Thursday, April 22, 2010

Evaluation Criteria for Location Privacy

I ran across an interesting study the other day out of the U.C. Berkeley School of Information. The study considered the privacy provisions laid out in the W3C Geolocation API, and recommendations for its improvement. The Geolocation API is a part of the HTML5 specification, and as such will play an important role in location-based mobile web applications as mobile devices continue the rapid adoption of HTML5.

While the conclusions of the study were certainly excellent, I found most interesting the list of privacy-related criteria that were derived after considering a range of existing frameworks and standards. These are reprinted here:
  1. Appropriateness: Is the collection of location information appropriate given the context of the service or application?
  2. Minimization: Is the minimum necessary granularity of location information distributed or collected?
  3. User Control: How much ongoing control does the user have over location information? Is the user a passive receiver of notices or an active transmitter of policies? Are there defaults? Do they privilege privacy or information flow?
  4. Notice: Can requesters transmit information about their identity and practices? What information is required to be provided to the user by the requesting entity? What rules can individuals establish attach to their location information and transmit? Is there a standard language for such rules?
  5. Consent: Is the user in control of decisions to disclose location information? Is control provided on a per use, per recipient or some other basis? Is it operationalized as an opt-in, opt-out or opt model?
  6. Secondary Use: Is user consent required for secondary use (a use beyond the one for which the information was supplied by the user)? Do mechanisms facilitate setting of limits or asking permission for secondary uses?
  7. Distribution: Is distribution of location information limited to the entity with whom the individual believes they are interacting or is information re-transmitted to others?
  8. Retention: Are timestamps for limiting retention attached to location information? How can policy statements about retention be made?
  9. Transparency and Feedback: Are flows of information transparent to the individual? Does the speci cation facilitate individual access and related rights? Are there mechanisms to log location information requests and is it easy for individuals to access such logs?
  10. Aggregation: Does the standard facilitate aggregation of location information on specific users or users generally? Does the specification create persistent unique identifi ers?
When designing Veriplace, we considered these very same questions. In some cases (such as appropriateness and minimization) the application developer is largely in control of managing these issues. Veriplace addresses these cases by working with the developer, ensuring that guidelines such as these are followed. In other cases (such as user control, consent and transparency) Veriplace is more actively involved, building these requirements and safeguards directly into the platform architecture.

Taken together, this is a great list, and expands in important ways on existing guidelines, such as the CTIA Best Practices and Guidelines for LBS. Although perhaps an implementation detail, I might add one item: Uniform Privacy Management Interface. As LBS services proliferate, it will become more difficult for the end user to effectively manage location privacy. Providing a unified, consistent interface for managing access to location across services will be critical to ensuring the simplicity and transparency necessary to safeguard user privacy.

Scott

Thursday, March 25, 2010

Six things to know about remotely locating phones with Veriplace

1. Remote location APIs are great for server-based apps. Web sites; mobile web sites; apps written on platforms like Facebook or Salesforce; IVR and SMS apps. We get asked if remote location is useful for native mobile app development. The answer is, "it depends."

2. You can locate some phones for free. Others cost money. If you are content to focus on remotely locating smartphones, use our "Freedom Mode" (free for most developers). If you need more coverage or have other special needs, "Professional Modes" provide access to every phone on supported carriers (at a cost of pennies per locate).

3. Our APIs use OAuth. Veriplace treats location as a protected resource, something that requires permission from the user before it can be accessed. The OAuth protocol provides a framework for obtaining permission to access such protected resources. OAuth is becoming a well known standard, and library implementations are available for most development environments.

4. Locating somebody requires user consent. Always. Veriplace handles this for you. Your users will be asked - by us - whether they are comfortable sharing location with your app. Once you have permission, you won't have to ask again until the user revokes it.

5. Apps in development are restricted in who they can locate. We can't let the general public share their location with your app until it is certified. However, you can whitelist phones you want to use for testing purposes. You list the phone number in your developer account, and the corresponding user is given a chance to opt in to "developer mode." They can then share their location with your app.

6. The general public can begin sharing location with your app as soon as it's certified by Veriplace. Certification is usually quick and painless as long as you've followed guidelines and are transparent about how you are using location. When your app is ready, find the "publish app" link within the My Apps section of your developer account. We look forward to seeing what you have built!

Monday, March 22, 2010

T-Mobile joins Veriplace, 2/3 of all phones in the USA now locatable with a single API

T-Mobile is now the third major tier 1 carrier to go live on Veriplace, joining AT&T and Sprint. We are thrilled to bring this unprecedented capability to our developer partners.

