Wednesday, December 08, 2004

Privacy the 'Hot' Topic of 2004?

As soon as it came to my attention, I added Michael Fitzgibbon's fantastic blog Management Updates: Thoughts from a Management Lawyer to my blogroll. He consistently has very high quality analysis and insights on important issues that affect all employers. (He's also a charter member of the Canadian legal blogging community.)

Needless to say that I wholeheartedly agree with his post that privacy is consistenly one of the hot topics of 2004. I just hope it will continue to be so in 2005! Check it out: Privacy - The 'Hot' Topic of 2004?

Federal Privacy Commissioner to enter the DRM discussion

According to P2PNet, the Office of the Privacy Commissioner is about to become involved in the discussions related to copyright reform and digital rights management:
DRM personal privacy threat:

"p2pnet.net News:- Jennifer Stoddart, Canada�s privacy commissioner, says she's about to, "become involved in the process to amend Canada's copyright laws".

Her statement came in response to a CIPPIC (Canadian Internet Policy and Public Interest Clinic) request to address privacy implications of proposed copyright legislation.

In it, Stoddart said she would, 'oppose legislation or legislative amendments that conferred unjustified privacy-invasive surveillance powers upon digital copyright holders,' going on: 'However, we have not as yet been consulted by either Heritage Canada or Industry Canada officials regarding the proposed legislation referred to in your letter. I have instructed my staff to initiate a dialogue with these departments to ensure that privacy risks are identified and addressed.' ..."

CN Rail turns on hidden cameras to investigate vandalism

Further to my earlier post (CN's hidden camera sparks workers' ire (Winnipeg Sun), Canadian National Railway says hidden cameras will stay), the Winnipeg Sun is reporting that CN Rail has activated the hidden cameras at issue and the union is pretty mad about it:
Winnipeg Sun: NEWS - CN spying: union:

"Operating four hidden cameras

By KATHLEEN MARTENS, BUSINESS REPORTER

CN Rail has now turned on four hidden cameras in its Transcona Wheel Yard, the Canadian Auto Workers union says. The news is a blow to the union, which had been fighting to get the company to disconnect the covert surveillance discovered two weeks ago.

A maintenance-area worker found one camera in the ceiling and the union contacted the media about the find. The railway confirmed publicly there were two cameras that had not yet been activated trained on an area where repair work was under investigation.

Union spokesman Dennis Wray said he received a letter from CN yesterday saying four cameras were now running.

'The members are upset,' said Wray, who is CAW Local 100 vice-president for the Prairie region."

Tuesday, December 07, 2004

More Ontario government damage control

The Ontario government has released an apology and an account for what happened in the most recent breach of privacy that involved 27,000 government benefits recipients:

Update On Disclosure Of Personal Information :

Government Apologizes And Takes Immediate Steps To Correct Computer Error

  TORONTO, Dec. 6 /CNW/ - On behalf of the Ontario government, Gerry Phillips, Chair of Management Board of Cabinet, today repeated his apology to recipients of cheques from the Ontario Child Care Supplement for Working Families Program whose privacy was breached last week. The breach, which affects approximately 27,000 people, resulted from an error that caused the stub portion of the cheques to include the name, address and an identifier that includes the SIN number of another client.

  Phillips has stressed that the Ontario government will take every action possible to help prevent the recurrence of such incidents in the future.

  This disclosure of personal information about another recipient was caused by a cheque-printing error that occurred during the implementation of a computer software upgrade. These cheques were dated November 30, 2004, and were part of a run of approximately 27,000. The approximately 86,000 people who receive payments by direct bank deposit were not affected.

  While there were many people affected, the personal information of any single recipient is only included on one other cheque stub.

Measures Taken

--------------

  Once ministry staff learned of the nature and scope of the problem on the evening of December 2, government cheque production and distribution were stopped.

  On December 3, the government informed the Information and Privacy Commissioner and all MPPs of the breach. Government officials worked with the Information and Privacy Commissioner and others to determine the most appropriate way to assist the affected individuals.

  On the weekend, letters of apology were prepared for all Ontario Child Care Supplement clients affected by this breach. At 7 a.m. today, the letters were given to Canada Post for delivery.

  Based on advice from the Information and Privacy Commissioner, the government has asked people affected by this to destroy any personal information they received which does not belong to them. As a precautionary measure, the government has recommended that cheque recipients monitor and verify all bank accounts, credit card and other financial transaction statements for any suspicious activity.

  Government officials have identified the problem, fixed and tested its computer cheque systems, and been assured that these systems will operate properly.

