Datafication, Phantasmagoria of the 21st Century

Tag: Data

[HOW TO] Protect From Data Theft? (Privacy)

Many people ask me how to protect from data theft from Big Tech. This is a really important question, so I asked a digital security expert friend of mine. This is his (unedited) reply. Some of those are more directly actionable than others. I will regularly add to the list.

Use a *trustworthy* VPN for all devices like Mullvad or ProtonVPN (or tor/I2P for truly sensitive things) with reliable DNS protection (but also aware VPN has own risks, strictly only to mask your true IP + mask your web activity from your ISP + provide more secure internet when connected to public or unsafe networks).

Use Linux on desktop (or any open source privacy friendly version, just avoid MacOS, Windows and ChromeOS).

Use de-googled android (grapheneOS) on mobile. Neither Androids not iPhones are safe. A mobile phone is most invasive and privacy leaking device in our lives.

Delete all social media and big tech accounts.

Replace the services/apps one uses with open source/libre software alternatives. Email, contacts, calendar, cloud storage, apps on phone etc… Especially avoid any products or services by big tech (e.g. Google docs, Gmail, drive, youtube, search, Chrome, WhatsApp etc…).

Use privacy friendly web browser (recommend “brave” browser) with disabled telemetry and tracking blocking and fingerprinting resistance settings set to maximum.

Use privacy friendly search engine (duckduckgo is OK), do not use Google search, Microsoft Bing, etc.

Understand how internet and web infrastructure works (networking basics) as this is key to knowing how to manage own data trail and emissions. Key part is understanding that every single action taken in relation to internet or digital anything leaves a permanent record and digital trail of breadcrumbs. So to know how to get by using alias information when possible, and to be extremely judicious in providing any true personal data in any digital context. Doesn’t matter that one uses the most private and secure computer system if they just go and share their personal life story and details by posting such on the internet. Disclose as little as possible online, and if needed use false/alias data.

Use end to end encrypted and metadata minimising methods of online communication (e.g. Signal is not perfect but probably best balance between privacy/security and usability/widespread use).

Generally opt to use software and services that rely on well-implemented encryption technology and *end to end* and *zero knowledge* encryption wherever possible.

Do not use regular phone call or SMS (use secure WiFi call or message via secure apps instead).

Why I Am Quitting WhatsApp – Part II

A couple of months ago I sent a message that started as follows: “For the past 5 years, I have been doing a PhD research on large social platforms. I want to share a few thoughts on why I am quitting WhatsApp before February 8th 2021.” The short memo was written after WhatsApp unilateral announcement that there were changing their T&C to accommodate WhatsApp For Business. Since then, Facebook postponed the changes to their T&C to May 15th after the announcement caused an uproar. 

Since I sent the message in January, I received many questions and comments, some people quit WhatsApp altogether, some opened accounts on other messaging platforms (mostly Telegram and Signal), and some disagreed completely with my analysis and kept using WhatsApp as usual. Based on the rich discussions I had with friends and acquaintances in the past few months, I want to share a few more thoughts before the change comes into reality. 

Why Did FB Postpone the Change to May 15th?

Delaying the change gave Facebook time to achieve two things. 

1. First, to rewrite the narrative through a process of habituation.

Habituation is a tactic that has been widely utilised by large social tech corporations in the past 15 years to gradually get us used to increasing encroachments on our privacy. 

The tactic works as follows:

  • Unilaterally announce the change. Ignore signs of disgruntlement. If the announcement causes a major uproar, issue a statement saying that you have been misunderstood and postpone. Stay low for a little while until some other news takes front stage (that shouldn’t take too long). 
  • This gives you time to design a communication campaign that heavily emphasises specific (reassuring) aspects of the issue (e.g., privacy is built into our DNA, we do not have access to the content of your messages) and completely obfuscate the real truth (we do not care a bit about the content of your messages, we want to track your behaviour not your words).
  • If opposition is too strong – for example as in the case of the Facebook Beacon feature implemented in 2007 and abandoned in 2009 after a class action lawsuit – find other technical ways to achieve the same goal, which is what FB did with Facebook Connect and spreading a piece of code in its Like button that sends information back to FB when you visit any unrelated site anywhere on the web. 

2. Second, it allowed Facebook to think out and implement a campaign of misinformation (I am using the word with purpose). Disinformation is the phenomenon of spreading lies. Misinformation is the phenomenon of spreading half-truths to create confusion or take control of the main narrative. WhatsApp is emphasising that the CONTENT of our messages is and will always remain private. What WhatsApp is not saying is that they could not care less about that content, because the data they hunger for is metadata. 

METADATA & PRIVACY

What’s Metadata? 

