<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>unitstep.net &#187; aol</title>
	<atom:link href="http://unitstep.net/blog/category/aol/feed/" rel="self" type="application/rss+xml" />
	<link>http://unitstep.net</link>
	<description>the home of peter chng</description>
	<pubDate>Tue, 18 Nov 2008 02:09:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<item>
		<title>AOL search query data release: The aftermath</title>
		<link>http://unitstep.net/blog/2006/08/08/aol-search-query-data-release-the-aftermath/</link>
		<comments>http://unitstep.net/blog/2006/08/08/aol-search-query-data-release-the-aftermath/#comments</comments>
		<pubDate>Wed, 09 Aug 2006 00:44:11 +0000</pubDate>
		<dc:creator>Peter Chng</dc:creator>
		
		<category><![CDATA[aol]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[search engine]]></category>

		<guid isPermaLink="false">http://unitstep.net/blog/2006/08/08/aol-search-query-data-release-the-aftermath/</guid>
		<description><![CDATA[As expected, there has been much discourse following AOL&#8217;s release of the search query records of 650,000 of their users over a three-month period.  After the publically-released data (which was originally put up for research purposes, with no ill intent), was discovered by a blogger, news subsequently spread throughout the online communities, prompting many [...]]]></description>
			<content:encoded><![CDATA[<p>As expected, there has been much discourse following <a href="http://unitstep.net/blog/2006/08/07/aol-releases-search-queries-for-650000-users-in-blatant-disregard-for-privacy/">AOL&#8217;s release of the search query records</a> of 650,000 of their users over a three-month period.  After the publically-released data (which was originally put up for research purposes, with no ill intent), was discovered by a blogger, news subsequently spread throughout the online communities, prompting many people to download the data and AOL to eventually pull the data from their site.  However, some of those who had already got the data began to offer it up for download, either from their servers or through Bittorrent, providing a very good example of &#8220;letting the cat outta the bag&#8221;. </p>
<h3>No end to the data</h3>
<p>Traditional news began covering the story today, with even <a href="http://www.time.com/time/business/article/0,8599,1224405,00.html">TIME magazine</a> penning a little piece about the incident and its relation with privacy rights, or the lack thereof.  Other people have been more enterprising, with <a href="http://www.techcrunch.com/2006/08/08/aol-data-first-web-interfaces-up/">someone setting up</a> <a href="http://www.aolsearchdatabase.com/">an online, searchable database</a> of the results, thus saving people the time of importing all the data into their own DBMS.  </p>
<p>After it was discovered that users were apparently searching for <a href="http://plentyoffish.wordpress.com/2006/08/07/aol-search-data-shows-users-planning-to-commit-murder/">&#8220;how to kill your wife&#8221;</a>, ValleyWag set up a <a href="http://valleywag.com/tech/aol/find-the-scariest-aol-user-search-record-192602.php">contest to find</a> the scariest search record.  Apparently, the online community&#8217;s appetite for the grotesque is insatiable.</p>
<p>Even more interesting were some of the <a href="http://www.valleywag.com/tech/aol/scariest-search-records-aol-saves-crew-of-oceanic-flight-815-192860.php">results  from the contest</a>: Someone apparently submitting a search query that looked very much like a &#8220;message in a bottle&#8221; of a castaway stranded on an island.  ValleyWag suspects a viral marketing campaign for the TV series <cite>Lost</cite>.  Or, maybe someone is actually stranded on an island in the South Pacific with a laptop and WiFi access - though that wouldn&#8217;t be such a bad life!</p>
<h3>Changes upcoming</h3>
<p>With all the bad publicity AOL has been getting as of late (problems with cancelling customer accounts, workforce reductions, etc.), this leak could not have come at a worse time.  Further complicating the situation is the fact that bloggers spread the information like wildfire, and helped the data get into wide release.  In fact, the previously mentioned <a href="http://www.aolsearchdatabase.com/">AOL Search Database</a> is in violation of the user agreement that came with the search data - it states that the information provided is only to be used for non-commercial (research) purposes.  The search database site is clearly displaying ads and the owner hoping to profit from it.</p>
<p>Companies are going to tighten up their policy on data release, and I wouldn&#8217;t expect any of them to be releasing data to the research community any time soon.  At the very least, the way they deal with search records will be kept even more discreet.</p>
<hr/>Copyright &copy; 2008 <strong><a href="http://unitstep.net">unitstep.net</a></strong>. This Feed is for personal non-commercial use only. If you are not reading this material in your news aggregator, the site you are looking at is guilty of copyright infringement. Please contact <strong><a href="mailto:webmaster@unitstep.net">webmaster@unitstep.net</a></strong> for more information.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">Plugin</a> by <a href="http://www.taragana.com/">Taragana</a></span>]]></content:encoded>
