US Postal Service has privacy problems with change of address information

October 9, 2014

The Washington Post in How the Postal Service put your change-of-address information at risk reports on an audit of the US Postal Service which uncovered a significant weakness in the data security privacy breach.   The weakness was poor controls over those outside groups who were given access to those records including a failure to follow its own procedures.  One of those procedures was to require entities to submit security plands when they apply for licences.  This episode highlights 2 issues in privacy protection; that weaknesses Read the rest of this entry »

Sophos survey reveals fewer than a quarter of staff in UK, France and Germany believe their organisation complies with data protection laws

October 6, 2014

It has been over 6 months since the amendments to the Privacy Act took effect.  While the Privacy Commissioner’s office has been reasonably active in publishing guidelines, releasing statements and handing down 3 determinations a robust use of the enforcement powers has not been in evidence yet.  That may be consistent with the softly, softly then gradually escalating model as set out in its statement The OAIC’s enforcement approach to new privacy laws from 12 March 2014 which Read the rest of this entry »

JP Morgan announces data breach of 83 million customers personal information.

October 3, 2014

In December 2013 I posted on JP Morgan’s notification of a data breach (found here).  As of the end of last year JP Morgan believed the personal information of 465,000 customers had been compromised. That was bad but now JP Morgan announces that in fact the cyber attack involved customer acccounts of 83 million customers as reported by itnews in JPMorgan reveals 83 million customers exposed by hack.  This makes the data breach one of the largest in history.

It provides:

The JPMorgan Chase & Co systems hack has joined the ranks of the biggest data breaches in history, as the company revealed overnight that 83 million households and small business accounts were affected by the attack.

The bank revealed the scope of the previously disclosed breach on Thursday, saying that there was no evidence that account numbers, passwords, user IDs, birth dates or Social Security numbers had been stolen. Read the rest of this entry »

Patient in NZ hospital breaches privacy of other patients

October 1, 2014

Health care facilities, especially hospitals, hold sensitive information (as defined in the Privacy Act).  They are also quite prone to data breaches.  There are a number of reasons for this, poor systems, reasonably regular turnover of staff, a large number of individuals concentrated in a small space often in quite busy (if not chaotic) environment and often a culture which is not given to more modern strictures on data handling.  In Hospital patient takes peek at info of others Stuff NZ reports on a patient in Hutt’s emergency department using Read the rest of this entry »

Report reveals 75 million records compromised so far in 2014

At the 3/4 mark in the 2014 calendar year the Identity Theft Resource Center reports that 75 million records have been compromised in 568 breaches.  This has been reported by SC Magazine in Report: 75 million records compromised so far in 2014.  With no mandatory data breach notification legislation it is difficult to assess how many breaches there are in Australia.  That is Read the rest of this entry »

Seller of spyware app charged with selling a surreptitious interception device

September 30, 2014

That mobile apps are a privacy worry has moved from speculation through to allegation and are moving into the realm of a truism.  Regulators have known about this for years and have in 2013/14 raised concerns, conducted reviews and surveys to highlight the problems with mobile apps.  Those problems include non existent to poor privacy policies, failure to notify users of what will be done with their personal information, generally poor security, inadequate protections when transmitting information across wifi networks and poor quality software.  In US man charged for selling spyware phone app the problem is even more concerning, an app designed to be installed by another person for the purpose of intercepting communications, including Read the rest of this entry »

Privacy Commissioner issues statement about BASH/Shellshock/Bourne Again vulnerabilities and need to protect IT systems

The Privacy Commissioner has today issued a statement about the Bourne Again Shell (BASH) vulnerability that has caused more than a few waves within the IT community in the last week or so.  The statement Read the rest of this entry »

Shellshock flaw and obligations under the Privacy Act

The Shellshock flaw has sent more than a ripple through the IT industry. There is a data protection regulation issue involved as well.  The genesis of the problem is a flaw in longstanding software, Bash, which was first installed in 1989.  Given the software enables users to issue commands to computers an exploitable weakness is of particular concern.  Exploitable flaws in ubiquitous software which is now part of the structure of many operating systems pose immediate cyber security threats and require immediate response when detected.  The Age in  Shellshock: The latest security superbug explained provides an exellent explanation.  In addition there has been coverage at Shellshock flaw ‘intertwined’ with modern internet, may affect some Mac usersShellshock: How to protect your Unix, Linux and Mac servers,  Shellshock makes Heartbleed look insignificant and Shellshock flaw ‘intertwined’ with modern internet, may affect some Mac users.

The seriousness of the threat has prompted the Information Commissioner’s Office in the United Kingdom to issue a release under the heading ICO highlights need to apply security updates after Shellshock flaw discovered which provides:

The Information Commissioner’s Office is urging organisations and individuals to make sure that their IT systems are up-to-date.

The warning comes after the identification of a flaw, referred to by the researchers who discovered it as Shellshock, which has been found in a software component called Bash. Bash is a part of many Linux systems, as well as the OS X operating system used by Apple Macs. The flaw potentially allows any computer with the vulnerability to be taken control of remotely. Read the rest of this entry »

Drones go showbiz and an article on drones and privacy

September 26, 2014

Two articles, Cirque du Soleil Is Incorporating Drones and Filmmakers Get Permission to Use Drones in the U.S. highlight how ubiquitous drones are becoming; becoming part of a show and another way to get that perfect angle for a movie.

An article in the Smithsonian titled The Invention of the “Snapshot” Changed the Way We Viewed the World draws the comparison of the onset of drones and their privacy intrusive capabilities with the invention of Kodak’s personal camera.  It is a very useful historical comparison between the advent of an early valuable piece of technology which had an impact on privacy and the latest development.  The rapid take up of Read the rest of this entry »

ACMA finds Channel Nine Queensland breached privacy and accuracy guidelines

September 25, 2014

ACMA announced that Channel Nine breached the factual accuracy and privacy clauses of the Commercial Television Code of Practice.

The media announcement

The announcement provides Read the rest of this entry »