Thursday, October 4, 2007

A Post Having Nothing to do With Information Security or Data Privacy

Recently, I was invited to do some guest posting at Metlin - an eclectic blog run by Karthik Narayanaswami, a multi-talented (quantum physics, programming, mathematics and mountaineering, to name just a few) friend of mine from Cincinnati. My first post can be found here and, as advertised, it has nothing to do with information security or data privacy.

Regularly scheduled programming will resume shortly...

Tuesday, October 2, 2007

Banks Object to Bill Limiting Use of SS Numbers

Two new government initiatives to restrict the use of Social Security numbers have put banks on the defensive. As part of President Bush's Identity Theft Task Force, the FTC has sought comment on the necessity for such a widespread use of Social Security numbers and alternatives. In addition, the House Ways and Means Committee has approved a bill that would strictly limit the "sale, purchase, or display" of Social Security numbers. This bill is expected to be voted on this fall, but a companion bill has not yet been introduced in the House. Analysts say that the banking industry has voiced opposition to any efforts to limit the use of Social Security numbers, since these numbers are an integral part of their customer information files. Bank Technology News However, they are in danger of finding themselves in the midst of a public relations snafu, since it would not reflect well on banks to oppose efforts to protect customers' identity. Further, banks would arguably benefit from limiting the use of Social Security numbers in connection with account relationships, since one category of bank fraud losses, new account fraud, is directly tied to the use of stolen Social Security numbers. But those losses pale in comparison to the costs banks would incur in being required to shift to a different customer idenification number system.

Monday, October 1, 2007

Study Finds TJX Data Theft Was Preventable

According to a study conducted by Canadian privacy authorities, TJX failed to utilize sufficient security precautions which would have prevented the security breach experienced by the retail giant earlier this year. Jennifer Stoddart, the Privacy Commissioner of Canada, commented on the report, identifying TJX's information gathering and retention policies, as well as weak encryption technology, as the reason that the criminal groups were able to carry out the largest data security theft to date. Stoddart cited the TJX incident as a wake up call to other businesses that collect personal information.
<"http://news.zdnet.co.uk/security/0,1000000189,39289645,00.htm ">See this article. The Disposal Rule imposed by U.S. regulations is intended to prevent companies from retaining customers' personal information longer than necessary, but unfortunately it only applies to consumer credit reports. Retailers run the same risk of a security breach as TJX does if they do not heed the "wakeup call." Collecting unnecessary information in connection with a transaction and retaining it indefinitely presents an example of sloppy information management, and can provide criminal groups with a treasure trove of data ripe for resale and abuse.

Sunday, September 30, 2007

Collision of Privacy and Security?

Wired.com has an article up entitled Dot-Name Becomes Cybercrime Haven which discusses security implications of fees which are charged by Global Name Registry, the entity which administers domain names ending in ".name". For most domains (e.g., those ending in ".com") you can easily and without paying any fee find out who has registered the domain. However, with domains ending in ".name", to find out who has registered a domain, it is necessary to pay a fee of $2.00. The wired article makes this sound like a catastrophe for security, quoting one researcher who says that "What they have done is made sure the .name TLD is free haven for bad guys to lurk on...If I need to report 1,000 domains, I'm not going pay $2,000." But is charging $2.00 to learn who registered a domain really such a problem for security? After all, if a black hat hacker registers a .com domain, it seems very unlikely that they'd use their real name and address to do so (something which was pointed out in this comment to the wired.com story). Similarly, if Global Name Registry was served with legal papers, they'd almost certainly cough up the registration information without a fight. Thus, charging a gatekeeping fee seems to be just what the president of Global Name Registry said in his own comment to the story: a compromise between protecting the privacy of individuals and the legacy of openness which has been one of the hallmarks of the Whois domain name system.

The problem with that is that Global Name Registry's protestations about caring for individual privacy are totally disingenuous. For example, to sign up for a ".name" domain you have to agree to terms and conditions which include the following privacy policy:

PRIVACY POLICY: You agree and consent that we will make available the domain name registration information you provide or that we otherwise maintain to the following parties: ICANN, the Registry administrator, and to other third parties as ICANN and applicable laws may require or permit (including through web-based and other on-line WHOIS lookup systems), whether during or after the term of your domain name registration services of the domain name. You hereby irrevocably waive any and all claims and causes of action you may have arising from such disclosure or use of such information. Additionally, you acknowledge that ICANN may establish or modify the guidelines, limits and/or requirements that relate to the amount and type of information that we may or must make available to the public or to private entities, and the manner in which such information is made available.
(emphasis added)

In other words, as long as the law doesn't prohibit Global Name Registry from disclosing information, you agree that they'll do so - not exactly the policy of an organization which values its customers' privacy. Instead, it's exactly the policy you'd expect from an organization which wished to maximize its profit.

