Tag Archive for Privacy

Privacy on IPv6 Networks

Privacy on IPv6 Networks

Internet service providers, websites, and equipment vendors around the globe took part in the World IPv6 launch in June, Internet companies including AT&T (T), Cisco (CSCO), Comcast (CMCSA), Facebook (FB), Google (GOOG), Microsoft (MSFT), Verizon Wireless (VZ), and Yahoo (YHOO) decided to permanently turn on IPv6. A small fraction of Internet users and devices have started communicating via IPv6 networks, with more and more transitioning to the new protocol over the coming months and years. There are security and privacy implications in the switch to IPv6.

IPv6All kinds of devices will get new IPv6 numbers as the addressing format grows. The IPv6 addresses for these networked devices can be generated in a number of different ways and the choice of how they are created has potentially wide-reaching effects for security and privacy Center for Democracy & Technology explains. One of the original methods for assigning new addresses involved using a unique device identifier (known as a MAC address) as the suffix of the IPv6 address. This method creates a permanent, unique address for a device, potentially allowing any server that the device communicates with to indefinitely track the user.

IPv6 designers soon realized the potential security and privacy problems of MAC-based addresses; as a result, they created an alternate method known as “privacy extensions” or “privacy addresses” the article reports. The privacy extensions use a randomly generated number instead of a MAC address. In order to protect privacy on an IPv6 network, the random number is unrelated to any device identifier and in practice lasts no more than a week (and often much less time), ensuring that the user’s IP address cannot be used for long-term user tracking.

SmartphoneIt is up to operating system vendors to choose which IP address assignment method will be the default on their devices. The author says that some vendors have made good choices, particularly within the last year. Microsoft has long led the charge on IPv6 privacy, with privacy extensions on by default in all versions of Microsoft Windows since the release of Windows XP nearly a decade ago. Apple followed suit last year, with privacy extensions activated by default in all versions of Mac OS X since 10.7 (Lion) and with the release of iOS 4.3 for iPhone and iPad. Google did likewise in its Android 4.0 release last year.

The CDT says that as long as Internet users choose to upgrade their operating systems to the latest versions, they should be protected against perpetual security and privacy threats from IPv6 network address tracking.

rb-

mobile OS's send private information about their users to the networHowever, I wrote about reports from H.Security that mobile operating systems do not protect security or privacy on IPv6 networks. The report says mobile OSs send private information about their users to the network. The H.Security article says this is not a flaw in IPv6, rather it is lazy programming in some cases. The article points out that neither Apple’s iOS nor Android devices have the option to enable Privacy Extensions or the option to disable IPv6. apparently, the only thing smartphones need is a control option in the user interface to protect mobile OS users’ privacy and security on an IPv6 network.

Related articles
  • Romania Has the Fastest IPv6 Adoption Rate (maindevice.com)

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Credit Agency Trawls Facebook

GigaOm has an article that documents the efforts by Schufa, the largest credit rating firm in Germany to mine data from the Facebook (FB), LinkedIn (LNKD), and Twitter accounts of its customers. David Meyer cites documents leaked to German media, that the firm whose slogan is “We Build Confidence” would use the information “to identify and evaluate opportunities for and threats to the company.

“It cannot be that social networks are systematically scoured for sensitive data, resulting in credit ratings of customers,” said consumer protection minister Ilse Aigner.

rb-

Get over it.

Facebook logoI wrote about firms like RapLeaf mining social networks for employers and banks back in 2010. What is surprising to me and Mr. Meyer is that this latest social network mining operation comes out of Europe and especially Germany, a country where most people are very conscious of data protection concerns.

This goes back to the internet-age-old issue of privacy. Where is the line between public and private is it different for some groups than others? Do the NSA, CIA, MI5, and whoever else is listening get different access to data than Rapleaf, Apple (AAPL), Facebook, Twitter?

Just because the info is out there, public by default do they have the right to use it?

Get over itOn the other hand users of Facebook and Foursquare happily tie their credit cards to these accounts, post status updates, and check in to places for the world to see.  

Maybe we are just getting what we deserve.

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedIn, Facebook, and Twitter. Email the Bach Seat here.

States Collect More School Kid Data Than Needed

States Collect More School Kid Data Than NeededStates often collect far more information about school students than necessary and fail to take adequate steps to protect their privacy, a national study by Fordham University concludes. The Washington Post reports that dossiers go far beyond test scores, including Social Security numbers, poverty data, health information, and disciplinary incidents.

PrivacyThe study from the Fordham University Center on Law and Information Policy casts light on data systems created at the urging of the federal government to track student progress. One finding: States often fail to spell out protocols for purging records after students graduate.

Ten, 15 years later, these kids are adults, and information from their elementary, middle, and high school years will easily be exposed by hackers and others who put it to misuse,” said Fordham law professor Joel R. Reidenberg, who oversaw the study. States, he told the Washington Post, “are trampling the privacy interests of those students.