It is data about data, or data about your behaviour (not your words) when you are online. A few (non-exhaustive) examples are: who you know (your contacts), who you message, when and how often, who they know, who they message etc. But also, your device and user ID, your name, your location, your email, and all sorts of user and device content. In short, any activity that can be tracked and linked to you.

The Gold of the Internet

In tech parlance, metadata is referred to by the euphemism “breadcrumbs” (a noun that deceptively emphasises the innocuous and insignificant nature of this type of data). Google discovered early on that users left collateral behavioural data (the breadcrumbs) behind when they searched, and that the breadcrumbs could be aggregated and fed into machine learning to get really deep insights into who we are. Those insights go well beyond what we think we reveal when we live our life online. This collateral behavioural data is the “gold” of the internet. 

The discovery above marked the birth of “targeted advertising”, another euphemism for the enterprise of surveillance that has grown exponentially and largely unchecked since the early 2000s. It’s not what you say online (content), it’s the traces you leave that count (metadata). For more, see Shoshana Zuboff under “resources” below (if you read only one book on this topic, let it be hers).

A Narrow Definition of Privacy 

When we, users, think of privacy, we think about the content of the information we share online. But a quick look at WhatsApp Privacy Policy (see link below) makes two things clear:

  1. metadata (not content) is the core commodity being harvested. 
  2. we have no say in what and how our data is collected, how it is treated and what it is being used for.

Under the “Information We Collect” heading, there are 3 paragraphs. Interestingly, the first one is called “Information You Provide”, hinting that the other two are information that you do NOT (and may not want to) provide. Indeed, they are: “Automatically Collected Information” and “Third Party Information”. 

Here is an excerpt: “Device and Connection Information. We collect device-specific information when you install, access, or use our Services. This includes information such as hardware model, operating system information, browser information, IP address, mobile network information including phone number, and device identifiers.” It is really interesting to read through https://www.whatsapp.com/legal/privacy-policy if you have not already done so.

NB: WhatsApp Terms of Service and Privacy Policies change with time. I posted the pdf and some experts of the document as of 27 March 2021 in a post above.

REAL IMPLICATIONS OF WHATSAPP FOR BUSINESS

What’s Really Behind WhatsApp For Business?

As you probably know, WhatsApp has been sharing metadata from your chats with its parent company Facebook for some time already. The changes in T&C are meant to allow WhatsApp For Business (WFB) to take off the ground. 

What does it mean? On the face of it, WFB is merely a tool to help businesses “better communicate” with us, their customers. Officially, Facebook tells us that it just means that businesses will be able to chat with you, give you information on their products, follow up on your purchases and give you “better” customer service. But if you think about it, most of that could already be achieved before WFB. By opening the possibility for transactions on WhatsApp, WFB will allow Facebook to get extraordinarily granular collateral behavioural data on aspects of our lives it had only indirect, limited or no access to before

What Business?

One thing you may want to contemplate: what does “business” mean in “WhatsApp For Business”? Retail brands certainly, and this seems innocuous enough. But not only (and by the way, what seems innocuous to you is not so innocuous once it goes through the analytical capacities of Big Data). But “Business” may also cover health-related communications and transactions. You may not mind if Facebook peeks into your interactions with a fashion brand, but how would you like it to have granular access to your exchanges with businesses selling health devices and health practitioners (and that may include how much and how often you spend on treatments), insurers, money lenders, financial institutions and more? Do you really think that Facebook ought to have access to details from your credit cards and bank accounts statements (a statement states who, when and how much you spent with, so essentially, FB will have access to your statements)? 

IMPLICATIONS

Commodification of users 

I sometimes hear people say: “if you do not pay for a service online, you are the product”. It is true in spirit, but not completely. The massive enterprise of data extraction shows that we (users) have become, not the product, but the cheap commodity. From this, FB and Google extract the raw material they use to create the valuable products they sell not only to advertisers but to be honest, to anyone who is willing to pay for them whatever their intention. In other words, we are the pigs, not the Iberico ham

An Enterprise of Territorialisation

Another aspect of the enterprise of digital surveillance can be summed up in two words: “never enough”. The internal competitive logic of the targeted advertising model drives those corporations to ceaselessly expand in order to acquire ever-more predictive collateral behavioural data. Since we still live (slithers of) our life offline, it is not enough to surveil our lives online, so the tactics used online are seeping through to the physical world. 

Our bodies are the next frontier (in January 2021, Google paid $2.1 billion for Fitbit, a company that makes bracelets that record health and fitness data). Sensors, wearables, our bodies have become territories to conquer. How do you claim that territory? By creating new needs and new habits. 

Wearables and sensors in the physical world (think “smart” cities) can detect changes that happen in your body below the dermal layer. How is that for an invasion of privacy? Who gets all that data about your heart rate and the number of steps you take and how many times you wake up at night? Where does that information go? What happens to that data after it is collected? Who decides what to do with it? Who benefits in the end? Do you know? And more importantly do you mind? 

