Search This Blog

Friday, May 30, 2008


ACXIOM PROVIDES BUSINESS NEW AUTHENTICATION OF ONLINE CUSTOMERS. BUT, HOW ACCURATE IS IT?


Junk mail data broker, Acxiom, has just announced that it will introduce a new service, FactCheck-X Authenticate, to business clients based on unique biographically based questions asked of online customers that are designed to qualify them with the company they are contacting. This could be logging into your stock portfolio, accessing your bank statements, or perhaps even looking at your medical records. In an article on PR-inside.com, “businesses are more secure and customers can experience a better online authentication experience.” I doubt the latter, and here’s the reason why.

In 2005—and if anyone finds a later report please let me know—the non-profit Privacy Activism did a study to determine the accuracy of biographical information in two major data brokers, Acxiom and ChoicePoint. Acxiom’s authentication, above, is based on biographical data. It was discovered that even in the most basic information like name, address, phone number, Social Security number, errors were found in 67 percent of Acxiom’s reports. If this has been corrected, I welcome factual substantiation that it has.

NewsEnet.com provides insight into some of those biographical questions inquiring consumer minds might be faced with.

• In what subdivision do you live?

• Where does your brother Mike live?

• Select a state which you were previously licensed to drive.

• How many fireplaces are in your current residence?

OK, what if both Mike and I just moved? Will Acxiom allow for this mistake, and then ask where the former residences were? The fact that they are asking anything about my driver’s license bothers me, but I guess telling them about my fireplace won’t hurt.

Jennifer Barrett, Acxiom’s chief privacy officer, won’t reveal specific sources of your biographical data, but adds that it did come from “public document files and private sources.” She also cites the Patriot Act as a crutch for doing this, which immediately throws up warning flags and reminders of NSA’s warrantless spying. Lee Tien of non-profit Electronic Frontier Foundation sees no advantage to the service. Others can find out many of these facts about you, and her opinion is that a random, newly assigned PIN would be safer.

I did a post in February of this year where it is shown how your name and personal information are eternalized—similar to your name and date of passing on your tombstone—in data broker databanks across this country and throughout the world. The major companies responsible for collecting your private information and archiving it forever are Experian, TransUnion, Equafax, ChoicePoint, and of course Acxiom. The first three are also credit bureaus, holding your most precious credit data as well.

In March of 2007, another post was done on Acxiom’s new connection to May Company stores, which were eventually converted to Macy’s. Acxiom was enhancing the Macy’s list—including Bloomingdale’s, also a part of Federated Stores—with customer personal data, among which is your age, income, plus a number of other demographic characteristics, then purchase and lifestyle behavior like health interests, religion, credit cards held, politics, cell phone owners, investments, reading and vacation habits, and wine drinkers. If you are a Macy’s or Bloomingdale’s card holder—there are over 3.6 million—go to this site to see what all they know about you.

So the next time you shop at Macy’s or Bloomingdale’s online, they might ask you if you have arthritis, or if you like baseball, if you are on a diet, what shape your houseplants are in, or how was your recent skiing trip? If you can’t answer the questions, don’t be surprised if they hesitate to sell you a collar for your cat, which they already know you own.

Thursday, May 29, 2008


2008 PRESIDENTIAL CANDIDATES ON PRIVACY: JOHN MCCAIN


This is the first in a series of posts on the 2008 presidential candidates’ positions on privacy. With identity theft the number one consumer threat to Americans today, you would expect at least the Democrats to be coming out full-bore with promises to secure our sensitive data. The Dems used to be the party of the people, protectors of individual rights, but that has gone by the wayside in favor of just winning elections. I even contacted the Obama campaign at the national and local levels because of his cry for “change.” There was no response. But then this is about John McCain.

Although it seems apparent that this candidate plans to carry out many of the policies of the Bush administration, he did stray recently by stating that he didn’t believe Congress should immunize the phone companies for liability in the NSA warrantless wiretapping. See Electronic Frontier Foundation.

According to Michael Arrington, a blogger and former corporate attorney, McCain’s reply to a question re. the government’s role in preventing identity theft and protecting online privacy: "I think the best solution is continued consumer education and business innovation to try [to] come up with further safeguards." This is from an interview Arrington had with McCain back in late 2007, and reported by Tech Policy Central.

Along the same lines in the Los Angeles Times blog, a McCain representative speaking on behalf of the candidate at the Computers, Freedom and Privacy conference held earlier this month, indicated that “McCain preferred a more market-oriented approach to technology issues.” Although directed primarily at the Internet, it is further substantiation that the Republican will act like a Republican, favoring big business over the consumer. The latter my comments.

If you go to McCain’s presidential election site, you won’t find any commitments to protecting your privacy. There is a page of “Issues” that lists fourteen topics, from the economy to the space program, but nothing that says he will address the ID theft problem and individual privacy in general. Earlier in an MSNBC article, the candidate states that he will talk about consumer issues during the course of his campaign.

In another recent blog by Lindsay Byerstein, Majikthise, she feels that McCain could be entertaining an advocacy of executive power even more extreme than the Bush doctrine. This stems from the presidential contender’s comment at Wake Forest University recently that “activist” federal judges were usurping the power of state legislatures. Byerstein wonders whether McCain is recommending that the Executive branch now assume full responsibility for interpreting the Constitution. She quotes Jeffrey Toobin, attorney and legal expert for The New Yorker and CNN who compares McCain’s position with Bush who expressed contempt for judges who “legislate from the bench.”

