Tuesday, January 27, 2009
Data Privacy Day 2009: Raising awareness
January 28th marks the 2nd annual international data privacy day in Canada, the U.S. and 27 European countries. The purpose of the event is to "raise awareness and generate discussion about data privacy practices and rights." It also serves the important purpose of furthering international collaboration and cooperation around privacy issues.This year's data privacy day comes on the heels of what may have been the largest breach ever reported, with the personal information of nearly 100 million exposed at a U.S.-based credit card processing firm. Hackers breached the computer network at Heartland Payment Systems Inc., exposing customers' credit card numbers, card expiration dates and some internal bank codes - all information that could be used to forge a credit card. The company handles 100 million card transactions for 250,000 businesses nationwide each month.
The scale of the breach is “shocking,” says Jennifer Stoddart, Privacy Commissioner of Canada.
“After what we saw at TJX, that you could have such a major data breach, I'm asking myself what is happening and what is not getting through to organizations?” she says. “You should always take the steps to make sure there is suitable protection.”
As this most recent breach demonstrates, there is still much work to be done to raise awareness about data privacy.
Posted by Sharon E. Herbert at Tuesday, January 27, 2009 0 comments
Labels: Privacy, Privacy breaches
Saturday, September 1, 2007
Lessons from the massive privacy breach at Monster.com
Last week’s massive security breach affecting Monster.com is a reminder of what is at stake as we all come to rely on web-based services for everything from shopping to dating to job searching. For those unfamiliar with the service, Monster.com is an international job search site, where employers can post job ads and employees can post their resumes and apply for positions. According to CRN Business:The stolen data, which was found on a remote server and shut down by Monster.com this week, included users' names, addresses, phone numbers and e-mail addresses. Symantec security researchers first reported the incident last week, although it's still not clear when the breach first occurred.
The data was collected by the Trojan Infostealer.Monstres, which likely used stolen login credentials of legitimate employment recruiters to gain access to the site's resume database, according to a posting by Symantec researcher Amado Hidalgo on Symantec's Web site. The unsuspecting job seekers whose information was stolen then became the victims of various phishing e-mail scams attempting to empty their bank accounts.
To be safe, he said, all Monster.com users should assume that their contact information has been taken.
Ianuzzi offers little comfort to Monster’s customers:
"I want to be clear and I want to be frank: There is no guaranteed fix," Iannuzzi said. "I wish I could say . . . there will be absolutely no way that the Monster site can be compromised. I cannot ever make that promise, and no Internet company can." (emphasis is mine).
Some ways you can reduce your risk:
1. When signing up for a Web service – anything from Facebook to Ticketmaster alerts to a blogging utility – how much personally identifiable information are you required to provide? How important is the service to you when weighed against the risk of your personal data being stolen or unlawfully accessed?
2. Could you access this service in another way? For example, is it possible to apply for a job by e-mailing the employer directly, rather than uploading all of your application data to a Web service?
3. When you are making an on-line purchase, be sure the vendor is providing a secure means of making the transaction – look for the https:// prefix in the URL (e.g. https:// www.abc.com). You should see a lock box on your screen if the site is secure.
4. Make sure you run anti-virus software regularly to ensure that key sniffers are not at work on your computer. Because you cannot be assured that this is happening in libraries and internet cafes, don’t access your on-line banking service or make financial transactions on public Internet computers.
5. If you are using a wireless Internet connection, secure it to ensure that no one can access your computer.
6. When making a transaction online, always decline the option for the service to retain your credit card information. The inconvenience of re-keying this information is not worth the risk of a data breach.
7. Vote with your feet and with your money. Don't support companies or services that aren't taking data security seriously. If you have a concern about the amount of personal data you are required to provide in order to access a service, don't go ahead with the transaction. Write the companies and let them know your concerns. Read their privacy policy thoroughly.
Most of us wouldn’t leave our houses without locking the doors, but we can so easily become complacent about the amount and type of personal information we share in our day-to-day activities.
Posted by Sharon E. Herbert at Saturday, September 01, 2007 6 comments
Labels: Consumers, Monster.com, Privacy breaches
Wednesday, July 25, 2007
Ask.com and Microsoft call for privacy standards
According to PC World, Ask.com will be the first major search engine to offer an anonymous searching option to users. Their new AskEraser feature will give users the option to request that their search data not be stored.This is in stark contrast to Google’s recent announcement that they will reduce the time they save search data from over 30 years to “only” two years. In spite of Google’s voluntary reduction in cookie life, European privacy experts, among others, have soundly criticized the lifespan of Google’s cookies:
"Compared to the previous lifetime of 30 years, the period of two years seems to be short," Schaar wrote in an email. "But from a data-protection perspective, and considering the fact that the user's search behaviour is recorded and can be analysed for any purposes, this period is still too long."Meanwhile, Microsoft has joined Ask.com in calling on technology leaders to find a way to meet their need for advertising data without compromising user privacy:
"The first step is, we'll be in contact with all the other players in this space and talk about what a summit might look like," said Cullen. "We're very happy to host it, if that's the answer ... both Microsoft and Ask.com think that this is the time to make this happen."
Microsoft is planning to allow users to opt out of having their search data used to generate targeted advertising on Microsoft's Web sites, and under a new privacy policy, plans to scrub all search query data of any user-identifiable information after 18 months. While this is in part a shot at Google, it is encouraging to see some leadership within the industry to safeguard the privacy of their users’ search data.
