Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, April 2, 2012

Would You Fire Someone for Trying to Make a Co-Worker Laugh?

This is a story about a Michigan teacher's aide who was fired, she claims, for trying to crack up a co-worker–and out of hours, too.
But like many workplace-related giggles gone awry in the 21st century, this one begins in social media, or more specifically, Facebook.
In April 2011 Kimberly Hester, a teacher's aide at Frank Squires Elementary in the village of Cassopolis, Michigan, posted to Facebook a photo of a co-worker's pants around her ankles and a pair of shoes. The caption: “Thinking of you." (See the photo here.)
“It was very mild, no pornography,” Hester told Michigan's WSBT TV station. She added: “It wasn't at work, it was off work time."
A parent at Lewis Cass Intermediate who was friends with Hester on the social network promptly alerted the school to the photo. (Hester's aide job was at the elementary school, but she technically was employed by Lewis-Cass Intermediate.)
Lewis Cass Intermediate superintendent Robert Colby called Hester into his office a few days later and, according to her, asked her three times for access to her Facebook page, which was private.
"I repeatedly said I was not OK with that,” Hester told WSBT.
Within days, Hester received a letter from the Lewis Cass ISD Special Education Director, which she provided the TV station. It read, in part: “…in the absence of you voluntarily granting Lewis Cass ISD administration access to you[r] Facebook page, we will assume the worst and act accordingly."
She was put on administrative leave and eventually suspended.
“I have the right to privacy,” she told WSBT.
Hester has taken legal action.
“I stand by it,” she said. “I did nothing wrong. And I would not, still to this day, let them in my Facebook. And I don’t think it’s OK for an employer to ask you.”
But University of Notre Dame labor law professor Barbara Frick told the TV station that the school didn’t break any laws by asking for Hester’s Facebook information.
Right now there are no state or federal laws protecting social media privacy in the workplace, Frick said. Michigan currently is one of several states pushing for legislation that would make an employer's asking for a Facebook password illegal, though–and the social network itself has said it will seek legal action against offending employers.
Both sides are scheduled to go to arbitration in May.
Last week, Republicans in the U.S. House of Representatives defeated an amendment titled "Mind Your Own Business on Passwords", that would have banned employers demanding access to Facebook accounts. (Democrats had added the provision to a larger Federal Communications Commission reform package.) It can still return as separate legislation.
Also last week, a pair of senators (Democrats Charles Schumer of New York and Richard Blumenthal of Connecticut) called for an investigation to determine whether employers asking for Facebook passwords are breaking the law. They sent letters to the U.S. Department of Justice and the U.S. Equal Employment Opportunity Commission, questioning whether the practice is in violation of laws prohibiting intentional unauthorized access to electronic information.

Friday, March 23, 2012

Employee Passwords Are None of Your Business, Says Facebook

If the growing number of companies and law enforcement agencies asking job applicants for Facebook passwords was encouraging you to do the same, think again.
Facebook Friday issued a warning to employers that requesting passwords is an invasion of privacy that opens companies to legal liabilities.
The world's largest social network also is threatening legal action. Wrote Erin Egan, Facebook's chief privacy officer, in a lengthy post: "We'll take action to protect the privacy and security of our users, whether by engaging policymakers or, where appropriate, by initiating legal action, including by shutting down applications that abuse their privileges."
The company says it has seen a "distressing increase" of reports of employers attempting to access user accounts, Facebook's Egan wrote. "The most alarming of these practices is the reported incidences of employers asking prospective or actual employees to reveal their passwords," she said.
A user should never be forced to cough up private information just to get a job—"and as the friend of a user, you shouldn’t have to worry that your private information or communications will be revealed to someone you don’t know and didn’t intend to share with just because that user is looking for a job," Egan wrote.
The company has changed its Statement of Rights and Responsibilities, making requests to share or solicit a Facebook log-in a violation of the rules.
The American Civil Liberties Union this week used the reports to urge support for its "Demand your dotRights campaign."
ACLU attorney Catherine Crump called the password solicitation an "invasion of privacy."
"You’d be appalled if your employer insisted on opening up your postal mail to see if there was anything of interest inside," she said. "It’s equally out of bounds for an employer to go on a fishing expedition through a person’s private social media account."
The ACLU of Maryland currently is fighting for a social media privacy bill in the state, where the Department of Public Safety and Correctional Services asks applicants to "voluntarily" provide access to their social media accounts during interviews.

