Thursday, March 28, 2013

Extending CALEA to Cover the Cloud?

There is a great discussion over on Slate about how the FBI sees it's ability to listen in via tapping phones as "going dark".  Why use a landline or a cell phone when you can use your webcam to orchestrate your criminal enterprises?

http://www.slate.com/blogs/future_tense/2013/03/26/andrew_weissmann_fbi_wants_real_time_gmail_dropbox_spying_power.html

The blog suggests that the FBI is interested in extending CALEA, the Communications Assistance for Law Enforcement Act, to cover Gmail, Google Voice, and other cloud services.  This isn't a new thing exactly.  Law enforcement has been working for some time now to figure out how to apply CALEA to VoIP, for example.  It was only a matter of time before Instant Messaging fell under that same category.

Kids today prefer texting to talking anyway.

Monday, March 18, 2013

Judicial Revolt Against Invasions of Privacy

Last week saw two major Judicial decisions related to privacy come out of the 9th Circuit, perhaps signaling a new offensive against warrantless wiretapping.

First, a Federal Appeals court ruled that customs agents no longer have carte blanche to search electronic devices coming into the country.  The 9th Circuit decision has an impact on border crossings into California and Arizona.  That doesn't mean that Texas or New Mexico will follow the same rules. The case comes from a California man who was flagged by agents because of prior convictions for child molestation.  Agents found no incriminating evidence on his two laptops or three digital cameras, so they seized them and sent them away to a forensic lab.  Pictures of pornographic pictures of children were allegedly found by the forensic team, but the judge threw the evidence out because the devices were removed from the border area.  The 3 judge appeals panel upheld the ruling.


On Friday,  another Federal judge ruled that National Security Letters are an unconstitutional ban on companies First Amendment rights in the case of a telecommunications company that sought to fight the gag order.  The court refused to conform the order, as the 2nd Circuit did in a prior case.

The battle in the courts over the balance between law enforcement and privacy continues.  The Supreme Court last year rejected the case against warrantless wiretapping, but did so on the grounds that the individuals being tapped couldn't prove that their communications had been monitored.  If the gag order on NSLs is removed, then it's possible that a new case could go before the Supreme Court for them do decide whether the Executive Branch has the authority to issue NSLs without judicial review.

Thursday, March 14, 2013

Privacy, Customs, and You

If you are travelling to Mexico and you are a technophile, good news!  The 9th Circuit now says that Customs agents no longer have carte blanche to search your devices.

See more from the Wired article:

http://www.wired.com/threatlevel/2013/03/gadget-border-searches/

The 9th Circuit decision has an impact on border crossings into California and Arizona.  That doesn't mean that Texas or New Mexico will follow the same rules. 

Monday, March 11, 2013

Was Aaron Swartz the victim of Prosecutorial Overreach?

After Aaron Swartz's tragic death in 2012, a lot of bloggers have started throwing around the term, Prosecutorial Overreach when talking about Federal prosecutors Carmen Ortiz or Stephen Heymann.  The problem is that this is a new term, invented seemingly out of nowhere in 2012.  It sounds like legalese, but it isn't a Legal term.  It sounds like one.  It sounds very similar to Prosecutorial Misconduct, which is a Legal term…this is what the prosecutor of the Duke Lacross case was found guilty of when he withheld evidence from the defense.

Unfortunately, since Prosecutorial Overreach isn't a Legal term, people can use it in ways that they can't use Legal terms.  People can say that the Prosecutor in this case is guilty of Prosecutorial Overreach.  Usually, when we have a legal charge against someone, you say they are accused of, not guilty of, until they are tried in court. 

So what does Prosecutorial Overreach really mean?  Here are some possible definitions:
  • When a prosecutor should have better things to do, but spends their time going after small fish.
  • When a prosecutor throws a bunch of charges at a person that are frivolous.
  • When a prosecutor goes after a case for purely political or career motivated reasons.
Unfortunately, it's not clear what people are actually saying when they use this new term.  There are protections built into the legal system from an overzealous prosecutor bringing frivolous charges against someone…in the Swartz case, this was the Grand Jury.  In this case, the grand jury indictment was unsealed, and it showed that a jury of 24 of Swartz's peers found that there was enough evidence to proceed with further legal action against him.