In Toobin’s The New Yorker piece, he observes the candidate’s reference to “penumbras” and “emanations” used by the Supreme Court as a way of skirting “clear and rigorous constitutional reasoning.” Not accidental, the use of the two terms penumbras and emanations says Toobin; the same words coming from William O. Douglas in 1965 in a ruling that a state could not deny married couples access to birth control. In the court case, Griswold v. Connecticut, it was also the first time the Supreme Court recognized a constitutional right to privacy.

Wednesday, May 28, 2008


IT’S OPEN SEASON ON OPEN ID


If you haven’t already heard of it, OpenID is a shared identity service that lets Internet users log into a number of web sites with only one digital identity. This eliminates the need for a user name and password for each site. In a Washington Post article by Brian Krebs, “The key to your online identity [in OpenID] is the use of a Web or blog address, such as http://myblog.someplace.com.”

An OpenID is obviously no more than a URL, which simplifies things if you already own one. Then you have to pick a provider like Live Journal, Vox, VeriSign or MyOpenID. By using your online identity at a site accepting OpenID, you then have to confirm your identity credentials, and you’re in.

From what I can tell by visiting the four providers mentioned, the most personal data you give up to join is date of birth. You may be asked for additional private information later as a member when participating in company promotions or sweepstakes. And this data could be shared with outsiders. But the only site asking for a full name—almost completing the formula that could trigger identity theft along with date of birth—Is Vox, and they also want your gender. MyOpenID and VeriSign offer passwords along with normal industry standards for security. Vox and LiveJournal add to that SSL encryption to protect some data transmissions.

Bill Gates said Microsoft would throw their support behind OpenID, but, then, MS attempted to control online IDs with MSN Passport a few years ago which never caught on outside the company. Yahoo and Google also tried their own versions. Maybe it took a new set of entrepreneurs to get things rolling, because it is reported that there are over 160-million OpenID-enabled URIs (Uniform Resource Identifier), and nearly ten-thousand sites supporting this kind of login.

There are mixed reviews with advocates feeling OpenID can both prevent and open the floodgates to phishers and scam artists. But I think we have long since accepted the fact that if sensitive information that can lead to ID theft is available out there, the bad guys will find a way to harvest it. Prove me wrong, but I don’t think this is any different. There is another site from the WP article that provides more depth to the technology of OpenID that I am linking to here.

The upside is plainly convenience. The downside—and you’ve heard this many times from me—is that the OpenID is yet another process of creating a community of databases with at least four players already collecting your personal data. Since this new-found brainchild from geekdom will open the way to every portal on the Internet with which you have an association, and potentially could expose your complete world of private information, don’t you think you should demand some major controls over its security?

I’m not crying wolf before he’s in the henhouse, but at the least I would like to hear more from this new industry about what their plans are to protect your sensitive data, and just what safeguards will be put in place to combat a potential disaster of data loss when it happens. And we know it will…eventually.

Tuesday, May 27, 2008


IS THE YOUTH VOTING REVOLUTION HERE?


According to a “Letter to the Editor” in my local newspaper, youth voters are predicting a revolution in the election process, and all signs point to a culmination of this promise in November of 2008. The young lady refers to a “reigning generation” that laments dropping a lousy situation in their laps, but she complains that the same group never asked for her or her peers’ input on the issues. Further, the younger constituents have only had the experience of two presidents to help them establish their opinions in the political process, and neither has been what they consider presidential role-models.

In the past, the youth vote has had poor turnout at the polls leading some candidates to believe they don’t deserve much effort. But a recent article in Readers Digest claims there is a new group, ages 18 to 29 called the “Millennials,” that is finding its voice, and plans to use it in the November 2008 election. They profess to be leaving you “Apathetics” behind, and do something about their future. They also accounted for 28 percent of the identity theft victim complaints in 2007, indicating to me there must be concerns for the protection of their names and personal data.

While Millennials are more liberal than their parents, they aren’t as interested in universal health care as simply reducing health care costs. They support gay marriage, but have become more religious in recent years. They voted first in 2000 when they directed their attention to John McCain because of his call for “shared sacrifice and community service.” The Arizona Senator may not be able to expect that same support in 2008. In 2004, Millennials cast almost as many votes as those age 65 plus.

In another piece on the Millennial revolution in the Zero Beta blog, 80 percent feel the economy is very important, followed by 61 percent who felt the environment was the major issue. According to one report, 40 percent of the “M” crowd is Independents, 35 percent Democrats and 25 percent Republicans. And they aren’t poor or uneducated; they are middle class, educated and savvy. But Zero Beta says the Millennials need incentives to get them to the polls, and they haven’t had them in recent years…not until now.

RD found that there was “widespread disillusionment” with the Bush administration, and apparently not a full endorsement of the Democrats by the M folk. They are firmly against the Iraq war, and want to see a sense of morality and good deeds return to the White House. Christina Gagnier of Mobilize.org puts it this way: “…we’re entrepreneurial, not for the traditional purpose of making money but for doing social good.” The White House and congressional leaders could do well by adhering to those values.

