Sunday, February 05, 2006

Lipstick on Your Caller

The New York Times is running another article on the problem with companies that sell cell-phone records (Lipstick on Your Caller - New York Times), but the most significant "action item" from the piece is a quote from Marc Rotenberg of EPIC:

'The bigger problem is that all this information is lying around,' said Marc Rotenberg, the executive director of the Electronic Privacy Information Center. 'If companies can't keep the information secure, then they shouldn't keep it.'

That's advice that bears repeating: The Canadian Privacy Law Blog: Don't keep the data that you don't need.

Technorati tags: :: ::

Congressional committee seeking more info on online data brokers

According to RCRNews.com and others, the House Commerce Committee is seeking information from online data brokers in the course of investigating the sales of phone records. Their polite letter also threatens subpoenas if they do not cooperate.

Technorati tags: :: :: ::

More on metadata

The Globe and Mail's technology section has an article on hidden metadata, where it comes from and what Microsoft is trying to do to address the issue. (See: globeandmail.com : Stamping out metadata.)

Here are my own thoughts on the issue:

Metadata is one of the greatest privacy and confidentiality risks for users of Microsoft's Office suite of programs. It has caused innumerable slip-ups, mostly caused by users who are generally oblivious to its presence or how to remove it. It is also compounded by the fact that some of the most obvious meta data (track changes and comments) can be completely inapparent. For example, if someone sends you a document full of markups but their copy of Word is set to only show the "final" version, they won't see it before they send the document on. The setting to not show changes follows the document, so the next person to open it will not see the markups unless they manually change the option. The same goes for "comments", which can be handy but are often not apparent to the viewer of the document.

Like many things, there are features in Word that will help you avoid metadata blunders (Options Security Privacy), but they have to be manually turned on and the average user is completely oblivious. To make things worse, one of the options is misleading. If you click yes to "Warn before printing, saving or sending a file that contains tracked changes or comments" it will not really warn you when you send a file the way that 99.9% of people do. If you attach it to an outlook message, no warning. None. One might think that those two parts of the Office program would talk to one another. Or that the "feature" might be accurately labelled. No such luck.

Even with all the publicity given to metadata issues of late, I have still seen first-hand some metadata blunders that could have had a huge impact on confidentiality. I've seen a closing checklist for a huge transaction that was based on a precedent document. Whoever typed the changes had (likely accidentally) used "track changes" with the markups hidden, so they didn't see that the markups fully identified another client of the firm who authored it. I've also seen documents sent with lawyers' comments embedded that were sent to the other side. I've also seen service agreements with pricing information embedded from a previous customer. This is a serious issue.

So what's the solution? It is not to remove features like comments, track changes and the like. These are all useful features. Those who understand what the metadata problem is and how these applications work are likely pretty about the meatadata issue. The problem is that this is a potential security hole that exists out of the box and uneducated users don't know it is there and what it can do. Program designers need to make sure that the programs they publish are set to be secure and that users are educated about the possibility of compromising confidential information if the features are enabled. And while I'm at it, I'll suggest that the two most-used programs in Microsoft's Office suite, Word and Outlook, need to work together to deal with the issue. Programming a feature to warn users that they are about to e-mail a document with metadata probably wouldn't be impossible. Or have it only throw up a flag if the document is mailed to someone beyond the local exchange server. And have it alert if a document is being copied off a networked drive onto a CD, thumb-drive or other portable media. Finally, if the security setting says it'll warn you when you e-mail a metadata-ridden document, it should at least do so.

Update: Jim Calloway has a great post about metadata and lawyers: The Mysteries (and Magic) of Metadata.

Technorati tags: :: :: :: ::

Saturday, February 04, 2006

Queries about search queries answered

With all the fuss about search engines and what they know about users, Declan McCullagh of CNET has asked some probing questions of Google, Yahoo!, MSN and AOL. The answers are interesting: FAQ: When Google is not your friend Tech News on ZDNet.

Technorati tags: :: :: :: :: :: :: :: :: :: :: ::

Prototype RFID in Dutch passports cracked

According to Engadget (which got the story via The Register and Vara (Dutch)), the new (prototype) RFID technology being implemented in Dutch passports has been cracked:

Dutch RFID e-passport cracked -- US next? - Engadget:

