Showing posts with label ID theft. Show all posts
Showing posts with label ID theft. Show all posts

Friday, April 16, 2010

How much do you trust that bouncer?


Australian nightclubs feel they are leading the way in scanning and retaining ID's, and even biometric data, of patrons.

No, it isn't a joke.

The more sophisticated will of course throw their heads back and laugh before walking down the street to a club with a clue. Giving a nightclub operator carte blanche to steal the patron's ID, or to lose it to a thieving employee with virtually no consequence, is not smart.

Privacy concerns as clubs roll out ID scanning - ABC News (Australian Broadcasting Corporation)

"Nightclub operators, and private business in general, are not qualified to hold your ID. Show it to them, but never hand it to them. Refuse, deny, walk out. If you operate such an establishment, understand the liability of allowing your employees to demand this info. One cell phone photo of an ID, and it's over for you." - Jonathan Warren

Wednesday, March 10, 2010

WARNING: Copy Machines Save Everything You Copy

Before you copy that tax return, your ID, child's passport application, or legal documents, you'd better check the privacy policy of the copy machine owner.

Copy machines are not the Mimiagraph machines of old. They are computers attached to very sophisticated scanners. Whatever you copy is stored in that computer. For how long? Ask the machine's owner.

Where does your lawyer make copies? Who copied your loan application? what about that lease? Who copied your daughters's school amission forms? All of those images are easily extracted from the copier, usually with a laptop, and not always by the owner. Who has access to copiers containing your private information?

Chances are, you shouldn't risk copying anything with personal information on any copy machine which you do not own.

Copy Machines Can Store Your Private Info - wbztv.com

Tuesday, March 9, 2010

Classmates.com Sued Over Privacy Setting Change


Changing privacy options without giving users the whole picture and a real opt-out option can be risky. Classmates.com apparently hoped nobody would notice.

MediaPost Publications - High School Reunion Ruin: Classmates.com Sued Over Opt-Out Privacy Setting Change 03/09/2010

Lifelock to pay $12 Million in False ID Theft Protection Claims Settlement


"...Protection actually provided left enough holes that you could drive a truck through it" - FTC

03.09.2010 International Association of Privacy Professionals--/

In a press conference held Tuesday, March 9, Federal Trade Commission (FTC) Chairman Jon Leibowitz and Illinois Attorney General Lisa Madigan announced that LifeLock, Inc., has agreed to pay $11 million to the FTC and $1 million to a group of 35 state attorneys general to settle charges that the company’s claims of providing 100-percent protection against identity theft were false.


“While LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it,” Leibowitz said.


In addition to the $12 million settlement, LifeLock and its co-founders Richard Todd Davis and Robert J. Maynard, Jr. are prohibited from making deceptive claims and required to better safeguard customers’ personal information.


According to the FTC’s complaint, LifeLock’s claims included protecting against identity theft “ever happening to you” and being “the first company to prevent identity theft from occurring.” The FTC, however, contended that LifeLock’s practice of placing fraud alerts on its customers’ credit reports only protected them against specific types of ID theft, but had no effect on the most common form: the misuse of existing credit card and bank accounts.


“There is nothing you can do or purchase that will provide you with a 100-percent
guarantee against identity theft,” Madigan said during Tuesday’s announcement, urging consumers to be aware of the steps they can take to protect their personal information. “Most of what they did you can do on your own, and you can do it for free.”


In addition to what the FTC described as deceptive identity theft protection claims, Leibowitz noted that LifeLock’s own data security practices did not adequately protect its customers’ information.


According to an FTC press release issued after Tuesday’s conference, LifeLock routinely collected sensitive information from its customers, including their Social Security numbers and credit card numbers, but did not encrypt the data. Additionally, the FTC alleges, “sensitive consumer information was not shared only on a ‘need to know’ basis…the company’s data system was vulnerable and could have been exploited by those seeking access to customer information.”


The FTC has confirmed it will use the $11 million it receives from the settlements to provide refunds to consumers. For more information, visit www.ftc.gov/lifelock.

— Jennifer L. Saunders IAPP

Tuesday, January 19, 2010

2 in 5 Employers Admit Eliminating Candidates Due To Facebook Profile

Creditors have already admitted to screening you on Facebook, now its employers. Half of employers now admit to screening your facebook profile as part of the hiring process.

COMPLETE STORY from CareerBuilder.co.uk

What if they have the wrong person? Search for friends by your own name, and see how many pop up. Could you be confused with them? What if one of those other people with your name decides to pretend to be your facebook profile, to improve their chances of getting a job, or even credit?


A new Facebook application can make sure your profile checks out as yours, and that nobody else's can pretend to be you. Identify.nu, a service of the Consular Chamber of Commerce has created a global platform whereby members provide passport copies to consular officers anywhere in the world, who then verify and legalize a copy of the passport for upload to identify.nu secure servers in Denmark. The member always owns and can delete the data.

COMPLETE STORY - FACEBOOK APPLICATION

Members can trade passport identification with other members, and can authorize social networking interfaces like Facebook and even Gmail to display certain criteria, such as the name, age and confirmation that a full passport copy including passport photo is on file and can be provided to other members when authorized by the identified person.

Saturday, July 11, 2009

Chips in official IDs raise privacy fears - Yahoo! News

Nightmare security issues with the new US Passport and e-Passport (Passport Card) call into question the compliance of these documents with even the most basic security issues.


Chips in official IDs raise privacy fears - Yahoo! News


The Dept. of Homeland Security did much to avoid risk of hackers getting in to the database, by making the number a mere pointer to their own files grounded in DHS computers. But the very function of the RFID chip, broadcasting an ID number, is easily co-opted by the private sector (retailers), and combined with the other information the retailer collects.

No need to obtain the government's data file, just about anyone can buy the data collected by the retailer, including your identity, all of your buying habits and payment options, demographics information, etc. The data then is neatly wrapped up and tied together with your RFID number, then sold, legally, to any number of buyers.

Now you walk through the mall, with your new drivers license, passport or passport card in your wallet, and that Israeli chick at the kiosk with the Dead Sea soap calls you by name - from 30 feet away.

Worse, some creepy guy likes what he sees when you pull up next to him in traffic. He inputs your RFID on his mobile, and gets everything about you, including address. He may even add your license plate number to the database app on his iphone.

Worse again, you can be completely watched on cameras which turn on only when you are within 30 feet, anywhere in the world. You might not be worried about that at home, but what about when you are at a foreign airport, or in a foreign city? How about when you are crossing between two foreign countries?

It seems that RFID has no redeeming value. Please comment.