The ability to search anonymously is essential in allowing individuals to explore any area of inquiry without fear of discovery or retribution. When companies track user data, their primary motivation is to inform their decisions about advertising. The abuse of search data has additional implications if the data is merged with that of advertisers, as I wrote in an earlier post about the proposed Google and DoubleClick merger.
When search data is breached, the consequences could be far more serious than mere embarassment. About a year ago, AOL inadvertently released the search data for about 650,000 searches on their site and New York Times reporters were actually able to identify one of the searchers. Breaches of this magnitude and specificity could ruin careers and reputations, while creating a chilling effect on the exploration and sharing of ideas over the Internet.
Google needs to stop hedging on privacy and get on board with this initiative.
Posted by Sharon E. Herbert at Wednesday, July 25, 2007 5 comments
Labels: Anonymity, Ask.com, Google, Microsoft, Privacy, Privacy breaches
Wednesday, June 13, 2007
TJ Maxx: Privacy and Consumer Apathy
Given the scale of the breach – customer financial information dating back to 2003 was stolen – and the revelation that TJ Maxx was retaining far more information on customers far longer than required to support the transaction, I am surprised that sales did not go down. What message are customers sending to retailers about the importance of privacy and the trust that consumers place in them when making a transaction? Are customers so weary of hearing about security breaches that they have become apathetic to the issue?
It’s not that TJ Maxx hasn’t made an effort to redress the problem:
The company reported a charge of $20 million, or 0.5% of net sales for the lastAnd many irate consumers are taking the issue to court:
quarter of 2006 toward investigating and containing the computer intrusion, work
to improve the company's computer security and systems, communicating with
customers, and technical, legal, and other related costs
TJX is facing class-action lawsuits from customers in state and federal courtsStill, it is stunning that a retailer can expose consumers to one of the largest and most costly security breaches in history and the shoppers just keep on shopping.
in Alabama, California, Illinois, Massachusetts, Michigan, Ohio, and Puerto
Rico, as well as in provincial Canadian courts in Alberta, British Columbia,
Manitoba, Ontario, Quebec, and Saskatchewan. Additional class-action suits from
financial institutions affected by the computer intrusion -- those issuing
credit and debit cards used during the time of the intrusion -- have been
filed against TJX in federal court in Massachusetts. All-told, nine lawsuits
have been filed against TJX since April 17.
Posted by Sharon E. Herbert at Wednesday, June 13, 2007 5 comments
Labels: Apathy, Consumers, Privacy breaches, TJ Maxx
Wednesday, April 18, 2007
Was your privacy breached today?
Consider these scenarios:- Your new husband’s ex-wife, who works for a medical office, looks up your medical records.
- The mail delivery cart in a government office is left unattended in a public area while the mail clerk takes a coffee break.
- You drop by your boss’s office to update her on your project and notice a disciplinary report on her desk, with the name of a fellow manager showing prominently on the front page
- You open your annual pension plan update and discover someone else’s report is in the envelope instead of your own
- A major retailer discovers that their network has been hacked, with potentially hundreds of thousands of customer credit card numbers accessed
- Your friend in the benefits department tells you at lunch that a co-worker and mutual friend has been submitting claims for visits to a psychiatrist for the past several months.
Which of these scenarios would you consider to be a privacy breach? If you answered all of them, you would be right. According to Canadian privacy legislation, data that is collected or disclosed without authorization is considered a privacy breach. It doesn’t matter that the breach was overt, inadvertent or accidental; the consequences and implications are equally severe.
Security is a means to achieve privacy. Security is established through rigid policies and procedures, a code of ethics and regular training for staff. Security is also established on the information technology side by restricting data access to only those who need it. For example, the government health minister, responsible for overseeing policy direction for his jurisdiction does not require access to citizen health records to do his job, while a clerk responsible for verifying medical claims does require access to those records. While one might expect the health minister to understand the importance of ensuring the privacy of medical records, it is the staff member who actually accesses the records who is in most need of training. And often, these front-line staff are the least-trained in the organization, yet they have the greatest potential to cause a security breach, the majority of which will be accidental or inadvertent.
Organizations need to ensure that the staff who assume the greatest risk through their exposure to confidential information receive annual training about their obligations with respect to privacy legislation and the potential consequences of a privacy breach. Organizations also need a clear set of policies and procedures for dealing with privacy breaches.
Organizations need to ensure that their I.T. departments have adequate budgets to ensure regular upgrades to hardware and software, as well as regular training for their staff.
Governments also need to strengthen privacy legislation to ensure that organizations are accountable to the public in the event of a privacy breach. In the case of the recent TJ Maxx hacking, for example, most U.S. states and Canadian provinces had no legal requirement for the retailer to inform customers that their credit card data had been compromised. Monday's session at the Prairie health information privacy conference highlights the ongoing challenge that privacy breaches, inadvertent or otherwise, present to the public and private sector.
So think back on where you were today – where you work, where you shop, where you ate lunch, where you live – do you know if your privacy was breached today?
Posted by Sharon E. Herbert at Wednesday, April 18, 2007 0 comments
Labels: Employment, Ethics, Legislation, Privacy, Privacy breaches
