Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, November 27, 2007

Shakespeare on Identity Theft

On the Loss of Two CDs by Her Majesty's Revenue and Customs containing the Records of 25 Million Taxpayers and their Children.

Shall I compare thee to a string of digits?
Thou art more personal and more private.
Rough Humphreys doth quiz the Darling on Today,
And Gordon's lease hath all too short a date.
Sometime too close the eye of Google shines,
And oft is gold from banking accounts skimmed;
And every mother’s maiden name declines,
By chance, or nature's changing course untrimmed.
But thy perfect database shall not leak
Nor lose possession of that CD they sent;
Nor shall the hacker spam and phish and phreak,
When with eternal ID card thou went,
So long as cars have chips and streets have CCTV,
So long lives your identity, and this gives life to thee.


Sources: BBC News, The Register, Robin Wilton, Into the Machine.

Saturday, March 18, 2006

Network Privacy 2

Following on from my previous post on Network Privacy.

Privacy and data protection are primarily understood in terms of facts about one person. But most of the facts we are really interested in (gossip, political scandal, dastardly deeds and worse) involve more than one person.
This is particularly true if we are rigorous about including provenance. An allegation against person A by person B is a fact about B as well as a fact about A. B's credibility (and any other allegations made by B, as well as links between B and any other people making allegations against A) may be relevant to the veracity of the allegation.

(If someone made an unfounded allegation about me, I should perhaps feel slightly more comfortable if this was stored in some database as an allegation, with a defined provenance, rather than as unvarnished fact or vague probability. And I should want anyone reading the allegation to be automatically presented with my refutation as well. See my post on Google and Spin, which discusses the Prince Charles approach to news management.)

Why are we more interested in facts involving two or more people? One reason is that it is relevant to trust. If a politician has failed to disclose a loan, this may be relevant to his/her public duties. This is where there starts to be a conflict between privacy and public interest.

Where does this leave Prince Charles and his diaries? The relationship between royalty and the newspapers has often been uncomfortable. In 1908, Kaiser Wilhelm II of Germany unwisely gave an interview to the London Daily Telegraph, in which he liberally insulted half the people of Europe. Surely the people (vox populi and all that) have a right to know if the Kaiser is an ass?

Network Privacy

In his post on Social Cartography - Mapping the Electorate, Scribe reminds that it's not enough to have privacy and data protection at the individual level. We also need to consider the privacy of relationships between individuals.

There are many concerns about data protection and privacy at the individual level. (In his recent post on the Status of Privacy in the UK, Robin Wilton points out that Prince Charles used arguments based on confidentiality and copyright to protect his diaries, presumably because of a lack of adequate privacy legislation.)

But if we think about interpersonal privacy, this becomes much more complex, and raises some serious ontologicial and practical issues that privacy campaigners don't seem to be addressing. So I thought it might be useful to cross-post a few notes here.

Let's start with an incident that might be regarded as an example of breached privacy. John Major, former UK prime minister, was embarrassed by the publication of an autobiography by fellow (hrm hrm) politician Edwina Currie, in which she revealed details of a long-standing affair between them. His public response was ungracious and ungentlemanly. [BBC News, September 2002]

Privacy means that some data subject has some rights over some data.
  • What can the data subject do with the data? (e.g. publish, hide, preserve, alter, destroy)
  • What can other agents NOT do with the data? (e.g. publish, hide, preserve, alter, destroy)
  • What recompense is the data subject entitled to, in the event of any accidental or deliberate breach of these rights.
Data protection implies a set of mechanisms to support the rights of the data subject, to limit the actions of other agents, and to resolve any disputes. This raises a number of complex issues.

Ownership Who ‘owns’ the data? Does a company own the data it has collected about a person? Does a person have any ownership rights over his/her ‘own’ data? What data (if any) are governed by the principles of data protection, and what data are not so governed?
Identity There must be some reliable mechanism for matching the identity of the data subject with the identity referenced by the data. Furthermore, this mechanism should not itself represent an invasion of privacy.
Ontology Many types of data reference multiple individuals. For example, data about a secret relationship between two individuals can be understood as belonging to the pair (which is a composite data subject). However, the very existence of this pair may be part of the secret.
Collaboration If secret data belong collectively to multiple individuals, then any legitimate action over such data may require a collaboration between them. Of course, any individual named as a party to a secret relationship may seek individual recompense. It is not always clear what rights (if any) an individual has when details of a secret relationship are published unilaterally by one party.
Fiction / Libel Reports of a secret relationship may sometimes be fabricated. Standing up for one's rights against libel or slander may involve reference to a pairing that was only brought into being by the libel.

