<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wilted buttercup, grey skies, and geek &#187; Privacy</title>
	<atom:link href="http://mmt.me.uk/blog/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://mmt.me.uk/blog</link>
	<description>Mischa’s ramblings on the interweb</description>
	<lastBuildDate>Mon, 16 Jan 2012 23:23:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>shareNice : unintrusive social sharing</title>
		<link>http://mmt.me.uk/blog/2011/07/19/sharenice/</link>
		<comments>http://mmt.me.uk/blog/2011/07/19/sharenice/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 19:49:49 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[dnt]]></category>
		<category><![CDATA[nologging]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[sharenice]]></category>
		<category><![CDATA[tracking]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=480</guid>
		<description><![CDATA[This post is about the shareNice social sharing widget I have been working on recently. I am pitching shareNice as a &#8220;uninstrusive social sharing&#8221; tool for webmasters. Webmasters can add shareNice to their websites if they want to let their users&#8217; share the pages they browse with their friend, via the many social networks platforms. [...]]]></description>
			<content:encoded><![CDATA[<p>This post is about the <a href="http://sharenice.org/">shareNice</a> social sharing widget I have been working on recently. I am pitching shareNice as a &#8220;uninstrusive social sharing&#8221; tool for webmasters. </p>
<p>Webmasters can add shareNice to their websites if they want to let their users&#8217; share the pages they browse with their friend, via the many social networks platforms.  </p>
<p>So, what is different about shareNice, and why should you choose to use it? </p>
<ul>
<li>shareNice <a href="http://sharenice.org/website/privacy">respects your users&#8217; privacy</a> .</li>
<li>shareNice is <a href="http://sharenice.org/website/technical">ONLY a social sharing widget</a>.</li>
<li>shareNice is not an analytic tool, we DO NOT log any of your user&#8217;s information.</li>
<li>shareNice does NOT track your users.</li>
<li>shareNice is <a href="https://github.com/mischat/shareNice">free-software and you can choose to host your own copy if you wish</a>.</li>
<li>shareNice is NOT a profit making endeavour.</li>
</ul>
<p>Below is an example screenshot of the shareNice tool being used on <a href="http://data.southampton.ac.uk"> The University of Southampton&#8217;s OpenData site</a>.</p>
<p><a href="http://data.southampton.ac.uk/"><img alt="shareNice example" src="http://mmt.me.uk/blog/wp-content/uploads/2011/07/soton-shareNice.png" title="data.southampton.ac.uk shareNice integration" width="427" height="282" /></a></p>
<p><br/></p>
<p>As it stands, shareNice is being used on the following sites : <a href="http://data.southampton.ac.uk">http://data.southampton.ac.uk</a>,<a href="http://www.garlik.com"> http://www.garlik.com</a>, <a href="http://mmt.me.uk/">http://mmt.me.uk/</a>, and the<a href="http://sharenice.org/"> http://sharenice.org/</a> itself. And yes most of these sites are friendlies, but I would love to other people to start making use of the site too! </p>
<p>We are currently working on a <a href="http://wordpress.org/">WordPress</a> plugin for the shareNice widget, and an <a href="http://eprints.org/">eprints</a> plugin too. I would love if someone would like to create a <a href="http://drupal.org">Drupal</a> plugin for shareNice, that would be great!. You can see a list of feature requests on : <a href="http://sharenice.org/">http://sharenice.org/</a>.</p>
<p>Given that the apache instance which this runs off of doesn&#8217;t generate ANY logs, I have no way of know if people are using the service, so please do let me know. Either via my blog, twitter, or github. </p>
<p>Finally, I should name dropped all the nice people which have helped in the development of shareNice: Monika Stepinska, Steve Harris, and Sebastien Francois. You guys rule! </p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2011/07/19/sharenice/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Knocking up my own RSS reader</title>
		<link>http://mmt.me.uk/blog/2010/12/13/rss-reader/</link>
		<comments>http://mmt.me.uk/blog/2010/12/13/rss-reader/#comments</comments>
		<pubDate>Sun, 12 Dec 2010 23:05:14 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[rss]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=455</guid>
		<description><![CDATA[Since Newsgators RSS Reader asked me to supply them with a Google Account, becoming Google Reader, I gave up on the service. I using an RSS reader which would sync my laptop with my phone and when my phone became capable of reading interwebs when traveling about. In short RSS is awesome, and Google Search [...]]]></description>
			<content:encoded><![CDATA[<p>Since <a href="http://www.newsgator.com/rss-readers.aspx">Newsgators RSS Reader</a> asked me to supply them with a Google Account, becoming <a href="http://www.google.com/reader">Google Reader</a>, I gave up on the service. I using an RSS reader which would sync my laptop with my phone and when my phone became capable of reading interwebs when traveling about. In short RSS is awesome, and Google Search is awesome, but I try and spread my personal data thin across many companies instead of giving it all away to one. I used the <a href="http://www.google.com/ig">iGoogle</a> page for a while, but I thought I could just emulate that on my website, so I did &#8230;</p>
<p>In short: </p>
<p><a href="http://www.google.com/">Google</a> offer a great search experience, they can have my search history, <a href="http://www.facebook.com/">Facebook</a> offer a good way to stay in touch with your friends, <a href="http://www.flickr.com/">Yahoo/Flickr</a> provide a good photo sharing experience, and well <a href="http://www.last.fm/">Last.fm</a> do an awesome job of recommending me music &#8211; get what I am hinting at. I could just used Google to do all of the above, but somehow I feel better about myself spreading my data around a bit (sorry crazy doesn&#8217;t it!).</p>
<p>So, I made a start at knocking together my own RSS reader which I can use to catch up on stuff : <a href="http://mmt.me.uk/rss/">http://mmt.me.uk/rss/</a>. I used this <a href="http://www.scriptol.com/rss/rss-reader.php">PHP RSS Reader library</a>. Sadly, it doesn&#8217;t understand RSS 1.0 which is RDF, it only seems to parse RSS 2.0. </p>
<p>It was really easy to do not more than an hours work. I am going to start parsing in the descriptions of the items in the RSS feeds, but sadly this isn&#8217;t trivial, people are starting to flood their streams with linked to google-analytics, to facebook share (including links to icons hosted on facebook.com [naughty]), and other nastiness. So I will have to write some code to pull out all the evil in the descriptions before adding them to <a href="http://mmt.me.uk/rss/">http://mmt.me.uk/rss/</a>, I will update my blog when I get round it to it. I can also release code if people want, just shout&#8230;</p>
<p><a href="http://mmt.me.uk/blog/wp-content/uploads/2010/12/Screen-shot-2010-12-12-at-23.03.04.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/12/Screen-shot-2010-12-12-at-23.03.04.png" alt="" title="Simple HTML based RSS Reader" width="95%" class="aligncenter size-full wp-image-458" /></a></p>
