Trends in Data Exfiltration and Privacy Policies

Total Page:16

File Type:pdf, Size:1020Kb

Trends in Data Exfiltration and Privacy Policies Trends in Data Exfiltration and Privacy Policies Alexander Huang Alex Kimn Jesse Widner [email protected] [email protected] [email protected] Diane Zhou [email protected] May 13, 2020 1 Contents 1 Introduction 4 2 Background 5 2.1 Companies . .5 2.1.1 Cisco Webex . .5 2.1.2 Discord . .6 2.1.3 Google Hangouts . .6 2.1.4 Skype . .6 2.1.5 Zoom . .6 3 Methodology 7 3.1 Metrics . .7 3.1.1 Vagueness/Specificity . .7 3.1.2 Responsibility . .7 3.1.3 Readability . .8 4 Results: General Trends 9 4.1 Personal Data Collection . .9 4.2 Third Party Data Sharing . .9 4.3 Personal Data Retention . 12 4.4 Audio/Video Recording . 14 2 4.5 Overall Readability . 15 5 Results: Case Studies 16 5.1 Zoom 2019 vs. Zoom 2020 . 16 5.2 Jitsi Meet . 17 6 Conclusion 18 3 1 Introduction Recently, it has come to light that a tablet driver released by the graphical tablet manufacturer Wacom tracks the name of every application window opened by the user1. Within the privacy agreement the user sees during the driver installation process, it is mentioned that Wacom sends \aggregate usage data, technical session information, and information about [the user's] hardware device" to Google Analytics. However, the agreement fails to state exactly what is being sent and why, using only vague and uninformative language to mask a blatant example of user data exfiltration. Unfortunately, this form of data exfiltration is now a common occurrence. Under the (often correct) assumption that users will not thoroughly read privacy agreements, well-known and trusted companies like Wacom can obtain sensitive user information without the explicit knowledge or consent of the user. These data can then be sold to data companies or other third parties for a profit, implying that unbeknownst to the user, their information could be made available to a wide range of unknown actors. Moreover, any security vulnerabilities present during the transfer of this exfiltrated data present opportunities for potentially malicious actors to obtain private user information. In this way, seemingly trustworthy actors can breach a user's privacy and data security by exploiting their naivete. Therefore, it is critically important for software users to both: (i) know if a downloaded piece of software could potentially expose them to data exfiltration and (ii) understand what the consequences of such data exfiltration are. Thus, in this work, we analyze the privacy policies of various videoconferencing services to determine potential data privacy vulnerabilities and avenues for data exfiltration. We then evaluate the privacy policies according to three metrics: specificity, responsibility, and readability to determine how well each service accounts for these data privacy issues. Finally, we provide several recommendations for users wishing to protect their data privacy. 1https://www.theverge.com/2020/2/6/21126245/wacom-tablet-app-tracking-google-analytics 4 2 Background The historic lack of standardization in software privacy policies has conditioned most users to automatically click \yes" and agree to everything in order to access the software. A study performed in 2017 showed that 74% (N=543) of individuals did not choose to read the privacy policy when presented with the option but 97% agreed to it. Even when presented with a mandatory terms of service (TOS) policy, which should take roughly 15 minutes to read at a typical adult reading rate of 250-280 words per minute, users spent an average of 51 seconds reading it. Those who declined the TOS spent 90 seconds longer reading it[1]. This study elucidates an important point: most users do not read privacy policy and terms of service with enough time and given the obfuscated nature of data exfiltration, users are largely unaware their data is being taken from them and do not know how that data will be used. Furthermore, privacy policies contain technical jargon that is difficult for most average users to grasp, making readability low. Even if users are proactive in reading the policies, there is a good chance they will not understand it. The readability of privacy policies is important since users tend to trust them more having understood them [2]. We argue that privacy policies serve as a contract between users and service providers. Therefore, it is important to ensure that all parties, particularly the user, are fully aware of the implications of agreeing to the contract. We will assess the readability of all privacy policies examined in this project. 2.1 Companies Given the recent increased usage and increased scrutiny of videoconferencing platforms due to the ongoing COVID-19 pandemic, we focus on five videoconferencing platforms for our analysis: Cisco Webex, Discord, Google Hangouts, Skype, and Zoom. We provide a brief introduction and description of each of the videoconferencing services studied in the following sections. 2.1.1 Cisco Webex Cisco Webex (originally Webex) is a videoconferencing and collaborative platform wholly owned by the technology conglomerate Cisco Systems. The primary videoconferencing service offered within the Webex platform is Webex Meetings. Thus, we primarily analyze the privacy policy of Webex Meetings [3] specifically, in addition to the general policies outlined in Cisco Systems' online 5 privacy policy [4] where the latter is applicable. 