Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

The Welcome Page


This post used to be pinned to the top of the blog but I decided to let it move down the stack. It's purpose was, and still is, to explain that I am Stephen Cobb and this is my personal blog. 

The blog was set up in 2005 but I didn't start regular blogging on it until 2006. That's because I had another blog, also started in 2005, where I covered my main interest back then: information security.

Over time, this blog became a place to talk about things other than cybersecurity. Things like dealing with several medical conditions: my primary aldosteronismbasal cell carcinoma, and very low grade prostate cancer; also my partner's hemochromatosis and Giant Cell Arteritis (UK readers can just add an 'a' after the 'e' in the hemo words).

Brief notes on 70+ years of life

I was born in a house in the medieval city of Coventry, in the middle of England, in the middle of the last century, to parents who survived heavy aerial bombardment in the global conflict known as World War Two, which ended seven years before my life began. 

After going to university—first in Leeds and then in Canada — I travelled the world for several decades before moving back to the city of my birth with my partner and our adopted cat, Lola (seen above).

My partner of 39 years, the phenomenal Chey Cobb, is a US citizen, legally resident in the UK. I am a citizen of both the UK and the US. We have both spent, and continue to spend, a lot of time researching how humans create and confront technology risks and health challenges. I write about my research for a variety of websites and publications, like:
This blog is where I write about more personal stuff such as: the fact that I'm retired, although I'm still open to interesting projects; my plans to publish another book, but I'm not sure when; my attempts to raise awareness of the medical problems which disabled my partner; the role of registered carers and how it can be supported; my hopes for radical reform of the patriarchal medical establishment that continues to fail women so badly. 
Photo of a Minolta lens on my Olympus camera

On a lighter note, Chey thinks I should have a hobby to take my mind off things, so I'm been trying "classic glass" photography: using lenses from old 35mm film cameras to take pictures with modern digital cameras (for example, the Minolta lens on my Olympus camera shown here).

On a more serious note, I feel the need to use some of my "free" time to contribute to society. So in addition to sharing my knowledge about thwarting digital criminals, I serve on the board of a charity, Carers Trust Heart of England

I also do driving jobs for our local hospital as one of the hundreds of UHCW Volunteers. As I travel around Warwickshire collecting and delivering patients I engage in another hobby: sampling independent coffee shops and their menus.

Fortunately, I still find some time to continue my research at the nexus of ethics and technology. I am currently exploring the harm caused by abuse of technology, which I have written about here. and talked about here, on YouTube.

If you want to contact me, you can use the form on this page or find me on Facebook or LinkedIn

Note: I am aware of some formatting issues and missing images in the older articles on this site—a side-effect of moving this blog from WordPress to Blogger—I'm fixing them as and when I can.

Will "repeal and replace" hurt genomic medicine and victims of genetic conditions?


Let me give you the short version of my answer up front: Yes. If the current privacy protection for genetic medicine in the US, in which Obamacare/ACA has played a key role, is diminished by the "repeal and replace" efforts of the current US administration, then America's hopes for genomic medicine will also be diminished. Victims of some genetic conditions will be particularly hard hit, as will all forms of research that involve the human genome.

The even shorter version goes like this: Why would I give anyone my genetic information if that might lead to myself and my family being denied insurance or paying higher premiums, for medical, life, or longterm care policies?

brian0918, Public domain, via Wikimedia Commons
Fans of genomic medicine are apt to respond by saying there's no need to worry because there are laws to prevent that type of discrimination. To which I have heard many people say: I don't trust the insurance companies and/or the government to abide by those laws. And besides, laws can be repealed, and databases can be hacked.

In short, when it comes to enjoying the benefits of medical science, Americans face a bleaker future than the residents of other wealthy countries due to the absence of two rights: the right to health care and the right to privacy.

Background

Who am I to present these arguments? For more than 25 years I've been studying information security, data privacy, and risk. I've been a Certified Information System Security Professional for more than two decades and I have a Master of Science degree in Security and Risk Management. I have also put in more than a decade as primary caregiver for someone with a genetic illness (variously known as hereditary hemochromatosis, genetic haemochromatosis, Celtic Curse, Bronze Diabetes, Iron Overload). In that role I have spent many years interacting with the families of hemochromatosis patients and the main support group for this condition, the Iron Disorders Institute.