  Officials have also taken steps to ensure that no problems have arisen in other computer cheque systems. These systems are operating correctly, cheque processing has resumed, and no backlog is expected.

  The government has implemented additional quality assurance measures and will continue to update appropriate technical and procedural measures to ensure the highest standards for safeguarding personal information.

  The government welcomes and will cooperate fully with the Information and Privacy Commissioner during any investigation into this matter.

  In addition to seeking the Commissioner's advice, the government is conducting an internal audit into this breach to determine precisely what happened and why.

  The government sincerely regrets the breach of privacy."

Glitch lets you mess with the phone book

I just received a pointer to a story in the Vancouver Sun about an interesting glitch that appears to allow anyone to alter any directory listing on the SuperPages online phone directory. The site is available from myTelus.com. Not a good thing. I expect that Telus has had enough of dealing with the Privacy Commissioner as of late.

I just went to www.mytelus.com and it looked like I could change the info of my west coast relatives. Not that I would ...

The story is available on the Vancouver Sun website, but they expire their content quickly.

SuperPages glitch lets anyone alter your listing

"Fancy an address in Shaughnessy? Or do you dream about moving your boss to Timbuktu?

A security glitch in SuperPages' online listings allows anyone to change the telephone number, address and other personal information of any listing and the edited version will show up in the SuperPages and myTelus.com listings for subscribers across Canada.

A similar loophole in www.SuperPages.com allows users to do the same for U.S. listings, although unlike SuperPages.ca, the U.S. site doesn't permit telephone-number changes.

Jonas Abersbach, who runs his own tech-support company, SupportLINK Systems, discovered the glitch when he went online to change his company's SuperPages listing.

SuperPages is the Telus directory that handles both the online and print white pages and classified directory.

Making the change requires some deception. Abersbach found that, by using a free e-mail account and a password of his own invention, he could not only change his own information, he could change others' as well.

"If you do it properly you can use the same computer to update many listings," said Abersbach, who started his company at the age of 17 and ran it part time while he completed a computer-science degree at the University of B.C. "Thousands of records could be corrupted. What's maybe more of a problem, for example, is the address of the police chief could be changed or added, or his name could be slandered, or he could be given a middle name -- and the same for government figures, political figures or famous people.

"Their privacy is infringed upon. Everybody's privacy is infringed upon."

Abersbach said he took his concerns to SuperPages because he was worried any savvy hacker could create a program to wreak havoc with the online database. He said someone with knowledge could write a program in a couple of days that could override the SuperPages condition allowing only two updates per e-mail address.

"You could write a program to register an e-mail address online and use a different e-mail address after every two updates," he said.

Abersbach said after two weeks it appeared SuperPages had updated one of its servers to prevent the unauthorized editing, but anyone clicking on the site could be directed to a server that still had the glitch.

I tested SuperPage's security, first giving our business editor an address on Dante's Ave. in Hades and then moving him to: 1234 Vancouver Sun St., Pouce Coupe, B.C., H0H0H0, with the phone number 604-123-4567...."

A Background of a 'Background Checker'

Slashdot has a discussion about privacy, profiling and Abika.com, an American company that was recently the subject of a complaint to the Office of the Privacy Commissioner (see: CIPPIC complaint raises a number of novel and interesting issues). The discussion was kicked off by a profile of the founder of the company in the Times of India: Now, invasion of Pravasi privacy. Interesting reading, all of it.

B.C. hospital giving patients unprecedented chart access (MedicalPost.com)

The Medical Post has a good article on how the BC Childrens' Hospital has been providing patients and their parents liberal access to medical records, without disruption and also fostering trust and better communication: MedicalPost.com: B.C. hospital giving patients unprecedented chart access.

Privacy Commissioner issues first spam decision under the Personal Information Protection and Electronic Documents Act (PIPEDA)

Michael Geist, of the University of Ottawa and member of the federal SPAM Task Force, has instigated the first finding of the Office of the Privacy Commissioner related to spam. Not only is it the first decision of its kind, it also concludes that business e-mail addresses are not included in the so-called "business card exception" to the definition of "personal information" and that the harvesting of e-mail addresses from an organization's website does not allow the use of the consent exception that applies to "publicly available information".

The "business card exception" relies on the definition of "personal information" under s. 2 of PIPEDA:

"personal information" means information about an identifiable individual, but does not include the name, title or business address or telephone number of an employee of an organization."

The Assistant Privacy Commissioner, in the written finding to Professor Geist, concludes that because business e-mail addresses are not listed in the definition, they are not excluded from the definition.

