Search This Blog

Tuesday, February 20, 2007


PUBLIC SHOULD DEMAND ENCRYPTION OF THEIR PERSONAL DATA


There’s a good article in the South Florida Sun Sentinel on recommendations from privacy advocates of how to protect your sensitive data. Linda Foley, executive director of Identity Theft Resource Center, says: “Have we not learned from history yet, that if you’re going to give [data] to a third party that you either encrypt or password protect it?” I checked my sources in junk mail and learned that at least one of the big six data brokers has been using encryption for the past year, and a computer maintenance facility combines password protection with encryption. I plan to follow up and see just how prevalent this is within the industry. Beth Givens, director of Privacy Rights Clearinghouse, comments: “The reason that we’re hearing of security breaches on almost a daily basis is because there’s so little encryption of the data.” Since ChoicePoint started encrypting its databases, they haven’t had a breach. However, experts will tell you that security depends on the level of sophistication of the encryption standard. The next question CP should answer is to what degree their encryption goes, and what are the odds of it being broken?

HEAVY DUTY LOSS OF LAPTOPS AT FBI


The FBI is so busy recovering lost laptops and missing weapons that one wonders how they have the time to protect American citizens. According to ZDNet and The Washington Post, 160 laptop computers, including 10 that hold “sensitive classified information,” went missing from 2002 to 2005. Once again, we have a case of not knowing the content of the loss, thus, an impossible situation to curb the damage. The FBI maintains more than 26,000 laptops, reports the WP, and only reported 38 of the 160 missing. GOP Rep. Thomas M. Davis of Virginia said Justice reported only two missing laptops to his committee in 2006. Whether or not consumer data is included in the loss, this is yet another example of the lax security at federal agencies, and even more reason to be concerned about government spying on innocent Americans.

NEEDED: CONSUMER PERSONAL DATA BILL OF RIGHTS


There was talk of a “Voter Bill of Rights” after the 2004 election. Now the Associated Press has a piece on MSN Travel, “Passenger Bill of Rights Proposed.” Both excellent ideas, but I have an even better one. How about a “Consumer Personal Data Bill of Rights?” It could pave the way for individuals to control their names and private information, also paying them whenever it is sold. James Madison, proponent of a new U.S. government instead of fixing the old one, was a major contributor to the Constitution’s Bill of Rights. However, the Constitutional Convention of 1787 could not possibly have conceived of the advancements in technology that have brought us to the current identity crisis. I am putting something together on this, and would welcome input from readers. Also planned is another volley of e-mails and letters on the subject to Congressional leaders sympathetic to consumer issues.

Thursday, February 15, 2007


BEWARE POSTING PERSONAL INFORMATION


The Wharton School of the U. of Pennsylvania did an interesting and quite comprehensive study on whether you give up your privacy when posting information online. This article is must reading, especially for the younger set. There are two points well worth covering in relation to my concept of giving the individual control over their names and personal data, and compensating them for its sale. Number one, there is a burning question of who owns the information on sites like MySpace, Facebook, Xanga, and the like. The junk mail companies are convinced they own your sensitive data, and the attitude may be catching. Number two, these sites will most likely hold on to your private information forever, regardless of how active you are. There seems to be an utter lack of concern within the younger generation about giving up their personal data, breeding a generation of grownups that will be even more apathetic about the problem than their parents…if that’s possible.

IDENTIFYING A DATA BREACH ISN’T ROCKET SCIENCE


One of the major problems with congressional leaders today is that they don’t understand the proliferation of the sale of consumer personal data, therefore are incapable of putting together a decent data protection bill. The burgeoning amount of private information has confused both Congress and the individuals whose information is being collected. Ultimately, the confusion has been passed on to defining just what a data breach is. Most of the current data bills allow the data broker to identify “significant risk” to the consumer, which is like putting the fox in charge of the chicken coop. Congress is busy now promising more legislation, but Roy Mark, in his piece “When Is a Breach a Breach?” says this is “…so much hot air.” Based on experience, I’d have to agree. Consumer groups say it’s simple: You expose it, you inform the consumer. Mark, however, doesn’t think that will happen. Fortunately, I still hold out hope the American public is eventually going to wake up.

YOUR PRIVACY IS FOR SALE, SAYS CONSUMER REPORTS


It’s nice to have your theories confirmed by one of the largest consumer-oriented organizations in the country, Consumer Reports. Their article in the October 2006 issue, “Your privacy for sale,” is must reading for anyone who is serious about their inner-sanctum. In an earlier post I covered the subject generally, but want to be more specific here in pointing out striking examples of today’s identity crisis. First, CR mentions the high number of inaccuracies in background reports requested by their staffers from data brokers, including names, addresses, Social Security numbers. What is even more astounding is a statement by LexisNexis—one of the big ones—that said: “We do not examine or verify our data, nor is it possible for our computers to correct or change data that is incorrect.” As to the first part of this sentence, knowingly selling inaccurate private information should be a crime. Next, the allegation their “computers” cannot make corrections is an outright lie. Second, Elizabeth Rosen, the nurse whose sensitive data was stolen from ChoicePoint—another biggie data broker—had no problems in the early stages, but became victimized more than a year later. Evidence the crooks are sophisticated enough to lay low at first, and strike when the trail gets cold.

