国产视频

In Short

Chilling Effects of the Ashley Madison Scarlet Letter

This post is co-authored by Alex Bradshaw (CDT) and Jake Laperruque (OTI Fellow).

It鈥檚 been a little over a week since massive amounts of data from the popular cheating website, Ashley Madison, were published online. Impact Team, the group behind the breach, released everything from email and home addresses of Ashley Madison鈥檚 users to their credit card and bank account information. Not surprisingly, the consequences were brutal. Although public reaction has been a mix of , the hack鈥檚 effects will likely spread far beyond the site, to affect anonymity and online security throughout the Internet.

Many are likely reacting to the Ashley Madison hack with humor and righteous glee because they see this data dump as something that will only affect 鈥渂ad people,鈥 but this sentiment is fundamentally misplaced. Just as the 鈥淚鈥檝e got nothing to hide鈥 critique of government surveillance misses the point that many others have legitimate things to keep secret, laughing at the Ashley Madison hack ignores the fact that there are many online services that require privacy, and this breach threatens their use.

Consider the huge range of websites that offer community forums and live chat for dealing with issues such as substance addiction, suicide prevention, mistreatment of LGBT youth, domestic abuse, and sexual assault. Individuals will often turn to these anonymous online services because these topics carry social stigma or the potential for discrimination if revealed. By outing millions of Ashley Madison users, hackers have shown that online safe havens for anonymous activities may not be safe at all. In the process they may chill use of services that provide important support to those in need.

This is not to say Ashley Madison is free from blame. There are a number of ways it could have mitigated injury. For one, requiring users to pay $19 to have their data deleted is ridiculous and borders on blackmail. There鈥檚 no reason to keep that much information on someone who no longer uses a site 鈥 not only does this require more storage and security (which adds to operating costs), but it also increases the chances of a hack. The FTC has repeatedly said that , and the Office of the Privacy Commissioner of Canada, Center for Democracy & Technology, and a host of other organizations agree that . Ashley Madison should have employed an automatic data purge policy for individuals no longer using the site or, at the very least, offered customers the option to delete their data for free upon service cancellation. And it goes without saying that if a company insists on charging a user for data deletion it should actually delete all of that users鈥 data (something Ashley Madison failed to do).

Furthermore, the fact that Ashley Madison鈥檚 homepage continues to boast having 鈥渙ver 39,645,000 anonymous members鈥 and being 鈥渢he world鈥檚 leading married dating service for discreet encounters鈥 is baffling; the majority of its members are no longer (if they ever were) anonymous, and their communications are anything but discreet. Ashley Madison is making the same mistake , and made: overpromising. No matter how sincerely a company desires to keeps their users鈥 secrets confidential, . This doesn鈥檛 mean services shouldn鈥檛 strive to provide anonymous messaging platforms. Rather, companies should be transparent with customers about exactly how they define 鈥渁nonymity,鈥 as well as the technical limitations of these services. Achieving anonymity requires completely separating a users鈥 identity from their activity on a site. Even if this is done perfectly, there鈥檚 always a chance that metadata can be linked to track activity back to a particular individual. This is occurring with Ashley Madison users that created fake email addresses, but are being tracked down via location data included in the leak.

Additionally, the technical limitations of anonymous messaging do not excuse a company of its obligation to provide strong data security. Encryption, security audits, compliance officers, and employee training are just a sampling of security policies that companies should implement. This is especially important for services that promise 鈥渟ecret鈥 interactions (because users are signing up for the very purpose of maintaining their online privacy). Adopting these practices could also help businesses avoid FTC actions based on poor data security (we鈥檙e looking at you, ).

This also raises the question of how we should view Impact Team who justified their data dump as an attempt to damage a company engaged in 鈥.鈥 Exposing Ashley Madison鈥檚 deceptive data retention policies and poor security did not require publicly posting sensitive personally identifiable information about its users 鈥 all that accomplished was grabbing attention and . There are even and the Saudi Arabian government to hunt down adulterers and individuals engaged in gay relationships (punishable by death in the country).

When releasing their data, Impact Team advised exposed users to 鈥淢ove on with your life 鈥. Embarrassing now, but you鈥檒l get over it.鈥 The true impact of their actions shows how outrageous this suggestion is to those affected, and how disingenuous the label 鈥渉acktivist鈥 is for such a group. There are enormous that will result from the en masse public branding of a digital Scarlet Letter on Ashley Madison鈥檚 users. This breach reflects a severe disregard for privacy, safety, human rights, and the digital dignity that all individuals are entitled to. There is no excuse for it. The Ashley Madison hack does not deserve praise or applause, it should not be greeted with jokes and amusement. It deserves nothing less than disdain.

More 国产视频 the Authors

Alex Bradshaw

CDT

Programs/Projects/Initiatives

Chilling Effects of the Ashley Madison Scarlet Letter