Tuesday, December 11, 2007

Theft of personal data more than triples this year

According to a USA TODAY analysis of data losses reported over the past two years, more than 162 million records have been reported lost or stolen in 2007, triple the 49.7 million that went missing in 2006.

The article states:

Names, birth dates, account numbers and Social Security numbers have become like gold in the cybercrime underground. Meanwhile, organizations expose rich veins of such data as they convert paper documents into digital records. Business data worldwide are expected to swell to 988 billion gigabytes by 2010, up from 161 billion gigabytes in 2006, says researcher IDC.

As they "cram more and more data into a single place," companies and agencies present thieves with more opportunities for a big score, says Benjamin Jun, vice president of technology at Cryptography Research.

...

Organized-crime rings are on the lookout for unattended laptop computers, mail that contains disks or tapes and employees susceptible to bribery, says John Watters, CEO of security firm iSight Partners. "They're looking for the weak link," he says, "and aiming their resources at it."

Click here to read the article in its entirety.

Monday, December 10, 2007

Legislators, residents speak out against REAL ID program

The REAL ID Act - passed as an attachment to a supplemental spending bill for the Iraq war effort in 2005 - continues to meet resistance across the country whenever the public gets a chance to comment on it. Unfortunately, the Homeland Security Department (HSD) has kept such public gatherings to a minimum.

The Real ID Act would turn our state driver’s licenses into a genuine national identity card and impose numerous new burdens on taxpayers, citizens, immigrants, and state governments – while doing nothing to protect against terrorism. This new federal identity document would be required of every American in order to fly on commercial airlines, enter government buildings, open a bank account, and more.

The common reaction from concerned public citizens across the country to the Act has centered on the threat it would pose to individual privacy, the high costs states would incur to implement it, the increased danger of identity theft, and the possible loss of freedoms due to expanded government power. The recent hearings in Pennsylvania were no different. The good news is that 17 states have already passed legislation that opposes the Real ID Act...with Pennsylvania currently debating the passage of their own such bill.

The Daily American reported on the overwhelming public opposition displayed at the hearings:

The problem begins with a number of constitutional issues, opposition leaders say, and will only get worse when the identity database created by the act begins to be linked to financial institutions and essentially becomes a national identity card.

...

Many of the residents attending the event were uncomfortable with the program. Chris Faris, of Somerset, said that the act is not about security. “It’s about money. There’s a cottage industry of buying and selling information. They’re going to profit from it and say that we’re alarmists crying Fascism,” he said.

Click here to read the article in its entirety.

Friday, December 7, 2007

Report cautions consumers to look at online privacy policies

I thought this might be useful for readers being that it is the holiday season. A new report by CyberStreetSmart.org, a project of the New York Public Interest Research Group, rates retail websites on how well their customers' personal information was protected.

AP details the findings:

The group reviewed the privacy policies of 484 online retailers in October and November, focusing on two aspects: how well customers were informed about how their information would be used, and how much control customers have over who has access to their information.

Disneyshopping.com and homedepot.com received screen door awards; sites that won steel door awards include netflix.com, ralphlauren.com and rocawear.com. Disneyshopping.com was rapped because its privacy policy is "very technical and lengthy" and may be hard for people to understand, said Tracy Shelton, a consumer attorney with NYPIRG.

...

Homedepot.com was singled out because its policy says personal information may be transferred if the company is sold.

I did not see which companies it gave 'steel door' ratings to. I'll follow up on this post next week. To read the article in its entirety click here.

Thursday, December 6, 2007

Apologetic, Facebook Changes Ad Program

So Mark Zuckerberg, founder and chief executive Facebook, has apologized, says "they've made mistakes". Well, something tells me their deal with advertisers, and the use of Beacon, wasn't so much a "mistake" as an intentional desire to make as much money as possible.

Perhaps he means he made a mistake in getting caught?