I am always looking for a grass-roots base for support in my concept that individuals should be granted control over their names and private information, and be compensated when it is sold as incentive to take on this new responsibility. On the latter, the M crowd is the perfect age group to share in this supplemental compensation to their retirement of an average of $607 each month.

Time will tell just what the Millennials want in their next President, but hopefully one of the qualities is that he or she endorses an agenda for them to take back the rights to their privacy.

Monday, May 26, 2008


A SAD COMMENTARY ON AMERICAN VALUES IN THEIR VOTING HABITS


If you watch American Idol (I don’t), you know that the voting that crowned David Cook the current “Idol” was a record 97.5 million votes cast. Of that, 82,875,000 were age 18 and over. I will get into some other interesting age demographics later. But this is a commendable accomplishment for an event that is entertainment only, and which has no real bearing on the future of this country. Or does it?

In the 2004 Presidential election, 64 percent of the 197 million citizens age 18 and older (126 million) voted. But of the 72 percent that took the time to register (142 million), 89 percent indicated they voted. Big difference in those percentages, proving that to get out the vote, you have to get people to register first. Duh! Independents totaled 26 percent of the voting population; Democrats and Republicans were 37 percent each. So what’s the problem, you say? Looks like the apathetic way American voters have always approached their elections, and that, I tell you, is the problem.

Here are the statistics to prove it. The 97.5 million Idol votes in 2008 were 23.5 million more (31.8%) than the 74 million in 2007, when another very popular contestant by the name of Jordin Sparks won. Now compare that with Presidential voting in 2000, where the turnout was 60 percent, only increasing to 64 percent in 2004, an increase of only 6.7 percent. Keep in mind that in both 2000 and 2004, there were critical issues at stake to this country, and concerned Americans should have rushed to the polls in droves. But they didn’t. So they ended up getting what they deserved.

Back to my earlier point reflecting on how American Idol mirrors the pitiful state in which this country finds itself. Don’t get me wrong; I am not blaming the TV show for the state of our affairs. That’s our own doing. What I am saying is that if the American public can become so focused on a purely entertainment media event, why can’t we use this same enthusiasm in exercising our right to vote? The answer is that Idol provides release, and Presidential elections only give us decisions to make that will determine how the country is run. And of course they are tough decisions, but if you want to be a voice in the political process, you had damn well better get to the polls in Noverber.

Here are the demos promised earlier: Of the American Idol votes in 2008, 84 percent were age 18 and over; 34 percent were 50 plus; 11 percent 65 plus. The 25 to 49 age group was largest at 43 percent. Don’t know what you were thinking, but that blows me away. I had visualized the demographics as pre-teen to around age 35, but not 63 percent of the Idol voters over age 35.

This tells me that a TV show like American Idol can capture a large percentage of the public’s attention, drive them to the polls to record their votes, increase participation in subsequent years, while duplicating the same event on an annual basis. And it is this statement in comparison to Americans’ presidential voting habits that is a sad commentary on our values.

The answer has not been found in the two-party system we have today. Republicans have doomed the ethics of the voting system to a number of years necessary to repair itself. But Democrats have allowed them to do it, and have offered nothing as a fix.

If you recall earlier, Independents now represent 27 percent of the voting public, and growing by the day. If you want to help restore this country to a representation of the people over big business and lobbyists, take a look at the Independent movement as a possibility. I am convinced it is the only answer to renewed protection of our names and personal data, and the privacy of this country’s citizens in general. Check out the Web site for Independents: Committee for a Unified Independent Party (CUIP). I did and found a home as an Independent.

Thursday, May 22, 2008


SUPPLEMENT YOUR RETIREMENT INCOME (SOCIAL SECURITY, PENSION, SAVINGS) WITH JUNK MAIL…IT’S THE AMERICAN WAY


Our American way of life dates back to the 17th century, and is based on individual rights including life, liberty and the pursuit of happiness. The one thing that separates one person from another is a unique personality that comprises habits and lifestyle characteristics. The given, and legal, way we differentiate between the population is with names and personal data. No one could experience the American Dream without them but alas, we have sorely lost control over this most precious of possessions. And this is where the story begins today on how to help solve a bleak retirement outlook.

That is the subject of a recent article on MSN’s Money Central. With only a few Americans contributing to their retirement accounts—and in small amounts when they do—the article determines that the outlook is definitely bleak. Only 14% gave to themselves in 2006. In another discouraging statistic, just 60 percent of workers between 21 and 64 (58 million) work for companies that have retirement plans. The outcome is that half of all working Americans do not have the means to live comfortably when their ability to perform in the marketplace is over. Washington: we have a problem.

Before the total picture became so dismal, I blogged on this several times suggesting how those that depended on Social Security could supplement their income with junk mail. Today it has become a necessity for all. To understand the predicament, it has been estimated that a 65-year-old couple retiring in 2007 would require $215,000 just for medical expenses over 20 years, not including the unreal costs of nursing homes, assisted-living facilities or home health care. And it is sure to get worse.

