Showing posts with label Web 2.0. Show all posts
Showing posts with label Web 2.0. Show all posts

Zero Privacy: Thoughts on McNealy and Zuckerberg and “privacy statements”


In some of my recent posts about privacy, occasioned by Facebook founder Mark Zuckerberg's apparently dismissive attitude to privacy concerns, I referenced the "infamous" privacy comment that Scott McNealy made in 1999.

At that time, McNealy was the CEO of Sun Microsystems, and Sun was hot. Java was cooking, so to speak. Anyway, McNealy was reported to have said, to a group of reporters, something like: “You already have zero privacy anyway, so get over it.” The rest of this post is what I wrote on this subject in my 2002 book on privacy (which you can always download, for free, if you feel like reading more) followed by a few fresh thoughts.
Light Down Under
When Scott McNealy addressed the National Press Club of Australia in September 2000 he explained what he meant by that zero privacy remark. Here is a verbatim transcript:
“If you get hit by a truck, you want somebody to have your medical records. If you cannot tell them the combination to your safe or where your medical records are kept, you have a problem. In effect you want your medical records to be available online out over the Internet. You want every ambulance driver to be able to unlock it. So that is a little risk you take. Every ambulance driver might be able to tap into your medical records. Get over it. That is better than getting hit by a truck and dying.”
That's not quite the same as simply saying: "You have zero privacy, get over it."

Various versions of the quote—and Mr. McNealy’s last name—rapidly populated articles and presentations about privacy, most of which made no mention of the original context. That context was frustration at announcing a new product, JINI, then having to field questions about the one thing it can’t do—guarantee absolute privacy of personal data—rather than the many things it can do, such as make vital data instantly available across a wide range of hardware, software, and networks.

A lot of people in business can relate to Mr. McNealy’s frustration with those who have turned privacy into an absolute. While the potential to abuse information technology such as Web sites and email is a genuine cause for concern, foolishly equating privacy with anonymity—somehow forgetting that you cannot participate in society unless you share information about yourself—does nobody any good. As I said in Chapter 1, the reason that privacy on the Web is such a big challenge is that nobody yet understands exactly what privacy means in the context of today’s highly interconnected, heavily computerized, data-dependent world. About the best we can say is that privacy in the information age is a work in progress.

Of course, if you are the sort of person who thinks corporate America is only out to steal people’s wallets and ruin their lives, you are unlikely to be swayed by my assertion that most businesses actually want to respect the privacy of their customers, particularly if that is what their customers want. The problem is that we, as a society, simply haven’t finished our homework on this one. In other words, we are not yet at the point where a significant percentage of consumers have articulated specific Web and email privacy demands that businesses have chosen to reject.

As Rob Leathern, a Jupiter Research privacy analyst recently observed, “Neither consumers nor businesses effectively address online privacy issues.” He was reflecting on a Jupiter Media Metrix report that found more than 80 percent of U.S. consumers would give out personal information in exchange for small rewards, while at the same time nearly 70 percent said they were concerned about their privacy online. They might be concerned, but 60 percent admitted that they did not read privacy statements before handing over personal information to Web sites (not helped by the fact that a lot more than half of consumers surveyed found online privacy statements difficult to understand).

Notes from 6/26/2010: A lot has changed since 1999, but a lot remains the same. As Facebook and Twitter attest, digital privacy is still very much a work in progress. And some things never change: CEOs do not have "freedom of speech" any more than their employees. A bank clerk can be fired for mouthing off about the company. A CEO can put his or her job in jeopardy by saying the wrong things in the wrong place, like in email that lives forever or in the presence of a reporter's microphone. What may be new is the extent to which we are all more closely watched, surveilled if you will, which adds a level of transparency to our society, the implications of which we don't yet fully grasp.]

Mark Zuckerberg Faces the Privacy Meter: Facebook trends open book


Face it folks, it's time to dust off the Privacy Meter for a quick check of Facebook founder Mark Zuckerberg. According to an internal source, Mr. Zuckerberg has placed himself in the camp made (in)famous in 1999 by Scott McNealy, the CEO of Sun Microsystems, who was reported to have said: “You already have zero privacy anyway, so get over it.”

Mr. Zuckerberg's position was recently described by a Facebook insider in response to this question: "How does Zuck feel about privacy?" Response: “He doesn’t believe in it.”

