Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Tuesday, November 27, 2007

Shakespeare on Identity Theft

On the Loss of Two CDs by Her Majesty's Revenue and Customs containing the Records of 25 Million Taxpayers and their Children.

Shall I compare thee to a string of digits?
Thou art more personal and more private.
Rough Humphreys doth quiz the Darling on Today,
And Gordon's lease hath all too short a date.
Sometime too close the eye of Google shines,
And oft is gold from banking accounts skimmed;
And every mother’s maiden name declines,
By chance, or nature's changing course untrimmed.
But thy perfect database shall not leak
Nor lose possession of that CD they sent;
Nor shall the hacker spam and phish and phreak,
When with eternal ID card thou went,
So long as cars have chips and streets have CCTV,
So long lives your identity, and this gives life to thee.


Sources: BBC News, The Register, Robin Wilton, Into the Machine.

Wednesday, July 05, 2006

Protection and Resistance

Adam Shostack notes that business tactics can sometimes be compared to the mafia.
  • Identity Theft Protection (Eric Rescorla). "That's a great credit rating you've got there ... shame if anything happened to it" (Adam).
And legitimate business services can be used by the mafia.
  • Mexican kidnappers are in league with the insurance companies (Tyler Cowen). Columbian kidnappers pull your credit file from the credit agency to calculate optimum ransom (Alex Tabarrok).
Does this mean that some structural similarity with the mafia should be sufficient to reject some business innovation?
  • Net Neutrality. "FedEx would never suggest intentionally losing your packages. They also would never suggest tearing them open to see if there’s anything good inside. But Verizon and Comcast and a number of other broadband providers are gleefully declaring their intent to drop your traffic, starting with whatever you consider most valuable. This, they call "innovation". (Dan Kaminsky).
Many stakeholders clearly regard arguments against network neutrality, or proposals that undermine network neutrality, as a form of bad faith. For example, telecoms analyst Martin Geddes argues eloquently against network neutrality, tells his readers You Won't Like This, Not One Bit, and is rewarded with the following comment: "There is a special place in jail for people like you".

Of course it's natural to be suspicious of change. Even if the old Internet model was a myth, people may regard any kind of innovation as a breach of trust.

It't not easy to decide which innovations to trust. While superficial similarities to mafia practice make good rhetoric, they may not be the best basis for trust decisions.

Technorati Tags:

Wednesday, September 07, 2005

Noticing Data Misuse

On information leakage, Bruce Schneier comments:

It's easy to say "we haven't seen any cases of fraud using our information," because there's rarely a way to tell where information comes from. ... Everyone thinks their data practices are good because there have never been any documented abuses stemming from leaks of their data and everyone is fooling themselves.

Many years ago, when I worked on some information systems for direct mail marketing, it was standard practice to include fictional entries in a mailing list, which allowed for the rapid detection of abuse. In this context, abuse generally means using the mailing list for a purpose not authorized by the mailing list owner/administrator, and/or without proper payment. The data owner has an incentive to control abuse, because abuse degrades the value of the data to the owner. The relationship between the data owner and the data user is one of provisional trust, with retrospective sanctions whenever abuses of trust come to light. This relationship works because of the detection mechanism. And the mechanism works because the data user cannot discriminate between the fictional entries and the real ones.

So why doesn't this work for the current spate of privacy violations and identity theft vulnerabilities? Assuming that the fictional entries are properly constructed. There are some technical considerations and some social considerations (including regulation), but the value of such a mechanism should be obvious.

Technorati Tags:

Thursday, March 31, 2005

Berufsverbot

Adam Shostack rails against the Kafka-esque implementation of "watch lists" in the United States and cites the sad case of Juan Carlos Merida, who is apparently barred from his job because his name appears on a watch list. Note: this can happen as an accidental result of innocent association with not-so-innocent people, or as a result of identity theft (including biometric impersonation).

(With a combination of identity theft, false accusation and other tricks, it may be possible to get anyone blacklisted. Ruin their career for a few years, while they get investigated to death. If you cover your tracks properly, it can never be traced back to you. I understand this happened a lot in the United States during the McCarthy years.)

Michael Froomkin points out an interesting twist to the Juan Carlos Merida case. As part of his campaign to restore his good name, Merida was persuaded to provide confidential information on fellow students. (In a police state, this process is known as denunciation.) From one perspective, Merida's willingness to do this demonstrates that he is trustworthy; from another perspective it demonstrates the exact opposite. (Veiled Chameleon makes this comment on Michael's blog.) Meanwhile, Merida's good name remains unrestored.

The only way for the people to fight against a police state is by collective action. If everyone is on the watch list, then it ceases to be of any significance. But to deliberately get yourself onto the blacklist? Foolhardy unless everyone else does the same thing. Complex trust issues here.

More on no-fly lists.
More on identity theft and biometric impersonation/repudiation.