Author: azeeadmin

18 Mar 2019

EU gov’t and public health sites lousy with adtech, study finds

A study of tracking cookies running on government and public sector health websites in the European Union has found commercial adtech to be operating pervasively even in what should be core not-for-profit corners of the Internet.

The researchers used searches including queries related to HIV, mental health, pregnancy, alcoholism and cancer to examine how frequently European Internet users are tracked when accessing national health service webpages to look for publicly funded information about sensitive concerns.

The study also found that most EU government websites have commercial trackers embedded on them, with 89 per cent of official government websites found to contain third party ad tracking technology.

The research was carried out by Cookiebot using its own cookie scanning technology to examine trackers on public sector websites, scanning 184,683 pages on all 28 EU main government websites.

Only the Spanish, German and the Dutch websites were found not to contain any commercial trackers.

The highest number of tracking companies were present on the websites of the French (52), Latvian (27), Belgian (19) and Greek (18) governments.

The researchers also ran a sub-set of 15 health-related queries across six EU countries (UK, Ireland, Spain, France, Italy and Germany) to identify relevant landing pages hosted on the websites of the corresponding national health service — going on to count and identify tracking domains operating on the landing pages.

Overall, they found a majority (52 per cent) of landing pages on the national health services of the six EU countries contained third party trackers.

Broken down by market, the Irish health service ranked worst — with 73 per cent of landing pages containing trackers.

While the UK, Spain, France and Italy had trackers on 60 per cent, 53 per cent, 47 per cent and 47 per cent of landing pages, respectively.

Germany ranked lowest of the six, yet they still found a third of the health service landing pages contained trackers.

Searches on publicly funded health service sites being compromised by the presence of adtech suggests highly sensitive inferences could be being made about web users by the commercial companies behind the trackers.

Cookiebot found a very long list of companies involved — flagging for example how 63 companies were monitoring a single German webpage about maternity leave; and 21 different companies were monitoring a single French webpage about abortion.

Vulnerable citizens who seek official health advice are shown to be suffering sensitive personal data leakage,” it writes in the report. “Their behaviour on these sites can be used to infer sensitive facts about their health condition and life situation. This data will be processed and often resold by the ad tech industry, and is likely to be used to target ads, and potentially affect economic outcomes, such as insurance risk scores.”

“These citizens have no clear way to prevent this leakage, understand where their data is sent, or to correct or delete the data,” it warns. 

It’s worth noting that Cookiebot and its parent company Cybot’s core business is related to selling EU data protection compliance services. So it’s not without its own commercial interests here. Though there’s no doubting the underlying adtech sprawl the report flags.

Where there’s some fuzziness is around exactly what these trackers are doing, as some could be used for benign site functions like website analytics.

Albeit, if/when the owner of the freebie analytics services in question is also adtech giant Google that still may not feel reassuring, from a privacy point of view.

100+ firms tracking EU public sector site users

Across both government and health service websites, Cookiebot says it identified a total of 112 companies using trackers that send data to a total of 131 third party tracking domains.

It also found 10 companies which actively masked their identity — with no website hosted at their tracking domains, and domain ownership (WHOIS) records hidden by domain privacy services, meaning they could not be identified. That’s obviously of concern. 

Here’s the table of identified tracking companies — which, disclosure alert, includes AOL and Yahoo which are owned by TechCrunch’s parent company, Verizon.

Adtech giants Google and Facebook are also among adtech companies tracking users across government and health service websites, along with a few other well known tech names — such as Oracle, Microsoft and Twitter.

Cookiebot’s study names Google “the kingpin of tracking” — finding the company performed more than twice as much tracking as any other, seemingly as a result of Google owning several of the most dominant ad tracking domains.

Google-owned YouTube.com, DoubleClick.net and Google.com were the top three tracking domains IDed by the study. 

“Through the combination of these domains, Google tracks website visits to 82% of the EU’s main government websites,” Cookiebot writes. “On each of the 22 main government websites on which YouTube videos have been installed, YouTube has automatically loaded a tracker from DoubleClick .net (Google’s primary ad serving domain). Using DoubleClick.net and Google.com, Google tracks visits to 43% of the scanned health service landing pages.”

 

Given its control of many of the Internet’s top platforms (Google Analytics, Maps, YouTube, etc.), it is no surprise that Google has greater success at gaining tracking access to more webpages than anyone else,” it continues. “It is of special concern that Google is capable of cross-referencing its trackers with its 1st party account details from popular consumer-oriented services such as Google Mail, Search, and Android apps (to name a few) to easily associate web activity with the identities of real people.”

Under European data protection law “subjective” information that’s associated with an individual — such as opinions or assessments — is absolutely considered personal data.