What is the problem? The House recently passed legislation called the American Health Care Act of 2017 (H.R. 1628). There is a Senate version known as the Better Care Reconciliation Act of 2017. As far as I know, both of these pieces of legislation remove a gene-related provision of the current law, ACA (a.k.a. Obamacare). Here's the problem:
  1. The Genetic Information Nondiscrimination Act of 2008 a.k.a. GINA says employers and health insurers can't use your genetic data in hiring decisions and health insurance coverage; but, as Maryam Zaringhalam at Slate points out: life, disability, and long-term care insurance are not covered under GINA’s provisions, and those insurers "already use genetic testing results to deny coverage to otherwise healthy individuals".
  2. Furthermore, GINA only protects people who are genetically predisposed to a disease as long as they are asymptomatic. In other words: "once a person begins showing symptoms, GINA no longer matters" (Zaringhalam- see link in References below). For example, my wife was born with the HFE mutation that can produce a potentially fatal condition known as iron overload but she was asymptomatic for the first few decades of her life. Then, in her forties, due a phenomenon dubbed hemopause, she became increasingly symptomatic. She is now eminently "declinable" under pre-Obamacare rules.
  3. This GINA "loophole" as Zaringhalam calls it, was closed by Obamacare. That's because the ACA outlawed discrimination in health care insurance pricing or coverage based on preexisting conditions.
  4. Now the current administration looks set to return America to the days when preexisting conditions were considered grounds for charging higher insurance premiums.
  5. That would mean returning health insurance to the list of things you pay more for if your insurer has knowledge of your genes. Remember, that list already includes life, disability, and long-term care insurance.
I would be the first to admit that the above is a simplified account of the problem, but I stand by its accuracy and will go into more detail below. A complicating, and possibly offsetting factor in this story is the plethora of state laws on genetic data, medical privacy, and health insurance. Those might give you hope, but then you have to factor in the rampant hacking of supposedly private databases of personal and medical information that we have witnessed over the past few years. Bottom line? It is not hard to understand a response of "No way!" when you suggest to someone that they should get their genes tested, even when that test could potentially save their life, or those of their relatives.

Fighting malware, cybercrime, and hemochromatosis = I've been busy


I enjoy reading a wide range of blogs. Recently, I was shocked to visit one of my own blogs -- this one -- and see that I had not posted anything since February. Surely I had written more than that? In fact, I have been doing a lot of writing, but on other blogs. So I decided to post a roundup of recent writings and presentations, for my own edification, and to show that I have not been slacking. Enjoy!

Living Security


A lot of my writing these days appears on We Live Security, the website that grew out of the Threat Blog at blog.eset.com. Here are some highlights:

Being Security


I have also been writing some posts about security and privacy on my first blog, Scobbs Blogspot. The idea is to put security pieces there when they are not a good fit for We Live Security, for example, a strong personal opinion, or a speculative piece. (In general, I want to keep this blog here, Cobbsblog, for non-security stuff.) Recent posts on Scobbs Blogspot include:

Security Slides and Webinars and Podcasts


You can find some of the slides from my security presentations at SlideShare under the zcobb account. These include slides that ESET graciously makes available for anyone who is working to increase security awareness in their organization. Here is a recent example from a webinar on cybercrime:



Some of my security education presentations are done as webinars and you can find these in the ESET channel on a service called BrightTalk. The channel requires a one-time registration process but is free and there are dozens of recorded webinars available from myself and my colleagues.

I have also recorded a lot of podcasts on security and privacy. These are available on this page but they are not marked as to author. All of the podcasts are worth a listen and feature my fellow researchers at ESET.

Earlier this year I answered several questions for a reporter while visiting the Latin America headquarters of ESET. Topics covered in the resulting video include the effects of Snowden's revelations about the NSA, the relationship between privacy and security, and social media issues for young people. Spanish subtitles are provided.



Fighting Hemochromatosis


My writings on hemochromatosis started here on this blog in 2008, with "dsgds". Then, in 2010, I created CelticCurse.org and post there when I have something substantial. Here are some recent posts.

In addition to Celtic Curse, I created another channel of communication about hemochromatosis, the Hemochromatosis page on Facebook. This has reached over 100,000 people so far this year and led to the publication of the first ever "Hemo Doc Stars" list of recommended hemochromatosis doctors from around the world.

