Sunday, July 22, 2018



DIGITAL LIFE




hand-apple-iphone-smartphone
Venmo's Privacy Settings Could Be Exposing Your Biggest Secrets
Researchers and online activists are highlighting what they say is a serious flaw in Venmo, the popular mobile payments app. By default, the app makes a lot of users' transaction data publicly viewable, allowing strangers to closely scrutinize individual behavior.That fact is dramatically illustrated at Public By Default, a research project detailing the 2017 transaction of five real people. Created by German artist, researcher, and recent Mozilla Media Fellow Hang Do Thi Duc, the site uses Venmo's public data feed to show everything from extremely personal lover's quarrels carried out in the public comments attached to payments, to detailed business records of the food cart operator and cannabis retailer.Venmo's data feed also reveals user names by default-but Do Thi Duc chose to conceal these individuals' identities. She told the Guardian that the goal of the project was to highlight Venmo's privacy practices, not to expose individuals.An even more dramatic illustration this week came in the form of a Twitter bot that searched Venmo data, then tweeted about transactions that seemed to be connected with drugs, alcohol, or sex-including the transactor's first name and last initial. Like Public by Default, the bot was created by an activist, Joel Guerra, hoping to highlight Venmo's shortcomings. He has since deactivated the bot.Venmo, a wildly popular way for the under-35 set to split restaurant bills, is actively designed to promote public sharing of financial transactions. A PayPal spokesperson told Gizmodo that "It was designed for sharing experiences with your friends in today's social world, and the newsfeed has always been a big part of this." Of course, that's one thing when you're talking about photos shared on Facebook , but the implications of making "social" payments are a bit more complex. Do Thi Duc, for instance, suggests that the public records of one user's unhealthy habits could be of interest to an insurance company. The data could also invite scrutiny from users' bosses or other professional contacts.Paypal told Gizmodo it has worked to clarify privacy settings with Venmo users, including with more detailed tutorials and more aggressive pop-ups in the app. But it has not addressed the core issue-that users must actively change the default setting to stop the public sharing of their data. The fact that at least some users are advertising illegal activities suggests not everyone understands just what's in stake.


David Morris

No comments:

Post a Comment

  DIGITAL LIFE ISACA : how to prepare for AI risks in 2026 AI-powered social engineering is considered the most significant cyber threat org...