So tracker-fuelled inferences being made about site visitors are subject to EU data protection law — which has even more strict rules around the processing of sensitive categories of information like health data.

That in turn suggests that any adtech companies doing third-party-tracking of Internet users and linking sensitive health queries to individual identities would need explicit user consent to do so.

The presence of adtech trackers on sensitive health data pages certainly raises plenty of questions.

We asked Google for a response to the Cookiebot report, and a spokesperson sent us the following statement regarding sensitive category data specifically — in which it claims: “We do not permit publishers to use our technology to collect or build targeting lists based on users’ sensitive information, including health conditions like pregnancy or HIV.”

Google also claims it does not itself infer sensitive user interest categories.

Furthermore it said its policies for personalized ads prohibit its advertisers from collecting or using sensitive interest categories to target users. (Though saying you’re telling someone not to do something is not the same as that thing not being done. That would depend on the enforcement.)

Google’s spokesperson was also keen to point to its EU user consent policy — where it says it requires site owners that use its services to ensure they have correct disclosures and consents for personalised ads and cookies from European end users.

The company warns it may suspend or terminate a site’s use of its services if they have not obtained the right disclosures and consents. It adds there’s no exception for government sites.

On tags and disclosure generally, the Google spokesperson provided the following comment: “Our policies are clear: If website publishers choose to use Google web or advertising products, they must obtain consent for cookies associated with those products.”

Where Google Analytics cookies are concerned, Google said traffic data is only collected and processed per instructions it receives from site owners and publishers — further emphasizing that such data would not be used for ads or Google purposes without authorization from the website owner or publisher.

Albeit sloppy implementations of freebie Google tools by resource-strapped public sector site administrators might make such authorizations all too easy to unintentionally enable.

So, tl;dr — as Google tells it — the onus for privacy compliance is on the public sector websites themselves.

Though given the complex and opaque mesh of technology that’s grown up sheltering under the modern ‘adtech’ umbrella, opting out of this network’s clutches entirely may be rather easier said than done.

Cookiebot’s founder, Daniel Johannsen, makes a similar point to Google’s in the report intro, writing: “Although the governments presumably do not control or benefit from the documented data collection, they still allow the safety and privacy of their citizens to be compromised within the confines of their digital domains — in violation of the laws that they have themselves put in place.”

More than nine months into the GDPR [General Data Protection Regulation], a trillion-dollar industry is continuing to systematically monitor the online activity of EU citizens, often with the unintentional assistance of the very governments that should be regulating it,” he adds, calling for public sector bodies to “lead by example – at a minimum by shutting down any digital rights infringements that they are facilitating on their own websites”.

“The fact that so many public sector websites have failed to protect themselves and their visitors against the inventive methods of the tracking industry clearly demonstrates the educational challenge that the wider web faces: How can any organisation live up to its GDPR and ePrivacy obligations if it does not control unauthorised tracking actors accessing their website?”

Trackers creeping in by the backdoor

On the “inventive methods” front, the report flags how third party javascript technologies — used by websites for functions like video players, social sharing widgets, web analytics, galleries and comments sections — can offer a particularly sneaky route for trackers to be smuggled into sites and apps by the ‘backdoor’.

Cookiebot gives the example of social sharing tool, ShareThis, which automatically adds buttons to each webpage to make it easy for visitors to share information across social media platforms.

The ShareThis social plugin is used by Ireland’s public health service, the Health Service Executive (HSE). And there Cookiebot found it releases trackers from more than 20 ad tech companies into every webpage it is installed on.

“By analysing web pages on HSE.ie, we found that ShareThis loads 25 other trackers, which track users without permission,” it writes. “This result was confirmed on pages linked from search queries for “mortality rates of cancer patients” and “symptoms of postpartum depression”.”

“Although website operators like the HSE do control which 3rd parties (like ShareThis) they add to their websites, they have no direct control over what additional “4th parties” those 3rd parties might smuggle in,” it warns.

We’ve reached out to ShareThis for a response.

Another example flagged by the report is what Cookiebot dubs “YouTube’s Tracking Cover-Up”.

Here it says it found that even when a website has enabled YouTube’s so-called “Privacy-enhanced Mode”, in a bid to limit its ability to track site users, the mode “currently stores an identifier named “yt-remote-device -id” in the web browser’s “Local Storage”” which Cookiebot found “allows tracking to continue regardless of whether users click, watch, or in any other way interact with a video – contrary to Google’s claims”.

“Rather than disabling tracking, “privacy-enhanced mode” seems to cover it up,” they claim. 

Google did not provide an on the record comment regarding that portion of the report.

Instead the company sent some background information about “privacy-enhanced mode” — though its points did not engage at all with Cookiebot’s claim that tracking continues regardless of whether a user watches or interacts with a video in any way.

