almost always be combined either with themselves or with other domains to create a
much more personal, intrusive set of combined data—for instance, by combining the
Google search data with the Google search cookies to identify users by cookie, or by
combining the Google search IP addresses with ISP logs (as required by the EU data retention directive) to identify users by IP address.
All these different possible uses and combinations of data represent networks of
trust. A rational user ought to evaluate these decisions about trust carefully, though in
practice few have the time to do so with any level of sophistication. The example of
Google demonstrates the complexity of these issues of trust—about how data are collected, who has access to it, and what is done with it. Google is collecting vast amounts
of information from users in ways that are not clear to most users, yet most users
eagerly accept the arrangement that Google offers them. Most users presumably understand that they are giving Google access to their search terms, but some may not
understand that Google is storing these data. Yet other users are likely not to understand that Google generates its revenue through its advertising brokerage business. It
is not at all clear that clicking on any Google AdWords ad takes you to a Google server
first and only then redirects you to the clicked ad. Nor is it clear that by clicking on a
Google AdWords ad, you are sharing with the advertiser the fact that you searched for
or browsed content about a given subject. The potential of Google’s vast store of user
data creates a serious risk of disclosure throughout this network of trust regardless of
whether Google’s intentions are in fact good for its customers.
The exchange of data between user and server establishes a relationship of trust. A
survey by the Internet security company WebSense found that 60 of the 100 most popular sites on the Internet had hosted malicious code at some point in the past year. 25
The examples that WebSense cites are attacks on the Web pages displayed to users
rather than the back-end servers, so they do not give direct access to user data stored
on the servers. But they do hijack the identity of the server on behalf of the attacker,
allowing the attacker to present a portion of the Web page as if it is coming from the
trusted server. The result is a variety of attacks that collect data on behalf of an attacker
posing as the trusted server. These widely prevalent Web site attacks allow attackers to
insert themselves into users’ networks of trusted actors by way of the infected sites.
Google tried to use the EU data retention directive as part of the rationale behind its
eighteen-month data retention period for certain user data, though some observers
contend that the directive does not apply to Google as a ‘‘content provider,’’ as
opposed to a ‘‘communication service.’’ 26 EU commissioners beat back that particular
argument and have aggressively lobbied for Google to reduce the amount of data
it keeps and how long it keeps the data under its privacy directive. 27 This exchange
demonstrates precisely the problem at the intersection of the EU data retention directive and the way that surveillance works in the networked public sphere today. The
same EU authority that is responsible for guarding against the retention of personal
44
Hal Roberts and John Palfrey
Précédent

- 61/635

Suivant