Showing posts with label Privacy breaches. Show all posts
Showing posts with label Privacy breaches. Show all posts

Tuesday, January 27, 2009

Data Privacy Day 2009: Raising awareness

January 28th marks the 2nd annual international data privacy day in Canada, the U.S. and 27 European countries. The purpose of the event is to "raise awareness and generate discussion about data privacy practices and rights." It also serves the important purpose of furthering international collaboration and cooperation around privacy issues.

This year's data privacy day comes on the heels of what may have been the largest breach ever reported, with the personal information of nearly 100 million exposed at a U.S.-based credit card processing firm. Hackers breached the computer network at Heartland Payment Systems Inc., exposing customers' credit card numbers, card expiration dates and some internal bank codes - all information that could be used to forge a credit card. The company handles 100 million card transactions for 250,000 businesses nationwide each month.

The scale of the breach is “shocking,” says Jennifer Stoddart, Privacy Commissioner of Canada.

“After what we saw at TJX, that you could have such a major data breach, I'm asking myself what is happening and what is not getting through to organizations?” she says. “You should always take the steps to make sure there is suitable protection.”

As this most recent breach demonstrates, there is still much work to be done to raise awareness about data privacy.

Saturday, September 1, 2007

Lessons from the massive privacy breach at Monster.com

Last week’s massive security breach affecting Monster.com is a reminder of what is at stake as we all come to rely on web-based services for everything from shopping to dating to job searching. For those unfamiliar with the service, Monster.com is an international job search site, where employers can post job ads and employees can post their resumes and apply for positions. According to CRN Business:

The stolen data, which was found on a remote server and shut down by Monster.com this week, included users' names, addresses, phone numbers and e-mail addresses. Symantec security researchers first reported the incident last week, although it's still not clear when the breach first occurred.

The data was collected by the Trojan Infostealer.Monstres, which likely used stolen login credentials of legitimate employment recruiters to gain access to the site's resume database, according to a posting by Symantec researcher Amado Hidalgo on Symantec's Web site. The unsuspecting job seekers whose information was stolen then became the victims of various phishing e-mail scams attempting to empty their bank accounts.
Last week’s reports indicated that a staggering 1.3 million individuals’ data had been stolen, but Monster.com’s CEO Sal Iannuzzi is now saying that the breach is likely even larger:
To be safe, he said, all Monster.com users should assume that their contact information has been taken.
While Monster is assuring users that it is working to improve security on their site and contacting users about ways they can ensure their privacy, this is too little too late given that millions of users’ confidential data, including names, residential addresses, e-mail addresses, home telephone numbers, cell phone numbers and employment history have been stolen by individuals who have not been identified or arrested for purposes yet unknown. It is not yet known if any financial transaction data has been stolen.

Ianuzzi offers little comfort to Monster’s customers:
"I want to be clear and I want to be frank: There is no guaranteed fix," Iannuzzi said. "I wish I could say . . . there will be absolutely no way that the Monster site can be compromised. I cannot ever make that promise, and no Internet company can." (emphasis is mine).
This is a sobering reality check to all of us who share information and make transactions on the Web – that there are no iron-clad guarantees for the security of your data, financial or otherwise. It is up to individuals to stop and think before providing any personally identifiable information to access a service or conduct a transaction over the Internet.

Some ways you can reduce your risk:

1. When signing up for a Web service – anything from Facebook to Ticketmaster alerts to a blogging utility – how much personally identifiable information are you required to provide? How important is the service to you when weighed against the risk of your personal data being stolen or unlawfully accessed?

2. Could you access this service in another way? For example, is it possible to apply for a job by e-mailing the employer directly, rather than uploading all of your application data to a Web service?

3. When you are making an on-line purchase, be sure the vendor is providing a secure means of making the transaction – look for the https:// prefix in the URL (e.g. https:// www.abc.com). You should see a lock box on your screen if the site is secure.

4. Make sure you run anti-virus software regularly to ensure that key sniffers are not at work on your computer. Because you cannot be assured that this is happening in libraries and internet cafes, don’t access your on-line banking service or make financial transactions on public Internet computers.

5. If you are using a wireless Internet connection, secure it to ensure that no one can access your computer.

6. When making a transaction online, always decline the option for the service to retain your credit card information. The inconvenience of re-keying this information is not worth the risk of a data breach.

7. Vote with your feet and with your money. Don't support companies or services that aren't taking data security seriously. If you have a concern about the amount of personal data you are required to provide in order to access a service, don't go ahead with the transaction. Write the companies and let them know your concerns. Read their privacy policy thoroughly.

Unfortunately, even using these precautions will not eliminate your risk. A few months ago, I wrote about how in-person shoppers at TJ Maxx stores had their credit card information stolen because the company’s databases were breached and they retained the data far longer than required to support the transaction. Regulations to protect consumers are lagging and differ from country to country and within state and provincial jurisdictions. Many companies are lax in protecting consumers and do not provide the level of I.T. support required to secure data.

Most of us wouldn’t leave our houses without locking the doors, but we can so easily become complacent about the amount and type of personal information we share in our day-to-day activities.
Always ask yourself: is the convenience worth the potential risk?

Wednesday, July 25, 2007

Ask.com and Microsoft call for privacy standards

According to PC World, Ask.com will be the first major search engine to offer an anonymous searching option to users. Their new AskEraser feature will give users the option to request that their search data not be stored.