Overall, Google’s main point of rebuttal vis-a-vis the report’s conclusion — i.e. that even on public sector sites surveillance capitalism is carrying on business as usual — is that not all cookies and pixels are ad trackers. So it’s claim is a cookie ‘signal’ might just be harmless background ‘noise’.

(In additional background comments Google suggested that if a website is running an advertising campaign using its services — which presumably might be possible in a public sector scenario if an embedded YouTube video contains an ad (for example) — then an advertising cookie could be a conversion pixel used (only) to measure the effectiveness of the ad, rather than to track a user for ad targeting.

For DoubleClick cookies on websites in general, Google told us this type of cookie would only appear if the website specifically signed up with its ad services or another vendor which uses its ad services.

It further claimed it does not embed tracking pixels on random pages or via Google Analytics with Doubleclick cookies.)

The problem here is the lack of opacity in the adtech industry which requires users to take ad targeters at their word — and trust that an adtech giant like Google, which makes pots of money off of tracking web users to target them with ads, has nonetheless built perfectly privacy-respecting, non-leaky infrastructure that operates 100% as separately and cleanly as claimed, even as the entire adtech industry’s business incentives are pushing in the opposite direction.

Also a problem: Certain adtech giants having a long and storied history of bundling purposes for user data and manipulating consent in privacy-hostile ways.

And with trust in adtech at such a historic low — plus regulation having been rebooted in Europe to put the focus on enforcement (which is encouraging a cottage industry of GDPR ‘compliance’ services to wade in) — the industry’s preferred cloak of complex opacity is under attack on multiple front (including from policymakers) and does look to be on borrowed time.

And as more light shines in and risk steps up, sensitive public sector websites could just decide to nix using any of these freebie plugins.

In another “inventive” case study highlighted by the report, Cookiebot writes that it documented instances of Facebook using a first party cookie workaround for Safari’s intelligent tracker blocking system to harvest user data on two Irish and UK health landing pages.

So even though Apple’s browser natively purges third party cookies to enhance user privacy by default Facebook’s engineers appear to have managed to create a workaround.

Cookiebot says this works by Facebook’s new first party cookie — “_fbp” — storing a unique user ID that’s then forwarded as a URL parameter in the pixel tracker “tr” to Facebook.com — “thus allowing Facebook to track users after all”, i.e. despite Safari’s best efforts to prevent pervasive third party tracking.

“In our study, this combined tracking practice was documented on 2 Irish and UK landing pages featuring health information about HIV and mental illness,” it writes. “These types of workarounds of browser tracking prevention are highly intrusive as they undermine users’ attempts to protect their personal data – even when using browsers and extensions with the most advanced protection settings.”

Reached for a response to the Cookiebot report Facebook also did not engage with the case study of its Safari third party cookie workaround.

Instead, a spokesman sent us the following line: “[Cookiebot’s] investigation highlights websites that have chosen to use Facebook’s Business Tools — for example, the Like and Share buttons, or the Facebook pixel. Our Business Tools help websites and apps grow their communities or better understand how people use their services. For example, we could tell them that their site is most popular among people aged 20-25.”

In further information provided to us on background the company confirmed that data it receives from websites can be used for enhancing ad targeting on Facebook. (It said Facebook users can switch off ad personalization based on such signals — via the “Ads Based on Data from Partners” setting in Ad Preferences.)

It also said organizations that make use of its tools are subject to its Business Tools terms — which Facebook said require them to provide users with notice and obtain any required legal consent, including being clear with users about any information they share with it. 

Facebook further claimed it prohibits apps and websites from sending it sensitive data — saying it takes steps to detect and remove data that should not be shared with it.

ePrivacy Regulation needed to raise the bar

Commenting on the report in a statement, Diego Naranjo, senior policy advisor at digital rights group EDRi, called for European regulators to step up to defend citizens’ privacy.

For the last 20 years, Europe has fought to regulate the sprawling chaos of data tracking. The GDPR is a historical attempt to bring the information economy in line with our core civil liberties, securing the same level of democratic control and trust online as we take for granted in our offline world. Yet, as this study has provided evidence of, nine months into the new regulation, online tracking remains as hidden, uncontrollable, and plentiful as ever,” he writes in the report. “We stress that it is the duty of regulators to ensure their citizens’ privacy.”

Naranjo also warned that another EU privacy regulation, the ePrivacy Regulation — which is intended to deal directly with tracking technologies — risks being watered down.

In the wake of GDPR it’s become the focus of major lobbying efforts, as we’ve reported before.

“One of the great added values of the ePrivacy Regulation is that it is meant to raise the bar for companies and other actors who want to track citizens’ behaviour on the Internet. Regrettably, now we are seeing signs of the ePrivacy Regulation becoming watered out, specifically in areas concerning “legitimate interest” and “consent”,” he warns.