2.1.2 Discord Discord is a VoIP and general communication application that features text, image, video, and audio communication over chat channels on a digital distribution platform similar to a centralized version of IRC designed primarily for gamers, but also other communities including education. We analyze the company's privacy policy [5] as it applies to the platform and software distributed by Discord, Inc. 2.1.3 Google Hangouts Google Hangouts is a communications software developed by Google that supports text chats, audio chats, and video conferencing. It was originally just a feature of Google+, a discontinued social media platform, but has since become a standalone service. Hangouts does not have its own privacy policy and instead references the general Google privacy policy that is shared across many Google services. 2.1.4 Skype Skype is a telecommunications application that allows for video chatting, voice calling, and instant messaging. Microsoft acquired Skype in 2011, so Microsoft's privacy policy now applies to Skype [6]. Skype can be used between various devices such as computers, tablets, mobile devices, the Xbox One console, smartwatches, and Amazon Echo. Specialized Skype products include Microsoft Teams (originally Skype for Business) and Skype for content creators, but we will focus on the general Skype product available for free to all consumers. 2.1.5 Zoom Zoom is a cloud-based peer-to-peer platform for videoconferencing and online chatting developed Zoom Video Communications. The service was originally launched in 2012 by a former executive at Cisco Webex, and has since grown to become one of the most popular videoconferencing platforms. We note that due to increased media scrutiny surrounding its data privacy policies, Zoom made 6 significant updates to its privacy agreement on March 29th, 2020. As such, though we analyze both Zoom's current privacy agreement [7] in comparison to the other videoconferencing services, we also compare its previous privacy agreement [8], dated to December 31st, 2019 in a separate case study in Chapter 5. 3 Methodology In analyzing the privacy policies of each company, we consider a few metrics as described in the next section. We find it important to distinguish between language and substance, so we include metrics for both. Language reflects how easy it is for a consumer to understand the privacy policy, while substance reflects what companies can actually be held accountable for. 3.1 Metrics 3.1.1 Vagueness/Specificity The privacy policies that we have analyzed vary based on notions of specificity and vagueness related to the amount of detail put into the privacy policies by the respective companies. These notions apply to what data the company collects, when it does so, and any guarantees on what it does with such data along with the type of data that is shared with different entities (if any) and what the data is used for. If a company were to list all of this information in full detail, i.e. without some form of catch-all clause, the company would be considered fully specific in how it handles user data. If a company does not list all of this information or includes a catch-all clause in its privacy agreement, then it may be considered more vague depending on the amount of detail in the privacy policy. An example of a fully vague policy would include not disclosing what data is collected or how it is used in any detail. 3.1.2 Responsibility Companies vary in how much responsibility they claim to take when it comes to privacy and data protection. We rate the responsibility of a company from full responsibility, i.e. the company proactively makes sure data is only collected with consent and used for certain functions, to no responsibility, i.e. it is entirely up to the user to consider what data they are sharing when they 7 take certain actions and should have no expectations about what that data might be used for. In the case that a privacy policy does not explicitly state what the company takes responsibility for, we assume the company to fall on the \no responsibility" side of the spectrum. 3.1.3 Readability Readability is another metric we will use in our analysis and evaluation of each company's privacy policies. Quantifying readability is a concurrent research problem in its own right with many viable methods for producing a readability score, but we used the Flesch{Kincaid readability test in this project.
Recommended publications
  • Uila Supported Apps
    Uila Supported Applications and Protocols updated Oct 2020 Application/Protocol Name Full Description 01net.com 01net website, a French high-tech news site. 050 plus is a Japanese embedded smartphone application dedicated to 050 plus audio-conferencing. 0zz0.com 0zz0 is an online solution to store, send and share files 10050.net China Railcom group web portal. This protocol plug-in classifies the http traffic to the host 10086.cn. It also 10086.cn classifies the ssl traffic to the Common Name 10086.cn. 104.com Web site dedicated to job research. 1111.com.tw Website dedicated to job research in Taiwan. 114la.com Chinese web portal operated by YLMF Computer Technology Co. Chinese cloud storing system of the 115 website. It is operated by YLMF 115.com Computer Technology Co. 118114.cn Chinese booking and reservation portal. 11st.co.kr Korean shopping website 11st. It is operated by SK Planet Co. 1337x.org Bittorrent tracker search engine 139mail 139mail is a chinese webmail powered by China Mobile. 15min.lt Lithuanian news portal Chinese web portal 163. It is operated by NetEase, a company which 163.com pioneered the development of Internet in China. 17173.com Website distributing Chinese games. 17u.com Chinese online travel booking website. 20 minutes is a free, daily newspaper available in France, Spain and 20minutes Switzerland. This plugin classifies websites. 24h.com.vn Vietnamese news portal 24ora.com Aruban news portal 24sata.hr Croatian news portal 24SevenOffice 24SevenOffice is a web-based Enterprise resource planning (ERP) systems. 24ur.com Slovenian news portal 2ch.net Japanese adult videos web site 2Shared 2shared is an online space for sharing and storage.
