Bookmarks for a Web privacy tune-up

I talked at length about privacy when I spoke this morning at the Washington Apple Pi user group’s general meeting–but I realized halfway through that I was keeping too much documentation to myself. As in, I hadn’t remembered to put together a set of links for the privacy settings I discussed.

That’s where this post comes in.

Ad preferences: If you don’t want giant Web platforms to target you with ads based on your browsing history–or if you want to correct some inaccurate targeting–these settings will let you do that.

  • At Amazon, selecting “Do Not Personalize Ads from Amazon for this Internet Browser” will stop the retailer from retargeting you across the Web with reminders of things you searched for. But you’ll have to remember to adjust this in every browser in which you shop at Amazon.
  • Facebook provides more control, allowing you to set “Ads based on data from partners” and “Ads based on your activity on Facebook Company Products that you see elsewhere” to “Not allowed.” You can also see what interests Facebook thinks you have and check which advertisers and businesses have targeted you on the social network with their own uploaded contact lists.
  • At Google, you can see what interests the Web giant has discerned in you and opt out of its ad personalization; taking that step will reward you with the image of the sleeping robot shown above.

Tracking protection: If you use Apple’s Safari, you’re already protected from ad networks’ attempts to follow you around the Web to build a model of your interests. New installs of Mozilla Firefox include a comparable level of default tracking protection, as I wrote at USA Today two weeks ago, but you may need to change these settings yourself. Select “Content Blocking” from the menu, click “Custom” and set it to block trackers “Only in Private Windows” and block only cookies identified as “Third-party trackers.”

You may also want to install the Facebook Container extension to shut down Facebook’s attempts to track you on other sites, although I’m not totally clear on what this adds over the newest tracking protection.

Limit Google’s memory: While Google’s ability to remind you of where you’ve been can be useful, that doesn’t mean it should have unrestricted access to that information. Fortunately, you can now set Google to automatically erase your Web and app activity after three or 18 months. You can also take advantage of the lesser-known of option of setting a sync passphrase for your copies of Google Chrome that will encrypt your browsing history, leaving Google unable to use that data in building a profile of your interests.

Advertisements

First impressions of 1Password

After several years using the same password-manager service–and then paying for its premium version–I’ve spent the last few weeks trying an alternative.

I can credit a sales pitch that included the italicized phrase “completely free” for this departure: 1Password’s offer of a free membership to journalists, in celebration of World Press Freedom Day this May 3. But I was also overdue to spend some time in a password manager besides LastPass.

So far, I’m impressed by the elegance of the interface but a little put off by how persnickety 1Password can be to set up. You don’t just create a username and password, you also have to type in a complex and random secret key to get going.

Having read this Toronto-based firm’s documentation of how this extra step helps ensure that a successful guess of your password still won’t compromise your account, I get where they’re coming from. But I’m not sure I’d recommend it to just anybody, especially not when LastPass’s free version suffices for many casual users.

Further time with 1Password’s Mac, Windows and Android apps has revealed other things I like:

This time has also surfaced one thing I don’t like: an incomplete approach to two-step verification that seems to require choosing between running an authenticator app on your smartphone or employing a weird Yubikey implementation that requires running a separate app instead of just plugging a standard USB security key. That’s no better than LastPass’s inflexible notion of two-step verification.

I’d like to see 1Password improve that and support the WebAuthn standard for security-key confirmation. But I’m prepared to give them some time, based on everything else I’ve seen so far.

AirDrop apologists have some opinions

Who knew suggesting that an Apple interface enabled undesirable outcomes and ought to be changed would be so controversial? Me–I’ve been critiquing Apple’s products since before the company was doooomed in 1996.

But even so, the level of enraged techsplaining that greeted last weekend’s Yahoo post about AirDrop file-sharing has been something else. To recap that briefly: While AirDrop’s default contacts-only setting is safe, accepting a file transfer from somebody not in your contacts requires setting it to “Everyone”–a setting that does not time out but does automatically display a preview of the incoming image. The predictable result: creeps spamming strangers who had set AirDrop to Everyone and then forgot to change it back, and by “spamming” I mean “sending dick pics from iPhones with anonymous names.”

AirDrop settings screen on an iPhone.(For more details, see my Aug. 2017 USA Today column or this Dec. 4 post from the security firm Sophos.)

Suggesting that Apple have the Everyone setting time out or not auto-preview images did not go over well the people–most apparently men–who filled the replies to my tweet Sunday sharing the post. Let me sum up the major points these individuals vainly attempted to make, as seen in quotes from their tweets:

“It’s contacts only by default.” Yes, and if nobody ever interacted with people who weren’t in their contacts and offered to use this handy feature to share in a file, you would have a point. As is, this request comes up all the time–my wife saw it from Apple Store employees–as I explained in the post that these techbros apparently did not finish reading.