Today if you retire, nearly 40 percent of your receive your income from Social security, just over 19 percent from pensions and annuities. Then there are 23.7 percent who get it from earnings, 15.4 percent from assets like IRAs. But in low income households, 87.6 percent of their retirement comes from Social Security. As the article suggests, if you are in that group that has hesitated to plan for the future, now might be the time to change your habits.

So even if you can look forward to some retirement income, chances are that it won’t be enough, and it will have to be supplemented. So how do you do that? I just happen to have an answer. You can add to what you will have available in retirement using your junk mail purchases. If you are still in your teens, you could have an additional monthly income averaging $607 monthly. Nothing to do but shop through junk mail, and have a portion of the revenue made from selling your name and personal data put away for you to tap at age 65. To learn how this is done, see the posts here, here and here.

Basically, it involves placing one-half of the $4 billion made each year from the sale of consumers’ names and private information. Why not? Without you, and millions of others like you, the junk mail list industry would have nothing to sell. Place this money in an interest-bearing account and at maturity it could amount to an average $607 each month for the individual. The latter is figured at simple interest, and with more aggressive methods of investing, could be much higher.

What could be simpler?

Wednesday, May 21, 2008


HOW LONG BEFORE WE ACCEPT INEVITABILITY OF PERSONAL HEALTH RECORDS DATABASES? PART 3


The day has finally arrived. On Monday, Google launched its personal health records (PHRs) information service, which combines their search capabilities with consumers’ personal health records online, according to a Reuters’ article on MSNBC. Microsoft also recently introduced its own version, HealthVault. Google will warehouse participants’ basic medical history, and will collect additional data relating to their condition. There will be links to doctors including their specialties, U.S. pharmacies, medical testing labs, and doctors’ groups. There will be a “virtual pillbox” for notification to take prescriptions, and there will be a warning for potential drug reactions. Users can schedule appointments with their caregiver, refill medications, and get diagnostic results online.

It’s all wrapped up in a neat package, but Reuters says “while medical providers are covered by U.S. privacy laws, there is little in the way of established privacy, security and data usage standards for electronic personal health records despite decades of industry effort.” However, in yesterday’s post Jay Cline reported in Computerworld, “free-standing PHRs are subject to consumer-protection laws that prohibit false statements and impose security requirements.”

Confused? Go to My PHR, a site sponsored by the American Health Information Management Association (AHIMA), scroll down to “Access and Privacy Laws.” Click on the sixth question. Here’s the Google Health site. And I haven’t overlooked Microsoft; did two posts on them in October of 2007 here and here.

There are other players. Dossia Founders Group consortium of large employers providing independent, lifelong health records for employees, their dependents, retirees and others. This is another database of health records where participation is voluntary, but the individuals do have complete control over who sees the information. Next, WebMD Health Record, the forth database of health information we’ve covered, available free, which works in coordination with WebMD Health Manager.

Finally, and the fifth database to be introduced in the market so far, Revolution Health, run by former AOL CEO Steve Case, with notable board directors like former secretary of state, Colin Powell, and former Hewlett Packard CEO Carly Fiorina. Fiorina was leaving HP at about the time the company was embroiled in the pretexting controversy involving the illicit collecting of board member telephone records in an investigation over who leaked confidential company information.

So we have now arrived at the number of at least five personal health record databases being created where personal data will be housed along with our private health information. Two companies, Microsoft and Google, are at least capable of, if not already at some level of encryption of their data. The other three I am not sure about. If ever there was the need for safe encryption, it is certainly demanded in a depository of the ultimate in personal sensitive data

However, what is missing in this new technology is major control over its security, and the promise that it won’t become a marketable commodity like the junk mail industry’s mailing list business which already chronicles our lives in databases and sells it on the open market in the amount of over $4 billion each year. The question, of course, is will we get that promise, and from whom?

Tuesday, May 20, 2008


HOW LONG BEFORE WE ACCEPT INEVITABILITY OF PERSONAL HEALTH RECORDS DATABASES? 2


In yesterday post, I quoted from a Computerworld article by Jay Cline that believes the needs of the medical community for personal health data will outweigh the privacy concerns within five years. Don’t know where the timing comes from, but my guess is it will happen sooner.

Cline hits all the right buttons on construction of the database, like limiting it to one location, simplification of files and patient access among them. But he lost me when he implied that there may be no limit to what might be included in the database. Like I pointed out yesterday, the junk mail data brokers started with small collections of information on consumers several years ago, and today there is very little they don’t know about American households. The problem with this is that they share it with government agencies almost at will, and sell it to the tune of $4 billion annually. A practice that has proven itself highly conducive to identity theft.

What really frosts me is a statement by the author that is tragically true: paraphrased, it indicates that the U.S. would have to look to European Union standards to meet the standards that privacy advocates would certainly ask for in this kind of program. They are:

• Consumer total awareness of what is in personal health records (PHRs)

• Complete user access

• Data integrity (common sense but sorely lacking in U.S.)

• Best available security.

• Voluntary participation

• Control over individual health information

• Strict enforcement for violators

This is perhaps one of the saddest commentaries on congressional leaders that have been totally inept in passing privacy legislation to protect their constituents.

Advocates are concerned what a user, other than the consumer whose data it is, might do with the information. Good point, and the way to solve this issue is to limit outside use to only that approved by the individual, unless under emergency conditions. Then, only the caregivers involved should be able access it.