The details of this revelation can be read here and I'd have to say it hardly amounts to a public statement by "Zuck" himself (for the record, Scott McNealy's declaration was not a public statement either, and should be placed in context, something I tried to do in my 2002 book on privacy).

I doubt that either Mr. Zuckerberg or Mr. McNealy would say, on the record, that they don't believe in privacy. What both men seem to share is a frustration with privacy concerns as they relate to digital systems. Human beings can be annoyingly inconsistent and hard to predict when it comes to matters of personal information. That makes it inherently difficult to design online communications and online communities that satisfy every shade of sentiment with respect to the sharing of personal information. And that's why I created the Privacy Meter:

Not exactly a high tech device, it nevertheless serves its purpose: to help people assess their own attitude to their personal information. I developed the privacy meter as a teaching tool, specifically to teach Chief Privacy Officers and other C-level execs that:

a. Everyone has a different place on the privacy scale, there is no "correct" score;

b. Entities like companies and agencies cannot handle privacy issues according to one person's views about privacy.

In other words, the fact that you're an open book kind of person does not make it okay to impose an open book approach on people who are more closed book. If you are closed book you can't impose that view either because it could limit your organization's ability to serve its customers. Most importantly, the way you handle other people's private data has to be in accordance with their view, not yours. That principle was established, in the context of computer data, back in 1974, and remains one of the pillars of privacy best practices in the realm of data protection (see Chapter 3 of Privacy for Business, available as a free .pdf file here).

Several years ago I put together a short set of slides on the privacy meter and the potential benefits and problems arising from getting privacy positioning right or wrong. You can click here to download the slides as a .pdf file which I recently updated to include Facebook's current privacy perception problem. That slide is pretty easy to understand:

Just a few hours after Wired puts out the story that your CEO doesn't believe in privacy, PC World publishes a story about the latest privacy invading scam that your system is enabling. Not good. Just the sort thing that can hurt your share price and tarnish your brand. Which is why your personal feelings about privacy should probably remain private when you are running a company.

[BTW, you can now download the full 240 page text of Privacy for Business (2002) as an Adobe Acrobat document from this web site; there's no charge and no registration required.]

Can You Hear Me? Radio interview at ad:tech


speakerAs you can see from the lack of recent posts on Cobbsblog, things have been particularly busy this month. My November started out with a trip to a trade show in New York called ad:tech. This event brings together a very interesting mix of companies that are in some way or another related to digital marketing.

Digital marketing is one way to describe what my work for Monetate is all about, so I was at the show checking out the digital marketing scene and looking to learn whatever I could. (Quote du jour: "A real expert always looks to learn more and does not always try to look like he's learned everything.")

Judging by the huge crowds, digital marketing is doing well these days. For all our sakes I am hoping that the larger-than-expected attendance bodes well for the economy in 2010.

Shortly after I fought my way through the check-in lines and gained entrance to the exhibit hall I was interviewed for WebmasterRadio by marketing guru Bryan Eisenberg. Here is a link to the interview. (I apologize for sounding out of breath but I had to shout to be heard above the crowd--the sound engineers at WebMasterRadio did an amazing job of filtering out background noise but they couldn't change the fact that I was shouting.) Oh, and here's a link to Bryan.

Anyway, if you take a listen to the interview you will get an idea of what Monetate is about and what my role as "evangelist" for the Monetate technology involves. (If you can't listen to the audio right now, the short answer is that my role as an evangelist is to get people excited about what the technology can do.)

I carry out my role by communicating across multiple media, most of which don't charge for participation. Over the years I have learned how to do this out of necessity, often working for startup companies that did not have a marketing budget to speak of (or we had a budget but it got eaten by engineering, or product delivery, or something else that was deemed a priority over marketing at the time).

Starting from back in the days when this type of thing was called guerilla marketing, I have pioneered the idea that if you offer up free content that is also valuable content, people will find that content, consume that content, and give some respect to the content creator. So when I created a web site back in the mid-nineties that was full of high quality computer security information, people who had read the content would call up looking for security advice, which we sold as security consulting, creating a blue ribbon client portfolio that became very valuable and was eventually snapped up by a much bigger company that paid us a premium for it.

A dozen years on and I am working on marketing a marketing product, finding that a lot of people have twigged to this strategy, so things are not quite so easy. But the strategy is still sound and I will keep persevering, adding new tactics like social media (an umbrella term for Facebook, Twitter, LinkedIn and blogs) to my arsenal. And of course, radio interviews whenever they present themselves.

