Sunday, February 9, 2014

Boredat Privacy and Protection

Regarding information that Boredat has on file


Types of information that I have readily available:
  • I can tie anonymous posts with the ones posted using a screen name.
  • I can usually connect posts from one user across multiple accounts, though this is case-by-case.
  • I can usually identify with a "pretty good" degree of confidence that someone is posting from campus. It has to be taken with a grain of salt as it's not always correct and the failure rate is unknown.
  • I can tell the age of an account, how often the user posts, how active the user is on the site, and other sorts of behavioral information, but this takes some investigative work on my part and not something I do regularly. I usually look at this type of information when I’m making a decision on whether to ban someone. For instance, an account created recently that is doing nothing but attempting to harm the community is obvious when looking at the data and an easy decision.
This is all anecdotal information. It might be useful in an investigation, though it is no guarantee to absolutely identify someone on its own. For all intents and purposes, you are all anonymous to Boredat and would be anonymous to anyone looking at the raw data that is stored in the database. It was designed this way intentionally.

I do look at this data though when necessary. Over the years, some of the behaviors I’ve discovered can sometimes be baffling, but if you can think of it, it has probably been done. I have seen cases where some users will post their own name or harass themselves and then turn around and complain about their name being posted. I have also seen student organizations post the same kind of content that they themselves protest. I have seen users have long, long winded conversations with themselves that can appear like multiple people are participating (it can be pretty convincing!). However, in all cases when looking at this behavior, if a user is causing harm to the community, I take action.

Types of information that *I* do not have available:
  • Given a specific post or account, I cannot provide the person's email address.
I cannot look at a post or account and tie it to a specific email address used in the creation of that account. In other words, I cannot go from the unique identifier issued at the time of the account creation to the email address that was used to create it. There are also no records of emails sent or received by the system that authenticates users. This is simply the policy that I have decided to uphold as part of running the service.

I should emphasize that *I* do not have this information, but since Snowden began releasing information, a closer look at how the internet works fundamentally and how SMTP outbound messages are sent makes me pretty sure that the trace of those emails (and their contents) can be easily stored by an internet service provider (or university network) and certainly is being stored by the NSA (presumably, indefinitely). The metadata information about those emails or their contents could be used to identify the user’s posts if matched up with the data in the Boredat server.

Types of information that are not readily available to me, but I could acquire in extreme circumstances if compelled with a court order:
  • The contents of private messages between accounts or screen names. 
For all intents and purposes, you can be sure your private messages are private. They never leave the server or traverse the public web so they are protected from snooping eyes of any 3rd party. I cannot see these messages easily nor do I want to. From my perspective, it's none of my business. They are stored in an encrypted, unreadable fashion, so looking at the raw data doesn’t glean anything. However, if it was absolutely necessary they could be decrypted.
  • IP address information. 
IP addresses would be very difficult for me to acquire, since they are not actively stored (there are no records of IP addresses in the database or server logs). I choose not to actively store this information to protect identities in the event of a raw data leak. However, it is technically possible by using different techniques. The type of technique used to acquire the information would be selected on a case-by-case basis. For instance, I could set up a sting to collect the information the next time the user logs in. If the user never logs in again, it might be possible to reverse-engineer parts of the Boredat system. Any kind of reverse-engineering would be computationally expensive and I would only try if I was issued a court order and no other techniques were possible.


Regarding information that an administration or law enforcement could acquire if they felt it were necessary


For all intents and purposes, you should assume that law enforcement agencies can collect pretty much ANYTHING, period. I cannot stress that enough. They can discover identities if they were determined to do it, with or without the help of information stored in Boredat servers. These facts are now known given Snowden's revelations. Here are some hypothetical scenarios (I am not suggesting, nor do I have any proof, that any one of these scenarios has been used):
  • If you are using a university email system, it is trivial to store records of all incoming and outgoing emails regardless of who’s sending them. From outside the university network, all information about inbound and outgoing emails (sender, recipient, contents) can be read in plain text when they are traversing the web. SMTP email is fundamentally unencrypted unless deliberately encrypted. It is now known that the NSA is making a copy and storing all emails (or at least as many as they can get their hands on).
  • As an internet service provider (Comcast, ATT, Verizon, any cell phone service provider)... ALL records of what sites you’ve accessed and what pages you view are almost certainly stored. It would be possible for a university network to do the same if configured proerply. Sadly, major commercial internet service providers sell this information to lord knows how many 3rd parties. Your “digital footprint” is unfathomably huge and more people, government and commercial organizations already have access to this information than you’d like to believe.
  • Secured SSL connections (like the connections made to Boredat) CAN be intercepted by an Internet Service Provider that is determined to do so. There are different techniques and specialized equipment you can buy to do this. It is most often called a man-in-the-middle attack. The contents of your browsing activity (i.e. the posts you make on Boredat) could theoretically be encrypted, decrypted to be read and stored, and re-encrypted before it leaves the network without the user or the server having any knowledge of this. This means any site you connect to (i.e. Facebook, your bank account, anything) could be intercepted and read in plain text if one of a growing list of techniques is deployed.

*   *   *

What Boredat protects you from:

It is pretty simple. Boredat anonymizes you from your peers and from the Boredat system itself. It was built with the intention of obfuscating traces of personally identifiable information as much as possible. Boredat protects you from a potential information leak. If you look at the raw data in the database, it would be very difficult to make positive IDs of the people who posted them. If I hired an intern and gave them access to the server, your identities would still be protected.

What Boredat DOES NOT protect you from:

This is also simple. Boredat does NOT protect you from breaking the law. (i.e. sexually harassing someone, cyberbullying, drug related activities, etc). Given the information that I’ve described here, please understand that if a law enforcement agency is determined to identify someone, they will catch them. There are hundreds of ways to investigate activity online and they know how to use them. They have very smart people on the job. Some techniques are easy and some are difficult. Local, state and federal authorities all have different tools with different degrees of investigative capabilities at their disposal, but they work together when it’s necessary.

So what does all this mean?

This is the simplest of all. Don’t be an idiot on the Internet, period. Not on Boredat, not on any site. Don’t give law enforcement a reason to track you down. Don't draw unnecessary attention to yourself. You should acknowledge that nothing on the internet (or at least the one we have today) is truly anonymous without fail. Just read about how the FBI took down the Silk Road. Read about how services like Tor, which is presumably the most sophisticated, industry standard anonymous system to-date, can still be taken down with good old fashioned detective work.

Understand that the intention of this service, from the very beginning, was to create a means of communication that might otherwise not exist. The intention was to create a place where truly honest discourse could occur. It was not built for people to harm each other. It was not built for people to conduct illegal activities. In the 7 years of Boredat existence, this has never been encouraged or accepted. The site has even been taking offline completely if it wasn't reasonably under control.

With all that said, please recognize that I am doing everything that I possibly can with the limited resources that I have to make Boredat a safe place for everyone. As an immediate countermeasure to recent events, I have adjusted the moderator policy to require only 3 votes to have something removed rather than 5. I am also making plans to implement new capabilities in the coming weeks to help curb the small handful of users who intentionally harm the community.

As always, should you ever find that a post needs to be removed more quickly than the moderator system alone, please email me the post in question directly at jaedaemon(at)gmail.com and it will be dealt with as soon as possible.


Jae

1 comment:

  1. I feel like you should make people read this before they even create new accounts. It's all pretty common sense to me, and you've even said a lot of it before, but people get all crazy whenever something like the recent case happens.

    <3

    ReplyDelete