My Pages

Showing posts with label confidentiality. Show all posts
Showing posts with label confidentiality. Show all posts

Tuesday, 20 February 2024

Privacy in a world of extroverts and exhibitionists

When is it too much?

It is interesting when you encounter invasive disclosure requirements that leave you wondering if you have become overexposed and vulnerable.

You meet a fine line and distinction that probably is left to gut instinct as to how you respond and what you are willing to give away. For instance, when over a decade ago the gap in my employment was predicated on the need for cancer treatment and recuperation, I offered to present a medical note from my consultant, but the employer instead requested my medical prescription.

For me, that was egregious and intrusive, I could find no rationale for such a request. Then again, I half appreciated that the request was being processed outside of the boundaries of Europe even as the job was in the UK and I lived in the Netherlands. Much as I could have challenged the request further than I did, I felt that this kind of unwarranted intrusion was not only adverse but that the cultural norms of a certain domain had not cultivated the understanding of elements of privacy we Europeans were accustomed to.

Handling the issues with tact

I soon removed myself from the process and declined the offer because we had reached an impasse beyond which there was no viable future in which I would have felt comfortable.

Indeed, the issues of privacy, secrecy, and confidentiality work together to protect the person we are, having the confidence that you only need to share what is necessary for the sake of meeting a requirement without losing the mechanisation or automation of expediency. I still believe even as a technologist that traditional methods of handling private data have better checks and balances that are less susceptible to unfortunate biases.

At other times, it is being embarrassed by circumstances engendering almost a sense of shame or failure, but these are all part of the story of life if systems are allowed to spare our blushes.

I hope I still have some control

I consciously curate what I am ready to reveal and share, I have faced some challenges that have required inspiration and dare I say of divine provenance to address certain requests. Important in all of this is being open about very significant elements of myself that half a century ago would not have been possible and is still detrimental in some countries and regions around the world.

Where you do not want to be is realising you have lost control of your own narrative in the quest for something you desire, but not at any price.

We have such wide-ranging diversity and have encountered serious adversity at various times, yet we are who we are with all that pertains to who we are and the relationships we hold dear. We understand responsibility and loyalty and appreciate the quality of character while striving for a better world in whatever place we might find ourselves.

I guess I am grateful for understanding and being understood. Even the most interesting and good books need covers, and the most beautiful windows do at times need the curtains drawn. Between the exhibitionist by inclination and the spectacle by duress, neither should be the only choices about how we choose to tell our stories if we are not fully persuaded.

Tuesday, 11 May 2010

Facebook: From figleaf privacy to fully dressed discretion

More Facebook about-face

Many of my friends and readers of my blogs would have read a number of postings about my experiences with Facebook.

There is no doubt that Facebook serves some purpose, I now have connections that date back to primary school about 40 years ago, a good number of secondary school friends are back in my social circle and I am also in contact with close and distant relations along with different acquaintances from all walks of my life.

In that way, Facebook provides a rich social networking experience, the problem arises when having put in all the information that creates the conditions for making, renewing or reestablishing connections you find that you have minimal control over who get access to that information.

Your privates are exposed

Facebook is a sponge for every detail of your life and everything you inadvertently put in can become global knowledge beyond your relations and friends to potential employers, detractors or worse.

Facebook itself is not known to have exemplary ethical conduct in the management of the privacy of its patrons, the company is in flux trying to determine who all this information from over 400 million accounts can be commercialised and monetarised without us having a say over what get push to us by our details or as a result of our relationship.

AllFacebook.com recently posted an article on how the default privacy settings had changed on Facebook between 2005 and April 2010 – I winced at how exposed I had become, it was like an involuntary strip-tease as you clothes were ripped off till I was left with the postscript of a tweet I posted – You only have a fig-leaf for your privates.

The animation of that graphics were originally published by Matt McKeon with the title - The Evolution of Privacy on Facebook – He includes information on how the data was sampled and the comments that follow do help one understand what might be at stake.

Rapidly evolving rules

What is driving the quest for more privacy and sometimes the exodus from Facebook is that the Terms of Service and rules are changing rapidly in favour of the company just exposing more and more of our information in the name of helping more social interaction – nothing could be further from the truth about that.

Personally, I have been actively locking down areas of information that I have put on Facebook just because I do not have much control over where all that information might end up.

Now, for those who are not as technically savvy or understanding of the finer details of privacy, secrecy and confidentiality – if you may know, these words are not synonyms, they mean completely different things, but you have to secure your privacy, manage your secrecy and definitely do not trust strangers with information you feel should be confidential – the underlying question being who can you trust with detail about what you like, what you do and what you’ll rather not share.

How to …

Jason Perlow, a writer for ZDNet; a technical magazine offers some advice in a video which can be very helpful in Lock Down Your FaceBook Profile in 20 Minutes (Video) – some of his suggestions take it to the extreme with the assumption that only friends that already know you are your default contacts, but you need to leave in enough information to distinguish you in some way to old friends like schools and other basic historical information.

You need something to network with but be smart about what you leave in, what you take out and in a more granular setting create lists of most trusted friends and give them more access whilst closing access to others.

Let us use Facebook for what we have intended for it to help us do, link up with friends and family and thwart attempt by the behemoth to convert our precious relationships into filthy lucre.