AN ECOLOGICAL CRISIS

Why It Is Urgent to Take Action 

We got where we are today because the unprecedented nature of these developments has obfuscated what was really going on (see Zuboff for more on this). In 2021 though, it is hard to ignore that we have reached a point where we can’t afford to be complacent

In 1964, environmentalist Rachel Carson wrote Silent Spring, a compelling call for the world to wake up to the large-scale slaughtering of our environment through the commodification of nature by large corporations with unmatched lobbying power. Today, we are doing to human experience what we started doing to nature 60 years ago

Reconfigurations of Power

First, it is an ecological crisis in the distribution of power. The digital developments of the past 20 years have created massive asymmetries of knowledge. In other words, Google and Facebook know heaps about us but we know very little about them. The algorithms that orchestrate the online life of several billion people across the planet are considered proprietary trade secrets. These massive asymmetries of knowledge lead to massive asymmetries of power

This is compounded by the void in the legal framework surrounding these issues. An army of in-house lawyers unilaterally controls our contractual relationship with some platforms which in many ways have become public spaces. The only alternative to full acceptance is not to use the service. And a second army of “communication experts” and lobbyists carefully craft the official narrative (the definition of privacy is only one example). 

Crisis of the Ecology of Knowledge

But there is another more insidious and less talked about implication. The commodification of users is leading to a major epistemological catastrophe. The reductionist approach to human experience (i.e., to quantify purely qualitative aspects of our lives, and discard what cannot be quantified) is corrupting what we know, and how we know what we know. It is an ecological crisis of knowledge of the sort only seen once in a millennium (more about that in another post). 

MISCONCEPTIONS

Everyone on the Web Collects Data, so Why Bother?

Now, coming back to where we started, I hope I have given some avenues of reflection for why quitting WhatsApp may not be such a bad idea after all. However, I want to address one concern that I heard many time in the past couple of months. 

Some people told me: “if I move to Telegram or Signal, they will also collect my data, so what’s the point?” That’s a very valid question. While it is true that data collection is widespread online (we all heard about the cooking apps collecting your device ID and geolocation), everything is not created equal so we need to use our power of discrimination.

First, Telegram and Signal collect much less metadata than WhatsApp (or Facebook Messenger). In fact, Signal only collects your phone number. You can easily check this. In fact, just like you brush your teeth in the morning, it is a good habit to check what metadata the apps you use get from you. But that’s not all. 

Exercise Our “WE” Muscle

Second, we need to exercise our “we” muscle instead of solely relying on our “I” muscle. As I mentioned above, this is an ecological issue. Self-centred thinking is not a luxury we can afford anymore. If social media have taught us anything, it is that we are intricately interconnected and that the decisions we make individually have global consequences. This is true for the environment; this is also true for the digital environment. 

Be selective in whose business you patronise, because as you do, you are participating in creating the world that we will leave to the next generations. In other words, do not underestimate the positive ripple effects from an individual decision to use an equivalent app outside of the Facebook domain (and that applies to Google as well by the way). As I said in my previous post, if you leave, some people in your network will also leave. The network effect works in favour of platform monopoly but it can also work against it. 

Final Word: Personal Convenience Is Not a Judicious Ground for Action

One last word. Some will decide to remain on WhatsApp not because they trust Facebook but simply for convenience. This is one option. Social platforms are built for convenience (in design parlance it is called “user experience” or UX for short), because they know that convenience drives users’ lethargy. To follow this argument, it is also more convenient to throw garbage through your car window, release harmful chemicals in rivers rather than in purifying facilities, and throw plastic bottles in the ocean rather than in recycling plants. Personal convenience is not always the most judicious ground for action. 

RESOURCES

I am starting a Datafication & Technology blog to keep writing about these issues (www.datafication.space). Post, comment or send me questions (datafication.space AT protonmail.com) on topics you would like to see treated.

GENERAL RESSOURCES

SPECIFIC TOPICS

  • To read more on the historical developments, the mechanisms and ideological premises of Surveillance Capitalism, check “The Age of Surveillance Capitalism” by Shoshana Zuboff, Professor Emerita at Harvard Business School who has researched technology since the 1970s. The book made such a noise since it came out that it now has a wikipedia entry (https://en.wikipedia.org/wiki/The_Age_of_Surveillance_Capitalism). Zuboff gave a string of interviews, and you can also easily find those online. 

Why I am quitting WhatsApp – Part I (13 January 2021)

For the past 5 years, I have been doing a PhD research on large social platforms. I want to share a few thoughts on why I am quitting WhatsApp before February 8th 2021. 

