Monday, March 31, 2008

State Leads Way on RFID Privacy

Washington has now become the national leader in addressing some of the privacy concerns related to the explosion of RFID technology.

In fact, we (CFC) are actively supporting nearly identical legislation as was just signed by Washington's Governor in California - sponsored by Senator Joe Simitian (SB 31) - that would make the malicious scanning of someones identification remotely without their knowledge and consent a felony. Washington actually went a step further by also making it a felony to possess information gained from an RFID-enhanced driver's license...further protecting unsuspecting consumers from having their personal information "skimmed" or their identities stolen.

The Seattle Times Reports:

HB 2729 says personal information on identity cards may be released to law-enforcement agencies only for customs and border-protection purposes. Personally identifying information may be released to law-enforcement agencies for other purposes "only if accompanied by a court order," the law states.

Another bill signed into law, HB 1031, outlaws "skimming," making it a felony for a person to "intentionally scan another person's identification device without that person's prior knowledge and consent for the purpose of fraud, identity theft or any other illegal purpose."

...

"This is a technology that the consumer is clearly unaware of unless it's pointed out to them," he said. The bill was opposed by the retail and cellphone industries, Morris said. "The RFID chip will be a huge revenue stream for them as they start to move the phone into the place of the credit card."

...

New Hampshire is poised to go further than Washington. This month, the New Hampshire House voted to ban RFID chip implants in humans and require a notification label on any product that contains RFID chips. The New Hampshire bill bars the state from using RFID chips in driver's licenses, license plates or traffic toll transponders.

Of course, California could become surpass both New Hampshire and Washington as the nation's leader in protecting personal privacy if just a few of the host of RFID related bills making their way through the legislature are signed into law. These include: SB 28, SB 29, SB 30, SB 31, and SB 388.

Click here to read the article in its entirety.

Friday, March 28, 2008

As More Of Our Health Records Move Online, Privacy Concerns Grow

At CFC we've been part of an effort to figure out the best way to protect the privacy of patients in the approaching reality of online and electronic health records. Without getting mired in a discussion of just how much money this will really save, or how long its really going to take to implement, let's delve into the privacy implications of such a move and possible ways to ameliorate them.

We're now seeing a major move by industry giants such as Microsoft and Google coming out with products for this information storing and sharing purpose. So the question that will confront those concerned about privacy will be how to ensure they institute the proper safeguards for patients.

I usually never go to Fox news for anything, but, this article seems to at least do a decent job of broaching the topic, and does quote and source one of the most respected voices in the privacy protection community, Pam Dixon of the World Privacy Forum.

Kristen Gerencher of MarketWatch reports:

Last October, software giant Microsoft unveiled a consumer-focused online platform for personal health records called HealthVault. Internet search behemoth Google is set to follow soon with a launch of its version called Google Health. About 200 companies now offer personal health records, or PHRs, experts say.

Earlier this month, health insurer Aetna announced it's adding to its secure member Web site a sophisticated search tool that brings up multiple resources such as relevant discount programs and a list of local doctors based on search terms that members enter. The company says the changes will complement Aetna's new PHR for members as well.

These developments may be good news for consumers looking to collect, store and selectively share their health-care information in a digital format, coordinate records with their doctors or enter medical questions into an intuitive online search query.

But the elephant in the room is privacy. Consumers who enter sensitive medical information into a PHR want assurance that their data won't be exposed in a way that embarrasses them or, worse, hurts their ability to secure a job or health insurance. Despite many companies' promises and some state laws that set additional privacy standards, there are more questions than answers when it comes to protecting consumers' PHRs, legal experts say.

...

The potential problem: Many of the companies offering PHRs aren't covered by a federal law called the Health Insurance Portability and Accountability Act of 1996, known as HIPAA, which covers information traded between health-care providers, health insurers and clearinghouses involved in processing payments, said Kevin Lyles, a partner in the health-care practice of law firm Jones Day in Columbus, Ohio.

Outside of those entities HIPAA doesn't apply, he said. "What you're relying on as an individual is the company's promise to you that they won't do anything with your information."

...

To be sure, Google and Microsoft plan to allow users to control the levels of access they want various parties to have and will offer the ability to revoke that access at any time.
Still, Pritts said consumers need to read and understand two important documents: the privacy policy and the terms of use.


