Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Friday, September 21, 2007

DRM: a Threat to Privacy

Via Michael Geist by way of BoingBoing we learn that The University of Ottawa's Canadian Internet Policy and Public Interest Clinic has released a report concluding that DRM pose a significant threat to privacy. From the executive summary:


• Fundamental privacy-based criticisms of DRM are well-founded: we observed
tracking of usage habits, surfing habits, and technical data.
• Privacy invasive behaviour emerged in surprising places. For example, we
observed e-book software profiling individuals. We unexpectedly encountered
DoubleClick – an online marketing firm – in a library digital audio book.
• Many organizations take the position that IP addresses do not constitute
“personal information” under PIPEDA [Personal Information Protection and
Electronic Documents Act] and therefore can be collected, used
and disclosed at will. This interpretation is contrary to Privacy Commissioner
findings. IP addresses are collected by a variety of DRM tools, including
tracking technologies such as cookies and pixel tags (also known as web
bugs, clear gifs, and web beacons).
• Companies using DRM to deliver content often do not adequately document
in their privacy policies the DRM-related collection, use and disclosure of
personal information. This is particularly so where the DRM originates with a
third party supplier.
• Companies using DRM often fail to comply with basic requirements of
PIPEDA.


This, sadly, should not be a surprise. Copyright organizations have shown themselves to be actively hostile to concerns about information security and data privacy (see, e.g., the discussion of concerns related to watermarking here, or Sony's now infamous fondness for installing rootkits). Indeed, the only time when copyright and information security are (supposedly) aligned is when copyright is trying to piggyback on security concerns to achieve its own ends (e.g., the destruction of P2P networks, as described here).

The happy news though, is that the study came out in the first place. It is possible that this examination of the impact of DRM on privacy could be a reflection of some sort of backlash against the copyright industry's current tactics - something that, if supported by legislation, could result in significant benefits for privacy and security of individual data.

Thursday, September 13, 2007

Major Change to California Law Regarding Security Breaches Coming

Back in July, I wrote about a proposed California law which would require merchants who suffer from data security breaches (think TJX) to reimburse financial institutions for the cost of replacing credit cards for people whose information is stolen (link here). Now, according to this article from Computer World, that bill has passed through the California senate and now awaits signature by governor Schwarzenegger. Though the law has had some changes as it moved through the legislature. For example, a new provision has been added which would allow merchants to excused for some or all of the costs of card replacement if it can show it was in compliance with all security requirements at the time of the breach. However, the main focus of the law - shifting costs from merchants to banks, remains intact. According to the Computer World article, if signed, the law is expected to have the same ripple effect that California's SB 1386 had on security breach notification in general.

Thursday, August 16, 2007

How Much Does a Mega-Breach Cost?

According to this article from Computerworld TJX has announced that the costs of a massive 45 million+ record data breach could reach over $150,000,000. While certainly a significant amount of money (I know my net worth doesn't even approach $150,000,000) the figure given by TJX is actually significantly less than I would have expected. When taking into account the magnitude of the breach, the per record cost given by TJX is only about $3.30. That's orders of magnitude lower than the $182/record average cost given by the Ponemon institute described in this article. While it's possible that larger breaches have lower cost/record numbers (something like buying in bulk), my guess is that $150,000,000 is something of a lowball estimate. However, even at $3.30/record, a breach like the one which hit TJX isn't cheap, and even the $150,000,000 figure is likely to spur some long overdue emphasis on information security.

Tuesday, August 14, 2007

Search Engines and Privacy

CNET has an interesting article comparing the privacy policies of major search engines. According to that article Ask has the best privacy practices while Yahoo had the worst. One apparent weakness in the article was its focus on the companies' use of data (e.g., how long is it kept; do the companies rely on behavioral targeting of ads). While a company's use of data is clearly a major privacy concern, I would also be interested to see a survey which included information on how protective the companies were of the data that they do have. For example, Google actively fought the government when subpoenas were issued requesting information on searches performed by Google users (see this article (have to scroll down) for more information). To my mind, that should give the search engine giant a bump, especially given how eager most companies seem to be to hand over any and all customer information to the government (e.g., AT&T, whose behavior resulted in a lawsuit by the EFF as described here.

However, in spite of its inadequacies, the article still contained useful information. One interesting point is the discussion in the article of the effect of regulation on search engine privacy policies. For example, the article cited efforts by a group of European bureaucrats called the Article 29 Working Party as being a contributing factor in adoption of time limits for data retention by search engine providers. If there really is a causal connection, it would be a good example of how globalization can actually benefit consumer rights, since Americans would essentially be reaping the privacy benefits of regulatory pressures experienced by companies doing business in Europe.

Friday, July 27, 2007

Priorities

Recently, at a hearing on P2P networks, Henry Waxman stated that he was considering laws aimed at the problem of inadvertent leaking of classified information (described here and here). Apparently, sensitive documents have been making their way onto P2P networks such as those accessed via Limewire or Kazaa. While this is obviously a problem, the solution proposed by Waxman - regulating the networks - is insane. I could access that sensitive data through my computer, and, in getting to my computer, that sensitive data would travel through a DSL line. However, Mr. Waxman isn't proposing that computer makers or telcos take responsibility for making sure that people can't access sensitive documents. The reason is obvious: telcos and computer makers can't be responsible for the actions of end users, because there is no effective way for them to control end users without effectively shutting down. P2P networks are no different. Looking at his comments charitably, it seems that Mr. Waxman simply doesn't understand the consequences of putting responsibility for the acts of consumers on the providers of P2P software.