Cline offers a coalition in healthcare similar to the retail industry’s Payment Card Industry Data Security Council. However, TJX (TJ Maxx, Marshalls) was in compliance with PCI standards when it lost 94 million credit and debit card holders’ account numbers to hackers trolling one of the TJX store’s parking lot with wireless equipment.

I am not for big government, but there are some things that are better handled at the federal level. Like the Federal Trade Commission’s Do-Not-Call registry with over 150 million people signed up. It is one of the FTC’s most outstanding success stories and could be repeated in the personal health records controversy (PHRs), possibly best in coordination with an agency like the National Institute of Health. The article does mention that PHRs are subject to consumer protection laws. That could bridge the gap until consumers are granted control over their names and private information, which should include their medical data.

Next post: What companies are competing for the personal health data, and how does the Health Insurance Portability and Accountability Act of 1996 (HIPAA) fit in the scheme of things?

Monday, May 19, 2008


HOW LONG BEFORE WE ACCEPT INEVITABILITY OF PERSONAL HEALTH RECORDS DATABASES?


The jury is still out but the heat is still on to collect and computerize our personal health records (PHRs). One opinion has it that benefits will “eclipse” privacy concerns. And with certain reservations, I agree. As staunch as I am for individual rights to control our names and private information, if you are in the hospital emergency room with a family member, you want them to receive the best possible care, and most agree that can happen only if the caregivers know the patient’s personal health history.

Jay Cline’s opinion piece in Computerworld, “Benefits of personal health records will eclipse privacy concerns,” makes a good case, concluding that the debate will be over in five years, but many privacy advocates who actually anticipate the inevitability, still want to see better control. Over both the PHR providers and by the individual concerned. Cline says there will be six prevailing stipulations of this kind of database.

• A single repository combing multiple sources.
• Simplified, easily searchable files.
• Doctor’s trust
• Understandable to the patient.
• Patient can add and flag incorrect information
• Patient controls who sees what

But when he gets to what will be included in the database, he makes the statement that, “The sky is really the limit…” And to me that is really scary, because that is how the junk mail companies like ChoicePoint, Experian, Acxiom, Equifax, TransUnion and other data brokers started years ago. With your name and address, and a few other items like age, income, education and occupation. That eventually expanded into what we read, drink and smoke, and whether or not we gamble. Who we vote for, what our religion is, our surfing habits online, the charities we favor, how we invest, and of course the precursor to today’s subject, what ailments we have and what medications we take. Yes, it’s all out there and for sale.

Promised data to the PHRs contains the following: prescriptions; drug allergies; immunizations; illnesses and hospitalizations; test and clinical records; living wills and other info you can see by going to the Computerworld article in the above link. I did a series of five posts you might want to refer to on this issue: “Medical Identity Theft Also Needs Your Attention…And Now.” It provides the background on what can happen when the bad guys steal your medical identity, and why it is so important for this private information to be protected.

In another of my posts, “Warning Out on Health Data Storage Sites,” there is a report issued by the World Privacy Forum in February of 2008 about the hazards of giving up your personal health records. The catch, according to the WPF, is that most of these companies are not subject to federal regulations relating to consumer privacy and security. It is for that very reason that I feel the right solution is only one database—as Cline specifies—operated by a non-commercial entity, with its own set of privacy rules backed by federal enforcement.

Next post: How the U.S. must take its privacy guidelines, even in healthcare, from the European Union.

Friday, May 16, 2008


THE “JUNK MAIL REVOLT” HAS ARRIVED


Any way you look at it, it’s junk. I’m talking about the tons of unwanted mail that overwhelms many Americans each year. The average household receives 800 pieces of junk mail annually, much of it not welcome to the people receiving it.

But, before reading further, check out the launching of the latest effort in the Do-Not-Mail war: JunkMailRevolt.org. This is a well-planned and calculating campaign to convince a lethargic Congress that some people are fed up with junk mail. I have been swapping comments with its founder, Rezzie Dannt, for over a week now on Center for Media and Democracy’s PRWatch.org.

The nucleus of the Junk Mail Revolt is to load up Washington with this unwanted advertising, and dump it on the desks of out of touch Congressional leaders. Like the movie, Miracle on 34th Street, where the post office piled up letters of kids addressed to Santa Claus on the judge’s desk to prove Edmund Gwenn, who was on trial as a fraud, was the real thing.

Here’s what the “Revolt” wants you to do: First, sign up on their Web site; second get a box and start collecting your junk mail; third, wait for instructions on what to do next and when. JMR also asks you to help enlist others in the fight, link to their Web site, sign a petition, and a host of other things that are easy to do but very effective if you want to join the revolt. You can see it all on their “Support” button.

Yesterday’s blog was an update on the Do-Not-Mail issue, which follows another one done on April 3, which was more environmentally focused. Two of the primary concerns in this issue are choice and waste damage to the environment. The Revolt is preference driven offering those who want to stop receiving junk mail the right to be heard, and providing an avenue to keep it out of the trash by limiting it only to those who want it.

