to predict with a fair amount of accuracy your political affiliation and sexual orientation, using algorithmic modelling to nudge you to buy something you are most likely to. Hyper-segmentation based on social media profiling can also be used to create a consumer base for political messaging, as has been suggested in the case of Cambridge Analytica.

The target
Many digital corporations, including Uber, Twitter and Microsoft sell their data to third parties who build apps and provide services on top of it. With machine learning, the targeting of individuals assumes new dimensions; it becomes possible to do nano-targeting, zoom in precisely on one individual.

A fintech startup in India recently rejected an applicant because they could uncover that she had actually filed for a loan on behalf of her live-in partner who was unemployed. The boyfriend’s loan request had been rejected earlier. The start-up’s machine learning algorithm had used GPS and social media data — both of which the duo had given permissions for while downloading the app — to make the connection that they were in a relationship.

That big data can be put to use in ways that reinforce ‘social and cultural segregation and exclusion’ is fairly well accepted now. It is this slippery slope from micro-targeting to the social allocation by algorithms of opportunities and privileges that poses serious concerns. A ProPublica investigation from 2016 collected more than 52,000 unique attributes that Facebook used to classify users into micro target-able groups. It then went on to buy Facebook advertisement for housing that demonstrated how it was possible to exclude African-Americans, Hispanics, and Asian-Americans. As Frank Pasquale notes, constitutionally inculcated rights and morality are slowly being undone “by the use of automated processes to assess risk and allocate opportunity”.

The public sphere
This brings us to the question of what the social role of digital intelligence means for the future of democracy. Elections play a vital role in a robust democracy. We seek to safeguard their free and fair nature through regulations that impose restrictions on exit polls or call out parties for unduly influencing voters through the distribution of freebies. Wouldn’t then, a nudging of voters through intimate knowledge of their behaviour be a threat to this socio-political hygiene we seek to maintain?
Can we allow the replacement of the will of the people by a market democracy in which the masses can be gamed? How should the Election Commission take due cognisance of and address such mass-scale manipulation?

Beyond electoral fairness, there are severe repercussions for the sanctity of the public sphere in the rapidly unfolding role of algorithms. When people know that online behaviour is monitored, they carefully moderate how they interact online, a phenomenon referred to as social cooling.


A man goes through the process of eye scanning for Unique Identification (UID) database system. Reuters

The collusion
The Cambridge Analytica episode bears a close resemblance to the Snowden disclosure of the unholy nexus of the state, private corporation, and uninhibited surveillance. India has already succeeded in building a ‘cradle to grave’ Panspectron by seeding citizens’ unique biometric identifier across databases. Aadhaar has allowed for an informationisation of life where “...the human body is reduced to a set of numbers that can be stored, retrieved and reconstituted across terminals, screens and interfaces”.

With the biometric, the body can never disassociate with its data and may be recalled, whenever convenient sans ‘the individual’. To add psychographic data akin to a ‘behavioural’ biometric to this mix is to give a ‘God’s eye view’ of society to the state, one that the state is bound to abuse to determine the human condition. For instance, China’s profoundly disturbing, Sesame Credit uses citizen data including data from everyday transactions, biometric data, etc, to dole out instant karma.

From the other end, corporations who already collect behavioural data are keen on accessing Aadhaar data, for this will allow them to trade data around a unique data point to attain, much like the state, a 360-degree view of their customers.

Facebook has faced criticism in the past for experimenting with users’ emotions, using unethical manipulation of information to influence the moods of users. The plausibility of nano-surveillance raises fundamental philosophical questions about society and human agency, calling attention to the urgent task of reining in the data capitalists.

The norm
While digital corporations claim to audit how third parties may use the data they have shared, monitoring is lax. India does have rules on data sharing; however, these pertain to a predefined list of data types. Traditionally, data protection legislation has focused on ‘personally identifiable information’(PII), but with technological advances — a la big data analysis and artificial intelligence, what is or is not PII is contested. The law, therefore, needs to be re-imagined to suit contemporary techniques of data analysis.

