Looking for privacy in the clouds

October 13, 2009

Millions of Internet users have been enjoying the fun -- and free -- services provided by advertiser-supported online social networks like Facebook. But Landon Cox, a Duke University assistant professor of computer science, worries about the possible down side -- privacy problems.

When people post pictures or political opinions to share with their friends, they're actually turning them over to the owners of the network as well.

"My concern is that they're under the control of a central entity," Cox said. "The social networks currently control all the information that users throw into them. I don't think that's necessarily evil. But it raises some concerns."

For instance, MIT student experimenters have demonstrated the ability to sneak in and download more than 70,000 Facebook profiles. And a BBC technology program also showed how such personal information could be stolen.

"A disgruntled employee could leak information about social network users," Cox said. "They could also become attractive targets for hackers and other computer ne'er-do-wells."

Though users may not have caught this when they clicked to accept a site's terms of service, they've largely signed away the rights to their own data by joining an Online Social Network. "These rights commonly include a license to display and distribute all content posted by users in any way the provider sees fit," Cox said.

To delve deeper into these issues and begin the search for alternatives, Cox recently won a $498,000, three-year grant from the National Science Foundation. The funding is part of the federal stimulus package called the American Recovery & Reinvestment Act of 2009 (ARRA). He and two of his graduate students, Amre Shakimov and Dongtao Liu, are collaborating closely with Ramon Caceres at AT&T Labs in Florham Park, N.J., which is also a major supporter.

"What the grant will do is fund research into alternatives for providing services that don't concentrate all this information in a single place," he said. Cox's notion is instead to create what network architects would call a "peer-to-peer" system architecture in which information is spread out. Being distributed, individual data is thus harder to steal or otherwise exploit.

"The basic idea is that users would control and store their own information and then share it directly with their friends instead of it being mediated through a site like Facebook. And there are some interesting challenges that go along with decomposing something like Facebook into a peer-to-peer system.

" is a great service because it's highly available and really fast. When you break something into thousands and millions of different pieces instead, you'd want to try to recreate the same availability and performance. That's the research challenge we're going to be looking at over the next three years."

Cox proposed three possible options in a report for the Association for Computing Machinery's Workshop for Online Social Networks in Barcelona in August 2009. In each, users would load their personal information into what is called a "Virtual Individual Server," or VIS.

One option would host each social network user's VIS on his or her own desktop. "But the problem with desktop machines is that they go down all the time," Cox said. "When desktops are shut off they are not available."

An alternative idea is to distribute VISs within redundant "clouds" of servers such as those offered by the Amazon Elastic Computer Cloud. "Amazon will run little computers on your behalf out in their infrastructure," Cox said. "The nice thing about that is the service will never go down. But the problem is that it's very expensive. It costs about $50 a month to have just one server out in the cloud."

A third notion is called "hybrid decentralization." The idea is to keep VISs on desktops when possible but switch to the more costly and reliable cloud distribution option when individual desktops go offline.

"So there are these different tradeoffs," Cox said. "Users can try to put their information in clouds of servers, which are going to be highly available but expensive. Or they could try to store it on their own machines, which would be cheap but subject to service interruptions."

Under his NSF stimulus grant, Cox will be able to pay Shakimov and Liu for three years and fund some of his own work to explore those options. Other AT&T Labs research participants besides Caceres are Alexander Varshavsky and Kevin Li. Amazon is also providing equipment support.

"The research will point in a couple of directions," he said. "Can we get a desktop machine to intelligently switch over to a cloud? Can we reduce the cost by only using a cloud when the desktop is not available?"

Or perhaps the same information can be put in a number of places in the hope that at least one of those computers is always working. "So in addition to serving my own stuff I might ask my friends to serve my stuff as well," Cox said.

"The problem there is that now you're trusting somebody else to serve and store your data. We have some interesting challenges ahead."

Source: Duke University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4 /5 (3 votes)


October 13, 2009 all stories

Comments: 0

4 /5 (3 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Facebook vows 'improvements' after user backlash
    created Mar 25, 2009 | popularity not rated yet | comments 0
  • Facebook buys social media aggregator FriendFeed
    created Aug 10, 2009 | popularity not rated yet | comments 0
  • Five users sue Facebook for being too social a network
    created Aug 18, 2009 | popularity not rated yet | comments 0
  • Social networking aggregator sues Facebook
    created Jul 10, 2009 | popularity not rated yet | comments 0
  • Facebook users hooked in new 'phishing' scam
    created May 15, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Aspiring Engineering major looking for general answers
    created Nov 19, 2009
  • Calculating max load of square tube (steel)
    created Nov 19, 2009
  • Passive Chemical Heating
    created Nov 19, 2009
  • Shortening Boat Trailer
    created Nov 18, 2009
  • Strain Gage Test Advice
    created Nov 17, 2009
  • How Could I do This? Motor to open and close doors on a timer??
    created Nov 17, 2009
  • More from Physics Forums - General Engineering

Other News

China is the world's largest emitter of the greenhouse gases blamed for global warming

China harnesses mountain wind power

Technology / Energy

created 5 hours ago | popularity 5 / 5 (1) | comments 0

In the mountains above the southwestern Chinese town of Dali, dozens of new wind turbines dot the landscape -- a symbol of the country's sky-high ambitions for clean, green energy.


Analysts say AmEx is most interested in the so-called peer-to-peer services of Revolution

American Express takes aim at PayPal with Revolution

Technology / Internet

created 2 hours ago | popularity not rated yet | comments 0

With its deal to buy Revolution Money, American Express is taking aim at the growing market for online and alternative payments, in a challenge to recognized leader PayPal, analysts say.


Hackers leak e-mails, stoke climate debate

Technology / Internet

created 16 hours ago | popularity 4.4 / 5 (20) | comments 17

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


Ubisoft steps up videogame fitness with virtual coach

Technology / Software

created 5 hours ago | popularity not rated yet | comments 0

French videogame powerhouse Ubisoft will have a virtual fitness coach whipping Wii users into shape starting Tuesday.


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 17

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...