“Still trying to make a big deal of something I’ve never experienced.” Thank you, sir, for proving my exact point about the problems of having development teams dominated by white men. As writing about “Gamergate” made obvious, things are often different for the rest of humanity, and “I don’t have this problem” is not a valid defense of a social feature without confirmation from people outside your demographic background. Sorry if asking you to acknowledge your privilege is so triggering, by which I mean I’m not sorry.

“At some point, you have to take some goddamn responsibility.” Ah yes, the old blame-the-customer instinct. I hope the multiple people who expressed some version of “why are you coddling people too dumb to turn Everything off” don’t and never will work in any customer-facing role.

“you don’t have to accept every airdrop item that comes in.” What part of “automatically display a preview” don’t you understand?

“What I don’t understand is why these creeps aren’t reported by the receivers to authorities.” What part of “iPhones with anonymous names” don’t you understand? And before you next resort to victim blaming like this, you should really read up on the relevant history.

“There are far worse UX issues in iOS if that is what you are concerned about.” News flash, whataboutists: I write about problems in the tech industry all the time. Stick around and you’ll see me take a whack at a company besides your sainted Apple.

And that brings me to the annoying subtext beneath all these aggrieved responses: The notion that questioning Apple’s design choice is an unreasonable stretch, so we should look anywhere else for solutions to what even most of my correspondents agreed was a problem. Well, if that’s your attitude, turn in your capitalist card: You’re not a customer, you’re a supplicant. And I don’t have to take your opinion here seriously.

Here’s my Web-services budget

The annual exercise of adding up my business expenses so I can plug those totals into my taxes gave me an excuse to do an extra and overdue round of math: calculating how much I spend a year on various Web services to do my job.

The result turned out to be higher than I thought–even though I left out such non-interactive services as this domain-name registration ($25 for two years) and having it mapped to this blog ($13 a year). But in looking over these costs, I’m also not sure I could do much about them.

Google One

Yes, I pay Google for my e-mail–the work account hosted there overran its 15 gigabytes of free storage a few years ago. I now pay $19.99 a year for 100 GB. That’s a reasonable price, especially compared to the $1.99 monthly rate I was first offered, and that I took too long to drop in favor of the newer, cheaper yearly plan.

Microsoft Office 365

Getting a Windows laptop let me to opting for Microsoft’s cloud-storage service, mainly as a cheap backup and synchronization option. The $69.99 annual cost also lets me put Microsoft Office on one computer, but I’ve been using the free, open-source LibreOffice suite for so long, I have yet to install Office on my HP. Oops.

Evernote Premium

This is my second-longest-running subscription–I’ve been paying for the premium version of my note-taking app since 2015. Over that time, the cost has increased from $45 to $69.99. That’s made me think about dropping this and switching to Microsoft’s OneNote. But even though Microsoft owns LinkedIn, it’s Evernote that not only scans business cards but checks LinkedIn to fill in contact info for each person.

Flickr Pro

I’ve been paying for extra storage at this photo-sharing site since late 2011–back when the free version of Flickr offered a punitively-limited storage quota. This cost, too, has increased from $44.95 for two years to $49.99 a year. But now that Yahoo has sold the site to the photography hub SmugMug, the free tier once again requires serious compromises. And $50 a year doesn’t seem that bad, not when I’m supporting an indie-Web property instead of giving still more time to Facebook or Google.

Private Internet Access

I signed up for this virtual-private-network service two years ago at a discounted rate of $59.95 for two years, courtesy of a deal offered at Techdirt. Absent that discount, I’d pay $69.95, so I will reassess my options when this runs out in a few months. Not paying for a VPN service, however, is not an option; how else am I supposed to keep up on American news when I’m in Europe?

LastPass Premium

I decided to pay for the full-feature version of this password manager last year, and I’m already reconsidering that. Three reasons why: The free version of LastPass remains great, the premium version implements U2F two-step verification in a particularly inflexible way, and the company announced last month that the cost of Premium will increase from $24 a year to $36.

Combined and with multi-year costs annualized, all of these services added up to $258.96 last year. I suspect this total compares favorably to what we spend on news and entertainment subscriptions–but that’s not math I care to do right now.

We finally got an Amazon Echo

More than four years after I first tried out an Amazon Echo, there’s now one in our house. Even by my late-adopter habits, that’s an exceptionally long time for us to pick up on a tech trend.

But waiting so many years did allow us to get an Echo at a good price: $0.00. Late last year, Verizon added a free Echo to its menu of promotions to new and renewing Fios subscribers, and the company (also the parent firm of my client Yahoo Finance) included us in this offer even though we only pay it for Internet access.

(Even weirder, this free Echo came on top of being offered a lower rate for a faster connection. I guess I should see that as belated compensation for us missing out on other new-customer incentives Verizon’s offered since our fiber-optic connection went live nine years ago today.)

