<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Applied Miscellany &#187; Identity Theft</title>
	<atom:link href="http://www.appliedmiscellany.com/blog/archives/category/identity-theft/feed" rel="self" type="application/rss+xml" />
	<link>http://www.appliedmiscellany.com/blog</link>
	<description>Technology, Tech Policy, Internet, Gadgets, Software, ...</description>
	<lastBuildDate>Tue, 15 May 2007 12:07:19 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Stock Up After 45M Card Numbers Stolen</title>
		<link>http://www.appliedmiscellany.com/blog/archives/39</link>
		<comments>http://www.appliedmiscellany.com/blog/archives/39#comments</comments>
		<pubDate>Thu, 29 Mar 2007 17:45:10 +0000</pubDate>
		<dc:creator>Scott Karlin</dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://www.appliedmiscellany.com/blog/archives/39</guid>
		<description><![CDATA[I thought it was particularly interesting to read the first paragraph and then the last paragraph of today&#8217;s AP article (as seen in the New York Times) reporting of the security breach of TJX Cos, the owner of T.J. Maxx and Marshall&#8217;s stores.  First paragraph:
Information from at least 45.7 million credit and debit cards [...]]]></description>
			<content:encoded><![CDATA[<p>I thought it was particularly interesting to read the first paragraph and then the last paragraph of today&#8217;s AP article (as seen in the New York Times) reporting of the security breach of TJX Cos, the owner of T.J. Maxx and Marshall&#8217;s stores.  First paragraph:</p>
<blockquote><p>Information from at least 45.7 million credit and debit cards was stolen by hackers who accessed TJX&#8217;s customer information in a security breach that the discount retailer disclosed more than two months ago.</p></blockquote>
<p>Last paragraph:</p>
<blockquote><p>TJX shares rose 51 cents, or 1.9 percent, to $27.01 in morning trading on the New York Stock Exchange.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.appliedmiscellany.com/blog/archives/39/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RFID Passports &#8211; Hi, I&#8217;m a Foreigner</title>
		<link>http://www.appliedmiscellany.com/blog/archives/27</link>
		<comments>http://www.appliedmiscellany.com/blog/archives/27#comments</comments>
		<pubDate>Fri, 14 Jul 2006 15:55:14 +0000</pubDate>
		<dc:creator>Scott Karlin</dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[RFID]]></category>

		<guid isPermaLink="false">http://www.appliedmiscellany.com/blog/archives/27</guid>
		<description><![CDATA[The CNNMoney.com article &#8220;e-Passports: Ready or not here they come&#8221; reports on the security and personal safety risks associated with the RFID (radio frequency identification) tags that will be embedded in U.S. passports by August 2006.  These tags are meant to be read via radio waves from a &#8220;short&#8221; distance by a passport reader; [...]]]></description>
			<content:encoded><![CDATA[<p>The CNNMoney.com <a href="http://money.cnn.com/2006/07/13/pf/rfid_passports/index.htm?cnn=yes">article</a> &#8220;e-Passports: Ready or not here they come&#8221; reports on the security and personal safety risks associated with the RFID (radio frequency identification) tags that will be embedded in U.S. passports by August 2006.  These tags are meant to be read via radio waves from a &#8220;short&#8221; distance by a passport reader; they are designed to protect against counterfeit passports and to streamline the processing of visitors.  However, as the article states, there are concerns:</p>
<blockquote><p>&#8220;Basically, you&#8217;ve given everybody a little radio-frequency doodad that silently declares &#8216;Hey, I&#8217;m a foreigner,&#8217;&#8221; says author and futurist Bruce Sterling, who lectures on the future of RFID technology. &#8220;If nobody bothers to listen, great. If people figure out they can listen to passport IDs, there will be a lot of strange and inventive ways to exploit that for criminal purposes.&#8221;</p></blockquote>
<p>There are two issues.  The first is that, currently, few people carry around anything with an RFID tag.  By simply detecting the presence of such a tag, a bad guy could infer that the person is likely to be a foreigner.  The second issue is that the tags are likely to be cracked &#8212; meaning that the personal information in the passport would be available to ID thieves.</p>
<p>I definitely see a market for passport holders with RF shielding.</p>
<p>Via <a href="http://yro.slashdot.org/article.pl?sid=06/07/14/1230253">Slashdot</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.appliedmiscellany.com/blog/archives/27/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Boarding Pass to Identity Theft</title>
		<link>http://www.appliedmiscellany.com/blog/archives/23</link>
		<comments>http://www.appliedmiscellany.com/blog/archives/23#comments</comments>
		<pubDate>Thu, 04 May 2006 20:27:34 +0000</pubDate>
		<dc:creator>Scott Karlin</dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.appliedmiscellany.com/blog/archives/23</guid>
		<description><![CDATA[The Guaridan reports that with just a discarded British Airways boarding-pass stub that was found in a dustbin, the journalist and his computer expert was able to access personal details:
We logged on to the BA website, bought a ticket in [the passenger's] name and then, using the frequent flyer number on his boarding pass stub, [...]]]></description>
			<content:encoded><![CDATA[<p>The Guaridan <a href="http://www.guardian.co.uk/idcards/story/0,,1766266,00.html">reports</a> that with just a discarded British Airways boarding-pass stub that was found in a dustbin, the journalist and his computer expert was able to access personal details:</p>
<blockquote><p>We logged on to the BA website, bought a ticket in [the passenger's] name and then, using the frequent flyer number on his boarding pass stub, without typing in a password, were given full access to all his personal details &#8211; including his passport number, the date it expired, his nationality (he is Dutch, living in the UK) and his date of birth. The system even allowed us to change the information.</p></blockquote>
<p>I&#8217;m a bit surprised that this level of access was granted without typing a password.  I wonder if the lack of a password is a system-wide feature or something that is configurable on a per-account basis.</p>
<p>The article then dives into the recent history of information gathering by the airlines/governments including the <a href="http://www.eff.org/Privacy/cappsii/">CAPPS II</a> and subsequent <a href="http://www.tsa.gov/public/interapp/editorial/editorial_1716.xml">Secure Flight</a> programs.  For additional background, see these weblog postings by <a href="http://www.schneier.com/blog/archives/2005/07/secure_flight.html">Bruce Schneier</a> and <a href="http://www.freedom-to-tinker.com/?p=974">Ed Felten</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.appliedmiscellany.com/blog/archives/23/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Difficulty of Protecting One&#8217;s Data</title>
		<link>http://www.appliedmiscellany.com/blog/archives/19</link>
		<comments>http://www.appliedmiscellany.com/blog/archives/19#comments</comments>
		<pubDate>Sat, 25 Mar 2006 16:06:56 +0000</pubDate>
		<dc:creator>Scott Karlin</dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.appliedmiscellany.com/blog/archives/19</guid>
		<description><![CDATA[It is becoming increasingly difficult to protect one&#8217;s personal data these days.  The threat, of course, is that the more complete a profile someone has on you, the greater chance that the information can be used against you for everything from unwanted solicitations to identity theft.  Computers are very good at combining information [...]]]></description>
			<content:encoded><![CDATA[<p>It is becoming increasingly difficult to protect one&#8217;s personal data these days.  The threat, of course, is that the more complete a profile someone has on you, the greater chance that the information can be used against you for everything from unwanted solicitations to identity theft.  Computers are very good at combining information from multiple sources to build up a profile.  In fact, this is the business model of the credit bureaus.  Every time you give out a bit of information about yourself to <em>anyone</em>, there&#8217;s some risk that it could find its way into your &#8220;global profile&#8221; and be used against you.</p>
<p>Even if you trust the entity with which you share your information, things can and do go wrong.  The March 20, 2006, issue of InformationWeek magazine has an article, <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=183700367&#038;subSection=">The High Cost Of Data Loss</a>, which describes incidents of customer data-loss affecting millions of people.  This cover caught my eye as it had a picture of Princeton computer science graduate student Alex Halderman; the article states:</p>
<blockquote><p>J. Alex Halderman, a doctoral candidate in computer science at Princeton University, about a year ago received a letter from the University of California, Berkeley, where he had been accepted as a graduate student in 2003, advising him that his personal data had been compromised. A university computer had been stolen that contained files with names and Social Security numbers of applicants and others at the university.</p>
<p>Berkeley warned people affected by the breach to be on the lookout for scam artists who might try to contact them under the pretense of being affiliated with the school. Halderman was shocked that two years after he applied to UC Berkeley, the application remained susceptible to a data breach. &#8220;It&#8217;s amazing that data can be on file for years, even when you think you&#8217;re finished with it,&#8221; he says. &#8220;There&#8217;s no way to take it back.&#8221;
</p></blockquote>
<h3>You can&#8217;t always &#8220;un-share&#8221; data</h3>