So, the next time I am wondering to myself "what have I accomplished this year?" I can look at this page and refresh my memory. And the above is not everything. I also got accepted into a postgraduate degree program in security and risk management in the Criminology Department of the University of Leicester, in England. I hope to have time to share some instructive tales of distance learning here as the program progresses.

2,500 Blog Posts and Counting


Stephen CobbThat's 2,500+ blog posts if you count all my posts across all my blogs and those of my employer (ESET). My blogging is now very infosec-oriented, but I'm still spreading the word about the silent genetic killer, hereditary hemochromatosis, on the Celtic Curse blog and the largely-self-sustaining Facebook hemochromatosis page, which now has over 1,750 followers. Of course, all views expressed on cobbsblog.com are mine and not those of my employer.

Mark Zuckerberg Faces the Privacy Meter: Facebook trends open book


Face it folks, it's time to dust off the Privacy Meter for a quick check of Facebook founder Mark Zuckerberg. According to an internal source, Mr. Zuckerberg has placed himself in the camp made (in)famous in 1999 by Scott McNealy, the CEO of Sun Microsystems, who was reported to have said: “You already have zero privacy anyway, so get over it.”

Mr. Zuckerberg's position was recently described by a Facebook insider in response to this question: "How does Zuck feel about privacy?" Response: “He doesn’t believe in it.”

The details of this revelation can be read here and I'd have to say it hardly amounts to a public statement by "Zuck" himself (for the record, Scott McNealy's declaration was not a public statement either, and should be placed in context, something I tried to do in my 2002 book on privacy).

I doubt that either Mr. Zuckerberg or Mr. McNealy would say, on the record, that they don't believe in privacy. What both men seem to share is a frustration with privacy concerns as they relate to digital systems. Human beings can be annoyingly inconsistent and hard to predict when it comes to matters of personal information. That makes it inherently difficult to design online communications and online communities that satisfy every shade of sentiment with respect to the sharing of personal information. And that's why I created the Privacy Meter:

Not exactly a high tech device, it nevertheless serves its purpose: to help people assess their own attitude to their personal information. I developed the privacy meter as a teaching tool, specifically to teach Chief Privacy Officers and other C-level execs that:

a. Everyone has a different place on the privacy scale, there is no "correct" score;

b. Entities like companies and agencies cannot handle privacy issues according to one person's views about privacy.

In other words, the fact that you're an open book kind of person does not make it okay to impose an open book approach on people who are more closed book. If you are closed book you can't impose that view either because it could limit your organization's ability to serve its customers. Most importantly, the way you handle other people's private data has to be in accordance with their view, not yours. That principle was established, in the context of computer data, back in 1974, and remains one of the pillars of privacy best practices in the realm of data protection (see Chapter 3 of Privacy for Business, available as a free .pdf file here).

Several years ago I put together a short set of slides on the privacy meter and the potential benefits and problems arising from getting privacy positioning right or wrong. You can click here to download the slides as a .pdf file which I recently updated to include Facebook's current privacy perception problem. That slide is pretty easy to understand:

Just a few hours after Wired puts out the story that your CEO doesn't believe in privacy, PC World publishes a story about the latest privacy invading scam that your system is enabling. Not good. Just the sort thing that can hurt your share price and tarnish your brand. Which is why your personal feelings about privacy should probably remain private when you are running a company.

[BTW, you can now download the full 240 page text of Privacy for Business (2002) as an Adobe Acrobat document from this web site; there's no charge and no registration required.]

You Can't See My House From Here: And I'm okay with that


Having written several posts in the past about Google Street View, including one featuring the house in which I was born, I thought I would post a Street View picture of where I live now:

Cobb Hill on Google Street View

As you can see--or rather, not see--the Google Street View camera vehicle did not get very close. In fact, it drove along the state highway near us, but that was it. Street View does not extend to the county road on which our 'official' address is located. And I'm okay with that.

I remain ambiguous about Street View in light of it's potential for abuse as a scouting tool by burglars and perverts. This has been widely discussed, particularly in the context of English cities where the narrowness of streets can put the Google camera very close to living room windows. But past discussions have focused on urban street views. Now Google is photographing rural roads, adding a new dimension to the potential for abuse.

