More Content - Including Podcasts

Thursday, February 16, 2012

Mobile Privacy and Security – The Perfect Storm

Panel A: Mobile Privacy and Security – The Perfect Storm
(Salon AB)
Moderator: Jill Clayton, Information & Privacy Commissioner, Province of Alberta
Speakers:
1. Chris Conley, Technology and Civil Liberties Fellow, ACLU of Northern California
2. Alex Manea, Security Product Manager. Global Security Group, Research In Motion
3. Kofi ???, Sales Systems Engineer, McAfee, Inc.
4. Stewart Cawthray, Chief Security Architect, IBM Global Technology Services

The were opening statements from each of them.

Chris began by sharing that smart phones have a unique set of data to them that make them a different paradigm than computers or cell phones. It was designed as a communications device that is constantly connected and constantly sharing information.

Example, Angry Birds (Rovio) has complete access to your iOS contact list. This was undisclosed and is an issue of transparency and control. I need to now if my information is being accessed, and stored, and used. Apple has a responsibility for providing an API that allowed this, Rovio for leveraging it, and the users for unwittingly consenting. Organisations should be held responsible for clear declaration and transparency of their intentions and actions. As a developer you need user trust to be long-term successful.

Alex thanked Chris for going after Apple. RIM experienced A paradigm shift in their security policies as they began as a corporate service provider, and had to shift to be more consumer risk and concern aware.

Your mobile device management strategy should start with what you do for your non-mobile assets and laptops. The additional key considerations are physical security and loss, and the fact that usage of mobile devices is not often contiguous, so security credentials often get simplified for convenience of device use.

Consider the platform itself, the basis of all security should be imbedded in the platform itself. You users want to download applications, and in some cases need to, have a strategy for optimising the use of applications. Third, how are you going to manage the deployment of the devices. The more you mix deployment strategies to more overhead you create and risk of something going wrong.

Kofi noted that a bridge from user experience to security policy is one of the greatest challenges in BYOD.

Stewart opened with the dichotomy between mobile devices and laptops, in so much that BYOD didn't really kick in until the prevalence of smartphones and other related tablet technologies became consumerised. The desktop and laptop market is primarily one OS, Windows, some Apple, and a tiny bit of Linux. The mobile platforms are far more diverse, not necessarily in over-all count of players, but more so in the equal distribution of platforms and increased percentage likelihood you will need to support four OSs.

You don't plan to have a security breach, but when it happens you need to have planned. The question asked is what do we have to do to stay out of the news? The reality is that we wont stay out of the news, but more how do we mitigate that story so that it is less "news worthy" and we can control the story, instead of the exploiters.

Fundamentally, your policy will dictate your security. Rely less on protecting the device, and more on protecting the data.

While the EULA may technically grant access to your personal information, expectations around transparency and reasonable use make this a legal grey area in Canada and the US. The app developers and platform developers have a responsibility, but not legal obligation, to provide that balance.

Question arose of whether there is a comprehensive online list of what apps leverage what data from your devices. The answer is that not really, but the App Genome Project was a start on this that may have fizzled out by now. A different approach to this issue is to encourage the platform developers to provide the option for the users to restrict information access by app, by information type (i.e.: contacts, location, call history, etc.). This is a more likely technological scenario and the platform vendors should be marshalled in this direction by consumer demand.

The concept of protecting the data more than the device was challenged well from the floor, based on the assumption that people don't have the level of insight on what data is where, and what data is at risk, it is a much simpler approach to lock the device itself. Debate ensued around the dilemma of balancing usability of personal devices with protection of corporate and private data.

My personal opinion here is that if users secured the devices to protect their own personal data as much as we'd like our corporate data protected, then there would be much less of an issue. It needs to be a multi-pronged solution, including educating our BYOD users about the risks to their own data as well as the private data they become couriers of, and encouraging the OS vendors to enable security management functionality and control to the API level for the device owners, and lastly, leveraging presentation and virtualisation technologies to keep the actual information in the data centre.

- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

The impact of mobility, social networking, data breaches and intelligent analysis on privacy and organizational security

Michael Argast, Director, Western Canada, TELUS Security Solutions
(Esquimalt)
The impact of mobility, social networking, data breaches and intelligent analysis on privacy and organizational security
In a whirlwind 30-minute session, Michael will cover a wide ranging set of topics and talk about their impact on privacy, security and risk management. He will provide practical, straight forward advice on how to orient your organization’s policies and security investments to ensure privacy needs are met, while balancing open access, security and fiscal considerations. Topics covered will include bring your own device strategies, flexible workstyles, social networking, data breaches, change in threat profiles and more. This session targets those interested in privacy and security from a business or operational perspective.

Four trends Telus sees in the business environment:
Consumeraisation of IT
Evolution of personal workstyles and employee mobility
Need to provide enterprise employees with access to data that is behind and beyond the firewall
Unequalled customer service quality

Privacy in mobility and security...
Who should get to know who your friends are?
Xinga is facebooks biggest customer, you are the commodity facebook sells them.
Overall, all organisations allow employees access to facebook for personal use.
IOS applications have full access to your address book with no controls, other than access to publish in the app store. Security controls are being provided to consumers to control this, but the individuals need to stay on top of these threats to our privacy.

Who should get to know where you are and where you've been?
Again we discuss the location tracking concepts that are either published and acknowledged or not. Are there positive aspects to this information being available? Certainly, but consumer need to control the access that data.

Bill C-30
With a warrant requires backdoors to be built for browsing history and Skype, GoogleTalk, etc. may limit availability of tech services and applications into Canada due to cost.
Without a warrant, law enforcement wants a long list of PII.
The ALPR Automatic License Plate Recognition systems allow an officer to grab a license plate and do a system lookup. It leverages an MC grabber which grabs all cell phone information in a geographic area. Leveraged with Bill c-30, this gives police the ability to track the movement of all private citizens.

About 90% of IT security breaches are not discovered by the company breached, but by third parties who are using big data correlation to build socio economic profiles. What else are they doing with this data though? Corollary, that people with more security technology in place, report more breaches. They don't actually have more breaches, they are just more aware of the breaches occurring. So are you not only aware of who is coming in, but what data is going out to third parties?




- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

Richard Thieme - "Living in a Glass House when Everyone Has Stones"

Session 5 - Keynote Speaker

Richard Thieme, Author, Media Commentator and Speaker
"Living in a Glass House when Everyone Has Stones"
Identity-shift is well under way. When the context of our lives changes, all of the contents are jumbled, including who we think we are and meta-national structures. We can’t help thinking inside paradigms that emerged from prior technologies but we also can’t help acting as new paradigms demand. The end of secrecy and the end of privacy are two sides of the same coin. Hackers appoint themselves as a Fifth Estate, while security and intelligence professionals tell themselves a story that filters out as much reality as it allows in. But reality won’t go away, and protocols, policies, and legalities lag behind. Add “biohacking” to the mix and the weird turn pro, pros feel weird, and ... what can we do to stay in the game?

Richard introduced the importance of cross-disciplinary learning, and the networking concepts that support this, and that we don't need to know everything, but just how to get that knowledge.

A checklist of everything in the "cyber arsenal" and motivations that should scare us was worked through,

A black hat hacker is a hacker. A grey hat hacker is a wily hacker who will manipulate the truth. A white hat hacker is one who put the truth down somewhere and forgot where it was.

Nation state no longer means what it once did, the boundaries were drawn for purposes that have since disintegrated, as the speed of information flow and complexity of socio-economic boundaries have shifted dramatically.

Human rights did not exist until it became an emergent property that the majority agreed upon; the same is the case with individual intellectual property rights. This was projected as a cognitive artefact that we accept as a reality because we were raised with the concept. The masses become religious about those who provide them the cognitive artefacts - see Steve Jobs as an example.

The new technologies will continue to stretch us and allow us to be redefined in new ways and improve ourselves. New social attacks don't require the technology, but as the majority becomes more dependent on technology and social networks. Inference attacks can move people unwittingly to a conclusion they don't hold, because analysis of vast quantities of data the 80% has provided has given the information to be analysed and concluded in a new social attack.

