<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Steve Nimmons &#187; Social Networking</title>
	<atom:link href="http://stevenimmons.org/tag/social-networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://stevenimmons.org</link>
	<description>At the intersection of science, technology, engineering and politics</description>
	<lastBuildDate>Thu, 09 Feb 2012 06:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
		<item>
		<title>Online Privacy, Extending the Johari Window</title>
		<link>http://stevenimmons.org/2012/01/online-privacy-extending-the-johari-window/</link>
		<comments>http://stevenimmons.org/2012/01/online-privacy-extending-the-johari-window/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 07:30:00 +0000</pubDate>
		<dc:creator>Steve Nimmons</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Systems Thinking]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[Online Privacy]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[SNA]]></category>
		<category><![CDATA[Social Network]]></category>
		<category><![CDATA[Social Network Analysis]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://stevenimmons.org/2012/01/online-privacy-extending-the-johari-window/</guid>
		<description><![CDATA[Extending the Johari Window: An online privacy thinking framework.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstevenimmons.org%2F2012%2F01%2Fonline-privacy-extending-the-johari-window%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstevenimmons.org%2F2012%2F01%2Fonline-privacy-extending-the-johari-window%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><em>Figure 1 – The Johari Window devised by Joseph Luft and Harry Ingham</em></p>
<p><a href="http://stevenimmons.org/wp-content/uploads/2012/01/johari-window.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="johari window" src="http://stevenimmons.org/wp-content/uploads/2012/01/johari-window_thumb.png" border="0" alt="johari window" width="591" height="322" /></a></p>
<p>The <a href="http://en.wikipedia.org/wiki/Johari_window" target="_blank">Johari Window</a> is a model for describing personal awareness types and human interaction.</p>
<p><strong>Quadrant A:</strong> encapsulates personal awareness and a wish to share information with others, for the purposes of simplicity assume this means publicly.</p>
<p><strong>Quadrant B:</strong> encapsulates personal awareness of a different type. The motivations for concealment are plentiful (bad habits, competitive advantage, Machiavellianism, protection of personal interests etc.). The size of this box tends to diminish as trust relationships expand, however I contend: a) there are many types and levels of concealment implied here and b) many different levels of trust in different social circles.</p>
<p><strong>Quadrant C: </strong>encapsulates weak personal awareness and misinterpretation (we assume others see us as we see ourselves, but this is not the case). This quadrant (in the context of Social Networking) provides an interesting opportunity for introspection and awareness development from social feedback, <a href="http://en.wikipedia.org/wiki/Social_network" target="_blank">Social Network Analysis</a> and <a href="http://en.wikipedia.org/wiki/Sentiment_analysis" target="_blank">sentiment analysis</a>. This is a box full of brambles!</p>
<p><strong>Quadrant D:</strong> Donald Rumsfeld’s infamous <a href="http://en.wikipedia.org/wiki/There_are_known_knowns" target="_blank">Known Knowns</a> speech of 2002 sums up this quadrant.</p>
<h2>A Prophetic View</h2>
<p>Just under two years ago I wrote a somewhat prophetic article concerning <a href="http://blog.atos.net/2010/01/25/the-problem-with-privacy-and-social-networks/" target="_blank">Privacy and Social Networks</a> in which I argued for the need for additional privacy controls and multiple walled gardens within social networks. Facebook lists were a crude approximation, but Goolge+ Circles now excel at delivering the concept. A sister post in February 2010 discussed <a href="http://blog.atos.net/2010/02/12/social-search-and-the-integrity-of-the-social-graph/" target="_blank">Social Search and the Integrity of the Social Graph</a>, concluding that Google was heading (with purpose) into the Social Networking space.</p>
<p><a href="http://blog.atos.net/2010/01/25/the-problem-with-privacy-and-social-networks/" target="_blank">What I said back in January 2010</a>:</p>
<blockquote><p>Visualisation of Social Network privacy controls is poor. The granularity of access controls is too coarse. My solution would be creation of (either my privacy “Onion model”) or perhaps more simply a ‘radar’ or quadrant model on which connections could be placed within ‘trust zones’ (by dragging and dropping them onto the appropriate region). Configuration is half the battle, and visualisation of the resultant privacy controls effect is essential. This is where current controls are weakest. I also want multiple walled gardens to play with (where I could segregate user groups) and ensure no (uncontrolled) information leakage between…</p></blockquote>