JMR hopes to establish a Do-Not-Mail registry similar to the Federal Trade Commission’s Do-Not-Call. And I think that is a good idea. The question is whether the public is fed up enough with junk mail—compared to how they felt about junk telephone calls during dinner and shower time—to support this legislation. The Revolt says yes: in 2007 a “Zogby poll found that 89% of Americans would support a Do Not Mail registry that allows people to opt out of unwanted paper junk mail.” Unlike the ineffective Mail Preference Service of the Direct Marketing Assn., an FTC Do-Not-Mail list could be another huge success.

But there are obstacles. One in particular was covered in yesterday’s blog, where I noted that we have, “a Congress that pretty much does what the lobbyists tell them to do—and I can assure you from my 35 years in the junk mail industry there is a strong lobby—so we could probably expect a law that is pro-business, leaving the consumer at their proverbial spot at the end of the line.”

That’s all the more reason you should get behind the Junk Mail Revolt if you don’t want the stuff, and give them your full support.

Thursday, May 15, 2008


TO DO-NOT-MAIL OR NOT TO DO-NOT-MAIL


After two weeks of my taking care of things in addition to protecting your name and personal data, the “Do-Not-Mail” issue jumped back into the news on May 5. In the Center for Media and Democracy’s PR Watch.org site, Anne Landman has done the constituents of “Leave my mailbox alone” a great favor. She examines the subject from all directions, and narrows it down to some alternatives that she feels are appropriate. Of course I could not resist commenting on her piece by espousing my concept that the answer is for consumers to be granted control over their names and private information.

My last blog on the issue was April 3, which started with the whining of junk mailers over the DNM idea, and proceeded to refute some facts and statements made by opponents of a do-not-mail law. There are arguments on both sides. For example, the junk mail industry is concerned that legislation could be passed that stops all junk mail, regardless, which would be bad. There are those who want it, just like another similar issue, smokers, afraid they would be banned from the world. It didn’t happen, and “limiting” junk mail will not sink an industry, nor put the U.S. Postal Service out of business.

Landman reminds us of some pros and cons of this kind of federal law that are worth reviewing. As already stated, the doomsday argument is not valid, and since it would probably be run by the Federal Trade Commission, and if the Do-Not-Call registry is any example, a DNM registry would be equally successful. But Landman reminds us of the pitfalls of a Congress that pretty much does what the lobbyists tell them to do—and I can assure you from my 35 years in the junk mail industry there is a strong lobby—so we could probably expect a law that is pro-business, leaving the consumer at their proverbial spot at the end of the line.

Next, the author brings up one of the real laughables in junk mail; the Direct Marketing Assn.’s “Mail Preference Service,” which is supposed to relieve its roster of most unwanted mail. The key word here is “most,” since it only applies to the DMA membership and those numbers are small compared to the total number of junk mailers, which means even saying most is an exaggeration. On top of that some of the largest junk mailers are not even in the DMA, like the Herrington catalog. I even caught a former colleague recommending to his clients to use the MPS list, reasoning since they weren’t getting much mail, their response would be good. He was right.

Another of Landman’s sore spots is the way corporate America displays its privacy notices in type size that requires bi-focals within bi-focals. We’re told they “might” share your name with other companies, the same wording you see on most every catalog mailed. However, they never come right out and say they will sell you names and personal data for an industry total in the list business of $4 billion a year. And there is always a “gotcha” when they offer freebies which usually means you have to turn over sensitive data to get it. Land refers to this as “address harvesting schemes.”

Her alternatives to a Do-Not-Mail list are: a paid postcard or toll-free number for opting out of a list; the post office could just quit delivering mail to “occupant;” or just adhere to the Rowan v. U.S. Post office law upheld by the Supreme Court that allows consumers to say they don’t want certain mail.

I still like my concept better. Grant consumers control over their names and personal data, and compensate them when it is sold as an incentive to assume
this new responsibility.

Tomorrow: the Junk Mail Revolt.

Thursday, May 01, 2008


PERSONAL DATA BREACHES THAT CAN’T BE IGNORED


First, one of the biggest recently, by Hannaford Bros., a grocery chain based in Maine, that sports the largest personal data breach of 2008; the loss of 4.2 million credit and debit card numbers. See my Apr. 2 post. It took place while shoppers were swiping their cards in checkout lines. But it was only numbers, not connected with the owner’s name and address, so no chance of ID theft, right? Wrong! There have been 1,800 cases of fraud so far, and the company actually expected more. So what happened? Gartner research analyst, Avivah Litan, commenting in a Computerworld Apr. 28 article, thinks it involved a “rogue insider.” Based on my 35 years in junk mail database marketing, it is possible that someone in the company was involved. The blog, Securosis.com says the fraud could have been performed “directly in the Hannaford system.” Based on the fact that Hannaford CEO, Ronald Hodge, states that the food chain does not keep any personally identifiable information on the customer, someone or something had to put the numbers back together with a name and address in order for the 1,800 individuals to be victimized.