"You can really be surprised by what's in the terms of use if you don't read them," she said. "Hardly anybody reads these. They're dense. They're written in language that's not consumer-friendly and we're used to just hitting 'I accept' and not thinking there's anything hidden in there."

...

The onus is on the consumer to check and recheck because companies can reserve the right to change their policies at any time, Lyles said. "Typically if they change it it's not going to be retroactive, but if they change it are you going to know? How many companies send privacy policies every year and do you read it for changes? I doubt it."

...

Aetna expects to nearly double enrollment in its PHRs to 6 million members this year. So far only members have access, but eventually doctors will have access too, Bahl said. The company maintains searches on SmartSource use profile data such as ZIP code, gender, age, benefit plan and health conditions to make results more meaningful, but that they don't include personal identification.

Pam Dixon, executive director of the World Privacy Forum, a public-interest research group in San Diego, said she's concerned about how well members' identities will be protected. "If this were all being done completely anonymously, I think some of the questions would go away but this is not anonymous searching," she said. "I think the greatest potential harm comes from new diseases and things they don't have about you."

This no doubt will be a continuing debate as these systems expand and progress. From my perspective, it always makes so much more sense to take into account all the issues, particularly privacy, BEFORE we jump in head first. Certainly, we can have both an efficient health records system, and healthy protections of individual patient privacy.

Click here to read the article in its entirety.

Thursday, March 27, 2008

Lamar seeing chance to nix Real ID Act

Republican Senator Lamar Alexander is getting ready to lead an effort to repeal REAL ID! I would argure this is yet another example of why we can safely say this law is unraveling before our very eyes. Taking REAL ID on at the federal level is especially heartening, because if successful, all the states would be saved from having to go through this fight individually.

The Hill reports:

Alexander’s target is the 2005 Real ID Act, which mandated that states adopt uniform federal standards for driver’s licenses. Despite the Tennessee Republican’s concerns, he was outnumbered by party colleagues who wanted to stop terrorists from exploiting loose identification laws. This time around, Alexander has leverage. As chairman of the Senate Republican Conference, he is the third-ranking Republican in the chamber. He also has a strong ally in Senate Majority Whip Dick Durbin (D-Ill.), who, like most Democrats, disagrees with the law.

...

When Congress returns next week, Alexander plans to file an amendment to the fiscal 2009 homeland security appropriations bill that would halt the program until the government finds a way to reimburse states for its cost.

...

Alexander, however, said he is still fuming over how the law was “stuck into the conference bill that all of us wanted to support, to fund the troops.”

“I objected as strongly as I could,” Alexander said. “But there never was a hearing [in] the Senate of any kind.”

Harper, of the Cato Institute, said such a dubious beginning to the bill may mean an early end. “If you pass a bill without hearings, you’re going to miss stuff,” he said. “And the authors of Real ID missed a lot.”

Click here to read the article in its entirety.

Tuesday, March 25, 2008

California Backs Off Real ID - Montana Wins Round 1

Some good news to report on the REAL ID front! The cracks in the DHS 's National ID plan are starting to widen. First, the California DMV requested an extension while specifically not making any promises as to whether it would actually implement the Act. DHS buckled, and gave the extension anyway.

What makes this important is DHS had originally said it would only grant extensions from the Real ID rules taking effect on May 11 to states that apply by March 31 and promise to implement Real ID by 2010.

But perhaps more importantly, DHS also granted Montana a waiver it explicitly did not ask for. In fact, Montana has specifically stated it will NOT COMPLY with the Act at all. Something tells me we may be seeing the beginning of the end of this abysmal piece of legislation.

From Wired Magazine:

That meant Tuesday's letter looked like enough to join California to the small rebellion against the Real ID rules. For Californians that would mean enduring the same fate facing citizens of South Carolina, Maine, Montana and New Hampshire.

They would have needed to dig out their passport, if they had one, every time they boarded a plane, or go through an extra level of TSA screening at airport metal detectors. Los Angeles and San Francisco airports could have had security lines stretching to the Sierras.

Californians would also have been barred from buying certain medicine, entering federal court buildings or getting help at the Social Security Administration, unless they have a passport. But after Threat Level provided Homeland Security spokesman Laura Keehner with the letter, Keehner said California's commitment to thinking about commitment is good enough.