			<wfw:commentRss>http://unitstep.net/blog/2006/08/08/aol-search-query-data-release-the-aftermath/feed/</wfw:commentRss>
		</item>
		<item>
		<title>AOL releases search queries for 650,000 users in blatant disregard for privacy</title>
		<link>http://unitstep.net/blog/2006/08/07/aol-releases-search-queries-for-650000-users-in-blatant-disregard-for-privacy/</link>
		<comments>http://unitstep.net/blog/2006/08/07/aol-releases-search-queries-for-650000-users-in-blatant-disregard-for-privacy/#comments</comments>
		<pubDate>Mon, 07 Aug 2006 17:33:59 +0000</pubDate>
		<dc:creator>Peter Chng</dc:creator>
		
		<category><![CDATA[aol]]></category>

		<category><![CDATA[privacy]]></category>

		<category><![CDATA[search engine]]></category>

		<guid isPermaLink="false">http://unitstep.net/blog/2006/08/07/aol-releases-search-queries-for-650000-users-in-blatant-disregard-for-privacy/</guid>
		<description><![CDATA[Well, the &#8220;blogosphere&#8221; (I hate using that word) and various online communities are abuzz with the news that AOL Research just released 20 million search queries of some 650,000 users over a three-month time period from March to May of 2006.  Though the data were released in order to provide &#8220;a real query log&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>Well, the &#8220;blogosphere&#8221; (I hate using that word) and various online communities are abuzz with the news that AOL Research just <a href="http://www.techcrunch.com/2006/08/06/aol-proudly-releases-massive-amounts-of-user-search-data/">released 20 million search queries</a> of some 650,000 users over a three-month time period from March to May of 2006.  Though the data were released in order to provide &#8220;a real query log&#8221; to aid in search engine research, it constitutes a huge violation of privacy, as though usernames have been removed, they have been replaced by unique identifiers, which can be used to track an individual user&#8217;s searches, allowing information to be collected about them and a profile built.  </p>
<p>The download was taken offline sometime yesterday (August 6th, 2006), but enough people had already downloaded it to ensure that <a href="http://www.gregsadetsky.com/aol-data/">mirrors</a> would quickly be set up, ensuring its continued spread.  While the intent of this release of data was obviously not malicious, it was a poorly thought-out move that AOL is sure to receive more bad PR for - especially in light of their <a href="http://www.courant.com/business/hc-aol0804.artaug04,0,3506664.story?coll=hc-headlines-business">recent troubles</a>.</p>
<h3>Good intent, bad execution</h3>
<p>The dataset was first released sometime on or before August 4th, 2006, on <a href="http://research.aol.com">AOL Research</a>.  Like Google, Yahoo! and Microsoft, AOL maintains a Research site to inform and help members of the academic and developer community of things they&#8217;re up to, and to offer assistance to researchers.  As <a href="http://72.14.207.104/search?q=cache:2Qvd2z9VbuIJ:research.aol.com/pmwiki/pmwiki.php%3Fn%3DResearch.500kUserQueriesSampledOver3Months+&#038;hl=en&#038;gl=us&#038;ct=clnk&#038;cd=1">Google&#8217;s cache</a> of the former download page indicates, the intent of offering this download was to facilitate research into making search engine technologies better, by offering a look into real users&#8217; search queries and behaviours.  </p>
<p>Having a little bit of experience in the research field (I&#8217;m currently working as a summer undergraduate research student), I can say that it&#8217;s not unheard of to see industry researchers helping out the academic community, either through joint research projects or, as in this case, the release of datasets for testing some particular sort of algorithm.</p>
<p>For example, one of the projects of the researchers in my lab is speech quality assessment, which is essentially developing an algorithm or system that can process a speech file and assess its quality as a human would, which has enormous benefits for Telco&#8217;s since they are always seeing what speech codecs are most efficient in terms of size/quality.  In order to do this, one needs a vast quantity of voice files (and their associated Mean Opinion Scores - rated by humans) to test around.  These voice files and their data can only be obtained through costly (both in time and money) trials that cost <strong>lots</strong> of money - we&#8217;re talking six-figures and above here.  Much of the data can thus only be obtained by Telcos who have the money to conduct these trials.  Fortunately, many of them have been gracious enough to release these datasets to our lab (and others) - <strong>but the data is only released after a strict <abbr title="Non-Disclosure Agreement">NDA</abbr> (Non-Disclosure Agreement) is signed</strong>, along with perhaps other agreements.  </p>
