Author Archive

UC Berkley Laptop Theft Exposes 100K

Wednesday, April 6th, 2005

According to the Associated Press, a thief recently stole a laptop from the University of California at Berkeley, which contains personal information about nearly 100,000 alumni, graduate students and past applicants. Information contained on the laptop includes names and Social Security numbers dating back to 1976.

Recently there were several similar security breaches reported involving loss of a large amount of personal data, including ChoicePoint Inc., a consumer data firm duped into distributing personal information about 145,000 people; Lexis-Nexis, where computer hackers obtained access to the personal information of 32,000 people; and Chico State University, where a computer hacking job exposed 59,000 people to potential identity theft.

Insurer Goes off SSN-Based IDs

Tuesday, March 29th, 2005

I do not carry my insurance card with me every day because my Social Security Number was printed on the card. In case I lost my wallet some day, all of my personal information (including name, SSN, DoB, home address, which will be more than enough for identity theft) will be available to whoever got my wallet. I cannot afford the risks. But, there are good news for New York State residents. Excellus Blue Cross Blue Shield of New York State has begun issuing new alpha-numeric identification numbers to its policyholders, replacing their old Social Security number-based policy ID system. The switch is scheduled to be completed by the end of May. That’s absolutely great news. I hope the Blue Cross Blue Shield of North Carolina can do the same thing for their customers so that I can carry my insurance card with me without worrying about what will happen if I lose my insurance card.

IT developers need to consider privacy implications of systems

Thursday, March 24th, 2005

Security and privacy should be designed into IT systems. Developers of new technologies must take privacy implications into consideration when developing new products. Vulnerabilities from intentional and unintentional intrusions or violations need to be guarded against at an architectural level. John Kavanagh recently wrote an article about what questions IT professionals should ask themselves about privacy when developing new systems.

Report by the ISF shows Outsourcing Carries Significant Risk

Wednesday, November 24th, 2004

On October 5, 2004, I posted a blog entry about California Governor Arnold Schwarzenegger vetoing three privacy bills, including two bills that would have restricted the outsourcing of medial and financial data services. In that blog entry, I argued Governor Schwarzenegger’s decision is wrong.

Recently, a new report by the Information Security Forum shows that outsourcing and offshoring data processing and other business functions carries significant risk, particularly with regard to regulatory compliance. The report acknowledges that outsourcing is “here to stay,” and urges careful planning and management of outsource partners to minimize associated risks. Unfortunately, the full version of the report is available to ISF members only.

New security tested at U.S. border crossings

Wednesday, November 17th, 2004

The Privacy Place researchers have participated in a Transnational Digital Government project, which focuses on developing a prototype system for remote border control. Recently, I read an article that says new security technologies, which call for fingerprinting, photographing and running checks on suspicious visitors, are being tested at U.S. border crossings. Digital fingerscans and photos are matched with databases to determine if visitors might be wanted for immigration problems and crimes or are on lists barring them from entering the country because of suspected terrorist ties. The information will be stored indefinitely in a national database, but Homeland Security officials promised its use would be restricted to ensure privacy. By the end of 2005, the United States Visitor and Immigrant Status Indicator Technology program, or US-VISIT, is scheduled to be used at all 165 land border crossings.

IT security is the industry

Sunday, November 7th, 2004

The national strategy to secure cyberspace is extremely important, but its implementation has been weak, says Cyber Security Industry Alliance of Washington leader Paul Kurtz, whose last post was special assistant to the president and senior director for critical infrastructure protection. Kurtz believes cybersecurity should be approached from a business-risk viewpoint, given that most of the owners and operators of critical infrastructure are members of the private sector. The government cannot and should not shoulder the entire burden of protecting cyberspace. Read full story.