It is no secret that farmers and ranchers don't always store their tractors and trailers in barns. In fact, putting all the equipment away at the end of every day, or every time you left the homestead to go to town, well that would be hugely unproductive, not to mention being a major pain in the butt. It's also common knowledge that some farms are located close to, sometimes bifurcated by, state and county highways, as seen here on Street View.



But common knowledge and specific knowledge are two different things; keeping them apart may keep some light-fingered city types from pillaging trusting country dwellers. Now Google Street View is bringing them together. Who knows who is surfing the hinterlands looking for easy targets?

Google Street View Privacy Survey: Win an Earth Day Prize!


I recently wrote about privacy attitudes to Google Street View and I thought it would be interesting to carry out a quick survey. Since viewing places on Google Street View is arguably more earth-friendly than going to see them in person, I decided to offers some cool Earth Day prizes!

Five people who complete the survey, between now and April 25, will be randomly selected to receive cool re-usable shopping bags, the kind that save using paper and plastic. These bags are burnt orange in color but very green. And the really cool thing is they fit in your pocket, no kidding! So please take a moment to fill out the form and include your email address if you want to be in the prize drawing. Good luck!

On the Street Where I Was Born


Recently, on my technology blog, I wrote about the mixed reception that Google Street View has received in England, land of my birth. I admit to having mixed feelings about this technology myself.

It is very easy to be seduced by technology that enables me to sit in a cottage on a hill in the wilds of Upstate New York and capture this image of the street in England where I was born. (Just to clarify, I was not born in the street, but in one of the houses on this street--home birth by midwife being the normal practice in England in the 1950s.)

The most obvious change in the last 50 years is the number of cars on the street. There were  practically none when I was born. You could easily play 20 minutes of football in the road without being disturbed. Now there are too many vehicles, which is why many front gardens have been replaced with parking spaces--compare the original gardens on the left with the parking pads on the right. And so it goes...

The Wisdom of Villagers? Google Street View stirs protest in the UK


When villagers in Broughton, England, stepped into the road and linked arms last week to block the progress of a Google Street View camera car, were they also blocking progress? Or were they demonstrating that the wisdom of ordinary folk can sometimes exceed that of the brightest, or richest, techno-geek?

Why wouldn't the villagers of England welcome a technology that is proving very popular in its land of origin, America, the ability to enjoy a 360 degree view of city streets, from street level? Well, when a journalist asks for comment I always say: There are three main points to consider.

1. Geography. Streets and sidewalks in English cities are typically narrower than they are in America. That puts the Google camera car very close to your front door. Take a look at this first image, from a street in Leeds.

Drive down the left hand side of this street with a camera mounted on the roof of your car and you are just a few yards from the front doors you are snapping.

(I used to live a few streets over from this one when I was a student at the University of Leeds, and we had no front garden at all, just a door that opened onto the sidewalk or "pavement".)

The upshot of this domestic geography is shots like the second one, of a young lady pushing her baby through the front doorway of a house in Coventry. As you can see this Google Street View also contains a clear view of the neighbor's living room. (I don't think that's a flat screen TV that I see over the fireplace--but maybe a few doors down you might get lucky.) I think a lot of people on both sides of the Atlantic would consider that image intrusive.

2. Crime. The"mob" in Broughton cited a recent spate of burglaries as one of their reasons for objecting to Google Street View and Americans should note that a home in England is twice as likely to be broken into as an American home. Furthermore, 53% of English burglaries occur when someone is at home (versus 13% in America).

As someone who has experienced being woken up in the middle of the night and seeing a burglar in an English home, I can tell you it gets the pulse racing and leaves a lasting impression. While English criminals are less likely to carry guns than their American counter-parts, the aggressive use of knives is widespread in the UK and rates of violent crime [other than murder] are higher in the UK than in the US. (I don't like to just assert a number like that wihtout a primary source, but here is a secondary source--aspiring criminologists take note, there is fame to be gained by publishing a thorough comparison of US/UK crime stats.)

In the UK burglary "case" with which I am personally familiar, the burglar had acquired knowledge of how to defeat a particular type of lock and was going from house-to-house in the middle of the night looking for, and entering, those that were fitted with such locks. How much safer and efficient, to do your research online, from the comfort of your sofa, using Street View?