Moving on to another case, this one definitely insider driven, a former Verizon Wireless employee who worked in telesales was charged with stealing the personal information of an unknown number of Verizon customers while he worked there from November, 2003 to January, 2005. The personal data taken included name/address, Social Security number, and/or Verizon account number. In the Breach Blog, Evan Francen says this position, along with customer service personnel, have a high rate of turnover. Obviously these people need access to the sensitive data to perform transactions connected with the accounts, but until two years ago, workers were able to see the full Social Security number, along with name and address. I am curious if Verizon still asks for SS#s to open an account, and if they do, someone is still viewing the full number, which is why privacy advocates say Social Security numbers should not be required for things other than the most weighty matters like medical and financial. Francen notes that Verizon has 69,000 employees and 65.7 million customers so their collection of personal data must be humongous. You will never prevent dishonest insiders from taking what they want, but we could solve this problem from the other end by giving consumers control over their names and private information.

And then there’s the case of two LendingTree vice presidents who are accused with stealing passwords to the personal financial information of customers seeking loans from LendingTree. The Los Angeles Times says the two former executives swiped this information and gave it to competitors. The five competitors receiving the information are named in the lawsuit but not the two former V.P.s. That sounds a bit strange, but apparently lendingTree has its reasons. Same company, on another front, LendingTree is “politely requesting” Alex Stenback, who does the Behind the Mortgage blog, to remove a comment that the company considers defamatory. Won’t expand on this because it might go into litigation and I don’t want to hurt Stenbeck’s chances to defend his 1st Amendment rights. I suggest you go to Consumerist.com for the details. My point in bringing up this incident, and the other two above, is to emphasize that the practice of employees stealing the personal customer information being collected by the company they work for is alive and very well. You won’t change the nature of those who turn greedy, and apparently we can’t stop data breaches, so the only answer is to let the individual take back control of their sensitive data.

Wednesday, April 30, 2008


LOSING YOUR CREDIT STANDING TO IDENTITY THEFT IS BAD ENOUGH, BUT LOSING YOUR HOUSE?


You know it had to happen, with all the problems in the housing industry. People are desperate and will do anything to save the roof over their heads. Including placing their confidence in the hands of con artists who claim to have a way to save the homestead, but really plan to sell it right out from under you. According to the Boston Herald, “house stealing,” as it is now referred to, combines identity theft and mortgage fraud that could leave you walking the streets.

In an article from NetworkWorld, they actually outline the scam, as follows: 1) the crooks decide to steal your house; 2) next, they heist your identity, readily available in public records and on the Internet; 3) forms are purchased from an office supply store to transfer your property; 4) By forging your signature, your house becomes theirs to sell. If it’s not your regular residence, it could be an empty house, vacation home, or second home like a summer place on Cape Cod. A ConsumerAffairs site adds a fifth step, one where the homeowner loses everything: “Once those papers are filed, the deed to the house transfers to the con artists. And the home belongs to them.”

A trio of thieves including a man and two women stole the identity of 65 year old Judy Melody in Dorchester, Massachusetts, then they attempted to buy two homes in Brockton and Halifax. They were finally caught when trying to sell Melody’s home. This seems almost as bizarre as yesterday’s post on “The Great Impostor of Identity Theft.” According to the FBI, there were 46,717 incidents of mortgage fraud in 2007, but there have already been 30,000 so far in 2008, an escalation which seems to mirror the general trend in ID theft.

The FBI reports in the Boston Herald that the schemes are most prevalent in real estate boom states like Florida and Nevada, but Massachusetts gets its share where Wells Fargo and four other lenders agreed to pay $1 million to victims of a foreclosure-rescue scam. The agency says that “Thieves are preying on people not paying attention to their financial statements.” If homeowners were given control over their names and personal data, much of this problem could be solved through transaction verification that would at least alert the victim to what is taking place.

In a case the FBI and IRS investigated last year, homeowners were targeted who were in foreclosure with a promise to refinance loans. Los Angeles real estate agent Martha Rodriquez used “straw buyers,” individuals who are paid for the illegal use of their personal information, to file fraudulent documents to buy 100 homes, making $12 million dollars in the deal. Rodriquez was caught and prosecuted, but the owners lost the titles to their homes and banks lost the money loaned to fake buyers.

ConsumerAffairs suggests consumers be aware of all material they receive from their mortgage company that looks suspicious, and periodically check the recorder of deeds to make sure the information is correct. The question is, where will they strike next?

Tuesday, April 29, 2008


THE GREAT IMPOSTOR RESURFACES…THIS TIME IN IDENTITY THEFT


You remember The Great Impostor, Robert Crichton’s book about Ferdinand Waldo Demara, who created and lived identities from deputy sheriff to Benedictine monk. Tony Curtis played the part in the 1961 movie which also starred Edmond O’Brien, Raymond Massey and Karl Malden. Demara actually tried to enter a Trappist monastery but failed, then joined the Army but ended up going AWOL.

Fast-forward almost 50 years and enter the female version of Demara/Curtis in Esther Reed, a country girl from Montana, with a good enough intellect to bamboozle the best. She first appeared on America’s Most Wanted in November of 2007, and after a nine year run was captured on February 2, 2008, in suburban Chicago. Esther was an above average student, loved to debate, but following her Mother’s death from cancer in 1998, turned to a life of crime. The question, of course, is who will play her part in the movie.

Whoever that is will have a wealth of profiles to explore, according to the Greenville News. Like stealing the identity of Brooke Henson, a Travelers Rest woman who disappeared nine years ago and whom Police believe to be dead; the latter not considered tied to Reed. Or using her above average intellect to hustle over $100,000 in student loans, and using a Pennsylvania woman’s date of birth and Social Security number to get a fake driver’s license, hit on a West Point cadet, then passes herself off as a chess champion.