Besides the fact of unencumbered data sharing, that Facebook was able to collect such vast amounts and varied kinds of data is itself unsettling. To prevent the frightening prospect of future society being reduced to an aggregate of manipulated data points, it may well be necessary to determine that certain kinds of data will not be collected and certain types of data processing will not be done. Restrictions on collection and use can be sector specific, based on well debated social norms and constitutionally driven, much like how the Delhi High Court held on the grounds of the Right to Health that excluding genetic disorders from insurance policies is illegal.

It is time we moved from individual-centred notions of privacy where the ‘user’ is constantly asked to barter the right to privacy for entitlements, credits, and conveniences. Nandan Nilekani's exhortation that citizens be empowered to monetise the plentiful data they generate and get easier credit, better healthcare, better skills and welfare benefits is a recipe for a disempowered society left to the whims of neo-liberal market democracy. The social value of privacy needs to be spotlighted for it urges us to look not only at the individual right over data, but the social benefits that we derive from its recognition.

So far as societies are products of behavioural modelling, Zuckerberg’s apology does not really count.

The authors are with IT for Change, an NGO that works at the intersection of digital technologies and social justice



Published Date: Mar 26, 2018 10:10 AM | Updated Date: Mar 26, 2018 11:14 AM

Monday, March 26, 2018

13103 - Modi app leaks data? More privacy scare after Cambridge Analytica, Aadhaar - Business Standard



French researcher Elliot Alderson has alleged that information of those who download the Narendra Modi app is being provided to a third-party US company, Clever Tap, without users' consent
BS Web Team  |  New Delhi 

Last Updated at March 25, 2018 14:34 IST

File photo of Congress President Rahul Gandhi speaking during the 84th Plenary Session of Indian National Congress
After the data leak scandal involving Facebook and Cambridge Analytica, and the many reports of Aadhaar data of Indian being at a risk of compromise, the Narendra Modi app seems to be in the eye of a storm, and a new flashpoint in the war between the Congress and the Bhartiya Janata Party (BJP).

Rahul Gandhi on Sunday alleged that Prime Minister Narendra Modi's app was leaking data to US companies. In a post on Twitter, Gandhi claimed that the Prime Minister was allowing ‘American companies’ to take away the data of users who signed up for his application.

“Hi! My name is Narendra Modi. I am India’s Prime Minister. When you sign up for my official App, I give all your data to my friends in American companies,” Rahul Gandhi tweeted.

To this, the BJP countered the charge by saying that Gandhi and his party had zero knowledge of technology.

The development comes close on the heels of the Cambridge Analytica scandal causing a political slugfest between the BJP and Congress. Both the parties accused each other of having links with the data company under the scanner for stealing data from Facebook and influencing elections.

BJP alleged that Cambridge Analytica was involved in Rahul Gandhi's social media campaigns, especially in last year's Gujarat Assembly election. Congress on its part claimed that BJP availed of the company's services in various state Assembly elections -- Bihar, Maharashtra, Haryana, Jharkhand, and Delhi -- besides for its 'Mission 272 plus' in the 2014 general elections.

Apart from these, the two parties also crossed swords several times over the Aadhaar data security.

In January, when the nodal agency implementing the Aadhaar project, Unique Identification Authority of India (UIDAI) filed an FIR against the The Tribune and its reporter Rachna Khaira for an article reportedly exposing the ease with which anybody would steal Aadhaar-related data, Congress had accused the NDA government of destroying the Aadhaar programme and called the FIR "unfortunate".

Here are the top developments in the latest data breach row allegedly involving the Narendra Modi app:

1. Rahul claims Modi's app steals data: Rahul took a jibe at PM Modi on Twitter on Sunday, alleging that his Narendra Modi app was leaking data to US companies.


Hi! My name is Narendra Modi. I am India's Prime Minister. When you sign up for my official App, I give all your data to my friends in American companies.

Ps. Thanks mainstream media, you're doing a great job of burying this critical story, as always.


2. BJP counters Rahul's claim: BJP said that Rahul Gandhi and his party had no knowledge about technology. Here is what BJP said in the tweet.


Rahul Gandhi truly shows why he and his party have zero knowledge of technology. All they can do is scare the masses about technology while they continue to steal data using his ‘Brahmastra’ of Cambridge Analytica.