The danger of this term, Prosecutorial Overreach, is that it is a distraction from the battle that Swartz was fighting: The fight against copyright that didn't serve the interests of the public or the academic community.

Thursday, March 7, 2013

Pentagon to use Nukes against Hackers?

What's the latest weapon in the Cyber Arms race?  Nuclear bombs, apparently.

http://www.acq.osd.mil/dsb/reports/ResilientMilitarySystems.CyberThreat.pdf

Okay, let's not over react.  The report says that the U.S. would only use nukes under extreme circumstances.  Hopefully that doesn't mean viagra related SPAM.

Seems like, if anything, maybe an EMP would be a better alternative?

Tuesday, March 5, 2013

Privacy is Dead: Now Where's My Inheritance - Part 3



As an American, when I picture the beginnings of civilization, I don't picture Neanderthals huddling together in caves.  I picture the pilgrims landing on foreign soil, building log cabins to sustain themselves against the winter.  With the hope of a new frontier to explore.

It strikes me that we are in the same position when it comes to the Internet.  It's a wild and dangerous frontier that can hold vast wealth or the dangers of identity theft.  In Part 1 of Privacy is Dead: Now Where's MyInheritance, I postulated that an individual's privacy is worth up to $10,000 per year.  In Part 2, I broke down each category of privacy related data and discussed how each area is important to the individual's privacy as a whole.

Individuals, however, aren't the only ones venturing out into this new frontier.  The question is, how can companies benefit from the same benefits to sharing private information as individuals?

Some companies have built sharing the personal data of their customers into their business plan.  Google does this through advertising.  Facebook benefits through the network effect: the more people and the more content, the more valuable they are.  In fact, any of the 10 domains of "Privacy Property" I identified in Part 1 could be integrated into a company's business plan.

What's interesting is that companies can reap similar benefits when they are willing to share information about themselves.  This is a little counter-intuitive, but most organizations are already doing this without knowing it.  For example, when a Microsoft or Apple program crashes, the first thing it does is ask you if you want to share information about the crash with Microsoft or Apple in order to fix the program.  The benefit is that the individual gets a better, more stable version of software.

Security Through Obscurity vs. Security Through Community

Security Through Obscurity is an old concept.  The idea is that you can protect the security of your software by keeping the source code secret.  The idea is a tried and tested human concept.  Think of buried treasure.  A more contemporary example would be a company's trade secrets, the secret formula to Coca Cola or the Colonel's 11 herbs and spices.  It makes sense to businesses to keep their code secret because that what every other part of the business already does.

The problem with this concept is that every day, thousands of evil hackers are looking for vulnerabilities.  Code sometimes gets leaked.  Code can be reverse engineered.  Sometimes vulnerabilities can be found without knowing the code at all.  If security through obscurity worked, then zero-day vulnerabilities wouldn't be worth hundreds of thousands of dollars on the black market.  Worse for businesses that use the software, no one knows when zero-days are found until high enough profile breaches occur because of them.

Another model is Open Source software, where thousands of good programmers have the ability to look at the code and clean the vulnerabilities more quickly.  And there are a lot more good programmers out there than ones willing to commit crimes.  To borrow a phrase from the U.S. Supreme Court Justice Brandeis, "Sunlight is the best disinfectant."  (Brandeis, coincidentally, is also the father of U.S. privacy law.) 

Companies like BrightCloud and FireEye are creating a market by collecting data about customer’s security related information.  BrightCloud and FireEye both gather user data in order to provide a reputation score for IP addresses, web sites, or even specific files.  FireEye, for example, will take a file and load it into their cloud based sandbox to observe whether the file contains malware.  Subscribers to the service will all then share the benefits of having shared that information with the community through fewer malware infections.  These services have the potential to save businesses hundreds of hours of time to clean infected machines and lost productivity time from employees.

Similarly, telecommunications providers like AT&T or Verizon, and to some extent managed security providers have the ability to correlate attacks against all of their customers.  These providers have the visibility to see attacks in real time against thousands of their customers.  Managed Security Providers can then prevent attacks from even entering their customer's networks.  This can help reduce the costs of bandwidth and loss of reputation with customers.