    [Show full text]
  • Integrating Business Processes with Microsoft Lync & Skype for Business
    Integrating Business Processes with Microsoft Lync & Skype for Business A Knowledge Guide by MindLink Software Contents Introduction 3 Barriers To Decision Making 3 Removing Barriers By Leveraging Real-Time Messaging 4 Making Information Accessible 5 • Pull • Push • Command Unleashing The Developer In Everyone 6 Worked Example – Integration With A 7 Marketing Automation Tool Mitigating Risk While Enabling Fluid Integration 10 What Is Mindlink™ 11 Mindlink Suite 11 Introduction Making decisions is hard. Making the right decisions without all the right information is harder. To make effective choices you need everything that matters in front of you, or at the very least you have to remember everything in context. Today’s businesses can’t settle for scattered sources from disparate systems that require manual searching, analysing and collating when it can all be delivered to their feet when they need it. Barriers To Decision Making Businesses evolve rapidly. New systems are designed, redesigned and implemented, replaced and updated regularly. Different departments have different requirements and this usually leads to various information systems spread throughout the organisation. When it comes to making decisions, multiple departments are normally involved, bringing with them information from their own systems. As a decision maker, how can you efficiently and effectively get exactly what you need to make the right choice? The standard procedure may be to ask each departmental stakeholder to send to you the information that they deem relevant. Getting everybody into a room or a conference is hard enough without having to worry about missing information. Ultimately it leads to a string of meetings with various different bits of information that make little progress as data is missing, forgotten, misplaced or misrepresented.
    [Show full text]
  • Facebook Response to the ACCC's Digital Platform Services Inquiry
    Facebook response to the ACCC’s Digital Platform Services Inquiry September 2020 Interim Report 8 March 2021 Executive Summary The growth in the use of messaging apps (private messaging services as referred to in the Digital Platform Services Inquiry (D SPI) Interim Report September 2020 (I nterim Report )) has been one of the key trends of the digital ecosystem in recent years, and this has accelerated during the COVID 19 pandemic as many families, friends and workplaces have used small group conversations and direct messaging to stay in touch. Many different competitive solutions have been developed to respond to this consumer demand - whether it is pre-installed and default messaging apps like iMessage and Android Messages which also have exclusive access to support SMS as well as their own proprietary protocols (along with similar device maker SMS solutions); the wide variety of downloadable apps offering messaging services such as Facebook Messenger, WhatsApp, Telegram, Signal, Snapchat, Discord, TikTok, Twitch or Google Chat (among others); or enterprise platforms such as Slack, Teams and Google Hangouts. Given the important role that messaging apps play in keeping Australian households connected and work colleagues productive, the inquiry as part of the DPSI by the Australian Competition and Consumer Commission ( ACCC ) into private messaging is timely. Following the release of the Interim Report, Facebook provides this submission in order to set forth its concerns with the conclusions reached in the Interim Report. In the Interim Report, the ACCC finds that Facebook’s online private messaging services (Facebook Messenger and WhatsApp) are not “competitively constrained” by other private messaging services, implying that - even though there is a broad array of competing private messaging services - they do not provide effective competition against Facebook’s services.