3. Union Minister K J Alphons responds: In an apparent response to Rahul Gandhi, Alphons said “I filled up to 10 pages for a US visa form.

We have absolutely no problem giving our fingerprints and being naked before the white man at all. When your own government asks for your name and address, there is a massive revolution saying it's intrusion of privacy.”

4. 'Narendra Modi app sending user info to US company': French researcher Elliot Alderson has alleged that information of those who have downloaded the app was being provided to third party US company Clever Tap without users’ consent.

In a series of tweet, Anderson had claimed that user's device information, as well as personal data, was sent to a third-party domain called in.wzrkt.com. when a person creates profile in the app.

5. Latest row after govt issued notice to Cambridge Analytica: The government on Friday issued a notice to UK-based Cambridge Analytica, asking it to give a list of clients and the source of data it had collected.

The IT Ministry has asked the firm to respond by March 31 on six questions, including how the company had collected user data, whether consent was taken from the individuals, and how the data was used.

6. Cambridge Analytica behind Rahul Gandhi's 'Gabbar Singh Tax' jibe, claimed BJP: Stepped up its attack on Rahul Gandhi and the Congress, BJP had said that Cambridge Analytica's "footprints" were visible in the Opposition party's campaign in Gujarat. Further, the BJP suggested that Cambridge Analytica had a role in the Congress chief's use of the term "Gabbar Singh Tax".

Union minister Ravi Shankar Prasad also suggested that the firm had a role in Gandhi's social media campaign and the Congress' "poisonous" electioneering in Gujarat.

7. Take action instead of holding press conferences, Congress tells BJP: Senior Congress leader Abhishek Manu Singhvi adviced the BJP that instead of holding press conferences, the ruling party should take action over its allegation that the Opposition party is indulging in data theft to influence elections in India.

Alleging that the BJP has dished out fake news for long, Singhvi said that the spread of false information has been its forte.

"BJP is the party in power. Rather than holding press conferences, why doesn't it take action?" he said about Union Law and Information Technology Minister Ravi Shankar Prasad's charge that the Opposition party was using data manipulation and theft to woo voters.

8. Congress called Ravi Shankar Prasad 'lie minister': Equating Ravi Shankar Prasad to Hitler's Goebbels, Congress spokesperson Randeep Singh Surjewala said that "now a new fake agenda" is being used to stop the proceedings in Parliament. Surjewala added that instead of law minister, Prasad should be called a "lie minister".

"One who stole data (Facebook and Mark Zuckerberg) is also Prime Minister Narendra Modi's friend. Still they are shouting so much. Modiji and Prasad must reply to a few questions," he added.

9. The battle over Aadhaar: Aadhaar has been another flashpoint between the two parties in their battle over data theft and privacy. Congress has time and again accused the NDA government of destroying the Aadhaar programme. In January, Congress had condemned action against the reporter for an article which reportedly exposed the ease with which anybody can steal Aadhaar-related data.

"Instead of helping the poor, it has become a tool of spying and surveillance," Congress spokesperson Shobha Oza had said.

In reply to Motion of Thanks to the President's address on February 7, prime minister Modi had attacked the Congress party over it's questions on the implementation of Aadhaar, saying that Congress was crying foul because we made Aadhaar scheme better.

“I remember clearly, when we won elections, you (the Congress) said Modi will finish Aadhaar because it is our scheme… (But) When Modi furthered it more scientifically and found new ways to implement it, now after it has been implemented and started benefiting the poor, you question its implementation,” the Prime Minister had said.


First Published: Sun, March 25 2018. 14:34 IST

Saturday, March 24, 2018

13078 - FB data breach puts spotlight on Aadhaar ET Now| - Economic Times

ET Now|
Mar 23, 2018, 01.19 PM IST

It’s a ‘Sorry’ from Zuckerberg, finally! In an interview with CNN, the Facebook founder admitted that the social media networking platform may have grossly erred by its failure to protect personal data of its millions of subscribers. Facing fire for the massive data breach involving British data analytics firm Cambridge Analytica, Zuckerberg says Facebook doesn’t have the right to serve its loyal customers anymore. 

But the controversy doesn’t seems to end there. The Modi government has intensified its attack against the Congress for the party’s alleged links with Cambridge, something which the main opposition party continues to deny. 

