Language Selection

English French German Italian Portuguese Spanish

Burden is on us to protect our data

Filed under
Security

If you had to guess, how many companies would you say have enough of your personal data stored in various databases to make even a rookie crook ready for prime-time conning?

Ten, perhaps? What about 50, 100 or 1,000?

You probably don't know the answer, and that is exactly the problem.

In the past six months, the personal data of millions of consumers have been lost, stolen or sold to identity thieves. The most recent case involved a financial unit of Citigroup Inc. CitiFinancial, which provides a wide variety of consumer loan products, disclosed that personal information (Social Security numbers, loan account data and addresses) of 3.9 million of its customers was lost by UPS in transit to a credit bureau. So far CitiFinancial said it had no reason to believe that the information has been used inappropriately.

So far.

Every time we hear of one of these cases, the companies involved tell their customers not to worry. Trust us, they say. They pledge to enhance their security procedures.

The promises don't make me feel any safer about my personal data. How about you?

It's time for the federal government and the states to step in and make sure the companies fulfill those promises.

There have been some efforts to protect people's financial information. On June 1, a new federal rule took effect that requires businesses and individuals to destroy sensitive information derived from consumer credit reports.

I was initially encouraged when I heard about this rule. It seems to cover all the bases -- individuals, and both large and small organizations that use consumer reports, including consumer reporting companies, lenders, insurers, employers, landlords, government agencies, mortgage brokers, car dealers, attorneys, private investigators, debt collectors and people who pull consumer reports on prospective home employees, such as nannies or contractors.

There's just one little problem with this "Disposal Rule." There is no standard for how the documents have to be destroyed. Here's the direction the Federal Trade Commission is giving to businesses and individuals: "The proper disposal of information derived from a consumer report is flexible and allows the organizations and individuals covered by the rule to determine what measures are reasonable based on the sensitivity of the information, the costs and benefits of different disposal methods, and changes in technology."

How strong is a standard if it has no standard? Basically, those who have our information get to decide how and when it is to be destroyed.

"The burden is completely on the consumer to protect what is important," said Evan Hendricks, editor and publisher of the newsletter, Privacy Times.

Full Article.

More in Tux Machines

FSFE: ‘German public sector a digital laggard’

With their lacklustre approach to free software, German public services remain behind other European member states, says the Free Software Foundation Europe (FSFE). When asked, the current governing parties’ say they support free software, but their statements are contradicted by the lack of action, the advocacy group says. In early September, the FSFE published its analysis of the free software policies put forward by the main political parties on the ballot, in preparation for Germany’s parliamentary elections on 24 September. This analysis (in German) is far more detailed than an earlier report generated by the Digital-O-Mat, a web portal set up to focus on political parties’ positions on 12 digital topics. Read more New release: ISA² interoperability test bed software v1.1.0

PocketBeagle: An Ultra-tiny, Open-source, Linux-powered Development Board

BeagleBoard.org has revealed its latest development board named PocketBeagle. It’s an ultra-tiny and open source USB-key-fob computer that’s crafted for DIYers, hobbyists, and educators. PocketBeagle is based on Octavo Systems OSD3358-SM 21mm x 21mm system-in-package, which gives it 512MB DDR3 RAM, 1-GHz ARM Cortex-A8 CPU, and 2x 200-MHz PRUs. It comes with integrated power/battery management as well. Read more

Security: SEC Breach, DNSSEC, FinFisher, CCleaner and CIA

Android Leftovers