Organizations can also partner with other organizations in their industry in order to directly share their information about security.  Most large organizations have an Information Security Advisory Council internally that will help report security threats, help refine policies, etc.  Many industries have adopted Councils of trusted practitioners who can share information across companies, even competitors, because sharing information about threats protects the industry as a whole.  The Payment Card Industry Security Standards Council is an example of this.   The Department of Homeland Security has a CISO Council for Federal security leaders.  The Banking industry has the Financial Services Information Sharing and Analysis Center.  The Power, Communications, Nuclear, Water, State, Public Transportation sectors all have their own ISACs as well.  There's even an ISAC of ISACs.

Security through Community is still immature, however, but the next big thing in security may come from this concept.  Just like with Anti-Virus, which many companies now offer for free when they used to be expensive add-ons, these services should also be free.  Today, all of the communities mentioned above require some cost to join, and most are very expensive.  It is precisely the network effect of having huge numbers of customers that makes these communities have value.  Cost is a barrier to entry, especially for a service that requires your private information to exist.  Imagine if Facebook asked people to pay for their service?

In part 1, I postulated that to an individual, sharing private information could be worth $10,000 per year.  It is more difficult to measure, but sharing some private data could be worth a lot more.

Friday, February 22, 2013

Diplomatic Immunity

The White House this week released a plan to stop state sponsored hacking, like the one uncovered by Mandiant this week, through the use of diplomatic pressure.  The 72 page report details the measures that the White House is willing to use as leverage.  The strategy stops short of threatening economic or other types of sanctions.

No word yet from the hackers on whether they will lay down their compilers.  A more likely response will be that they install malware into the PDF of the report.  Sorry if you already clicked the link.  I can picture the hackers learning to say "Diplomatic Immunity" a la Lethal Weapon 2.

Wednesday, February 20, 2013

Privacy is Dead: Now Where's My Inheritance - Part 2

In Part 1 of my Post, Privacy is Dead, I estimated that giving up Privacy in exchange for a number of benefits could be worth as much as $10,000 per year to an individual.  While this isn't pocket change for most of us, for someone making minimum wage, this might represent 6 months of work.  Let's take a deeper dive in where that $10,000 number is coming from.