IT and Law Minister Ravi Shankar Prasad slammed the Congress, accusing it of hiring Cambridge for its social media campaigns, even as party president Rahul Gandhi hit back, accusing the BJP of trying to frame his party. The Congress also charges Team Modi of using the Facebook fiasco to divert public attention from the massacre of 39 Indians in the Iraqi town of Mossul. 

The big political stand-off apart, the data breach at the world’s most popular networking platform raises some serious questions over privacy and data safety. At a time when Supreme Court is examining the constitutional validity of Aadhaar, the Facebook episode is sure to put the pressure on the government to ensure that data security gets top billing. 

It will also make the clamour for a greater scrutiny of social media platforms louder. The mega data breach at Facebook and what it means to privacy laws in India, That’s our topic of discussion on the India Development Debate tonight. 

HITESH JAIN
SPOKESPERSON, BJP 

Anyone can put any claim on website, but it needs to be validated. Validation for the Congress came during Gujarat elections, when details about Cambridge Analytica first emerged. Now the Congress is trying to distance itself from the company. The government is coming out with a strong data protection law. The consultation process is already on. 


SANJAY JHA
NATIONAL SPOKESPERSON, CONGRESS 

Ravi Shankar Prasad has conceded a self-goal. The BJP stands ashamed of lying in broad daylight. We have nothing to do with Cambridge Analytica. We have to look at the role of Facebook. PM Narendra Modi went to the company’s headquarters and hugged Mark Zuckerberg. Let us not take Zuckerberg at face value. 

SANJAY JAIN
FELLOW, ISPIRT 

On the privacy side, we want to make sure we have a world where we have complete control of our data. Data protection law will make sure that no data can be used without the knowledge of the procurer. We need a new set of laws and a strong infrastructure. This is the right opportunity to create a new law. 

SAKET MODI
FOUNDER, LUCIDEUSTECH 

India is a minefield of data. You can actually profile people on when they wake up, when they sleep. Ad is a just small part. The content shown to me is used to manipulate how I think. The BJP and the Congress don’t realise that Cambridge Analytica has not broken any law, apart from using the 50 million user details in the US. 

NIKHIL PAHWA
FOUNDER, MEDIANAMA.COM

It is not about how they used the data, but how they are going to use it. It is really easy to use big data analysis to send personalised messages. It creates mass polarisation. You are targeting people to change the way they think and that will have a negative impact on our democracy. The only recourse I see is data disarmament. 

Read more at:


Wednesday, March 21, 2018

13054 - Facebook crisis holds lessons for India and Aadhaar: we need multi-pronged regulation to ensure fair play and innovation - First Post


Mar 21, 2018 15:48:41 IST

Editors note: As India stands at the cusp of a new era in economic growth, it is time to ask a big question: Can a nation of one billion people build a global tech giant as new frontiers of technology arrive? The answer involves understanding global economic dynamics, innovation, ownership, management, competition, regulation, finance and intellectual property rights. Firstpost is publishing a series of stories, beginning today, that will seek to address these issues in a manner that helps entrepreneurs, policymakers and ordinary citizens understand what it takes to reach new highs without losing one's ground in a world where threats are as real as opportunities. Here's the second piece in the series. You can read the first piece here.

On Wall Street, the four darlings of the technology industry driving a boom in the stock market are collectively called FANG (Facebook, Amazon, Netflix and Google). Not for nothing, you may say. When these giants’ technological fangs are revealed, they show an incredible ability to snoop on you -- ostensibly with your permission and in order to serve you better, but full of possibilities where data that they have on you, can be used to cajole, persuade or fool you. And those who fool Internet users may not necessarily be these companies, but others who use an ecosystem of industries or services that "harvest" data.

If hard proof was needed, we found it this week following stunning revelations of how Cambridge Analytica, a UK-based data science company, profiled 50 million Facebook users with information mapping and then bombarded them to create what one could call a data ambush. Data-driven messages sent to Facebook users wove a mysterious web that persuaded their voting behaviour to pick Donald Trump as US President. This raises questions on ethics, laws and regulation in the digital age. Facebook shares have lost billions of dollars in market value in an ominous signal that business and politics intersect on social media.

