Sunday, July 03, 2005

Hotel Clerk Arrested After Choosing Privacy Over Police

Police in Connecticut have arrested a hotel clerk who refused to give police information about a guest of the hotel, citing respect for the guest's privacy. The police were responding to a report about a suicidal person and finally got the information when they convinced the clerk to call his manager. See NBC30.com: Hotel Clerk Arrested After Choosing Privacy Over Police.

ChoicePoint's IRS contract under review

ChoicePoint is back in the news. This time, it is because of a multi-million dollar contracted awarded to it by the IRS. The contract is now coming under review after widespread criticism: ChoicePoint's IRS contract under review.

Saturday, July 02, 2005

Security weakness in the data chain

The New York Times (yesterday's edition) has a revealing article on the payment processing industry with a particular focus now-notorious Cardsystems and on security (or not) in the industry: Weakness in the Data Chain - New York Times.

Indian PM For Making Illegal Data Transfer A Punishable Offence

The Indian government is trying some damage control and considering legislative changes in light of the most recent incident: Indian PM For Making Illegal Data Transfer A Punishable Offence. For background, see The Canadian Privacy Law Blog: How secure are India's call centres?.

The Canadian Privacy Law Blog has Moved!

After ages of deliberating, I've taken the plunge and moved this blog to my own domain: The Canadian Privacy Law Blog.

The new RSS feed is at http://www.privacylawyer.ca/blog/atom.xml.

I was wary of making the move, since it'll probably throw off all my previous Google rankings and my RSS subscribers, but I did manage to leave the old blog at pipeda.blogspot.com, with a redirect on each page so that all old links will redirect to the relevant page on the new server.

What follows is more geekish than usual, but it may be helpful for anyone else figuring out how to move a blog from blog*spot to another domain.

Follow the instructions that you can find here, but also add the following to the top of your blog templates, just after the <BODY> tag:

<SCRIPT LANGUAGE="JavaScript"> if (location.href.indexOf("privacylawyer.ca") != -1){} else { window.location = location.href.replace('pipeda.blogspot.com', 'www.privacylawyer.ca/blog'); } </SCRIPT>

I couldn't find any websites with a complete how-to, so I figured I'd post it here in case it can save anybody half a day of learning about javascript.

Before you publish to your new location, republish the blog on Blog*Spot, so that the pages left on Blog*Spot include the redirect code.

Also, as soon as you move to the new server, create a new blog with the old blogspot domain so that it will not be overwritten by anyone else.

Friday, July 01, 2005

This blog is moving soon...

Sometime over this weekend, I'll be moving this blog from its current spot at http://pipeda.blogspot.com to http://www.privacylawyer.ca/blog.

I'm sure this will probably mess up the RSS feed, but I think the new URL for that will be http://www.privacylawyer.ca/blog/atom.xml.

I hope that you can still find the site after the move.

FTC chief's credit card data stolen

The Associated Press, via CNN.com, is reporting that the head of the FTC's personal information was compromised in the DSW data incident: CNN.com - FTC chief's credit card data stolen

Incident: 3,300 affected as hackers hit UCSD server; fourth incident in just over a year

This is the fourth security/privacy incident at University of California San Diego since April 2004: SignOnSanDiego.com > News > Education -- 3,300 affected as hackers hit UCSD server.

Alberta Commissioner finds that local library had no authority to use keystroke logging software

The Alberta Information and Privacy Commissioner has concluded that a local library did not have authority to install keylogging software on an employee's computer:

Commissioner finds that Parkland Regional Library had no authority to collect personal information using keystroke logging software:

"The Parkland Regional Library installed keystroke logging software on the computer of an information technology employee, unknown to the employee. The employee complained that this collection was not permitted under the Freedom of Information and Protection of Privacy Act (the 'Act'), and that the collected information had not been adequately protected by the Parkland Library.

The Parkland Library relied on section 33(c) of the Act, which permits collection of information that relates directly to and is necessary for an operating program or activity of a public body. It argued that the collected information was necessary to manage the employee, based on concerns about his productivity, and his use of his working time.

The Commissioner found that the Parkland Library did not have the authority under section 33 of the Act to collect the Applicant's personal information that it collected through keystroke logging and noted that less-intrusive means were available for collecting information needed for managing the employee. However, the Commissioner did not accept the Applicant's argument that the collected information had not been adequately protected."

Ottawa mulls single information-privacy watchdog

Just hours before the end of his seven year term as Information Commissioner, John Reid has been given a three-month extention while Ottawa contemplates combinding the offices of the Information and Privacy Commissioners into a single person: TheStar.com - Ottawa mulls single information-privacy watchdog