At any rate, the Facebook flap highlights growing concerns about the increasingly sophisticated technologies used to track online activities in an effort to more precisely target advertising. It goes without saying these type of social networking sites have not exactly been forthcoming about how much user information they harvest, share, and with whom.

Nonetheless, as the New York Times article conveys, the Facebook story is one privacy advocates should feel good about. We made some noice, got some concessions, and now must broaden the scope of the fight.

The article details some of the reactions and aftermath to Facebook's apology:

Mark Zuckerberg, founder and chief executive of the social networking site Facebook, apologized to the site’s users yesterday about the way it introduced a controversial new advertising feature last month. Facebook also introduced a way for members to avoid the feature, known as Beacon, which tracks the actions of its members when they use other sites around the Internet.

...

Although Facebook has made the changes that MoveOn.org and others requested, some users said they believed the company had not been forthcoming. “I feel like my trust in Facebook has been violated,” said Christopher Lynn, 30, a Facebook user who also writes a blog on social media. “Facebook created this space that was a private space, where we share our experiences, and to share this data behind our backs is upsetting.”

...

Jeff Chester, executive director of the Center for Digital Democracy, said Mr. Zuckerberg should have explained Facebook’s full advertising and data collection program to users.

The user needs to decide how their information is going to be used, whether it’s going to be used for targeting at all, which advertisers have access to it and whether Facebook has the right to collect and analyze it,” he said. “Facebook is saying it is a safe place for you to share your innermost secrets; what’s not being told to users is that they are selling those secrets.”

Wednesday, December 5, 2007

Wiretap Oversight Urged

It's good to see The Center for Democracy and Technology taking yet another strong stand on behalf of individual privacy. I've covered the illegal wiretapping issue pretty extensively here, and it goes without saying that the telecommunications industry does not deserve immunity for the crimes they committed against their customers.

But, as CDT notes, there are numerous other problems with the FISA "reform" bills making their way through congress.

PC World reports:

The legislation, as approved by the Senate Intelligence Committee, would reauthorize warrantless wiretapping of some U.S. residents' telephone and electronic communications in the name of protecting the U.S. against terrorists. One of the most controversial provisions would give telecom carriers immunity from civil lawsuit judgements for assisting the government wiretapping efforts, but CDT officials said Tuesday that there are other important debates raised by the legislation, including the role of the U.S. FISA (Foreign Intelligence Surveillance Act) court in overseeing the wiretapping program.

The Senate Intelligence Committee version of the bill, which was put together with help from President George Bush's administration, offers "no meaningful protection" to U.S. residents and limits the involvement of the FISA court in approving wiretapping, CDT said. Several civil liberties groups have called the wiretapping program illegal because it spies on U.S. residents communicating with oversees suspects without court approval.

...

The CDT would prefer a substitute amendment from the Senate Judiciary Committee that's likely to come before the Senate during debate on the bill. That bill would give the FISA court more oversight of the wiretap orders, would prohibit the bulk collection of international communications and would sunset the bill in four years instead of six, as in the Senate Intelligence version. Even better is a House of Representatives bill, the Restore Act, which would allow ongoing FISA court supervision of the wiretapping program, and would require prior court approval of wiretaps in most cases, CDT said. The House narrowly passed the Restore Act Nov. 15.

Click here to read the article in its entirety.

Tuesday, December 4, 2007

California Government Surveillance Cameras Thrive Without Safeguards

Do you ever get that feeling you're being watched? Well, if you live in California - and most definitely in the UK - you probably are. One of the growing little privacy violation secrets in the US, particularly California, is the rapid expansion of the governments use of surveillance cameras with next to no safeguards or oversight.

A recent report by the ACLU entitled "Under the Watchful Eye", details this very real, and frightening encroachment on our privacy and civil liberties. But rather than me explain all the findings and suggested reforms, I suggest you read this article by Stella Richardson of the ACLU summarizing some of the report's findings.