<p>On a similar topic, the below blog post, states: </p>
<p><em>&#8220;One privacy protection model is to scatter your data about to make it more difficult to parse, akin to keeping valuables in different hiding spots in your house to thwart intruders getting everything in one go.&#8221;</em></p>
<p>When referring to the use of Facebook, as your one stop shop for IM messages, photos, emails and your social graph. </p>
<p><a href="http://blogs.forbes.com/kashmirhill/2010/11/29/how-facebook-applications-can-download-all-the-messages-in-your-inbox/">http://blogs.forbes.com/kashmirhill/2010/11/29/how-facebook-applications-can-download-all-the-messages-in-your-inbox/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/12/13/rss-reader/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Response to the NHS</title>
		<link>http://mmt.me.uk/blog/2010/11/30/my-response-to-the-nhs/</link>
		<comments>http://mmt.me.uk/blog/2010/11/30/my-response-to-the-nhs/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 12:57:54 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[instrusive]]></category>
		<category><![CDATA[nhs]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[privacypolicy]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=445</guid>
		<description><![CDATA[My letter to the NHS Choices Team dated 2010-11-30 Hi Team NHS Choices, So, I just thought I would let you know that, as per my blog post, the NHS Choices website is sharing information with Facebook on pages which DONT have the Facebook Like button, as pointed out by this person, as well as [...]]]></description>
			<content:encoded><![CDATA[<p><strong>My letter to the NHS Choices Team dated 2010-11-30</strong></p>
<p>Hi Team NHS Choices, </p>
<p>So, I just thought I would let you know that, as per my blog post, the NHS Choices website is sharing information with Facebook on pages which DONT have the Facebook Like button, as pointed out by this person, as well as being on my blog post for the last few days: </p>
<p><a href="http://www.privacylives.com/v3-co-uk-ico-probes-nhs-choices-over-data-privacy-fears/2010/11/30/">http://www.privacylives.com/v3-co-uk-ico-probes-nhs-choices-over-data-privacy-fears/2010/11/30/</a></p>
<p>Note that, NHS Choices keeps stating that its privacy policy is correct, but if you read the last few paragraphs of my blog post, right before the &#8220;comments&#8221; section, you will see that this is not the case.</p>
<p><a href="http://mmt.me.uk/blog/2010/11/21/nhs-and-tracking/">http://mmt.me.uk/blog/2010/11/21/nhs-and-tracking/</a></p>
<p>Do have a look at the following page on your website, there is NO like button, and the same data exchange is STILL happening with Facebook. </p>
<p><a href="http://www.nhs.uk/livewell/depression/pages/depressionhome.aspx">http://www.nhs.uk/livewell/depression/pages/depressionhome.aspx</a></p>
<p>The following screenshot illustrates this. People are free to replicate, all you need is Firefox and the Firebug plugin (both free and open source). </p>
<p><a href="http://mmt.me.uk/blog/wp-content/uploads/2010/11/Screen-shot-2010-11-24-at-17.01.38.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/11/Screen-shot-2010-11-24-at-17.01.38.png" alt="Firebug + Firefox + NHS Website + Facebook.com HTTP request + No Like Button" title="Screen shot 2010-11-24 at 17.01.38" width="90%" class="aligncenter size-full wp-image-441" /></a></p>
<p>I also talked about how there is a German website which changed the manner in which it implemented the Like button functionality in a non-intrusive manner. That is, a manner which does NOT send any information to Facebook.com unless the user ACTIVELY CLICKS (i.e. OPT-IN) the Like button; quoting my blog post.</p>
<p>&#8220;There is a way to deploy the Facebook Like button which would resemble an OPT-IN based user interaction, instead of the intrusive standard iframe based approach. This involves the use of an “onClick” function call in Javascript which would tell Facebook only when explicitly “liked”. Obviously this method of interaction does not display the “social information” such as like counts, and whether or not you would be the first of your friends to “like” a given page. The German social networking site jetzt.de moved from the iframe to the self-hosted version after vigorous backlash from the userbase about being tracked (see for instance <a href="http://jetzt.sueddeutsche.de/texte/anzeigen/385237">http://jetzt.sueddeutsche.de/texte/anzeigen/385237</a>, line 350). This example was given to me by Sören Preibusch from the University of Cambridge.&#8221;</p>
<p>Please see the Garlik blog for more information :  <a href="http://www.garlik.com/blog/?p=419">http://www.garlik.com/blog/?p=419</a> </p>
<p>Warmest Regards, </p>
<p>Mischa</p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/11/30/my-response-to-the-nhs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NHS.uk allowing Google, Facebook, and others to track you</title>
		<link>http://mmt.me.uk/blog/2010/11/21/nhs-and-tracking/</link>
		<comments>http://mmt.me.uk/blog/2010/11/21/nhs-and-tracking/#comments</comments>
		<pubDate>Sun, 21 Nov 2010 19:13:32 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[advertising]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[tracking]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=369</guid>
		<description><![CDATA[The NHS is allowing Google, Facebook, and others to track your http://www.nhs.uk/ browsing habits, regardless of the fact that people use the page to seek medical advice. It was recently pointed out to me that the NHS Choices website&#8217;s social features include the Facebook Like button (see e.g. the page on Testicular Cancer). Due to [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.nhs.uk/">NHS</a> is allowing <a href="http://www.google.com/">Google</a>, <a href="http://www.facebook.com/">Facebook</a>, and others to track your <a href="http://www.nhs.uk/">http://www.nhs.uk/</a> browsing habits, regardless of the fact that people use the page to seek medical advice. It was recently pointed out to me that the <a href="http://www.nhs.uk/Pages/HomePage.aspx">NHS Choices website&#8217;s</a> social features include the Facebook Like button (see e.g. the <a href="http://www.nhs.uk/Conditions/Cancer-of-the-testicle/Pages/Introduction.aspx">page on Testicular Cancer</a>). Due to the <a href="http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/">fact that the standard method of Facebook Like button deployment is intrusive to say the least</a>, I thought I would look into identifying which third party companies have been given permission to track users on NHS Choices, and my results are rather disconcerting.</p>
<p>In short there are four third-party, advertising/tracking companies which are informed every time a user visits one of the &#8220;conditions pages&#8221; on the NHS Choices website.  These listed below, all get to make a call from the user&#8217;s browser, in turn allowing the four companies to access their cookies, tracking the users (explained in<a href="http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/"> a previous blog post of mine,</a> and in <a href="http://www2.research.att.com/~bala/papers/">Bala&#8217;s research</a>). This means, that if one has ever logged into a Google account, or a Facebook account and then visits one of the pages on the NHS site, the company will then know that their user X was just looking at a page about condition Y on the NHS website. </p>