CONTROL MEANS ONLY YOUR CHOSEN JUNK MAIL


Damon Darlin in his article, “Don’t Call. Don’t Write. Let Me Be,” makes a statement that much of the public supports. Why should we receive mail, telephone calls, and e-mail we do not want? We have the FTC “Do-Not-Call” list, some flimsy attempts at halting spam, but the mail keeps assaulting our households with few or no restrictions. Unless…we grant consumers control over their names and personal data. In addition to stopping ID theft in its tracks, the procedure I envision would let you specify your interests, and the junk mailers would deliver only what you wanted. Colorado has proposed a “Do Not Mail” list, but this cannot be solved on a state-by-state basis; it must be nationwide to work. Besides, the companies you really don’t want the junk mail from don’t even use the do-not-mail lists. Another upside is the enormous paper savings; 98 out of one hundred pieces of junk mail go in the trash. This is really a no-brainer.

INCOMPETENCE PRODUCES FAILURE
If you’ve heard of the Peter Principle (Dr. Laurence J. Peter), you can understand the absurdity in Bush’s new Identity Theft Task Force. Dr. Peter says that people within a hierarchical organization advance to their highest level of competence, then are promoted to a level where they are incompetent. Precisely the position of Attorney General Alberto Gonzales as the task force Chairman, who, in 2006, said Bush has the power to spy on Americans without a warrant. We want this man to head the body that seeks a solution to the most important issue before Americans today? It is an insult to those 8.4 million victims of ID theft in 2006, and portends of the obvious attitude this administration has toward the average consumer. It’s like the Edsel; you know you’ve got it wrong, but you don’t know what to do about it.

Monday, February 12, 2007

NEW

DUNNING’S BLACKLIST


All junk mail catalog companies who do not use recycled paper to print their catalogs. FACT: 98 of 100 catalogs end up at the city dump. According to Greendimes, it costs 100 million trees a year and 28 billion gallons of water to support this voracious appetite. The typical American household receives about 70 pounds of junk mail a year. It is “junk” because with control over your names and personal data, you would receive only the advertising mail you wanted.

Ponemon Institute Tracks ID Theft


The Ponemon Institute has been tracking individuals’ attitudes on the possibility of becoming victims of identity theft since 2004. They ask the question: “Will you become a victim of an identity theft at some point in the future?” Still prior to the ChoicePoint incident in Feb. 2005, it started at 47 percent answering yes in August 2004. It shot up to 70 percent right after CP, and peaked at 82 percent right after the May 2006 VA data breach of 26.5 million records. What I don’t understand is that, if as little as 47 percent of the population thinks they will experience ID theft, why don’t we hear a roar from this group demanding that something be done to give them the control over their sensitive data to keep this from happening? In their studies, Ponemon has found that Americans remain concerned over a “loss of civil liberties and privacy rights,” and “surveillance into personal life.” Folks, it’s time to put up or shut up!

Behind the Scenes at TJ Maxx


Remember CardSystems, the Tucson, AZ credit card processing company that exposed 40 million debit and credit card accounts through a cyber breach? They failed to secure their network, and lost the Visa and American Express accounts as a result. Lurking in TJX’s (TJ Maxx’s parent) data background is Fifth Third Bank—fourth largest credit-card processor in the country—in what has been called possibly the largest breach of security in sensitive data. What is most alarming is the fact that neither TJ Maxx nor Fifth Third has been able to determine the extent of the breach; it happened in Dec. 2006. Until this happens, whatever sensitive data is out there is in limbo, ripe for the new ID thief that carefully plans his strategy. Fifth Third handles over 17 billion transactions a year, with Kroger, Nordstrom and Abercrombie & Fitch as clients in addition to TJ Maxx. The lawsuits are already piling up, and the Massachusetts Attorney General is leading a civil investigation into the matter. For some reason, they aren’t letting this one go.

2007 ID Theft Surveys Better But Still Appalling


Javelin Research’s “2007 Identity Fraud Survey Report” shows that even with an 11.5 percent decline in ID theft in 2006, it was still $49.3 billion. 8.4 million adult-Americans were victimized at an average of $5,720 each, spending another $535 to correct the problem. The Federal Trade Commission’s 2007 report found identity theft still topping the list of complaints at 36 percent of the total. Since the ChoicePoint incident in Feb. 2005, there have been over 100 million records lost or stolen from over four hundred breaches. CP’s original 800 victims, resulting from the breach of 135,000 records, have risen to 1,400. That’s over $8.7 million of consumer losses from just one company. So don’t take comfort in this decrease, because I sense the ID thieves are just regrouping with new strategy.

Here Come the Bills. Here Come the Bills. Everybody Look Out. Here Come the Bills


They’re at it again, those congressional representatives that make waves to convince voters they are acting in their best interest. It’s all over the news in a flurry of the same old legislation that Democrats proposed while they were under the thumbs of the GOP. More. Vermont Dem Patrick Leahy leads the pack with a memorable quote: “Americans live in a world where their most sensitive personal information can be accessed and sold to the highest bidder, with just a few keystrokes on a computer, yet our privacy laws haven’t kept pace.” I believe he’s got it, what I have been saying for two years in this blog, yet he comes up with worthless legislation. For all the good it does, it allows the data breachers to decide when to notify the individual breached. The FTC Chairman wants to make “significant risk” the notification trigger, but doesn’t explain what that is. Is it so unreasonable to at least consider giving consumers control over their names and personal data? Let’s put it out there and see if it flies.

Citibank Really Pushes the Envelope


Citibank, the folks who, in June 2005, lost 3.9 million of their customers’ personal records, including names, Social Security numbers, account history and loan information, just sent me an unsolicited credit card offer. Normally I pay no attention to the eight to ten of these received each week, but something about this one caught my eye. In the address window, plainly stated in bold letters was: “Pre-approved offer for: Jack E. Dunning.” What dishonor-bound ID thief could possibly resist this temptation? Years ago they outlawed sending the actual pre-approved card(s) in the same mailing with the offer. It’s time to rethink this whole process with around 5 billion of these mailings going out each year.

