Ebay's Flexible Privacy Policy
l2718 writes "Ha'aretz has a disquieting report on a presentation made by eBay's senior counsel to law-enforcement officials. Apparently eBay logs all user interaction with them, and will happily hand over all the information to any law-enforcement official without a warrant -- a fax is quite sufficient. He is actually proud of their 'flexible' privacy policy."
I've got a fax machine...
Maybe you need letterhead.
Oh, I've got an Internet connection, and plenty of places have seals and official logos online. The quality isn't great, but hey - it's a fax, right?
Maybe you need a phone number.
Oh, I've gota phone I can sit by and pretend to be whoever I want when I answer it.
What was it Kevin Mitnick said about social engineering?
That what was all this school was for... to teach us how to solve our own problems. -- janeowit
Don't complain about eBay and other companies doing this--complain about the laws that don't protect our privacy. Talk to your representative and make the case for protecting such information if this kind of thing bothers you (and it should).
In this current age of "let's go get them badguys", is anyone really surprised that a company would so willingly acquiesce to the government? Should they? Good question, but are you surprised that they DO?
Not that I condone it for even a second - how can eBay (yes, /. editors, that's how it's spelt, how can you not get that much right?) be sure that the person requesting the information is a legitimate law enforcement official?
Even if they were, any information garnered in this way would immediately be thrown out of court in most countries (including the US) as inadmissible, because the source would be deemed an illegal search if the proper warrants hadn't been obtained.
Without even examining the link it's obvious why eBay would do this - verifying the legality and scope of every warrant that it is presented with takes time, and time costs money. Rather than spend this time and money unproductively (cooperating with police officers doesn't produce revenues), they choose the path of least resistance.
Unfortunately, eBay is sufficiently large enough (or at least it thinks it is) that it doesn't see this as a reason for people to defect to less popular rival online auction sites.
"Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
Even scarier ... who owns PayPal these days?
I hear some people use it like a bank. Would you want your financial info tossed around like that?
One more reason so stay way from Paypal.
This should be the final proof, if proof were required, that privacy policies and TRUSTe seals audits and seals are ineffective at protecting consumers.
"How to Do Nothing," kids activities, back in print!
Public use of any portable music system is a virtually guaranteed indicator of sociopathic tendencies. -- Zoso
I work in Student Records at a technical college in MN. I will NOT allow anyone to request information over the phone. They must either MAIL or FAX me a request with a hand written signature in order for me to release this information to them...
State and Federal law states that people can request information over the phone if it is going directly to them and *I* feel that it is really that person. Problem here is that I cannot verify if it is really them and the social engineering thing comes into play. So basically I won't accept any phone requests. I feel that I cannot safely determine who the person is if I don't see a handwritten request.
Oh, for chrissakes - handwritten requests are completely and utterly useless. Let me guess, it has to be on letterhead? See parent post regarding availability thereof...
So I fax you a request. It has Police Department letterhead...or something similar. I mean, you don't know what the Jackass Police Department's letterhead looks like. And I sign it as the chief of Jackass Police Department. You don't know what his signature looks like either. And I put my phone number on it - but it has the same area code and extension as the main number, so it could be a non-main phone line. Or maybe I made up a police department that doesn't even exist.
How many E-bay knobs are going to fully check this? Are they going to get a directory assistance to find the PD and check the number? Are they going to talk to the chief, from the phone number they looked up, to make sure he ordered the data? What if they can't find the department's listing (could be a small department, could be I made it up)? Probably none of the above.
When you get down to it, faxed requests are pretty much worthless. Which is why I would want a warrant served by law enforcement personnel who I could easily check up on. As for DNR, I don't believe that helps with ebay.
-Looking for a job as a materials chemist or multivariat
From the article:
Attorney Nimrod Kozlovski, author of "The Computer and the Legal Process" (in Hebrew), heard the lecture, and could not believe his ears. "The consent given in the user contract should be seen as `coerced consent,' in the absence of any opportunity to exercise free choice, with no real alternative but to agree. This is most certainly not conscious consent."
I think this says it all. We are rapidly becoming a society in which corporations can strip individuals of their liberties not by virtue of law, but by using onerous contracts.
Imagine if the utility companies forced a person to hand over keys to their residence when they signed up for service, so that the company could "inspect the premises in the interests of public safety". It wouldn't be long before the utility company would realize that they can make additional income by "renting" your key to law enforcement agencies on demand. But you, the resident would effectively have no say in this - you either agree to their terms, or you do without gas/electric/phone service.
You see, the danger of this is that by "renting" the key, law enforcement no longer needs a warrant to search your house; you implicitly gave consent for entry to the utility company, who then resold that consent to law enforcement. It is these kinds of agreements which allow law enforcement to circumvent the checks and balances gauranteed by the constitution, and this is what makes them so dangerous.
How long will it be before our lives and liberties are entirely beholden to corporate interests?
The society for a thought-free internet welcomes you.