...

At issue are long-delayed rules that require states to collect, verify and store birth and marriage certificates for nearly all citizens who have state-issued licenses or identification cards.

...

DHS says that it is committed to rejecting the rebel states' driver's licenses as acceptable proof of identification come May 11. That means almost every driver's license holder will have to get certified documents and go into the DMV to get a new license -- and many will likely have to go in more than once.

Now to Montana, and Gov. Brian Schweitzer victory in his initial stand off with DHS. Every state considering opposing this Act should look to Montana now:

The federal government won't penalize Montana for refusing to comply with the REAL ID Act, state officials said Friday - and Montanans can use their driver's licenses for identification when they board commercial airplanes.“We just stood our ground,” Gov. Brian Schweitzer said. “We didn't blink, we didn't buckle, and they said OK. We gave up about nothing.”

...

The state therefore has an extension until Dec. 31, 2009, when the next phase of REAL ID takes effect, Baker said.Schweitzer said he had been negotiating directly with Chertoff, saying Montana driver's licenses have the security provisions that REAL ID is expected to require in the future, but doesn't require now.

“It was becoming the theater of the absurd,” the governor said. “It didn't make sense for them to penalize Montana. They've accepted where we're at and we will continue to use (our licenses) at airports.”

RFID-Hack Hits 1 Billion Digital Access Cards Worldwide

I'm back from my mini-vacation (hence no posts here since Thursday)...just in time to post this article in PC World detailing just how vulnerable RFID technology can be to would be hackers (at least this specific model anyway) and identity thieves.

PC World Reports:

NXP developed the Mifare Classic RFID (radio frequency identification) chip, which is used in 2 million Dutch building access passes, said ter Horst. One billion passes with the technology have been distributed worldwide, making the security risk a global problem. A spokesperson for the ministry told Webwereld, an IDG affiliate, that it had not yet notified other countries.

The warning comes in a week when two research teams independently demonstrated hacks of the chip's security algorithm.

...

Criminals can use the hack to clone cards that use the Mifare Classic chip, allowing them to create copies of building access keys or commit identity theft. The chip is used in payment systems worldwide, such as the Oyster Card in the U.K. and the CharlieCard that is used in Boston. Both offer payment systems that allow for wireless transactions.

Our position on this technology is pretty simple: as a society, before we jump head first into the full fledged implementation of any technology that raises these kinds of questions we should take a step back and do the kind of thorough review of the pros and cons first. Then, based on what we find, put in place common sense regulations and safeguards...using the Constitution and our right to privacy as the most important factors in formulating public policy...rather than factors like so called "consumer convenience" and corporate profit.

Click here to read the article in its entirety.

Thursday, March 20, 2008

Next lines of cell phones have privacy implications

Adding to the list of consumer goods that will soon contain RFID tags is the almight cell phone. Thankfully we have David Lazarus of the Los angeles Times (but article is in the Fresno Bee) takes us through the privacy implications of cell phones that will allow each and every one of us to be tracked, anywhwere and everywhere:

But the same chip-based technology that California won't allow to be forcibly placed under people's skin soon will be ubiquitous in cell phones, which the telecommunications industry believes will be used increasingly as electronic wallets to make purchases.

...

Here's how it'll work: You go to a store, select a pair of khakis and wave your phone in front of a reader at the cash register. The purchase price instantly is deducted from your checking account like a debit card or applied to a credit card account. A record of the purchase also is entered into the store's database. That's very convenient, and undeniably will be a boon to shoppers, merchants and cell phone companies.

What the technology also means, though, is that all cell phone owners, which is nearly everyone, will be technologically "tagged." In theory, anyone -- or any company or government agency -- with a desire to do so would be able to identify you from as far as 300 feet away and track you as you go about your business.

Your cell phone constantly would be broadcasting your location, along with, possibly, your name, address and other potentially sensitive information.

...

At the moment, the most common form of RFID tagging in this country is what is known as a "passive" emitter. That means the tag has no independent power source and must be activated by an external scanner, usually within a range of 25 feet.

