News: 1700119515

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Rights warriors claim online ad auction data is a danger to national security

(2023/11/16)


Online ad auctions represent a threat to national security in the US and Europe, a civil rights group claims, because the data that enables personalized advertising could be used to compromise civilian and military leaders.

The Irish Council for Civil Liberties (ICCL), a Dublin-based advocacy organization, issued two reports this week exploring the purported privacy risks posed by [1]real-time bidding (RTB).

For those who don't know... If you visit a website or use an app that gets its money from RTB-based programmatic advertising, when it's time to show you an ad, an automated auction process happens in a fraction of a second. Simply put, in that auction the site or app auctions off its ad space to a whole load of potential advertisers, and the advertiser that submits the highest bid in that moment wins; their advert is delivered and hopefully seen; and the publisher or developer gets some cash.

Advertisers are willing to bid more if they know that you, the user, are deemed valuable – if all the online tracking of your activities indicates your interests lie in, say, enterprise IT or wealth investment, advertisers will pay a lot to reach you. That's how you get targeted advertising, and that's why your personal information, collected through cookies and other means, gets [2]traded and shared in the ad-tech world, so that advertisers are sure who they are spending ads on. Adverts can be targeted through other means, such as by the content of the pages or publication you're reading.

The two ICCL reports – " [3]Europe’s hidden security crisis " and " [4]America’s hidden security crisis " – claim the data collected to target ads on the web and in apps puts political leaders, military personnel, and others at risk of blackmail, cyberattacks, and abuse while generally weakening organizational security.

"The RTB industry's data free-for-all has created a serious national threat," alleged Johnny Ryan, a senior fellow of ICCL, in [5]a statement . "We call on the US Federal Trade Commission, European data protection authorities, and the European Commission to urgently act. The industry can not be allowed to put our elected leaders and military personnel at risk."

The US-focused report, for one, warns RTB “can enable foreign states and non-state actors to target specific leaders and personnel in the United States, and mine RTB for information about their financial circumstances, mental state, and compromising intimate secrets," adding: "This exposes America's most sensitive institutions and industries to hacking, blackmail, and compromise."

[6]

It seems the argument goes that all the heaps of data out there can be analyzed to reveal specific targets' sensitive habits, opening them up to extortion and the like. We can also imagine someone using micro-targeting to throw suggestive, manipulative, or malware-laden adverts at particular individuals, or compromising the apps and sites a target frequents to gain more intelligence or infect their devices with spyware. The sky's the limit, potentially.

[7]

[8]

Both ICCL reports cite a group of conservative Catholics acquiring app data [9]to reveal a priest's use of a gay dating app, for instance.

Other researchers have reached similar conclusions: last week The Register [10]reported Duke University researchers found information about active military personnel could be bought from US data brokers for as little as $0.12 per record.

[11]

Google has challenged the reports for making inaccurate claims about its business – although Kent Walker, Google's chief of global affairs, last year also [12]called for action , in the form of a US federal data privacy law.

[13]Meta's fix for teen online mental health? Hold Apple and Google responsible

[14]Google, Amazon, Microsoft make the Mozilla naughty list for Christmas shopping

[15]YouTubers kindly asked to mark their deepfake vids as Fake Fakey McFake Fakes

[16]Google Chrome coders really, truly, absolutely ready to cull third-party cookies from 2024

The reports also cite behavioral audience segments available to ad buyers from platforms like Microsoft Xander, Nielsen, Epsilon, LiveRamp, comScore, Oracle, and others. These include whether a person suffers from depression, or other conditions like chronic pain, substance abuse, or anxiety disorders.

Advertisers – or more troublingly, foreign intelligence agents – can also target gamblers, income level, debt, ideology, and religion, among audience segments.

The Internet Advertising Bureau (IAB), an industry trade group, gets called out for maintaining sensitive data categories as part of its technical standard for RTB. "The 'IAB Context Taxonomy' is an RTB industry standard that categorizes what target individuals are watching, reading, or listening to," the report on Europe observes. "The code IAB-122 marks a person's interest as 'defense industry.'"

And the US-centric report alleges, "Google and other RTB firms send RTB data about people in the US to Russia and China, where national laws enable security agencies to access the data."

We have the strictest restrictions in the industry on the types of data we share in real-time bidding

Google insists that it stopped providing data to Russia in 2022 and that its policies forbid abuse. "To protect people's privacy, we have the strictest restrictions in the industry on the types of data we share in real-time bidding," a spokesperson told The Register . "This report makes misleading and inaccurate claims about Google. Our real-time bidding policies simply don't allow bad actors to compromise people's privacy and security."

