Ten reasons why Privacy matters

January 14, 2014

Daniel Solove, a professor at George Washington University, is a leading authority on privacy.  He has penned both academic tomes (eg Information Privacy Law) and immensely readable polemics on privacy (The future of reputation and Nothing to Hide).  He is also a prolific blogger on both serious legal sites and the more general linked in.

One of his recent posts is 10 Reasons Why Privacy Matters which provides:

Why does privacy matter? Often courts and commentators struggle to articulate why privacy is valuable. They see privacy violations as often slight annoyances. But privacy matters a lot more than that. Here are 10 reasons why privacy matters.

1. Limit on Power

Privacy is a limit on government power Read the rest of this entry »

Drones back into the spotlight with privacy issues hovering overhead

January 13, 2014

The Economist again considers the development of drones in the USA in Game of drones.  As I have posted previously drone technology is moving along at an astounding speed with pressure for commercial use. That is currently not permitted but that restriction is probably going to disappear.

It provides:

DEEP in the bowels of the engineering building at Oklahoma State University, Ben Loh flips a switch on a remote control. A rotor starts whirring and a white sphere the size of a large beach ball rises. Mr Loh navigates it around the room, then lands it and rolls it across the floor.

The flying sphere Read the rest of this entry »

ABC reports on data breach of Target and Neiman Marcus notifies its customers of its own data breach

The ABC radio program, AM, reports in Huge hack of consumer data in the USA on  a massive data breach involving Target over the Christmas period.

It provides:

TIM PALMER: It’s been described as the worst security breach of personal data in history and we may not yet know the full extent of it.

US retailer Target revealed over the weekend that the details of tens of millions more customers than first thought have been stolen in a massive hacking scandal, and now the upscale retailer Neiman Marcus says it’s been hacked too.

Security experts say Read the rest of this entry »

Privacy Commissioner issues a reminder about the changes to the Privacy Act

In Know your privacy rights the Privacy Commissioner has posted a reminder of the upcoming changes to the Privacy Read the rest of this entry »

Deep mining of data and privacy

January 12, 2014

The current edition of the New York Review of Books has a detailed and very readable article, How Your Data Are Being Deeply Mined, on data mining by business and the growing business of database marketing. The clear privacy concerns Read the rest of this entry »

Analysis reveals flaws in personal banking apps

In a fascinating, if somewhat technical for the non technical, post IOActive Labs Research very recently undertook an analyis on personal banking apps.  The post is titled Personal banking apps leak info through phone and is found here. The research involved testing 40 home banking apps from the top 60 most influential banks in the world.  The study involved banks in the Australian jurisdiction.

Some of the salient conclusions are:

40% of the audited apps did not validate the authenticity of SSL certificates presented. This makes them susceptible to Read the rest of this entry »

Tracking consumers via their smartphones and the data held by them

The International Consumer Electronics Show (“CES”) again delivers a story of technology having huge privacy implications.  In Want to find a great deal? It’s looking for you, too the Washington Post reports on technology used by department stores to not only to use a person’s smartphone to track his/her movements but use other data from in it to sell.

The article provides:

Salvador Alejo was a man on a mission. Walking the floor at the Consumer Electronics Show in Las Vegas, he used his phone and the event’s app to find nine spots that would earn him the digital badges he needed to finish a high-tech scavenger hunt.

But in this case, the scavenger hunt was looking for him, too.

The Consumer Electronics Association placed sensors known as “iBeacons” Read the rest of this entry »

Driver data and privacy

 The International Consumer Electronics Show (“CES”) held in Nevada every January, generates plenty of media interest as new gizmos and gadgets are unveiled for the first time.  Some go on to be world beaters while others sink without trace.  Privacy concerns are also a regular fixture of the product launches.  And this year is no different.   The Washington Post in As automakers tap smartphone technology, concerns grow about use of drivers’ data highlights the privacy risks Read the rest of this entry »

Slow appointment of privacy commissioners

January 10, 2014

In his excellent Open and Shut blog of 7 Januuary 2014, titled Appointing a privacy commissioner low priority for most states, Peter Timmins sets out in detail the lamentable situation of state governments not appointing or making permanent the privacy commissioners in Queensland and Victoria and the lack of regulatory oversight in South Australia,  West Australia and Tasmania.

But it seems that governmental lethargy is not an Australian problem only.  On 7 January 2014 Peter Hustinx Read the rest of this entry »

UK Government issues revised identity proofing guidelines

January 9, 2014

The UK Government has updated its guidelines on identity proofing and verification.  The guidelines have been jointly issued by the Cabinet Office and the UK’s National Technical Authority on Information Assurance.  It is found here. The government previously issued a consultation paper on draft identity assurance principles (found here)

There are four levels of assurance that organisations can have about an individuals’ identity with details of the evidence and checks required in order to claim compliance with each level.

The standards range from requiring a basic level of verification and validation of documents to the need to obtain and verifyidentifying documentation including biometric passports and bank statements.  It is relevant that the principles require ID assurance service providers to only process “the minimum data that is necessary” to meet the needs of individual service users. In addition, ID assurance providers would have to provide individuals with a right to access their personal data for free and transmit the data to another provider “in a standard electronic format, free of charge and without impediment or delay” upon the request of a user.