Wednesday, December 23, 2009

Phillippine Supreme Court Wrestles With RFID for DMV


A public transport group has asked the Supreme Court sday to nullify the Land Transportation Office’s radio frequency identification system for being unconstitutional.

FULL STORY

Tuesday, December 22, 2009

'InvisibleBracelet.org' says 'trust us' with your medical records, personal contacts, insurance and exact physical location data





If you wonder how a private firm like Docvia can afford to intake, store, document, disburse, update and protect your medical history, personal emergency contacts, health insurance records and more for only $5. per year, don't. It doesn't really happen like that.

InvisibleBracelet.org, or "iB" as the firm likes to call it, appears to have a profit model entirely different than they would have you believe from their very government-looking website. In press releases accommodatingly picked up verbatim by the AP, the Company appears benevolently intervening to assist the American Ambulance Association, among others, with the capability to virtually diagnose your medical problems, call your wife, text your kids and probably take out the trash, all while you are on the way to the hospital, in the capable hands of a paramedic to whom you have granted all this data.

The magic pill to perform this miracle is iB's online storage of your information, and its provision of documents to carry in your wallet to prove it. All for $5. per year.

Or not.

If you want to opt out, "[iB] stores all electronic communications...your health information, contact information and financial information for a period of at least ten years."

"Locator information is your name, electronic mailing address, physical address, and/or other data that allows someone to identify you."

"Docvia and your internet service provider (ISP) may use locator information as is necessary to enforce any of the terms of the Docvia Terms of Use."

"Docvia works with many business partners in making the iB service available to consumers."
"Certain features of the iB service may be used in conjunction with other Docvia products, and those features may share information..."

"Docvia may assign a Member's rights under the program with or without notice to such member."

"Aggregate information may be provided or sold to third parties."

Docvia and iB appear to be just another firm masquerading as a public service provider in an effort to gain valuable data under misleading marketing practices. This practice has itself come to be known as noncompetitive privacy policy.

Noncompetitive privacy policy is demonstrated whenever a company gathers valuable information from customers, for resale, without acknowledging the value gained, and obtaining the data under misleading circumstances.

Insurance companies and their investigators are certainly salivating to become 'partners' according to Docvia's privacy policy. This would allow them to track you using your IP address, mobile phone, and the mobile phones and contact numbers of those in your emergency contact list.

Customer lists, blinded as to specific health records, can easily be sold to insurers, health provider networks and more. The list goes on and on.

And they even get $5. from the consumer.

Has an RFID tracking chip been smuggled into your implants?


According to presenters of the 2009 RFID Journal's medical proposals, RFID chips have been implemented to track "implantable medical devices."

Questions arise concerning whether or not RFID chips, which broadcast an ID number or other data, remain in the chipped products when they are implanted into patients.

Journal Evidence: http://www.rfidjournal.com/videos/healthcare

The safeguards and disclosures regarding the practice have likely yet to be developed or considered. Potential HIPAA violations, in addition to other likely challenges, are lurking, yet nobody has spoken up. The RFID Journal trade group continues to quietly lobby for zero regulation on the matter.

Sunday, October 11, 2009

Auto License Plates With RFID: Sport-bike Outlaws Cited as National Cause

In one of the strangest, most reaching arguments for promoting RFID contractors, the RFID Journal has printed the argument that speeders riding sports motorcycles across the US are such a menace to society that we all must now broadcast an ID number from our license plates, from 30 feet away, to anyone who wants to read it.

Believe it or not, the article actually makes the case that if the speeding sport bikers across the US only had RFID chips in the license plates, which they routinely remove or "flip" to hide, then the stalwart police would not have to give high speed and winged persuit. The image is one of the officer in his crisp uniform, slowly shaking his head as the biker goes by at mach 2, returning to his latte secure in the knowledge that the biker would get his ticket and summons in the mail.

"Drat!" Says the biker when he gets the later uniformed knock on his door, "foiled again by the RFID chip!"



Needless to say, not only would the bikers remove the entire plate if they want, since the cops can't catch them anyway, they would also buy, borrow or steal other license plates to broadcast the wrong number to the idiot with the latte.

Here's the article: Please comment!




U.S. Department of Transportation Solicits Proposals From Small RFID Companies


In actuality, it doesn't need to be a motorcycle. What do they do when they are outrun by a bicycle?