Google maintains that it does not share Personally Identifiable Information bid requests, and that no Google Account information is ever shared with RTB buyers. The Chocolate Factory further argues that it follows the law in Europe to obtain consent for personalized advertising and that it does not allow advertisers to build or use profiles based on sensitive information.

[17]

The existence of policies against abusing RTB data doesn't necessarily preclude data buyers from flouting those rules, however. The ICCL reports highlight a private firm based in Israel called ISA Security that makes a tool called Patternz – and boasts access to RTB data that covers five billion devices. Some of that data, it's claimed, came from Google and Twitter.

The ISA website describes the software as an advertising-based intelligence tool. It claims "PATTERNZ allows national security agencies [to] utilize real-time and historical user advertising generated data to detect, monitor and predict users actions, security threats and anomalies based on users' behavior, location patterns and mobile usage characteristics."

ISA Security – which, at the time this article was filed, lacked a valid TLS certificate – could not be reached for comment because its web submission form was nonfunctional.

Microsoft and the Internet Advertising Bureau did not respond to requests for comment. ®

Get our [18]Tech Resources



[1] https://advertising.amazon.com/library/guides/real-time-bidding

[2] https://www.natlawreview.com/article/going-once-going-twice-sold-real-time-bidding-data-privacy-breach

[3] https://iccl.ie/digital-data/europes-hidden-security-crisis/

[4] https://www.iccl.ie/digital-data/americas-hidden-security-crisis/

[5] https://www.iccl.ie/2023/new-iccl-reports-reveal-serious-security-threat-to-the-eu-and-us/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVX2W091fb8cciDR9a-3XwAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVX2W091fb8cciDR9a-3XwAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVX2W091fb8cciDR9a-3XwAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.washingtonpost.com/dc-md-va/2023/03/09/catholics-gay-priests-grindr-data-bishops/

[10] https://www.theregister.com/2023/11/07/data_brokers_military_data/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVX2W091fb8cciDR9a-3XwAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://blog.google/outreach-initiatives/public-policy/the-urgent-necessity-of-enacting-a-national-privacy-law/

[13] https://www.theregister.com/2023/11/15/metas_teen_safety/

[14] https://www.theregister.com/2023/11/15/google_amazon_microsoft_mozilla/

[15] https://www.theregister.com/2023/11/14/youtube_ai_label/

[16] https://www.theregister.com/2023/11/14/google_chrome_devs_third_party_cookie/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVX2W091fb8cciDR9a-3XwAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://whitepapers.theregister.com/



Alumoi

...data that enables personalized advertising could be used to compromise civilian and military leaders...

So it's OK for the peasants but not for the leaders?

Naah, that's not it. Wait, I've got it! It's OK when it's done by the state but it's evil if it's done by private companies.

lglethal

I believe this is more along the lines of:

Minion: Sir, we've discovered that ad companies are selling personal information that could compromise members of the public.

Politician: Bah! If those people didnt want to be embarrased, they shouldnt be doing naughty things. Serves them right, if they get caught out...

Minion: Ahhh Sir, it turns out they're also selling personal information about your visits to Cross Dressers Weekly and the Man Boy Love Association!

Politician: This is an outrage! We have to protect the public from these evil ad companies. How dare they compromise people's personal information! (And I was looking for the Marlon Brando Look Alikes website, honest *cough*)

Scam out-bidding real businesses

Anonymous Coward

Sometimes I see a lot of annoying, but honest business ads. But there are days when only scam is shown. That means scam pays more, and is more profitable than real business.

What if media-companies earn considerable portion of their revenue from crime and are organized crime enablers? Enablers of hate speech and public disorder, they are, in my opinion.

Taming ad-business will not harm real business. The measure will stimulate other tech areas, as googles and facebooks would still want earning money, but hopefully from more productive, beneficial, (and well) harder business activities.

"are willing to bid more if they know that you, ..., are deemed valuable"

Anonymous Coward

Sounds a bit like a slave auction :(

As many have stated previously: on the internet - you are the product.

Basically, ioctl's will _never_ be done right, because of the way people
think about them. They are a back door. They are by design typeless and
without rules. They are, in fact, the Microsoft of UNIX.

- Linus Torvalds on linux-kernel