Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, April 20, 2008

How criminals will benefit from the REAL ID legislation

Forgot to publish this post for some reason, just noticed today.

“State a point for or against the National ID System, or a facet thereof. Please include references in addition to the book.”



A national ID system is a system used by the government of the country to track the people in the country. It has generally consisted of a unique identifier, with the possibility of appearing on an ID card which would be issued by the government. These types of identification systems have lead to many concerns over privacy, since they often become used for more than they were intended to do. The United States currently uses the Social Security number, which when originally created, “the numbers would only be used by the Social Security Program.”, however as people realized the value of a system which has an unique identifier for all the citizens in the country, it's use began to spread. Currently the Social Security number is used for a large variety of things, from obtaining a job to applying for a credit card. A citizen without a Social Security number would have a enormous number of problems doing things that most people take for granted.



The current legislation for the REAL ID system in the United States would in effect create a new standard for a national ID. It does this by establishing a new set of guidelines for what states would have to include in drivers licenses or other identification cards. If a state does not meet these criteria, “the penalty is barring people without a REAL ID from flying and from entering any federal buildings, such as a courthouse, Social Security Administration office or the office of an elected federal official.” This is a huge infringement on state's rights. When did the federal government get the ability to decide how and who the state's will issue drivers licenses or other identification cards to?



Proponents of the legislation say that the REAL ID act say that it “is necessary to prevent terrorists, criminals, and illegal immigrants from successfully obtaining and using fraudulent driver's licenses.” however, there are no facts proving the legislation will do this.. Criminals currently still obtain legal documents that are supposed to be difficult to obtain, what makes it that much harder for them to obtain the new forms of identification? The average citizen is who this would really affect. If they lose or need to obtain a new ID for any reason, it would become much more difficult for them to do so. The new IDs would also be a prime target for identity thieves. They contain much more information about the citizen, and as proposed the information would be contained in a 2D bar code, or some other computer readable information on the card.



This also brings up the privacy concerns related to having all of your information in a central location. It is not unlikely that the new IDs would be used widely, since drivers licenses are already used in this way. Whenever you need to present identification, you would just have to let a computer scan this card. This allows easy tracking of nearly every aspect of ones life. The data centers containing the information associated with these cards would be under constant attack by identity thieves, since this would become the most centralized location of personal data anywhere. It's foolish to believe that having this information would not lead to abuse of the information. Whenever data is collected, it is always possible for a leak to occur even in the most secure facility, because someone the data now exists where someone (legitimately or not) can access it.



The benefits to having the REAL ID system in place are few and often misleading. The ease of having only one card to prove your identity is a trade-off with losses in both security and privacy. The increased security measures required would force a huge cost on the states to implement these features, which would undoubtedly never become completely secure. This just makes it harder for a normal citizen to obtain identification, while criminals would have access to these cards, giving them the benefits of this system, instead of stopping them. Some of the reasons given for enacting the bill are to fight terrorism and reduce identity theft, but there is no convincing evidence that the legislation would accomplish that, but it does increase the centralization of personal information, which is likely to attract abuse instead of prevent it.

Sunday, April 13, 2008

I would subscribe to any politician's blog who follows my idea.

Quick rant about politicians. I'm reading the article Administration Set to Use New Spy Program in U.S. on The Washington Post which was shared with me by Co-contributer Shane via Slashdot. I'll let you make your own decision about the article.

The article has a passage in it which made me think:

"There is no basis to suggest that this process is in any way insufficient to protect the privacy and civil liberties of Americans," Chertoff wrote to Reps. Bennie G. Thompson (D-Miss.) and Jane Harman (D-Calif.), chairmen of the House Homeland Security Committee and its intelligence subcommittee, respectively, in letters released yesterday.

"I think we've fully addressed anybody's concerns," Chertoff added in remarks last week to bloggers. "I think the way is now clear to stand it up and go warm on it."


I believe that what they are saying is that he said this in a conference with some bloggers. The way it is used implies he responded to all bloggers. This is wrong. I'm a blogger. If you're reading this you're a blogger. Some people dogs are bloggers. The point is everyone is a blogger. I think that politicians should be responsible for responding to everyone.

How about we make every politician write a paragraph summarizing why they are voting for every proposal they have to vote on. Let's make them bloggers too. Then they actually are talking to everyone, and they become more responsible since they actually have to show something to the general public. The only people who wouldn't want that are the politicians; but who decided they get to be in change?

Monday, March 31, 2008

Another data breach goes nearly unnoticed.

Vague topic this week, I'm under the assumption that I can basically choose anything involving ethics in computer science for this article. Link to the original assignment.

A recent incident of personal data being unintentionally released has occurred affecting 75,000 members of the public website for The Dental Network. The information contained full names, complete addresses, dates of birth, and social security numbers. This was reported by The Baltimore Sun on March 26th, 2008, even though the security breach happened February 20th, and the affected persons were informed by letter on March 10th, nearly three weeks later. Thousands of dollars in unauthorized purchases, accounts being opened and held for use at a later date, and many other illegal activities all could have happened before anyone was informed that they were at risk.

According to the Baltimore Sun: article,

“The company says that to its knowledge, no one has misused the information.”
The company has offered those who were affected 12 months of free credit monitoring, and sent information to these people on how to contact the credit bureau's and put a fraud alert on their account.
"We moved in a timely fashion to secure the data and notify the members,"
said CareFirst spokesman Michael Sullivan, but the article also mentions that
“[The information] had been posted on its Web site for two weeks in February because of a technical error.”

