Thursday, January 12, 2006

Phone records of Gen. Wesley Clark bought for under $100

I expect we'll see some strong legislative action in the US to stop the sale of calling records if bloggers follow AMERICAblog's footsteps and buy the phone records of prominent Americans. AMERICAblog bought the phone records of General Wesley Clark, the former Supreme Allied Commander of NATO. They apparently did it to prove a point: "We wanted to see if it was possible to buy the phone records of someone high profile in order to prove that this is a problem with serious national security implications, and frankly, we didn't want to pick a Republican since we thought such a choice would be perceived as partisan or mean-spirited, and that is not our intent for exposing this. Our intent is to get this problem fixed so that we all can benefit." Check it out (and the hundreds of comments) here: AMERICAblog: Because a great nation deserves the truth.

Thanks to EPIC West for the link: EPIC West: Electronic Privacy Information Center West Coast Office: Blogger Buys General Clark's Cell Phone Records.

Technorati tags: :: :: ::

Privacy is in the eye of the beholder

If you were looking for evidence that some people take privacy pretty seriously, look no further than the situation that has befallen Cheryl Gallant, a Conservative candidate for Member of Parliament for Renfew-Nipissing-Pembrooke. A short while ago, I blogged about a fuss that has been kicked up after her constituency office sent birthday cards to constituency residents. It appeared that the only place that the MP's staffers could have gotten the citizens' birthdays was from passport applications processed through her office. At least two people were upset then (see: The Canadian Privacy Law Blog: Birthday Cards lead to investigation by the Privacy Commissioner).

The story continues: The candidate began her remarks at a recent debate by wishing everyone there a happy birthday. (Some in the audience booed the reference, though they might have been Liberal plants.) Her remarks have been taken as being a bit flippant.

ottawasun.com - Election - Gallant vows privacy probe

Asked if constituents' privacy was a joking matter, she said people have been complaining they didn't get a card, so she thought she'd simply send greetings to everyone at once.

On Monday, Gallant said, the number of people calling her office requesting cards crashed the office's phone system.

She intends to conduct a probe and said that although her office is not covered under the jurisdiction of the privacy commissioner, they've always conducted business as if it was.

"If one person can get so upset and make such a hullabaloo, we want to ensure no one else's feelings are hurt," she said.

"What we did was a courtesy, a gesture of kindness."

Deep River resident Leslie White, who has no affiliation to any political party, said her husband and mother both received birthday cards from Gallant last month. Both had recently had passports processed through Gallant's office. Other constituents have come forward with similar stories, including a 19-year-old man. Gallant couldn't explain how he came to get a card, but said they are sent out on request and most people are happy to get one.

"In the five years I've been a member of Parliament, two days into this election was the first time I had ever received a complaint about receiving a birthday card," Gallant said. "So I almost wonder if somebody gave us the referral and knew that she didn't like it and that it would put her off her rocker, so to speak."

Privacy is an emotional issue. Some people are very sensitive and are not shy about going to the press when they feel they've been "violated". What might have appeared to be a gesture of kindness on the part of the sender may be a very creepy experience for the recipient of the gesture. Anyone dealing with personal information or thinking about it has to keep in mind that privacy is a very sensitive issue for a lot of people and you should look at your proposed actions through the eyes of your most privacy sensitive customer. If it'll upset them, it probably is not worth doing since the fallout often consumes your energy and detracts from whatever beneficial effect you might have hoped for.

Technorati tags: Privacy :: Passport :: Politics :: Canada

Checking out Mao? No need to worry

In the wake of the (ultimately false) report that the federales had visited a student becuase he requested Mao's Little Red Book (See: The Canadian Privacy Law Blog: Borrow the wrong book and get it personally delivered by the feds; and then The Canadian Privacy Law Blog: Story about feds visiting after request for Mao book is a hoax), the UMass Dartmouth and Penn libraries are trying to reassure patrons that their records are safe. In fact, they say that once you return the book you've checked out, the title is no longer connected to your borrowers' record. Check out the Daily Pennsylvanian: Checking out Mao? No need to worry.

Technorati tags: Privacy :: Libraries :: Security :: Personal Information :: Patriot Act.

Visa and Mastercard mull open standard for transaction security

The New York Times reports that Visa and Mastercard have been quietly meeting to discuss setting up an open standards body to set best pactices for the processing of electronic and payment card transactions. See: Credit Card Rivals to Unite in Data Protection Effort - New York Times.

Technorati tags: Privacy :: Credit Cards :: Electronic Payments :: Open Standards :: Security

Wednesday, January 11, 2006

Nova Scotia Auditor General concerned about effect of USA Patriot Act on citizen privacy

The Nova Scotia Auditor General released his report for 2005 in December. The fourth chapter is entitled Electronic Information Security and Privacy Protection.