We got the code to redeem for a free second-generation Echo a couple of weeks after our speed upgrade went through, I waited a week to cash it in, and our new voice-controlled gadget arrived Friday. I promptly found a spot for this cybernetic cylinder in our kitchen.

So far, I’ve set up our Echo with only a few skills: it can play Pandora Internet radio, read the news from WAMU and can control our Philips Hue lightbulbs. (The Echo’s role as a smart-home hub is the use case that I utterly ignored in the first-look post I wrote for Yahoo Tech.) I’ve already determined that the Alexa app does not make for a great grocery-list manager, so I’m now going to see if Todoist can better handle that role. And I’ve changed one setting from the default: Because we have an eight-year-old at home, purchasing by voice is off.

There’s a lot to learn, but at least I’m no longer quite so illiterate at such a major tech platform. I just hope I can keep up with our kid, who already talks to Alexa far more than my wife and I combined.

2018 in review: security-minded

I spent more time writing about information-security issues in 2018 than in any prior year, which is only fair when I think about the security angles I and many of other people missed in prior years.

Exploring these issues made me realize how fascinating infosec is as a field of study–interface design, business models, human psychology and human villainy all intersect in this area. Plus, there’s real market demand for writing on this topic.

2018 calendarI did much of this writing for Yahoo, but I also picked up a new client that let me get into the weeds on security issues. Well after two friends had separately suggested I start writing for The Parallax–and after an e-mail or two to founder Seth Rosenblatt had gone unanswered–I spotted Seth at the Google I/O press lounge, introduced myself, and came home with a couple of story assignments.

(Lesson re-learned: Sometimes, the biggest ROI from going to conference consists of the business-development conversations you have there.)

Having this extra outlet helped diversify my income, especially during a few months when too many story pitches elsewhere suffered from poor product-market fit. My top priority for 2019 is further diversification: The Parallax is funded by a single sponsor, the Avast security-software firm, which on one hand frees it from the frailty of conventional online advertising but on the other leaves it somewhat brittle.

I’d also like to speak more often at conferences. Despite being half-terrified of public speaking in high school, I’ve become pretty good at what think of as the performance art of journalism. This took me some fun places in 2018, including my overdue introduction to Toronto. (See after the jump for a map of my business travel.)

My focus on online security and privacy extended to my own affairs. In 2018, I made Firefox my default browser and set its default search to DuckDuckGo, cut back on Facebook’s access to my data, and disabled SMS two-step verification on my most important accounts in favor of app or U2F security-key authentication.

At Yahoo, it’s now been more than five years since my first byline there–and with David Pogue’s November departure to return to the New York Times, I’m the last original Yahoo Tech columnist still writing for Yahoo. My streak is even longer at USA Today, where I just hit my seventh anniversary of writing for the site (and sometimes the paper). Permanence of any sort is not a given in freelance journalism, and I appreciate that these two places have not gotten bored with me.

I also appreciate or at least hope that you reading this haven’t gotten bored with me. I’d like to think this short list of my favorite work of 2018 had something to do with that.

Thanks for reading; please keep doing so in 2019.

Continue reading

LastPass shows how to do two-step verification wrong

I finally signed up for LastPass Premium after years of using the free version of that password-management service. And I’m starting to regret that expense even though $2 a month should amount to a rounding error.

Instead of that minimal outlay, I’m irked by LastPass’s implementation of the feature I had in mind when typing in credit-card digits: support for Yubikey U2F security keys as a form of two-step verification.

Two-step verification, if any reminder is needed, secures your accounts by confirming any unusual login with a one-time code. The easy but brittle way to get a two-step code is to have a service text one to you, which works great unless somebody hijacks your phone number with a SIM swap. Using an app like Google Authenticator takes your wireless carrier’s security out of the equation but requires regenerating these codes each time you reset or switch phones.

Using a security key–Yubikey being one brand, “U2F” an older standard, “WebAuthn” a newer and broader standard–allows two-step verification independent of both your wireless carrier and your current phone.

Paying for LastPass Premium allowed me to use that. But what I didn’t realize upfront is that LastPass treats this as an A-or-B choice: If you don’t have your Yubikey handy, you can’t click or type a button to enter a Google Authenticator code instead as you can with a Google account.

A LastPass tech-support notice doesn’t quite capture the broken state of this user experience:

If multiple Authentication methods are used, only one will activate per login attempt. If you disable one, then another will activate on the next log in attempt. Because only one activates at a time, you cannot have multiple prompts during the same log in.

The reality you see if you happened to leave your Yubikey at home or just have your phone closer at hand: an “I’ve lost my YubiKey device” link you’re supposed to click to remove that security option from your account.

This absolutist approach to two-step verification is not helpful. But it’s also something I should have looked up myself before throwing $24 at this service.