Privacy Property

Why should a company, either your phone company or a bank, be able to share information about you?  Because it creates a new type of property…Privacy Property is the new Intellectual Property.  Google and Facebook have both been very successful at leveraging this Privacy Property to create a new source of wealth.  And we welcome it for the same reasons that we wanted credit scores.  There are scores of new types of Privacy Property that have been created in the last 10 years, and some that have been made even more valuable.
  • Credit – $2,000/yr to $4,000/yr – Today, the average American has approximately $200,000 in debt between mortgages, cars, student loans, and credit cards.  Just one percentage point of difference on a loan could mean thousands of dollars per year in value that this sharing of private information creates.
  • Book Reading – $100/yr – Librarians have a long tradition of protecting what books their patrons are reading.  They’ve fought and won to protect the FBI or other groups from being able to find out who checked out books like “Mein Kampf”.  As it turns out, perhaps that fight was all for nothing.  With eBooks, retailers like Amazon and Barnes and Noble have the ability to not just track what books you have read, but they can provide detailed demographics back to the publishers, who in turn can use this information to tailor books at their audiences.  In addition, they can figure out things that were impossible before, like what pages or passages were most bookmarked, what chapter caused people to lose interest and stop reading.
  • TV Viewing habits – $500/yr – Arthur C. Nielsen created a company starting in the 1950s that tracked what television programs their subscribers watched.  Subscribers were paid for this information.  Today, this information can be gained without special tracking equipment.  TiVo has the ability to not only track what we watch, but how we watch it…which became especially clear when they reported that Janet Jackson’s wardrobe malfunction during the 2008 Super Bowl was the most replayed video ever.
  • Driving History – $100/yr to $1,000/yr – For years, Insurance companies have used driving history to help underwrite their insurance practices.  Today, they have begun using “black boxes” to track how their customers are driving, whether they stop or speed, where they drive and when they drive.  Their customers love this, because they can save hundreds or thousands of dollars per year.  Loss of privacy creates value.
  • Shopping Habits – $1,000/yr – For years, advertisers have tried to figure out what makes a shopper tick.  Now they don’t have to.  Companies like Amazon can figure out what you will like before you know it.
  • Video Rental – $500/yr – Your movie watching history is critical to figuring out what you’ll want to watch next.  Netflix has come up with their own algorithms that can predict better than their competitors what movies you want to watch.  If they know what you want, the more likely you are to buy it, and buy it from them.  The next Step for Netflix and Hulu, Blockbuster, Amazon, and others is to let you tell your friends about the great movie you just watched…but to do that in an automated fashion, they need to get Congress to change the VPPA.  Oh, wait, Congress just passed that in January of 2013!  Welcome to the future!
  • Location Information – $1,000/yr – Today, Google will customize your search results based on where you are, so you get results in your city, not just anywhere in the US. Your location information can be used to better target advertising to you.  This was naturally the case when television advertisers bought airtime based on the region you lived in.  Google already knows where you are generally based on your IP address, mobile technologies take this a step further.
  • Change of Life Predictors – $500/yr – Today, Credit Card companies know enough about your daily habits that they can predict, for example, when you are going to get divorced or have children.  Not that those two things are related.  These major life events can have a large impact on your risk profile, perhaps reducing or increasing your credit rating profile.
  • Health Records – $1,000/yr HIPAA was originally enacted, not because of Privacy concerns, but because there was a need to move from paper health records to electronic ones.  Just like any other business, this was cost driven.  Electronic insurance claims processing has helped reduce health care costs.  Just imagine how much more expensive health care would be with only paper records.  The future is complicated.  Should individuals who smoke or drink have to pay more for health care?  Your employer says yes!
  • Free Stuff – $1,000/yr – Remember in the early 2000’s when you could get free Internet Access or even a free computer if you signed up for a service that would display a constant stream of advertising to you?  It’s possible in the future that a clever company could provide you a cellular smart phone for free with no monthly fees.  All you have to do is let it track your every move, pop up location based advertising wherever you go.  Let it show you ads based on what you say in text messages just like how Google advertises in their mail.  Sell your driving habits to insurance companies without the need for a black box.
Privacy Property is great when you live in a country where you aren’t worried about government persecution.  It becomes dangerous if this can be used against you.  Because of their history, this is why European countries consider Privacy a “fundamental human right”.  Other countries with repressive control generally snoop on Facebook posts or text messages in order to suppress the flow of information.  There is a high “Privacy Inheritance Tax” that can wipe out any benefit, and perhaps cost people more than their money.  And just like with other violations of privacy, oversharing can enable stalking, which is why Congress is considering passing Location privacy rules.  In December of 2012, the Senate Judiciary Committee voted in favor of Sen. Al Franken’s (D-Minn) Location Privacy Protection Act.
Facebook’s Chief of Privacy was quoted as saying that they are working to get rid of surprises.  That seems to address privacy issues…so long as people aren’t surprised by what they are sharing, then it’s okay.  As long as we’re getting our Inheritance, we’re happy.  Hopefully we don’t find ourselves cut out of the will.

Monday, February 18, 2013

Privacy is Dead: Now where's my Inheritance - Part 1

Privacy is Dead.
It’s not the first time you’ve heard this, surely.  A private investigator, Sam Rambam was quoted as saying “Privacy is Dead – Get Over it” in 2006.  In 2012, Huffing Post contributor Miles Feldman posed the question “Is Privacy Dead?”
If it is, then we’ve been collecting our inheritance without knowing it for years.
When did it die?  It seemed to have contracted some terminal illness sometime around the same time that the computer was invented.  It slipped away in the night somehow without anyone noticing.  People worry about privacy related to the Internet, but this was only the first time we noticed that our attitudes about privacy were changing.  There were two major events that most likely started this – the first was the Phone Book and the second was your credit rating.
When the telephone was first invented, people needed a way of reaching each other…in order to make the device useful, operators would connect two people to each other.  This was a costly way of doing business, so phone companies published subscriber information in a “Book” so that subscribers could directly connect with one another without human intervention. In this way, we willingly gave up some of our privacy in order for the value that connection gave us.  Phonebooks became a business model for phone companies – they began selling advertising space in their phone books and now make billions.  You could get your privacy back by requesting an unlisted number, but this too had its price.
Before the early 1900s, when you needed credit to make a purchase, a man from the bank would go around and ask your friends, relatives, and neighbors what kind of person you were.  Credit translated into character.  It was the best we could do at the time.  After WWII, people started needing more and more credit after coming back from a costly war.  In 1970, the Fair Credit Reporting Act was enacted to offer some rules to govern this new model of collecting and distributing personal information.  Now, banks could share your information with each other, which allowed them to know when someone had defaulted on or had excessive amounts of loans with other organizations.  This reduced the risk of issuing a loan, which allowed banks to give loans at better rates.  Again, giving up privacy created real value for an individual.
When you add it all up, my estimate is that the loss of Privacy, i.e. all the private information that we give up every day to do business actually has a significant tangible value.  My estimate is that our Privacy Inheritance is worth as much as $10,000 or more per year.  For most Americans, that’s like having a second part time job.

