Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Friday, September 21, 2007

DRM: a Threat to Privacy

Via Michael Geist by way of BoingBoing we learn that The University of Ottawa's Canadian Internet Policy and Public Interest Clinic has released a report concluding that DRM pose a significant threat to privacy. From the executive summary:


• Fundamental privacy-based criticisms of DRM are well-founded: we observed
tracking of usage habits, surfing habits, and technical data.
• Privacy invasive behaviour emerged in surprising places. For example, we
observed e-book software profiling individuals. We unexpectedly encountered
DoubleClick – an online marketing firm – in a library digital audio book.
• Many organizations take the position that IP addresses do not constitute
“personal information” under PIPEDA [Personal Information Protection and
Electronic Documents Act] and therefore can be collected, used
and disclosed at will. This interpretation is contrary to Privacy Commissioner
findings. IP addresses are collected by a variety of DRM tools, including
tracking technologies such as cookies and pixel tags (also known as web
bugs, clear gifs, and web beacons).
• Companies using DRM to deliver content often do not adequately document
in their privacy policies the DRM-related collection, use and disclosure of
personal information. This is particularly so where the DRM originates with a
third party supplier.
• Companies using DRM often fail to comply with basic requirements of
PIPEDA.


This, sadly, should not be a surprise. Copyright organizations have shown themselves to be actively hostile to concerns about information security and data privacy (see, e.g., the discussion of concerns related to watermarking here, or Sony's now infamous fondness for installing rootkits). Indeed, the only time when copyright and information security are (supposedly) aligned is when copyright is trying to piggyback on security concerns to achieve its own ends (e.g., the destruction of P2P networks, as described here).

The happy news though, is that the study came out in the first place. It is possible that this examination of the impact of DRM on privacy could be a reflection of some sort of backlash against the copyright industry's current tactics - something that, if supported by legislation, could result in significant benefits for privacy and security of individual data.

Sunday, August 26, 2007

Monster.com Breach Highlights Limitations of Notification Laws

Do you have your resume posted on line? If so, then there's a good chance you've heard about the data breach at Monster.com, described in this article from C|NET. The breach itself wasn't record breaking...a mere 1.3 million job seekers had their data stolen. While the fact that 1.3 million records seems like a relatively small breach is somewhat troubling in itself, this post isn't written to decry the fact the disturing frequency of data breaches. Instead, it is written to show some of the limits of data breach notification laws as they are currently written. In the monster.com breach, the information stolen included names, addresses, phone numbers, and email addresses. No other details such as bank account numbers were uploaded. While most states have laws that require companies to provide notification of unauthorized access to their customers' personal information, those laws don't necessarily cover breaches like that at monster. For example, California's SB 1386 defines "personal information" as

an individual's first name or first initial and last name in combination
with any one or more of the following data elements, when either the
name or the data elements are not encrypted:
(1) Social security number.
(2) Driver's license number or California Identification Card
number.
(3) Account number, credit or debit card number, in combination
with any required security code, access code, or password that would
permit access to an individual's financial account.

In the monster.com breach, none of the information set forth in subsections (1)-(3) quoted above was stolen, so the breach itself appears to fall outside the scope of the law. Does this mean that the monster.com breach was innocuous? Not at all. According to the C|NET article, the individuals who hacked monster.com would send emails attempting to get further information from people whose data had been stolen. The emails would be created using the stolen data, giving them more credibility than they would otherwise have, and making it more likely that the emails' recipients would think they were legitimate. While that type of risk doesn't seem to be one that California's data breach notification law was intended to cover, it is possible that more breaches of the monster.com variety will occur, as businesses begin to react to existing law by making it less likely that bank account numbers or other information are available for hackers. If that is the case, state legislatures might consider revisting their existing laws, and revising them as necessary to deal with this newer type of threat.

Wednesday, April 11, 2007

State Enforcement Actions

While federal laws such as Gramm-Leach-Bliley and HIPAA are often the focus of concern for organizations seeking to maintain regulatory compliance, it is important to remember that many states have put in place requirements which must be observed as well. Case in point: Texas, where the attorney general took action against Radio Shack for violating that state's 2005 Identity Theft Enforcement and Protection Act and section 35.581 of Chapter 35 of Texas' Business and Commerce Code. According to the attorney general's press release Radio Shack had failed to properly protect and dispose of their customers' by simply dumping bulk records in a garbage receptacle behind a store. The dumped records included, ironically, a receipt from a woman who purchased a shredder from Radio Shack to protect herself from identity theft - just the kind of potential victim the media loves to focus on. Thus, the Radio Shack prosecution should serve as a reminder to businesses everywhere that Federal Law isn't the only source of data privacy and information security law, and it is necessary to be mindful of state statutes as well.

Monday, March 12, 2007

Private Sector Responding to Data Privacy and Security Concerns

While my last post discussed whether federal data security legislation was inevitable, it seems that industry isn't waiting for Congress to act before implementing measures which should be welcome news for anyone concerned with the security of their personal information. First, on the 12th, Seagate Technology announced that a manufacturer would begin selling laptops with built in encryption technology. According to this article, Seagate the new machines
will include a chip that makes it impossible for anyone to read data off the disk, or even boot up a PC, without some form of authentication.
thus (hopefully) making the scares following loss or theft of laptops containing sensitive information a thing of the past. Also, coming fast on the heels of the Seagate announcement, Google has announced that it will revise its data retention policies to protect user privacy. According to this article, Google will begin implementing a policy to anonymize user search records 18-24 months after their creation. When some privacy advocates, such as the electronic privacy information center's executive director, Mark Rotenberg, say that Google's new policy doesn't go far enough, it should be a welcome improvement from Google's current policy of maintaining identifying information in search records indefinitely.

Sunday, February 4, 2007

Wired.com currently has a very interesting series of articles up on the world or criminal carders (individuals who steal, sell, and use credit card and identify information of others). Largely, the articles are interesting because they provide a fascinating look into a world that most law abiding citizens don't even know exists. However, they also provide some helpful advice for businesses seeking to reduce their vulnerability (e.g., when information is changed on an on-line account, have a substantial waiting period before the assets in the account can be withdrawn).

Bottom line: an interesting read for anyone who uses or issues credit cards.