“A watering down of the ePrivacy Regulation will open a Pandora’s box of more and more sharing, merging and reselling of personal data in huge online commercial surveillance networks, in which citizens are being unwittingly tracked and micro-targeted with commercial and political manipulation. Instead, the ePrivacy Regulation must set the bar high in line with the wishes of the European Parliament, securing that the privacy of our fellow citizens does not succumb to the dominion of the ad tech industry.”

18 Mar 2019

YC-backed Basement is a social network for close friends only

The past few years have been a bit of a dark age for budding social media startups. Facebook, Instagram, Twitter, Snap and messenger apps took up all the time of their users, leaving little room for yet another social media platform.

But the tide is shifting. Privacy scandals have shaken some users’ faith giants like Facebook, Instagram and Twitter, and users have grown fatigued by the constant onslaught of #content.

Basement, a YC-backed startup, is looking to give users a new, simpler social network.

Basement allows users to only add up to 20 friends on the network. Cofounders Fernando Rojo and Jeremy Berman said they waited around for someone to build something like Basement after seeing their own friend groups migrate most of their communication to messenger apps from Facebook and other social networks.

On Basement, there are no filters or influencers. The hope is that users share with the people they actually want to share with.

It uses a feed-based system for sharing, letting users share content to their 20 friends. Users can also share to a smaller group of friends by tagging them, which limits the viewership to only mutual friends of those tagged.

Users who are friends can see one another’s comments on a mutual friend’s post. However, comments left by non-friends will always appear anonymous.

Alongside the main feed, Basement also has a meme feed, letting users choose from the internet’s top trending memes to share to their friend group.

Processed with VSCO with f2 preset

Of course, Basement isn’t the first startup to try out the idea of a close-friends social network. Path was founded by Shawn Fanning and Dave Morin in 2010, giving users a photo-sharing and messaging platform that maxed out at 50 friends.

The network grew in the face of competition from Facebook, and at peak had around 50 million users. In fact, Path was raising money at a valuation of $500 million and turned down a $100 million offer from Google in its early months.

But it failed to retain talent, users and momentum. (A controversial privacy scandal in 2012 didn’t help.) In 2015, Path sold to Kakao for an undisclosed amount and was shut down for good just last year.

Rojo and Berman believe timing is more in their favor than it was with Path, but are also targeting a different audience. Whereas Path was aimed both at close friends and family, Basement wants to position itself squarely with young people who are already spending their time in meme-laden group chats.

“One of the challenges is that growth isn’t necessarily as inherently explosive in a micro-network as it would be with a broader social network,” said Rojo. “What’s exciting to us is that if anyone tries to spark up something similar to this, they’ll be one or two years behind. It’s harder to grow a micronetwork, but once it’s bigger it’s much more robust because it’s the place where people turn when they want to connect with their close friends.”

What’s more: Basement promises to never run ads on the platform.

The company plans to mimic the WhatsApp business model, giving users their first year free and then charging an inexpensive subscription after that.

18 Mar 2019

5 reasons to apply to compete in Startup Battlefield at Disrupt SF 2019

The search is in full swing for the most innovative, interesting and utterly disruptive early-stage tech startups to compete in Startup Battlefield, our premier pitch competition, at Disrupt San Francisco 2019 on October 2-4. Founders, if you think your startup has the right stuff, then by all means, apply right here, right now.

Not sure whether you should apply? We think it’s a no-brainer, but we’re happy to break it down for you. Buckle up and get ready for five reasons — in reverse order — why you should apply to compete in Startup Battlefield.

5. You have nothing to lose

It won’t cost you a dime to apply or, if you’re selected, to participate in Startup Battlefield. Nada, zip, zilch. Any early-stage startup — from any country, in any vertical — can apply. What’s more, TechCrunch does not charge any fees or take any equity.

4. Maximum exposure

We’re expecting record-breaking crowds at Disrupt SF ’19 with well over 10,000 attendees. Startup Battlefield takes place on the Disrupt Main Stage in front of a panel of elite venture capitalists and a live audience of thousands. That audience includes hundreds of media outlets and eager investors — influencers and dream makers whose interest and coverage hold the potential to change your life and the course of your company. What’s more, we live stream the entire competition around the world to millions of viewers.

3. Free expert pitch coaching

Battlefield teams have just six minutes to pitch and present a live demo to our panel of top VC judges. Following each pitch, the judges engage in a six-minute Q&A with each team. Fear not! Our Battlefield-tested editorial team will work with you extensively until your presentations, demos and business models are, well, pitch perfect.