Cobbsblog on YouTube (via Stagecoach not Satellite)


This is a quick post to highlight the video I just uploaded to YouTube. Probably not my finest mixed media effort, it's a quick screencast to demonstrate the fact, oft-mentioned to friends and colleagues, that the $80-per-month HughesNet Satellite Internet service which I get at my house "blocks" access to my blog.

(10/2/2009: Video link updated. For the video, click here.)

In fact, even as I write this, I am being forced to eat a veggie pannini at Stagecoach Coffee in Cooperstown so I can use their free WiFi to get to my blog to post this on my lunch hour. As you can see in the video, accessing my blog via HughesNet  "normally" results in a DNS Lookup Error. However, there is nothing wrong with the blog, as can be demonstrated with DownForEveryone, which I demonstrate in the video.

I have reported this problem to HughesNet but they tell me it must be a problem with my web site or web hosting company. Obviously the problem is NOT with my web site or host. I am pretty sure the problem is HughesNet DNS. I even demonstrated this to HughesNet by running Anonymizer which, as shown in the video, intercepts the HughesNet DNS and makes my blog accessible over the very same HughesNet connection that said "DNS Error."

My speculation that this problem occurs because I am frequently critical of HughesNet, on this and other blogs, is indeed speculation. But you don't have to be ultra-paranoid to think it mighty strange that my HughesNet connection, which can reach Google.com but not Cobbsblog.com, is fishy. It certainly stinks.

Hey 19: Things to do when promoting a cause or company, product or person, band or brand


hey19This is a quick attempt to put into one place various bits of advice that I've been giving out to various people over the past few months with respect to raising the profile of a person, place, or thing.

The idea is that you have something you want to publicize. It could be a band, a brand, a product, a company, or an indie film; or it could be you.

Before you go out and hire a PR agency or pay for a press release, you might want to try these things. They are free, except for your time and an Internet connection. In the old days they would have been called guerilla marketing. Now it's called Web 2.0 marketing or New Rules marketing. The strategy is to create interest--in whatever you are promoting--by being interesting. You want to draw people to the object of attention rather than subject them to a message. I will try to post something later on how to be interesting. The following are 19 things to get started with. I've broken them down into 3 phases:

On the Street Where I Was Born


Recently, on my technology blog, I wrote about the mixed reception that Google Street View has received in England, land of my birth. I admit to having mixed feelings about this technology myself.

It is very easy to be seduced by technology that enables me to sit in a cottage on a hill in the wilds of Upstate New York and capture this image of the street in England where I was born. (Just to clarify, I was not born in the street, but in one of the houses on this street--home birth by midwife being the normal practice in England in the 1950s.)

The most obvious change in the last 50 years is the number of cars on the street. There were  practically none when I was born. You could easily play 20 minutes of football in the road without being disturbed. Now there are too many vehicles, which is why many front gardens have been replaced with parking spaces--compare the original gardens on the left with the parking pads on the right. And so it goes...

Well That Was Fun: Monetate launches Smellr


There are many things I enjoy about working for Monetate and they all came together today: Cool technology, brilliant developers, cutting-edge digital artistry, crafty copy-writing, savvy leadership, and great camaraderie. All of this orchestrated in a concerted team effort to execute a good idea with skill, excellence, and a good laugh.

And we succeeded!

The web site Smellr got over 14,000 visitors. The Monetate Post-click Marketing Blog and the main Monetate web site both received at least 20 times the normal amount of traffic. We've been mentioned in the Associated Press, The Guardian, and many blogs, including blogs.com and the bostonist. We were even seen on CNN in the Netherlands!

I know some people get tired of April Fool's jokes, but I think one reason they still persist is that many people feel the need for a good laugh about this time of year. You've struggled through the Winter and it's still struggling to hold back Spring. The nights are getting longer but the skies are still too grey. It's time to take things a little less than seriously for a day.

Happy April First!

Fun With Smells? Or smells Funny?


On the lighter side, I've been having a lot of fun telling people about Smellr, the very latest in Web 2.0 social networks. I particularly like the tag line: "It's like Flickr, but for your nose." This is a project we put together at Monetate just in time for this special day. I think you'll agree the graphics are stunning (Luke) and the ad copy is just about right (me).

You will also find that some of the page content reflects your location when you visit this page, thanks to some Monetate special sauce. And although the site has been getting thousands of hits per hour, it is performing very well (Tom and Jeff).