In a generous handout to what will surely be picked up by both civil libertarians and ultra-right wing conspiracy nuts, the Federal Government has jumped into the fray by having the Departement of Transportation request bids by RFID contractors to submit solution bids.

Wednesday, September 23, 2009

Costing US Jobs: FBI’s Data-Mining System Sifts Airline, Hotel, Car-Rental Records, May Be Chasing Away Business

Competetive Privacy Policy is the new vernacular referring to companies and jurisdictions which demonstrate an understanding that personal security requires personal privacy, and that the sacrifice of privacy sometimes necessary to do business with a company, or to do business within a jurisdiction, has a monetary and social value to consider, to safeguard, and at times to trade.

Companies and organizations large and small are fleeing countries with privacy policy which does not recognize the value of personal and private business data gathered, or the responsibility of the holder of the data to protect it.

Case in point: US Loses SWIFT Wire Transfer System to Europe. Again.

http://www.irishtimes.com/newspaper/world/2009/0728/1224251491497.html

Case in point: FBI invades tourism industry. Again.

FBI’s Data-Mining System Sifts Airline, Hotel, Car-Rental Records Threat Level Wired.com

Case in point: Google Street View challenged in U.K.

http://news.cnet.com/8301-1009_3-10202817-83.html?tag=mncol;title

Companies have choices as to where they operate from, where they base themselves, and where they pay taxes. Jurisdictions have to compete to get the 'customer'. Arrogance is not paying off. US lawmakers may need to get out more often to see what the competition is offering.

http://www.isoc.org/briefings/015/

http://www.msnbc.msn.com/id/15221111/ns/technology_and_science-privacy_lost/

Saturday, September 19, 2009

FTC Under Heavy Pressure to Establish RFID Safeguards

Washington D.C. based, non-profit Electronic Privacy Information Center (EPIC) sets its successful sights on the FTC to establish RFID safeguards

In comments to the Federal Trade Commission, EPIC reiterated recommendations (pdf) it made in 2004 to the consumer protection agency to address the risks to consumer safety of the unregulated use of RFID tags that reveal personal data. The FTC is hosting a "Transatlantic RFID Workshop on Consumer Privacy and Data Security" to discuss consumer concerns. The workshop follows an event, organized by the US Department of Commerce, promoting the benefits of RFID. Comments on RFID may be submitted to the FTC until October 23. For more, see EPIC's RFID Privacy page. (Sept. 22, 2008).

Guidelines were issued back in 2004, and are gaining traction due to the new attention given RFID in the press. They would prevent, among other things, "Tracking, Snooping and Coersion" using RFID data.



Guidelines on Commercial Use of RFID Technology
(FINAL VERSION - July 9, 2004)

Introduction

The guidelines are proposed to guide the use of RFID technology in order to protect both
private enterprise interests and consumer privacy interests. This means that these
guidelines do not address protection of consumer privacy from any governmental action.
Rather, they seek to protect consumer privacy from private enterprises. Further, these
guidelines focus on use in the retail and manufacturing industry where retailers and
manufacturers are beginning to implement item-level RFID tagging to facilitate supply
chain efficiency, inventory control, and similar applications.

These guidelines primarily address commercial, private applications which may use
RFID tags to draw conclusions about consumers without their knowledge or consent, or
that might generate data which could be used for entirely different purposes at a later
date.

These guidelines are divided into three parts. Part A addresses the duties of private
enterprises that use RFID technology. It imposes minimum requirements on RFID users,
recognizing the advantages that RFID technology can provide while at the same time
addressing privacy concerns. Part B addresses practices in which the RFID Users
should never engage, including tracking, snooping, and coercing consumers to accept
live RFID tags or associate their personal data with an RFID application. Finally, Part C
states the rights of consumers who are exposed to RFID technology and incorporates
some of the Users' duties stated in Part A.