No Child Left BehindThe movement toward statewide databases with unique student identifiers, rooted in the standards-and-testing movement of the 1990s, has grown significantly in this decade under the federal No Child Left Behind law and is getting a fresh push this school year from the Obama administration. The article says federal officials want to link student test scores to teacher files to help evaluate instruction. They also envision systems that track students from pre-kindergarten through college, to help raise college completion rates.

Nearly all states, have built or are planning virtual education “data warehouses,” aided by federal funding. Advocates say the warehouses have strong privacy protections, but they acknowledge potential shortcomings according to the author.

Data miningIs there data collected that’s not necessary anymore?” asked Aimee Guidera, executive director of the Data Quality Campaign, based in the District, which is funded by the Bill and Melinda Gates Foundation, among others. “Probably.” She cited Kansas and Tennessee schools as leaders in establishing rules for data control.

But a larger concern, Guidera said, is that states often lack “a strategic, thoughtful way of connecting information and using it to answer questions.

The Fordham study canvassed public information on state data systems and compliance with federal privacy law writes the Washington Post. Among the findings, at least 23 states note reasons for withdrawal from schools such as jail, illness, or mental health issues. At least 22 count student absences. At least 29 track whether students are homeless.

Data theftThe study also found that at least 16 states use or allow the use of Social Security numbers to identify school students and at least 10 note whether a student is a single parent. Another finding: Florida, Kentucky, New Jersey, and North Carolina track the date of a student’s last medical exam.

The Washington Post says Fordham recommended that states tighten protocols to keep data anonymous, with special provisions for those in local schools who need to know more; that they articulate reasons for collecting data and jettison what is unjustified; and that they appoint officers to oversee compliance with state and federal privacy laws.

Charles Pyle, a Virginia Department of Education spokesman, said data are protected through policies and programming that prevent unauthorized access. The data help the states comply with NCLB, he said, and help pinpoint student needs. “You need a statewide system to keep track of the kids,” Grover Whitehurst of the Brookings Institution, told the paper. He oversaw education research for President George W. Bush’s administration and claims, “Otherwise, they fall off the screen.”

rb-

The lackadaisical attitude toward data security and privacy I see in K-12 amazes me. This article tells me it’s a national problem. – Why don’t I feel any better about that?

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

How-secure-is-my-password Tells You

How-secure-is-my-password Tells YouThe former DownloadSquad points out howsecureismypassword.net. How secure is my password is basically like a full-screen version of one of those password-strength meters websites sometimes use. But instead of showing you a bar going from “weak” to “strong”, it shows you an estimation of how long your password would take to crack. That’s a much more visceral way to understand why your password is strong.

How Secure is My Passowrd

rb-

How secure is my password helps make password best practices meaningful.

For example, when I entered “Detroit”, it came back with “your password is one of the 1090 most common passwords. It could be cracked almost instantly.  “D3troit!” would take 57 days, and “!D3tro1tM!” would take 928 years to crack.

Password best practices include using:

8 or more characters, that is not a dictionary word, which includes capital letters, digits, and a symbol or two.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

LinkedIn Pulls A Facebook

LinkedIn Pulls A FacebookBusiness social networking firm LinkedIn made me get out of my Bach Seat and jump up and down this morning, LinkedIn (LNKD) pulled a Facebook and made a sneaky change to the terms of service that made user’s names and photographs available to advertisers if they want to use them.

Thankfully BrandImpact tells how to keep up your privacy.

  1. LinkedIn logogClick on your name on your LinkedIn homepage in the upper right corner. From the drop-down menu, select “Settings.”
  2. In the “Settings” page, select “Account.”
  3. In the column next to “Account,” click “Manage Social Advertising.”
  4. Uncheck the box next to “LinkedIn may use my name, photo in social advertising.”
  5. Now check the new default settings under “E-mail Preferences” and “Groups, Companies & Applications.” Make sure to opt-out of “Data Sharing with 3rd-party applications” as well.

In the face of negative user reactions and a growing media firestorm, LinkedIn has decided to make a change in the policy. That’s a step in the right direction. I have written about social networking’s assault on privacy here, here, and here.

rb-

Even though LinkedIn has backtracked on this it still irks me. I believe that most people on LinkedIn are working on their professional brand and do not want to be associated with ads. Facebook is for kids who don’t care, LinkedIn was for professionals. This seems like LinkedIn is wasting the goodwill they’ve built up over the years as it tries to justify its $9 billion IPO valuation. This is not a good sign for LinkedIn, I doubt they can beat Facebook in the teenie-bopper social network segment.

What do you think?

Are you concerned about your privacy on Facebook?

View Results

Loading ... Loading ...
Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.