<p>These are the four third party companies that make requests every time a &#8220;conditions page&#8221; on <a href="http://www.nhs.uk/">http://www.nhs.uk/</a> is viewed by a user:</p>
<p><code>jambi:~ mt $ grep "Host" tcpdump.ext.20101121.log | sort -u<br />
Host: l.addthiscdn.com<br />
Host: statse.webtrendslive.com<br />
Host: www.facebook.com<br />
Host: www.google-analytics.com</code></p>
<p>Two of the four third-party sites (<a href="http://www.facebook.com">facebook.com</a> and <a href="http://addthiscdn.com">addthiscdn.com</a>) are contacted in order to provider the &#8220;social functionality&#8221; shown in the following screenshot. This intrusive OPT-OUT method of adding social features to the NHS website, in my opinion is NOT acceptable. I would only deem this to be acceptable if NHS has written declarations from the two aforementioned services stating that they WOULDN&#8217;T be tracking peoples&#8217; browsing habits on <a href="http://www.nhs.uk/">http://www.nhs.uk/</a>. </p>
<p><a href="http://mmt.me.uk/blog/wp-content/uploads/2010/11/nhschoices2010-11-21T17.28.24.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/11/nhschoices2010-11-21T17.28.24.png" alt="" title="NHS Choices &quot;Social Features&quot;" width="90%" class="aligncenter size-full wp-image-411" /></a></p>
<p>And the other two sites contacted (<a href="http://webtrendslive.com">webtrendslive.com</a> and <a href="http://www.google-analytics.com">google-analytics.com</a>) seemed to be used for analytics purposes. In my view, this task should NOT be outsourced to a third party. If this was a website about pub reviews these third-party services would be acceptable, but due to the nature of the information on the Choices website, I feel the NHS should be hosting their own analytics code. Ok, I understand that the NHS needs to gather statistics about their website usage, but <strong>their user&#8217;s privacy should be of utmost importance</strong>, there do exist a high number of open sourced analytics software which the NHS should run themselves.</p>
<p>In order to show that I am not making this up, I have captured all of the HTTP requests made by my browser when loading the HIV and AIDS information page on NHS Choices.  </p>
<p><a href="http://www.nhs.uk/conditions/HIV/Pages/Introduction.aspx">http://www.nhs.uk/conditions/HIV/Pages/Introduction.aspx</a></p>
<p><a href="http://mmt.me.uk/blog/wp-content/uploads/2010/11/firebugNetNHS.uk_.2010-11-21T13.49.15.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/11/firebugNetNHS.uk_.2010-11-21T13.49.15.png" alt="" title="Firebug Network traffic output HIV/AIDS Information Page on the NHS" width="90%" class="aligncenter size-full wp-image-371" /></a></p>
<p>The below two files are logs of all HTTP requests made when loading the HIV page:</p>
<p><a href="http://mmt.me.uk/misc/nhscookies/tcpdump.full.20101121.log">http://mmt.me.uk/misc/nhscookies/tcpdump.full.20101121.log</a></p>
<p>And this cut down log file shows all of the third-party HTTP requests made by one&#8217;s browser when loading the aforementioned page: </p>
<p><a href="http://mmt.me.uk/misc/nhscookies/tcpdump.ext.20101121.log">http://mmt.me.uk/misc/nhscookies/tcpdump.ext.20101121.log</a></p>
<p>The above logs where captured using the following bash command:<br />
<code>tcpdump -A -s 1024 -i en0 dst port 80</code></p>
<p><strong>An example: </strong></p>
<p>My colleague <a href="http://steve.harris.name/">Steve</a> captured output from the HTTP trace via the NHS website, it can be found on <a href="http://pastebin.com/4TfDRRZJ">http://pastebin.com/4TfDRRZJ</a></p>
<p>The browser (Safari) had it&#8217;s history cleared, logged into facebook, the facebook window closed, then sent to the NHS page. </p>
<p>Bits of confidential data replaced with XXXs</p>
<p><code>GET /plugins/like.php?href=http%3A%2F%2Fwww.nhs.uk%2fConditions%2fHIV%2fPages%2fIntroduction.aspx&#038;layout=button_count&#038;show_faces=true&#038;width=450&#038;action=like&#038;colorscheme=light&#038;height=21 HTTP/1.1<br />
Host: www.facebook.com<br />
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_4; en-gb) AppleWebKit/533.18.1 (KHTML, like Gecko) Version/5.0.2 Safari/533.18.5<br />
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5<br />
Referer: http://www.nhs.uk/conditions/HIV/Pages/Introduction.aspx<br />
Accept-Language: en-gb<br />
Accept-Encoding: gzip, deflate<br />
Cookie: presence=DJ290173073BchADhA_22112.channelH1L60XXXXXXXXXXXXXXXXX4104WMblcMsndPBXXXXXXXXXXXsbPBtA_5b_5dBfAnullBuctMsA0QBblADacP0VXXXXXXXXXXXX0K290173073QQQ; x-referer=http%3A%2F%2Fwww.facebook.com%2Fhome.php%23%2Fhome.php; xs=976XXXXXXXXXXXXXXXXXXX0e11a0e600; sid=2; sct=12XXXXXX70; made_write_conn=12XXXXXX70; lu=ghXXXXXXXXXXXXXXXXXXYgqQ; datr=12XXXXXXXX-XXXXXXXXXXXf24</code></p>
<p><strong>Possible Data Protection Violation</strong></p>
<p><em>It was pointed out to me that I was reference the incorrect ICO filing. The data controller for the NHS Choices website is the Department of Health and not NHS Direct. </p>
<p>Find below, my amended version of this and the following section of this blog post. &#8211; <strong>Mischa 2010-11-24 11:00:00</strong>.</em></p>
<p>In order to see the NHS&#8217;s Data Protection Policy, we had a look at their <a href="http://www.ico.gov.uk/">ICO</a> filing, which led me to the following page:</p>
<p><del datetime="2010-11-24T10:12:42+00:00"><a href="http://www.ico.gov.uk/ESDWebPages/DoSearch.asp?reg=4693360">http://www.ico.gov.uk/ESDWebPages/DoSearch.asp?reg=4693360</a></del><br />
<a href="http://www.ico.gov.uk/ESDWebPages/DoSearch.asp?reg=4906007">http://www.ico.gov.uk/ESDWebPages/DoSearch.asp?reg=4906007</a></p>
<p>I should start this section by saying that I am not a lawyer. But it seems like <del datetime="2010-11-24T10:12:42+00:00">sections 6 and 4</del> <strong>purpose 2</strong> <del datetime="2010-11-24T10:12:42+00:00">are</del> <strong>is</strong> relevant to my question of &#8220;how come the NHS website has third-party tracking enabled, especially given that the tracking is provided by for profit advertising companies?&#8221;. Firstly, it should be noted that by contacting facebook and google, data is being sent outside of the European Economic Area. Which is in violation of their Data Protection commitment of &#8220;Transfers: None outside the European Economic Area&#8221;.</p>
<p><del datetime="2010-11-24T10:12:42+00:00">And as per the ICO filing the potential recipients are: Business associates and other professional advisers, Central Government, Data subjects themselves, Employees and agents of the data controller, Healthcare, social and welfare advisers or practitioners, Local Government, Ombudsmen and regulatory authorities, Other companies in the same group as the data controller, Persons making an enquiry or complaint, Police forces, Relatives, guardians or other persons associated the data subject, Survey and research organisations.</p>
<p>I will like to point out that no where in the ICO filing can one see that the NHS will be sharing data with advertising companies.</del></p>