If India is to breed technological giants, it is important to keep in mind the double-edged nature of digital technologies including the Internet, mobile telephony and social media. If their global reach, speed and efficiency seem to empower ordinary consumers and citizens with the power of knowledge, choice and opinion, it unequally empowers giants like FANG to gather data and map digital footprints. On a fine day, you could call it ethical cyberstalking. On a bad day, it could lead to disruptions that can fool citizens, shape monopolies that are anti-competitive, or offer fake news or biased views that masquerade as customised insights.

India, if it wants to empower ordinary citizens on the one hand, build technology giants on the other, and at the same time preserve the essential purpose of democracy, has to think of strengthening or ushering in progressive regulation on three fronts. First, it must ensure fair competition between global giants and local competitors in a manner that nurtures innovation without predatory power. The Telecom Regulatory Authority of India (TRAI) rejected Facebook's Free Basics initiative in India on the ground that it violates Net Neutrality, which requires content and commerce to be separate from carriage.


The Enforcement Directorate (ED) in India has probed Amazon to see if it circumvented a ban on direct sales to domestic consumers, while the Karnataka government has probed possible tax evasion by Amazon via smart warehousing. The Competition Commission of India (CCI) recently slapped a hefty fine on Google on grounds that it had a "search bias" abusing its dominant position.
Secondly, India's regulators need to ensure that neither money power, nor conflicts of interest stand in the way of innovation, consumer interest or competition. Typically, one-stop-giants like Facebook (socialisation), Amazon (shopping), Netflix (entertainment) and Google (search) have monopolistic tendencies because they are platforms where various kinds of competitors converge -- and it is important that a platform does not become a super-competitor to those it serves with its own proprietary services without proper Chinese walls or supervision in place. Indian entrepreneurs have cribbed about "capital dumping" where a cash-rich global giant can snuff out a local challenger (especially startups) at an early stage. We need tech-savvy anti-trust regulations that are able to define market dominance and service categories properly in the digital age, because dominance need not come from cash alone; it can also come through clever algorithms, software or business models.

Thirdly, India needs to create a new regime of data hygiene. With the Aadhaar unique identification scheme caught up in a Supreme Court case amid allegations of unnecessary government surveillance and alleged leaks of confidential data online, the imperative is clear: we need Internet user education akin to what the Securities and Exchange Board of India (SEBI) does for investor education. Internet giants, as well as their local competitors, say their websites ensure privacy and choice for consumers, but what we need is informed consent, not just inertial consent that is based on half-truths. We need policies, regulations and a public awareness campaign in place to ensure that not only is privacy not breached, but people know what is done with the data that they may be unconsciously revealing to Internet companies. Sometimes, your behavior on Facebook is as good or bad as allowing a local mall to install CCTVs inside your living rooms or your kitchen. Do people really want that?
All in all, what the digital age needs is a multi-pronged legal and regulatory regime that ensures both political and economic choices and freedoms. Activists, on one front or the other, will talk of how it impinges on free speech or entrepreneurial freedom, but answers lie in the basic principles of both democracy and market economics. It is imperative to employ policy-makers and regulators who are knowledgeable about what smart technologies can do to fend off shrewd lobbyists.
"Data is the new oil" is a business motto for the 21st Century. What we need to remember is that data thefts can even result in the hijacking of new-age oil tankers, with the power to fuel confusion.

The author is a senior journalist. He tweets as @madversity.


Published Date: Mar 21, 2018 15:03 PM | Updated Date: Mar 21, 2018 15:48 PM

13045 - In Light Of Recent Facebook Breach, Privacy Advocates Demand Stronger Data Laws In India

As Part Of The Breach, Cambridge Analytica Harvested Information Of 50 Mn Facebook Users During The Last US Elections

March 20, 2018 5 min read
INC42 STAFF

After news of one of Facebook’s biggest data breaches perpetrated by British big data analytics startup Cambridge Analytica surfaced earlier this week, privacy advocates in India are now demanding stronger data privacy laws in the country.
This comes at a time when the Indian government’s Aadhaar programme has been garnering widespread attention due to its suspected vulnerability, which has left the system susceptible to countless data breaches and attacks.