Tuesday, September 25, 2007

TJX to Pay Settlement (Maybe)

According to this article from ComputerWorld TJX has proposed to settle consumer class actions arising from its massive data breach earlier this year. As part of the settlement, TJX would provide credit monitoring, identity theft insurance, and payment of the cost of credit card replacement for individuals whose personal data may have been stolen during the breach. The company would also agree to hold a 15% off sale at some point in the next year, and to pay for "certain losses from identity theft" for individuals whose driver's license or other ID numbers were the same as their Social Security numbers.

The questions now are whether consumers should take the settlement, and whether the court should bless it as fair. At first blush, it seems like the settlement is almost an insult. After all, large retailers routinely hold sales with discounts greater than the 15% off that TJX is offering, and it is not clear what the "certain losses from identity theft" that TJX would agree to cover would actually entail. On the other hand, the credit monitoring, card replacement and free identity theft insurance are real benefits. True, it might seem like paying these costs is the least TJX should do, but when consumers have tried to use courts to force those payments out of companies which have had a security breach they have generally been unsuccessful. For example, this post discusses a case from the seventh circuit where consumers were thrown (figuratively) out of court because the judges decided that damages from fear of future identity theft weren't real enough to be used as a basis for compensation - even compensation for the cost of credit monitoring. Thus, while the settlement from TJX may seem like a bargain, it could be the best that the consumer plaintiffs can reasonably expect.

Friday, September 21, 2007

DRM: a Threat to Privacy

Via Michael Geist by way of BoingBoing we learn that The University of Ottawa's Canadian Internet Policy and Public Interest Clinic has released a report concluding that DRM pose a significant threat to privacy. From the executive summary:


• Fundamental privacy-based criticisms of DRM are well-founded: we observed
tracking of usage habits, surfing habits, and technical data.
• Privacy invasive behaviour emerged in surprising places. For example, we
observed e-book software profiling individuals. We unexpectedly encountered
DoubleClick – an online marketing firm – in a library digital audio book.
• Many organizations take the position that IP addresses do not constitute
“personal information” under PIPEDA [Personal Information Protection and
Electronic Documents Act] and therefore can be collected, used
and disclosed at will. This interpretation is contrary to Privacy Commissioner
findings. IP addresses are collected by a variety of DRM tools, including
tracking technologies such as cookies and pixel tags (also known as web
bugs, clear gifs, and web beacons).
• Companies using DRM to deliver content often do not adequately document
in their privacy policies the DRM-related collection, use and disclosure of
personal information. This is particularly so where the DRM originates with a
third party supplier.
• Companies using DRM often fail to comply with basic requirements of
PIPEDA.


This, sadly, should not be a surprise. Copyright organizations have shown themselves to be actively hostile to concerns about information security and data privacy (see, e.g., the discussion of concerns related to watermarking here, or Sony's now infamous fondness for installing rootkits). Indeed, the only time when copyright and information security are (supposedly) aligned is when copyright is trying to piggyback on security concerns to achieve its own ends (e.g., the destruction of P2P networks, as described here).

The happy news though, is that the study came out in the first place. It is possible that this examination of the impact of DRM on privacy could be a reflection of some sort of backlash against the copyright industry's current tactics - something that, if supported by legislation, could result in significant benefits for privacy and security of individual data.

Thursday, September 20, 2007

Quick Roundup

A few links of interest having to do with data privacy and information security. First, there's this article from Computer World which says that Facebook and MySpace users are happy to trade privacy for features. Really, this isn't a big surprise (I blogged here about a Wired story which described the small value most people place on privacy), but it is yet another data point showing just how little most people care about privacy. Also of interest is a current series of posts at the Dunning letter where Jack Dunning lays out his proposal for how individuals can control (and profit from) their personal information. Jack is highly knowledgeable about privacy issues, having worked on the inside as a junk mailer for years, and now working on the outside trying to improve privacy protections for individuals.

However, what has been devouring my internet time of late isn't actually privacy related - it's the "don't tase me bro" story (link to a discussion of the underlying incident here). Hopefully when that has played out, I'll find myself less distracted, and more able to provide some substantive analysis (especially of Jack's recent posts, which certainly deserve careful consideration).