Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Think Your Online Content Is Yours? Think Again. They Can Read Your Passwords, Travel Plans, Ideas And Everything Else.
Articles

Think Your Online Content Is Yours? Think Again. They Can Read Your Passwords, Travel Plans, Ideas And Everything Else.

ISBuzz TeamBy ISBuzz TeamJanuary 10, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Last week, the Internet caught fire when Evernote changed their Terms of Service privacy policy to explicitly allow them to read user content. After a very vocal and rightfully negative response, Evernote recanted their position and will only read user content if users opt-in to a new service they are creating for the platform.

In reality, they’ve always been able to read a user’s content. In fact, just about every service on the Internet can do that. Always could, and always will.  Most services’ business models, like Facebook, Twitter and Google, depend on reading user content, so their Terms of Service explicitly allow it. Because Facebook’s terms also give them a license to the photos users post on their service, they not only can (and do) have access to this content, they also kind of own it.

So why is this a surprise? Because most users don’t actually read a Terms of Service agreement before using an app. According to a social science study at the University of Connecticut and York University, 74% of individuals skipped reading privacy policies before signing up for a service, and 98% missed “gotcha” clauses that included giving up first born as payment and turning over all of your data to the NSA.

How did the web services and application industry get to this place of at-will access to user content, with next to no consequence or accountability?

Built-in features of application architecture.

Web apps are designed to read a user’s stuff all the time. Take, for instance, the feature of “Search” in any web service, such as Evernote, Slack or SalesForce. Once a user types a search term, that text is sent from the browser to the application’s servers, where they look through all of a user’s content to find the items that match, then list the results. On the contrary, when searching for a Word document on a computer, the search only happens on that device and Microsoft never knows about the file or what term was searched. Search is a valuable feature, but users shouldn’t overlook what it means for the privacy of their content or conversation.

The need for business models to monetize.

The predominately funded business model of Silicon Valley and beyond is one that monetizes users. That can be done by selling data about customers to advertisers, partners, data brokers – whomever will pay money for it. A good example of this is when a user is shopping online at Amazon and drops something in their cart, but doesn’t purchase it, they will likely begin to see ads for those same products appear on Facebook. Service companies have postured this behavior as “creating a better experience for users,” but with all of the sophisticated technology that makes web services work, their business model is as simple as a small town’s 17th century newspaper.

Relaxing attitudes around privacy.

Our parents’ generation preferred cash over checks, because what you bought was your own business. Today, everyone pays with credit cards, some of us even forgoing cash for the cheapest of services. With convenience—and rewards—driven transactions a priority for many consumers today, there’s less awareness about security and reliability implications, even though users expect this protection from banking and retail institutions. However, we’ve been told, “the people who care about privacy are those who have something to hide.” This browbeating comes from many of the executives running companies mentioned in the previous paragraphs, as their business’ livelihood depends on users not caring about privacy.

Software development is generational, too.

Most developers learning to build applications today do so for web services, not desktop applications. Web services, by design, share resources across user domains, which makes keeping things private pretty much impossible. Why create new tables and maintain meta data in the database for every customer when it’s far easier to have just one table with everyone in it? My father’s generation coded on mainframes, I did it on personal computers, and now my son does it on the web. With little demand from students or the industry to teach future developers how to write COBAL or C++, most of the code is now JavaScript, CSS, and either PHP or Python. It’s practical, in a sense, but not the most sensible when it comes to building protection in from the ground up.

Only recently have more people begun to challenge the anti-privacy cartel controlling how we live online. There are a few players out there building services that only use and store encrypted text, not “plain text”, and those are the role model service providers users and the industry alike should support for their own security and privacy benefits.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}