She writes:

California cities are moving quickly to install video surveillance cameras on public streets and plazas without regulations, with little or no public debate, and without an evaluation of their effectiveness... public records survey done by the ACLU disclosed that, even though 37 cities have some type of video surveillance program and 10 are considering expansive programs, none has conducted a comprehensive evaluation of the cameras’ effectiveness [full list of cities and their responses].

...

In the last two years, the federal Department of Homeland Security has made more than $1.4 billion available to cities for anti-terrorism projects. This funding, along with rising homicide rates and aggressive marketing by security companies, has led many cities to approve and install surveillance camera systems.

...

Surveillance camera programs do not significantly reduce crime in city centers, the report argues. Mark Schlosberg, Police Practices Policy Director of the ACLU of Northern California and co-author of the report said, “The use of surveillance cameras, unfortunately, comes at the expense of proven crime reduction measures such as better lighting, foot patrols, and community policing. In this sense, throwing money at video surveillance actually detracts from law enforcement’s efforts to reduce crime.”

The report cites a survey commissioned by the British Home Office, which found that improved lighting led to “a 20 percent average decrease in crime, with reductions in every area of criminal activity including violent crime,” while cameras led only to reductions “no more significant” than in control areas with no cameras. Britain has more than four million cameras operating in more than 500 towns and cities.

...

Nicole Ozer, Technology and Civil Liberties Policy Director and report co-author, raises another serious concern. “The threat of widespread government surveillance only multiplies when cameras are combined with other new technologies.” She cited automated identification software among such technologies. “In this light, video surveillance cameras provide a critical pillar for an emerging government surveillance infrastructure,” Ozer added.

For the ACLU's recommendations, as well as the article in its entirety, click here. From my perspective, allowing anyone, especially government, to have such broad reaching and all encompassing surveillance abilities begs two questions: "How much do you trust those in power to always do the right thing? And more importantly, "How much do you trust anyone that is given such enormous power to keep doing what's right?" The old adage "Absolute power corrupts absolutely" keeps coming to mind.

Oh, and they don't reduce crime either!!

Monday, December 3, 2007

Editorial: Facebook move doesn't clear up privacy fears

During my 5 days absence a lot has happened in regards to the MoveOn versus Facebook clash. Unless you've been living under a rock, I'm sure you heard the people won this round.

As MoveOn noted in a November 30th action alert, Facebook's "about face" is something we should all celebrate:

Big news! Last night, Facebook changed their policy and announced that no private purchases made on other websites would be displayed publicly on Facebook "without users proactively consenting." This is a huge victory for online privacy—and shows how regular people can band together to make a difference as the rules of the Internet get written.

...

The Washington Post, New York Times, and media outlets around the world cited the 50,000 Internet users who joined MoveOn's Facebook group and online petition as critical in getting Facebook to reconsider their policy. The New York Times called it a "mass protest" and London's Telegraph newspaper said we achieved "dramatic change."

But, before we pop the champaigne and declare the 29th of November to be "National Privacy Protection Day", check out this editorial by the San Jose Mercury News entitled "Facebook move doesn't clear up privacy fears".

As the editorial points out, this is only one part of a much larger struggle to protect ones personal information - particularly in cyberspace:

The backlash against Facebook last week is a lesson to all Internet companies: Tread more carefully with consumer privacy, even in this linked-in age.

...

But the issue of privacy in the Internet age doesn't stop there. Facebook fixed the notification feature, but it's still collecting the data. Web sites like Facebook and MySpace make it possible to share intimate details of our lives with online friends and contacts. That allows the sites themselves to collect troves of personal data, such as what movie we saw, what books we like and where we plan to go on vacation. And they can share that data with Internet marketers.

...

Despite Facebook's concession, the Center for Digital Democracy and other privacy groups plan to press the Federal Trade Commission to examine Internet marketing practices. It's time to look at updating the ground rules for marketing in the Internet age. Social networking sites have brought us into a new era of connectedness. But the basic expectation of privacy must not change.

Click here for the complete editorial...