The Consumerist also picked up this article and added a few interesting points. They are critical of the companies offer of free credit monitoring services for a year, saying it's too short.
“Companies, is it really that expensive to offer 5 years, or 10 years, of credit monitoring to victims of your data security incompetence? Seriously, own up to your responsibility in exposing people to the risk of financial and credit problems and give them the tools they need to protect themselves. After all, it's your fault.”

This is a valid point. The company is at fault here, and the threat of identity theft due to this will not be gone in one year.

While on the website of The Dental Network, I could find no mention of the data breach, even though it is now only 3 weeks after the affected users were informed, and only 3 days after the article was picked up by The Baltimore Sun. The home page of the site is now displaying the message that:
“New Sales of Dental HMO Products Temporarily Halted in Maryland, Due to a technical issue involving the internal restructuring of The Dental Network (TDN).”

The company seems to be taking no responsibility for what has happened, instead trying to hide it away from people to attempt to maintain a semblance of security. Take a look and judge it for yourself, the website looks like it was created 10 years ago, and their policy for data integrity probably hasn't been updated since then.

It is the responsibility of The Dental Network to inform the people affected in this case. There is a state law passed in Maryland that requires businesses to respond promptly in the case of a data breach. It is my opinion that this company did not adhere to this law. The users in this case should have been given the positive right to privacy by the company, but instead it was broken, and the data was leaked. This clearly violates the ACM Code of Ethics, specifically section 1.7:
“Respect the privacy of others.”
The Dental Network should have been more diligent in securing the personal data of it's users, and much faster at noticing the breach and notifying it's users. There was a total of two weeks before the breach was noticed, and 3 more weeks before users were notified. That's 5 weeks were a potential criminal could have had access to this data. Five weeks is completely unacceptable.

UPDATE: I found the FAQ for the data breach. The data there isn't very helpful, and would likely only confuse and cause most people to ignore it. All of the information contained is about what you should do, the company seems to be doing nothing on it's own, therefore leaving the majority of people affected without any security against identity theft.

Thursday, March 27, 2008

U.S. Patriot Act causes ethical concerns for software developers

Here's the topic from the third paper:

“Pick an example from Chapter 2 or 5 and show if the people who built the software acted ethically according to Appendix A and your general sense of ethics.”


It occurs to me that I haven't noted which textbook we are using. It is A Gift of Fire, by Sara Baase, Third Edition.

Here's my paper, I tried not to include too much reference to the book, but it was needed for this assignment.

A good example of software that has been built upon questionable ethics is the software and procedures that the government uses to obtain personal information about suspected criminals.[1] “The U.S. Patriot Act, passed in the weeks after the September, 2001, terrorist attacks in the United States, gives authorities the means to secretly view personal data held by U.S. Organizations” from the article Patriot Act haunts Google service on www.theglobeandmail.com. This law conflicts with many other government's privacy laws, which require organizations to protect all private information, and also require that the consumer is informed when this information is obtained, regardless of the process, by a third party. According to the Software Engineering Code of Ethics and Professional Practice (Version 5.2) section 1.04 Software engineers shall, as appropriate “Disclose to appropriate persons or authorities any actual or potential danger to the user, the public, or the environment, that they reasonably believe to be associated with software or related documents.” It is my argument that the U.S. Patriot Act causes the potential threat of private data being obtained by an outside party, in this case, the U.S. government, and that this causes an ethical dilemma for software developers, specifically in the U.S.

Some people have recently noted effects of the law. In the recent article posted on www.theglobeandmail.com, and also covered on boingboing.net, there is a discussion of how the U.S. Patriot Act affects the use of Gmail, specifically in countries outside of the U.S. The information obtained by Google when a user uses Gmail can legally be reviewed by the U.S. government under loose controls. Not only is the ethicalness of the U.S. Patriot Act in the regards to privacy put into question, but it also causes an ethical dilemma for software developers. If the government can obtain personal information about someone without a warrant, is it ethical for a software company to keep data about you without informing you of the potential breach of privacy? A well defined privacy policy such as Google's are likely to provide a clause for this situation, such as “We may also share information with third parties in limited circumstances, including when complying with legal process, preventing fraud or imminent harm, and ensuring the security of our network and services.” It is my opinion that privacy policies are created to protect the organization, instead of to protect the end user.

Many people would argue that the privacy policy is a solution to the ethical issues prevented here, but I do not think that it provides a full solution. The majority of users will never read a privacy policy, and of those that do, many of them will not understand the complete implications of it. It's likely the privacy policy misses some small detail that is important to the user, or some situation that the writer completely overlooked. It would be nearly impossible for the writer to know the complete set of laws that govern their organization, especially with the recent globalization of Internet based companies. How far do you have to go in informing the end user of possible dangers of using the service for you to have done what can be considered ethical?

Unfortunately, I don't have a solution to this problem. Ethical guidelines dictate that you should inform the end user of all potential danger to them, and breaches of privacy clearly fall in this category. However, “because no matter what promises companies make (or what privacy laws Congress might enact), data leaks happen.”, so maybe that should be taken into account when writing up a privacy policy. If there is a distinct possibility of a third party obtaining a user's personal data without the permission of that user, the software developer should make this information apparent to all of it's users. It doesn't matter if the third party is a government, or someone malicious looking to steal your identity, it still constitutes a breach of privacy, and the user needs to be informed.