Moral human behavior optimizes the survival and nourishment of the human species. . .
Immoral behavior is a threat to all mankind.

I pledge allegiance to the flag of the united states of America and to the republic for which it stands, one nation under God, indivisible, with liberty and justice for all!

Showing posts with label data management. Show all posts
Showing posts with label data management. Show all posts

Friday, October 10, 2008

Data Breaches, What Options Does the Consumer Have?

I have written about this before but it is always scary when the topic rears its ugly head.

The Identity Theft Resource Center, of San Diego, found that this year's data breach tally has easily eclipsed 2007's 446 incidents. At an average of 57 caches of consumer data reported lost or stolen each month, U.S. organizations are on track to divulge at least 680 breaches by the end of 2008.

About 80 percent of the breaches involved digital records, while the remainder stemmed from the loss, theft or exposure of paper-based records. A description of each incident is available in the Identity Theft Resource Center 's 2008 Breach List.

Some 30 million records on consumers have been exposed so far this year. But experts say that figure almost certainly masks a much larger problem, as there is currently no federal requirement for organizations that experience a data breach or loss to acknowledge precisely how many consumers nationwide may have been affected.

Some states require entities to alert consumers of a data breach, but this is, in most cases, pretty useless. I personally have been notified on three occasions (by my credit card company and a hospital and the VA) of my data being ‘lost’ and each time the date of the letter was 6-8 months after the fact. How does notification help in these cases? As usual the law was not written well enough to actually protect the consumer. Entities should be forced to notify consumers in a more timely manner, for example, within one week of a data breach in order for us to be aware that our personal information has been compromised.

If only these companies protected my information as if it were their own.

Most of us make some attempt to protect our data while on our own home computer, but when it becomes necessary to give out our personal information we have to trust that the entity we give it to will protect it. Instead we find we are becoming more and more vulnerable to whatever level of seriousness corporations extend to preventing a data breach. Sometimes, their own employees misuse our data, either through negligence or downright theft.

In other cases, the company that we are forced to trust with our data hands that data over to a contractor, without our knowledge, which increases our vulnerability.

How many of us would be notified of a data breach if it were not for state law forcing the notification? It is understandable that these companies and our government would not want consumers to lose faith in their ability to properly care for your personal information, but this is exactly the type of information we need be informed of about these entities. If they are not forthright enough to tell us of problems on their own without the threat of penalty, then why should we trust them with any other transaction? Because we have to.

In order to make purchases online we must send personal information over supposedly secure networks. When we make purchases at brick and mortar stores with credit cards we must have faith that those transactions are forwarded to our credit card company and the stores headquarters over secured lines. Plus, we have the added vulnerability of exposing our credit card numbers to store clerks. Some of these concerns are being addressed to remove the clerk from the equation but once our information is sent through those desktop data collection devices, what guarantee do we have that the information is not intercepted?

We are asked to have a lot of faith in whoever we give our information to and we are being told that there are more data breaches almost every day.

There are many data encryption routines that can protect data, but many companies don’t want to take the extra time involved to encrypt and de-encrypt to access the data. Therefore we, the consumers, lose.

Can we sue entities for losing our data? It is becoming increasingly apparent that suit brought against these entities is going nowhere. The main road block to getting a judge to hear such a case is the extent to how much harm is actually done to the person whose data was ‘lost’ or ‘stolen’. Plus, how do you prove the data was either ‘lost’ or ‘stolen’? As a result, the consumer is left to worry about when their data will be used by unscrupulous persons and will then be faced with having to suffer whatever damage is done.

In a world that is increasingly going digital, coupled with corporations farming out work to contractors and sub-contractors, the risk to our personal data is increasing. Human error and greed accounts for the vast majority of these data breaches and until we can take the human element out of the data stream we will always be at risk.

As an additional threat, Homeland Security and the FBI have been pursuing the creation of databases containing extensive data on every person in the U.S. The prospect of accessing this ‘mother lode’ of personal data must has hackers salivating.