This is in stark contrast to Google’s recent announcement that they will reduce the time they save search data from over 30 years to “only” two years. In spite of Google’s voluntary reduction in cookie life, European privacy experts, among others, have soundly criticized the lifespan of Google’s cookies:

"Compared to the previous lifetime of 30 years, the period of two years seems to be short," Schaar wrote in an email. "But from a data-protection perspective, and considering the fact that the user's search behaviour is recorded and can be analysed for any purposes, this period is still too long."
Meanwhile, Microsoft has joined Ask.com in calling on technology leaders to find a way to meet their need for advertising data without compromising user privacy:

"The first step is, we'll be in contact with all the other players in this space and talk about what a summit might look like," said Cullen. "We're very happy to host it, if that's the answer ... both Microsoft and Ask.com think that this is the time to make this happen."

Microsoft is planning to allow users to opt out of having their search data used to generate targeted advertising on Microsoft's Web sites, and under a new privacy policy, plans to scrub all search query data of any user-identifiable information after 18 months. While this is in part a shot at Google, it is encouraging to see some leadership within the industry to safeguard the privacy of their users’ search data.

The ability to search anonymously is essential in allowing individuals to explore any area of inquiry without fear of discovery or retribution. When companies track user data, their primary motivation is to inform their decisions about advertising. The abuse of search data has additional implications if the data is merged with that of advertisers, as I wrote in an earlier post about the proposed Google and DoubleClick merger.

When search data is breached, the consequences could be far more serious than mere embarassment. About a year ago, AOL inadvertently released the search data for about 650,000 searches on their site and New York Times reporters were actually able to identify one of the searchers. Breaches of this magnitude and specificity could ruin careers and reputations, while creating a chilling effect on the exploration and sharing of ideas over the Internet.

Google needs to stop hedging on privacy and get on board with this initiative.

Wednesday, June 13, 2007

TJ Maxx: Privacy and Consumer Apathy

Information Week is reporting on the financial statements for TJ Maxx following the massive security breach last year and – surprise! – sales at the retailer are up 6% over last year.

Given the scale of the breach – customer financial information dating back to 2003 was stolen – and the revelation that TJ Maxx was retaining far more information on customers far longer than required to support the transaction, I am surprised that sales did not go down. What message are customers sending to retailers about the importance of privacy and the trust that consumers place in them when making a transaction? Are customers so weary of hearing about security breaches that they have become apathetic to the issue?

It’s not that TJ Maxx hasn’t made an effort to redress the problem:

The company reported a charge of $20 million, or 0.5% of net sales for the last
quarter of 2006 toward investigating and containing the computer intrusion, work
to improve the company's computer security and systems, communicating with
customers, and technical, legal, and other related costs
And many irate consumers are taking the issue to court:

TJX is facing class-action lawsuits from customers in state and federal courts
in Alabama, California, Illinois, Massachusetts, Michigan, Ohio, and Puerto
Rico, as well as in provincial Canadian courts in Alberta, British Columbia,
Manitoba, Ontario, Quebec, and Saskatchewan. Additional class-action suits from
financial institutions affected by the computer intrusion -- those
issuing
credit and debit cards used during the time of the intrusion
-- have been
filed against TJX in federal court in Massachusetts. All-told, nine lawsuits
have been filed against TJX since April 17.
Still, it is stunning that a retailer can expose consumers to one of the largest and most costly security breaches in history and the shoppers just keep on shopping.

Wednesday, April 18, 2007

Was your privacy breached today?

Consider these scenarios:

  • Your new husband’s ex-wife, who works for a medical office, looks up your medical records.

  • The mail delivery cart in a government office is left unattended in a public area while the mail clerk takes a coffee break.

  • You drop by your boss’s office to update her on your project and notice a disciplinary report on her desk, with the name of a fellow manager showing prominently on the front page

  • You open your annual pension plan update and discover someone else’s report is in the envelope instead of your own

  • A major retailer discovers that their network has been hacked, with potentially hundreds of thousands of customer credit card numbers accessed

  • Your friend in the benefits department tells you at lunch that a co-worker and mutual friend has been submitting claims for visits to a psychiatrist for the past several months.

Which of these scenarios would you consider to be a privacy breach? If you answered all of them, you would be right. According to Canadian privacy legislation, data that is collected or disclosed without authorization is considered a privacy breach. It doesn’t matter that the breach was overt, inadvertent or accidental; the consequences and implications are equally severe.

Security is a means to achieve privacy. Security is established through rigid policies and procedures, a code of ethics and regular training for staff. Security is also established on the information technology side by restricting data access to only those who need it. For example, the government health minister, responsible for overseeing policy direction for his jurisdiction does not require access to citizen health records to do his job, while a clerk responsible for verifying medical claims does require access to those records. While one might expect the health minister to understand the importance of ensuring the privacy of medical records, it is the staff member who actually accesses the records who is in most need of training. And often, these front-line staff are the least-trained in the organization, yet they have the greatest potential to cause a security breach, the majority of which will be accidental or inadvertent.

Organizations need to ensure that the staff who assume the greatest risk through their exposure to confidential information receive annual training about their obligations with respect to privacy legislation and the potential consequences of a privacy breach. Organizations also need a clear set of policies and procedures for dealing with privacy breaches.

Organizations need to ensure that their I.T. departments have adequate budgets to ensure regular upgrades to hardware and software, as well as regular training for their staff.

Governments also need to strengthen privacy legislation to ensure that organizations are accountable to the public in the event of a privacy breach. In the case of the recent TJ Maxx hacking, for example, most U.S. states and Canadian provinces had no legal requirement for the retailer to inform customers that their credit card data had been compromised. Monday's session at the Prairie health information privacy conference highlights the ongoing challenge that privacy breaches, inadvertent or otherwise, present to the public and private sector.

So think back on where you were today – where you work, where you shop, where you ate lunch, where you live – do you know if your privacy was breached today?