Wednesday, February 22, 2012

Apple, Google, And Others Agree To Mobile App Privacy Policy Guidelines

Though Apple, Google, Microsoft, RIM, Amazon, and HP don’t always see eye-to-eye, the six of them have entered into an agreement brokered by California Attorney General Kamala Harris to take a tougher stance on the issue of mobile privacy.
Going forward, the six companies involved must provide users with a privacy policy if the app in question collects personal information. Though the move will affect the app submission and downloading process for users the world over, it was designed to bring those six companies into compliance with California state law.
“The majority of mobile apps sold today do not contain a privacy policy,” Harris said. “By ensuring that mobile apps have privacy policies, we create more transparency and give mobile users more informed control over who accesses their personal information and how it is used.”
It isn’t just enough for these companies to provide app-specific privacy policies to their users; they must also do it before the user downloads it, creating a much-needed means for them to opt-in. Apple and company also need to be consistent in how they display that information, as the agreement Harris brokered called for “a consistent location for an app’s privacy policy on the application-download screen.”
On top of that, users will also be given tools to help police their respective app stores. The terms of the agreement note that the platforms in question will allow users to report non-compliant apps, which could bring about some welcome change in some respects — while the Android Market already allows users to flag questionable apps, the iOS App Store and the Windows Marketplace don’t give users that power.
The past few weeks have made the mobile privacy issue a hot-button topic outside of the tech sphere, and the attention doesn’t just end with California’s AG — two congressmen sent a letter to Apple CEO Tim Cook posing questions about user data privacy, and the White House will be holding an online meeting tomorrow to accompany the release of a white paper on online privacy. Regardless of how this privacy discussion began, don’t expect for the talk to subside any time soon.

Microsoft’s Clash With Google Over Privacy Settings May Be Part of a Larger Problem

Google’s policies are once again under scrutiny as Microsoft and others have caught the company circumventing users’ privacy settings to track them with cookies. But Google representatives have pointed out that they are not alone.
It all started with Apple’s Safari Web browser. According to the Wall Street Journal, Google and other advertising companies have been using a special code to trick Safari into bypassing users’ privacy settings to monitor their activities online. Stanford grad student Jonathan Mayer first spotted the code. A follow-up investigation by WSJ advisor Ashkan Soltani revealed that the Google tracking code had been installed on a test computer through ads on 22 of the top 100 websites and that the code was also installed on an iPhone browser through ads on 23 sites. (Once the Journal contacted the company about the matter, Google disabled the code.)
When Microsoft heard that Google had circumvented user privacy settings on Safari, they wondered if Google was also bypassing users’ privacy preferences on Internet Explorer. Microsoft’s Internet Explorer corporate vice president Dean Hachamovitch wrote in a blog post, “We’ve discovered the answer is yes: Google is employing similar methods to get around the default privacy protections in IE and track IE users with cookies.”
The real issue, according to a blog post by TAP, is that the default setting Microsoft created to block third-party cookies has a bug. As a result, many companies – including Facebook – have been able to get around the requirement for third parties to summarize their privacy policies and offer users a way to opt out of sharing their personal data. The protocol for writing compact policies (CP), as defined by the Platform for Privacy Preferences Project (P3P), has not been widely implemented since it was first created in 2002 by the World Wide Web Consortium.
A Facebook representative told ZDNet, “While we would like to be able to express our cookie policy in a format that a browser could read, P3P was developed 5 years ago and is not effective in describing the practices of a modern social networking service and platform. Instead, we have posted a public notice describing our practices that is consistent with Section 3.2 of P3P. We have reached out directly to Microsoft in hopes of developing additional solutions and we would welcome the opportunity to work with W3 to update P3P to account for the advances in social networking and the web since 2007.”
Google’s response to Microsoft’s complaints said more or less the same thing. “Today the Microsoft policy is widely non-operational,” Google wrote. “A 2010 research report indicated that over 11,000 websites were not issuing valid P3P policies as requested by Microsoft.”
The complexity of the issue begs the question, is there an easier way to handle this? According to Jonathan Mayer, there is. He and fellow Stanford researcher Arvid Narayanan are currently working on Do Not Track, a policy proposal that would allow users to opt out of being tracked across all third-party sites, much like the Do Not Call Registry.
If it goes through, would you sign up?
Image by Gunnar Pippel via Shutterstock