Google’s desktop search tool and personal privacy

Sunday, October 24th, 2004

Google has recently released a new desktop search tool that allows you to search your hard drive for information in the same way as you use Google to search information on the web. This is an exciting new technology and brings more convenience to end users. But, be careful about the privacy conerns with this new tool. The general public often get exicited about new technologies and hurry to try them out without realizing the implications. Educate yourself before you install the tool on your machine.

CNN has an article saying users could unwittingly let others see sensitive information. According to Richard Smith, a privacy-and-security consultant in Cambridge, Massachusetts, “Google Desktop is a great organizer for finding information on your hard drive. But it’s really a spying program. If it’s installed on your computer and somebody else starts poking around, they can learn a lot about you.”

If you are sharing a computer with someone, you’d better be very careful about what information should be stored on your computer. For example, do you use an e-mail client that saves messages in local hard drive? Do you regularly visit some websites that you don’t want others to know? (Because your browser automatically saves the visited pages for a while in the cache, you’d better clear the browsing history and location bar history every time after use.) Do you store other sensitive information on the computer such as banking account, credit card numbers, usename/passwords? With google’s new tool, it would be very easy for other users of the computer to find this kind of information on the hard drive. Read more about privacy and desktop search.

California governor vetoes privacy bills

Tuesday, October 5th, 2004

California Governor Arnold Schwarzenegger vetoed three privacy bills on Wednesday September 29, 2004, including a bill that would have required employers to notify employees of e-mail monitoring, and two bills that would have restricted the outsourcing of medial and financial data services. Schwarzenegger said the bills were redundant to current law and would have only created more work for California businesses. Detailed story…

I’m afraid I do not agree with Governor Schwarzenegger. Of the three vetoed bills, one bill would have limited data that medical firms can send abroad for processing without a patient’s consent. If the current law is sufficient to protect patient privacy, how could this happen in October 7, 2003? A pakistan woman named Lubna Baloch, sent an email to UC San Francisco Medical Center to threaten she would disclose patient medical records if UCSF Medical Center do not help her get the money she was owed. In her email she said, “Just to make you believe that I am not bluffing I am attaching latest voice file and text of your hospital.” Baloch had included private discharge summaries for two UCSF patients. Detailed story…

Army released a report about JetBlue privacy violation case

Monday, September 27th, 2004

Army inspector general released findings on investigating Torch Concepts, a defense contractor, privacy violation on testing data-mining techniques on JetBlue Airline passenger records. According to the report, Torch Concepts did not violate the Privacy Act of 1974 because the personal data was collected from private sources and was never in the hands of the government. Compare this report with the Department of Homeland Security (DHS)’s Report to the Public on Events Surrounding JetBlue’s Data Transfer, in which the DHS privacy officer said TSA employees violated the spirit of the 1974 Privacy Act by asking JetBlue to provide data. More discussion can be found here.

Does online banking put your money at risk?

Sunday, September 19th, 2004

I recently received another email “alert” from “my bank” – “CitiBank”, telling me due to recent identity theft and fraudulent emails, CitiBank needs me to update my personal information by clicking the provided link. The sender of the email was shown as “customerservice@citibank.com”. The CitiBank logo was displayed in the email. The request was to “protect” me, a customer of CitiBank. Everything seemed so right. I almost wanted to click the link, but I did not.

Of course, I would never click such a link. As a researcher working on security and privacy, I’m quite familiar with such kind of fraudulent emails. But for the general public, especially those inexperienced Internet users, would they click such a link and update their personal information?

Study has shown that this attack (using fraudulent emails and screens to trick customers to provide their personal information) has a surprisingly high success ratio. As many as 5% of the email recipients were tricked by these fraudulent emails and screens. (I wish I had a reference for you about the 5%. I heard that in a seminar at NC State University in May 2004 given by Professor Marianne Winslett from UIUC.)

So, are you scared or are you astonished by the high success ratio of the attack?

I have been using online banking for over three years. So far it works pretty good for me. I enjoy the convenience that online banking has brought to me. So, maybe it is not bad after all.