    [Show full text]
  • Download Windows Live Messenger for Linux Ubuntu
    Download windows live messenger for linux ubuntu But installing applications in Ubuntu that were originally made for I found emescene to be the best Msn Messenger for Ubuntu Linux so far. It really gives you the feel as if you are using Windows Live Messenger. Its builds are available for Archlinux, Debian, Ubuntu, Fedora, Mandriva and Windows. At first I found it quite difficult to use Pidgin Internet Messenger on Ubuntu Linux. Even though it allows signing into MSN, Yahoo! Messenger and Google Talk. While finding MSN Messenger for Linux / Ubuntu, I found different emesene is also available and could be downloaded and installed for. At first I found it quite difficult to use Pidgin Internet Messenger on Ubuntu Linux. Even though it allows signing into MSN, Yahoo! Messenger. A simple & beautiful app for Facebook Messenger. OS X, Windows & Linux By downloading Messenger for Desktop, you acknowledge that it is not an. An alternative MSN Messenger chat client for Linux. It allows Linux users to chat with friends who use MSN Messenger in Windows or Mac OS. The strength of. Windows Live Messenger is an instant messenger application that For more information on installing applications, see InstallingSoftware. sudo apt-get install chromium-browser. 2. After the installation is Windows Live Messenger running in LinuxMint / Ubuntu. You can close the. Linux / X LAN Messenger for Debian/Ubuntu LAN Messenger for Fedora/openSUSE Download LAN Messenger for Windows. Windows installer A MSN Messenger / Live Messenger client for Linux, aiming at integration with the KDE desktop Ubuntu: Ubuntu has KMess in its default repositories.
    [Show full text]
  • Wiretapping End-To-End Encrypted Voip Calls Real-World Attacks on ZRTP
    Institute of Operating Systems and Computer Networks Wiretapping End-to-End Encrypted VoIP Calls Real-World Attacks on ZRTP Dominik Schürmann, Fabian Kabus, Gregor Hildermeier, Lars Wolf, 2017-07-18 wiretapping difficulty End-to-End Encryption SIP + DTLS-SRTP (SIP + Datagram Transport Layer Security-SRTP) End-to-End Encryption & Authentication SIP + SRTP + ZRTP Introduction Man-in-the-Middle ZRTP Attacks Conclusion End-to-End Security for Voice Calls Institute of Operating Systems and Computer Networks No End-to-End Security PSTN (Public Switched Telephone Network) SIP + (S)RTP (Session Initiation Protocol + Secure Real-Time Transport Protocol) 2017-07-18 Dominik Schürmann Wiretapping End-to-End Encrypted VoIP Calls Page 2 of 13 wiretapping difficulty End-to-End Encryption & Authentication SIP + SRTP + ZRTP Introduction Man-in-the-Middle ZRTP Attacks Conclusion End-to-End Security for Voice Calls Institute of Operating Systems and Computer Networks No End-to-End Security PSTN (Public Switched Telephone Network) SIP + (S)RTP (Session Initiation Protocol + Secure Real-Time Transport Protocol) End-to-End Encryption SIP + DTLS-SRTP (SIP + Datagram Transport Layer Security-SRTP) 2017-07-18 Dominik Schürmann Wiretapping End-to-End Encrypted VoIP Calls Page 2 of 13 wiretapping difficulty Introduction Man-in-the-Middle ZRTP Attacks Conclusion End-to-End Security for Voice Calls Institute of Operating Systems and Computer Networks No End-to-End Security PSTN (Public Switched Telephone Network) SIP + (S)RTP (Session Initiation Protocol + Secure Real-Time
    [Show full text]
  • The Extreme Right on Discord
    Gaming and Extremism The Extreme Right on Discord Aoife Gallagher, Ciaran O’Connor, Pierre Vaux, Elise Thomas, Jacob Davey About the series This briefing is part of ISD’s Gaming and Extremism Series exploring the role online gaming plays in the strategy of far-right extremists in the UK and globally. This is part of a broader programme on the ‘Future of Extremism’ being delivered by ISD in the second half of 2021, charting the transformational shifts in the extremist threat landscape two decades on from 9/11, and the policy strategies required to counter the next generation of extremist threats. It provides a snapshot overview of the extreme right’s use of Discord. Gaming and Extremism Contents 3 Contents Executive Summary 4 Key Findings 4 Findings of Analysis 5 Vetting, Verification & Channel Creation 5 Function of Servers 5 The Role of Gaming 6 Case Studies 8 Conclusion 10 Methodology 11 Gaming and Extremism The Extreme Right on Discord 4 Executive summary Discord is a free service accessible via phones and Key Findings computers. It allows users to talk to each other in real time via voice, text or video chat and emerged • We found that the Discord primarily acts in 2015 as a platform designed to assist gamers in as a hub for extreme right-wing socialising communicating with each other while playing video and community building. Our analysis suggests games. The popularity of the platform has surged that Discord provides a safe space for users in recent years, and it is currently estimated to to share ideological material and explore have 140 million monthly active users.1 extremist movements.