Tuesday, February 06, 2007

FTC Looks At Junk Mail Negative Option

The Federal Trade Commission all of a sudden wants to “understand” the use of negative option in junk mail. I was in the industry for 35 years and it has been going strong during that time. Columbia House tried to drop it several years back and almost went under. The practice involves sending you a notice of something the company is going to ship automatically, if you don’t say no. I hate it! Had to chastise Writer’s Digest twice for sending unordered books. Most companies pay the return postage, but this is still the opposite of convenience if it’s something you don’t want. As with most recent FTC action, they’ll study it until everyone has forgotten the original purpose of the study.

TJ Maxx Data Breach Opens Can of Worms

Data breaches occur so frequently these days that they are barely worth mentioning. However, the recent hacking into the T.J. Maxx discount chain’s computers has produced different results from both the consumer and business sides, according to the InformationWeek Blog. In Patricia Keefe’s article, the consumer was violated through inadequate security, having their data kept for longer than legal periods, and responding to the problem a month after, with an attitude of, “You’re on your own.” On the business side, fines are being assessed for violating the Payment Card Industry Data Security Standard. AmeriFirst has already filed a class-action lawsuit against TJX, TJ Maxx’s parent company, and its card processor, Fifth Third bank. WMAQ-TV, Chicago, reported a shopper embarrassed when her credit card was declined, due to cancellation by TJ Maxx. More on this in future blogs.

2006 “Kind of Disaster” for Data Security

Liz Gasster, acting director and general counsel, Cyber Security Industry Alliance (CSIA) is “discouraged” with Washington’s lack of attention to data security, and calls 2006 a “kind of disaster,” for this issue. According to Roy Mark in InternetNews.com, she faults Congress the most for inadequate legislation, and the private sector for continuing to lose our sensitive data. Gasster brings up encryption, which, when used on our private information, is supposed to make it burglar-proof. Not completely true with current standards established in 1994, but this could change at the behest of the National Institute of Standards and Technology (NIST). More. The problem is, like hackers finding new ways to beat spy-ware, the encryption algorithm periodically becomes obsolete…like now.

Javelin Strategy & Research Releases “2007 Identity Fraud Survey Report”

Javelin’s 2007 Report on Identity Fraud is out and, although there is a 12 percent decrease, there is even more reason to keep up our defenses. The crooks are starting to specialize, like in retail chains, reflected in the recent hacking into the TJ Maxx computers, covered above. The same people had broken into systems at other retailers in a well orchestrated, concentrated attack, which proves the level of sophistication reached. Victims are down due to targeted specialization. Identity fraud still costs Americans and business a total of $49.3 billion each year, with the average individual loss at $5,720. Younger Americans beware: the 18 to 24 age group. You’re the ones at most risk due to your higher degree of apathy over the issue. You’re not alone; most consumers have similar sentiments.

Gartner Research Reports Consumers’ Security Concerns in 2006

Gartner says that nearly $2 billion was lost in E-Sales in 2006 because people are not comfortable with Internet security. Half of that from shoppers who refuse to shop online because of security concerns. Almost half of U.S. adults are worried someone will steal their sensitive data. Washington: We have a problem! But does any one of us think Congressional leaders will listen? Of course not. That is until American consumers form a grass-roots effort to take back control of their names and personal data. While we’re at it, pay us each time it is sold. I’m taking names so if you’re willing to sign up, e-mail me at jack.dundiv@cox.net.

Thursday, February 01, 2007

They’re Paying More for Your Name and Personal Data. What Are You Getting?

The databrokers are selling your names and personal data for about 4 percent more this year than last, according to one of the list companies that sell it, Worldata. The individual amount is incidental, but the total annual revenue of around $4 billion is startling to those who don’t know the insides of the junk mail list industry. As a former list/databroker, I do, and if at least half of that $4 billion was returned to the name-holders and invested over a period of years, you could supplement your retirement by an average of $607 monthly.

Courts Can’t Protect Consumers Against ID Theft

If your private information is hung out there for the taking by the company collecting it, you’d think potential damages would apply in the legal system. The courts don’t agree. Bank Technology News reports on several cases from New Jersey to Minnesota that have tried but failed. That’s because the data thieves haven’t harmed the victims…yet. In one such case from Minnesota against Brazos, a student loan company, it was argued not to have been the result of negligence, although Brazos turned over sensitive data to a third-party whose representative had the laptop containing the information stolen from his home. Sound familiar? If the individual had control over his or her name and personal data, they could sleep at night knowing no matter what happens, the bad guys could not touch their private information.

Does Your State Post Your Social Security Online?

Ohio did in Cynthia Lambert’s case when they posted her speeding ticket, including key personal data like her driver’s license number, date of birth, Social Security number. They might as well have sent it to the crooks special delivery. In an MSNBC story, NBC’s Lisa Myers “…found state and county Web sites across the country that, with a few clicks of the keyboard, give identity thieves what they need to take over someone’s life.” Other guilty states are Missouri, New York, and Florida. Lambert sued the Ohio county and they stopped posting the tickets. Other states are following suit. I checked my state, Arizona, and couldn’t find any such action. Suggest you do the same.

AARP Warns Against Someone Stealing Your Medical Identity

In the September American Assn. of Retired People (AARP) Bulletin, they alert members of the devastation caused by medical identity theft. For one, going into the hospital for one thing and being treated for something entirely different, based on records created by an imposter’s health history. Or another, getting the wrong medication that could prove fatal. You could even be denied life or disability insurance. It could be an inside job by employees who steal the records, or dumpster divers from hospital trash. Some of us give it up willingly online as a result of purchasing health products, or completing surveys. AARP says your medical data is getting top dollar these days, so here’s your heads-up to be careful.