<blockquote><p>A trust and privacy ‘radar’ would be equally interesting, with those closest to the centre having the greater trust relationship and access to more personal data.</p></blockquote>
<h2>The Johari Window and Google+ Circles</h2>
<p><em>Figure 2 – The Google+ Circle Model</em></p>
<p><a href="http://stevenimmons.org/wp-content/uploads/2012/01/circles.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" title="circles" src="http://stevenimmons.org/wp-content/uploads/2012/01/circles_thumb.png" border="0" alt="circles" width="600" height="195" /></a></p>
<p>I have a number of Circles within Google+: Friends, Family, Acquaintances, Scientific Community, Social Media, Politics, Techies etc. There is also a ‘Public category’ which maps neatly onto Quadrant A of the Johari Window.</p>
<p>Quadrant B maps neatly to the different circles (Friends, Family etc.). This creates controlled separation, where I can isolate various topic discussions. This helps prevent Family members from being bored by discussions about Social Network Analysis or Social Psychology! Equally it saves Scientific Community colleagues reading my latest views on the European Union. There is a great deal more depth to this than simple ‘separation of interests.’ Despite what we may think, as multi-dimensional beings, we do not necessarily want everyone in cyberspace or our social sphere having a complete 360 degree view of our personality, interests or social connections.</p>
<p>Quadrant C could make for a ‘fun’ social network game – tell me something about myself that I don’t know, but you do know. Play at your own risk!</p>
<p>Quadrant D is ripe for <a href="http://en.wikipedia.org/wiki/Reality_mining" target="_blank">Reality Mining</a> as long as there is a digital footprint.</p>
<p>The Johari Window provides an interesting thinking framework on which to base an approach to online privacy protection and information sharing across social groups.</p>
<h2>Extending the Johari Window for Privacy and Reputation Protection</h2>
<p>I propose an extension to the Johari Window (as depicted in Figure 3). As information flows into a Circle we lose control of it. We must assume that we have chosen Circle members well and that each member will understand (and abide) by our privacy wishes in respect of that information. The obvious drawback however is that there is no adequate meta-data associated with the shared information to indicate to Circle members what is ‘allowable’. Perhaps Google will introduce ‘Circle Contracts’ to stipulate between parties what is acceptable!</p>
<p>Adding an A+ <span style="background-color: #ffff00;"> </span><span>box (Figure 3) </span><span style="background-color: #ffff00;"> </span>recognises that there will be information which I am happy to be disclosed by people acting as relays between Circles with no restrictions.</p>
<p><span>Box </span>B+ recognises information disclosed to certain Circles must stay within that Circle or may be selectively disclosed to other Circles (not under my ownership) which meet certain membership/privacy criteria. There is currently however no way to express this (or manage disclosure across ‘logically chained Walled Gardens’).</p>
<p><span>Box</span> C+ recognises that there is information about myself of which I am unaware, and would be happy about being disclosed. If it is information which may be publicly disclosed, it fits within box A. If it requires restriction per &#8216;Walled Garden’ or Circle, it fits within box B.</p>
<p><span>Box</span> C++ recognises that there is information about myself of which am I unaware, and would be unhappy about being disclosed. This box is ripe for Reputation Protection.</p>
<p><span>Boxes C+ and C++</span> are interesting as I would be theoretically unaware of my privacy requirements until the information is disclosed (of course heuristics could be employed).</p>
<p><span>Boxes</span> B, B+, C, C+ and C++ all have potential for information leakage. As Circles and Networks are highly interconnected, chances are the information could reach parties which you would rather not see it.</p>
<p>Extending the Johari Window and applying this thinking technique to online privacy within Social Networks is useful in terms of surfacing complexity and also challenging personal views of requirements for information management.</p>
<p><em>Figure 3 – Extending the Johari Window</em></p>
<p><em>[source: <a title="Steve Nimmons" href="http://en.wikipedia.org/wiki/Steve_Nimmons" target="_blank">Steve Nimmons</a>]</em></p>
<p><a href="http://stevenimmons.org/wp-content/uploads/2012/01/johari-window-extended.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="johari window extended" src="http://stevenimmons.org/wp-content/uploads/2012/01/johari-window-extended_thumb.png" border="0" alt="johari window extended" width="564" height="459" /></a></p>
 