    [Show full text]
  • Discord and the Harbormen Gaming Community 1
    Running Head: DISCORD AND THE HARBORMEN GAMING COMMUNITY 1 DISCORD AND THE HARBORMEN GAMING COMMUNITY Maya Anderson Comm 416 June 7 2019 DISCORD AND THE HARBORMEN GAMING COMMUNITY 2 Introduction Discord is an application mainly used by video game players to communicate with one another. A specific gaming community known as the Harbormen has made consistent use of this platform to communicate with its members. My interest lies in exploring how Discord has shaped this online gaming community. Social media is known to play a role in our very identities, and the platforms we use can often determine what personas we present (Cirucci, 2012). Exploring Discord specifically may yield different results than one would find in other platforms due to the niche audience and nature of the application. As a result of affordances, the platform has potential to remove social insecurities and enhance communication (Kowert, Domahidi, & Quandt, 2014). I would ultimately like to understand if Discord helps enforce the values and behaviors of the Harbormen gaming community. There are several studies on the impact of video games and gaming communities on sociability and skill development, yet they do not address how culture is created within these gaming communities, much less how the platforms utilized by these communities influence them. Studying this may create a greater understanding of how individuals experience community and culture in these online environments. It may prove also prove useful to leaders of gaming communities by locating areas of improvement, highlighting favorable communication techniques, and understanding members’ needs. Company Profile Discord is an application specifically built to enhance communication among video game players.
    [Show full text]
  • Jitsi User Guide
    Jitsi Guide Multi-platform open-source video conferencing Quick guide to Jitsi calls, meetings and office hours by Peter E. Humphries, March 21, 2020 English (GB): Peter Humphries, [email protected] English (US): Peter Humphries, [email protected] Français (FR): Peter Humphries, [email protected] Licensed under a Creative Commons Attribution-ShareAlike 4.0 International Licence (CC BY-SA 4.0). Android Client: 1. Open the Jitsi application on your Android device. 2. Enter a new name for your meeting “room” to start a new meeting. You can enter the name of an existing meeting room to join a meeting already in progress. Figure 2 Jitsi Android client iOS Client: 1. Open the Jitsi application on your iOS device. 2. Enter a new name for your meeting “room” to start a new meeting. You can enter the name of an existing meeting room to join a meeting already in progress. Figure 3 Jitsi iOS client Getting Started You can host or attend Jitsi meetings from your browser or from the Jitsi client application on your mobile device. For more information about Jitsi meetings, go to the https://jitsi.org/ page. Click on START A CALL to open a Jitsi meeting room! Figure 4 Jitsi home page ( https://jitsi.org/ ) Jitsi can handle up to 75 participants in a “meeting room.” Practically, fewer should be active participants. For larger groups, Jitsi offers easy integration with YouTube’s live streaming service. Starting a Meeting Web Portal: 1. Go to https://meet.jit.si/ or click on START A CALL if you are on the Jitsi home page.
    [Show full text]
  • National Security Agency | Cybersecurity Information Selecting
    National Security Agency | Cybersecurity Information Selecting and Safely Using Collaboration Services for Telework - UPDATE Summary During a global pandemic or other crisis contingency scenarios, many United States Government (USG) personnel must operate from home while continuing to perform critical national functions and support continuity of government services. With limited access to government furnished equipment (GFE) such as laptops and secure smartphones, the use of (not typically approved) commercial collaboration services on personal devices for limited government official use becomes necessary and unavoidable. We define collaboration services as those capabilities that allow the workforce to communicate via internet-enabled text, voice, and video, and can include the sharing of files and other mission content. Collaboration can occur between two people or widened to include a large group to support mission needs. This document provides a snapshot of best practices and criteria based on capabilities available at the time of publication and was coordinated with the Department of Homeland Security (DHS), which has released similar guidance: “Cybersecurity Recommendations for Federal Agencies Using Video Conferencing” [1] and “Guidance for Securing Video Conferencing” [2]. This NSA publication is designed to provide simple and actionable considerations for individual government users. The intent of this document is not meant to be exhaustive or based on formal testing, but rather be responsive to a growing demand amongst the federal government to allow its workforce to operate remotely using personal devices when deemed to be in the best interests of the health and welfare of its workforce and the nation. Recommendations in this document are likely to change as collaboration services evolve and also address known vulnerabilities and threats.