Friday, May 2, 2008

Protection of Privacy and Civil Liberties is our responsibility

The right to privacy is something we all expect and yet the concept is not found expressly in the Constitution or any amendment.
We assume the right to privacy is granted and protected even though we freely divulge information about ourselves on a daily basis, i.e.,
while navigating the internet our internet address can be captured to pinpoint where we live;
using credit cards, online as well as at brick and mortar stores, leaves a trail of purchases that marketers can use to tailor their advertisements towards what they think we may want to purchase;
telephone conversations and email correspondence can be intercepted which further defines who we are or what we are planning to do;
anything we do outside the home and who we do it with are all subject to monitoring by someone with the right equipment.
Accumulated information about each one of us, collected by using any or all of the sources mentioned, can be used to create a very clear profile of who we are. This information can also create a pattern of behavior that can then be interpreted, using sophisticated computer software, to predict the likelihood of future behavior and intentions.
It is no secret that our government eavesdrops on our internet activity. It should come as no surprise to learn that email correspondence in the workplace has no expectation of privacy. Surveillance cameras are becoming more ubiquitous in public places around the world.
Now, local police are advocating the use of spybots. They claim to be needed for, and will only be used for, tactical reasons during hostage situations. Homeland Security pushes for more complete fingerprinting, but only to catch terrorists. FBI wants more complete biometric data on everyone, to help catch criminals and, oh yeah, terrorists.
High-tech spy tools have become the most lusted after weapon in law enforcements arsenal of crime fighting tools. Flying drones are among the more exotic tools. These handy portable devices, complete with infrared sensors and able to fit in a backpack, will allow police to see behind barricades during SWAT actions. They will also be able to help police watch any neighborhood, any house, any person they want to.
Fingerprinting in hopes of catching terrorists is just an excuse to build a more complete profile of everyone in America. A known terrorist is not going to be caught by airport security through the use of fingerprints. Those people who readily submit to fingerprinting are least likely to be the type of people the police need to watch.
Scanners with the ability to “see” under our clothing in graphic detail will soon become common place.
How far are we willing to allow our government to creep into our private lives under the guise of combating terrorism? Who are the real terrorists here? Illegal immigration, terrorism, and criminal activity all provide our government an obvious cover for the proliferation of the latest spy devices and biometric data collection.
Most of us realize that foreigners come to this country in search of a better life for themselves and their families. As such, these people are highly unlikely to commit any crime that could result in them being deported. Of course there will always be a percentage of ‘bad guys’ in the mix, and fingerprinting them will not prevent them from crossing our borders until several conditions are met:
1) we are completely walled off and the only way in is through a tightly monitored entrance,
2) we have the ability for fingerprints to be immediately matched with a complete database,
3) the person being checked has to have already been fingerprinted.
Nothing will accurately predict future criminal behavior which is why fingerprinting is a useless exercise unless the purpose for doing so is to build a more complete profile of everyone in America.
Law abiding citizens should have nothing to fear from bring profiled by our government. But the requirement to be fingerprinted reveals a level of mistrust toward the individual by the establishment and creates a level of mistrust from the citizen being scrutinized. The few low-lifes who choose to live outside the ‘constraints’ of the rules of civilized society are the people causing law enforcement to pursue these heavy-handed measures, not in an attempt to control our movements but to remain aware of where the criminal element is at all times. The ability to ‘know’ where someone is and what they are doing is beyond human ability, therefore technology comes into play.
The issue of trust is of course at the center of the right to privacy vs. the need for personal protection issue. Police use the argument that during a SWAT situation they need a greater ability to collect more accurate and thorough information for the protection of both themselves and any citizen in the immediate vicinity. They say that remote controlled cameras offer this ability. Which is true. But I, like many others, have become weary of what police will do with these tools when not being used for SWAT actions. Who is to guarantee that these tools will not be used to ‘collect’ data on other citizens then?
Trust has eroded as a result of past incidents on the part of police against the very people they are sworn to protect. We no longer have trust in a police force that abuses its power and then is exonerated. We no longer have faith in the sincerity and purity of intentions of a police force that so readily resorts to tasering wheelchair bound or handcuffed individuals. We can no longer believe that our guardians will not use collected data for their own personal nefarious purposes.
Privacy advocates have warned of the dangers of a government collecting information on private citizens and we are beginning to see the great ‘Big Brother’ society materializing when we learn that our government is snooping through our phone records and trying to pass legislation to exclude telecommunications companies involved from liability. We can no longer expect privacy concerning employee email sent on company time. Websites we access at home on our private computers are monitored by our internet service providers. And we can’t even count on the press to inform us about what our government is up to.
We see evidence that the lack of attention to detail in performing our job duties can result in a threat to human life. Nuclear tipped missiles accidentally loaded aboard a B-52 bomber last August and flown across the U.S., electrical fuses for ICBM’s accidentally shipped to Taiwan in 2006, inspections of nuclear facilities on submarines not done resulting in false reports being submitted. These are of course the most serious examples of the infallibility of humans and how events can be purposefully triggered if the desire is there. But they illustrate how humans are prone to not take their individual jobs seriously enough to even protect their fellow man. How can we in any clear conscience give spy tools to a police force we no longer trust?
As these situations show, it is only a matter of time before some rogue individual in a security position or government office will use data collected on an individual to exert undue, unlawful, and immoral pressure on that person for their own dark reasons. This is human nature, no matter what assurances we are given that this situation will never happen, we still all know that it could and probably will.
Building a bigger, more complete database of American citizens only further erodes trust between citizens and those officials appointed to protect us. If we are willing to have complete blind faith in our protectors then watching our every move would not bother us. If the protectors would have complete blind faith in us then they would not need the ability to spy on our every move. It would be nice if such a world existed, but it doesn’t. That lower subset of humanity, the criminal, who would rather prey on the rest of us instead of putting forth the effort to become a productive member of our society, is the reason local police want spybots and why Homeland Security wants a complete profile on everyone that crosses our borders and why the FBI so fervently pursues having a complete data history on every person within our borders.
To add to the horrifying specter of our government knowing everything about us, private citizens can get their hands on our data not only though theft but through sheer incompetence of government officials. An alarming amount of data has been reported just within the past year and it has been going on for several years now. The following is a partial list (it would take up too much space here to list them all) is from actual headlines involving the personal data of millions of people:
Britain’s HM Revenue and Customs lost computer disks containing confidential details of 25 million child benefit recipients.
Half of London boroughs lost citizens’ data.
Connecticut Sues Accenture Over Lost Data.
More personal data lost — this time on paper.
Personal Data Lost on 650,000 credit card holders.
It is unconscionable that any individual would be so careless with other people’s personal data that they would loose that data.