<span class = "" style = " "><iframe src="http://www.facebook.com/plugins/like.php?href=http://stevenimmons.org/2012/01/online-privacy-extending-the-johari-window/&layout=box_count&send=false&show_faces=false&width=&action=like&colorscheme=light&font=" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:px; height:px"></iframe></span><img src="http://stevenimmons.org/wp-content/plugins/pixelstats/trackingpixel.php?post_id=632&amp;ts=1328840798" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://stevenimmons.org/2012/01/online-privacy-extending-the-johari-window/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Problem with Privacy and Social Networks</title>
		<link>http://stevenimmons.org/2010/01/privacy-and-social-networks-on-atos-origin-blog/</link>
		<comments>http://stevenimmons.org/2010/01/privacy-and-social-networks-on-atos-origin-blog/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 10:36:11 +0000</pubDate>
		<dc:creator>Steve Nimmons</dc:creator>
				<category><![CDATA[Editors Choice]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Network]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://stevenimmons.org/?p=242</guid>
		<description><![CDATA[Steve Nimmons writing on the Atos Origin CIO / CTO blog seeks to tame the Privacy Chimera of Social Networking.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fstevenimmons.org%2F2010%2F01%2Fprivacy-and-social-networks-on-atos-origin-blog%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fstevenimmons.org%2F2010%2F01%2Fprivacy-and-social-networks-on-atos-origin-blog%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>“Privacy is an onion” (patent pending maxim); it is situational, temporal and multi-dimensional. Perhaps said axiom should be recast as a ‘genetically modified onion’.</p>
<p>Perusing articles on Facebook privacy control changes from a well-known security company, there is the revelation that “no private information should be on the Internet”. A wise statement for an information security purist, but what constitutes ‘private information’, to what degree is it fluid and are the controls within Social Networks sufficient to allow us to restrict access in the ways we demand / require? What are the ’sociological norms’, and what of ’super-social’ libertines (such as I) that have exceeded Dunbar’s Number by a magnitude of 700%?</p>
<p>How does information aggregation affect risk and perception of privacy control – are we at risk through inference channels in the Social Network? How do we perceive and manage trust? With rigour, paranoia, neutrality; is it earned, easily lost. How do we convey this and ensure our privacy is being managed accordingly? This brief set of questions hints at the complexity: cultural and emotional; qualitative; psychological; behavioural that guides our experiences online. Are Social Networks really equipped to meet sophisticated information management demands from a savvy user-base? How will they augment existing controls to facilitate virtual world technologies and context aware devices that would provide further “locational” (excuse the Social Computing neologism) and situational information?</p>
<p>Today’s Social Network (I take Facebook as a pervasive example) is a walled-garden (in general terms). Most users create a ‘private’ profile and control access by granting or denying friend requests, which can then (by and large) see profile information, pictures, status updates and other friend connections (there are nuances, but for brevity I generalise). My ‘bug bear’ with this model is a) poor visualisation of what effect the setting of privacy attributes has b) it’s not more walls we need, it’s more gardens! I shall elaborate on my latter ethereal viewpoint. Going back to trust, you may trust someone implicitly in the office, but don’t want to entrust them with private information in a personal Social Network. Trust and privacy are also really inter-woven concepts. There are also gradations of trust. For example I might trust someone based on their profession (doctor, airline pilot), but there is a limitation in the trust.</p>
<p>I might trust someone with another career background differently, or the trust may be quite neutral. We need more trust and privacy zones (which need to be explicitly defined and explicitly visible) to place individual connections inside a more sophisticated information handling model within the Social Network. In a rudimentary sense this exists with “Friend’s Lists”. These can be created in Facebook and ‘friends’ added to multiple lists which can then be used to permit or deny access to information at a group level. I term this ‘rudimentary’ as the configuration is somewhat arcane, and the visualisation of the result is best described as disappointing, a point to which I shall return.</p>
