Feeds

AOL publishes database of users' intentions

Your search history, right here

Security for virtualized datacentres

AOL Labs prompted a weekend of hyperventilation in the 'blogosphere' by publishing the search queries from 650,000 users. This mini-scandal may yet prove valuable, however, as it reveals an intriguing psychological study of the boundaries of what is considered acceptable privacy.

In his turgid book on Google - one so obsequious and unchallenging that Google bought thousands of copies to give away to its staff - former dot.bust publisher John Battelle enthused about something he called the "database of intentions". The information collected by search engines, he trumpeted, would be a marketer's dream, and tell us more about ourselves than we ever realized we could know. AOL's publication is the first general release of such a database to the public.

But hold on a minute. Is it, really?

AOL's data was anonymized, with user identification removed. The search logs contained 10.8m normalized queries from 658,086 unique users, collected between March 1 and 31 May this year, amounting to around a third of all queries made by its US users. The data has since been removed, but an AOL research paper which was built on the data can still be found, here [PDF, 228kb]. You may find it about as enlightening as similar studies we've covered before (see People more drunk at weekends, researchers discover).

Although the user's IDs were hidden, and didn't contain information on what the user actually clicked on, some argued that the data permitted personally identifiable information to be inferred from the query logs.

Something called TechCrunch, a weblog devoted to hyping its publisher's personal investments and companies created by his friends, explained how:

"The most serious problem is the fact that many people often search on their own name, or those of their friends and family, to see what information is available about them on the net. Combine these ego searches with porn queries and you have a serious embarrassment. Combine them with 'buy ecstasy' and you have evidence of a crime. Combine it with an address, social security number, etc., and you have an identity theft waiting to happen. The possibilities are endless."

Now, you may be thinking - that only serves people right for conducting vanity searches. But more seriously, there are dangers in following this line of reasoning.

It's not only individuals who "ego surf", it could be the individual's spouse, a member of their family, a colleague, or even their web stalker. (I've had a few).

Similarly, is the query "buy ecstasy" necessarily the intention of a raver, or tweaker? It might be a parent, a neighborhood watch scheme, or a promoter, keen to stamp out drug dealing at his venue before an event.

So the "database of intentions", then, turns out to be more more of "a database of inferences" - as reflective as it is of the inferrer as the web surfer.

And if, as TechCrunch weakly suggests, the act of typing "buy ecstasy" into a search is itself "evidence of a crime", then there will be a lot of happy policeman out there this evening, for whom the business of catching criminals has just been made a lot easier.

The" precogs" of Phillip K Dick's story Minority Report - who are able to predict crimes before they take place, thus allowing them to be prevented - will no longer be necessary. Plod will simply be able issue a pre-emptive warrant for a crime that never took place, on the basis of a user's Google results, no?

So that's one line of sloppy thinking dealt with. It ignores another, however.

Reducing the cost and complexity of web vulnerability management

Next page: Leave No Trace

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
JINGS! Microsoft Bing called Scots indyref RIGHT!
Redmond sporran metrics get one in the ten ring
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Murdoch to Europe: Inflict MORE PAIN on Google, please
'Platform for piracy' must be punished, or it'll kill us in FIVE YEARS
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Sony says year's losses will be FOUR TIMES DEEPER than thought
Losses of more than $2 BILLION loom over troubled Japanese corp
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.