<p>It should be noted that the <a href="http://www.ico.gov.uk/ESDWebPages/DoSearch.asp?reg=4906007">ICO filing</a> does not make it explicit that the Department of Health would not:</p>
<ul>
<li>Sell advertising to patients </li>
<li>Sell/Provide user data for third party advertising</li>
</ul>
<p><strong>Next Steps: FOI </strong></p>
<p>I am about to post off a Freedom Of Information request (tomorrow morning), asking the NHS to please supply the minutes of all policy and technical meetings involved in the decision to deploy iframes referencing non-NHS sites and to use third-party analytics software on NHS choices pages. </p>
<p><strong>Next Steps: Official Complaint </strong></p>
<p>Further to the FOI request I am going to submit an official complaint via the official NHS Choices feedback form :<a href="http://www.nhs.uk/aboutNHSChoices/Pages/ContactUs.aspx">http://www.nhs.uk/aboutNHSChoices/Pages/ContactUs.aspx</a>.</p>
<p>I have the latest copy of the <del datetime="2010-11-24T10:12:42+00:00"><a href="http://mmt.me.uk/misc/nhscookies/FOIRequest.pdf">FOI Request</a></del> <a href="http://mmt.me.uk/misc/nhscookies/FOIRequest.pdf">updated FOI Request</a> and the<a href="http://mmt.me.uk/misc/nhscookies/LetterOfComplaint.pdf"> Letter of Complaint</a> up in .pdf format on <a href="http://mmt.me.uk/">my website</a>.</p>
<p><strong>Note that: </strong></p>
<p>There is a way to deploy the Facebook Like button which would resemble an OPT-IN based user interaction, instead of the intrusive standard iframe based approach. This involves the use of an &#8220;onClick&#8221; function call in Javascript which would tell Facebook only when explicitly &#8220;liked&#8221;. Obviously this method of interaction does not display the &#8220;social information&#8221; such as like counts, and whether or not you would be the first of your friends to &#8220;like&#8221; a given page. The German social networking site <a href="http://jetzt.de/">jetzt.de</a> moved from the iframe to the self-hosted version after vigorous backlash from the userbase about being tracked (see for instance <a href="http://jetzt.sueddeutsche.de/texte/anzeigen/385237">http://jetzt.sueddeutsche.de/texte/anzeigen/385237</a>, line 350). This example was given to me by Sören Preibusch from the University of Cambridge.</p>
<p><strong>And Finally&#8230;</strong></p>
<p>I would like to thank <a href="http://steve.harris.name/">Steve Harris</a> and <a href="http://danbri.org/">Dan Brickley</a> for helping me decide how to take this forward. And I would like to thank <a href="http://twitter.com/rich13">Richard Northover</a> for the link.</p>
<p><strong>Amendment 2010-11-24 16:57 Conflict in terms of NHS privacy policy</strong><br />
It has been pointed out to me that in relation to the NHS stating that how only on pages with the Like button&#8230;. communications with Facebook.com occurs, this is also not true : </p>
<p>See the following page : </p>
<p><a href="http://www.nhs.uk/livewell/depression/pages/depressionhome.aspx">http://www.nhs.uk/livewell/depression/pages/depressionhome.aspx</a></p>
<p>I see no &#8220;Like&#8221; button on this page. But according to firebug, There is still an HTTP request made to facebook.com from my browser. </p>
<p>The following quote from the <a href="http://www.nhs.uk/aboutNHSChoices/aboutnhschoices/termsandconditions/Pages/Privacypolicy.aspx">NHS Choices privacy policy</a> states : </p>
<p><em>&#8220;While we only share your information with the Data Processors, when you visit pages on our site that display a Facebook Like button, Facebook will collect information about your visit. For more information, read the relevant section of the Facebook privacy policy.&#8221;</em></p>
<p>Which is NOT true. </p>
<p>The following screenshot illustrates this. People are free to replicate, all you need is Firefox and the Firebug plugin (both free and open source). </p>
<p><a href="http://mmt.me.uk/blog/wp-content/uploads/2010/11/Screen-shot-2010-11-24-at-17.01.38.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/11/Screen-shot-2010-11-24-at-17.01.38.png" alt="Firebug + Firefox + NHS Website + Facebook.com HTTP request + No Like Button" title="Screen shot 2010-11-24 at 17.01.38" width="90%" class="aligncenter size-full wp-image-441" /></a></p>
<p><strong>NHS privacy policy</strong></p>
<p>I thought I would cut and paste the NHS&#8217;s privacy policy, in case it changes dated 2010-11-25 15:58:00 GMT</p>
<p><em>&#8220;As a government department, we do not share data with other organisations unless the law permits us to do so. We do not sell individual information. We will share it only with our authorised Data Processors, who must act at all times on our instructions as the Data Controller under the Data Protection Act 1998. Before you submit any information, we will notify you as to why we are asking for specific information and it is up to you whether you provide it.</p>
<p>While we only share your information with the Data Processors, when you visit pages on our site that display a Facebook Like button, Facebook will collect information about your visit. For more information, read the relevant section of the Facebook privacy policy.&#8221;</em></p>
<p><strong>Furthermore</strong></p>
<p>It should be noted that it has been pointed out to me that <a href="http://www.addthis.com/privacy">AddThis&#8217; privacy policy</a> reveals they monetise their product through behavourial targeting. Would you be somewhat surprised if you started to received adverts about their ailments on third-party websites.?</p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/11/21/nhs-and-tracking/feed/</wfw:commentRss>
		<slash:comments>57</slash:comments>
		</item>
		<item>
		<title>Disabling Referer Headers in Firefox</title>
		<link>http://mmt.me.uk/blog/2010/11/21/disabling-referer-headers-in-firefox/</link>
		<comments>http://mmt.me.uk/blog/2010/11/21/disabling-referer-headers-in-firefox/#comments</comments>
		<pubDate>Sun, 21 Nov 2010 16:25:22 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[header]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[referer]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=392</guid>
		<description><![CDATA[Given the awesome work detailed by Bala from AT&#038;T, and some recent privacy related measures I have been taking in my Firefox browser (see https-everywhere and adblocking fb), I have decided to instruct my browser to stop sending the Referrer Header (nb: incorrectly referred to as the &#8216;referer header&#8217;), when I am clicking around on [...]]]></description>
			<content:encoded><![CDATA[<p>Given the<a href="http://www2.research.att.com/~bala/papers/"> awesome work detailed by Bala from AT&#038;T</a>, and some recent privacy related measures I have been taking in my <a href="http://mozilla.org/firefox">Firefox browser</a> (see<a href="http://mmt.me.uk/blog/2010/10/26/https/"> https-everywhere</a> and <a href="http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/">adblocking fb</a>), I have decided to instruct my browser to stop sending the <a href="http://en.wikipedia.org/wiki/HTTP_referrer">Referrer Header</a>  (nb: incorrectly referred to as the &#8216;referer header&#8217;), when I am clicking around on the web. </p>
