Author Message

<  General  ~  NiceRide released the data - privacy issues?

PostPosted: Thu Nov 29, 2012 6:05 pm
User avatarHandslingerJoined: Sat Jun 26, 2010 9:32 pmPosts: 471Location: stpaulmidwaybikelove
NiceRide released the data for the last season. This information contains the start site, end site, and dates and times. The data also contains a unique user ID. Does anyone think this raises privacy issues?

If you are a regular user, and I know where and when you typically pick up your bike and where your drop it, I can figure out pretty quickly what your Subscriber ID is. From there I can tell where you went and when.

When combined with other sources of data, this information becomes even more usable.

Here is a sample screen shot:



https://t.co/L4fxKSa6


Offline Profile
PostPosted: Thu Nov 29, 2012 6:38 pm
User avatarArrière du pelotonJoined: Sat Apr 21, 2012 2:08 pmPosts: 523Location: Longfellow
Yes.

I can believe that there is reasonable public interest in knowing about how people are using NiceRide. I don't believe there is reasonable public interest in knowing how a person uses NiceRide throughout the season. The data is not de-identified enough. A court may or may not agree with me, but I'm pretty sure the court of public opinion will not be pleased.

If they'd kept a consistent subscriber ID for a single day, so that one could see the pattern of check-ins and check-outs for a whole ride, I'd call that ok, but that isn't what they did; according to the readme, that's the user's subscriber id for the season. So if someone used NiceRide consistently through the year, I can find out who you are and where you were and where you might be next year.

MN recognizes the public disclosure of private facts tort, and I'd think this would qualify. It might also be a violation of their contract with subscribers.

TL;DR *facepalm*

ETA: There is also the question of what can be done with that Subscriber ID. If it is a user's actual Subscriber ID, it may be possible to do hinky things with it; the Nice Ride contract forbids users from sharing their ID. It's probably hashed or something, but may be recoverable (since I'm not a subscriber, I have no way to check). I also looked at the contract regarding confidentiality; it just says "NRM will comply with the Privacy Policy maintained at www.niceridemn.org, but the Privacy Policy is about information collected on the website only. So damned if I know.


Last edited by giddything on Thu Nov 29, 2012 7:05 pm, edited 1 time in total.

Offline Profile
PostPosted: Thu Nov 29, 2012 6:47 pm
User avatarSaw Greg Lemond once at a restaurantJoined: Tue Dec 26, 2006 7:01 pmPosts: 1974Location: Lake Calhoun
can you link to the data without an url shortener plz.



_________________
I'll procrastinate later.
Offline Profile
PostPosted: Thu Nov 29, 2012 7:40 pm
Super DomestiqueJoined: Sat Dec 16, 2006 8:24 pmPosts: 2263
Whatsisname wrote:
can you link to the data without an url shortener plz.


+ 1

People like me really like the actual links. That way I choose if it's a site I should be going to before I click the link.

No hard feelings. Nothing personal. Just prefer the full link. I know people that won't click url shortened links at work because they worry about their job.


Offline Profile
PostPosted: Thu Nov 29, 2012 8:56 pm
User avatarGlass CrankerJoined: Tue Jun 28, 2011 10:14 pmPosts: 220Location: SW Minneapolis
Links to a 7.5M zip file

https://niceridemn.egnyte.com/h-s-inter ... e2f74045be

I never heard of egnyte.com, either, so here's the link to their front page:

https://www.egnyte.com/


Offline Profile
PostPosted: Thu Nov 29, 2012 10:25 pm
Super DomestiqueJoined: Sat Dec 16, 2006 8:24 pmPosts: 2263
I'm going to think about this a bit.

Ok, I'm back half a second later. I believe it's irresponsible for this data to be released to the public. I should not be able to have this data on my computer. I do not believe that the people that made this information public are qualified to have the data. If they were they wouldn't have released it. It wouldn't be on my computer.


Offline Profile
PostPosted: Thu Nov 29, 2012 10:29 pm
User avatarArrière du pelotonJoined: Sat Apr 21, 2012 2:08 pmPosts: 523Location: Longfellow
Fanatic wrote:
I never heard of egnyte.com, either, so here's the link to their front page:

https://www.egnyte.com/

Egnyte's a legitimate cloud-based file sharing service for small/medium businesses; I've used them before in my consulting work.


Offline Profile
PostPosted: Thu Nov 29, 2012 10:37 pm
User avatarSaw Greg Lemond once at a restaurantJoined: Tue Dec 26, 2006 7:01 pmPosts: 1974Location: Lake Calhoun
Interesting, despite having rented twice, I have the same subscriber ID, presumably because I used the same credit card for both 24 hour subscriptions.

Check out where I went, if you feel like it: HO85QIR2VS

Or a better example, can anyone figure out what I was doing or where I was going?