Take a deep breath and enjoy!

Coldplay Viva La Vida Satriana Ripoff? The Internet helps you decide!


There's an interesting Web 2.0 twist in the lawsuit brought by guitar legend Joe Satriani against Coldplay for alleged plagiarism in Viva La Vida (one of the tunes used to sell iPhones). Thanks to the magic of the Internet you can play both songs at the same time. I think this is quite telling.*

Here's one of the places that has both performances on the same page so you can decide what you think. If you time your "Play" clicks just right, and you have decent bandwidth, you can get them playing on top of each other.

Having admired Satriani's musicianship for many years, as well as his extensive knowledge of the history of guitar technique, I am inclined to take him seriously. This could well be a My Sweet Lord He's So Fine moment, although that case--in which George Harrison's 1970 hit "My Sweet Lord" was found to have plagiarised "He's So Fine" composed by Ronald Mack and recorded by the Chiffons in 1962 lasted for a lot longer than a moment--the moment the question was raised, the public could start deciding for itself, albeit without the benefit fo the Internet.

Regardless of the outcome of the Satriani Coldplay case, there's a fascinating historical twist: Apple Computer used this possibly plagiarized tune to promote its iPhone less than two years after the conclusion of decades of trademark litigation involving Apple Music, of which Harrison was a co-founder.

*Note: The author of this blog post was declared "tone deaf" by his third grade teacher, Mrs. Ashby, and makes no claim to having any special knowledge about music, except a. He knows what he likes when he hears it, and b. He claims he can recognize any Otis Redding recording within 3 seconds.
.

Turducken? Feeling chuffed with my Thanksgiving post


I just completed a blog post for Thanksgiving over on the Monetate Post-Click Blog and I'm quite pleased with it (back in the old country people would say they were "chuffed" when they were feeling pleased with something).

I've spent quite a bit of time the past two months studying various aspects of blogging, notably the role of the corporate blog. I've been getting a lot of good insights from reading Naked Conversations by Robert Scoble and Shel Israel. I remember skimming through this book in my local Barnes & Noble not long after it came out (in 2006 I think) but at that time I did not have a "corporate" blogging role and some of the points didn't really sink in. Now I'm contributing to a company blog the advice from Scoble and Israel really clicks, things like: write in first person and be authentic, timely, and relevant. The turducken piece follows that advice. Here's hoping it generates some buzz. I mean, there can't be that many other bloggers talking about turducken in the context of search engine marketing, can there?

Under Pressure? Wikipedia can help


A few posts ago I wrote about the need to have the right amount of air in our tires. I was going to make a witty reference to the song "Under Pressure," you know, the one with the wicked bassline that's been used in ad campaigns for everything from Propel Fitness Water to Zales Jewelry, and movies such as Grosse Pointe Blank, The Players Club, Stepmom, 40 Days and 40 Nights, The Girl Next Door, I Now Pronounce You Chuck and Larry, and The Heartbreak Kid. It's the one that rapper Vanilla Ice sampled without permission for his big hit, "Ice Ice Baby."


My problem was not that I couldn't remember the name of the song but I wanted to say who wrote it and that's where things get tricky. Was it Queen or David Bowie? This was not immediately clear from my initial Googling. A few days after the post I realized that all I needed to do was to go to Wikipedia, where an entire page is devoted to the song at this URL:  http://en.wikipedia.org/wiki/Under_Pressure.


It seems that rock music is one area where Wikipedia is growing at a phenomenal rate, adding details down to a level that some people might think obsessive, but others, like me, find fascinating, and actually rather helpful. Thanks Wikipedia!

Labor Day for Virtual Workers?


A few days ago I wrote a post over on the Monetate Blog to make the point that every worker should be proud on Labor Day, even those of us who work with bits and pixels and other nebulous, virtual things. Code slingers and geeks and digital tinkerers are responsible for a significant percentage of the GDP, not to mention the joys of MP3s and Hi-Def TVs and cell phones and IM and texting and such.

Happy Labor Day!

Cool Stuff for Online Stores


Had a very interesting chat today with David Brussin whose new company, Monetate, has developed a very powerful tool for online retailers. This tool/product is also called Monetate and what it does is pretty amazing. Suppose you’re shopping on the web, maybe for new boots. You visit a couple of sites that sell the boots you want. As you flick between sites to find the best price, an offer pops up, giving you 20% off on the exact product you want, if you order today.