As you probably heard by now, WhatsApp is changing its Terms & Conditions as of 8th of February, 2021. Furthermore, as is customary with Facebook companies, the move is unilateral and if users do not accept the new terms, they will lose access to their account. There are two things you want to be very clear about when you make your decision to remain on the platform. What “data” and “privacy” mean and why WhatsApp is making the change. 

WHAT DO DATA & PRIVACY MEAN?

It is not the first assault on our privacy in the race to control the use of our data. WhatsApp has been sharing information with Facebook, its parent company, for a while. However, this change opens the door for major, more intrusive and more unilateral changes that violate the privacy and the dignity of their users. We all know about the privacy issues that come with social platforms. We all know that FB collects our data. But the real questions are: what is this data we are talking about? FB claims that “privacy” is built into their DNA, but how do they define privacy?

Over the years, FB has been very careful to maintain ambiguity about this and have adopted a very narrow definition. They equate data with CONTENT, i.e. WHAT we say in the messages we exchange, and equate privacy with not having access to that content. They say that WhatsApp supports point to point encryption, and even WhatsApp does not have access to the content of what we write, therefore, they respect our privacy. 

This is a FALLACY. The data that FB and WhatsApp want is not the content (what we write), but data on our behaviours when we are on their platform, like where we are, who we contact, how long we stay on the platform, who do we message most, at what time, who is in our network etc… This data is called “breadcrumbs”, because it is a kind of side effect that happens when we use their main service. But it is the most valuable data because, when it is aggregated and analysed by super computers (what is called Big Data), it gives Facebook very deep insights into you, who you are, your personality, what presses your buttons, your body, your health, your mental state, your wishes and many things that you would not want other people to know about you, and rightfully so. 

I often hear people say that “Facebook sells our data”, but Facebook says they don’t and it is true! They do not sell our data, they sell something much more valuable than our raw data. They use our data as raw material to create computer-ready products that they sell on their platform not only to advertisers but to whoever wants to buy them (governments, extremists, third parties trying to influence elections… you name it). In other words, we, the users, have become not the product, but the raw material, the cheap commodity. We are called “users” but a better name should the “USED”. (If you want to know more about this, read Shoshana Zuboff’s “The Age of Surveillance Capitalism”, a powerful eye opener!)

WHY THE CHANGE?

So why is WhatsApp making the changes now? 

First, because Facebook wants to monetise WhatsApp. Think about it as an expensive piece of real estate with just a small house on it. Even if the house is quite nice, that piece of land is not optimised. Facebook wants to create a universe that is so all-encompassing that users never need to leave it. It wants to be the “WeChat of the West”, a place where ultimately, you will be able to socialise, communicate with your friends, share moments, workout, buy stuff, send money, follow your favourite brands or celebrities, fall in love, manage your health and bank accounts or credit cards etc. In other words, Facebook wants you to live your life through Facebook. Why? Well data of course!

Second, because Facebook wants to integrate WhatsApp so deeply into the Facebook family that it will soon be impossible (or very difficult) for regulators to break them down. Think about it as baking a cake. Once the flour and the eggs and the sugar have become the cake, you can’t get the eggs back. Facebook is under scrutiny from governments in several countries. The EU already set up the GDPR, a regulation on data protection and privacy, in 2016. In the US, there is a strong bi-partisan concern and Facebook is being investigated for abuse of dominance and anti competitive conduct, with the idea of possibly breaking it up. But as I said, once the cake is baked, it is really tricky to get the eggs back… 

SO WHAT SHALL I DO?

In the past week or so, many people have downloaded Telegram and Signal, two WhatsApp-like apps that provide instant messaging services. But I also hear a lot of people say they will stay on WhatsApp even though they downloaded the new apps. 

“I will stay on WhatsApp for now but I will quit later”. This is exactly what Facebook is counting on, because they know one fact about human psychology: that we are essentially creatures of habits, and once we are used to doing something in a certain way, it is going to take a lot of effort to change it (ask smokers how easy they find it to stop smoking). Right now, there is a knee jerk reaction, we download Signal or Telegram and it makes us feel better and safer. But in one month time, when another breaking news occupies our (limited) mental space, all will go back to the way we have always done it, i.e. “I’ll WhatsApp you!” 

“I can’t quit WhatsApp, all my friend/clients are there”. True, with over 2 billion users, your friends, family, clients and their cats and dogs are probably all on WhatsApp. But the argument above is the snake biting its own tail. If people leave WhatsApp, people will leave WhatsApp. I am quite certain that you would be surprised if you checked how many people around you actually do have an account on another major messaging app, or are ready to download it and make the switch! (I certainly was). 

So for all those reasons, it’s Farewell WhatsApp for me. And I am looking forward to life without Facebook with curiosity and anticipation!