2. Awesome access

All Startup Battlefield competitors receive prime access to events at Disrupt SF ’19. We’re talking three full days of exhibition space in Startup Alley — at no cost — backstage access, invitations to VIP events and free passes to all future TechCrunch events. It even includes complimentary subscriptions to Extra Crunch, our new editorial offering that provides in-depth content, coverage, products and events designed for our most engaged readers.

You’ll also become part of the Startup Battlefield Alumni Community. This impressive cohort includes the likes of Vurb, Dropbox, Get Around, Cloudflare, Mint and more. To date, 857 Battlefield teams have collectively raised $8.8 billion and produced 108 successful IPOs or acquisitions. Imagine all the networking possibilities in that crowd.

And finally, the top reason to apply for Startup Battlefield is — drum roll please:

1. You could win $100,000

That’s right — the winner of Startup Battlefield scores a $100K equity-free cash infusion. Plus, they’ll hoist the highly sought-after Disrupt Cup, become a media and investor darling and take their business to a whole new level.

Those are five mighty compelling reasons to apply, and we can’t wait to see what we know will be an incredible pool of applicants. It’s not easy choosing from among such a rich field of startups, but we’re up for the challenge and wouldn’t want it any other way.

Startup Battlefield takes place at Disrupt San Francisco 2019 on October 2-4. Don’t miss your chance to launch your startup on a world stage. Apply to compete in the Startup Battlefield today. We hope to see you in October!

18 Mar 2019

WorkClout brings SaaS to factory floor to increase operational efficiency

Factory software tools are often out of reach of small manufacturers, forcing them to operate with inefficient manual systems. WorkClout, a member of the Y Combinator Winter 2019 class, wants to change that by offering a more affordable SaaS alternative to traditional manufacturing software solutions.

Company co-founder and CEO Arjun Patel grew up helping out in his Dad’s factory and he saw first-hand how difficult it is for small factory owners to automate. He says that traditional floor management tools are expensive and challenging to implement.

“What motivated me is that when my Dad was trying to implement a similar system,” Patel said. He said that his father’s system had cost over $240K, taken over a year to get going and wasn’t really doing what he wanted it to do. That’s when he decided to help.

He teamed up with Bryan Trang, who became the CPO and Richard Girges, who became the CTO to build the system that his Dad (and others in a similar situation) needed. Specifically, the company developed a cloud software solution that helps manufacturers increase their operational efficiency. “Two things that we do really well is track every action on the factory floor and use that data to make suggestions on how to increase efficiency. We also determine how much work can be done in a given time period, taking finite resources into consideration,” Patel explained.

He said that one of the main problems that small-to-medium sized manufacturers face is a lack of visibility into their businesses. WorkClout looks at orders, activities, labor and resources to determine the best course of action to a complete an order in the most cost-effective way.

“WorkClout gives our customers a better way to allocate resources and greater visibility of what’s actually happening on the factory floor. The more data that they have, the more accurate picture they have of what’s going on,” Patel said.

Production Schedule view. Screenshot: WorkClout

The company is still working on the pricing model, but today it charges administrative users like plant management, accounting and sales. Machine operators get access to the data for free. The current rate for paid users starts at $99 per user per month. There is an additional one-time charge for implementation and training.

As for the Y Combinator experience, Patel says that it has helped him focus on what’s important. “It really makes you hone in on building the product and getting customers, then making sure those two things are leading to customer happiness,” he said.

While the company does have to help customers get going today, the goal is to make the product more self-serve over time as they begin to understand the different verticals they are developing solutions for. The startup launched in December and already has 13 customers, generating $100,000 in annual recurring revenue (ARR), according to Patel.

18 Mar 2019

Moby’s new album is exclusive to the Calm meditation app

Album exclusives are nothing new in the age of Tidal, of course. But Moby’s latest is taking a kind of circuitous route to the world’s mobile devices. The electronic artist has released his latest, Long Ambients 2, as an exclusive through the Calm meditation app.

The album dropped over the weekend in celebration of World Sleep Day — which we fittingly appeared to have slept on. It’s a sequel to 2016’s fittingly titled Long Ambients 1: Calm . Sleep. This time out, there are six ambient tracks each running ~37 minutes.

“I originally made these songs for myself because I couldn’t find this type of music anywhere,” the musician and tea entrepreneur said in a release issued with the news. “Long Ambients 2 was designed to help me sleep and to help other people find calm and maybe get a good night’s sleep. I hope to share it with other people who have sleep issues or battle anxiety or have a hard time calming themselves down.”

Calm certainly has the money to through around. Last month it announced an $88 million Series B, freshly minting its unicorn status. At the time, it noted that the funding would go toward an international push and an investment in content. The mobile deal marks an interestingly high profile version of the latter.