If you're selling boots and your site that makes that offer, you may well get the order. Making that offer is what Monetate does.

Even better, from the site owners point of view, Monetate can extend offers like this based on very specific criteria, like "free next day delivery on big screen TVs" but offered only to customers who are within 50 miles of the warehouse. You might think online retailers already have the ability to do this sort of thing and a few do. But many are still struggling to implement this level of personalization. Monetate is relatively easy to implement (it's SaaS, but without the need for clients to code to an API). Plus, you can make personalized offers even to people who have never shopped at your site before.

How does Monetate do this? I'm about to find out. I will report back soon.

Two Blasts From The Past In One Day: Monetate and IMCD


I got two exciting calls today from friends and former colleagues, David Brussin and Michael Miora. two of the guys with whom I co-founded InfoSec Labs and ePrivacy Group.

Mr. Miora is a seriously qualified information security and disaster recovery expert (as in Michael Miora, CISSP, ISSMP, FBCI). He has been working on a product that helps businesses recovery from disasters. It is called IMCD, from Incident Management CD, because one of its many clever tricks is to store, one on CD (or USB thumb drive or SD card) everything your company needs to know in an emergency: who to call, contact details, systems and software applications and data, by department, priority, location, and so on and, Wow, there really is a lot of stuff you need to get your hands on fast when the nasty stuff meets the whirling blades.

One reason I'm familiar with this product is that my brother (Mike Cobb, CISSP, ISSAP, MCDBA) was heavily involved, coding the interface and algorithms and such. The exciting news today was the availability of the new version, boxed and priced to sell, on places like Amazon, for $99.00. At this price it's a very cheap insurance policy and potential life-saver for owners of small-to-medium businesses as well as in charge of regional offices of larger companies. The next step in the marketing plan is to move into brick and mortar retail stores like Staples and OfficeMax. I look forward to seeing it on the shelves soon.

The news from Mr. Brussin was also very exciting--his new company's new product is ready to rock and they've just activated the first client. David is one of those people obsessed with making things work better through the appropriate application of technology. He was running his own networking company before he turned 20 and has been coming up with bright ideas ever since, like the anti-spam router, still the single most effective anti-spam tool you can buy. This latest company/idea is a means of making online retail sites work better (a by-product of spending too much time Internet shopping?). It sounds like David has put together an ace tech team to build this thing and I look forward to learning more about it.

What Are Facebook Friends For? Maybe data mining


Further evidence that Facebook does not 'get' privacy is brought to you this month by the BBC, which recently built a Facebook application that could mine personal data from anyone who played it, and their friends. (In a nice touch of irony, the application was called The Miner, as in 'data miner' get it?)

A video clip from the BBC's Click programme can be seen here (you can find a text report here). It turns out that, by default, Facebook gives application developers wide-ranging access to anyone who installs the game, and their friends. Notice the theme here: "and their friends." In other words, you might be exercising due diligence over what you do with your Facebook account, but just one careless friend could undermine your privacy.



And you'll love the Facebook response: Using an application to abuse access would be a violation of the Facebook terms and conditions. Oh well then, no problem. That should take care of that. And here I was worried that someone would steal my credit card, but no worries, using someone else's credit card is a violation of Visa's terms and conditions. Those terms and conditions are probably what's limiting online credit card fraud losses to just a few billion dollars a year. And that's considerably less than what some analysts think Facebook is worth.

Dare Not Walk Alone Trailer


Yes! The theatrical trailer is now appearing in select cinemas in Los Angeles.

We have had several emails about how powerful this trailer is. Please email the following URL to anyone you know who might be interested (or anyone you think SHOULD be interested): http://www.darenotwalkalone.com/trailer.html

Blog Blending Begins: Cobb's blogs coming together at cobbsblog.com


A big welcome to readers joining me from my other blogs! The time has come to put those other blogs on hold and focus my attention on a single blog of record: this one. I am still looking for a way to make the content of the other blogs searchable from this one. And one day I might figure out how to copy the posts over. Until then, here are links to those "other" blogs:

What Profiteth It Google to Know Your Ip Address


A couple of thoughts in light of Google's divergence from the norm as far as PII is concerned (see previous post On IP and PII: Merely the Location of a Computer? Non!). The debate over what exactly constitutes Personally Identifiable Information is not merely academic or a sidebar for policy wonks, it goes to the heart of how data about people should be handled, stored, shared, protected, etc.