Unsolicited Credit Card Offer Pile Gets Higher and Higher

I said I was going to shred all these unsolicited credit card offers received in the last couple of years, but couldn’t resist letting it grow just a little more. Over a foot since the last time I posted on this. When checking, a large number of the mailings are from Capital One to our family and former junk mail list brokerage business. According to a Business Week article, Capital One reaps a great deal of their profits by issuing several cards to the same individual with low limits resulting in the cardholder exceeding their limits, thus, allowing Cap One to collect late fees. 30 percent of its credit card loans are to sub prime borrowers. They find you by “blitzing” credit reports for “new prey,’ says ConsumerAffairs.com, adding “soft inquiries” to the credit records of those not holding the card. Soft inquiries don’t bring down your credit score, unless they are mistakenly listed as “hard inquiries,” which happens in this mistake-prone industry. One consumer received one offer per week from Capital One; our family gets between two and three. Think I’ll hold on for a while to see how much larger the pile gets.


NEW

THIS MAILING LIST COULD BE HAZARDOUS TO YOUR PRIVACY

The “National Date of Birth File with Opt-In E-Mail Addresses,” offered by NobleVentures.com, has a total universe of almost 12 million individuals. Folks, with your name and date of birth, it is almost guaranteed that ID thieves can obtain additional personal data on your household sufficient to do additional harm. It also offers excellent information to secure your Social Security number online for the grand slam.

Tuesday, January 30, 2007

George W. Bush: A Nation's Nemesis for Individual Rights

Newsweek Comments on State of the Union Address


“A Sorry State” is the Newsweek magazine headline in a story that shows the Big Brother-In-Chief in a state of freefall that indicates a new lowest approval rating of 30 percent. 58 percent of the country (Republicans and Democrats) “…say they wish the Bush presidency were simply over…” If that weren’t enough, the man is viewed as “ineffectual” by 71 percent of all Americans, a majority seeing him as a “below-average” president. You can see all of Newsweek’s findings on the link above. There is no doubt in my mind that one of the leading reasons for this loss of confidence is how this arrogant autocrat has completely absconded with the individual’s right to privacy.

Duh…Guess We Don’t Own the NSA


For over a year now the Bushies have been telling us the Foreign Intelligence Surveillance Act Court (FISA) is not flexible enough, and then he abruptly decides to give in. Newsweek magazine discloses from a Capitol Hill source that the Democrats want to know why his imperial majesty couldn’t have realized this earlier. Congressional committees will question the domestic snooping and try to learn just who they are looking for. Senator Jay Rockefeller, a Dem, will use his Senate Intelligence Committee to find out.


But Really Halting Warrantless NSA Spying? Don’t Believe It.


Yes, the Bush administration publicly decided to halt the warrantless NSA spying, but if you believe that, you’ll believe Cheney that there are still WMD’s in Iraq. The Village Voice reports that it is unclear whether the new FISA Court warrants will be individual or a “blanket dragnet,” attached to no one in particular for Bush to use indiscriminately. It’s all academic because the New York Times legal analyst Adam Liptak says the Bush/Cheney gang still thinks they can “operate without court approval.” Another snub of the Fourth Amendment by this band of despotic bullies. The top investigative reporter for ABC-TV, Brian Ross, had his phone records taken without a judge’s ruling. Hopefully, Ross won’t take this lying down.

ACLU Rechallenges Bush Administration on Domestic Surveillance


In the 6th U.S. Circuit Court of Appeals, the ACLU moved to keep active its challenge to NSA’s stakeouts of innocent American citizens. In an Associated Press article, they quoted the same position used by Liptak, above, in the NYT. The White House wants the case dismissed since it has “agreed” to the monitoring. Beginning to sound like a decision of convenience? AG Gonzales says we can trust them now, but the ACLU doesn’t think so. Anybody who does would buy the Golden Gate Bridge on E-Bay.

Get ‘em While They’re Down


Alexander Cockburn and Jeffrey St.Clair had a great idea in their political newsletter, CounterPunch. Now that the totalitarian cretin has feigned weakness by giving in to warrants for his spying fantasies, “Don’t let him off the hook.” Congress should rush right in and take advantage of a situation that at least made someone in this administration think for a change. We probably won’t get another chance because once Bush recognizes the cerebral mistake, things will no doubt return to normal, whatever that is. It just seems pathetic that we vacillate all around the issue of individual rights but no one in the White House seems to get it.

Thursday, January 25, 2007

Thursday Ruminations

Identity Crisis Gains Momentum


A recent data breach at TJ Maxx, a discount chain, illustrates the level of sophistication attained by the ID thieves. An article on ZDNet indicates, “…it was a well orchestrated, targeted attack…same people who have broken into systems at other retailers.” Never thought I’d see the day when the identity crooks would specialize, but it’s happened. With the involvement of organized crime, I am convinced the bad guys maintain their own databases on American consumers, to use when and as they see fit. Business and government cooperate fully by continuing to collect every piece of private information they can get their hands on and managing to lose it regularly.

Charities Not So Charitable Anymore


I did an earlier post on junk mail fundraisers about how charities sell your name. In this it was noted how your name breeds like rabbits when making just one contribution, moving with lightning speed from one philanthropic organization to another. Also covered was a list of major charities, and what percentage of the take they devote to their programs. From my experience as a data broker, they sell your names, with limited personal data, as aggressively as regular junk mailers. But an MSNBC article by Sharon Hoffman lowers the boom on this field, starting with a Harris Poll that found only 10 percent of Americans strongly believe charities are “honest and ethical” with your contributions. Apparently Congress is concerned about some nonprofits’ tax-exempt status, and are taking action.

