How Well Do Tech Companies Protect Your Data From Snooping? | WAMU 88.5 - American University Radio
Filed Under:

How Well Do Tech Companies Protect Your Data From Snooping?

Play associated audio

What happens to your information online? Is it safe? Is it private?

The answers depend in part on what services you use. So we set out to help you figure out the answers for yourself.

But you may have noticed there is a lot of stuff on the Internet and I am sorry to say we didn't test it all.

Fortunately for you, we are not the only ones asking these questions. The Electronic Frontier Foundation surveyed big tech companies and asked them what kinds of encryption they've been using. And last week Google started naming and shaming email providers who were not encrypting email messages as they passed between companies.

We drew on their efforts and our own results to build this chart.

Enjoy. [And if you are wondering what HSTS or what those percentages mean, there is an explanation at the bottom of the post.]

Now where did I put my invisibility cloak?

Update at 11:44 a.m. ET: Apple Now Says It Working To Encrypt Email Between Providers

The Electronic Frontier Foundation has asked service providers to implement strong encryption. Here's what the EFF wants:

HTTPS by default. This means that when you connect to a website, it will automatically use a channel that encrypts the communications from your computer to the website.

HSTS (HTTP Strict Transport Security). Lots of services offer encrypted and unencrypted versions of the same website or service. HSTS basically forces the service to always use the encrypted secure option.

Forward secrecy. Sometimes called perfect forward secrecy, it uses a different cypher or code to encrypt messages on each session. This means that if the NSA or someone else cracks the code keeping one of your messages secure they can't unravel everything you have ever written.

STARTTLS. If you are on Gmail and send me a message at my Yahoo account, those two email providers have to talk to each other. STARTTLS lets companies encrypt those messages in transit. But it is only possible if both companies use it. It takes two to tango — and Google recently started naming and shaming companies that are refusing to do this dance.

Encrypting email in transit. Lots of companies have announced this year that they will add encryption to their networks — including when they are sending email back and forth to other service providers. For this to work both companies have to use encryption.

But, unfortunately, saying you'll do something and actually doing it are two different things. Google has started publishing the percentage of email it sends and receives from other providers which is actually encrypted. You'll see the numbers are all over the map. But one thing is clear: A lot more email traffic is encrypted today than a year ago and since Google started publishing these numbers the figures have shot up.

Ahh, transparency.

So, how did we pick what companies to test? We picked services we used or where we had interesting data and something to useful to say.Largely this is stuff we use and were curious about.

Aren't Skype and WhatsApp owned by other companies? Yes, well almost. Microsoft owns Skype and Facebook's acquisition of WhatsApp hasn't closed yet. But we tested these services independently because mergers don't necessarily change how a company's technology works.

Copyright 2014 NPR. To see more, visit http://www.npr.org/.

NPR

Fresh Air Weekend: Toni Morrison, Ross Macdonald's Crime Fiction, Will Forte

Nobel laureate Morrison reflects on her life and her regrets; Maureen Corrigan reviews a reissue of four of Macdonald's 1950s novels; SNL alum Forte discusses comedy and Bruce Dern's acting advice.
NPR

PepsiCo Swaps Diet Drink's Aspartame For Other Artificial Sweeteners

The company says Diet Pepsi consumers are concerned about aspartame. But the Food and Drug Administration has long affirmed that the sweetener is safe in amounts commonly used by beverage companies.
NPR

Surgeon General Vivek Murthy On Gun Control, Vaccines And Science

Surgeon General Vivek Murthy was officially sworn in this week. His confirmation was held up for more than a year because of comments he made about gun violence. Murthy talks with NPR's Scott Simon.
NPR

As Health Apps Hop On The Apple Watch, Privacy Will Be Key

The notion of receiving nutrition advice from artificial intelligence on your wrist may seem like science fiction. But health developers are betting this kind of behavior will become the norm.

Leave a Comment

Help keep the conversation civil. Please refer to our Terms of Use and Code of Conduct before posting your comments.