Tuesday, June 24, 2008

Throw those credit cards out...unless you like not having any privacy,

A recent report by Freedom Works discussed one of the newest privacy threats we should know about. Congress has sketched a new proposal that would require all merchants' payment systems to be tracked, recorded, and reported to the federal government.

This legislation will affect any credit card transaction made. Businesses will be required to give up that information once they swipe a card. The hopes of Internet privacy or being able to surf anonymously may be nonexistent if you use Amazon, PayPal, or any other online merchant. The online vendors are also required to divulge the information and report transactions to the government.

Many questions are raised throughout this article such as:
  • What is the federal government's purpose with this kind of detailed data?
  • How will this database be secured, and who will have access?
  • Many small proprietors use their Social Security number as their tax ID. How will their privacy be protected?
  • What compliance costs will this impose on businesses?
These important questions need to be answered before the legislation continues. With the rise of ID Theft and American citizens' worries about government spying, this legislation seems to completely forgo privacy protection.

Wednesday, June 18, 2008

Airport security adds another invasion of privacy to the list.

Remember when you were younger and wanted x-ray glasses? Well now all you have to do is get a job with the Transportation Security Administration. This recent article from The Dallas Morning News (dallasnews.com) reports on the newest invasion of privacy when traveling.

The TSA is using a new scanning method which has many people baffled and shocked. The new millimeter wave whole body image device shows what's going on under a traveler's clothes. The TSA argues that this will speed up the screening process...at the expense of someone seeing a 3-D image of what is under your clothes. This will increase security measures since only metal objects are detected via a magnetometer.

Privacy advocates are saying that these images are too revealing. This is the equivalent of being strip searched. The TSA and privacy advocates do not agree on the potential uses for this. Ultimately privacy advocates are saying, "American passengers should not have to parade naked in front of security screeners in order to board the plane."

The TSA has a modesty filter on the machines so that images are not too revealing...how does this help either way? So if I am hiding something it can potentially be blurred...but if I'm not then, I still have a machine basically taking naked photos of me. The screening is completely optional...but the TSA doesn't promote that fact. A passenger can skip the screening and be patted down by security. People are being put through this screening process without even being made aware that it is happening. Is it their fault for not questioning airport security? I would say no...it is the TSA's fault for not letting passengers know what they are being subjected to.

Saturday, June 14, 2008

Traveling to the Olympics? Don't bother bringing your privacy...

A recent USA Today tech article focused on the invasion of privacy many will face when traveling to the Olympics in China this summer. The warnings, aimed mostly at federal officials and business people, are telling travellers that the Chinese government will most likely attempt to penetrate the electronic devices (cell phones, PDAs, and laptops) being brought into the country. The Chinese government intends to steal information and plant bugs to gain access to U.S. networks. Just about anyone that has political influence, a government position, or works for a large company is at risk to have their privacy completely compromised.

The Overseas Security Advisory Council states that Chinese government frequently uses these tactics to gain access to personal and official computers. China's Internet and wireless networks are run by the government, which has access to any bit of data being transferred. A laptop being searched by airport security or left in the hotel while attending the day's games are vulnerable to attack. The control that the government has over the Internet allows them to invade any one's privacy since they have to surf the web through their network.

This is a major privacy threat for anyone travelling abroad for the Olympics. Any information you have on you is subject to Chinese inspection. Further, travelers coming home. should have their systems checked before connecting their network.

So now where does it go from here? Consider travelling without any of these electronics. If you have to bring them with you, make sure no personal or official information (of a sensitive nature) is stored on them. And if none of those precautions can be taken, then make sure a good proxy server is used while in China, and have everything on the computer's drive encrypted.

Wednesday, June 11, 2008

PogoWasRight.org

PogoWasRight.org is here to bring us, "Privacy news, data breaches, and privacy-related events and resources from around the world." This is a great site to visit for news and important information regarding your privacy. PogoWasRight contributor, PrivacyNews, updates frequently with headlines that are important to all of us. You can see the most recent, updated headlines and additions right on the front page.

If you want to search for articles and postings on a specific subject you have many to choose from. The sections include: Federal Government, REAL ID, Internet & Computers, Surveillance, and Business & Privacy. Clicking one of these topics brings you to the most recent updates for that section.

The "Other Privacy Sections," area offers resources for proposed legislation. The site also offers a blog, Chronicles of Dissent, which has some great articles and links to a blog dedicated to information about medical privacy. The site also shows upcoming Privacy Events and Conventions, with links to each for more details. PrivacyNews also takes leads by e-mail, in case something slipped by, that you feel should be a headline. You can also become a member of PogoWasRight.com and post comments and submit items.