Your Name is “Forever” to Junk Mailers


Over thirty years ago I used a decoy name to purchase a product from a company whose name I can no long remember. A decoy is something junk mailers employ to track what the competition does in their mailings. You simply change a middle initial, which identifies the company from which you made the purchase. Just yesterday I received a mailing to this decoy; another had been received in October of 2006. It just shows how long your names and personal data are maintained on file by the junk mail industry. Another big offender in this area is those unknown mortgage companies you get mail from right after closing a mortgage. Received one of these in October of 2006 that was 14 years old. My point is just how many locations where your sensitive data can reside, and how many years it sits there a virtual goldmine for ID thieves.

Guns Don’t Kill…B_ _ _ S_ _ _!


A Reuters’ article on MSNBC quotes advocates saying this “administration ‘in denial’ about weapons’ role in violence.” Having heard nothing of substance on this subject from the Democrats recently, I doubt if they plan to focus on gun control either. Reuters reports: “More than 30,000 people die from gunshot wounds every year, through murder, suicide and accidents.” To give you an idea of the magnitude of the gun industry, there are 49 junk mail lists on the market under the heading of “guns.” When you Google mail-order guns, you get 1.2 million hits. One in particular blew me away when in response to why they didn’t give their phone number on the site; their clouded answer indicated it was simpler for you to respond my e-mail first. Of course they didn’t mention they will keep your e-mail address forever, perhaps reminding you in the future of their Colt or Smith & Wesson special. I won’t even give you the site because it is so easy to order firearms. In all fairness, law prevents delivery by mail; you must pick up the gun from a local dealer, but this is a simple three-step process. On a personal basis, I met someone here in Arizona—yes, it is legal to carry firearms here with a permit—who, along with his wife, has permits to carry concealed weapons. According to him, for no reason other than he needs to protect himself. Since I don’t even have a gun, guess I run with a different crowd, one I don’t need protection against.


NEW

DUNNING’S BLACKLIST


The college and university community for allowing multiple data breaches of student, staff and faculty sensitive data. UCLA lost 800 thousand records, Boston College 100,000. USA Today reports 109 such breaches on 76 college campuses since January 2005. Security is low and interest by ID thieves is high, because they can get the same personal data easier than from most commercial databases. Education is way behind the times in the protection of private information, and needs to catch up fast. Otherwise, the “gov-ment” might have to do something.

Tuesday, January 23, 2007

Tuesday Morning Musings

Stay Healthy or the World Will Know


I made an appointment with Mayo Clinic recently and they sent me a personal health form to complete before my appointment. Four pages, almost two-hundred questions that cover nearly any malady a person could ever have. It is thorough, and the doctor should know as much as possible about the condition of your health in order to help you. However, where does all this healthcare information end up? Just about everywhere, according to the Privacy Rights Clearinghouse. In their “How Private Is My Medical Information?” site, possible locations include insurance companies, government agencies, employers, and the Medical Information Bureau (MIB), a central medical database used by insurance companies. It could also be collected by junk mailers if you participate in health screenings or complete medical questionnaires. The Health Insurance Portability and Accountability Act (HIPAA) helps but does not cover your financial records, education records and employment files. I decided to cancel my Mayo appointment.

Daily Kos Agrees Dems Should Put Privacy in the Platform


In a recent Firedoglake blog, there was a quote from Daily Kos; both are political Weblogs. Kos was commenting on how Hillary Clinton called for a Privacy Bill of Rights to protect Americans’ personal information, and how this should be a primary plank of the Democratic Party. This is a good move, but doesn’t quite go the full route needed to halt the identity crisis. We must give control of consumers’ names and sensitive data to the individual, and they should be paid each time it is sold. If the Dems won’t do it, maybe an Independent Party could get the job done.

LifeLock recruits Limbaugh


LifeLock is a company that advertises that it can stop junk mail, credit offers and identity theft. So convinced is the founder, Todd Davis, that he gives you his actual Social Security number on their Website, a dare to try and steal his identity. The company offers guaranteed ID theft prevention for $110 a year, and Rambling Rush will endorse the whole thing. That’s $110 that no consumer should have to pay. My deal is you should have control over you name and private information at no cost, and it is the individual who should be paid, not a company taking advantage of the identity crisis. I still think Al Franken was right.

Wireless Pickpocket the Latest Scam


You may have received one in the mail recently. They are called contactless credit cards which can wirelessly communicate information about you and your account. But scanner thieves can steal this just like the original pickpocket that preceded today’s advanced technology. According to Liz Pulliam Weston on MSN Money, these cards do not have an “off” switch, therefore, it’s like open season for the experienced hacker. Card issuers say everything is safe through encryption, but privacy advocates are skeptical. Actual data captures have been documented by the New York Times and the Today Show, one of which read data from a briefcase out of a person’s back pocket.. What we’re talking about is an RFID chip that is being considered by several industries to track a multitude of things, including human beings. Marc Rotenberg of the Electronic Privacy Information Center (EPIC) thinks there are flaws, and isn’t entirely sure companies wouldn’t pull info from these cards to add to their databases. Along with other data available on the Internet and otherwise, individuals could be targeted for a number of illegal endeavors such as robberies, even carjacking.


NEW

This Mailing List Could be Hazardous to Your Privacy

“Cell Phone Numbers” is a new list from the Media Source Solutions company with 14.3 million individual cell phone numbers. They also have your age, which is a great start in acquiring more sensitive data for ID thieves, should they get their hands on the list. Could cell phone junk phone calls be right around the corner?