<p>The following example shows the Referrer header of the HTTP request telling <a href="http://www.facebook.com/">facebook.com</a>, that I have just been looking at a page about <a href="http://www.nhs.uk/conditions/HIV/Pages/Introduction.aspx">HIV on the NHS choices website</a>. </p>
<p><code>GET /<br />
Host: www.facebook.com<br />
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_4; en-gb) AppleWebKit/533.18.1 (KHTML, like Gecko) Version/5.0.2 Safari/533.18.5<br />
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5</code><br />
<strong>Referer: http://www.nhs.uk/conditions/HIV/Pages/Introduction.aspx</strong><br />
<code>Accept-Language: en-gb<br />
Accept-Encoding: gzip, deflate<br />
Cookie: presence=DJ290173073BchADhA_22112.channelH1L60X...</code></p>
<p>I followed instructions on the following blog post <a href="http://cafe.elharo.com/privacy/privacy-tip-3-block-referer-headers-in-firefox/">http://cafe.elharo.com/privacy/privacy-tip-3-block-referer-headers-in-firefox/</a> to configure my Firefox instance to not send the &#8220;referer header&#8221;. </p>
<p>In short, the steps needed are as follows: </p>
<ul>
<li>Type <strong>about:config</strong> into your firefox awesome bar, to bring up your settings</li>
<li>find the setting <code>network.http.sendRefererHeader</code>. This is probably set to 2.</li>
<li>Choose one of the following values:
<ul>
<li>0: Completely disables the referer header (mischa&#8217;s setting)</li>
<li>1: Sends a referer header when following a link to another page, but not when loading images on the page</li>
<li>2: Always sends the referer header (default)</li>
</ul>
</li>
</ul>
<p>I am going to experiment with setting it to 0, disabling the referer header all the time, I will post back here to say if it causes me any problems.<br />
<a href="http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/"></p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/11/21/disabling-referer-headers-in-firefox/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>HTTPS: Making more use of SSL</title>
		<link>http://mmt.me.uk/blog/2010/10/26/https/</link>
		<comments>http://mmt.me.uk/blog/2010/10/26/https/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 10:31:16 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=360</guid>
		<description><![CDATA[There has been a lot of talk about how more and more people are using their laptops on public wifi connections, and with the advent of the Firesheep plugin, there has been a number of scares around session hijacking, and unencrypted login details being sent through the ether. As a result, I thought I would [...]]]></description>
			<content:encoded><![CDATA[<p>There has been a lot of talk about how more and more people are using their laptops on public wifi connections, and with the advent of the <a href="http://github.com/codebutler/firesheep/downloads">Firesheep plugin</a>, there has been a number of scares around session hijacking, and <a href="http://blogs.computerworld.com/17228/firesheep_firefox_extension_opens_fire_on_sheep_browsers">unencrypted login details being sent through the ether</a>. </p>
<p>As a result, I thought I would describe the steps I have taken in securing my <a href="https://www.mozilla.com/en-US/">Firefox</a> instance on my laptop. These are : </p>
<ul>
<li>Installing the <a href="https://www.eff.org/https-everywhere">HTTPS Everywhere</a> plugin from the <a href="https://www.eff.org/">eff</a>, which attempts to select https if available when accessing a site. I have tested it with <a href="http://www.facebook.com/">Facebook</a>, <a href="http://www.google.com/">Google</a>, <a href="http://www.hotmail.com/">Hotmail</a>, <a href="http://linkedin.com/">LinkedIn</a> and a few other sites</li>
<li>I have set my homepage to be <a href="https://encrypted.google.com/">encrypted.google.com</a></li>
<li>I have changed the search engine in top right hand of my Firefox instance to use the encrypted google service, by installing <a href="https://addons.mozilla.org/en-US/firefox/addon/161897/">their plugin</a></li>
<li>I have set a master password on my Firefox keychain, which gives my stored passwords some level of protection</li>
<li>And I run Adblocking software, (with a custom Facebook Like Button blocking extension) as per an <a href="http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/">earlier blog post</a></li>
</ul>
<p>Furthmore, I use Firefox as my main browser, I have chrome installed, but I hardly ever use it, and I have a <a href="http://mmt.me.uk/blog/2009/11/15/private-browsing-with-safari/"> locked down, stateless Safari instance</a> which I wrote about earlier.</p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/10/26/https/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Facebook and their Horrible &#8220;OPT-OUT&#8221; Policy</title>
		<link>http://mmt.me.uk/blog/2010/08/20/facebook-opt-out-policy/</link>
		<comments>http://mmt.me.uk/blog/2010/08/20/facebook-opt-out-policy/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 12:24:26 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[evil]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[geolocation]]></category>
		<category><![CDATA[optout]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=237</guid>
		<description><![CDATA[So Facebook announced their new Facebook Places functionality a couple of days ago, the service seems well implemented, and following the uptake of 4square, probably a timely service for fb &#8211; good luck to them. What I am most disappointed about (**rant) is the way that Facebook, seem to think that an &#8220;OPT-OUT&#8221; policy is [...]]]></description>
			<content:encoded><![CDATA[<p>So <a href="http://www.facebook.com/">Facebook</a> announced their new <a href="http://blog.facebook.com/blog.php?post=418175202130">Facebook Places</a> functionality a couple of days ago, the service seems well implemented, and following the uptake of <a href="http://foursquare.com/">4square</a>, probably a timely service for fb &#8211; good luck to them. </p>
<p>What I am most disappointed about (**rant) is the way that Facebook, seem to think that an <strong>&#8220;OPT-OUT&#8221;</strong> policy is the right way to go about landing new functionality on their users. By default, Facebook allows your friends to log your geolocation at given point in time. And this is simply NOT ACCEPTABLE. As far as I am aware (and please do let me know if I am wrong), none of the other popular geo-logging services allow for other people to log your location at a given point in time. I see this as a massive invasion of your privacy, and as have others, as discussed in the following CNET article: </p>
<p><a href="http://news.cnet.com/8301-13577_3-20014168-36.html">Shots already fired over Facebook Places privacy</a></p>
<p>An <strong>OPT-OUT</strong> policy to services which compromise your privacy and your personal information is simply NOT acceptable, and DRACONIAN. I mean, Facebook, DID NOT even attempt to inform me, that friends of mine can can geolog my location at any given point in time. I mean, what is stopping a friend of mine, who is hanging out in a brothel from geologging me, and defaming my character, by suggesting that I too was at the same place as him.</p>