Increasingly, passive tags are being replaced with tiny battery-operated "active" tags that continuously transmit signals as far as 300 feet. Those signals can be picked up by anyone with an RFID scanner.

...

In 2006, for example, IBM received patent approval for a system that, according to the patent application, could be "used to monitor the person through the store or other areas."

That "or other areas" is what spooks privacy advocates. At the moment, there are few limits on how this technology can be used.

"The notion that we're building a surveillance society is very real," said Sophia Cope, a staff attorney at the Center for Democracy and Technology, which focuses on civil liberties in the digital age.

Click here to read the article in its entirety, and hear some of the ideas being pushed to regulate the technology.

Wednesday, March 19, 2008

Privacy advocate, ACLU hit new Virginia privacy law as misguided

As many know, California passed a law (which was signed) called AB 1168 (Jones) last year that requires state and local government agencies, as well as all colleges and universities in California, to honor consumer expectations of personal privacy by safeguarding Social Security numbers.

In Virginia they're apparently not so lucky. In fact, its worse than that, as the state has decided to target privacy advocates rather than the laws that leave the door open for identity theft.

This one is really hard to believe people, so let's go to Computerworld for the story:

A Virginia-based privacy advocate who has been fighting to stop county and state governments from posting public records containing Social Security numbers on their Web sites is now preparing to do battle against an amendment to a Virginia law that bars individuals from disseminating any of those numbers, even if they obtain them legally from public records.

Far from viewing the bill that amended Virginia's Personal Information Protection Act as a cause for celebration, privacy advocate Betty "BJ" Ostergren claims that it violates her free-speech rights and will do nothing to stop county governments in the state from posting documents without first redacting Social Security numbers and other sensitive data. In fact, Ostergren said the measure seems to have been designed to curtail her campaign to publicize and end that practice.

...

According to Ostergren and other privacy advocates, county government Web sites in Virginia and elsewhere around the U.S. have become veritable treasure troves of sensitive data for identity thieves and fraudsters. Ostergren, who lives in Virginia's Hanover County, said the bill signed by Kaine will do little to prevent just about anyone worldwide from accessing the public records on county Web sites for a nominal fee. All the amended law does is prohibit people from spreading the information after it is made available to them, she contended.

Ostergren runs a Web site called The Virginia Watchdog, which she uses to highlight the privacy problems that she claims can result from the posting of unredacted tax lien records and other documents on government Web sites. In recent years, she has chronicled dozens of cases in which local governments have inadvertently exposed Social Security numbers and other personal data through their Web sites.

As part of her strategy to highlight the seriousness of the issue, Ostergren has routinely posted on her Web site the Social Security numbers of public figures that she accessed via government sites. The list includes former Florida Gov. Jeb Bush, former Secretary of State Colin Powell, former U.S. House Majority Leader Tom Delay, former Missouri senator Jean Carnahan and several of Virginia's county clerks. Ostergren claims that she posted the numbers to demonstrate the ease with which such information could be obtained and to pressure county officials into taking action.

...

Ostergren said that in challenging the amendment, her ultimate goal remains convincing the Virginia legislature to stop county clerks from openly posting sensitive personal data. Currently, she claimed, 84 of the 121 county governments in Virginia post unredacted public documents — such as land records, state and federal tax liens, divorce decrees and name change records — on their Web sites.

...

In a prepared statement issued last week before the governor signed the bill, Kent Willis, executive director of the ACLU's Virginia chapter, said the organization is a "staunch supporter" of laws that would prevent the government from posting Social Security numbers on publicly accessible sites. "But the government can't put the numbers online and then turn around and prevent the public from using those numbers," Willis said. "This is a grossly misplaced bill that attempts to mask the fact that Virginia's lawmakers have failed to prevent Social Security numbers from being placed online in the first place."

I don't know what's the most disturbing aspect of this story:

  • that social security numbers are so easy to find by would be identity thieves;
  • that this proposed law is so utterly useless in dealing with the stated problem;
  • that the Virginia legislature and Governor appear to be targeting Ms. Ostergren because of her efforts to draw attention to these privacy concerns;
  • or that this bill might have something to do with the fact she's posting Social Security numbers of powerful people like Jeb Bush and Colin Powell...versus say, doing something to stop identity thieves from stealing from everyday people?!
Click here to read the article in its entirety.