18 Mar 2019

America Movil acquires Nextel in Brazil for $905M

Latin America continues to remain a focus for investors that are eyeing up its large population and growth potential. In the latest development, America Movil, the Latin American carrier that is part of the Carlos Slim empire, today announced that it would acquire Nextel in Brazil, owned by NII (formerly Nextel International), for $905 million. NII in turn said that once the deal is closed, it has received approval “to dissolve and wind up NII.”

This is a move to scale up an existing carrier in competition with existing large players like Telefonica (which co-owns Vivo with Portugal Telecom), Telecom Italia and Oi (owned by Telemar). America Movil already has an operation in the country, Claro, which it plans to merge with Nextel to “consolidate its position as one of the leading telecommunication service providers in Brazil, strengthening its mobile network capacity, spectrum portfolio, subscriber base, coverage and quality, particularly in the cities of São Paulo and Rio de Janeiro, the main markets in Brazil.”

America Movil — based out of Mexico — has been on a consolidation spree, swallowing up other smaller holdings in a variety of markets in the region. In January, it acquired Telefonica’s assets in Guatemala and El Salvador respectively for $333 million and $315 million.

The Nextel Brazil deal will include buying a 70 percent stake in the carrier from NII, as well as a remaining 30 percent stake from AI Brazil Holdings BV, NII said today. AI Brazil Holdings is controlled by Len Blavatnik’s Access Industries, the company that owns Warner Music, Deezer and a number of other assets and investments. It had reportedly also been interested in increasing its share in the carrier, before agreeing to sell its stake altogether.

The acquisition is the final chapter for the struggling business, which had originally been the international division of Nextel but had spun out as a separate company before Sprint acquired Nextel in the US in 2005. NII’s focus had been mobile carrier operations across a range of developing markets but it struggled and had been through multiple bankruptcy processes.

“The announcement of this transaction marks the culmination of an extensive multi-year process to pursue a strategic path for Nextel Brazil and provides our best opportunity to monetize our remaining operating assets in light of the competitive landscape in Brazil and long-term need to raise significant capital to fund business operations, debt service and capital expenditures necessary to remain competitive in the future,” stated Dan Freiman, NII’s Chief Financial Officer, in a statement. “Management and our Board of Directors believe the transaction is in the best interest of NII’s stockholders.”

The deal represents a final chapter of sorts for the Nextel brand, which had been a trailblazer in the mobile market through its push-to-talk, walkie-talkie-style mobile service. This was was an early mover in the bigger wave of messaging services that competed with basic carrier SMS, and some came to think of it as the first mobile social network. Over time, though, the iDEN digital network that carried the service became outmoded and most carriers that offered iDEN-based services (including Nextel) discontinued them to focus on 3G and subsequent mobile technologies.

More generally, the acquisition underscores how a number of investors, willing to ride the waves of economic and political ups and downs in Latin America, continue to view the growth opportunities in the region.

NII — which is based out of Reston, VA — was traded on Nasdaq and had a market cap as of last market close, of just $322 million. The company currently has 3.3 million subscribers. But while it was reportedly looking for a buyer of the business in Brazil, its last remaining asset, for some time, this final price — at nearly three times its market cap — is a sign of how some might see locked up value in Nextel Brazil that exceeded all that.

Last week, Paypal and Dragoneer collectively committed $850 million towards MercadoLibre, a marketplace in Argentina. The week before that, SoftBank announced that it would set up a new $2 billion fund to invest in tech companies out of the region, and to help existing portfolio companies to expand there. (By coincidence, the SoftBank venture will be led by Marcelo Claure, who is also executive chairman of Sprint, which swallowed up the US part of Nextel years ago and eventually got acquired by SoftBank.)

18 Mar 2019

MySpace may have lost more than a decade’s worth of user music

It’s not as if the internet needed another cautionary tale about backing up data, but for many artists, this news is heartbreaking nonetheless. MySpace has issued a tersely worded message noting that a huge amount of user uploaded music has been lost during a server migration.

The once dominant social network posted a note on its site reading, “As a result of a server migration project, any photos, videos, and audio files you uploaded more than three years ago may no longer be available on or from MySpace. We apologize for the inconvenience.”

Users have been reporting issues with music uploaded between 2003 and 2015 for around a year now. We’ve reached out to MySpace for additional insight into the issue — and whether what could well be millions of tracks are indeed permanently lost in the digital ether. Honestly though, things don’t look too good for MySpace or music uploaders.

Some are understandably skeptical of the whole situation. Others are suggesting this be seen as a cautionary tale for those relying on more contemporary services to host their art. For many, however, it’s a huge segment of formative internet years seemingly wiped away like a sand castle in the tide.