<p>I noticed this yesterday, and then I got round to <a href="https://twitter.com/mischatuffield/status/21583540429">tweeting it</a>, and had a lot of people thanking me for informing them of this change of service. So, I thought I would expand what is going on in a bit more detail. If you would like a more verbose write up on how to disable this new &#8220;feature&#8221;, visit the <a href="http://www.garlik.com/">Garlik</a> blog article: </p>
<p><a href="http://www.garlik.com/blog/?p=328"><br />
Garlik Blog: Disabling Facebook Places</a>.</p>
<p>As far as I am aware there has been no recent changes to <a href="http://www.tosback.org/organization.php?cid=8">Facebook&#8217;s privacy policy or their terms of service</a> as illustrated on the awesome <a href="http://www.tosback.org/">Terms of Service Tracking site</a>.  From my point of view, Facebook should inform their users about new functionality, especially new functionality which by definition shares your geolocation information both with people within Facebook, and with the <a href="http://www.skyhookwireless.com/">Skyhook geolocation gazetteer</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/08/20/facebook-opt-out-policy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Facebook Like Button, and how it is following you around the web</title>
		<link>http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/</link>
		<comments>http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 00:13:32 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[like]]></category>
		<category><![CDATA[likebutton]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=148</guid>
		<description><![CDATA[There has been a lot of hype and talk around the Facebook Like button, and I do understand that the issues I raise in this blog post have been addressed before, I will cite some relevant literature at the bottom of this post. In short, I fear that Facebook via the Facebook Like button which [...]]]></description>
			<content:encoded><![CDATA[<p>There has been a lot of hype and talk around the Facebook Like button, and I do understand that the issues I raise in this blog post have been addressed before, I will cite some relevant literature at the bottom of this post. </p>
<p>In short, I fear that <a href="http://www.facebook.com/">Facebook</a> via the <a href="http://developers.facebook.com/docs/reference/plugins/like">Facebook Like button</a> which you can find on many high volume, mainstream sites, such as <a href="http://www.imdb.com/">imdb</a>, <a href="http://www.rottentomatoes.com/">rottentomatoes</a>, <a href="http://www.cnn.com/">cnn</a>, etc, is tracking you even if you are not logged into Facebook from your browser.</p>
<p>So, I have no solid evidence to say that they are DEFINITELY doing so, but I will explain why it is technically possible for them to do so. And well, the <strong>cynic in me thinks that if it is technically possible for facebook to log that my facebook id is on a given page, it will, regardless of whether or not I am logged in or not</strong>.</p>
<p>From this point onwards, I will be referring to all of various versions of the <strong>Like</strong> button, i.e. Like, Recommend, Fan, etc as the Facebook Like button. </p>
<p>So, the Facebook Like button can be implemented in one of two ways, using facebook&#8217;s <a href="http://wiki.developers.facebook.com/index.php/XFBML">XFBML</a> or via the inclusion of a Facebook <a href="http://en.wikipedia.org/wiki/HTML_element#Frames">iFrame</a>. FWIW, all of the instances of the Like button I have come across have been implemented using the iFrame approach, but I will look into the XFBML method of doing things soon and will blog about it then (he says &#8230;) </p>
<p>So, if you are a facebook user, and you have visited facebook<br />
since the last time you cleared you cookies, you will have a facebook cookie in your browser. It is this cookie which allows facebook to inform you of how many of your friends have liked the page your browser is currently pointing to. An example of functionality can be seen in the below screenshot.</p>
<p> <a href="http://mmt.me.uk/blog/wp-content/uploads/2010/07/max.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/07/max.png" alt="fblike" title="Max and Facebook Like" width="412" height="75" class="alignnone size-full wp-image-190" /></a></p>
<p>I am aware that if you are signed out of facebook you wont see your list of friends which are have already clicked the like button, you will end up seeing something like:</p>
<p> <a href="http://mmt.me.uk/blog/wp-content/uploads/2010/07/max2.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/07/max2.png" alt="not logged in" title="Facebook Like Button sans logged in" width="342" height="65" class="alignnone size-full wp-image-194" /></a></p>
<p>So, given that the Like button is an iFrame, i.e. it is actually hosted on www.facebook.com, it means that facebook can read your facebook.com <a href="http://en.wikipedia.org/wiki/HTTP_cookie">cookies</a>, and they can tell whether you are logged in (to show you which are of your friends have &#8220;liked&#8221; the page before you). And well, technically this implies that they know <em>who you are</em> which enables them to tell whether you are logged in or not. </p>
<p><a href="http://danbri.org/foaf.rdf#danbri">Dan Brickley</a> created a neat drawing of the what a iFrame is actually doing (thanks Dan, and see below). The illustration highlights the fact that a page which seems to be coming from a given web address, if it includes an iFrame, is actually coming from multiple web servers. </p>
<p>This is danbri&#8217;s illustration of what an webpage which includes iFrame&#8217;s is actually doing</p>
<p><a href="http://www.flickr.com/photos/danbri/4722327870"><img src="http://farm2.static.flickr.com/1155/4722327870_793fc37846_d.jpg" alt="Dan Brickley's drawing of an iFrame" /></a><br />
<a href="http://creativecommons.org/licenses/by-nc-sa/2.0/"><img src="http://creativecommons.org/images/public/somerights20.gif" alt="Some Right Reserved" /></a></p>
<p>This makes me class the Facebook Like button in the same category as ad tracking sites, insofar as the fact that if you turn up to a page with a Like iFrame, and you have a facebook cookie, you are <strong>in theory</strong> being tracked, regardless of whether or not you choose to click the Like button or not. </p>
<p>So, why do I class this in with ad trackers, I do this because of the fact that you are being tracked passively, i.e. regardless of whether or not you choose to like something, facebook is <strong>theoretically</strong> logging the fact that you have been to that website.  </p>
<p><strong>So, now to give an example : </strong></p>
<p>Let&#8217;s say that you turn up to<a href="http://www.cnn.com/"> cnn.com</a> can you visit the below article: </p>
<p><a href="http://www.cnn.com/2010/US/07/29/wisconsin.roush.crash/">http://www.cnn.com/2010/US/07/29/wisconsin.roush.crash/</a></p>
<p>The page them subsequently loads up the following iFrame and serves it to you, it renders the Like button on the page, the iframe revolves to a url on facebook.com</p>