Of course, it is also possible to look at Mr. Waxman's comments in a less charitable light. Currently, the federal government is scrambling to meet a White House directive on securing personal data (details can be found here) and it seems that there is an almost continuous stream of incidents of lost data involving government employees (e.g., the theft of a laptop containing records for 26.5 million veterans, described here), so attacking an easy target, such as P2P networks, could serve an instrumental purpose for Waxman of making it appear that he is doing something about information security. Further, by attacking P2P networks as a threat to national security, Waxman is undoubtedly pleasing the powerful recording industry, which has been seeking to destroy P2P technology ever since Napster. In this regard, it is telling that Waxman said that he would seek to achieve a balance between "sensitive government, personal and corporate information and copyright laws" (emphasis added). Given that protecting copyrights, while a valid concern, is an entirely different type of objective than protecting the physical well-being of Americans by improving national security, the inclusion of copyright law on that list seems strange. However, if the primary motivation to regulate P2P networks is to benefit copyright holders, then the list provided by Mr. Waxman makes perfect sense, with the national security concerns acting as window dressing for the desire to shut down P2P networks on behalf of copyright holders.

In any case, I think it is extremely unlikely that regulating P2P networks is a viable solution to the Federal Government's information security problems. Even if P2P networks were banned entirely, that would do nothing to stop people from stealing data, or from losing the media on which data are stored. However, when faced with a decision as to whether to spend time exercising oversight on HR or training policies which might increase information security, and blasting the enemies of the RIAA, it is clear where Congress' priorities lie. Disappointing, but not at all a surprise.

Tuesday, June 26, 2007

What Can Information Security Learn From Digital Rights Management

Recently, Mircosoft decided not to remove virtualization restrictions from its Vista operating system. According to this article, the probable reason for Microsoft's decision is that Vista's virtualization features have the practical effect of incapacitating Vista's Digital Rights Management (DRM) features. Given that the fundamental purpose of DRM technology - controlling reproduction and use of information - is the same as the fundamental purpose of most information security policies, Microsoft's decision to simply restrict access to a desirable product feature could mean that some technologies, such as virtualization, are simply incompatible with information control. The lesson for businesses seeking to avoid security breaches? The threat from some technologies (e.g., portable mass storage devices) might be so great that they should be kept out of corporate networks all together. Otherwise, until an effective technical solution is found (and Microsoft apparently hasn't been able to develop one yet), some things are just an invitation for trouble.

Wednesday, June 20, 2007

Banks v. Merchants

One rift between interest groups which has emerged in the world of information security is between merchants and banks. The basic conflict is driven by banks' fear of exposure based on acts (or failure to act) by merchants. This leads to banks imposing standards (e.g., the payment card industry data security standard) on merchants, who are then faced with the prospect of struggling to comply with what seem to be mercurial and/or contradictory mandates. The result, predictably, is frustration for all sides, such as was shown in a recent panel discussion sponsored by Symantec (described in this article). That frustration has also manifested itself in more problematic ways, such as noncompliance by merchants who feel that they are too expensive or too unwieldy (as blogged here).

However, it seems that that frustration also has the potential to lead to positive change. For example, in response to complaints by merchants, the payment card industry is changing the way its data security standard will be defined in the future (blogged about here). Similarly, in response to concerns from banks, states are considering laws which would shift the cost of cleaning up after data breaches to the entities who cause them (one such proposal is described in this article). The lesson from all this? First, if you have concerns about data security, regardless of what type of organization you represent, you're not alone. Second, if you express your concerns, there's a real possibility that they will be addressed, as both public and private organizations have shown themselves to be responsive to feedback and criticism.

Tuesday, June 12, 2007

Dubai First Arab Nation to Adopt Data Protection Law

On May 29, 2007, the Data Protection Commission of Dubai issued an Enforcement and Compliance Notice. It directs all DIFC entities, whether or not regulated by the Dubai Financial Services Authority, to register with the Commissioner of Data Protection by June 30, 2007, and to comply with all aspects of the Dubai Data Protection Law. Companies failing to comply will be subjected to fines and penalties.

In January, 2007, the Data Protection Law 2006 became effective, which applies in the jurisdiction of the Dubai International Financial Center (DIFC). The law regulates and protects individuals’ “personal information,” and will have immediate implications for companies operating in Dubai, especially those companies that transfer data from one office to another in different jurisdictions. “Personal information” is defined broadly as “any information relating to an identifiable natural person.” The law also protects “sensitive data” such as information about a person’s political affiliation or racial identity.

The most significant provisions of the Dubai Data Protection Law concern international transfer of data, governing the transfer of personal information out of the DIFC to other countries. It requires that those recipient countries provide “an adequate level of protection” for the personal information, which is the same as the standard imposed by the EU Data Privacy Directive. Transfers of personal information to countries without such protection (including the United States) are permitted only with the consent of the newly appointed Commissioner of Data Protection. The regulations, which became effective in March, 2007, do not specify which countries qualify as having an “adequate level of protection,” however, although it is anticipated that the DIFC will simply adopt the list of the EU “certified” countries.

The regulations also provide for an application process to obtain a permit to process information out of the DIFC to a country that does not provide an adequate level of protection. There are other stated conditions to the transfer of personal information, such as the written consent of the data subject, or that the transfer is necessary or legally required on grounds important in the interests of the DIFC.