You can immediately log into your Veriplace Developer Account at developer.veriplace.com and provision and locate T-Mobile test phones. Developer partners who have commercially deployed services can now add T-Mobile phones to their list of locatable devices… no additional work required.

As part of this launch, we have updated the Veriplace Developer Terms of Service. If you are already a Veriplace developer, your continued use of the Veriplace Location Platform indicates your acceptance of these updated Terms of Service.

If you're not yet a Veriplace developer, visit developer.veriplace.com to get started.

Wednesday, January 6, 2010

Veriplace gives developers access to AT&T location

Big news! As announced today at the AT&T Developer Summit in Las Vegas, AT&T is opening up access to their location infrastructure as part of a trial program with Veriplace.

Like many tier 1 carriers, AT&T has the ability to remotely locate any AT&T phone (see for example AT&T FamilyMap). AT&T is now making this capability available to third party developers via Veriplace. This more than doubles the number of phones locatable using Veriplace, bringing the total to around 130 million phones.

As noted in the official press release:

"By utilizing the carrier network, Veriplace allows for a background polling solution, enabling developers to write SMS, Web, WAP and IVR applications that can employ location information even when an application is not in use. For example, a customer who signs up for a mobile weather application can give the application permission to send alerts about approaching storms or severe conditions based on the customer’s location, even when the customer may not have the app actively running on the handset. Additionally, utilization of the carrier network allows devices to be located both indoors and outdoors, to varying degrees of accuracy."

Many will be interested to know that this announcement includes AT&T iPhones. iPhone developers no longer need an application running on the phone in order to locate it, which means ever-elusive "background location" is finally available to all iPhone developers. Developers who simply want to remotely locate iPhones can skip the Apple App Store process altogether.

The trial program will launch in the coming weeks for registered Veriplace developers. Visit developer.veriplace.com to get started.

Friday, October 2, 2009

Oct 7 presentation on location-enabling Enterprise Services

Veriplace is helping to location-enable enterprise services. Our CTO Scott Hotes presents at the Location Intelligence Conference 2009 in Westminster, Colorado, October 7th. As he will demonstrate during his session, the Veriplace Location Platform makes it easy for enterprise developers to incorporate mobile location data into their applications:

Enterprise services can benefit greatly from access to device location. The challenge for the developer is that accessing location is often operator-specific. Doing individual deals with each operator individually is expensive and time-consuming. Veriplace provides a single, secure interface for accessing location across all operators and location technologies. In this presentation we will walk step-by-step through the process of location-enabling your Web, mobile-Web, SMS and mobile-resident service.

Through a single interface, participants will learn how to access location across mobile operators and location technologies.

Monday, September 28, 2009

Veriplace at Microsoft's Mobile Incubation Week

We're in D.C. this week, taking part in Microsoft's Mobile Incubation Week. It's a great opportunity to pepper Microsoft engineers with questions, while showing off how easy it is for developers to location-enable their applications with our network-based APIs.

Beneath the hood, the Veriplace Location Platform has to use different techniques to locate different types of phones. Locating a Windows Mobile phone differs from locating a BlackBerry, which in turn differs from locating an entry-level Sprint feature phone. There are as many subtle details as there are OS versions, manufacturers, and carriers.

The Veriplace Location Platform simplifies this for you, the developer. By writing to the Veriplace API, you let us worry about the type of phone your user has and how to locate them. Furthermore, as indicated by our presence in D.C. this week, you can write to our API knowing that we're always out there keeping up with the latest developments in location technologies and phone operating systems. Our continuing mission is to be the location experts.

If you happen to be a developer in the D.C. area, drop us a line!

Tuesday, September 1, 2009

Upcoming appearances at Mobilize and MetaPlaces conferences

Our CEO Tasso Roumeliotis will be at Mobilize 09 on September 10 in San Francisco. He'll be sharing his thoughts as a panel member for the "Location: Context is Money" session.

We'll also be at MetaPlaces09 in San Jose September 22-23 as both a participant and platform sponsor for the conference.

Drop us a line if you'd like to connect!

Tuesday, June 23, 2009

The first of many: uShip launches

We're extremely pleased today to announce that uShip is the first 3rd party to use the Veriplace Location Platform and WaveMarket's carrier connections to obtain location information from mobile phones.

As explained in today's press release, uShip is "the first and largest online marketplace for shipping and transportation services.... Using Veriplace, uShip customers can now track the exact location of their shipments – not just intermittent check points – bringing a new level of transparency not seen in the shipping industry."

Visit developer.veriplace.com to learn how you can location-enable your own site or service with real location info from mobile phones.