3. Rights. In the comments of some Broughton residents I got a whiff of unease that has been brewing for some time, a sense that we, the people, are tired of corporations profiting from our existence. A bunch of companies, from credit reporting agencies to data aggregators, make their money off the fact that we exist. They sell information about me. And now one of the richest companies in the world is enhancing its profits with a snapshot of my house while big companies, Sears for example, charge you for using photographs of their "house." I sense the common man, and woman, is getting a little tired of this state of affairs. It doesn't feel quite right, even though it is hard to say exactly what is wrong with it.

So there you have the three points. And, as I would say to the interviewer, let me conclude by observing: The error often lies not in the act but in the reaction. Google's reaction was to say, in effect, "What's the big deal? It's easy for people to remove images." Oh yes, like the lady with the baby is going to be checking the status of her online identity every few weeks to see who's snapping her. I am reminded of the response companies used to give in the early days of spam, before spam became both imprudent and illegal: "What's the fuss? There's an easy way for consumers to get off the mailing list." The wisdom of folk suggests that Google has some serious work ahead if it is to avoid the emergence of a "Do not photo" list. Otherwise, Broughton may become a rallying cry for a whole lot more trouble to come.

I leave you with a question. What the heck is that plant growing in the living room of number 185?

And the Good News is? Apple's iPhone works in my house


phonesAs some readers already know, I've had to abandon my faithful Treo 680 because it wouldn't always work in my house. Sad, because I've had a Treo since they first came out, operating on T-Mobile, then Cingular, now AT&T.

Although it was only GPRS, I was able to read the news on my Treo, do email, Twitter, and write notes pretty darn fast. But the fact is, you can't very well use a cell phone for business if it doesn't work reliably in your house.

I was going to hold out for a new Palm Pre but it looks like that device is anchored to Sprint at the moment (my choice of "anchor" being quite intentional). And current speculation is that the Pre won't be available on AT&T until next year (per the TreoCentral forum). Sprint coverage at my place is zero. Verizon is better and so a Pre on Verizon might be appealing at some point in the future.

But for now, the iPhone 3G is my phone, which means

More for Virgins, Less for Screw-ups: The surprising cost of data breaches


In its fourth annual study on data breaches, the Ponemon Institute examined the costs of 43 companies that had been hit by a data breach. The study found, not surprisingly, that the cost per record breached had risen (actual numbers coming up).

I have always thought it ironic that one of the biggest obstacles to getting organizations to take action on issues of data privacy and security is a lack of data, namely data about what a security failure might cost. If known, that cost can then be weighed against the cost of putting security measures in place.

After all, Adam and Eve did not cover their bodies in the garden of Eden,  likewise organizations operating in crime-free utopias have no need to spend money to protect against data exposures. In the real world, however it is sad but true that a certain percentage of people are not sufficiently constrained by either personal ethics or a fear of consequences and go about steal data for personal gain.

Thus the need for security spending to avoid the costs, which are now averaging over $200 per record. So, next time you read a story about some bank or retailer exposing thousands of records, you can just multiply by $200 to figure the hit they have just taken).

This study is more good work by Larry Ponemon and the Ponemon Institute. Consistently reliable data over time is particularly useful. For example, if you read up on all the data breaches that have been happening you might have formed the impression that more of them are now coming from third parties, i.e. people who process customer data for retailers, banks, etc. And the survey shows that yes, third party data breaches were reported by more organizations in 2008 than in 2005 (21% then, 44% now). Less predictable perhaps is the finding that third party data breaches are more expensive, $231 per compromised record versus an overall average of $202.

As you might expect, breaches experienced by data loss "virgins" are more costly, $243 versus $192 for "experienced" companies, sardonically referred to as "repeat data screw-ups" by Larry Dignan in the TechRepublic blog post referenced at the beginning of this post. What surprised and saddened me is that more than 84% of all cases examined by Larry Ponemon's team were repeat data breach offenders.

Sadly, until there is an uptick in the general standards of human behavior, things are likely to carry on like this. Data entrusted to the feckless will be exposed by the lawless, innocent lives will be disrupted, money will be lost, and the cost to defend against miscreants will mount.

Go Larger Than Life: Easy access to a cool new medium


Finally got to spend some time this week with friend and fellow Philly-geek Kendall Schoenrock at the LTLprints. That's LTL as in Larger Than Life, on the web at LTLprints.com and on the map in Center City, Philadelphia.