To a certain extent I sympathize with Google in that the best definition of PII is a relative or functional one. Even my name, Stephen Cobb, has limited value in identifying me--it identifies me only in limited circumstances--even though "name" is included in most lists of PII identifiers. The reason for this is the popularity of Stephen as a name for Cobbs (you could say "the commonness of Stephen Cobb as a name," but hey, I'm trying to maintain some PPD here--personal pride and dignity).

My wife's name, Chey Cobb, is clearly going to be PII in most situations. The same is true of my friend Michael Miora (there's only one, AFAIK). But even something like "Stephen Cobb in ZIP Code 32084" does not identify me because there are several people who share these identifiers (I know because my friend Bruce Dufresne, who knows more about the history of the automobile that anyone else I know, knows two Stephen Cobbs and sometimes calls me by mistake when he wants a ride to the car auction). So, the extent to which any piece of data can be considered PII depends upon the context and the aggregate.

As for Google and your IP address, it seems like they may be putting too much store in its value. Consider what happened the last time I was visiting my brother in England and Googled a number of different pieces of hardware, some for my him, some for me. Google was a mess. When I Googled from my hotel room, Google assumed I was in the Netherlands (the hotel's Internet service was provided by a Dutch company).

When I Googled from my brother's office in Surrey, Google really didn't want to tell me about product offerings in the US because I was Googling from a UK IP address. And when I am in America I cannot see the ads served up to UK visitors to his web site, School Sports Action TV, because Google is making assumptions based on my IP address.

In other words, my IP address might be of limited relevance with respect to what I want to see on the Internet. It seems like it would be better to have a "focus" option in Google that I could select to shape my results rather than let them be determined by my IP address. Of course, some folks in marketing are then going to want to know where the people live who select UK as their focus. My point is that my IP address does not reliably provide that data. So Google might want to think about how hard it wants to defend its collection and retention of that data.

Facebook Stickiness or Sticky Mess?


Sometimes I read something in the newspaper that makes me feel better, not because it is good news, but because it lets me know I am "not the only one" or "not imagining things." So it was with a recent New York Times article about Facebook focusing on the difficulty people have had deleting their data from Facebooks's computers.

The article plays on the term "stickiness" as in "the amount of time users spend at a web site over a period of time." This can be a major factor in selling ad space on a web site or otherwise monetizing it. But the sticky-ness described in the article is the problem of closing a Facebook account, which basically you cannot do. I found this out when I realized I had two Facebook accounts. Not sure how that happened (but it would seem to be a flaw in the Facebook design that it could happen).

I figured I would delete one account. I could not. I could close it down, somewhat, but the stuff, the data that was associated with it, remains in the Facebook server farm, ostensibly so I can revive that account at some point in the future. I assumed this difficulty in deleting an account was driven by security concerns, as in: make it hard for people to close accounts they are not unauthorized to close, i.e. one's belonging to other people. Apparently that might not be the case. Could it be they want to keep mining that data forever? Here are a few points to note, from the Times article:

  • Facebook’s terms of use state that “you may remove your user content from the site at any time,” but also that “you acknowledge that the company may retain archived copies of your user content.”

  • Its privacy policy says that after someone deactivates an account, “removed information may persist in backup copies for a reasonable period of time.”

  • Facebook’s Web site does not inform departing users that they must delete information from their account in order to close it fully—meaning that they may unwittingly leave anything from e-mail addresses to credit card numbers sitting on Facebook servers.


Seems to me Facebook is still growing up in terms of understanding data privacy issues. After all, the retention policy in the terms of use is pretty much in direct contravention of the basic principles of data privacy.

On IP and PII: Merely the Location of a Computer? Non!


A recent AP article entitled "EU Official: IP Is Personal" shows that some people still don't understand, or are prepared to willfully misconstrue, one of the basic privacy concepts: personally identifiable information or PII.

On the one hand you have the head of the European Union's group of data privacy regulators stating that "IP addresses, string of numbers that identify computers on the Internet, should generally be regarded as personal information." He is correct.

On the other hand you have Google insisting that "an IP address merely identifies the location of a computer, not who the individual user is." Google is incorrect.

An IP address does not merely identify the location of a computer, just as your street address does not merely identify a physical location and your year of birth does not not merely identify a year. All someone needs is a few 'mere' facts about you and your identity can be established. That's why it is called personally identifiable information.

There are plenty of simple experiments you can conduct to prove this.