We need to allow ourselves to shift to the first 10% of the bell curve and see what is coming down the road before the 80% in the hump. We need to not be stuck in the cognitive artefacts we grew up with, to protect ourselves and those we care about from the threats shared in the beginning.

The DYIBio is the next revision of social engineering, and it only takes someone with the mental state of a suicide bomber to create a

We need to keep the cognitive dissonance at the right level to use the real fears to motivate us, and the unreal ones from crippling us; even if the unreal ones occur we can be prepared to adapt.

We need to not be afraid to be honest about where we are, where we need to go, and get business and government leaders to accept this and commit the funds to move us to the right places to manage the risks. Be mindful, be supremely aware, and be vigilant.






- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

Telus - The Impact of Disruptive Technologies on Data Protection

Keynote Luncheon Address
(Salon AB)

Ken Haertling, Chief Security Officer, TELUS

The Impact of Disruptive Technologies on Data Protection
In 2011, the industry witnessed an unprecedented year of security incidents and privacy breaches. In 2012, organizations are faced with the further proliferation of mobile devices/tablets and initiation of bring your own device (BYOD) policies. This will lead to the further co-mingling of personal and private data on joint-use devices. Meanwhile, with the addition of these devices and the erosion of the traditional network security perimeter, the enterprise network is no longer as trusted as it once was. Organizations cannot ignore other disruptors such as off-shoring, cloud computing, and virtualization that may further expose sensitive data. Ken will explore popular coping strategies and discuss which, if any, are likely to succeed.


Core to the disruptors is the movement of data outside the traditional geopolitical boundaries, outsourcing and offshoring. Commerce will drive work toward least cost providers, and businesses take an open view toward what is considered core.

Another core disruptive technology to security and privacy is employee mobility, and the advent of device mobility.

BYOD or tablet grows the concern of more personal information risking transport over potentially risky networks outside the workplace and being saved amongst personal data on a mobile device.

Last disruptor is the concept of cloud computing and storage. Centralising should provide economies of scale, but there is an increased loss of control over data and information.

All in all, data is moving outside of organisational control and into areas of greater exposure to risk of compromise.

You can't start your strategy with picking tools, but instead understand your data. Understand the threat, data, and people; this is data classification which helps understand what is critical data.
A surgical application of data security controls is key to success in this initiative. Pick the key systems and data flows, and focus on those. Use encryption, but also tokenization and obfuscation. The latter two can be more effective. Study internally by Telus indicated that 10% of the organisation needed 80% of the critical data, allowing a focus for policy and governance work.

Network segmentation and perimeter hardening is important from an architectural perspective. Most networks today are quite flat, and must be better segmented. Internal employee networks should not be fully trusted to allow unfettered access to core systems. The focus on privacy and security should be on the data centre first, and include an architectural philosophical extension beyond the network to the data and application layers.

The question was asked how many in attendance have some form of security solution enabled on their mobile device. The response was a very small percentage.

There are two approaches Telus uses to securing mobile devices.
Containerised and non-containerised. Containerised separates personal and corporate data, corporate data being in a secured container. Remote policy enforcement is leveraged, and device full capabilities are limited. Non means that the entire device is encrypted and managed centrally. In either case there is a strong push at the data and application layers to ensure that data is not pushed to the mobile device if at all possible.

A virtualised environment provides the ability to greater control where the data resides, and give views into the data for classification purposes. However, the risk is that much more importance needs to be placed on credentials and user identity, as the keys to the kingdom are more widely distributed, and the data is more centralised.


- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

Sensitive Data: The Electronic Health Record

Panel B: Sensitive Data: The Electronic Health Record
(Theatre)
Moderator: David Flaherty, former Privacy Commissioner of British Columbia
Speakers:
1. Mimi Lepage, Executive Director, Information & Privacy Policy Chief Information Officer Branch, Treasury Board of Canada Secretariat
2. Khaled El Emam, Canada Research Chair in Electronic Health Information, University of Ottawa
3. Marc Smith, Senior Information Management Specialist, SAS
4. Lorraine Dixon, Senior Manager/Privacy Officer, Oracle Canada
5. Leroy Brower, Assistant Commissioner for Policy and Adjudication, Office of the Information and Privacy Commissioner, Province of British Columbia

Started with a vote as to who is a fan of the electronic health record, the audience was evenly split.