<p>Thus AOL&#8217;s intent certainly was not bad, as they merely wanted to help out in the academic circles, and maybe get cited in a paper or two.  However, their execution of this release was poor.  They should not have released this data publically, allowing just anyone to download it, but rather have followed a pattern of <strong>releasing only under an <abbr title="Non-Disclosure Agreement">NDA</abbr></strong> and only to parties that they thought were reasonably going to use it for research purposes.  In many ways, it&#8217;s worse than releasing data they paid for, because much of the data constitutes the private data of regular AOL users, data that <em>perhaps</em> they agreed to protect under AOL&#8217;s privacy policy.  </p>
<h3>Privacy concerns?</h3>
<p>Some of you might be wondering why this matters at all.  After all, it&#8217;s just a few million search queries that AOL users entered - containing no personally identifiable information.  Well, that&#8217;s true - however, since the usernames were merely replaced by unique identifiers (eg. a username is changed to a random, unique number, so &#8220;John Doe&#8221; is always mapped to &#8220;123456&#8243;, for example), profiles of users&#8217; searches can be built - opening so many cans of worms that I can&#8217;t even count that high.</p>
<p>Here&#8217;s a complete breakdown of what information is provided for each query:</p>
<dl>
<dt>AnonID</dt>
<dd>an anonymous user ID number.</dd>
<dt>Query</dt>
<dd>the query issued by the user, case shifted with most punctuation removed.</dd>
<dt>QueryTime</dt>
<dd>the time at which the query was submitted for search.</dd>
<dt>ItemRank</dt>
<dd>if the user clicked on a search result, the rank of the item on which they clicked is listed.</dd>
<dt>ClickURL</dt>
<dd>if the user clicked on a search result, the domain portion of the <acronym class="uttInitialism" title="Uniform Resource Locator">URL</acronym> in the clicked result is listed.</dd>
</dl>
<p>This is an absolute <em>goldmine</em> of information to anyone concerned with search engines, SEO or anything related to that.  Not only do you get a complete profile of a user&#8217;s searches, but you get the exact time they conducted the search, what, if any, results they clicked on (and the rank of that result), along with the domain name of site the clicked-through to.  Running datamining techniques on this information is somewhat trivial, as it can easily be analyzed to determine patterns of most any sort. </p>
<p>Internet marketers would give an arm and a leg for this sort of data, but they now will have their hands on it - <em>for free</em>.  In fact, there&#8217;s <a href="http://plentyoffish.wordpress.com/2006/08/06/aol-releases-googles-most-prized-keyword-list-google-is-gonna-get-mega-spammed/">already been</a> analysis on the dataset, producing valuable results, and claims that Google will get spammed with made-for-adsense sites (a clear violation of their TOS) targetting keywords for popular and profitable markets.  This will further pollute search results, and generate more noise, creating more headaches for search engines like Google, who will have to further adapt to prevent the <a href="http://unitstep.net/blog/2006/07/31/comment-spam-evolution/">signal-to-noise ratio from further deterioration</a>. </p>
<p>However, this dataset probably (or hopefully?) won&#8217;t have a lasting effect for spammers.  As <a href="http://www.thoughtmarket.com/blogarch/2006/08/how_useful_will_1.php">Thought Market points out</a>, since everyone has access to this data, so does Google as well.  And Google has proved themselves not to be slackers on developing data analysis techniques - after all, how did they become arguably the most successful search engine? You can bet they will be analyzing this dataset to see what results <em>they can get</em>, and hypothesizing about how these results might be used.  If they seen anything fishy going on, you can bet they&#8217;ll remove those sites from their index. </p>
<h3>Justice is blind</h3>
<p>But perhaps the most important or unnerving aspect of the release of this dataset is the implications it has on legal matters.  The data released is <em>exactly the sort of data the <a href="http://www.boingboing.net/2006/01/19/_doj_search_requests.html">US DOJ requested</a></em> from the major search engines (Google, Microsoft, Yahoo! and AOL) earlier this year to &#8220;defend its argument that the Child Online Protection Act is constitutionally sound&#8221;.  Microsoft, Yahoo! and AOL complied, while Google resisted the subpoena - and when the matter went to court, the judge ruled <a href="http://googleblog.blogspot.com/2006/03/judge-tells-doj-no-on-search-queries.html">in Google&#8217;s favour</a>.</p>
<p>Taken in this context, things do not look good for AOL - while Google&#8217;s fighting to protect your privacy, AOL&#8217;s actively working in the opposite direction, it seems.  I realize it was not meant to be that way, but with something this serious, the effect is sometimes far more important than the intent.  Looking at the raw search queries of some users reveals things ranging from embarrasing or weird searches, to queries that may <a href="http://plentyoffish.wordpress.com/2006/08/07/aol-search-data-shows-users-planning-to-commit-murder/">indicate they&#8217;re up to no good</a>.</p>