Thursday, January 18, 2007

Government's Ceaseless Meddling in the Identity Crisis

Big Brother-In-Chief Does Another About-Face


After almost five years of monitoring our phone calls and e-mails, Bush said on Wednesday that he has decided to allow the Foreign Intelligence Surveillance Court to monitor his monitoring, according to an MSNBC article by the Associated Press. Apparently the FISA court assured both speed and agility in the future, which sounds hollow since this was guaranteed all along. W’s mouthpiece, Tony Snow, “…could not explain why those concerns could not be addressed before the program was started.” When do we start on impeachment?

Government Data Mining “Could” Be Investigated


I say “could” because this new Democratic Congress hasn’t shown any indication of getting seriously interested in protecting your privacy. More on the Dems later in this post. Rebecca Carr, reporting from Cox News Service, quotes privacy experts that feel the government is so captivated by data mining being able to reveal terrorists with the touch of a computer keyboard that anything goes. Both the ACLU and Center for Democracy and Technology check in with concerns. A former FBI agent who handled domestic terrorism cases says data mining isn’t even that effective.

Defense Department Database Forced to Purge “Good Guys”


In another MSNBC article, “US protestors found in Defense database,” reporting on a Pentagon memo released by the ACLU, after Defense Department examination of the database called TALON that collects info on potential threats to the military, almost 9 percent of the reports involving Americans justified deletion. Of those, 186 were “anti military protests or demonstrations in the U.S.” An earlier evaluation by Counterintelligence Field Activity (CIFA), which manages TALON, reported only 1 percent of the reports questionable. Are we surprised at yet another example of incompetent governmental oversight?

Democratic Senator Patrick Leahy Weighs in on Data Privacy


Senator Leahy from Vermont seems to have always been in the consumer’s court, and now he vows to regulate government and commercial “databanks.” In his speech, “Ensuring Liberty and Security through Checks and Balances” to Georgetown University Law Center, Leahy comments on the unilateralism of the Bush administration. Paraphrased, he thinks Big Brother-In-Chief has unlawfully spied on the lives of innocent American citizens. The Senator maintains he will shoot for stronger legislation protecting individual sensitive data. No mention of my concept to give consumers control over their names and personal data, and pay them when it is sold. Can’t imagine why since I have written him about this twice.

Pentagon Keeps on Prying Into Your Finances…Cheney Says OK


Big Brother II says “…the Pentagon and CIA are not violating people’s rights by examining the banking and credit records of hundreds of Americans and others suspected of terrorism or espionage in the United States.” This from an Associated Press article quoting Cheney on, where else, Fox News. The only thing he left out of this arrogant and absurd statement was “innocent” Americans. But the Pentagon keeps on prying, using the Patriot Act as its authority to request and receive—no questions asked—these private records from financial institutions, according to the Washington Post. The FBI does it but they have to issue a National Security Letter, which allows them scrutiny of innocent US residents. Is it possible to impeach a President and Vice President simultaneously?

Democrats Still Soliciting From Recent Turncoat


I keep getting requests for donations to the Democrats, although I reregistered as an Independent before the 2006 election. I’m glad they keep coming because it allows me to keep track of their efforts toward consumer privacy, or lack thereof. Received such a piece of mail on last December 7, with another “Key Democratic Party Planning Survey.” It’s almost identical to the one received earlier, and which became an integral part of a post. It asks questions about Dems in my state, Arizona, going then to “National Focus.” There are seven issues from Social Security to Iraq and terrorism to the environment. Not one mention of privacy. Just like last time. Are they deaf, dumb and blind? Folks, if we can’t get this side of the aisle on our sides, there is no hope. Unless…we start a grassroots effort to give individuals control over their names and sensitive data. Think about it!


NEW

This Mailing List Could be Hazardous to Your Privacy

“Cruise Travelers” from Mokrynski Direct labels over 700 thousand households as “enthusiastic” travelers, away from home for extended periods of time. They can also identity your age, income and lifestyles, potential profiles for burglary if in the wrong hands. There are a total of almost 800 travel lists on the market, many with your sensitive data like the one above.

Tuesday, January 16, 2007

Why Protecting Your Name and Personal Data Is So Critical

Identity Theft Resource Center Reviews 2006


Linda Foley, founder of ITRC, is optimistic in her 2006 Review that business is watching the store better when it comes to data breaches. Although this is promising, there is much more to do, based on my 35 years of experience as a junk mail data broker. There are too many inbred problems that will require major “re-tooling” to solve. Things like incompetence in handling mailing lists; greed trumps security; junk mailers’ attitude that they own our names and personal data. Government and educational arenas need the most work, says Foley. 2007 will see fraud increases in the use of checks.

Your Identity Far From Safe


ZDNet reports that the new Democratic Congress is dragging up the same ho-hum, ineffective ID theft legislation as they did when the GOP was in control. Sen. Dianne Feinstein of California either doesn’t understand the problem or doesn’t really care about the consumer in her new bill. In another article by Bob Keefe, there are too many exceptions for business and government and too few rights for Americans, according to Marc Rotenberg of Electronic Privacy Information Center. Bill preempts stronger state laws, says Beth Givens at Privacy Rights Clearinghouse. Basic problem, legislation all focused on after-the-fact, rather than preventing the crime.

Is the US Postal Service Aiding and Abetting ID Theft?


Certainly they would not do it consciously. However, like so many other government entities, security levels are lower than they should be, and there are inherent risks like the one that happened to me. We had been missing mail recently, one or two pieces at a time which eventually reached us. This last Friday, a neighbor brought me five pieces, three junk mail, one personal financial, one credit card offer, also considered junk mail, wrongly delivered to his address. The financial did have sensitive data, but the credit card offer had all the ingredients for someone to steal my identity, had the neighbor not been so thoughtful and the offer ended up in the wrong hands. I’m complaining, which you should do if it happens to you.