9 institutions at the federal level have legitimised access to your EHR.

Secondary uses of the data is big data processing for optimising health care delivery, data is released and shared, and we trust it is done responsible. The data should be anonymised or de-identified, but how do we know this is done with our data?

Mimi LePage cited an example in Ottawa of how effectively health information flowed from an MRI to the correct health practitioners from primary care to specialists.

Closer to home, an example of a cancer patient had excellent service while the attending was dealt with within the BC Cancer Agency, but information did not flow well to other health care services, so when there was a complication there was an extensive delay in response that might have been fatal. While dramatic, the point being that distributed EHR/EMR systems and practitioners not leveraging EMR/EHR create information gaps, as the assumption becomes that "everyone who needs your information will get it.".

Sensitivity of the data was discussed; this might seem obvious to those of us in health care, but some concrete examples of PHI as sensitive, biographical core information were given as stigmatised conditions, prescriptions, and other aspects of non-benign conditions. The panel debated on whether PCI or PHI was more sensitive; the consensus was that both are, and both must be respected at least equally, and the priority seems to be based on which is currently at more risk in the eyes of the individual.

Discussed ownership or control over our PHI. The Lab Info System of BC has your data if you've had a lab test, private labs like LifeLabs have their proprietary system, but this is being folded into the central system later this year. This information is no longer yours.

David asked the panel what the best defence in controlling your information is, and the response was that we must understand what is being released, and how it is protected. All your medical information is highly correlated, so hiding or encrypting one piece, such as a diagnoses, but leaving lab results, or treatment, still makes the locked information highly predictable. So the value of locking parts of the correlated data is minimal if not de-identified for secondary uses. Patients overly concerned with privacy have the right to have information not entered into EHRs, but this risks future health.

A case study of in patient teenagers on use of facebook indicated that they would not use facebook to share information about their current health as they wanted to be viewed as "normal" to their peers. These same teenagers were very conscious of facebook privacy settings as opposed to their peers, and used facebook to communicate with their health care practitioners via facebook messaging.

The concept of lockboxes in Ontario healthcare EHRs was discussed, and studies have shown that few health care providers actually have educated patients of their rights. Disclosure Directives are the BC equivalent; labs have been given posters and bulletins to share with clients, and information is available on the govt of BC website. This has had a very small uptake, and only certain health communities with stigmatised conditions have shared the information heavily. This does not apply to private data collections of private labs.

The panel was asked to weigh risks and benefits, and provide their over-all opinion of the value of EHRs.

the Canadian Health Ways motto of "knowing is better than not knowing" was cited, but importantly stressed that control over who is accessing what information and for what purposes is vital. This does give us reason to worry, and the controls and governance is critical, but governance and controls without enforcement and management/monitoring is ineffective for those who truly wish to abuse the access. It seems there is still no good answer to how do we actually police the use of these systems. You have handed this information into the trust of the public service and their private agents, and we need to ensure we hold the public sector accountable for what they do with it.

Examples of Alberta's provincial EHR failures would include the citizens not knowing about or how to mask their data, and more so, that a high percentage of the physicians are also ignorant of this. Benefits would be the provincial financial benefits of the secondary use of the data to reduce fraud, and improve service delivery.

The question came to the panel of whether they support 3rd party access (such as the RCMP or other police agencies) to EHR data for public safety purposes. The response from the panel was mixed, the primary concern against was the slippery-slope argument. This brought up the lawful access debate on federal Bill C30. It was an example of public backlash against concerns over privacy being successful. Correlating data across different health agencies or institutions could be considered for lawful disclosure, and limited to health care service works, perhaps the definition of what is health care service provision needs to be addressed. Breakdowns in social working systems were suggested as being fixed by leveraging wider access to HR data, but this seems like a knee-jerk reaction that must be considered beyond the emotional reaction for an instant fix, and elevated to finding the right solutions, governed by the right policies.




- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference

The Repo Men Reductio Body EULAs, Privacy and Security of the Person

Ian Kerr, Canada Research Chair in Ethics, Law & Technology at the University of Ottawa
(Salon AB)
The Repo Men Reductio Body EULAs, Privacy and Security of the Person
Recent medical advances allow us to transcend biological limitations through the implantation of microchips, digital body parts and artificial organs. However, surprisingly little thought has been given to the ethical and legal aspects of their design and use. In this keynote address, Ian Kerr, Canada Research Chair in Ethics, Law and Technology, examines current ethical and regulatory approaches that govern medical devices and argues that the existing paradigm of mass-market consumer goods is not particularly well suited for the health sector. His primary concern is that individuals are increasingly called upon to sign complex contractual documents that diminish privacy and autonomy not only as users of mass market consumer goods but, now, as medical patients. Drawing on lessons learned in the field of privacy and information technology law, he suggests that special considerations are required in the healthcare context to ensure that patient autonomy and privacy are adequately protected in an era where our bodies are becoming inextricably tethered by devices and software owned by health care providers in partnership with industry

Ian Kerr's premise is that the digital drives the mechanical. This covers the human-machine merger. We are implanting more equipment into our bodies, and giving machines more personification.

Digital body parts, and prosthetics; questions implicate the security of the person, beyond simply privacy concerns. Reductio ad absurdum almost seems an easy way out of the debate, except that things have already moved well beyond science fiction.

"Building Better Humans" is the course he teaches across North America in prestigious universities. The topic revolves around enhancement based medicine, intended to make us "better than well." The trans-humanist movement includes deliberative selection, not natural selection, including the use of artificial organs. Current examples are ventricular assist valves that can replace the need for a heart transplant, insulin pumps which replace the need for a pancreatic system, and cochlear implants for hearing.

A cochlear implant is an interventionist technology, as the change required to the auditory nerve is a one way road; the nerve is severed and this is a permanent change.

The book "My Bionic Quest for Bolero" summarises how the cochlear implant improved hearing beyond normal human capabilities to distinguish more discrete differences in frequencies.

What is the social model that goes along with this change in our technologies impacting our society?
There are politics infused in the architecture of these technologies.
This represents the cultural genocide of the deaf community. This implies that this group is broken and needs to be fixed. Political decisions are built right into the design of these technologies.

Reference to Alexander Graham Bell, his wife and mother both being deaf, and his political view of deaf culture was to assimilate deaf people into the society of those who could hear via hearing assist devices.

Discussion now shifts to the techno legal model. Prof Kevin Warnick has engaged in a number of experiments with a neural transducer. Placed in his arm, this "router" intercepts the signal and routes the signals to the Internet and to a robotic arm that performs the desired actions.

We live in a world of ad hoc sensor networks and wi fi. Devices we carry interact with each other, without our knowledge or permission. What are the implications?

Implantable devices and personal area networks have privacy implications, as the nature of the information we exchange intentionally or unknowingly changes. Our physiological information is also moving over the PANs and subject to the WANs.

IPV6 would allow us to provide 7 unique identifiers to every atom in every human body.

Process for getting a cochlear implant includes a consent to a contract with the vendor for warranty; effectively a terms of services agreement for the technology implanted in your body.

The business model for medical devices, is the exact same model for mass market consumer products. These devices are being regulated the same way your iPod is regulated.

There is a proprietary nature to these devices, but are the EULAs appropriate given the actual use? For software and hardware, these are take it or leave it bargains, where the consumer's choice is summarised by mandatory volunteerism. Fictional consent mechanisms imply a consent, contract where both parties have negotiating abilities, this should be offensive to each of us.

EULAs by default are not privacy friendly.

We should have freedom of contract, even more so, as the technologies enter our bodies, we need freedom from the contracts.