<p>Let&#8217;s be clear here - simply searching for &#8220;how to kill your wife&#8221; is not tantamount to murder - nor is it even enough proof of conspiracy to commit murder.  At least, that&#8217;s how I see things from my &#8220;not a lawyer&#8221; perspective.  However, consider a situation where someone <em>did kill</em> their wife.  If their search results were made available, and this query turned up, how do you think law makers would respond?  Or, consider sample size of 1000 murderers, and their search queries.  If it were statistically established that a significant percentage of murderers search on the Internet for some aspect of murder before the actual crime, how would law makers respond? </p>
<p>These are complex questions, and I&#8217;m not sure what I&#8217;d do with the data.  Statistics is a complex topic, but the important fact is they are often abused to support invalid and over-reaching actions.  This obviously leads to questions and issues like &#8220;thought crime&#8221; and comparisons with <cite>Minority Report</cite>.  I generally don&#8217;t like using slippery-slope arguments, but this is an area where it&#8217;s easy to see how abuse could happen, considering that the US DOJ has already expressed an interest in this sort of data, and with all the <a href="http://www.cnn.com/2005/POLITICS/12/17/bush.nsa/">NSA wiretaps</a> going on.  </p>
<p>There were also many other weird, and often disgusting search queries going on, often by the same set of users.  I won&#8217;t repeat them here, but you can easily <a href="http://plentyoffish.wordpress.com/2006/08/07/aol-search-data-shows-users-planning-to-commit-murder/">see for yourself</a> what some AOL users were searching for.  While these searches represent a very small percentage of all the searches conducted, it doesn&#8217;t paint a good picture of the Internet for lawmakers.  (Keep in mind that these sort of searches are to be expected - after all, even if the incident rate for violent crime is something low like 27 per 100 000, that&#8217;s still 0.027%, and keep in mind this search query dataset represents over 650,000 users.)</p>
<p>Note that I haven&#8217;t even touched on the topic of false positives.  What if someone was writing a paper on the effects of torture, or of any of the other examples of &#8220;man&#8217;s inhumanity to man&#8221;?  They&#8217;d obviously have to search for some pretty disturbing stuff (I&#8217;m glad I&#8217;ve never had such a writing assignment), and then these searches would be tied together by the unique identifier.  There are plenty of other examples, but the idea is that using someone&#8217;s search queries for legal purposes is an easy way to <cite>1984</cite> - while there obviously may be statistical connections between actual crimes, the potential for &#8220;though crime&#8221; is just too large.</p>
<h3>Waves and reverberations</h3>
<p>As far as I can tell, this story (and thus the wide release of the data) only started sometime this weekend, probably on Friday or Saturday.  But, it&#8217;s already making its way around the non-traditional news outlets (blogs, social communities) like fire through a tissue factory.  There&#8217;s been talk of how <a href="http://www.ugcs.caltech.edu/~dangelo/aol-search-query-logs/">personally identifiable information</a> may be available, and of the <a href="http://plentyoffish.wordpress.com/2006/08/07/aol-search-data-shows-users-planning-to-commit-murder/#comments">legal ramifications</a>.  It&#8217;s already in the top five among <a href="http://technorati.com/">Technorati</a> searches, so you can believe that anyone who wants this data will get it.  If this doesn&#8217;t hit the mainstream news soon, I&#8217;ll be very surprised and disappointed - so far there&#8217;s <a href="http://news.google.com/news?hl=en&#038;ned=us&#038;q=aol+data&#038;btnG=Search+News">only one result</a> for it in Google News. </p>
<h3>Update</h3>
<p>AOL has apparently responded to this privacy leak, in a comment <a href="http://plentyoffish.wordpress.com/2006/08/07/aol-search-data-shows-users-planning-to-commit-murder/">available here</a>.  </p>
<p>Nothing really new or interesting - other than the data represented only about 1.5% of all AOL users, and those included were only US users who used AOL&#8217;s client software.  As expected, Mr. Weinstein of AOL said that it was an &#8220;innocent enough attempt to reach out to the academic community with new research tools&#8221;, but as expected, it didn&#8217;t go through official channels for approval.  You can be sure that AOL&#8217;s going to change their policy on this sort of stuff - don&#8217;t expect any more stuff from AOL research for a while.  (Someone or some people probably also got fired.)</p>
<hr/>Copyright &copy; 2008 <strong><a href="http://unitstep.net">unitstep.net</a></strong>. This Feed is for personal non-commercial use only. If you are not reading this material in your news aggregator, the site you are looking at is guilty of copyright infringement. Please contact <strong><a href="mailto:webmaster@unitstep.net">webmaster@unitstep.net</a></strong> for more information.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">Plugin</a> by <a href="http://www.taragana.com/">Taragana</a></span>]]></content:encoded>
			<wfw:commentRss>http://unitstep.net/blog/2006/08/07/aol-releases-search-queries-for-650000-users-in-blatant-disregard-for-privacy/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
