Archive

Posts Tagged ‘Bruce Schneier’

On Data and Disclosure

December 15th, 2009

I like to think about ways to customize my world, and the digital world writ large, in ways that support and help us explore our unique selves. It is in our very diversity that individual strengths can play out to become our personal best, to help each other grow, and create fertile new worlds.

However, under the guise of “increased security,” we are increasingly surrounded by tools and technologies that minimize and standardize us, including video surveillance and data storage and analysis. About that last link to Google, CEO Eric Schmidt recently said “If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place.

This indiscriminate personal data hoarding is both an individual and a societal problem. Schmidt’s argument that we shouldn’t have anything to hide is specious (not to mention a double standard: it doesn’t apply to Schmidt). In a 2007 paper called ‘I’ve Got Nothing to Hide’ and Other Misunderstandings of Privacy, George Washington University Law School’s Daniel J. Solove convincingly critiques that argument. Indeed we have many things to hide, like our passwords and credit card numbers, certain personal habits and preferences, things that contribute to human dignity and respect. As noted security expert Bruce Schneier writes in his essay The Eternal Value of Privacy, “Too many wrongly characterize the debate as “security versus privacy.” The real choice is liberty versus control.”

Ironically, Gary Wolf and Kevin Kelly host a blog called The Quantified Self where they report about people exploring ways to keep track of themselves. It’s a significant difference between curiosity, personal need, and voluntary disclosure that’s driving data sets, and corporate ventures like Facebook (nod to jerking you around again with recent privacy policy changes), Google (Schneier’s response to Schmidt’s quote above), and damned near every corporate site you make an account with and that tracks your every move these days.

I’m looking for examples of sites that encourage liberty and demonstrate some respect for its users/clients. I will be reporting on what I find. If you have suggestions, I welcome them.

Coaching moment: Here’s a little thought exercise. Think about a typical day in your life.

What kind of things do you do in private? These might be taking a shower, brushing your teeth, thinking about the day. Some things might be really private as in just you by yourself, and other things may be private in some context, like thinking about your day out loud with your spouse or partner. Once you get a good list, which of those things would make you uncomfortable if they were made public in some way?

Now think of the kind of things you do in public, like driving to work or the store, walking around, having a conversation over lunch. Think about stories that might be told about you from the perspective of not knowing what you were really doing. You might take clues from signs that you walk by, or maybe other people (posture, groupings, facial expressions). Can you think of any stories that are not only wrong but might hurt you?

Finally, think about your online tools. Have you actually looked at the Terms of Service or Privacy Policies that you’re agreeing to? If you knew they were disrespectful to you or even abusive of your personal self and liberty, would you stop using them? Since the answer is “probably not,” what would you suggest these companies change?

friends/family, future, history, records, tools , , , , , , , , , , , , , , , , ,

Getting to know you

August 20th, 2009

National ID cards and programs are problematic at best, and an ongoing nightmare for citizens and visitors alike when the programs are poorly designed. The U.S. government has made earlier attempts at developing such a program, which have failed. However, the dream lives on in the minds of certain government officials and representatives.

The Electronic Frontier Foundation (EFF) has been following these efforts for years. EFF’s Richard Esguerra has a post, PASS ID: REAL ID Reanimated that offers an informed look at the latest effort to create the next version of a national identity card.

The PASS ID Act (S. 1261) seeks to make many of the same ineffectual, dangerous changes the REAL ID Act attempted to impose. Fundamentally, PASS ID operates on the same flawed premise of REAL ID — that requiring various “identity documents” (and storing that information in databases for later access) will magically make state drivers’ licenses more legitimate, which will in turn improve national security.

An ID card is only a small part of the picture. The government program that supports the card is where the devils live. I recommend to you Bruce Schneier’s testimony to the Senate on why this whole idea is seriously flawed.

Coaching moment: Have you ever filled out a form for a new service, at a web site or store, where the form asked for information that they might not have needed for the transaction you were seeking? Long forms that ask a lot of questions about you, your preferences, your income, and other personal information, are unnecessary. If you’re just buying something, why might the vendor need your income, your birthdate, or any information about other family members?

The fact is that they often don’t need it. They’re collecting information about you because they can, and because you might volunteer it. Even when certain information is marked as “required,” it might be in your best interest to think twice about doing business with companies that would be so invasive and demanding.