MySpace was, of course, a major internet presence in the mid-aughts. The company was purchased by NewsCorp for $580 million in 2005, becoming the most visited site in the States around the same time. Six years later, it was sold for a mere $35 million, having since been eclipsed by Facebook.

In recent years, MySpace has attempted to pivot to a music-first site, with middling results. Nothing gold can stay, as the saying goes — and for now, at least, that appears to include the volumes of music once hosted on its servers.

18 Mar 2019

Apple launches new iPad Air and iPad mini

Apple has refreshed its iPad lineup with a press release. The company is (finally) updating the iPad mini and adding a new iPad Air. This model sits between the entry-level 9.7-inch iPad and the 11-inch iPad Pro in the lineup.

All new models now support the Apple Pencil, but you might want to double check your iPad model before buying one. The new iPad models released today work with the first-gen Apple Pencil, not the new Apple Pencil that supports magnetic charging and pairing.

So let’s look at those new iPads. First, the iPad mini hasn’t been refreshed in three years and a half. Many people believed that Apple would simply drop the model as smartphones get bigger. But the iPad mini is making a surprise comeback.

It looks identical to the previous 2015 model. But everything has been updated inside the device. It now features an A12 chip (the system on a chip designed for the iPhone XS), a 7.9-inch display that is 25 percent brighter, features a wider ranger of colors and works with True Tone. And it also works with the Apple Pencil.

Unlike with the iPad Pro, the iPad mini still features a Touch ID fingerprint sensor, a Lightning port and a headphone jack. You can buy it today for $399 for 64GB. You can choose to pay more for 256GB of storage and cellular connectivity. It comes in silver, space gray and gold.

Second, the iPad Air. While the name sounds familiar, this is a new device in the iPad lineup. When Apple introduced the new iPad Pro models back in October, Apple raised the prices on this segment of the market.

This new iPad Air is a bit cheaper than the 11-inch iPad Pro and looks more or less like the previous generation 10.5-inch iPad Pro — I know it’s confusing. The iPad Air now features an A12 chip, which should represent a significant upgrade over the previous generation iPad Pro that featured an A10X. The iPad Air works with the Smart Keyboard.

You can buy the device today for $499 with 64GB of storage. You can choose to pay more for 256GB of storage and cellular connectivity. It comes in silver, space gray and gold.

18 Mar 2019

Slack hands over control of encryption keys to regulated customers

Slack announced today that it is launching Enterprise Key Management (EKM) for Slack, a new tool that enables customers to control their encryption keys in the enterprise version of the communications app. The keys are managed in the AWS KMS key management tool.

Geoff Belknap, chief security officer (CSO) at Slack, says that the new tool should appeal to customers in regulated industries, who might need tighter control over security. “Markets like financial services, health care and government are typically underserved in terms of which collaboration tools they can use, so we wanted to design an experience that catered to their particular security needs,” Belknap told TechCrunch.

Slack currently encrypts data in transit and at rest, but the new tool augments this by giving customers greater control over the encryption keys that Slack uses to encrypt messages and files being shared inside the app.

He said that regulated industries in particular have been requesting the ability to control their own encryption keys including the ability to revoke them if it was required for security reasons. “EKM is a key requirement for growing enterprise companies of all sizes, and was a requested feature from many of our Enterprise Grid customers. We wanted to give these customers full control over their encryption keys, and when or if they want to revoke them,” he said.

Screenshot: Slack

Belknap says that this is especially important when customers involve people outside the organization such as contractors, partners or vendors in Slack communications. “A big benefit of EKM is that in the event of a security threat or if you ever experience suspicious activity, your security team can cut off access to the content at any time if necessary,” Belknap explained.

In addition to controlling the encryption keys, customers can gain greater visibility into activity inside of Slack via the Audit Logs API. “Detailed activity logs tell customers exactly when and where their data is being accessed, so they can be alerted of risks and anomalies immediately,” he said. If a customer finds suspicious activity, it can cut off access.

EKM for Slack is generally available today for Enterprise Grid customers for an additional fee. Slack, which announced plans to go public last month, has raised over $1 billion on a $7 billion valuation.

18 Mar 2019

Fifty years of the internet

When my team of graduate students and I sent the first message over the internet on a warm Los Angeles evening in October, 1969, little did we suspect that we were at the start of a worldwide revolution. After we typed the first two letters from our computer room at UCLA, namely, “Lo” for “Login,” the network crashed.

Hence, the first Internet message was “Lo” as in “Lo and behold” – inadvertently, we had delivered a message that was succinct, powerful, and prophetic.

The ARPANET, as it was called back then, was designed by government, industry and academia so scientists and academics could access each other’s computing resources and trade large research files, saving time, money and travel costs. ARPA, the Advanced Research Projects Agency, (now called “DARPA”) awarded a contract to scientists at the private firm Bolt Beranek and Newman to implement a router, or Interface Message Processor; UCLA was chosen to be the first node in this fledgling network.