The "publicly available information" exception is contained in s. 7 of PIPEDA:

Collection without knowledge or consent
7. (1) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may collect personal information without the knowledge or consent of the individual only if

...

(d) the information is publicly available and is specified by the regulations.

Use without knowledge or consent
(2) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may, without the knowledge or consent of the individual, use personal information only if

(c.1) it is publicly available and is specified by the regulations;

The key provision in this case is contained in the regulation that stipulates that one can only use "publicly available information" for the purposes for which it was made available to the public in the first place:

(b) personal information including the name, title, address and telephone number of an individual that appears in a professional or business directory, listing or notice, that is available to the public, where the collection, use and disclosure of the personal information relate directly to the purpose for which the information appears in the directory, listing or notice;

In this case, the Assistant Commissioner concluded that Professor Geist's e-mail address was posted on the University of Ottawa website to further the interests of the University. This purpose did not include receiving solicitations to buy sports tickets.

I will be interested to see if Professor Geist will take this matter to the Federal Court to provide us a more definitive conclusion on these important points.

See, also, a very good article on this incident at the Toronto Star: Football club broke email privacy rules.

Monday, December 06, 2004

Ontario government switches to damage control

After the recent incident that saw personal information of 27,000 Ontarians disclosed (see: Another privacy breach to round out the week, et seq), the government of Ontario has switched to damage control mode. Interestingly, the Chairman of Ontario's Management Board says there is no threat of identity theft or fraud from the incident:

Government insists no threat of identity theft after release of personal data:

"TORONTO -- There's no serious threat of identity theft after the government mistakenly sent out 27,000 provincial cheques with the wrong names and social insurance numbers attached, Management Board Chairman Gerry Phillips insisted Monday.

''We know exactly who got the name of the next person,'' Phillips told the legislature. ''I think that frankly eliminates any possibility of theft or fraud in this case.''...."

Sunday, December 05, 2004

US Government developing standard for positive identification

According to Privacy Digest, the National Institute for Science and Technology is developing a national standard for positive indentification of government employees and contractors. The following is a general introduction to the project, from a working paper released on the NIST site:
The “Personal Identity Verification for Federal Employees and Contractors” briefing was developed in response to the Homeland Security Presidential Directive (HSPD-12). The directive sets a policy for a common identification standard for Federal employees and contractors. It also establishes the high level requirements to be satisfied in the Personal Identity Verification standard.

The following information is intended to convey current thinking regarding the NIST response to the HSPD. The concept and design decisions contained herein are tentative and subject to change in the course of consultations with affected Federal government departments and agencies.

A general threat facing government agencies is the unauthorized access to physical facilities or logical assets under the protection umbrella of the PIV system and in which a PIV card is employed in access control processes. Specific examples of threats to government resources include the following:

  • Cardholder makes improper use of a valid card
  • Counterfeit cards are used to intercept or gain access to stored information
  • Stolen or borrowed cards are used to gain unauthorized access
  • PIN information is captured / intercepted through passive surveillance
  • Lower sensitivity rated cards are used to gain access to more sensitive and critical assets.

HSPD-12 mandates a government-wide standard for secure and reliable forms of identification. The policy further defines the following criteria for a secure and reliable form of identification. The identification standard (PIV FIPS 201) will be:

  • Based on sound criteria to verify an individual employee’s identity
  • Strongly resistant to fraud, tampering, counterfeiting, and terrorist exploitation
  • Rapidly verifiable electronically
  • Issued by providers whose reliability has been established by an official accreditation process
  • Applicable to all government organizations and contractors
  • Used to grant access to Federally controlled facilities and information systems
  • Flexible enough for agencies to select the appropriate security level for each application by providing graduated criteria from least secure to most secure
  • Not applicable to identification associated with national security systems
  • Implemented in a manner that protects citizens’ privacy

The program working paper is available at http://csrc.nist.gov/piv-project/Papers/Narration-PIV-Briefing10-1.doc and a slideshow from the project briefing is available at http://csrc.nist.gov/piv-project/Papers/PIV-BriefingSept16-2004.pdf.

Thanks to Privacy Digest for the pointer.

This is a complete aside, but I found it very interesting that the word document above is loaded with metadata, showing the last minute revisions that were made to it before the briefing. The tone of the narrative was shifted slightly. To see the changes, open the document, right-click on the toolbar above the document, select "Reviewing" and, on the toolbar that appears, select "Final, showing changes" in the drop-down box. Voila, you can see the revisions made.

Lucily for NIST, the document it is not full of "notes to draft" or anything significantly embarrasing. It is a bit surprising in any event that the organization responsible for IT security standards is posting metadata-laden documents on its website!