Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, 22 September 2013

Sen. Franken seeks data on privacy controls in iPhone 5S fingerprint tech

September 20, 2013 04:10 PM ETComputerworld - A U.S. lawmaker wants to know whether the Touch ID fingerprint reader in Apple's iPhone 5S has adequate controls to protect the personal data of users.

In a letter to Apple CEO Tim Cook, Sen. Al Franken (D-Minn.) sought answers to a set of detailed questions on whether the technology includes controls for securing fingerprint data and whether the company has any undisclosed plans to share the data.

While Touch ID could improve certain aspects of mobile security, it also raises "substantial privacy questions" said Franken, chairman of the Senate Judiciary Subcommittee on Privacy, Technology and the Law.

In the letter, Franken told Cook that he is "seeking to establish a public record of how Apple has addressed these issues internally and in its rollout of this technology."

Apple didn't respond to Computerworld's request for comment on Franken's concerns.

Apple's Touch ID is a fingerprint-based authentication system for the iPhone 5S, that allows up to five users register fingerprints on a single device. Apple says the technology is designed to make the iPhone a less attractive target for thieves.

Industry analysts have so far generally hailed the technology as a step forward in mobile security. Some analysts predict that it won't be long before the Touch ID feature is included on all Apple products.

In the letter, Franken acknowledged that Apple has taken measures like ensuring that fingerprint data is encrypted and only stored locally, and to block third-party access to Touch ID. "Yet important questions remain about how this technology works, Apple's future plans for this technology, and the legal protections that Apple will afford it," Franken said.

Unlike passwords that can be changed at will, fingerprints are permanent, Franken wrote. "You can't change your fingerprints. You have only 10 of them. And you leave them on everything you touch; they are definitely not a secret. If hackers get a hold of your thumbprint, they could use it to identify and impersonate you for the rest of your life."

Franken asked Cook to explain how Apple will convert locally stored fingerprints into a digital or visual format that could be extracted and later used by Apple or third parties. "Is it possible to extract and obtain fingerprint data from an iPhone? If so, can this be done remotely, or with physical access to the device?" he said.

He also asked whether the iPhone 5S is designed to transmit diagnostic information about the Touch ID back to Apple or other third parties, and whether fingerprint data would be backed up on a user's computer.

He also sought information on how Touch ID interacts with iTunes, iBooks and Apple's App Store. "Can Apple assure its users that it will never share their fingerprint data, along with tools or other information necessary to extract or manipulate the iPhone fingerprint data, with any commercial third party?" Franked asked.

John Zurawski, vice president at Authentify, a vendor of voice-based authentication tools, said questions like thosed posed by Franken should be asked of any vendor of biometric devices.

Biometrics does offer a secure layer of authentication, he noted. "The ability to reverse engineer a fingerprint from its encrypted digital form would be very labor intensive," and probably not worth the effort for cybercriminals he said.

"The average consumer's credit and identity information may not be worth the computational effort required to reverse engineer," he said.

"I think many of Senator Franken's questions hit important areas," added Joe Schumacher a security consultant with Neohapsis, a vendor of mobile and cloud security services. "It is important for the consumer to understand how Touch ID communicates with Apple regarding use of the service, diagnostic information and interaction with other Apple applications."

The fact that fingerprint data is stored locally on the iPhone is a good thing from a security and privacy perspective, Schumacher noted.

However, Apple must clarify how the sharing of fingerprint data will proceed when Apple rolls out the technology to other devices. "Biometric fingerprint technology is a great form of identification but not the best form for authentication, at least not by itself," he said.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at Twitter@jaivijayan, or subscribe to Jaikumar's RSS feed Vijayan RSS. His email address is jvijayan@computerworld.com.

Read more about Mobile/Wireless in Computerworld's Mobile/Wireless Topic Center.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Tuesday, 27 August 2013

Sept. 23 deadline looms for business compliance with HITECH Act on patient privacy

Organizations handling protected health information (PHI) have until Sept. 23 to comply with new security and privacy requirements that were included in the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009.

After that date, all covered entities, including online storage vendors and cloud service providers, will be subject to new breach notification standards and limitations on how they can use and disclose PHI. They will also be required to ensure that their business associates and subcontractors are compliant with the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA). The HITECH Act amended portions of HIPAA by adding new security and privacy provisions on patient information.

[ For a quick, smart take on the news you'll be talking about, check out InfoWorld TechBrief -- subscribe today. | Read Bill Snyder's Tech's Bottom Line blog for what the key business trends mean to you. ]

In addition, covered entities will be required to have updated patient privacy notices in place that state the patient's rights over the data and how the data can be used and shared.

Unlike the original HIPAA privacy and security rules, which primarily applied to healthcare organizations and insurance companies, the new HIPAA Omnibus rules apply to business associates and their subcontractors. Under the omnibus rules, a business associate of a healthcare provider, such as a cloud service provider, is directly liable for protecting any patient data it handles, even if the vendor is just storing the data.

Business associates are also liable for ensuring that any subcontractor it hires, such as a document-shredding company, is similarly protecting PHI.

The new rules for safeguarding PHI create a complex liability chain, said Peter MacKoul, president of consulting firm HIPAA Solutions LC. A covered entity or a business associate could face stiff civil penalties for a breach by a subcontractor, regardless of how far down the chain the subcontractor might be, he said.

Under Omnibus HIPAA rules, covered entities and business associates are directly responsible for protecting against the use of PHI by employees, contract workers, trainees and even unpaid volunteers and interns, MacKoul noted.

The rules also give healthcare organizations and business associates less latitude to determine when to make a breach notification, he said.