Together with co-founder Carsten Petzold we reviewed the ways in which LTLprints is using Monetate, the post-click marketing platform for which I am evangelizing these days (loads more about that subject can be found here).

Even more exciting, I got to see what LTLprints is doing with large scale peel-and-stick printing. You've probably seen peel-and-stick prints advertised by Fathead on TV and by Wallhogs on the web. What LTLprints is doing is a little different and potentially much more creative.

Basically they are selling peel-and-stick printing by the square foot. You choose the size of your canvas and then you fill it with whatever you like. One huge rectangular photo, a lifesize cutout photo of your dog, or a bunch of big cutouts arranged to use every inch of the printing real estate. Your images are then printed out by LTLprints on this amazing material that can be stuck to walls and other smooth surfaces, but later removed and stuck somewhere else.

printsI even put a print on my laptop, with no fear that it will leave a sticky mess when I decided to swap it out. Okay, so it's an LTLprints logo, but imagine the graphic possibilities, and so much better than traditional stickers that shrink and curl and get icky round the edges. Of course, the amazing machine that LTLprints uses to produce these prints also cuts them out, ready to peel and stick. They arrive on your doorstep on a large roll safely packed inside a sturdy tube.

One of the hurdles to creating great cutouts is smoothly outlining and cropping the images. This can be intimidating for the novice, but Kendall and Carsten have it covered. All you need to do is upload the original hi-res photo and use LTLprints' web software to loosely draw the outline of where you want the image to be cropped. The company will then have skilled hands smooth the outline so that it is just right.

I couldn't wait to get home and go through my photoa archives for images that would look good on the office wall, and on my laptop. These guys are totally commited to delivering a quality product and I think they are going to do well. Check them out.

Cobb's First Law of Digital Comms


Cobb's first law of digital communications states:  You should never say anything in a digital communication that you wouldn't want your mother to read.

Why? Because there is a chance that at some point in the future your mother might read it. The probability varies, but it is there, whether your mother uses a computer or not; just ask the scores of embarrassed CEOs and public officials who have seen some of their nastiest emails reprinted in newspapers.

In the context of this law, "digital communications" means email, instant messaging, SMS, Twitter, web pages, blog posts, blog comments, social network content, and more. The term "say anything" means write or post and includes images as well as words. What constitutes digital communications will change but the law will remain the same.

I came up with the basic premise for this law before blogs were invented, before the web as invented, even before Internet email started to take off and millions of people began sending messages under the mistaken assumption that only the intended recipients could read them. However, it was email that really brought the 'message' home, so to speak.

Leaving aside the wrongly addressed and incorrectly cc'd emails, the fact is that email is like a postcard, not a letter, it can be read by any machine it passes through (with the possible exception of some specially encrypted email, although there are people who can read that too--and some of them can be hired by the lawyers that your ex-spouse or ex-employer hired).

I started using digital messaging in the early 1980s on services like The Source and CompuServe. Although these were 'closed' networks with paid admission, it was clear even then that the contents of digital communications could easily be exposed by human errors, technical errors, court orders, and business decisions, to name a few. It was also clear that digital messages could linger a long time after they were sent, read, and supposedly deleted.

Like many 'early adopters' I learned the hard way that it was better to moderate the wording of one's messages, or simply leave some things unsaid, than to face the embarrassment of rash words getting into the wrong hands. I don't think I ever went so far as to call a client a jerk in a message that ended up in the client's hands, but I did discover, to my chagrin, that there is no 'unsend' button in email applications and an email retraction never arrives before an emailed statement.

I happen to think there are some very positive ethical and philosophical implications to the reality I have tried to encapsulate in this first law of digital comms. I will try to lay out my thoughts on this in more depth in a future post. But here's the short version: the transparency and persistence of digital comms tend to reduce the fudge factor in human existence, forcing us to be true to ourselves in all aspects of our lives. For all the talk about the ways in which things digital can be faked, the underlying thrust of our world becoming more digital is that we are faced with a fuller, and truer, picture of ourselves, across multiple dimensions. We are more likely, over time, to engage in dialog than to stay silent, to be ourselves in all things, to both give and seek acceptance, to accept diversity of thought and lifestyle rather than to censure and straightjacket.

Of course, this will all take time, so in the meantime I humbly suggest that we all keep the first law of digital comms in mind. Big brother is one thing, mother is another.