Click here to read Part 2 of this post.

Tuesday, December 18, 2012

Instagram Apocalypse 2013



Everyone knows that the Mayans may or may not have predicted that the world will end on December 21, 2012.  Experts are now saying that there is another major calamity awaiting right around the corner for those of us who survive on January 16, 2013.  That's when Instagram's new privacy policy will take effect.

There are a number of reasons why this isn't the end of the world.

The EFF is claiming that by including language in the "Rights" section of Instagram’s new Terms of Use, Instagram will now be able to sell your photos to other companies.  This is an accurate reading of the terms "transferable" and "sub-licensable" that are added to the license you grant Instagram in order for them to display their photos on the site.  This reading, however, discounts the rest of that sentence which says the photos you post are still restricted to whatever privacy settings you already have in place and that the use must comply with Instagram's privacy policy.

There will probably be herds of Zombies after the Mayan Apocalypse walking around with their smartphones, wondering if an equally undead corporation might use their pictures of brains for their own purposes.  Like when Virgin Mobile of Australia took pictures from a 16 year old’s Flickr stream to use on bus stops for its wireless phone marketing campaign.  It has happened, and  that scenario is not allowed by Flickr’s current Terms of Use…so there aren’t any guarantees even if the Terms of Use are perfect.

There is also another explanation for Instagram’s change.  The privacy policy has certain limited uses for what Instagram is allowed to do with your content.  In addition to requiring that they respect your privacy settings, the privacy policy says that in case of a merger, the content you upload might be a part of what is transferred to the new company.  The Terms of Use "transfer" language is very common in software contracts and is typically used to protect in the event the company is sold or acquired so that their customers can't run away kicking and screaming. 

Is Facebook considering selling off Instagram?  Maybe they just want to have their options open if the world does come to an end on Friday?

Perhaps they need the language in order to do what Facebook is already doing when they let you "Like" news articles and other pages on sites outside of Facebook.  (Please feel free to "like" and/or "share" this article.)  Or maybe they have a new feature or product up their sleeve that necessitated a change.

Or it could be that Facebook is just bringing Instagram's Terms of Use into line with Facebook's existing policy that uses the same "transferrable" and "sub-licensable" language.  That’s probably it.

Tuesday, December 4, 2012

Safe Web Act Reauthorized

Some laws are permanently on the books.  Other laws have a sunset date...like the Bush Era Tax cuts.  Sunsets have become popular these days as a way of keeping Congress honest so they have to renew the laws if they think they worked out well.

The Safe Web Act was one of those laws.  Safe Web was passed in 2006 and granted the FTC the ability to share online fraud related data with foreign law enforcement.  In the last several years, the FTC has become the central clearinghouse in the US Federal government for all things identity theft related, so it's good to see this law renewed.

Read more about the bill at the Hillicon Valley blog:

http://thehill.com/blogs/hillicon-valley/technology/270943-obama-signs-safe-web-act-into-law

The only catch is that there's another sunset. This time it's 2020.

Friday, November 30, 2012

Warrantless Wiretap-Dancing



Yesterday the Senate Judiciary Committee voted to update a law, the Electronic Communications Privacy Act, (ECPA), to require law enforcement to obtain a warrant before conducting searches of people’s online communications, including email, Facebook posts, Twitter updates, and documents stored online.  The full Senate is not expected to vote on the changes to the law until 2013. As written the ECPA is somewhat ironically named, since it currently allows law enforcement to view any data stored online for more than six months without a warrant.