2
Definitions
"RFID" means Radio Frequency Identification, i.e., technologies that use radio waves to
automatically identify individual items.
"Tag" means a microchip that is attached to an antenna and is able to transmit
identification information, i.e., capable of receiving data from, or transmitting data to, a
Reader.
"Reader" means a device, capable of reading data from a tag or transmitting data to a
RFID tag.
"RFID Subject" or "Individual" means a consumer, customer, or any other such individual
that comes in contact with a product that has attached to it, or contains, an RFID tag.
"RFID User" means an RFID operator, such as a store, warehouse, hospital, and the
like, who employs RFID technology, including RFID readers and tags.
"Premises" means a store, a warehouse, a hospital, or any other such equivalent space
that encompass the tags and the readers that communicate with RFID tags.
"Consent": means the freely given, specific and informed indication of a RFID subject's
wish to have his/her personal information processed by the means of RFID technologies.
RFID Guidelines

A. What RFID Users Must Do:

1. NOTICE. Give notice to a RFID Subject of:

a. Tag presence, whether through labels, logos, or equivalent means, or through
display, either at the place where a tagged item is stored, such as a shelf or counter, or
at point of sale, such as a cash register. The notice shall be reasonably conspicuous to
the individual and contain information that enables the individual to be reasonably aware
of the nature of the RFID system and the data processing in place.

b. Reader presence, whether through labels, logos, or equivalent means, or through
display, whenever tag readers are present. The notice shall be reasonably conspicuous
to the individual and contain information that enables the individual to be reasonably
aware of the nature of the RFID system and the data processing in place.
c. Reading activity. RFID Users must use a tone, light, or other readily observable and
recognized signal whenever a tag reader is in the act of drawing information from an
RFID tag anywhere on the sales floor.

2. REMOVAL. Attach tags to items in such a way as to allow for the easiest possible
removal of tags.

3. ANONYMITY PRIORITY. Any RFID user -- before linking RFID tags to personal
information -- should first consider alternatives which achieve the same goal without
collecting personal information or profiling customers. If personal information must be
collected and associated with tag data, the RFID user must satisfy the following five
requirements:

a. Consent. Obtain written consent from an individual before any personally identifiable
information of the individual, including name, address, telephone number, credit card
number, and the like, is attached to, stored with, or otherwise associated with data
collected via the RFID System.

b. Purpose. Before obtaining written consent, the RFID User must inform the RFID
subject about the purpose of associating gathered data with personal information, and
specify that purpose before such attaching, storing, or association.
c . Use limitation. Before obtaining written consent, the RFID User must inform
individuals about the scope of use of gathered data, whether the use is limited to the
person's own interests or whether the data will be disclosed to third parties. Keep data
only as long as it is necessary for the purpose for which the data was associated with
personal information.

d. No third party disclosure. Not disclose, directly or through an affiliate, to a
nonaffiliated third party an individual's personally identifying information in association
with RFID tag identification information.

e. Data quality. Keep gathered data accurate, complete and up-to-date, as is necessary
for the purposes for which it is to be used.

4. SECURITY. Take reasonable measures to ensure that any data processed via an
RFID system is transmitted and stored in a secure manner, and that access to the data
is limited to those individuals needed to operate and maintain the RFID system.

5. OPENNESS. RFID Users must make readily available to individuals, through the
Internet or other equivalent means, specific information about their policies and practices
relating to its handling of personal information. Any personally identifiable information
itself shall be provided upon written request of the individual in a secure manner.

6. ACCOUNTABILITY. Designate someone who is accountable for the RFID User's
compliance with these guidelines.

B. What RFID Users Must NOT Do:

1. TRACK. Track the movement of RFID subjects at any time without their written
consent to all tag reading events. RFID users shall not track individuals via tagged items
on the premises or outside the premises where an RFID system is employed to obtain
individual shopping habits or any other such information obtainable through tracking,
even upon suspicion of such activities as fraud or shoplifting.

2. SNOOP. Record or store tag data from tags that do not belong to the RFID User for
any reason except for the processing of returns or warranty service and upon the
consumer's request. RFID users shall not collect RFID data from objects on, or carried
by, an individual person for the purpose of generating a consumer profile, even if the
profile is assigned anonymously.

3. COERCE. Coerce or force individuals to keep tags turned on after purchase for such
benefits as warranty tracking, loss recovery, or compliance with smart appliances; and
not require individuals to provide unnecessary personal information as a precondition of
a transaction. RFID Users must allow individuals who so desire to enroll anonymously in
any RFID data-gathering scheme.

C. RFID Subjects' rights:

1. ACCESS. RFID Subjects must have the right to access data containing personally
identifiable information collected through an RFID system, and have the opportunity to
make corrections to that information.

2. REMOVAL. RFID Subjects have the right to get tags removed from tagged items.

3. ACCOUNTABILITY. RFID Subjects have the right to challenge the compliance of
persons employing RFID systems when practice contradicts the guidelines set forth
above.