Monday, April 04, 2005

Universities get a failing grade for security of personal information

Thanks to Rob Hyndman for sending me this link.

The New York Times has been noticing that universities offer a plentiful supply of privacy incidents, not only related to student information but also information about research subjects. The article does a good job of noticing the problem and thinking about its root cause:

The New York Times > Technology > Some Colleges Falling Short in Security of Computers: "... Data collected by the Office of Privacy Protection in California, for example, showed that universities and colleges accounted for about 28 percent of all security breaches in that state since 2003 - more than any other group, including financial institutions.

'Universities are built on the free flow of information and ideas,' said Stanton S. Gatewood, the chief information security officer at the University of Georgia, which is still investigating a hacking incident there last year that may have exposed records on some 20,000 people.

'They were never meant to be closed, controlled entities. They need that exchange and flow of information, so they built their networks that way.'

In many cases, Mr. Gatewood said, that free flow has translated into a highly decentralized system that has traditionally granted each division within a university a fair amount of autonomy to set up, alter and otherwise maintain its own fleet of networked computers. Various servers that handle mail, Web traffic and classroom activities - 'they're all out in the colleges within the university system,' Mr. Gatewood explained, 'and they don't necessarily report to the central I.T. infrastructure.'..."

Should parents be able to see children's library records?

I'm a regular reader of the LibraryLaw Blog. Over the weekend, Mary Minow posed the question, Should parents be able to see children's library records? Good question. Under PIPEDA (if PIPEDA applies to the library in the first place) or the provincial public or private sector privacy law, the answer would be no as long as the kid is old enough to make their own decisions.

Should parents be able to see children's library records? Amanda Welsh points out an article about a bill in Maine, sponsored by Rep. Randy E. Hotham, that would require public libraries to tell parents what books their children have checked out.

The bill is definitely part of a trend ... what do librarylaw blog readers think? Should parents be able to see their children's records, and if so how should "parents", "children" and "records" be defined? My thoughts, generally, on the topic are here.

For more on this topic, see PIPEDA and Canadian Privacy Law: Privacy and Public Libraries, which links to a presentation on the topic and has a bit of a dialogue with Mary in the comments.

Privacy Digest: Privacy News (Civil Rights, Encryption, Free Speech, Cryptography)

Privacy Digest (via Slashdot) is writing about a recent fuss being made in Italy about using RFID to track employees without their knowledge or consent.

News Item 2163 Privacy Violation in Italian Media Giant - tagging employees with Rfid chips since last December

Privacy Violation in Italian Media Giant.  orzetto writes  "Italian newspaper La Repubblica is reporting that Silvio Berlusconi's company, Mediaset (that owns three of the six main TV stations in Italy), has been tagging employees with Rfid chips since last December (for English version, ask the fish).

The chips would allegedly be able to track the movements of any worker, even if Mediaset spokesmen say it's only to automatically open some doors to authorized personnel only and such things. Trade unionists from CGIL have reported the company's behaviour to the authorities, as it would be in violation of the Italian workers' charter (again, fish). This would probably be small news (yet another bad employer) if Silvio Berlusconi were not the Italian Prime Minister, violating the same laws he should enforce."  [Slashdot: Your Rights Online]

BC Court dismisses union's privacy arguments in case over outsourcing

Professor Michael Geist, in his blog, is reporting on the BC union's loss in the courts in the battle against the provincial government's outsourcing of medicare processing services. The court opined on the adequacy of privacy protection in the oursourcing arrangement: B.C. Government and Services Employees' Union v. British Columbia (Minister of Health Services), 2005 BCSC 446.

www.MichaelGeist.ca - B.C. Court Dismisses Privacy Claim Over Data Outsourcing :

"The British Columbia Supreme Court has dismissed a claim by a B.C. union challenging the outsourcing of the management of health information to a U.S. company. The court emphasized the importance of privacy protection, but concluded that 'the contractual provisions, the corporate structure, and the legislative provisions provide more than reasonable security with respect to records in British Columbia.' It also noted that 'all reasonable steps to ensure the confidentiality of the information which Maximus will receive in order to discharge its contractual obligations. Privacy is not absolute.' Case name is BC Govt Serv. Empl. Union v. British Columbia (Minister of Health Services).

A very interesting decision since it may set the standard for the privacy issues and protections to consider when creating a data outsourcing to the United States. The case is part of an ongoing battle dating back to last summer over the Patriot Act and the protection of Canadian personal information. As I argued with Milana Homsi, the real issue is not the outsourcing of data to the U.S. Rather, it is the ability of U.S. courts to assert jurisdiction over Canadian organizations with even a small U.S. presence, which, notwithstanding PIPEDA, effectively limits the privacy protection enjoyed in Canada."

Sunday, April 03, 2005

Privacy Advocates Criticize Plan To Embed ID Chips in Passports

Discussion of RFID enabled passports has been going on for some time in the privacy community, but it is starting to hit the mainstream press:

Yahoo! News - Privacy Advocates Criticize Plan To Embed ID Chips in Passports:

"... State Department officials said the chips are part of a global effort to prevent passport fraud. Each chip will contain a digital record of all information printed on the passport, including the holder's name and document number. The chip will also contain the passport holder's photograph, enhanced by facial recognition technology. That way, even if the paper passport is altered, customs agents would be able to compare the information on the chip with the person presenting it....

"If you're walking around in Beirut, it would be well worth Al Qaeda's money to use one of these readers to pick out the Americans from the Swedes without any problem," said Barry Steinhardt, director of the American Civil Liberties Union's technology and liberty program...."

