Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

February 16, 2008

The Anonymity Experiment

A Popular Science writer spends a week staying anonymous in the digital age: paying cash, dodging surveillance cameras and using disposable cellphones.

November 22, 2007

WSJ: Home invasions target wealthy

The Wall Street Journal reports that the higher-profile rich are being targeted for home invasion robberies:

One reason for the rise in home invasions is demographic: The numbers of rich people with homes to plunder has risen fast in recent years. But police and security experts say robbers are hitting homes more because their traditional targets -- banks, stores and offices -- have been hardened with closed-circuit video surveillance, alarms and guards. By comparison, security at many private homes remains lax, they say.

Increasingly, wealthy and high-profile individuals must step up security at home and be vigilant in their cars to avoid becoming victims, security experts and police say. They may also need to reduce the amount of information they reveal about themselves on the Internet in places like Facebook, and in the media. And perhaps most importantly, they should thoroughly investigate the background of anyone who has access to their home, because many robberies are inside jobs.
Several security and alarm experts say crimes like these can be prevented with a perimeter motion-detection system that sounds whenever someone drives or walks onto a property. Many alarm systems wire only the doors and windows of a home; the problem with that, security experts say, is that by the time someone trips the alarm, it can be too late. Moreover, any alarm system has to be armed to work, and often, they aren't.


Home-invasion robbers also pick their victims by staking them out in public and following them home.

Police and security experts say that to avoid this type of robbery, people should be alert to whether they are being followed before driving onto their property, and if they are, to call the police or drive to a police station. Houses should be well-lighted with automatic exterior lights. Additionally, security experts advise clients to avoid drawing attention to money and possessions while they're out and about. They also recommend reducing the amount of detailed personal information that can be found on the Web.

While at home, it is a mistake to open the door without verifying the identity of a visitor first and to accept unscheduled deliveries. Security experts say homes should be equipped with a voice-video intercom system with cameras trained on the doors and the grounds, and deliveries should be sent to a post-office box or family office instead of to the residence.

February 9, 2007

Laptop data searches at border checks

U.S. courts have approved border agents' search of traveler's laptops without articulable probable cause.

Indications are that U.S. and Candian customs officials are searching laptops for pornography and obscene material.

Some travelers report being asked if the laptop they were carrying was a personal or company unit. Presumably, corporate laptops are less likely to be checked for obscene material than personal units are.

Authorities also have the ability to conduct forensic computer searches at border crossings and have done so in the past.

Data transmitted across national borders via the Internet is more strongly protected than data hand-carried through Customs checkpoints, because wiretaps must comply with the requirements of Title III, 18 U.S.C. §§ 2510-2522, or the Pen/Trap statute, 18 U.S.C. §§ 3121-3127. The few advantages of hand-carry are totally lost if one cannot be assured that the data hasn't been copied, or that software or hardware spying mechanisms haven't been implanted within it.

Travelers with sensitive or legally privileged data will want to Customs-proof their laptop before crossing a controlled border. Strong encryption is the best tool to protect data that must be hand-carried through Customs instead of residing on a remote server. Some organizational IT departments are investigating hardware hard-disk encryption, sometimes combined with hardware biometric readers.

It is unclear at this time whether a traveler can be forced to divulge a password. One privacy wonk has suggested wearable or concealable USB drives as a measure of protection.

February 3, 2007

The power of data mining

An exercise in finding subversives through Amazon.com wishlists illustrates the power of data mining:


It used to be you had to get a warrant to monitor a person or a group of people. Today, it is increasingly easy to monitor ideas. And then track them back to people. Most of us don't have access to the databases, software, or computing power of the NSA, FBI, and other government agencies. But an individual with access to the internet can still develop a fairly sophisticated profile of hundreds of thousands of U.S. citizens using free and publicly available resources. Here's an example.

There are many websites and databases that could be used for this project, but few things tell you as much about a person as the books he chooses to read. Isn't that why the Patriot Act specifically requires libraries to release information on who's reading what? For this reason, I chose to focus on the information contained in the popular Amazon wishlists.

January 5, 2007

Medical Identity Theft

From the January 8, 2007 issue of Businessweek, an article about medical identity theft and health care databases:


But some privacy advocates fear that the rush toward digital health records could ironically create new nightmares for victims of medical ID theft. Rather than residing in a single doctor's paper files, fraudulent information—such as the erroneous diabetes diagnosis in Lind Weaver's records—could circulate in other medical databases across the country. Given that some medical ID thefts are "inside jobs," wherein rogue clerks sell patient data to fraudsters on the outside, privacy advocates believe that allowing data to flow more freely around a national network could make such thefts even easier. "We can expect [medical ID theft] to grow the more we move toward an electronic health-care system. It's going to be a disaster," says Dr. Deborah Peel, an Austin (Tex.) psychiatrist and founder of the Patient Privacy Rights Foundation.


...but, as usual, the weakest link is usually a human:


In September, federal authorities arrested a scheduling clerk at the Cleveland Clinic's Weston (Fla.) hospital who allegedly had passed on the personal identification information of more than 1,100 patients to her cousin—who in turn submitted $2.8 million in false claims to Medicare. "Hospitals have done a poor job of implementing security procedures on their computer systems," says one federal investigator. "You'd be astonished how many people have access to your medical records."

January 1, 2007

The Value of Privacy

Cryptographer Bruce Schneier on the value of privacy:


Cardinal Richelieu understood the value of surveillance when he famously said, "If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged." Watch someone long enough, and you'll find something to arrest -- or just blackmail -- with. Privacy is important because without it, surveillance information will be abused: to peep, to sell to marketers and to spy on political enemies -- whoever they happen to be at the time.