Online privacy is good, right?  Which means warrantless searches are bad?  There is a lot of contention on the issue.  Law Enforcement’s chief argument is that the ECPA has been in place for 26 years, and nothing has gone wrong.  Privacy groups argue that the Internet is a different place than it was 25 years ago, so the law should be updated to reflect how people use it today.  Senator Leahey’s bill also weakens the privacy of video viewing history, to the benefit of companies like Hulu and Netflix, so overall any benefit to online privacy may be a wash.

Congress is examining these issues at the same time that an FBI investigation went to the heart of these issues.  The investigation into the affair between CIA Chief David Petraeus and his biographer, Paula Broadwell, presumably was done using some amount of warrantless wiretapping to gather emails related to the affair and the harassment of Jill Kelly by Broadwell.  This investigation will be at the forefront of the minds of the Congress when they take up the bill next year.

CNET last week discovered an alternate version of the amendment last week that would have instead expanded warrantless access to multiple types of online communications of private citizens, from email to Facebook posts, to 22 different federal agencies.  This would have been a reversal from Leahy’s earlier position, and may just have been a part of negotiations between the two sides.  Despite pressure from multiple Law Enforcement groups, Leahy released a statement denying that CNET’s reports were accurate.

Barriers
Senator Chuck Grassley (R-Iowa), is the ranking Republican on the Senate Judiciary Committee.  Grassley has expressed Law Enforcement’s perspective that creating new barriers for wiretaps could hamper investigations.  At least one amendment to the proposed legislation is expected that would create an exception to the warrant process for cases involving kidnapping, child pornography or violent crimes against women.

This comes after a Federal Appeals court okayed Warrantless Wiretapping in August.  A three judge panel of the 9th U.S. Circuit Court of Appeals wrote in their decision that “This case effectively brings to an end the plaintiffs’ ongoing attempts to hold the Executive branch responsible for intercepting telephone conversations without judicial authorization.”  The case involved two American attorneys who were spied on without warrants as a part of President George W. Bush’s secret terrorist surveillance program.

The case hinged on the issue of Sovereign Immunity.  Even though the United States was breaching its own wiretapping laws, the court reasoned, the plaintiffs could not bring suit against the government for the collection of the information itself.  The court did leave room for the plaintiffs to bring suit against the government if the information were used in some way.  The proposed changes to the ECPA wouldn’t affect the Sovereign Immunity issue, which means citizens still have no real recourse if the government doesn’t follow its own rules.

Not so simple?
It’s not surprising that wiretapping has increased as Law Enforcement has evolved along with the digital age.  The surprising part is that a solution has not come along that helps streamline the warrant requesting process.  The intention behind a warrant isn’t to slow down the searching process, or even to discourage it, but to ensure that a member of another branch of government is available to ensure probable cause exists for the search.  According to the ACLU, warrantless wiretapping has increased over 600% in the last 10 years.  If this continues, by 2020, the Justice Department may request over 100,000 warrantless wiretaps.  I think a long term question should be whether the already overburdened court system can handle even more requests in a timely fashion.

No one is saying that the increase in wiretapping is the result of more crime.  Most crime statistics show that over the last decade, crime rates are down.  Why more wiretaps, then?  Wiretaps represent the way our world has changed to be more data driven.  There is a longer paper trail than there used to be, so Law Enforcement has to follow it.

Thursday, July 26, 2012

Controversial Cybersecurity Act Vote Coming Soon?

This week, House Majority Leader Harry Reid hopes to finally bring the long awaited Cybersecurity Act of 2012 to the floor for debate.  Senator Joe Lieberman and the four co-sponsors of the Cybersecurity Act introduced a revised version last week, which they indicate incorporates extensive negotiations with the bill’s opponents.  The Hill’s Technology Blog reports that Senators Rockefeller and Feinstein are reaching out to key technology CEOs to help lend their support to the bill.

This is great, because if the bill doesn’t get voted on soon, it won’t happen this year.  President Obama has weighed in as well.  The President wrote a rare op-ed piece in the Wall Street Journal to boost support.  He writes, “The American people deserve to know that companies running our critical infrastructure meet basic, commonsense cybersecurity standards, just as they already meet other security requirements.”