    [Show full text]
  • SOCIAL MEDIA Edie White, M.Ed
    SOCIAL MEDIA Edie White, M.Ed. Coordinator for Bullying Prevention Social media are web-based communication tools that enable people to interact with each other by sharing and consuming information. CAN YOU NAME THESE APPS? ADVANTAGES OF SOCIAL MEDIA Communication Connection Personal branding Technological literacy Access to information DIGITAL DANGERS Risky behavior for “likes” Increase in anxiety and depression Sleep deprivation Low self-esteem COMPARISON TRAP FEAR OF MISSING OUT “FOMO” THIS IS YOUR BRAIN... ADDICTION DIGITAL FOOTPRINT Nothing ever truly disappears in the digital world. DIGITAL DRAMA CYBERBULLYING SOCIAL NETWORKING APPS SNAPCHAT • Snaps disappear immediately after viewing and Stories disappear after 24 hours • “Snap Map” shows location • Snapchat Discover Stories regularly have sexually explicit images and articles — not for kids! TWITTER INSTAGRAM • Doesn’t enforce content restrictions • Instagram accounts are public by default • Sub-tweeting creates digital drama or • Finsta accounts crosses the line into cyberbullying • Sexually explicit content NAVIGATING INSTAGRAM CHECKING FOLLOWERS PRIVATE DOESN'T ALWAYS MEAN PRIVATE VIDEO APPS YOUTUBE TIKTOK • Access to inappropriate material • Explicit language • Bullying • Inappropriate material • Bullying • Direct message MEET UP APPS LIPSI MEETME YUBO • "It’s a platform that attracts the • “Chat and meet new people” • “Tinder for Teens” boldest who want to step out of their • Default privacy settings are to comfort zone. Meet new people in • MeetMe is aiming people class,
    [Show full text]
  • Linphone a Good Working Skype Voice Over IP Alternative
    Walking in Light with Christ - Faith, Computing, Diary Articles & tips and tricks on GNU/Linux, FreeBSD, Windows, mobile phone articles, religious related texts http://www.pc-freak.net/blog Linphone a good working Skype voice over IP alternative Author : admin If you never tried linphone I warmly recommend it. 2 days ago, with a friend of mine we tested a bunch of Linux softwares to find out what is the situation with possible alternatives to Skype to transmit Voice and Video. I've been interested into Skype Alternative programs since about 2 years, but so far I never found good and easy to set up working Linux alternative. We first tried Ekiga. Though it is said to be a good Linux SKype alternative, my ekiga client running on Debian Linux stable Squeeze ver. 3.2.7.2 failed to connect to SIP account I've created on ekiga.net. I've tried hard to make ekiga connect to account SIP created from ekiga.net but all time I was getting an error on connect: Ekiga did not manage to configure your network settings automatically. You can still use it, but you need to configure your network settings manually. Please see http://wiki.ekiga.org/index.php/Enable_port_forwarding_manually for instructions After continously trying to follow instructions from above pointed URL and making proper settings on my DL-524 Wireless Router and all time ending up with the annoying error, we decided to finally completely abondoned it and try some other voice over IP clients. We tried Jitsi and few others which prooved to be unworking.
    [Show full text]
  • Virtual Excursions – Web Conferencing
    Virtual excursions Create amazing STEM engagement programs online Technical set up | Best practice Partnering for impact | Engaging community Evaluate & Iterate ABOUT THE MANUAL About Inspiring Australia Inspiring Australia is the national strategy for public engagement with STEM and contributes to the Government’s vision to engage all Australians with science. Since 2009, the initiative supported by Commonwealth, State and Territory Governments facilitates science engagement programs and supports communities in diverse ways including through fostering influential networks to connect science to big audiences and delivering grant programs to organisations, groups and individuals. Inspiring Australia science engagement activities connect with people nationwide to: • build an awareness and appreciation of science • celebrate the excitement of science and scientific discovery • enhance capability and skills • improve science communication. In 2020, global events forced many organisations to adapt their large scale events and STEM engagement for online delivery modes. Inspiring Australia state programs have developed this online training opportunity to assist community partners to transition their programs to online delivery. This manual draws on the expertise of specialists in online education and STEM communication backed by research to deliver the tools, techniques and tips to help practitioners develop rich, deep and meaningful online STEM engagement. The Virtual Excursions training package has been coordinated for national delivery by Inspiring Australia NSW. It is produced and delivered by Fizzics Education, Sydney Science Education and Refraction Media with support from the Office of the NSW Chief Scientist & Engineer and state Inspiring Australia programs in NSW, ACT, QLD, WA and SA. © Inspiring Australia. Published by Refraction Media on 11 May 2020.
    [Show full text]