Note - these issues apply to commercial relationships between organizations, as well as to sexual relationships between consenting adults.

Technorati Tags:

Wednesday, September 07, 2005

Noticing Data Misuse

On information leakage, Bruce Schneier comments:

It's easy to say "we haven't seen any cases of fraud using our information," because there's rarely a way to tell where information comes from. ... Everyone thinks their data practices are good because there have never been any documented abuses stemming from leaks of their data and everyone is fooling themselves.

Many years ago, when I worked on some information systems for direct mail marketing, it was standard practice to include fictional entries in a mailing list, which allowed for the rapid detection of abuse. In this context, abuse generally means using the mailing list for a purpose not authorized by the mailing list owner/administrator, and/or without proper payment. The data owner has an incentive to control abuse, because abuse degrades the value of the data to the owner. The relationship between the data owner and the data user is one of provisional trust, with retrospective sanctions whenever abuses of trust come to light. This relationship works because of the detection mechanism. And the mechanism works because the data user cannot discriminate between the fictional entries and the real ones.

So why doesn't this work for the current spate of privacy violations and identity theft vulnerabilities? Assuming that the fictional entries are properly constructed. There are some technical considerations and some social considerations (including regulation), but the value of such a mechanism should be obvious.

Technorati Tags:

Thursday, July 08, 2004

Security Threats

I have received several copies of an email inviting me to download some Big Brother software, in order to keep tabs on my loved ones. (Is my spouse cheating online? Are my kids talking to dangerous people on instant messenger?)

At one level, this product claims to provide me with a mechanism to invade another person's privacy - in other words to breach the security of some system. It is therefore selling (or at least promising) a security threat. At another level, it is sold as a way of protecting me and my family from various threats - spouse or kids innocently (or not so innocently) having contacts with dubious characters via the internet. There is an interesting tension between these two levels.

But perhaps the real implied danger (apart from running up excessive phone/ISP bills) is when the contacts cease to be mediated by the Internet - e.g. online cheating leads to offsite cheating. Online cheating (whatever that may be) becomes not the primary offence/risk, but a clue towards some other offence/risk.

This illustrates a general point -- that there is a temptation (encouraged by technology) to measure and monitor what is easy to measure and monitor, even if this provides at best an indirect indication of what's really at issue.

The general point applied to trust and security is that security monitoring typically measures the wrong things. This may start with a valid observation, that there is a close correlation between X (which is the real threat) and Y (which is easy to measure). So by measuring Y, we get an indication of X. But this is vulnerable in two ways.

Firstly, the fact that X-threats are monitored via Y may leak out and become public knowledge - and therefore useless. Secondly, a determined investigator or hacker may be able to infer an internal connection between X and Y by observing (and testing) the behaviour of the system from the outside. The forced coupling between X and Y represents a simplification in behaviour, a reduction in requisite variety.

Note that indirect measurement is commonplace in quality management systems, as long as you have appropriate mechanisms to callibrate and control the metrics. Among other things, an indirect measurement may give earlier warning of an impending problem than waiting for the direct measurement. But the reasonable precautions that may be necessary and sufficient for quality management systems are grossly inadequate for security systems.

And this is not just a technological point, but a sociological one. People generally use weak and unreliable signals to make significant trust/mistrust decisions, and may flip catastrophically from blind trust to unremitting suspicion. Even in relation to their loved ones (as Shakespeare discovered).

Tuesday, May 18, 2004

Security and Warrants

In his latest newsletter, Bruce Schneier argues for the warrant as an essential (sociopolitical) control over certain security mechanisms (such as electronic surveillance).

Certain acts (for example, search or surveillance) are “security-charged”. By this I mean that these acts alter the geometry of risk for affected stakeholders. These acts are permitted under rules that are supposed to minimize the invasion of privacy while maximizing the effectiveness of crime prevention and criminal prosecution. Some of these acts (such as wire-tapping or domestic search) may require a warrant. A warrant is the authority to perform some security-charged act, granted by an independent body (such as a magistrate).

Schneier argues (and I agree with him) that if old methods of search and surveillance require a warrant, then new technological methods should also require a warrant. In other words, the rules should be expressed in technologically neutral terms, should not have technological loopholes, and should not be constantly lagging behind technological innovation.

But I have a more general concern about these security-charged acts. There is a need for a properly constituted governance function, which is much broader in powers than simply granting or denying a warrant in a particular instance. Governance has to do with setting objectives and priorities, making appropriate judgements about security trade-offs, deciding where to allocate security resources to achieve the best results with minimum social and economic cost.