{"id":1242,"date":"2011-01-24T13:04:03","date_gmt":"2011-01-24T12:04:03","guid":{"rendered":"http:\/\/t-machine.org\/?p=1242"},"modified":"2011-01-24T13:04:03","modified_gmt":"2011-01-24T12:04:03","slug":"identity-theft-exploitation-and-gravatar","status":"publish","type":"post","link":"http:\/\/new.t-machine.org\/index.php\/2011\/01\/24\/identity-theft-exploitation-and-gravatar\/","title":{"rendered":"Identity theft, exploitation, and Gravatar"},"content":{"rendered":"<p>There&#8217;s a growing problem right now with Facebook Connect: it can silently log you in to websites that you *don&#8217;t want* to share your private data with. I saw a funny example last month where a porn website had integrated Facebook Connect &#8230; so when you visit the site, one miss-click and you&#8217;ll broadcast to all your work colleagues your embarassing love of HardCoreGrannies.<\/p>\n<p>But there&#8217;s another example right now that may be worse, and is definitely food for thought. Facebook doesn&#8217;t broadcast your data &#8211; not to protect your privacy, but to prevent competitors getting access to data they are currently making money out of themselves. By contrast, there&#8217;s Gravatar: these guys take your private data and give it away to everyone &#8211; and they refuse to stop doing it (I&#8217;ve asked, directly, and they refused. They had no reason to refuse &#8211; they knew my identity, they knew my request was valid, and I believe under UK \/ Europe law it would be *illegal* for them to refuse. But &#8230; they&#8217;re American, and I guess all they care about is money).<\/p>\n<p>So, for instance, I just had one of my online identities ruined by Gravatar. A website that I rarely use recently &#8220;upgraded&#8221; and implemented the gravatar system &#8211; and immediately took a private account and publically broadcast that I was the owner. They didn&#8217;t ask me, they just went ahead and did it. Like many web developers, I&#8217;m sure they had no idea what they were doing &#8211; few seem to be aware of the scam that underlies Gravatar.<\/p>\n<p>Fortunately, I&#8217;m not going to lose something massively important, like my job \/ marriage \/ life (c.f. the news stories when Google Wave launched), but the website owners had no way of knowing that. They&#8217;ve just unleashed this upon their hundreds of thousands of users; what are the chances that one of them will be affected?<\/p>\n<p>(incidentally, if you&#8217;re a website owner, I strongly recommend you think twice before adding Gravatar (or any of the clones) to your own site. I don&#8217;t know if anyone&#8217;s been sued for it yet, but I&#8217;m sure it&#8217;ll happen eventually)<\/p>\n<p>There are two halves to the problem. Gravatar is fundamentally a violation of privacy: they take your data and give it to *everyone* without you knowing. So what? That&#8217;s the whole point of the service! Yes, the Gravatar author is a little incompetent (c.f. OpenID for how he *should* have implemented it), but otherwise there&#8217;s no problem, is there? In theory &#8230; if you voluntarily sign-up for it, it&#8217;s all OK. Isn&#8217;t it?<\/p>\n<p>Well &#8230; maybe not. They won&#8217;t let you (the user \/ owner) control that flow of data. What happens if you change your mind &#8211; can you delete their data? Nope. Why? I&#8217;m not sure, but I would guess: If you did that, you&#8217;d undermine their ability to make $$$ out of you. You can (theoretically) set your pictures back to empty. But &#8230;<\/p>\n<p>&#8230;But there&#8217;s a second half to this. I believe most people are on Gravatar because WordPress &#8220;gave&#8221; the user&#8217;s private data to Gravatar. That&#8217;s a nasty mess right there; what does WordPress&#8217;s privacy policy say? Again, when they acquired Gravatar, they apparently didn&#8217;t ask their users what they wanted, they just forced this privacy violation on them. Back then, it didn&#8217;t have much effect (Gravatar itself was relatively unknown \/ little used), but as Gravatar gets used more widely, the problem becomes more acute.<\/p>\n<p>And here&#8217;s the rub: Gravatar&#8217;s staff refuse to adhere to privacy requests because (precising \/ summarising): &#8220;you have to use your wordpress.com account&#8221;. What if you don&#8217;t have one? &#8220;you must have had one in the past and we won&#8217;t help you. Go away, and stop bothering us&#8221;.<\/p>\n<p>Meanwhile, WordPress refuses to send password details to anyone, ever. A wise security decision in some ways (e.g. many people use the same password on multiple sites. Doh!). Your only choice is to delete the password and recreate it.<\/p>\n<p>Is that a problem? Sadly, yes. Because (due to some very short-sighted \/ stupid marketing decisions by the WP folks) there are lots of admin systems &#8211; e.g. anti-spam &#8211; that are run off people&#8217;s WordPress accounts. So far as I can tell, no reason exists for this *except* to harvest email addresses and try and lure people onto paid WordPress.com plans. Further, WordPress uses an archaic password-based system (instead of e.g. Yahoo&#8217;s  permission-based API &#8211; which, again, is how WP should have implemented this) &#8211; so if you change your password, all those websites will break.<\/p>\n<h4>Summary<\/h4>\n<p>These services are a nice idea in theory, but when you get terrible implementations like Gravatar, combined with lazy \/ stupid staff, the user does pretty badly. They get screwed, they get patronised (just look at the Gravatar.com FAQ; they&#8217;ve cleaned it up in the last 12 months, it&#8217;s no longer so actively offensive as it used to be, but it&#8217;s still pretty bad), and many times they don&#8217;t even know about it until the violation is widespread.<\/p>\n<p>And, ultimately, any website that uses this system is in danger of losing badly if it goes to a court-case. I&#8217;m not a lawyer, but when there are industry standards for user-controlled privacy (OpenID), and specific laws demanding that Gravatar honour the requests it currently refuses (UK Data Protection Act, for instance), I suspect a court is unlikely to look favourably on a website claiming innocence. Ignorance isn&#8217;t generally a valid legal defence.<\/p>\n<p>But how much damage do these systems do to themselves? If Automattic were a little less greedy, or a little less selfish, would a lot more people embrace the idea of sharing their identity openly? Will OpenID provide a gravatar-replacement that doesn&#8217;t shaft the user, and will that take off much bigger than the original?<\/p>\n<p>Personally, I look at recent events like Google Wave, and Blizzard&#8217;s &#8220;forum identity = credit-card name&#8221; &#8211; and the s***storm of angry users in both cases &#8211; and I suspect these privacy issues are much more damaging than corporates expect. Which is good news: the world appears to be slowly waking-up to the abuses inflicted upon them in the digital world, and the importance of keeping certain things (passwords, email addresses &#8211; and now, finally: identity) sacrosanct. And that is definitely a good thing&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s a growing problem right now with Facebook Connect: it can silently log you in to websites that you *don&#8217;t want* to share your private data with. I saw a funny example last month where a porn website had integrated Facebook Connect &#8230; so when you visit the site, one miss-click and you&#8217;ll broadcast to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47,53,6],"tags":[],"_links":{"self":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts\/1242"}],"collection":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/comments?post=1242"}],"version-history":[{"count":0,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts\/1242\/revisions"}],"wp:attachment":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/media?parent=1242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/categories?post=1242"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/tags?post=1242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}