Saturday, April 02, 2005

School surveillance cartoon

Couldn't help but post this, from Cagle's Cartoon Index:

Privacy in the Workplace: Case Studies on the Use of Radio Frequency Identification in Access Cards

RAND has released an interesting report on the use of RFID in the workplace. While the future and potential uses of RFID has gotten a lot of press lately, not much discussion has taken place about the thousands of companies that are currently using the technology for controlling access to buildings. Few companies have policies about how the information collected will be used and how long it will be maintained. In short, companies need to give this matter some thought, document their practices and let their employees know about it.

RAND | Privacy in the Workplace: Case Studies on the Use of Radio Frequency Identification in Access Cards:

"Companies use RFID workplace access cards to do more than just open doors (e.g., for enforcing rules governing workplace conduct). Explicit, written policies about how such cards are used generally do not exist, and employees are not told about whatever policies are being followed. Using such systems has modified the traditional balance of personal convenience, workplace safety and security, and individual privacy, leading to the loss of "practical obscurity." Such systems also raise challenges for the meaning and implementation of fair information practices."

Thanks to the Surpriv blog for the link: Surpriv: RFID Surveillance and Privacy: RAND Study of RFID Access Badge Data Policies and Practices.

ChoicePoint's CISO Speaks to Information Security Magazine

Adam Shostack's Emergent Chaos is carrying an extract from an extensive interview with Richard Baich, the CISO for ChoicePoint. The article is from a "subscribers only" site, but Adam has reproduced much of it in his posting: Emergent Chaos: Information Security Magazine on Choicepoint.

Friday, April 01, 2005

Debate over surveillance cameras in Halifax

A minor controversey is brewing here in Halifax over surveillance on Spring Garden Road, Halifax's principal shopping street. (See PIPEDA and Canadian Privacy Law: Surveillance cameras coming to Halifax's public places.) Merchants on the street are increasingly distressed by the number of young 'uns and panhandlers who hang out on the street, intimidating the shoppers. A lack of police on the street has led them to hire their own rent-a-cops. Now the merchants association wants to install their own video cameras to monitor the sidewalks and other public spaces. This has led to some comment, including an editorial from Bruce Wark in The Coast:

Upfront - Columnists - The Coast (MARCH 31 - APRIL 7 2005):

"The friendly folks at the credit union want to “see” my face and eyes, but they also have designs on my ears. The lobby with the cash machines is filled with the din of a happy voice informing me from overhead speakers about the incredibly low rates the credit union charges for loans. I do not want any more loans thank you, just reasonable fees, decent service and at least a tiny bit of interest on my savings. But the happy voice says nothing about that—at least, not as far as I can tell. A couple of weeks ago, the sound system went to rat shit. When I visited last Sunday, there was still a happy-voiced roar but it was so muffled, I couldn’t make out any words. Call me bitter and twisted, but as far as I can tell, the folks at the credit union do not “see” my face at all—the face of a longtime customer and financial supporter. No, to them, I look like either a potential criminal, or a stupid fool they can peddle loans to.

I guess I shouldn’t be too hard on the friendly folks at the credit union. They’re merely following the latest surveillance and marketing trends. In some Nova Scotia high schools for instance, administrators with expensive cameras spy on teenaged students while also selling the teenage thirst for soft drinks and fruit juices to the cola companies. (The high schools get kickbacks from the vending machines in exchange for giving the companies exclusive access to their students.) Some of our fine universities charge young adults sky-high tuition fees, then watch them with cameras and peddle them to big corporations. Ah yes, the morning Ethics 1000 class (enrollment 800) will be held in the Dominion Petroleum Building, in the Bank of Big Profits Lecture Hall, just down the corridor past the spy cams. And students, don’t forget to buy lunch cooked up by International Plasti-Foods Inc. in the Chemical Corporation Dining Room. Happy learning!

Now some Spring Garden merchants are yammering about the need for surveillance cameras on Halifax’s main drag where “young hooligans” have been swarming and robbing. As I see it, the call for spy cams is part of the ongoing campaign against panhandlers, the homeless and otherwise down-at-the-heel citizens, too poor to spend serious coin in Spring Garden boutiques, beauty parlours, eateries and watering holes. Mind you, as a solid middle-class burgher with a big, no-interest savings account at the Heritage Credit Union, I’m not defending swarming and robbing. But I can’t see how surveillance cameras will solve our social problems. Call me bitter and twisted, but I’d say some Spring Garden merchants see those of us on the public sidewalks as either criminals-in-waiting who need to be spied on, or gullible fools who can be made to believe that a few spy cams will make the world safe. I can just see the signs now: “We love to see your faces... and for security reasons, please remove all hats, helmets and sunglasses when ambling down our lovely Spring Garden Road.”""

Incident: Data from 270,000 Japanese bank accounts lost

There does not appear to be any malevolence at play in this incident. According to CNET, one of the largest banks in Japan has lost hundreds of thousands of customer records as a result of combining different IT systems. I call it an "incident" because the code of fair information practices requires a custodian to protect information against loss.

Lost: Data from 270,000 bank accounts | CNET News.com:

"Japanese bank Mizuho said it has lost the confidential data of 270,000 account holders. Mizuho Financial Group, which owns the retail bank, said it had lost customer account numbers and names at 167 branches over several years, according to a Financial Times report on Wednesday. The bank is said to have suffered problems integrating systems and managing data since it was formed three years ago...."