This is in response to the bill’s critics who have stated that they would be concerned about the costs to businesses that would be imposed by the new law.  John McCain’s bill, in contrast, focuses on strengthening the government’s Cybersecurity, but stops short of mandating that businesses do the same.

All this should be read in light of the larger Cyber conflict that is currently going on.  New York Times writer David Sanger wrote last month that an inside source had confirmed what many had suspected, that the Obama administration had ordered a cyber attack against Iranian enrichment facilities.
Maybe this was a good thing.  There was no loss of life that we know of, compared to a conventional military strike against Iranian facilities.  A Cyber retaliation from the Iranians or their allies would have also been limited to computer infrastructure.

But the new Cybersecurity bill needs to be read in light of the fact that the US government dropped the most sophisticated Cyberweapon on the world that we have ever seen.  It’s been analyzed and perhaps reproduced by other countries.  And unlike a physical war where proximity to a conflict means greater risk, businesses are on the front lines of a Cyber conflict.  At a psychological level, most businesses don’t have the same outlook that a business in a war torn country might perceive their situation.

The reality of Cybersecurity in America is that it’s not just stolen identity that businesses need to worry about.  in November of 2011, for the first time, Robert Bryant, U.S. National Counterintelligence Executive released a report naming China as the world’s leading source of economic espionage, with Russia coming in a close second.  The reality is that by attacking an economy is the equivalent of holding a government hostage, as the Russians did against Georgian banks in 2008.

Cybersecurity laws need to play catch up to the current state of the world where a rogue nation like Iran or North Korea with nothing to lose economically could lanuch a terrorist like attack against small or medium sized businesses with very weak defenses and wreak havoc.  Unfortunately, the news today indicates that the bill is being fought on mostly partisan lines despite months of compromise that went into the new bill.  Senator McCain wants to delay the bill and Heritage Action, a conservative advocacy group related to the Heritage Foundation indicated it will track lawmakers votes on their key vote scorecard.

Tuesday, June 5, 2012

What happens when a public company has your private data?


What happens when a public company has your private data?  It used to be that Facebook was owned and operated by a private citizen.  Sure it was fun to question his motives.  Those were the days.  Maybe it wouldn’t have changed if Facebook shares had started to skyrocket from the getgo, but they didn’t.  And now they have shareholders to think about.  So what happens to Privacy when Facebook shares drop like an anchor?  

The shareholders start to yank the leash.

This week, Facebook announced they will start allowing individuals under the age of 13 to join its site.  A bit of background here, most Internet companies have policies against catering to kids younger than 13, not because they care about the kids, but because they have to comply with a set of guidelines called the Children's Online Privacy Protection Act  or COPPA.  COPPA requires service providers to verify that they have their parent’s consent, usually by taking a credit card number or having their parents call a telephone number.
To sweeten the IPO, look at the changes they made in the final weeks before their IPO.  They announced a major change to their privacy policy.  They will now “retain data for as long as necessary to provide services to users and others”.  This is after FB was fined $138,000 in 2011 inIreland for keeping a deleted user’s data.

Now back to children under 13.  Zuckerberg was quoted in 2011 with saying that kids should be allowed on Facebook.  Not for selfish reasons, of course, but because he thinks that it could help with their education.  Because they can learn a lot from other students.  And why not allow kids on Facebook?  Lots of parents create accounts for their kids while they are still in the womb…like the Superbowl commercial for Google where the parents create an account and start emailing their child pictures and stories.

Lawmakers are highly concerned that Facebook is opening up to children under 13 to create a whole new market of potential advertises for themselves.  You can already sell targeted ads by age group, so why not start targeting kids with more sugar cereals and toys and movies.  Because maybe kids don’t watch so many commercials anymore.  Thanks TiVo!

Of course, Facebook also announced that they will allow their users to vote on the new change.  To be binding on the company, whatever the vote turns out, 30% of the users or 270 million people need to click.  US National voter turnout in 2010 was only about 37% and only 90 million people voted.  Only Facebook knows how many of their 900+ million users are very active on the site, my guess is that it is probably less than 50%, but it would be astounding that enough people would vote, for or against, the privacy policy changes.  So one might ask...is the vote just going through the motions?