<p>Aggregation of information and how this affects risk exposure and privacy concerns are also interesting. Simplistically it might be argued “have a sparse profile with little personal information and this is a non-issue”. Whilst logical from a simplistic perspective, consider the aggregation of information from interaction, commentary, and chat services (etc.) and over time information aggregation becomes an increasing concern. I have also (of late) been thinking about the risk of “Inference Channels” in Social Networks. Database and data mining “theorists” will be familiar with this concept. Without diving into a treatise on Claude E Shannon and Entropy Theory, suffice to say this is concerned with deducible links through network connections and whether knowing about a set of relationships (perhaps even individual pieces of personal information) could lead to the discovery of inferred or elicited relationships or information. This may of course be entirely benign, but the Inference Channel has an implied risk that ‘unknown information’ will be discovered through analysis of multiple relationships (as I mention a known concern in highly secure database systems). A subject on which I have written (at some length) is also the opportunity for Social Engineering and leveraging elicited information for nefarious purposes. I am satisfied that the corporate world is generally cognizant of such risk, but wonder if more could be done in terms of “general public education.”</p>
<p>Risks have a tendency to multiply rather than divide, and the unrelenting pace of Social Network development leads me to concerns over a number of “emerging technologies”. Those that read my recent predictions on Social Network developments will have noted my belief that virtual world technologies will augment the rather unsophisticated and stifled ‘networking’ model that we have today. Context Aware devices will provide further enrichment, but both enrich not only networking experience but also the quality of personal information (now situational) that might ‘leak’. The Social Network’s model for configuring privacy controls, defining trust relationships and visualising the result is not equipped for this (I think it barely struggles with today’s limited demands).</p>
<p>Control, visualisation, predictability have been central themes of my ‘critique’ of existing offerings. I therefore close by suggesting a few improvements and opportunities for development and research in this area:</p>
<ol>
<li>Visualisation of Social Network privacy controls is poor. The granularity of access controls is too coarse. My solution would be creation of (either my GM Onion model) or perhaps more simply a ‘radar’ or quadrant model on which connections could be placed within ‘trust zones’ (by dragging and dropping them onto the appropriate region). Configuration is half the battle, and visualisation of the resultant privacy controls effect is essential. This is where current controls are weakest. I also want multiple walled gardens to play with (where I could segregate user groups) and ensure no (uncontrolled) information leakage between. So my ‘quadrant model’ needs to work in three dimensions!</li>
<li>A trust and privacy ‘radar’ would be equally interesting, with those closest to the centre having the greater trust relationship and access to more personal data.</li>
<li>Inference Channels are ‘tricky’ due to the myriad of links, attributes and permutations affecting such. I continue to read widely on the subject and would welcome comments on how this might be best addressed. One area that would be interesting to research further would be ‘real-time risk advisors’ (as an example) on chat services seeking to warn users when the aggregation of personal information across “conversations” reaches a certain threshold. This would have numerous applications.</li>
</ol>
<p>Finally, I hope my musings have not dissuaded anyone from participating in ’speculative networking’. We don’t agonise over privacy concerns before exchanging business cards, so with a degree of care and attention pro-active and speculative Social Networking can be beneficial. But remember, I am a self-confessed libertine!</p>
<p><a title="Privacy and Social Networks, by Steve Nimmons" href="http://blog.atosorigin.com/2010/01/the-problem-with-privacy-and-social-networks/" target="_blank">This article first appeared</a> on the <a title="Steve Nimmons on the Atos Origin CIO Blog" href="http://blog.atosorigin.com/author/steve-nimmons/" target="_blank">Atos Origin CIO / CTO Blog</a> in January 2010.</p>
 
<span class = "" style = " "><iframe src="http://www.facebook.com/plugins/like.php?href=http://stevenimmons.org/2010/01/privacy-and-social-networks-on-atos-origin-blog/&layout=box_count&send=false&show_faces=false&width=&action=like&colorscheme=light&font=" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:px; height:px"></iframe></span><img src="http://stevenimmons.org/wp-content/plugins/pixelstats/trackingpixel.php?post_id=242&amp;ts=1328840798" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://stevenimmons.org/2010/01/privacy-and-social-networks-on-atos-origin-blog/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

