Follow EFF's service guidelines, and advertise that we do

Bug #487200 reported by Chad Miller
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu One Servers
Confirmed
Wishlist
Unassigned
unity-lens-shopping
New
Undecided
Unassigned

Bug Description

Ubuntu should be obvious choice for people who don't trust MSFT and APPL on privacy and security grounds. We should minimize leakage of data into our hosted environments, and make sure our online services are not the weakest point.

Let's follow EFF's service guidelines.

http://www.eff.org/wp/osp

Summary of Recommendations

   1. Develop procedures for dealing with legal information requests and providing notice to users.
   2. Work with both attorneys and engineers to develop a privacy policy that fits your OSP’s practices.
   3. Collect the minimum amount of information necessary to provide OSP services.
   4. Store information for the minimum time necessary for operations.
   5. Effectively obfuscate, aggregate and delete unneeded user information.
   6. Maintain written policies addressing data collection and retention.
   7. Enable SSL as much as possible throughout your site to secure users’ information and communications.
   8. Understand threats to the security of sensitive information and communications on your systems, and mitigate them appropriately.
   9. Follow best-practice principles for the use of cookies on your site.
  10. Insist that the OSPs and other service providers you work with observe these best practices, too.

Chad Miller (cmiller)
description: updated
tags: added: eff-guidelines
Changed in ubuntuone-servers:
status: New → Confirmed
assignee: nobody → Ubuntu One Ops+ team (ubuntuone-ops+)
tags: added: ops+
Chad Miller (cmiller)
information type: Private → Public
Revision history for this message
Chad Miller (cmiller) wrote :

unity-shopping-lens is not tagged for its source code, but to track its anonymization service to more upstreams.

Revision history for this message
Chad Miller (cmiller) wrote :

I don't have a way to track our NTP servers. Let's make sure those never keep more than aggregate information about presence of users.

description: updated
Curtis Hovey (sinzui)
Changed in ubuntuone-servers:
assignee: Registry Administrators (registry) → nobody
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.