Previously, a healthcare organization needed to notify individuals of a data breach only if there was a serious risk of financial or reputational harm. Under the new requirements, covered entities and business associates will be required to issue a breach notification in most cases, unless they can specifically show there is a "low probability" of the breached data being misused, MacKoul said.

Healthcare companies will be required to consider four specific factors, including the nature of the data that was breached and whether PHI was acquired or viewed only, to determine the seriousness of a breach. Importantly, breach notification requirements can be triggered even if an employee, contractor or unpaid volunteer uses PHI in an impermissible manner, he said.

Healthcare entities need to identify all their business associates, especially newly covered entities such as data storage companies, and ensure they have proper business associate agreements with them by Sept. 23, said William Maruca, a partner with Fox Rothschild LLP.


View the original article here

Saturday, 24 August 2013

Privacy groups criticize proposed $8.5 million Google settlement

Five U.S. privacy groups have opposed a proposed $8.5 million settlement with Google in a class-action lawsuit over search privacy, as it fails to require Google to change its business practices, they said.

Google was sued in October 2010 in the U.S. District Court for the Northern District of California. The Internet giant allegedly transmitted user search queries to third parties without their knowledge or consent in order to enhance advertising revenue and profitability. Google shares search queries "via referrer headers," according to a court document.

[ Also on InfoWorld: Google to pay record-setting $22.5 million fine over privacy practices. | For a quick, smart take on the news you'll be talking about, check out InfoWorld Tech Brief -- subscribe today. | The Web browser is your door to the world -- and to many security threats. Learn how to secure your browsers in InfoWorld's "Web Browser Security Deep Dive" PDF guide. ]

The headers identify the address of a Web page that linked to the current page. When a Google user clicks on a link from Google's search results page, the owner of the website that the user clicks on will receive from Google the user's search terms in the referrer header because the search terms are included in the URL.

The search terms can contain users' real names, street addresses, phone numbers, credit card numbers, and Social Security numbers, all of which increases the risk of identity theft, according to the original complaint. Those queries can also contain highly personal and sensitive issues, such as confidential medical information, racial or ethnic origins, political or religious beliefs, or sexuality, according to the complaint.

On Monday, the plaintiffs in the class-action lawsuit filed a motion for settlement. Google has agreed to pay $8.5 million in cash into a settlement fund, according to the motion.

The proposed agreement provides for a single settlement class, in this case all persons in the United States who submitted a search query to Google at any time from Oct. 25, 2006 until the date of the notice of the proposed class-action settlement, according to the document.

The money however will not be divided among all Google users in the United States, but rather be paid to organizations that can protect the interests of individuals.

Part of the settlement fee is meant to cover settlement administration expenses and part will be paid to the World Privacy Forum, Carnegie-Mellon, Berkman Center for Internet and Society at Harvard University, and Stanford Center for Internet and Society among others, according to the document.

The recipients must agree to devote the funds to promote public awareness and education, and/or to support research, development, and initiatives, related to protecting privacy on the Internet, according to the proposed settlement.

Besides a monetary settlement, Google also agreed to notify users as to its conduct so that users can make informed choices about whether and how to use Google search.

But the settlement proposal is not good enough, according to privacy organisations including the Electronic Privacy Information Center, Consumer Watchdog, Patient Privacy Rights, the Center for Digital Democracy, and the Privacy Rights Clearinghouse.


View the original article here

Wednesday, 21 August 2013

Tech legal news site Groklaw shutting down, citing email privacy concerns

Technology legal news website Groklaw is shutting down due to concerns over the continued availability of secure email in the wake of revelations about U.S. government surveillance.

"The owner of Lavabit tells us that he's stopped using email and if we knew what he knew, we'd stop too," site founder Pamela Jones said in a farewell post Tuesday. "There is no way to do Groklaw without email. Therein lies the conundrum."

[ Also on InfoWorld: Lavabit founder says he can't legally explain why he shut down email service | Lavabit shutdown marks another costly blemish for U.S. tech companies | For a quick, smart take on the news you'll be talking about, check out InfoWorld Tech Brief -- subscribe today. ]

Groklaw, which was launched 10 years ago, has been known for its exhaustive coverage of technology law, particularly involving software patents, open source software, and privacy issues.

Secure email provider Lavabit recently announced it would shut down due to an ongoing legal dispute, presumably with the U.S. government. "I have been forced to make a difficult decision: to become complicit in crimes against the American people or walk away from nearly ten years of hard work by shutting down Lavabit," company owner Ladar Levison wrote on its website.

Lavabit was reportedly used by former U.S. National Security Agency contractor Edward Snowden, who leaked documents related to NSA spying programs and is now in Russia after being given asylum. Following Lavabit's closure, Silent Circle also shut down its secure email service, while calling the move a preemptive one rather than something precipitated by a government subpoena or warrant.

On one level it's little surprise Jones felt compelled to shut down Groklaw, given how fiercely she has protected her own privacy over the past 10 years.

"There is now no shield from forced exposure," Jones wrote. "Now that I know that ensuring privacy online is impossible. I find myself unable to write."

But that's not to say someone else won't restart Groklaw. In an email on Tuesday, Jones suggested she wouldn't stand in the way of such a scenario but called it unlikely.

"If someone else wants to do it, and everyone wants to participate knowing what they know, of course," she wrote. "But it's a lot of work, and I don't think anyone will step forward. Maybe they'd do it for money, but that would basically ruin the project, in my view."

It's also doubtful that Jones would be willing to restart the site herself, should acceptable circumstances arise regarding email security.

"For me, I looked into the security stuff pretty deeply, and no, I wouldn't reopen it myself," she said. "What I wrote, I meant."

Chris Kanaracus covers enterprise software and general technology breaking news for The IDG News Service. Chris' email address is Chris_Kanaracus@idg.com


View the original article here