<p><a href="http://www.facebook.com/plugins/like.php?action=recommend&#038;api_key=64b385429f05b2492d713f343d05ba02&#038;channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%23%3F%3D%26cb%3Df352b329c1716ae%26origin%3Dhttp%253A%252F%252Fwww.cnn.com%252Ffd00b01dbaa2ca%26relation%3Dparent.parent%26transport%3Dpostmessage&#038;href=http%3A%2F%2Fwww.cnn.com%2F2010%2FUS%2F07%2F29%2Fwisconsin.roush.crash%2Findex.html&#038;layout=standard&#038;locale=en_US&#038;node_type=link&#038;sdk=joey&#038;show_faces=true&#038;width=420">http://www.facebook.com/plugins/like.php?action=recommend&#038;&#8230;</a></p>
<p>By going to the first URL, you are also hitting the second one. Your user-agent, which based on <a href="http://panopticlick.eff.org/">http://panopticlick.eff.org/</a>, is kinda uniquely identifiable, and is therefore in facebook&#8217;s logs. Given that the iFrame (second URL above) is hosted on facebook&#8217;s site, they <strong>CAN</strong> read your facebook cookies, am <strong>NOT</strong> saying that they do as I can&#8217;t prove that in anyway, but my guestimate is that if they are not, they <strong>will be in the future</strong>. </p>
<p>So, I can see three scenarios, which are relevant to this </p>
<ul>
<li>A user is logged into facebook in their browser, and then visits a site in a different tab, not even knowing that the site has a facebook &#8220;like&#8221; button, because you will only become aware of the &#8220;like&#8221; button upon arriving at the page and having it in loaded in your browser, which is too late from my POV. This happened to me last night, and happened to me recently when I went to imdb (sighes).</li>
<li>A user is not logged into facebook, but has facebook cookies in their browser, they go to cnn.com, facebook knows (with a high probability) that a given facebook ID has visited a given site, by virtue of cookies and stuff</li>
<li>User has no facebook cookies, and then facebook will only get the user&#8217;s user-agent in their access logs, which I bet they store (even though once again I have no proof of this.</li>
</ul>
<p><strong>Ok, so solutions: </strong></p>
<p><em>Solution 1 :</em></p>
<p>You can delete all of you facebook related cookies from your main browser (<a href="http://www.mozilla.com/en-US/firefox/personal.html">firefox</a> being browser of choice), and then you can download another browser which you use for facebook&#8217;ing, so that you are no longer given facebook the option to track the pages you read on the web. </p>
<p><em>Solution 2 :</em></p>
<p>Which is the solution I am going for at the moment is that you can install <a href="http://adblockplus.org/">Adblocker Plus</a> and you can block all of the Facebook Like endpoints, using custom filters. </p>
<p>This is an export of my Facebook Like button filters, it is probably far from complete, and I will put it up a service which you can subscribe to in Adblocks Plus, and will update the list of URLs as and when I come by them (will blog post when I am done with this.) </p>
<p><code><br />
[Adblock]<br />
! Checksum: 1+81iD/9dKSZiqqW6WtQxA</p>
<p>http://www.connect.facebook.com/widgets/likebox.php?*</p>
<p>http://static.ak.connect.facebook.com/js/api_lib/v0.4/FeatureLoader.js.php?*</p>
<p>http://www.connect.facebook.com/widgets/like.php?*</p>
<p>http://www.connect.facebook.com/widgets/fan.php?*</p>
<p>http://www.facebook.com/plugins/fan.php?*</p>
<p>http://www.facebook.com/widgets/likebox.php?*</p>
<p>http://www.facebook.com/plugins/likebox.php?*</p>
<p>http://www.facebook.com/plugins/like.php?*</p>
<p>http://www.facebook.com/widgets/fan.php?*</p>
<p>http://www.facebook.com/widgets/like.php?*</p>
<p></code></p>
<p>The following screenshot, shows what my current step looks like in Adblocker plus: </p>
<p><a href="http://mmt.me.uk/blog/wp-content/uploads/2010/07/adblock.png"><img src="http://mmt.me.uk/blog/wp-content/uploads/2010/07/adblock.png" alt="Adblock" title="Adblock Facebook Like buttons"  /></a></p>
<p>My colleague Vaidas Jablonskis (who is awesome),  pointed me to <a href="http://adblockplus.org/">Adbocker Plus</a> which is also totally awesome <img src='http://mmt.me.uk/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Finally, it is worth mentioning that I am not sure whether or not all of these sites which have facebook like buttons are explicit about the fact that their users <strong>CAN</strong> be tracked passively by facebook. Or whether reputable brands like CNN have any form of agreement with Facebook regarding whether or not their users are being track. Are any of these big companies, breaking their terms and conditions ?</p>
<p>I will post an update on step by step instructions regarding how to subscribe to my Adblock filter list of facebook like buttons endpoints soon. </p>
<p>So, I suggest people download and install Adblock and block facebook like buttons, and subsequently install the <a href=" https://addons.mozilla.org/en-US/firefox/addon/162124/">Facebook Like plugin </a>, so that they are no longer being passively tracked by Facebook, and so that they are in control of when they tell Facebook that they like a given web page. </p>
<p>Finally, links to existing literature in this space: </p>
<p><a href="http://techcrunch.com/2010/04/23/like-buttons-evil-facebook-not-open/">http://techcrunch.com/2010/04/23/like-buttons-evil-facebook-not-open/</a></p>
<p><a href="http://philosophicalzombie.net/post/540799211/has-facebook-just-become-the-evil-empire-whats-wrong">http://philosophicalzombie.net/post/540799211/has-facebook-just-become-the-evil-empire-whats-wrong</a></p>
<p>Comment, corrections, or a simple &#8220;you are wrong because &#8230;&#8221; are very welcome <img src='http://mmt.me.uk/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Happy Interneting People </p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2010/07/30/the-facebook-like-button/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Private Browsing with Safari</title>
		<link>http://mmt.me.uk/blog/2009/11/15/private-browsing-with-safari/</link>
		<comments>http://mmt.me.uk/blog/2009/11/15/private-browsing-with-safari/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 20:38:33 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[OSX]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=122</guid>
		<description><![CDATA[I use Firefox as my primary browser, both at home and at work. So I have setup my Safari browser, as my private browser &#8211; that is sans cache, history, cookies or anything of a similar nature. I noticed that the &#8220;Private Browsing&#8221; option in Safari, doesn&#8217;t do that good a job of not leaving [...]]]></description>
			<content:encoded><![CDATA[<p>I use <a href="http://www.mozilla.com/firefox/">Firefox</a> as my primary browser, both at home and at work. So I have setup my Safari browser, as my private browser &#8211; that is sans cache, history, cookies or anything of a similar nature. I noticed that the &#8220;Private Browsing&#8221; option in Safari, doesn&#8217;t do that good a job of not leaving files hanging around in one&#8217;s operating system, furthermore unless your careful, <a href="http://en.wikipedia.org/wiki/Spotlight_%28software%29">Spotlight</a> will eventually end up indexing your browser history, cache, which may be less than ideal. </p>
<p>In order to have a zero cache safari instance on my laptop I have taken the following steps :</p>
<ul>
<li>1: Removed spotlight&#8217;s prying eyes, by excluding the following directories :
<ul>
<li>/Users/&lt;USERDIR&gt;/Library/Caches</li>
<li>/Users/&lt;USERDIR&gt;/Library/Safari</li>
<li>/Library/Caches</li>