Treat your personal information on a “need to know” basis. What that means is don’t give out more information about yourself than you think the companies need to know in order to carry out the transaction. If the company or form require more information than you’re comfortable giving, think hard about your future well-being as a trade-off for today’s discount. Your mindfulness is a low-cost insurance on your future.

friends/family, future, history, records , , , , , , , , , , , , , , , , ,

Data Privacy Day 2009

January 16th, 2009

Do you have a friend like this?

A group of organizations, including Intel, the International Association of Privacy Professionals, the Office of the Information and Privacy Commissioner of Ontario, several universities and government agencies, the European Commission, and lots more, have announced the second Data Privacy Day.

On January 28, 2009, the United States, Canada, and 27 European countries will celebrate Data Privacy Day together for the second time.

Designed to raise awareness and generate discussion about data privacy practices and rights, Data Privacy Day activities in the United States have included privacy professionals, corporations, government officials, and representatives, academics, and students across the country.

One of the primary goals of Data Privacy Day is to promote privacy awareness and education among teens across the United States. Data Privacy Day also serves the important purpose of furthering international collaboration and cooperation around privacy issues.

I wrote a post called Take Back Your Self that talks about why the concept of a digital self, or identity, is important to protect. I strongly support the passage of a comprehensive data privacy law, as described in Bruce Schneier’s article. But before we can get a draft for a new law going, we need to encourage a better understanding of what digital identity is all about, and why it matters to protect it.

Take a look at some of the resources available on this page to see if there is anything you can share. I’ll be blogging more as we get closer to Data Privacy Day 2009.

records, tools , , , , , , , , , , , , , , , , ,

Take Back Your Self

January 7th, 2009

On my Identities Overview page, I talk about the different forms of identities that we have. One of those forms is a digital you: the email and online accounts that you have, the mailing lists and databases that you’re part of. In reality, much of this identity reaches into our other identity forms, such as our economic profile and our citizenship.

Renowned security expert Bruce Schneier wrote an essay last May 15, 2008, called Our Data, Ourselves. In it he pointed out that:

Who controls our data controls our lives.

It’s true. Whoever controls our data can decide whether we can get a bank loan, on an airplane or into a country. Or what sort of discount we get from a merchant, or even how we’re treated by customer support. A potential employer can, illegally in the U.S., examine our medical data and decide whether or not to offer us a job. The police can mine our data and decide whether or not we’re a terrorist risk. If a criminal can get hold of enough of our data, he can open credit cards in our names, siphon money out of our investment accounts, even sell our property. Identity theft is the ultimate proof that control of our data means control of our life.

We need to take back our data.

Our data is a part of us. It’s intimate and personal, and we have basic rights to it. It should be protected from unwanted touch.

Schneier calls for the passage of a comprehensive data privacy law with real penalties for violations. I’m all for this, and given our new administration’s commitment to expanding broadband in America, it’s time to start talking about this now.

Coaching Moment: Recently many people on Twitter were stung by a series of “click here” phishing attempts to take over their accounts. One third-party company collected many twitter usernames and passwords while offering a momentarily helpful service, but then turned around and sold his database for a reported $1200. On a higher but related level, financial identity theft is (still) on the rise.

I hope you have not been a victim. Chances are increasing that you will be. What concerns you the most about losing your privacy or control over your digital destiny? I’d love to know.

future, records, tools , , , , , , , , , ,

A Transparent Society

January 3rd, 2009

Back in 1999, David Brin released a book called The Transparent Society: Will Technology Force Us to Choose Between Privacy and Freedom? Many of my friends and I thought that it was perhaps a bit alarmist, but I’ll admit that I had rosy glasses on then. I thought that it was still possible to right the wrongs that technology was imposing and allowing.

Fast forward to September 2007, when Law Professor and privacy activist Michael Geist was giving the closing talk at an International Privacy conference.

There’s no stopping it: we are increasingly living in a transparent society.

Coaching moment: In the book and in the video, both men talk about leaving fingerprints behind and being tracked by surveillance cameras and databases, and the consequent changes that this activity entails. On a personal level, many of us are uncomfortable with this level of involuntary disclosure. It’s as if we suddenly had a digital firefly attached to us.

On one hand, if everything and everyone is being tracked, who will have time to make sense of it all? On the other hand, we are quickly developing the computing power to visualize all kinds of activities and behaviors. It’s only when the tracking is focused on one single person that it becomes troublesome.

What would you do differently if you knew you were always being watched?

UPDATE: There’s an important essay written by noted security expert Bruce Schneier called The Myth of the “Transparent Society” that is a must read for everyone that thinks that increasing transparency is alright. The problem at its core is the imbalance of power between the disclosing and using parties.

future, records , , , , , , , , , , ,

Switch to our mobile site