This is definitely a place to go for news and information regarding privacy. The site offers relevant and recent headlines to keep us all informed on the next big threat to privacy.

Taking Back Control of Your Privacy

InsideCRM.com recently published an article that outlines 50 tips to maintain your privacy and avoid ID theft or other cyber crimes. This list is comprehensive and includes great advice on how to keep yourself protected. Everything you do online is susceptible to scams and other privacy risks; these tips could end up being the difference between security and theft. The article does not focus primarily on Internet privacy, it also discusses the ways to stay protected when offline. The full list can be found in the article, but the following are some of the major points.
  • Internet Privacy
    • Don't save e-mail address or password settings (log-in information) for frequently used sites such as online banking.
    • Use anti-virus protection.
    • If using wireless, set up a password and secure the connection.
  • Credit and Financial
    • Check you credit report about 2-3 times per year.
    • Use a credit card for online purchases instead of a debit card.
    • Never use your Social Security Number as a pin or password.
  • General Privacy
    • Don't use your Social Security Number as an identification number (such as an employee number) or write your SS# on checks. This number needs to be secured and given to as few people as possible.
    • Understand pretexting and the danger it poses to your privacy.
  • Cell Phones and Online Phones
    • Check and understand your providers Privacy Policy and frequently stay informed on updates to the policy.
  • Other Rules to Follow
    • Keep your Social Security card in a safe and secure place. That place is not your wallet or purse either!
    • Shred documents that contain personal information such as birth dates and credit card numbers.
    • Look for "https" when making an online transaction. This is different from "http" because the "s" indicates a secured and encrypted connection so only you and the site have access to the information.
The tips and tools on the site are very helpful. As stated before, these can be the difference between having your identity stolen or maintaining your security. Many of these tips are common sense for some people, but the fact is identity theft and cyber crime are a problem. If you already know to keep your Social Security Number secured, that's great! Now take the next step and do something else on the list to protect yourself.

Sunday, June 8, 2008

Transplants and "bad people"

Should moral factors enter into medical decisions? If so, which moral factors and whose moral values should be considered? It's an interesting question which is only partially answered in the article "Transplants and bad recipients".

Privacy, morality and ethics have long been tied together in disconcerting ways. While the question is raised whether or not criminals should be allowed to receive transplants which could have saved the lives of "good" people, the article does not address the very slippery slope that the question raises. If doctors can learn about a persons and make medical decisions about what they learn, what's to stop them from deciding not to treat individuals because they don't agree with their political views, religion, sexual orientation, etc...? While it's clear that doctors need complete medical history, and understand behaviour as it effects health, doctors should not learn more than that about patients and certainly should not make judgments based on non medical factors.

This is the privacy dilemma. It can be argued on both sides that more information affects the decision process. Is more information good or bad? Here are the questions from both sides of the argument: Do you really want doctors judging you instead of just treating you? What if a transplant saved the life of a criminal instead of saving the life of a loved one? It's easy to answer the questions if they affect you. But then again if you really think about the questions, maybe it's not so easy after all. What if your loved one was the criminal?

Thursday, June 5, 2008

How would you feel about being tracked via your cell phone?

MSNBC reported yesterday that Northeastern University conducted a study in which 100,000 users outside the U.S. were tracked by their cell phones. Did I mention the users were not told about this or consented to this. It was done in secret and concluded that most people stay relatively close to their homes.

Well, I am glad they know that information. It was worth spying on 100,000 people through calls and text messages to find out that people tend to stay close to home. I can live a much happier life now that I know this. This method of collection is illegal in the United States since it was non consensual. The researchers would not comment on which people were used, which country, or the service provider. Over a six month period outgoing and inbound calls and text messages were taken and analyzed.

The authors of the study said that the numbers were anonymous because they were scrambled into a 26 figure code. This would raise almost no ethical or privacy flags if the cell phone users consented to this. Some phone companies actually market tracking abilities to parents and employers. The fact of the matter is not how the information was used, but that the information was taken. So now I am a guinea pig just because? I don't buy it at all. Just because the researchers don't have the numbers I have to assume I'm safe. I think I know better than that. Someone out there has a list of all 100,000 people and their calls.

The scientists feel that since they are using it for research purposes it is alright. The data that could be misused is being handled properly so everything is fine...no need to worry, a scientist said so. The line between public research and personal privacy has surely been crossed here.