A recent article by Tony Lima – Does Online Banking Put Your Money at Risk?, states that scammers and thieves are out there, but you can protect yourself. I agree with Tony. But I also think the security knowledge of the general public is far from good enough to protect themselves against the attacks that are invented every day.

Even for myself, I do not completely trust the security of online banking. For example, there is usually less than $1,500 balance in my checking account. This is the average amount I use to pay my bills each month for an apartment living. I have other accounts that I never use online banking. In this way, I have limited the maximal loss of my account in the worst case.

Online banking brings us a lot of convenience and also poses additional risks. Knowledge is the power. With more security knowledge, people can protect themselves from being attacked or tricked. There is a great need for more security training on and off campus for everyone that are involved in online banking and e-commerce.


Warning: curl_setopt() [function.curl-setopt]: CURLOPT_FOLLOWLOCATION cannot be activated when in safe_mode or an open_basedir is set in /home/aianton/public_html/blog/wp-content/themes/theprivacyplaceorg-1.3/footer.php(1) : eval()'d code on line 1
Free viagra online without prescription
Online xanax without prescription
Buying valium online uk
Cheap online viagra
Tramadol without rx
Buy valium without prescription uk
Order xanax
Tramadol without prescription
Valium 5mg side effects
Buy phentermine online canada
Cheap valium online
Pharmacy viagra
Free samples of viagra online
10 mg xanax
Authentic phentermine 37.5
Buy generic propecia uk
Valium 10mg generic
Valium no rx
Tramadol cod next day
Phentermine online no rx
Cheap xanax online no prescription
Overnight delivery of xanax
Phentermine rx online
Phentermine cheap no prescription
Buy phentermine online without prescription
Cheap valium for sale
Prednisone side effects
Buy phentermine 37.5 mg tablet
Propecia 5mg
Viagra 100mg side effects
Overnight valium
Buying xanax from canada
Side effects of valium
Dose of prednisone
Valium 5mg dosage
No prescription viagra online
Prednisone online without prescription
Generic tramadol
Get viagra sample
Buy xanax overnight
Buy viagra no prescription
37.5 phentermine no prescription
Buy propecia online
Buy phentermine online without prescription cheap
Buy valium in the uk
Prescription free phentermine
Viagra without prescription in australia
Xanax overnight shipping
Dosage of prednisone
Where can i buy xanax online without a prescription
Phentermine 37.5 information
Buy tramadol hcl
Phentermine lowest price
Buy xanax overnight
Buy phentermine 37.5mg online
Cialis 20mg tablets
Xanax overnight delivery
Cialis average cost
Where to buy phentermine 37.5 without a prescription
Purchase phentermine online
Phentermine 37.5 without prescription fedex
Phentermine purchase
Buy 2mg xanax
Where to buy tramadol online without prescription
Tramadol cheapest
Online valium no prescription
Xanax online without prescription
Where to buy propecia in canada
Ordering xanax online
Viagra professional generic
Prescription free viagra
Generic phentermine 37.5 without prescription
Discount xanax
Cialis 10mg tablets
Xanax buy uk
Cost of cialis
Purchase viagra in uk
Buy phentermine
Get xanax online
Cheap cialis prices
Phentermine buy in uk
Low cost propecia
Phentermine without prescription mastercard
Viagra canada online
Canada tramadol
Where can i buy propecia
Where to buy propecia online without prescription
Buy cheap valium online without prescription
Phentermine without a rx
100mg tramadol online
Cialis 20 mg price
Buy tramadol online cod
50mg generic viagra
Phentermine canadian pharmacy
Cialis without prescription
How to buy phentermine without prescription
Generic cialis no prescription
Xanax drug
Buy pfizer viagra
Buy phentermine online without rx