Bamford Breaks Out: Shadow Factory exposes NSA, CIA, Hayden, Bush, 9/11


When it comes to books about the US intelligence agencies there's a lot of mumbo-jumbo and plain old BS out there. The shining exception has been the work that James Bamford has published about the National Security Agency [NSA]. And Bamford's latest book, the just released Shadow Factory, is really going to shake things up in the IC (spook-speak for Intelligence Community).

I ordered my copy from Amazon today and I urge you to do the same. But before your copy arrives you can get an idea of some of the shocking information it contains by checking out this explosive interview available in mp3 and Real Video. If the world was not in the middle of an economic meltdown right now, revelations like this would be headline news. Spoiler Alert: This interview includes explanations of how:

  • the NSA pays foreign companies and private contractors to create copies of all your Internet traffic;

  • the CIA prevented the FBI from tracking the 9/11 terrorists in America;

  • contractors in America swap tapes of our soldiers in Iraq calling home to their wives and girlfriends;

  • the head of the NSA, now the head of the CIA, General Hayden, agreed to Cheney's demands for an illegal domestic surveillance program to avoid personal embarrassment.


Bamford first brought the National Security Agency to the world's attention in 1982 with The Puzzle Palace. Back then the very existence of the NSA was classified, the book was essentially banned in the US, and Bamford was...

What Fighting Spam Taught Me About Marketing (and Market Forces)


Yesterday I reflected on the emergence of the spam problem and some early work on anti-spam strategies. I'd like to continue the topic today with a second observation from early in 2001:

2. A lot of people want to receive relevant offers.

This is not the same as observation #1 in my previous post: Some people like unsolicited email. Back in 2001, point #1 was true: a not insignificant percentage of email users were open to getting email they didn't ask for. This percentage dropped rapidly over the next few years as the quantity of unsolicited email that these people received increased, together with the proportion of that email which was deceptive and distasteful.

What did not change is point #2; it is human nature to be receptive to a good deal IF it is relevant. We realized this...

The End of the Internet As We Know It?


Could the day be approaching when blogging about how much you dislike the Church of Scientology or a certain political candidate gets you knocked off the net? Or worse, a heavy knock on the door?

Love it or hate it, the Internet of old appears to be on its way out. A few years from now, two recent news items, when taken together, may reveal a turning point. Most recent was the agreement of several major ISPs to censor Internet traffic. New York Attorney General Andrew Cuomo has coaxed Verizon, Time Warner Cable and Sprint into dropping the long-accepted notion that ISPs are immune from liability for content posted by users, much the same way that phone companies have eschewed liability for what people say in phone calls and, to get historical about it, printing machine makers took no responsibility for what was printed with their presses. This principle, that the carrier is not responsible for what is carried, is even established in law, notably under the 1996 Communications Decency Act.

But as David Kravets, writing at Wired.com observes, under the Cuomo deal, "the ISPs seem to acknowledge a moral role in policing the internet."

What Are Facebook Friends For? Maybe data mining


Further evidence that Facebook does not 'get' privacy is brought to you this month by the BBC, which recently built a Facebook application that could mine personal data from anyone who played it, and their friends. (In a nice touch of irony, the application was called The Miner, as in 'data miner' get it?)

A video clip from the BBC's Click programme can be seen here (you can find a text report here). It turns out that, by default, Facebook gives application developers wide-ranging access to anyone who installs the game, and their friends. Notice the theme here: "and their friends." In other words, you might be exercising due diligence over what you do with your Facebook account, but just one careless friend could undermine your privacy.



And you'll love the Facebook response: Using an application to abuse access would be a violation of the Facebook terms and conditions. Oh well then, no problem. That should take care of that. And here I was worried that someone would steal my credit card, but no worries, using someone else's credit card is a violation of Visa's terms and conditions. Those terms and conditions are probably what's limiting online credit card fraud losses to just a few billion dollars a year. And that's considerably less than what some analysts think Facebook is worth.

Hannaford Breach: A chance to learn


There is actually some upside to the recently announced multi-million record data beach at grocery chain Hannaford, including the possibility that it was detected a lot quicker than the retail mega-breach at TJ Max (although that assessment may change as more facts come out).