I don’t like the situation that the unethical and morally decrepit morons among us have created but it’s there just the same. So, how do we respond? Do we tie law enforcement’s hands to its traditional role of being backup in case we need them, or do we allow them to become ‘proactive’ and use any method at their disposal in the name of protecting us? I don’t see how the latter scenario will make any of us feel truly safe short of embedding tracking devices into each of us and having 24/7 monitoring of our every movement and thought. That is a society that I want nothing to do with.


Sunday, December 23, 2007

Another case of ‘lost’ data

This is yet another case of personal sloppiness affecting hundreds of thousands of adults and children.

This time the National Health Service has admitted to losing data collected on patients from nine hospitals in England.

The usual line was given to the affected individuals that there is no evidence data has fallen into the wrong hands. But once again, no one knows for certain because the data is missing.

In one case a disk failed to arrive at an east London Hospital. My first question, how was the disk sent? By private courier or daily mail?

Another case involves data on patients treated 40 years ago. They are all deceased and you may think no big deal, nothing can happen to them. But you would be wrong. Professional criminals would love to get their valid social security numbers and use them.

One hospital reported two breaches which means there are actually 10 new cases.

Law officials are of course promising to take action against anyone who failed their responsibilities under data protection laws. But the underlying problem of a lackadaisical effort at data protection again goes unmentioned. The individuals involved became derelict in their duty. The data needs to be transmitted using more secure methods. Privacy needs to be taken more seriously.

The whole culture of data management needs to be addressed. Rules are in place as required by laws but the individuals who are governed by them take shortcuts to make their personal lives easier. Sometimes it becomes a nuisance to take that extra precautionary step. We have all been faced with this situation. Maybe we will miss some deadline if we follow the rules to the letter so we circumvent one step.

Individuals set themselves up for misfortune by not practicing effective secure routines. If any of these same individuals who are tasked with protecting other peoples data discovered their own data had been compromised by someone not taking the rules seriously I am certain they would be concerned.

When we care for other people we are actually caring for ourselves. It is a simple thought to keep in mind as we go about our daily business. We need to care for other peoples data as if it were our own. If people really cared we would need rules to tell us to do so.
There is no wealth like knowledge and no poverty like ignorance. -Ali ibn Abi Talib

Transgressions that are tolerated today will become common place tomorrow. -Greg W

"If you are thinking a year ahead, sow a seed. If you are thinking ten years ahead, plant a tree. If you are thinking one hundred years ahead, educate the people."
Chinese Proverb