October 31, 2008 3:45 PM PDT

Google changes JotSpot privacy settings after complaint

by Elinor Mills
  • Font size
  • Print
  • 1 comment

(Credit: Google)

Google said Friday that it was modifying the privacy settings on its JotSpot online collaboration service after a researcher discovered that user e-mail addresses and names were being exposed to the Web without user consent.

Ben Edelman, Harvard Business School professor and security researcher, posted a blog entry on Thursday showing how JotSpot user names and e-mail addresses were easily accessible on Google search.

After being contacted by CNET News, Google issued a statement disavowing any responsibility by saying that the administrators of the JotSpot groups were responsible for setting the privacy controls. If the information was exposed on the Internet it was because the administrators had made it public.

Not satisfied with that response, Edelman pointed out the flaws with that excuse in an update to his original post.

JotSpot users didn't agree to have their names and e-mails made public and Edelman talked to several who said they indeed did not grant consent. Administrator permission is not sufficient to justify the practice, and administrators are not party to the privacy policy "contract" between JotSpot and the users, he added.

In addition, Edelman found that the language relaying this responsibility to administrators was not clear and likely led to administrators mistakenly exposing the information to the Web without meaning to.

"Google should prioritize defaults and options that accommodate reasonable users, reasonable administrators, and standard use cases," he wrote.

In other words, make the policy notice understandable and clear and make it rational. Clearly, those thousands of JotSpot users wouldn't have wanted to have their names and e-mail addresses exposed for strangers and spammers to see, even if the administrator of the group wanted it so.

In response, Scott Johnston, former vice president of products at JotSpot, sent an e-mail to Edelman outlining changes based on his feedback.

"Admins have always been in control of whether to make their wikis public or leave them set to private. JotSpot wikis are private by default, and unless an admin chooses to set it to public, none of the information in that wiki is publicly accessible," Johnston wrote.

"However, based on your feedback, we have taken action to improve the JotSpot user experience by setting the User Management page on all public JotSpot wikis to private, and we are in the process of removing these pages from our cache," the e-mail said. "All private wikis will be unaffected by this change, as their User Management pages have never been publicly accessible."

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Web-based Lookout protects mobile devices, data
Hackers claim to crack Kindle copyright armor
Using Facebook and Twitter safely
Report: FBI investigating Citibank cyberattack
White House appoints cybersecurity chief
So, is it safe to tweet now?
Twitter hijacked by 'Iranian Cyber Army'
Firefox, Adobe top buggiest-software list
Add a Comment (Log in or register)
by frasercrane November 1, 2008 3:34 AM PDT
Thank goodness there are guys like Edelman around who are persistent as well as alert.
Reply to this comment
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right