Strategies

How We Handle Privacy at F5 Labs

Managing online privacy is a balancing act for both users and security professionals. We can do better than simply following privacy regulations such as the GDPR and CPRA.
January 28, 2022
3 min. read

Managing privacy online is a constant balancing act. On the one hand, we need to provide a certain amount of our personal information to authenticate ourselves. In select environments, we also want to provide some additional information to our friends, family, and peers. On the other hand, we want to withhold that information from those who would misuse it or fail to protect it. Our information could be scooped up in a breach, sold for marketing purposes, aggregated as a doxing effort, referenced by current or potential employers, or even used against us in a violent and dangerous situation. American citizens caught up in the 2015 Office of Personnel Management (OPM) breach are acutely aware of the dangers of our information falling into the wrong hands: China acquired the records of 22.1 million individuals, many of which included 127 pages of extensive background check information for nearly any US governmental employee with a security clearance.1

This is why there are many consumer privacy regulations like the EU General Data Protection Regulation (GDPR) and the California Privacy Rights Act of 2020 (CPRA), which include extensive privacy rules that organizations must follow to enable their residents to retain control over their information. Compliance with the GDPR and CPRA is a great start towards protecting privacy, though many organizations simply check the box on these regulations without adhering to their spirit. Organizations often provide a consumer with a route to redress via a link in the footer at 8-point font, while collecting up as much information as possible in hopes that the consumer won’t ask to have it deleted.

In our daily lives, our privacy concerns usually center on how companies will use the information we provide them. App permissions, trackers, and so-called “personalized experiences” are becoming ubiquitous, and while these developments are not inherently bad, we often see them used in ways that we dislike. This is part of a larger mistrust we have with “marketing” in general: while “good” marketing can be used to provide just the solution you need at just the right time, “evil” marketing is far more often used to try and convince you to purchase a solution to a problem you don’t really have. Since marketing professionals use the same toolset to accomplish both ends, it is natural for our default attitude to be mistrust in any scenario where a company asks for our information.

F5 Labs sits at a sort of nexus among these concerns. As a team of dedicated security professionals, we are always striving to give other security professionals useful information and insights so that we can all do a better job of protecting ourselves—and we provide that information without asking you to tell us anything about yourselves. We distrust “evil” marketing too, and we’re never going to ask you to give us information that we don’t need. For instance, this is why we only ask for your name and email address when you sign up for the F5 Labs newsletter—we really just need to know where to send the newsletter and who to address it to, because our newsletter program isn’t a pipeline to generate leads or to sell information to other companies.

When we launch our new commenting functionality using Disqus (spoilers!), we’re doing it in this same spirit. For anyone who wants to participate in conversation about our content, we’ll need some personal information for authentication, but we’re collecting as little information as possible. There will be a secondary registration page that explains what our relationship is with Disqus, and provides links to their privacy policy and terms & conditions right up front, so that if you choose to opt in to using Disqus, you know exactly what you’re getting into. And anyone who does create an account will always be able to change their minds – we’re putting access to both a “standard” deletion and a full GDPR deletion in an easy-to-use spot on our new user Profile page. No attempts to convince you to stay, no re-use of your information in other marketing efforts by F5—just letting you give us direct feedback, or have conversations with your peers. We’re doing our best to give you something we hope you’ll like, while maximizing your privacy.

While we all try to balance our concerns with online privacy, companies have an outsized role in protecting the privacy of their users and customers. Companies often want to know as much as possible about their users and customers, but security professionals in those companies need to act as the guardians of those same individuals. We need to help people protect their privacy and allow them to have as much control as possible over how their information is used. When companies do this, it generates trust, which is a long-term benefit to the company. Those of us who are most aware of the importance of privacy and how it relates to security are in the best position to take action on behalf of our users, and to stand up to the internal pressures within our organizations that are always looking for a more complete user profile.

Join the Discussion
Authors & Contributors
F5 Labs Staff (Author)
Footnotes

1https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach

Read More from F5 Labs

2023 Identity Threat Report: The Unpatchables
Top Risks
2023 Identity Threat Report: The Unpatchables
11/01/2023 report 80 min. read
Sensor Intel Series: Top CVEs in March 2024
Top Risks
Sensor Intel Series: Top CVEs in March 2024
04/30/2024 article 7 min. read
2024 Bad Bots Review
Bots and Automated Attacks
2024 Bad Bots Review
03/14/2024 article 15 min. read