New Study Shows Anonymous Data Isn't Very Anonymous At All

from the hear-that? dept

We've pointed out time and time again that there's really no such thing as an anonymized dataset. Given the data, it's almost always easy enough to at least connect some of it back to a real person. It looks like there's now some research to support that. Steven Hoy points us to a new paper where some researchers wrote an algorithm that takes anonymized data from social networks and connects it back to names and addresses of individuals:
We present a framework for analyzing privacy and anonymity in social networks and develop a new re-identification algorithm targeting anonymized social-network graphs. To demonstrate its effectiveness on real-world networks, we show that a third of the users who can be verified to have accounts on both Twitter, a popular microblogging service, and Flickr, an online photo-sharing site, can be re-identified in the anonymous Twitter graph with only a 12% error rate.
Basically, the researchers are saying that anonymized data isn't really anonymous -- and social networks that insist they're "safe" because they've anonymized the data are being somewhat disingenuous.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

Filed Under: anonymity, anonymous data, social networks


Reader Comments

Subscribe: RSS

View by: Time | Thread


  • identicon
    Weird Harold, 27 Mar 2009 @ 3:02pm

    Nowhere to hide!

    Ha!

    You insipid little runts will pay for all the mean-spirited things you've been saying about me. It looks like you can't hide behind your little netwalls after all.

    I'll see you in hell, punks!

    wh

    link to this | view in chronology ]

  • identicon
    TheStuipdOne, 27 Mar 2009 @ 3:11pm

    Isn't that difficult

    Take for instance me on this site. While I acknowledge that IP address isn't anonymous if you just use geographic information from the IP you can get a pretty good idea of who I am.

    When I post on this site from work the IP logging would see an IP from corporate headquarters (I think). When I post from home you'd see the IP from my home. Knowing that from my posts what profession I'm in it wouldn't be too difficult to find a company headquarterd in area A with an office in area B that does the type of work I claim to be doing.

    So while this example doesn't give my name and address it does show more information than I've posted to this site to anyone who cares to look

    link to this | view in chronology ]

    • identicon
      ehrichweiss, 27 Mar 2009 @ 3:36pm

      Re: Isn't that difficult

      It's more than that though.

      What they found was that people tend to have the same groups of friends, even when they're "anonymous", and that by analyzing the groups of friends on different social sites combined with a few other tell tale signs, you can narrow down who they are 2 out of 3 times.

      I should have published on this years ago cause I've hunted people down in this manner for ages. It's not that difficult but it does require patience and some ability to use logic, as well as a keen understanding of human nature. Each piece of information is a new stepping stone to the next and eventually yields the ultimate goal.

      link to this | view in chronology ]

  • identicon
    AOL, 27 Mar 2009 @ 4:56pm

    Search

    Your anonymized dataset is safe with us.

    link to this | view in chronology ]

  • identicon
    AllXClub, 27 Mar 2009 @ 5:54pm

    Anonymous Data

    Your data is safe with us. AllXClub is totally confidential, and private. You can read more about allxclub and how important the confidentiality is at http://www.callxclub.com or more not so confidential information about the new mlm allxclub at http://www.callxclub.blogspot.com Why pay to play, when you can play and get paid?

    link to this | view in chronology ]

  • identicon
    Twin, 29 Mar 2009 @ 1:12am

    Hm.

    Well, *duh*.

    link to this | view in chronology ]

  • identicon
    Twin, 29 Mar 2009 @ 1:13am

    Clarification

    Post 10, I think post 9 was in the "satire" category...

    link to this | view in chronology ]

  • identicon
    Ray, 29 Mar 2009 @ 7:28pm

    Hide-n-go-seek?

    It appears, and I say 'appears' advisably since they have not posted the full results, that the more sites you post on that sell your "anonymized" information, then the better the chance that you can be matched up with what you might consider your private data.

    Really nothing new about this if that is true, it is a standard spy methodology used to identify what is going on someplace, just get a lot of data points and see what the pattern is. First saw the affects of that back in the late 70's when the monitoring of CB radios (about half the unit used them) and the telephones gave away the supposedly secret plans for a military training operation that most of us only knew tiny pieces of prior to the exercise. Or in the late 80's a security test group identified what was going on in a supposedly secret building by using license plates, normal phone listening, and hanging around local businesses people went to for lunch and drinks.

    So the next question is, what happens if you use a different IP address (not the same company/town, but a different company which has a different town listed), and a different user name for each social site? I think (but would not bet on it) that it would be much harder to cross-reference without analyzing postings carefully over a long period of time, not impossible since most people have unique habits that act like a signature.

    link to this | view in chronology ]

  • identicon
    Anonymous Coward, 29 Mar 2009 @ 7:52pm

    Below you will find the real names, addresses, phone numbers, and adjusted income for the 13 posters above.
    1. XXXX
    ...
    13. XXX

    [deleted by moderator]

    :-)

    link to this | view in chronology ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.