In his report, he reviews the privacy and information security practices of a number of departments, including Justice and Community Services. He also touches upon the USA Patriot Act and its possible impact on the personal information of Nova Scotians. Data processing and information storage services for the province are provided by wholly-owned subsidiaries of American companies, which are undoubtedly subject to American laws. The province has carried out a study of the situation, but refused to provide it to the Auditor General, citing solicitor-client and cabinet privilege. In an interview by the Canadian Press, the provincial Minister of Justice hinted that Nova Scotia will be introducing a law in the spring sitting of the Legislature to mirror that passed by British Columbia to better protect personal information from being disclosed to foreign law enforcement.

Read the CP article here: N.S. auditor concerned citizens information could be leaked to U.S. agencies - Yahoo! News.

Technorati tags: privacy :: Patriot Act :: Nova Scotia :: privacy law.

Nova Scotia FOIPOP Review Officer to form Right to Know coalition upon retirement

As reported here on Saturday (The Canadian Privacy Law Blog: Nova Scotia's FOIPOP Review Officer to step down), Nova Scotia's Freedom of Information and Protection of Privacy Review Officer will be stepping down from his post on January 23, 2006 when his term concludes. Today's Halifax Chronicle Herald reports on the retirement and mentions that Darce will not be disappearing into the sunset. He is planning to start a "Right to Know" coalition to educate people about access to information laws and to lobby for greater openness. See: Freedom of information protector leaving his post: Fardy plans to start citizens coalition called Right to Know

Technorati tags: :: :: .

Incident: Bank tape lost with data on 90,000 customers

Another bank data tape lost in transit on its way to a credit bureau. This time, it is People's Bank of Connecticut and the tape had the personal information of 90,000 customers. Check it out: Bank tape lost with data on 90,000 customers - Computerworld

Technorati tags: :: :: ::

Is iTunes reporting your listening back to the mothership?

Boing Boing passed along to its readers (Boing Boing: iTunes update spies on your listening and sends it to Apple?) a report that the latest version of Apple's iTunes is reporting back to Apple the music that users are listening to (see: since1968.com: iTunes Update: Apple's Looking Over Your Shoulder). This "feature" is via the MiniStore, which presents info about the performer whose song you are listening to and "other users also bought ..." information. The author was concerned that info about current listening was being passed back to Apple without telling users about it.

Other commentators have pointed out on Boing Boing that iTunes does not "phone home" if the MiniStore pane is closed.

This looks a lot like the feature in Windows Media Player which does something very similar, but I note that Microsoft at least asks you when you install if you mind having your info passed along to Microsoft. Apple the good doesn't look so good next to Microsoft.

Technorati tags: :: :: :: :: ::

Incident: Data for 55,000 customers stolen from Bahamas hotel

According to Computerworld, a high-clas island resort's databases have been hacked, leading to the exposure of personal information of 55,000 customers. The report says that the information compromised included "names, addresses, credit card numbers, Social Security numbers, driver's license numbers and bank account numbers."

What possible reason would a hotel have for collecting Social Security Numbers from guests? And if it had a reason to collect this sort of info, why would it keep it?

Personal information is like an underground tank, half full of oil. If you don't need it, get rid of it. The more of them you have and the longer you have 'em, the higher the risk of disaster.

Here's the gist of the Computerworld article:

Data for 55,000 customers stolen from Bahamas hotel - Computerworld

Data for 55,000 customers stolen from Bahamas hotel The upscale Atlantis Resort has acknowledged an apparent database break-in

JANUARY 11, 2006 (IDG NEWS SERVICE) - Travelers who stayed at the upmarket Atlantis Resort in the Bahamas should keep a close eye on their bank statements in the months ahead. The hotel has acknowledged an apparent database break-in in which personal information for 55,000 guests may have been stolen, including credit card and bank account numbers.

The resort said it is notifying affected customers in writing so that they can "take steps to protect themselves from possible identity fraud."

Kerzner International Ltd., which operates the 2,000-room "ocean-themed" resort on Paradise Island, reported the theft last week in a U.S. regulatory filing. An internal investigation revealed that the information had been stolen from a database of Atlantis customers.

...

The information stolen includes names, addresses, credit card numbers, Social Security numbers, driver's license numbers and bank account numbers. Approximately 55,000 customers may have been affected, the resort company said.

Technorati tags: :: :: ::

Iconic eatery Cafe Henry Burger shuts its doors after 83 years

The Ottawa Citizen is reporting that Cafe Henry Burger in Ottawa is closing down. According to the owner, the restaurant suffered a loss of business as fallout from the Radwanski scandal that lead to the downfall of the then Privacy Commissioner and opened all entertainment spending by public officials to much greater scrutiny.

Iconic eatery Cafe Henry Burger shuts its doors after 83 years

It made headlines of a different kind in 2003 when it was revealed that some public servants had run up huge bills at Cafe Henry Burger, including then-privacy commissioner George Radwanski. Mr. Bourassa concedes that the repercussions of that hurt sales at his restaurant.

"Following that, there was greater expense-account scrutiny and a greater call for access to information. This resulted in a loss of clients."

Despite the obvious sadness he feels at the closing of his restaurant, he is focusing on the many good experiences he has had.

I'm sure some would suggest that it was the loss of Radwanski's business that did it in.