CSE545 - Advanced Network Security - Professor McDaniel Page
Privacy
Professor Patrick McDaniel CSE545 - Advanced Network Security Spring 2011
1
Privacy Professor Patrick McDaniel CSE545 - Advanced Network - - PowerPoint PPT Presentation
Privacy Professor Patrick McDaniel CSE545 - Advanced Network Security Spring 2011 CSE545 - Advanced Network Security - Professor McDaniel Page 1 What are we talking about? What is privacy? What privacy concerns do you have when you go
CSE545 - Advanced Network Security - Professor McDaniel Page
1
CSE545 - Advanced Network Security - Professor McDaniel
Page
2
CSE545 - Advanced Network Security - Professor McDaniel
Page
3
principles
CSE545 - Advanced Network Security - Professor McDaniel
Page
4
CSE545 - Advanced Network Security - Professor McDaniel
Page
5
CSE545 - Advanced Network Security - Professor McDaniel
Page
6
CSE545 - Advanced Network Security - Professor McDaniel
Page
6
CSE545 - Advanced Network Security - Professor McDaniel
Page
7
CSE545 - Advanced Network Security - Professor McDaniel
Page
8
CSE545 - Advanced Network Security - Professor McDaniel
Page
9
CSE545 - Advanced Network Security - Professor McDaniel
Page
10
CSE545 - Advanced Network Security - Professor McDaniel
Page 11
CSE545 - Advanced Network Security - Professor McDaniel
Page 12
CSE545 - Advanced Network Security - Professor McDaniel
Page 13
CSE545 - Advanced Network Security - Professor McDaniel
Page 14
CSE545 - Advanced Network Security - Professor McDaniel
Page 15
CSE545 - Advanced Network Security - Professor McDaniel
Page 16
browser site Please store cookie xyzzy
browser site Here is cookie xyzzy
CSE545 - Advanced Network Security - Professor McDaniel
Page 17
that set them – but this may be any host in domain
– Sites setting cookies indicate path, domain, and expiration for cookies
database key that is used to look up user info – either way the cookie enables info to be linked to the current browsing session Database Users … Email … Visits …
Send me with any request to x.com until 2008 Send me with requests for index.html on y.x.com for this session only
User=Joe Email= Joe@ x.com Visits=13 User=4576 904309
CSE545 - Advanced Network Security - Professor McDaniel
Page
18
CSE545 - Advanced Network Security - Professor McDaniel
Page
19
CSE545 - Advanced Network Security - Professor McDaniel
Page 20
CSE545 - Advanced Network Security - Professor McDaniel
Page 21
Ad Ad
Search Service CD Store
CSE545 - Advanced Network Security - Professor McDaniel
Page 21
Ad Ad
search for medical information
Search Service CD Store
CSE545 - Advanced Network Security - Professor McDaniel
Page 21
Ad Ad
search for medical information
set cookie
Search Service CD Store
CSE545 - Advanced Network Security - Professor McDaniel
Page 21
Ad Ad
search for medical information
set cookie
buy CD
Search Service CD Store
CSE545 - Advanced Network Security - Professor McDaniel
Page 21
Ad Ad
search for medical information
set cookie
buy CD
replay cookie
Search Service CD Store
CSE545 - Advanced Network Security - Professor McDaniel
Page 21
Ad company can get your name and address from CD order and link them to your search
Ad Ad
search for medical information
set cookie
buy CD
replay cookie
Search Service CD Store
CSE545 - Advanced Network Security - Professor McDaniel
Page 22
CSE545 - Advanced Network Security - Professor McDaniel
Page 23
– Stock dropped from $125 (12/99) to $80 (03/00)
CSE545 - Advanced Network Security - Professor McDaniel
Page 24
CSE545 - Advanced Network Security - Professor McDaniel
Page 25
CMPSC443 - Introduction to Computer and Network Security Page
friends, …
etc ….
26
CMPSC443 - Introduction to Computer and Network Security Page
27
CSE545 - Advanced Network Security - Professor McDaniel
Page 28
Creative Labs Nomad JukeBox Music transfer software reports all uploads to Creative Labs. http://www.nomadworld.com Sportbrain Monitors daily workout. Custom phone cradle uploads data to company Web site for analysis. http://www.sportbrain.com/ Sony eMarker Lets you figure out the artitst and title of songs you hear on the radio. And keeps a personal log of all the music you like on the emarker Web site. http://www.emarker.com :CueCat Keeps personal log of advertisements you‘re interested in. http://www.crq.com/cuecat.html
See http://www.privacyfoundation.org/
CSE545 - Advanced Network Security - Professor McDaniel
Page 29
CSE545 - Advanced Network Security - Professor McDaniel
Page
30
CSE545 - Advanced Network Security - Professor McDaniel
Page 31
– Including information about cookies
might be shared
policies
There is lots of information to conveys -- but policy should be brief and easy-to-read too! What is opt-in? What is opt-out?