After looking at some of the data, I can see the possibility of trying to tie a Subscriber ID to a particular person. It is a little far fetched though as to what someone would do with it. If someone was nefarious, and already knows enough of your nice ride habits in person, to be able to figure out your subscriber ID in the first place, what more are they going to yield from looking at summer 2012's data?


Last edited by Whatsisname on Thu Nov 29, 2012 10:46 pm, edited 1 time in total.


_________________
I'll procrastinate later.
Offline Profile
PostPosted: Thu Nov 29, 2012 10:46 pm
Super DomestiqueJoined: Sat Dec 16, 2006 8:24 pmPosts: 2263
I want to clarify what I meant.

Look this id up.

2VPKT568K9


You can see the places this person went and when. You can see their patterns. If you know when they were at a particular location getting a bike you can see everywhere else they go. Subscriber id's should not be included in the data they released.


The big talk on privacy right now is license plate tracking data. This is actually quite a bit worse.


Offline Profile
PostPosted: Thu Nov 29, 2012 10:51 pm
User avatarSaw Greg Lemond once at a restaurantJoined: Tue Dec 26, 2006 7:01 pmPosts: 1974Location: Lake Calhoun
2VPKT568K9 appears to be a student or staff at the U.

So, if you knew the person behind 2VPKT568K9 well enough already, to be able seperate 2VPKT568K9 from other subscribers that are U staff or students with similar usage patterns, such as 8D2UCT5IYY, then what additional information is the data going to provide you, that you would't already have?



_________________
I'll procrastinate later.
Offline Profile
PostPosted: Thu Nov 29, 2012 11:07 pm
Seems like this data provides a useful tool if I wanted to stalk 2VPKT568K9.

Because I've been stalking them I can identify the person connected with 2VPKT568K9.

I might know they work or attend the U but I might not know where else they go. Now I do.


PostPosted: Thu Nov 29, 2012 11:10 pm
User avatarSaw Greg Lemond once at a restaurantJoined: Tue Dec 26, 2006 7:01 pmPosts: 1974Location: Lake Calhoun
You know where they went to within a many-block radius, sure.

I'm HO85QIR2VS. Where did I go?



_________________
I'll procrastinate later.
Offline Profile
PostPosted: Thu Nov 29, 2012 11:17 pm
Super DomestiqueJoined: Sat Dec 16, 2006 8:24 pmPosts: 2263
Whatsisname wrote:
2VPKT568K9 appears to be a student or staff at the U.

So, if you knew the person behind 2VPKT568K9 well enough already, to be able seperate 2VPKT568K9 from all the other subscribers that are U staff or students with similar usage patterns, then what additional information is the data going to provide you, that you would't already have?





I was network security programmer and data miner on a network operations security team at a very large institution (a couple hundred thousand people between employees and contractors) before I grew weary of corporate America. I dealt with very large amounts of private and sensitive data. I have a qualifying opinion on the matter as far as what is professional goes.


Really common sense wins out over that though. People don't like people to have information on where they have been and where they go and when... They like it even less when this data has been made public.


This data should not have been released with identifiers for people. It is irresponsible.


Offline Profile
PostPosted: Fri Nov 30, 2012 11:05 am
User avatarHandslingerJoined: Sat Jun 26, 2010 9:32 pmPosts: 471Location: stpaulmidwaybikelove
Whatsisname wrote:
You know where they went to within a many-block radius, sure.

I'm HO85QIR2VS. Where did I go?


I do not know where you went, but I suck at knowing what is at different streets around here.

But I know that you did not travel alone.
That you do not have a NiceRide subscription but that you paid with the same credit card each time.
And that you used the bikes on two occasions - a Saturday and Sunday in September and a Saturday in October.


Here is an example of the danger:

Let's say I take a bike out every morning near my house and ride it to work. My ex-wife knows I do this. She uses this information to figure out my subscriber ID because I am the only one who daily takes that bike from there and rides to the location near my work. Using my ID she looks at my other activity. She sees that I am riding places in the middle of the day. She sees that I am riding places when I told her I was out of town. She sees that I am riding around when I told her I was too sick to take the kids. She sees that I am riding to a place where I spent Saturday night and ride away the next morning. I just do not want her knowing that shit and I did not pay NiceRide to tell her.


Offline Profile
PostPosted: Fri Nov 30, 2012 11:51 am
User avatarDances on the pedals in a most immodest wayJoined: Thu Feb 12, 2009 11:15 amPosts: 7145
bat56 wrote:
She knows I went to that no-good, filty whore's house.
Forgot that one.



_________________
JenNastix wrote:
You guys ever wonder if we're over-thinking this bike riding thing sometimes?
Offline Profile

Display posts from previous:  Sort by:

All times are UTC - 6 hours [ DST ]
Page 1 of 2
20 posts
Go to page 1, 2  Next
Users browsing this forum: yer russian and 2 guests
Search for:
Reply to topic
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum


 

Featured Sponsor

Twitter Feed

Twitter: mplsbikelove

Flickr Photos

Flickr

More Sponsor