One piece of advices you should take away from this is to check your profile every month to see that it is still as watertight as you want it to be as Facebook shape-shifts around your privacy. Use Facebook but do not let it use you unethically and unfairly.

Sources

[1] INFOGRAPHIC: The History Of Facebook’s Default Privacy Settings


[2] The Evolution of Privacy on Facebook


[3] Lock Down Your FaceBook Profile in 20 Minutes (Video) | ZDNet

Tuesday, 15 August 2006

Was that the Real Story?

When documentaries sensationalise rather than educate
I did not see the Real Story episode that was broadcast last night, but the snippets that were shown in the news stories during that day did have a touch of sensationalised histrionics to it.
It is a well-known fact that certain enterprising but dishonest Nigerians have been involved in what is known as Advanced Fee Fraud or 419 in the local parlance.
Part of what I saw showed a raid on an Internet café in Nigeria where officials of the EFCC (Nigerian Fraud Squad) had everyone vacate the computers; they asked everyone to put up their hands facing the walls and then as one of the suspects remonstrated an EFCC official assaulted the man with a slap in the face commanding him to shut up.
This is a poor reflection on the Nigerian criminal justice system that suspects can be assaulted but law enforcement agents with impunity and very little recourse for justice.
My take on 419
Back to 419 - This is where using the human susceptibility to greed and gullibility, a victim receives a request to supposedly launder ill-gotten gains from bogus contracts or stashes of frozen sums of money by providing their bank account details and paying an upfront fee for the administration of the process. Some are so sophisticated in their ploys that it becomes too good to be true – anything that has that feel to it has my radar homing in on something fishy.
Many have fallen for this get-rich-quick scheme and lost large sums of money, but I have no sympathy for both the perpetrator and the victim, they were both about to engage in a criminal act. However, there are cases where the contracts do look real, but when you are about to invest money, especially in Nigeria, you have to have your wits about you and seek an independent, impartial review of the whole thing – involve lawyers and investigators you can trust before you part with your cash.
The Real Story episode revealed that people’s details were being sold for as little as 20 Pounds, the details were supposedly gleaned of hard disks which would have been in used and second-hand computers exported to Nigeria.
Your details can be used anywhere
The fact is the information on hard disks can be read in any country and can be used by any set of criminals either in Nigeria or elsewhere. Having completed a module on Computer Forensics, I am very well aware of the fact that it takes a lot more to delete data off a hard disk.
There are tools to recover long removed data and special tools are required to wipe hard disks to the security standard of the Department of Defence, in fact, in most cases, the hard disk would be melted if the data that it once contained is considered secret.
Besides, identity fraud is probably an issue closer to home than in faraway Nigeria. All you have to do to rummage through a bin and find letters, bank statements, if not credit card PIN slips that give enough information about a person – this is called bin raiding – a further search on the Internet can reveal birth date, birthplace and parents if the genealogy, census, birth, marriage and death registrations are online.
A letter posted to my cousin in England from Nigeria some 20 years ago ended up in the hands of a lodger who used that information to obtain a National Insurance number in my name – so identity theft does not have to be so complicated or sophisticated.
Developing a sense of security to protect privacy
People who generally would lock their doors when they go out and pull the curtains to keep prying eyes out, apparently, do not apply the same principle to their information, data, computers and personal details.
Everyone who receives a letter of any importance must invest in a paper shredder and shredders do have different security ratings from strips to pulp – I never dispose of any paper that has not been shredded and I have been doing that for at least 7 years.
Your computer when online is like an open door with drawn curtains and open windows; you need more than just any popular anti-virus software because virus developers test their malevolent programs against popular anti-virus software to prevent detection.
The general idea is to develop the fortress principle to your computer, an outer wall (a firewall), the doors and windows (an anti-virus software) and then the protection of valuables within the home (malware detectors).
Use good tools
In my case, I do use a hardware firewall found in my wireless router and enable the software firewalls on all computers, I have installed the well known McAfee VirusScan Plus and Trend Micro PcCillin Internet Security ensuring that the updates run every day at night.
Malware is software that gets installed inadvertently on your system through opening a suspicious email or visiting an innocuous web site, they can install key loggers which record all the keystrokes you have typed and send that information to a harvesting system where the information can be replayed as if it were you logging on to your bank account or some other security service. These are really the identity theft perpetrators.
I use Lavasoft Ad-Aware and SpyBot – Search and Destroy, with all that attention to detail, I still find that a keylogger still ends up on my laptop every few days – you just need to keep ahead of the criminals – time after time.
In addition, to remove all references to sites, I have visited and files I have opened on an operational system, I use CleanUP.
If you are done with your computer, you can recycle it, but before you do, search for a secure hard disk deletion tool as this write-up suggests – Purge hard drives before recycling.
Common sense approach to social engineering
In all, you have your identity to protect, ensuring that the people privy to your secrets are authorised to access that information with discretion under the contract of confidentiality, not of which should violate your right to privacy.
Where people, emails or forms ask for information that should be personal and known only to you like your PIN numbers, do not under any circumstances reveal that information because that that time you would be seriously compromised – they might want information about who you are where name, address, date of birth and account number might suffice, but that should only be divulged to those your have ascertained through obtaining their own details first.
Always err on the side of caution, err of the side of keeping the information than giving it out.
References