In this April 18, 2018, file photo, a graphic from the Cambridge Analytica website is displayed on a computer screen in New York.

In this April 18, 2018, file photo, a graphic from the Cambridge Analytica website is displayed on a computer screen in New York. AP Photo/Mark Lennihan, File

Why Data Privacy Is Crucial to Fighting Disinformation

Information collected as we go about our daily lives can be weaponized into influence operations that are harder to detect.

The data we give tech companies when we buy online or like a tweet will soon fuel disinformation campaigns intended to divide Americans or even provoke destructive behavior — and data-privacy legislation isn’t keeping up with the threat, intelligence community veterans, disinformation scholars, and academics warn.

This could bring back the kind of population-scale disinformation campaigns seen during the 2016 presidential election, which led to some reforms by social media giants and aggressive steps by U.S. Cyber Command. The fact that the 2020 election was relatively free of foreign (if not domestic) disinformation may reflect a pause as adversaries shift to subtler manipulation based on personal profiles built up with aggregated data.

As Michal Kosinski and his colleagues argued in this 2013 paper, easily accessible public information such as Facebook Likes “can be used to automatically and accurately predict a range of highly sensitive personal attributes including: sexual orientation, ethnicity, religious and political views, personality traits, intelligence, happiness, use of addictive substances, parental separation, age, and gender.”

It’s the sort of thing that worries Joseph E. Brendler, a civilian consultant who worked with Cyber Command as an Army major general.  Brendler discussed his concerns during a Wednesday webinar as part of the AFCEA TechNetCyber conference.

“A dynamic that started with a purely commercial marketplace is producing technologies that can be weaponized and used for the purposes of influencing the people of the United States to do things other than just buy products,” he said. “Activating people who are otherwise just observers to a political phenomenon that’s going on is accomplishing an extreme shift toward greater political activism. Some of that is a good thing. … the extent to which it might produce a violent outcome, it’s a really bad thing. Absent the appropriate forms of regulation, we really have an unregulated arms market here.”

The barely limited collection and aggregation of behavior data from phones, online activities, and even external sensors is no longer just a concern of privacy advocates. 

It’s “continuing to raise attention in our community,” said Greg Touhill of cybersecurity consultancy Appgate Federal and a retired Air Force brigadier general. 

While national security leaders have struggled—with mixed success—to predict broad social movements based on large volumes of mostly publicly available data, companies have gotten much better at anticipating individual behavior based on data that consumers give away, often without realizing it. A recent paper in Information & Communications Technology Law calls the process digital cloning.

“Digital cloning, regardless of the type, raises issues of consent and privacy violations whenever the data used to create the digital clone are obtained without the informed consent of the owner of the data,” the authors wrote. “The issue only arises when the owner of the data is a human. Data created solely by computers or AI may not raise issues of consent and privacy as long as AI and robots are not deemed to have the same legal rights or philosophical status as persons.”

In essence, if you can create a digital clone of a person, you can much better predict his or her online behavior. That’s a core part of the monetization model of social media companies, but it could become a capability of adversarial states who acquire the same data through third parties. That would enable much more effective disinformation. 

A new paper from the Center For European Analysis, or CEPA, also out on Wednesday, observes that while there has been progress against some tactics that adversaries used in 2016, policy responses to the broader threat of micro-targeted disinformation “lag.”

“Social media companies have concentrated on takedowns of inauthentic content,” wrote authors Alina Polyakova and Daniel Fried. “That is a good (and publicly visible) step but does not address deeper issues of content distribution (e.g., micro-targeting), algorithmic bias toward extremes, and lack of transparency. The EU’s own evaluation of the first year of implementation of its Code of Practice concludes that social media companies have not provided independent researchers with data sufficient for them to make independent evaluations of progress against disinformation.”

Polyakova and Fried suggest the U.S. government make several organizational changes to counter foreign disinformation. “While the United States has sometimes acted with strength against purveyors of disinformation, e.g., by indicting IRA-connected individuals, U.S. policy is inconsistent. The U.S. government has no equivalent to the European Commission’s Action Plan Against Disinformation and no corresponding Code of Practice on Disinformation, and there remains no one in the U.S. government in overall charge of disinformation policy; this may reflect the baleful U.S. domestic politics and Trump’s mixed or worse messages on the problem of Russian-origin disinformation.”

But anti-disinformation tools are is only part of the answer. The other part is understanding the risks associated with data collection for microtargeting, Georgetown Law professor Marc Groman, a former White House senior advisor for privacy, said on Wednesday’s panel. Neither the government nor the tech industry yet understand the ramifications of aggregate data collection, even when it’s lawful. 

“We don’t even have norms around this yet,” Groman said. “What we need is a comprehensive approach to risk” generated by data. What’s needed, he said, is to look at the process of data throughout that whole lifecycle of data governance.” 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.