In light of the reports claiming Cambridge Analytica harvested the profiles of up to 50 Mn Facebook users without their approval during the last US elections, privacy advocates in India have raised concerns that a similar breach could happen here to target voter opinion.

Speaking on the matter, advocate Apar Gupta told ET, “The government has not moved with necessary pace on data protection. Election commission (EC) has not taken up this issue of data protection for regulatory scrutiny. EC has in the past issued guidelines to protect election integrity and restrained exit polls and also required candidates to disclose social media handles. However, much more needs to be done.”
Interestingly, in September 2017, reports surfaced that a major Indian opposition party was looking to join hands with Cambridge Analytica for reaching a larger section of the country’s voting population in the upcoming 2019 general elections.

RELATED STORIES:

As per the digital publication, Moneycontrol, the data mining company made a presentation to the party in question a month prior to that, wherein it showcased a data-driven strategy based on voters’ behaviour on social media.

How Cambridge Analytica Perpetrated One Of Facebook’s Biggest Data Breaches

Created in 2013 as an offshoot of British big data analytics company Strategic Communication Laboratories (SCL) Group, Cambridge Analytica is a privately-held big data analytics firm that is partly owned by the family office of American right-wing billionaire, Robert Mercer.

Since its inception, CA has been involved in more than 44 American political races. Additionally, the big data startup was part of the famous “Leave.EU” campaign of the 2016 Brexit referendum. As part of these campaigns, Cambridge Analytica reportedly bought data from a multitude of sources, including shopping data, club memberships, bonus cards and public registries, among others.

The report further stated that the big data analytics company tracked information pertaining to the type of magazines people read, places they visit and churches they attend.


As explained by Cambridge Analytica CEO Alexander Nix, the startup’s expertise lies in collating vast amounts of seemingly disjointed data and connecting them in dots by matching voter profiles and databases. The data, according to Nix, allow CA to identify voting preferences of every voter in a particular area.

According to reports that surfaced recently, the British company accessed personal information of around 50 Mn Facebook users, without authorisation, in early 2014 to create a database of individual US voters, with the aim of targeting their political beliefs through personalised advertisements.

Commenting on the development, a person working closely with the company told The Guardian, “We exploited Facebook to harvest millions of people’s profiles. And built models to exploit what we knew about them and target their inner demons. That was the basis the entire company was built on.”

The data was collected through an app called thisisyourdigitallife, which was designed by  Aleksandr Kogan, sources have revealed.

In response to the reports of the data breach, Paul Grewal, VP and Deputy General Counsel of Facebook said in a statement, “Like all app developers, Aleksandr Kogan requested and gained access to information from users who chose to sign up to his app, and everyone involved gave their consent. People knowingly provided their information, no systems were infiltrated, and no passwords or sensitive pieces of information were stolen or hacked.”


However, since these reports emerged earlier this week, the social media giant’s stock has dropped by 7% in a single day.
Earlier in January 2018, in response to Supreme Court’s observation that a line has to be drawn between Aadhaar application and people’s right to privacy, the Indian government informed the apex court that a data protection bill was being drafted by a committee of experts. At the time, reports stated that the draft would be ready by the end of this month.
Prior to that, in November 2017, the government released a white paper on the data protection framework. As per the paper, a nuanced approach towards data protection will have to be followed in India, bearing in mind the fact that individual privacy is a fundamental right limited by reasonable restrictions.
Data privacy is increasingly becoming an area of concern in the country, with giants like Facebook, WhatsApp, and Monster India being inspected for allegedly sharing user information with third-party entities.
In September last year, the Supreme Court of India reportedly issued notices to Google and Twitter, in reference to the public interest litigation petition filed against the Internet behemoths over data privacy concerns by Pallav Mongia, an Advocate-on-Record at the Supreme Court.
The petition, according to sources, has raised concerns about the lack of control over information sharing with cross-border corporate entities, which could potentially be a violation of the Indian citizens’ right to privacy.
As digital transactions and Internet penetration in the country increases, it is but inevitable that more such issues around privacy and security of information will spring up. Whether the government takes heed of the concerns raised by privacy advocates, especially in light of the recent Facebook data breach, remains to be seen.