CSE545 - Advanced Network Security - Professor McDaniel
Page 32
– Limited ability to detect non-compliance
CSE545 - Advanced Network Security - Professor McDaniel
Page 33
CSE545 - Advanced Network Security - Professor McDaniel
Page 33
CSE545 - Advanced Network Security - Professor McDaniel
Page 34
– Federal Trade Commission has jurisdiction over fraud and deceptive practices – Federal Communications Commission regulates telecommunications
– Privacy commissions in each country (some countries have national and state commissions) – Many European companies non-compliant with privacy laws (2002 study found majority of UK web sites non-compliant)
CSE545 - Advanced Network Security - Professor McDaniel
Page 35
CSE545 - Advanced Network Security - Professor McDaniel
Page
36
CSE545 - Advanced Network Security - Professor McDaniel
Page 37
CSE545 - Advanced Network Security - Professor McDaniel
Page 38
CSE545 - Advanced Network Security - Professor McDaniel
Page 39
CSE545 - Advanced Network Security - Professor McDaniel
Page
Consortium (W3C)
issued 16 April 2002
about their privacy policies in a standard computer-readable format
change their server software
(built into browsers or separate applications) that
user preferences
40
policies
does not set baseline standards or enforce policies
(as of July 2002)
http://privacybird.com/
CSE545 - Advanced Network Security - Professor McDaniel
Page 41
CSE545 - Advanced Network Security - Professor McDaniel
Page 42
CSE545 - Advanced Network Security - Professor McDaniel
Page 43
CSE545 - Advanced Network Security - Professor McDaniel
Page 44
Web Server
CSE545 - Advanced Network Security - Professor McDaniel
Page 44
Web Server GET /index.html HTTP/1.1 Host: www.att.com . . . Request web page
CSE545 - Advanced Network Security - Professor McDaniel
Page 44
Web Server GET /index.html HTTP/1.1 Host: www.att.com . . . Request web page HTTP/1.1 200 OK Content-Type: text/html . . . Send web page
CSE545 - Advanced Network Security - Professor McDaniel
Page 45
Web Server GET /w3c/p3p.xml HTTP/1.1 Host: www.att.com Request Policy Reference File
CSE545 - Advanced Network Security - Professor McDaniel
Page 45
Web Server GET /w3c/p3p.xml HTTP/1.1 Host: www.att.com Request Policy Reference File Send Policy Reference File
CSE545 - Advanced Network Security - Professor McDaniel
Page 45
Web Server GET /w3c/p3p.xml HTTP/1.1 Host: www.att.com Request Policy Reference File Send Policy Reference File Request P3P Policy
CSE545 - Advanced Network Security - Professor McDaniel
Page 45
Web Server GET /w3c/p3p.xml HTTP/1.1 Host: www.att.com Request Policy Reference File Send Policy Reference File Request P3P Policy Send P3P Policy
CSE545 - Advanced Network Security - Professor McDaniel
Page 45
Web Server GET /w3c/p3p.xml HTTP/1.1 Host: www.att.com Request Policy Reference File Send Policy Reference File GET /index.html HTTP/1.1 Host: www.att.com . . . Request web page Request P3P Policy Send P3P Policy
CSE545 - Advanced Network Security - Professor McDaniel
Page 45
Web Server GET /w3c/p3p.xml HTTP/1.1 Host: www.att.com Request Policy Reference File Send Policy Reference File GET /index.html HTTP/1.1 Host: www.att.com . . . Request web page HTTP/1.1 200 OK Content-Type: text/html . . . Send web page Request P3P Policy Send P3P Policy
CSE545 - Advanced Network Security - Professor McDaniel Page Page
http://adforce.imgis.com/?adlink|2|68523|1|146|ADFORCE http://www.att.com/accessatt/
CSE545 - Advanced Network Security - Professor McDaniel
Page 47
Privacy icon on status bar indicates that a cookie has been blocked – pop-up appears the first time the privacy icon appears Automatic processing of compact policies only; third-party cookies without compact policies blocked by default
CSE545 - Advanced Network Security - Professor McDaniel
Page 48
Preview version similar to IE6, focusing, on cookies; cookies without compact policies (both first-party and third-party) are “flagged” rather than blocked by default Indicates flagged cookie
CSE545 - Advanced Network Security - Professor McDaniel
Page 49
CSE545 - Advanced Network Security - Professor McDaniel
Page 50
CSE545 - Advanced Network Security - Professor McDaniel
Page 51
CSE545 - Advanced Network Security - Professor McDaniel
Page 52
CSE545 - Advanced Network Security - Professor McDaniel
Page 53
CSE545 - Advanced Network Security - Professor McDaniel
Page 54
CSE545 - Advanced Network Security - Professor McDaniel
Page
check automatically at every site
preferences
actively block cookies, referrers, etc. or take other actions at sites that don’t match user’s preferences
are designed as plug-ins or other add-ons, and others may be provided as part of an ISP or other service
55
CSE545 - Advanced Network Security - Professor McDaniel
Page 56
– Users should not have to trust privacy defaults set by software vendors – User agents that can read APPEL (A P3P Preference Exchange Language) files can
– Preference editors allow users to adapt existing preferences to suit own tastes, or create new preferences from scratch – For more info on APPEL see http://www.w3.org/TR/WD-P3P- preferences
CSE545 - Advanced Network Security - Professor McDaniel
Page 57