<p>Alex&#8217;s experience illustrates that once information has been shared it is generally not possible to &#8220;un-share&#8221; it.  I recently met with a representative of a company that holds some of my retirement funds to discuss my allocations.  During the course of the conversation, the representative asked some questions about salary and retirement plans which was noted on a yellow pad of paper.  Additionally, I answered a short questionnaire to assess my risk tolerance which was entered into an untethered laptop computer. The meeting went well but I was never told that the salary information was going any farther than the yellow pad.  My mistake was not to make my wishes known that the information I provided was not to be kept on file.  Sure enough, a week or so later I received a &#8220;confirmation letter&#8221; with all the information listed.  It was clearly a form letter generated at the corporate office from data in a big database.  I immediately returned the confirmation letter with a note asking that my profile be removed.  A week or so later, I received a phone call from a customer service manager to discuss my request. The conversation was cordial and long but only partially effective.  It turns out that once the data exists in the system, there is no way to remove it.  The best he could offer was to set the values to obviously bogus values (like an annual salary of $1).  The manager was surprised that I was sensitive about this &#8212; after all, (1) they take special measure to protect the data and (2) if I met with a different planner in the future they would need to have the information.  My counter to this was (1) data gets lost/stolen/misused anyway (USA Today just <a href="http://www.usatoday.com/money/industries/brokerage/2006-03-23-fidelity_x.htm">reported</a> that a Fidelity Investments laptop computer containing sensitive data on 196,000 retirement-account customers was just stolen) and (2) I could easily bring the information to each face-to-face meeting.</p>
<h3>Other options</h3>
<p>In addition to carefully considering whether to share personal information, you can also push back and see if the requester really needs it or if there is a way for you to get the goods or service without providing the information.  Recently I renewed my family&#8217;s membership to a local swimming pool club.  The application stated that proving the full birthday for all members was mandatory.  After several e-mail messages I learned that the insurance company required that the club have this information on hand in the event of an emergency.  In this case, I reluctantly decided that this was OK.  In another case, I made a purchase at a nationwide home improvement store where my receipt indicated that I won a $10 gift certificate and could claim it by either visiting a website or by calling a phone number.  I went to the website and saw that one of the required fields on the web form was birth date.  Rather than using a bogus birth date, I tried the phone number.  Interestingly, I was able to claim my prize without giving out this information &#8212; the system never even asked.</p>
<h3>What to do?</h3>
<p>Does this mean one should never share personal information? No, but it does mean that each time you do, you should think about the associated risks and benefits.  What makes this trade-off tricky is that the benefits are often obvious and immediate and the risks are more nebulous.  An interesting example of an unexpected use of seemingly benign information involved Farrell&#8217;s Ice Cream Parlor Restaurant customers who signed up for free ice cream on their birthday.  The obvious benefit of sharing this information is that they would get free ice cream.  However, in 1983, the U.S. Selective Service <a href="http://www.cgl.uwaterloo.ca/~smann/IceCream/Shame/farrells.html">purchased</a> a list of names and birthdays of boys turning 18 that year so that they could be reminded to register.  Food for thought.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.appliedmiscellany.com/blog/archives/19/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Credit Card Information Found in UK Hotel Dumpster</title>
		<link>http://www.appliedmiscellany.com/blog/archives/5</link>
		<comments>http://www.appliedmiscellany.com/blog/archives/5#comments</comments>
		<pubDate>Thu, 12 Jan 2006 19:05:19 +0000</pubDate>
		<dc:creator>Scott Karlin</dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://www.appliedmiscellany.com/blog/archives/5</guid>
		<description><![CDATA[The BBC reports that a passer-by discovered hotel registration cards in a skip (dumpster) from the Grand Hotel, Brighton, UK. The cards contained signatures, credit card numbers, and contact information. This news item caught my eye as I happened to be there at last October&#8217;s SOSP&#8217;05 conference. Fortunately for me, I stayed in the hotel [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://news.bbc.co.uk/2/hi/uk_news/england/southern_counties/4594770.stm">BBC</a> reports that a passer-by discovered hotel registration cards in a <a href="http://en.wikipedia.org/wiki/Skip_%28container%29">skip</a> (dumpster) from the Grand Hotel, Brighton, UK. The cards contained signatures, credit card numbers, and contact information. This news item caught my eye as I happened to be there at last October&#8217;s <a href="http://www.sosp-20.com/">SOSP&#8217;05</a> conference. Fortunately for me, I stayed in the hotel next door and didn&#8217;t have occasion to use my credit card at the Grand Hotel.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.appliedmiscellany.com/blog/archives/5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