ChoicePoint Identity Theft Victims Almost Double


Soon after the ChoicePoint incident in Feb. of 2005, victims started showing up; 800 of them. CP questioned the figure which was eventually confirmed, but the news is that two years later the number of casualties losing money has risen to 1,400. The average loss per victim in 2005 was $6,383. That’s almost $9 million in consumer losses from just one data breach. There have been 444 since ChoicePoint, 10 since the first of the year and it’s only January!

Sr. Gets Jr.’s Credit Card Mail…Also His Credit Record?


A reader has told me about a situation that happened to him recently that reeks of potential disaster. The Sr. received an offer for a credit card through the mail, but it was addressed to him as “Jr.” Jr. has lived close by for several years, and is old enough to have established his own credit record. So why the switch all of a sudden. The problem is Sr. has had a bankruptcy which he does not want connected to Jr. in any way. It could be another example of credit report mistakes; 54 percent contain mistaken personal info, 25 percent serious errors. I advised Sr. to request his credit report and tell Jr. to do the same. Just another example of sloppy work in the data industry.

Cyber Crime Big in 2006


Brian Krebs reports in a recent Washington Post article there was a significant spike in 2006 in junk e-mail, and the crooks continue to get more sophisticated. I just had a “phishing” attack by someone masquerading as an eBay member who threatened to call the police if I didn’t explain where the phone he ordered was. He wanted me to respond with some personal information which, of course, I didn’t. What’s even more frightening is another industry article stating that marketers are turning to alternate methods of data collection after you opt-in for e-mail. Expect to receive surveys and polls, and ultimately relinquish more of your privacy.
This Mailing List Could Be Hazardous to Your Privacy


NEW


This Mailing List Could Be Hazardous to Your Privacy:

“Maladies and Ailments From Infolio” is a list of almost 13 million US consumers with ailments ranging from heart disease to impotence, ADHD, cancer, diabetes and more.

Want this list used in your next job interview or health insurance examination? Probably not.



Friday, January 12, 2007

Name, Personal Data Should be Recognized as Media Form

Like TV, Radio, Magazines, Newspapers, Internet


This is an idea I have toyed with for several years. Establish our names and private information as an official class of media like broadcasting, print and the Internet. Each of these entities has control over the use of their medium, and is paid handsomely for it. This new innovation could be called "Moniker Media," for lack of something more creative. Companies and government would have access to the Moniker Media, but only with the public’s permission, making this medium targeted, compared with the others’ shotgun approach.

Advertising a Fast-Growth Business


According to Kagan Research, a leading consumer research firm, advertising revenues will increase by almost 18 percent between 2007 and 2010, from $269.3 billion to $317.7 billion. I mention this because it doesn’t even include the sale of your name and private information by the junk mail industry, a figure that is well guarded due to its sensitivity. I have an idea what that is but decided to go to the experts to get their answers.

Junk Mail Industry’s Most Guarded Secret


I Emailed the Direct Marketing Association, industry trade organization, and DM News and Direct Magazine, leading industry trade papers. Not a word. Zilch. That’s been over a week with no reply, and, as has been the case in the past when asking for this kind of info, I don’t expect a response. These are not trade secrets, or at least, they shouldn’t be. Consumers have the right to know how much their names and personal data is being sold for. After all, they are the name-holder.

Actual Figure is Staggering


I have developed my own formula for determining what your names and private information sell for on the open market, and you should be aghast at the amount simply because you are not sharing in the gold mine. $4 billion annually and growing each year. That’s right and the growth of this field surpasses traditional advertising, therefore, it is probably more like 20 percent. If that’s the case, the $4 billion will be something like $4.8 billion in 2010. So what’s the purpose in telling you all this?

Supplement Your Retirement with Junk Mail


You can supplement your retirement income by an average of $607 monthly just by shopping junk mail, but first you must take control over your sensitive data. Either both business and government must agree to this arrangement, or federal legislation must be passed that will make it law. Then, half the annual revenue (currently $4 billion) goes into a simple interest-bearing account that can add up to the $607 figure at retirement.

Everybody Wins!


There is an initial loss of mailing list revenue by junk mailers, but they make it up in new customers anxious to share in the rewards of Moniker Media. Consumers will also have the right to decide what junk mail they want to receive, thus, making it more targeted for companies. The customer will also feel more secure in giving up personal data since they have control over its use. Government will have access to certain data based on need, but also with independent oversight. The individual, of course, gets what should have been theirs for years.

Wednesday, January 10, 2007

Brookstone "Surprised" Over Recent Comments

Blame It on Customer Service


In a recent post about Brookstone not providing an opt-out provision for selling your name, I quoted their customer service person, Patricia, as saying they do not provide this service. It’s not like she didn’t understand the question, because the answer was very specific as you can see in the post. As a result, I received an e-mail from Jay (no last name to protect the innocent), also in customer service, exclaiming his surprise at both what my blog said and what Patricia said.

Jay Has an Explanation, Requests Blog Update


“As is customary in the direct mail industry, we exchange our mailing list with other companies…” he starts, and proceeds to offer to remove my name from their list if I provide applicable information. He closes with a request to update my prior blog on Brookstone to reflect this latest statement on a policy that should have been in their catalog to begin with. At this point, I was becoming more concerned about Patricia’s fate, who most likely wouldn’t have given an answer that wasn’t predetermined policy.

!!!BROOKSTONE UPDATE!!!