By December, 1969, there were only four nodes – UCLA, Stanford Research Institute, the University of California-Santa Barbara and the University of Utah. The network grew exponentially from its earliest days, with the number of connected host computers reaching 100 by 1977, 100,000 by 1989, a million by the early 1990’s, and a billion by 2012; it now serves more than half the planet’s population.

Along the way, we found ourselves constantly surprised by unanticipated applications that suddenly appeared and gained huge adoption across the Internet; this was the case with email, the World Wide Web, peer-to-peer file sharing, user generated content, Napster, YouTube, Instagram, social networking, etc.

It sounds utopian, but in those early days, we enjoyed a wonderful culture of openness, collaboration, sharing, trust and ethics. That’s how the Internet was conceived and nurtured.  I knew everyone on the ARPANET in those early days, and we were all well-behaved. In fact, that adherence to “netiquette” persisted for the first two decades of the Internet.

Today, almost no one would say that the internet was unequivocally wonderful, open, collaborative, trustworthy or ethical. How did a medium created for sharing data and information turn into such a mixed blessing of questionable information? How did we go from collaboration to competition, from consensus to dissention, from a reliable digital resource to an amplifier of questionable information?

The decline began in the early 1990s when spam first appeared at the same time there was an intensifying drive to monetize the Internet as it reached deeply into the world of the consumer. This enabled many aspects of the dark side to emerge (fraud, invasion of privacy, fake news, denial of service, etc.).

It also changed the nature of internet technical progress and innovations as risk aversion began to stifle the earlier culture of “moon shots”. We are currently still suffering from those shifts. The internet was designed to promote decentralized information, democracy and consensus based upon shared values and factual information. In this it has disappointed to fully achieve the aspirations of its founding fathers.

As the private sector gained more influence, their policies and goals began to dominate the nature of the Internet.  Commercial policies gained influence, companies could charge for domain registration, and credit card encryption opened the door for e-commerce. Private firms like AOL, CompuServe and Earthlink would soon charge monthly fees for access, turning the service from a public good into a private enterprise.

This monetization of the internet has changed it flavor. On the one hand, it has led to valuable services of great value. Here one can list pervasive search engines, access to extensive information repositories, consumer aids, entertainment, education, connectivity among humans, etc.  On the other hand, it has led to excess and control in a number of domains.

Among these one can identify restricted access by corporations and governments, limited progress in technology deployment when the economic incentives are not aligned with (possibly short term) corporate interests, excessive use of social media for many forms of influence, etc.

If we ask what we could have done to mitigate some of these problems, one can easily name two.  First, we should have provided strong file authentication – the ability to guarantee that the file that I receive is an unaltered copy of the file I requested. Second, we should have provided strong user authentication – the ability for a user to prove that he/she is whom they claim to be.

Had we done so, we should have turned off these capabilities in the early days (when false files were not being dispatched and when users were not falsifying their identities). However, as the dark side began to emerge, we could have then gradually turned on these protections to counteract the abuses at a level to match the extent of the abuse. Since we did not provide an easy way to provide these capabilities from the start, we suffer from the fact that it is problematic to do so for today’s vast legacy system we call the Internet.

A silhouette of a hacker with a black hat in a suit enters a hallway with walls textured with blue internet of things icons 3D illustration cybersecurity concept

Having come these 50 years since its birth, how is the Internet likely to evolve over the next 50? What will it look like?

That’s a foggy crystal ball. But we can foresee that it is fast on its way to becoming “invisible” (as I predicted 50 years ago) in the sense that it will and should disappear into the infrastructure.

It should be as simple and convenient to use as is electricity; electricity is straightforwardly available via a trivially simple interface by plugging it into the wall; you don’t know or care how it gets there or where it comes from, but it delivers its services on demand.

Sadly, the internet is far more complicated to access than that. When I walk into a room, the room should know I’m there and it should provide to me the services and applications that match my profile, privileges and preferences.  I should be able to interact with the system using the usual human communication methods of speech, gestures, haptics, etc.

We are rapidly moving into such a future as the Internet of Things pervades our environmental infrastructure with logic, memory, processors, cameras, microphones, speakers, displays, holograms, sensors. Such an invisible infrastructure coupled with intelligent software agents imbedded in the internet will seamlessly deliver such services. In a word, the internet will essentially be a pervasive global nervous system.

That is what I judge will be the likely essence of the future infrastructure. However, as I said above, the applications and services are extremely hard to predict as they come out of the blue as sudden, unanticipated, explosive surprises!  Indeed, we have created a global system for frequently shocking us with surprises – what an interesting world that could be!