"End user licenses are becoming the rule, and those who draft them are becoming the rule makers." - Ian Kerr

Showed us the terms and conditions agreement you must sign to agree to get a bionic ear, which includes voiding a support if there is unauthorised maintenance or work on the device, putting you at the mercy of the manufacturer for a part of your body irrevocably implanted.

We need to be aware of our digital rights.


- Posted using BlogPress from my iPad

Location:13th Privacy & Security Conference, Victoria BC

Cory Doctorow and the Privacy Bargain

Cory Doctorow, Science fiction novelist, blogger and technology activist. Co-editor of weblog Boing Boing (boingboing.net), and contributor to The Guardian, the New York Times, Publishers Weekly, and Wired

Internet giants will tell you that they're participating in a "privacy bargain" where consumers trade privacy for services. But it's a funny sort of bargain that involves Internet users giving up everything, with no ability to dicker --- not even the ability to see what they're giving up and to whom. What if we gave Internet users the power to decline an offer? What if we changed the analytics shooting war so that the users were armed, too?

Cory started and discussed the Kim Possible game that Disney put in place in Florida. Kids are given mobile devices and actually inverse the common social media model, by making the humans the sensors, as opposed to the sensed. Private information is put into the hands of the users in this model.

GalaxyZoo & Google Page Rank are examples of crowd-sourcing where humans do what they are good at - making decisions, and computers do what they are good at, counting decisions. We cant rely on computers to make decisions for us as to what we should or shouldn't give away online. They can be tools to facilitate this, but humans need to be empowered to leverage the tools.

Discussed facebook's privacy "policies" and the concept of making terms and agreements confusing and obscure, which at the end should be "we'll give you this service for this information." It's all the mechanics of a rigged Vegas game. It's the same mechanism used to program slot machines for limited payouts to keep people addicted to their use.

It is a deliberate strategy.

How should we price our privacy?
What are the consequences of giving out our privacy?
Related story of person having a child giving child's name and birthdate to a marketing company in return for a basket each year. Child died shortly after, but baskets kept coming each year - what is the personal impact of that divulgence of privacy?

Introduced the concept of having an interest, vs. property rights with respect to information. Discussed Bill C30, SOPA act, and other aspects of privacy and ownership debates over information.

What about pop ups? They were prevalent, until Mozilla blocked them by default. technology was the impetus to kill that invasion of privacy. Cookie managers could be the new version of this concept.
As a case in point of why changes need to be made to make this feasible, try creating new users in browsers, and turning on "ask me every time" for cookie acceptance; you will be overwhelmed in a short amount of time. The impact to your Internet experience will drive you to simply accept them. This can be addressed by browser design by more easily managing cookies; managing cookies would be a key way to give the populace informed consent to the trade of privacy for service.

Users have come to the gunfight with analytics and advertisers with a wooden stick.

A call for people to be realistic about what the cloud can and should do, what information is reasonable to stream? What information is reasonable to have conglomerated into a single physical space that provisions the virtual space? What is the risk of the mash-up of the data?

The public needs bargaining chips in this war on our information. Android has an app/feature that allows you to lie to apps that are asking for your personal information. This mod feeds junk data to privacy sniffing apps, and arms the consumer to fight back against draconian imperialist forces.

Questioned on his stand on jailbreaking. Compared to alchemy, and the risk of having to learn everything over and over. Stated that alchemic operating systems that are illegal to break the "copyright" are equivalent to an engineering firm designing a building and disclosing anything about the design of the building. Case in point was audible.com policy of proprietary file format for audio books being enforced, and giving no flexibility, and in fact, removing the copyright of the author de facto. Discussed CarrierIQ being detected first on Android, due to the open aspects of the OS. People were able to learn that our privacy was being violated because the OS allowed inspection and transparency into what was installed and happening on our devices with our information.

Discussed the workflow for managing your personal information on the web. The browser would need to examine the cookies for "questionable" requests, and block them like email clients block images, and allow you to have an insight into what cookies you will trust and or distrust. A blacklist can be created in public crowdsourcing that leverages communal intelligence and experience.


- Posted using BlogPress from my iPad