I liked the coverage here at SearchSecurity which addresses the event relative to both the PCI DSS, something my brother and I have been writing about for SearchSecurity, and business continuity, something I am working on at the moment with my good buddy Michael Miora, one of the best guys in the BC business.

There's bound to be be "more later" but in the meantime, feel free to check out Da Cobbs on SearchSecurity (that's Chey, Stephen, and Mike).

What Profiteth It Google to Know Your Ip Address


A couple of thoughts in light of Google's divergence from the norm as far as PII is concerned (see previous post On IP and PII: Merely the Location of a Computer? Non!). The debate over what exactly constitutes Personally Identifiable Information is not merely academic or a sidebar for policy wonks, it goes to the heart of how data about people should be handled, stored, shared, protected, etc.

To a certain extent I sympathize with Google in that the best definition of PII is a relative or functional one. Even my name, Stephen Cobb, has limited value in identifying me--it identifies me only in limited circumstances--even though "name" is included in most lists of PII identifiers. The reason for this is the popularity of Stephen as a name for Cobbs (you could say "the commonness of Stephen Cobb as a name," but hey, I'm trying to maintain some PPD here--personal pride and dignity).

My wife's name, Chey Cobb, is clearly going to be PII in most situations. The same is true of my friend Michael Miora (there's only one, AFAIK). But even something like "Stephen Cobb in ZIP Code 32084" does not identify me because there are several people who share these identifiers (I know because my friend Bruce Dufresne, who knows more about the history of the automobile that anyone else I know, knows two Stephen Cobbs and sometimes calls me by mistake when he wants a ride to the car auction). So, the extent to which any piece of data can be considered PII depends upon the context and the aggregate.

As for Google and your IP address, it seems like they may be putting too much store in its value. Consider what happened the last time I was visiting my brother in England and Googled a number of different pieces of hardware, some for my him, some for me. Google was a mess. When I Googled from my hotel room, Google assumed I was in the Netherlands (the hotel's Internet service was provided by a Dutch company).

When I Googled from my brother's office in Surrey, Google really didn't want to tell me about product offerings in the US because I was Googling from a UK IP address. And when I am in America I cannot see the ads served up to UK visitors to his web site, School Sports Action TV, because Google is making assumptions based on my IP address.

In other words, my IP address might be of limited relevance with respect to what I want to see on the Internet. It seems like it would be better to have a "focus" option in Google that I could select to shape my results rather than let them be determined by my IP address. Of course, some folks in marketing are then going to want to know where the people live who select UK as their focus. My point is that my IP address does not reliably provide that data. So Google might want to think about how hard it wants to defend its collection and retention of that data.

Facebook Stickiness or Sticky Mess?


Sometimes I read something in the newspaper that makes me feel better, not because it is good news, but because it lets me know I am "not the only one" or "not imagining things." So it was with a recent New York Times article about Facebook focusing on the difficulty people have had deleting their data from Facebooks's computers.

The article plays on the term "stickiness" as in "the amount of time users spend at a web site over a period of time." This can be a major factor in selling ad space on a web site or otherwise monetizing it. But the sticky-ness described in the article is the problem of closing a Facebook account, which basically you cannot do. I found this out when I realized I had two Facebook accounts. Not sure how that happened (but it would seem to be a flaw in the Facebook design that it could happen).

I figured I would delete one account. I could not. I could close it down, somewhat, but the stuff, the data that was associated with it, remains in the Facebook server farm, ostensibly so I can revive that account at some point in the future. I assumed this difficulty in deleting an account was driven by security concerns, as in: make it hard for people to close accounts they are not unauthorized to close, i.e. one's belonging to other people. Apparently that might not be the case. Could it be they want to keep mining that data forever? Here are a few points to note, from the Times article:

  • Facebook’s terms of use state that “you may remove your user content from the site at any time,” but also that “you acknowledge that the company may retain archived copies of your user content.”

  • Its privacy policy says that after someone deactivates an account, “removed information may persist in backup copies for a reasonable period of time.”

  • Facebook’s Web site does not inform departing users that they must delete information from their account in order to close it fully—meaning that they may unwittingly leave anything from e-mail addresses to credit card numbers sitting on Facebook servers.


Seems to me Facebook is still growing up in terms of understanding data privacy issues. After all, the retention policy in the terms of use is pretty much in direct contravention of the basic principles of data privacy.