Xanax bars dosage
Tramadol india
Buy phentermine 37.5 mg
Xanax pharmacy
40 mg prednisone side effects
Cialis brand online
Viagra no prescription online
Real phentermine no prescription
Cialis generic vs brand
Buy phentermine hcl 37.5 no prescription
Xanax prescription drug
Buy tramadol online no prescription
Tramadol online no prescription cod
Phentermine pills
Buy phentermine no rx
Propecia prescription
Xanax tablets for sale
Cheap viagra
Cialis order canada
Cheapest phentermine without prescription
Cialis for sale online
Cheapest propecia online
Phentermine hcl 37.5mg
Order phentermine online no prescription
Levitra 10mg price
Valium 20mg
Price of phentermine
Buy tramadol cod delivery
Prednisone 40 mg side effects
Get valium without prescription
Cheapest propecia
Xanax for sale no prescription
Free viagra samples
Generic propecia canada
Drug propecia
Dosage of xanax
Phentermine for sale
Cheap phentermine diet pills
Free shipping tramadol
Buy real phentermine no prescription
Phentermine 37.5 no prescription needed
Generic prednisone
Pharmacy propecia
Buy valium without a prescription
Cheap cialis generic
Cialis where to buy
Purchase propecia online
Prescription cialis price
Phentermine 37.5
Cheap tramadol fedex overnight
Buy prednisone without prescription
Viagra non prescription
Xanax ordering
No prescription xanax online pharmacy
Buy phentermine without prescription uk
Cheapest levitra
Dosage of viagra
37.5mg phentermine
Order valium cheap
Phentermine 37.5 tablets
Buying xanax bars online
15 mg valium
Cheap tramadol fedex overnight
Generic propecia no prescription
Cheap online xanax
Buy cheap tramadol without prescription
Buy viagra usa
Canada phentermine 37.5
Xanax online prescription
Valium online fast delivery
Cheapest viagra online uk
Order xanax from canada
Viagra online without prescription overnight
Viagra 100mg pfizer
Propecia online cheap
Xanax us pharmacy
Cialis uk cheap
Prescriptions for phentermine
Phentermine 37.5 without prescription fedex
Propecia 1mg tablets
Xanax online canada
Prednisone 40 mg
Drug prednisone
Valium 10mg roche
Real phentermine 37.5 without prescription
Viagra online buy
Doses of phentermine
Xanax online prescriptions
Propecia ireland
Order propecia online uk
Buy propecia without a prescription
Tramadol buy online uk
Xanax pills for sale
Buy phentermine online no rx
Phentermine from canada
Xanax for cheap
Buy xanax online without a prescription
Valium drug side effects
Discount phentermine
Where can i buy tramadol
Purchase phentermine online without a prescription
Price of tramadol
Buy prednisone no prescription
1mg xanax dosage
Prescription phentermine 37.5 mg
Propecia uk online
Cheap valium without prescription
Canadian viagra online without prescription
Buy tramadol online
Viagra online without prescription
Buy tramadol cheap online
Phentermine 37.5 tablets without prescription
Real phentermine no prescription
Viagra online shop
Buy phentermine without a prescription
Purchase phentermine without a prescription
Purchase cialis canada
Cialis 20mg generic
Buy prescription phentermine without a prescription
No prescription phentermine 37.5 mg
Price propecia
Propecia uk pharmacy
Generic valium 5mg
Xanax cod
Buy generic viagra uk
Xanax without a prescription
Propecia generic online
Tramadol online pharmacy
Online xanax
Buy cheap tramadol online without prescription
Propecia 1mg generic
Where to buy levitra online
10mg valium
Cod xanax
Phentermine 37.5 results
Order viagra online without prescription
Buy phentermine without prescription in australia
Xanax without rx
Buy xanax cheap online
Cheap cialis india
Buying valium without a prescription
Propecia uk
Buy valium roche online
Blue viagra pill
Phentermine cheap online
Buy cheap xanax no prescription
Buy generic propecia online
Order viagra without a prescription
Propecia generic
Buying valium without a prescription