So here’s the update. First of all, Jay, speaking for Brookstone, doesn’t have the candor to say they sell their mailing list much more than they “exchange” it. Second of all, don’t look in the catalog for an opt-out because it isn’t there. Third, even if you e-mail Brookstone—at least in my experience—you won’t get satisfaction. Fourth, start your own blog and complain and you are likely to get results. Hopefully, this is what Jay was looking for.

Moral of the Story


The selling of your name in the junk mail industry is one of the best kept secrets in all of advertising. Not just that they do it; we all know that. The big secret is the mystery behind how they do it, and how much they rake in off consumers’ names and personal data. Ready for this? That figure amounts to over $4 billion every year, and you don’t get one penny out of it. On the other hand, if the individual had control, they could determine who has access to this sensitive data, and be paid each time it is sold. Update complete.

Monday, January 08, 2007

Big Brother Pushes the Envelope...Again

Bush, the Letter Opener


When working at my first junk mail company, one of the indoctrination drills was to observe the mailroom where all the orders were opened. In those days they did it by hand. Before I left, there were machines that did this automatically. Now the White House monarch wants to do that job for all Americans, except Bush is talking about your personal correspondence. Just when you think you’ve seen everything, this man comes up with a new zinger.

The “Signing Statements” Keep Coming


You remember “signing statements,” those additions this president keeps adding to bills that he signs. Well he added another one to the postal bill signed before Christmas, stating that the federal government can open your mail for “foreign intelligence collection.” MSNBC broke the news in a January 4 article, “Warrantless mail search may be allowed.” In case you forgot, Bush has issued at least 750 signing statements while in office, more than all other presidents combined.

Another Republican Questions Their Own…Again


The issue was first disclosed by the New York Daily News. It was Maine Republican Senator Susan Collins’ postal reform bill to which the signing statement was added, and she called on Bush to “explain why he used it to claim he can open domestic mail without a search warrant.” Of course all the Dems are crucifying Big Brother-in-chief, but it was another Republican, New York’s Mayor Bloomberg, who stated he “’would be surprised if the courts sided with the President,’ even if a warrantless search were done under threat of a terror attack.”

George Orwell Made Me Do It


The author of 1984 must have had an impact on the Bush/Cheney team as I have written before, although there is nothing historical to back that up. I still say Orwell’s teachings are revealed as a strategy play-book for this administration in Jackie Jura’s Orwell Today Web site in the “Surveillance” section. The novelist wrote about technical advances that allowed his Big Brother to spy on the citizenry 24 hours a day. All you owned was what was inside your head in 1984, but if the Bush gang has anything to do with it, that will go on the market soon. But Bush’s recent “signing statement” mentality seems to have been lifted right out of 1984, where the controlling Party from Orwell’s fictional city of Oceania opened all letters in transit. Case closed.

Complete Confusion as Usual


In one version from the Washington Post, the U.S. Postal Service is in agreement with the White House, according to Bush’s new Fox-trained, front man, Tony Snow. On the other hand, junk mail industry publication Direct says the USPS is disputing Bush’s right to open your personal mail. Snow goes on to reinforce this administration’s position that somehow it has been granted unlimited authority. Most Democrats and many Republicans disagree with the latest signing statement and sound as if they are becoming weary with this Big Brother bully-pulpit.

Let the fireworks begin!

Wednesday, January 03, 2007

Abacus on the Move Again...with Your Sensitive Data

Abacus Acquired by Data Broker Epsilon


The end of 2006 brought another move by the Abacus Alliance—so-named because it has the sensitive data from over 60 million households, representing hundreds of your junk mail catalog company purchases—from parent DoubleClick to another data broker by the name of Epsilon. You may remember how, when DoubleClick bought Abacus from its original owners in 1999, they attempted to combine 100 million private Internet profiles with the Abacus database. The whole thing was eventually stopped, and was even rebuffed by junk mailers.

Why Should You Be Concerned?


To begin with, those 62 million households made 257 million purchases from catalogs such as Brookstone, National Geographic, Restoration Hardware and Sharper Image using sensitive data such as credit card account numbers. That private information is now in the hands of Epsilon, a data giant on its own, with 227 million consumer names, including over 1000 demographic and lifestyle attributes. There is nothing to prevent Epsilon from marrying the two databases, providing additional insight into your daily activities. By the way, back in February of 2006, Epsilon had already acquired DoubleClick’s Email Solutions unit, one of the largest permission-based email marketing service providers in the industry.

It Gets Worse


Epsilon is owned by Alliance Data Systems, a leading provider of credit card purchasing activity services, with nearly 90 million accounts on file, resulting from 2.7 billion annual transactions. Alliance also does data mining/predictive modeling to, “…create intelligence, predict behavior, anticipate expectations and optimize customer economics.” Their words. Another behemoth like ChoicePoint, Acxiom and LexisNexis. One more location for your name and personal data to reside, and be manipulated to pry into every aspect of your inner-sanctum.

Why You Should Worry


I know you enjoy the conveniences of fast credit, shopping online, and even the loyalty programs that offer discounts from your local super market. But in each case your sensitive data is in jeopardy, and with organized crime now leading the way, the identity crisis can only worsen. And, there is no reason that you shouldn’t continue with these beneficial programs and add even new ones in the future. However, you must first be given control over your name and private information by business and government, in order to supervise its distribution. As an added benefit, you should be paid each time it is sold.

No End in Sight with Big Brother the Eventual Outcome


The Bush/Cheney administration, and many Republican members of Congress, would like nothing better than the merging of enough data companies that would allow the government to go to one source to do its domestic surveillance. The business community would salivate over this ability to pry into the lives of their customers. And folks, it is possible today by tying together an Epsilon, ChoicePoint, Acxiom, LexisNexis, TransUnion, Experian, and Equifax, in a network that could recreate George Orwell’s Big Brother in the year 2007.