</ul>
</li>
<li>2: Setup two cronjobs to constantly delete Safari cache-dir</li>
<p><code>*/10 * * * * find /Users/&lt;USERDIR&gt;/Library/Safari -type f -exec rm {} \; 2&gt;&#038;1 &gt; /dev/null<br />
*/10 * * * * find /Users/&lt;USERDIR&gt;/Library/Caches/Metadata/Safari/ -type f -exec rm {} \; 2&gt;&#038;1 &gt; /dev/null</code>
</ul>
</ul>
<p>And finally, I have created a wrapper .app file which open&#8217;s Safari, and then enables &#8220;Private Browsing&#8221; mode, as I could not find a way to do this through editing the Safari.plist file. I followed the <a href="http://www.macworld.com/article/139714/2009/03/enableprivatebrowsing.html">instructions posted on the MacWorld site</a>, and they go a little something list so: </p>
<ul>
<li>1.  One needs to enable the Enable Access for Assistive Devices option, which can be found in the Universal Access system preference.</li>
<li>2. Open the AppleScript editor, and type in the following commands :
<p><code><br />
tell application "Safari"<br />
&nbsp;&nbsp;	activate<br />
end tell<br />
tell application "System Events"<br />
&nbsp;&nbsp;	tell process "Safari"<br />
&nbsp;&nbsp;&nbsp;	     tell menu bar 1<br />
&nbsp;&nbsp;&nbsp;&nbsp;	         tell menu bar item "Safari"<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;	             tell menu "Safari"<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;	               click menu item "Private Browsing"<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; end tell<br />
&nbsp;&nbsp;&nbsp;&nbsp; end tell<br />
&nbsp;&nbsp;&nbsp; end tell<br />
&nbsp;&nbsp;end tell<br />
end tell<br />
</code></li>
<li>3. Save this shiny new AppleScript as an application (.app file), and I called mine &#8220;PrivateSafari.app&#8221;. </li>
<li>4. I then grabbed the icon file from Safari, and added to the PrivateSafari, and then replace the old shortcut in my Dock, with one to &#8220;PrivateSafari.app&#8221;.</li>
</ul>
<p>It should be noted that I am well aware that the private browsing features in most of the modern web browsers have come under a certain amount of scrutiny recently, below are some links to articles for the interested reader : </p>
<ul>
<li><a href="http://www.bbc.co.uk/news/technology-10891355">Private browsing modes leak data &#8211; BBC News</a></li>
<li><a href="http://arstechnica.com/security/news/2010/08/private-browsing-not-so-private.ars">Private browsing: it&#8217;s not so private &#8211; Ars Technica</a></li>
<li><a href="http://www.itpro.co.uk/625837/private-browsing-not-so-private">Private browsing ‘not so private’  &#8211; IT Pro </a></li>
<li><a href="http://www.theregister.co.uk/2010/08/06/private_browsing_mode_failure/">Private browsing modes in four biggest browsers often fail &#8211; The Reg</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2009/11/15/private-browsing-with-safari/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Privacy, Data Mashups, and Practical Obscurity</title>
		<link>http://mmt.me.uk/blog/2009/08/05/privacy-web-practical-obscurity/</link>
		<comments>http://mmt.me.uk/blog/2009/08/05/privacy-web-practical-obscurity/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 15:09:00 +0000</pubDate>
		<dc:creator>Mischa</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://mmt.me.uk/blog/?p=87</guid>
		<description><![CDATA[I have long been thinking about how the interweb affects the notion of practical obscurity and how one can no longer expect to be forgiven for a crime after they have served their sentence. An example I have used for a while now is the Georgia Sex Offenders mashup http://www.georgia-sex-offenders.com/maps/offenders.php IMHO sites like the above [...]]]></description>
			<content:encoded><![CDATA[<p>I have long been thinking about how the interweb affects the notion of practical obscurity and how one can no longer expect to be forgiven for a crime after they have served their sentence. </p>
<p>An example I have used for a while now is the Georgia Sex Offenders mashup </p>
<p><a href="http://www.georgia-sex-offenders.com/maps/offenders.php">http://www.georgia-sex-offenders.com/maps/offenders.php</a></p>
<p>IMHO sites like the above one will just end up creating ghettos of sex offenders as real-estate agents start to adopt such online resources to help sell properties to future homeowners. Eventually we will see neighbourhoods of sex offenders as no family would ever choose to live next to a rehabilitated offender. The key word in the previous sentence being &#8220;rehabilitated&#8221;, as they have been released by the judicial system into the community as reformed human beings.</p>
<p>Now one can install an iPhone App, which tells the phone own about sex offenders in their local area, GPS/web magic, note that this only works in the US :</p>
<p><a href="http://www.telegraph.co.uk/technology/apple/5918923/iPhone-app-tracks-sex-offenders.html">http://www.telegraph.co.uk/technology/apple/5918923/iPhone-app-tracks-sex-offenders.html</a></p>
<p>I believe that practical obscurity is a dying concept.<strong> At this point in the post I should stress that I DON&#8217;T classify sex offences are petty crimes</strong>, but I believe that the advent of such data on the web will set a president for other forms of crimes to be being posted to the public domain. I can easily imagine a future where all crimes committed in some US state X are posted to the web.</p>
<p>For example, high-school student Bob gets arrested for shop-lifting and gets a minor punishment that could be community service or something of a similar vain. Alice a classmate of Bob&#8217;s finds this so funny that she posts it to whatever cool social network she is currently a member of, pushing it into the public domain. Now after Bob has served his sentence in pre-interweb days this information would have been practically obscure, it would have been logged in a filing cabinet in some local magistrate court, and unless you had the impetus to seek out this information you would probably never have found out about it. Alice would have been able to communicate the &#8220;funny story&#8221; to her social network, but those conversation&#8217;s would not have been in the public domain. And now they would be.</p>
<p>Well that is all from me, would love to know if people in the US have installed this APP, and wonder how many linch mobs are going to run around US cities taking following their trusty iPhone and taking the law into their own hands. Here is a link to an article which<a href="http://www.wsws.org/articles/2000/aug2000/brit-a12.shtml"> describes some of the vigilantism which occured in the UK after the tabloid new paper &#8220;The News of the World&#8221; published a list of sex offenders in the year 2000</a>. Do excuse the fact that I am pointing to a document on the &#8220;world socialist web site&#8221;, but it seems to report the story well <img src='http://mmt.me.uk/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </p>
<p>Furthermore,<a href="http://eprints.ecs.soton.ac.uk/17123/"> Kieron O&#8217;Hara, Nigel Shadbolt and I wrote a paper</a> touching on this a while back, it can be downloaded from ECS eprints. </p>
]]></content:encoded>
			<wfw:commentRss>http://mmt.me.uk/blog/2009/08/05/privacy-web-practical-obscurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