"A Dutch television program 'Nieuwslicht' recently worked with local security firm Riscure to successfully crack and decrypt a Dutch-prototype RFID passport. In this case, the data exchange between the RFID reader and passport was intercepted, stored, and then the password was cracked later in just 2 hours on a PC giving full access to the digitized fingerprint, photograph, and all other encrypted and plain text data on the RFID tag -- just perfect for slapping together a cloned passport, eh? The flaw, at least in part, is due to the algorithm used when generating the secret key to protect the data. The key turns out to be predictable given that it is sequentially issued and constructed from the passport expiry date, birth date, passport number, and checksum. But don't kick back in superior isolationism just yet kid. Starting October 2006 the US will issue all new passports using the same ISO 14443 RFID tag and Basic Access Control encryption scheme employed by the Dutch e-passports (and others) and adopted by the ICAO as global standards. It's still not clear at what distance the exchange was intercepted -- while the passive ISO 14443 tag is spec'd with a read distance of only 2-milimeters you'll find claims of reads at several meters. This is important 'cause the greater the read distance in say, the line at airport immigration control, the greater the chance of abuse. Regardless, the Dutch e-passport system is still under development allowing for changes, which makes us wonder, is ours? Wouldn't be the first time we've abandoned RFID passport plans due to technology concerns.

Technorati tags: :: ::

Friday, February 03, 2006

Welcome Open and Shut

Welcome to the blogging world, Open and Shut. Peter Timmins of New South Wales in Australia works regularly with the freedom of information and privacy legislation down under. He has just started his new blog, Open and Shut. The blog goes hand in hand with his regular FOI Newsletter of the same name and should keep you up to date on what's happening in this area in Australia. Since the Austrailan experience with privacy and access law is similar to what we find in Canada, it's always worthwhile taking a global pespective. Welcome to blogging, Peter.

Thursday, February 02, 2006

Fact Sheet: Secure Destruction of Personal Information

The Information and Privacy Commissioner of Ontario has released a handy four page fact sheet on the secure destruction of personal information. Check it out in PDF here: .

Learn it. Live it. Love it.

Technorati tags: :: :: :: ::

Wednesday, February 01, 2006

Boston Globe wraps papers in subscribers' personal information

The Boston Globe is doing a major mea culpa after thousands of bundles of its paper were distributed with subscribers' personal information on the back of paper used to wrap the bundles. From the Globe itself:

Subscriber credit data distributed by mistake - The Boston Globe

Credit and bank card numbers of as many as 240,000 subscribers of The Boston Globe and Worcester Telegram & Gazette were inadvertently distributed with bundles of T&G newspapers on Sunday, officials of the newspapers said yesterday.

The confidential information was on the back of paper used in wrapping newspaper bundles for distribution to carriers and retailers. As many as 9,000 bundles of the T&G, wrapped in paper containing subscribers' names and their confidential information, were distributed Sunday to 2,000 retailers and 390 carriers in the Worcester area, said Alfred S. Larkin Jr., spokesman for the Globe.

In addition, routing information for personal checks of 1,100 T&G subscribers also may have been inadvertently released.

The Globe and T&G, which are both owned by The New York Times Co., share a computer system.

The release of the data is another in a long list of high-profile incidents in which companies, universities, and federal and state agencies have had sensitive financial information lost or stolen.

Globe and T&G officials said the newspapers have notified the four major credit card companies -- American Express, Discover, MasterCard, and Visa -- of the problem. The newspapers will turn over the card numbers of subscribers who may have been affected to the companies upon request. As of last night, Mastercard and Visa have asked for the details. The newspapers are doing the same thing with banks of customers who may be affected.

About 227,000 Globe subscribers pay by credit or bank cards, although it's unclear exactly how many had their information released. Larkin, however, said a reconstruction of the errors suggests a majority of those affected are Globe subscribers.

The newspapers have also set up a hot line, 1-888-665-2644, for customers to call to learn whether their financial information may have been distributed. As an extra precaution, newspaper officials also urged subscribers to contact their credit card companies if they are concerned about unauthorized transactions....

Ok. This is obviously a screw-up, but I'm left scratching my head about how this information went from accounting to bundling without anybody doing anything?

Technorati tags: :: :: ::

.

Tuesday, January 31, 2006

Missouri shuts down call record vendor

The Attorney General of Missouri has been successful in his effort to get a restraining order to prevent Locatecell.com from selling phone records of Missouri residents. See: Missouri Shuts Down Locatecell.com.

In related news, Verizon got a similar order from a federal judge in Trenton, NJ. See: Verizon wins injunction in privacy fight: Financial News - Yahoo! Finance.

Technorati tags: :: :: :: :: .

Australia to review privacy laws

The Attorney General of Australia has asked the Law Reform Commisison of that country to undertake a comprehensive review of the existing privacy laws, particularly with reference to changes in technology that have taken place since the existing Privacy Act became the law in 1988. See: Privacy laws to be reviewed. 01/02/2006. ABC News Online.