Next, on to Los Angels where she convinced a Cal State Fullerton professor to recommend her to Columbia University, claiming to have changed her name because she was in the witness protection program. Returning to Henson’s name, she earned a GED in Ohio, passed a SAT college admissions exam in California that got her into Columbia, where she got the $100,000 student loans.

But she wasn’t through with Henson, using her birth certificate and an Ohio identification card to get a job at Columbia U. in the Vice President University Development Alumni Relations office. In New York a year later, Reed confirmed her identity as Brooke Henson to police, even coming up with answers to personal family questions. She refused to take a DNA test and took flight once again. When they finally caught her in Chicago, she was using yet another identity created from an Iowa driver’s license, compliments of a Kentucky birth certificate and marriage license from Nevada. During all this time, which took place in multiple cities in multiple states, Reed was also using illegally obtained credit cards to charge with. Thanks to Eric Connor of the Greenville News for this running commentary.

As a result of all her escapades, Esther could get up to 47 years in the slammer, and more than $1 million in fines. This is obviously one of the most bizarre cases you will ever hear about, but it points out to just what length an individual will go to steal your identity.

Monday, April 28, 2008


FEDERAL TRADE COMMISSION TARGETS TARGET ADVERTISING – PART 2


Picking up where we left off in the last post on the invasiveness of behavioral marketing (AKA predictive modeling/target advertising), the position of Internet marketers, and other junk mailers as well, is that you, the consumer, want to receive more advertising in keeping with your interests. The question that arises is whether or not you are willing to give up your right to privacy in return?

I take the position that you should not be singled out individually putting all your personal data in the mix to get you that perfect ad. And there is a way to accomplish this by the advertiser focusing on aggregate households of 300 to 500 with the same demographic and lifestyle profiles, resulting in the same goal. Some marketers are even satisfied to work at the zip code level containing 2,500 to 3,000 households, but all of this becomes irrelevant in today’s methods since the individual household data must be used to create the groupings of zips.

You could solve the problem by creating an anonymous geographic cluster, but wait; doesn’t that also require the use of individual private information? The answer, of course, is yes. So what is the solution? Give consumers control over their names and personal data, and let them opt in to its use in situations such as this. Mission accomplished for business and the name-holder.

In yesterday’s post, the two companies working on systems to track every move that the Internet user performs as he or she surfs, is supposedly employing anonymous private information. But according to Saul Hansell of The New York Times, there were “a lot of questions he [Robt. Dykes, CEO NebuAd] wouldn’t answer.” Among them, not revealing the Internet service providers or Web sites he is working with, and he declined to identify what information he uses to determine how the ISP changes your address, both of which impact on what is being used to identify you.

Hansell also echoes my concern that, although personal data isn’t involved now, it could be at any time.

TRUSTe, the Internet version of the “Good Housekeeping” seal of approval, in a study conducted by global market insight and information group TNS, says: “Overall results indicate a high level of awareness that internet activities are being tracked for purposes of targeting advertising, and a high level of concern associated with that tracking, even when it isn’t associated with personally identifiable information.” This from Internet users asked about their reactions to behavioral targeting.

In the results from the survey, “71 percent of online consumers are aware that their browsing information may be collected by a third party for advertising purposes, but only 40 percent are familiar with the term ‘behavioral targeting.’ 57 percent of respondents say they are not comfortable with advertisers using that browsing history to serve relevant ads, even when that information cannot be tied to their names or any other personal information.”

“An overwhelming majority (91 percent) of respondents expressed willingness to take necessary steps to assure increased privacy online when presented with the tools to control their internet tracking and advertising experience…” I have placed the last sentence in bold type for emphasis on what the public is obviously willing to do to protect their privacy on the Internet. It confirms to me the willingness of the American consumer to take control over their names and personal data in all situations when granted that right. If only business, government agencies and Congress would realize that.

Friday, April 25, 2008


FEDERAL TRADE COMMISSION TARGETS TARGET ADVERTISING


For over twenty years the junk mail industry has had an on and off love affair with predictive modeling, which is a sophisticated way of targeting a customer by using technology to predict his or her habits. As a former list/data broker and database consultant, I have been in favor of this in aggregate geography, but never on an individual household basis. Anything to conserve paper and help protect the environment.

To explain aggregate geography; that means a cluster of households, from 300 to 500, where demographics and lifestyles are very similar. Enough so that a junk mailer can profitably send the same offer—say for young, upscale households that drink good wine—to the entire group. My objection to targeting individuals is that this uses the Big Brother approach which employs revealing everything there is to know about the consumer which is available to all concerned in the modeling process. A blatant invasion of the person’s privacy.

Now the Federal Trade Commission has decided to “aggressively” enforce Section 5 of the FTC act—which prohibits unfair or deceptive practices—by “encouraging” business to self-regulate itself in the area of behavioral marketing. That’s the latest buzz word for targeting and predictive modeling. By combining demographics and lifestyles using advanced technology, you come up with the actual behavior of an individual; like what books they read, what prescriptions they take, and whether or not they drink or gamble.

In a recent article from 26econ.com, a new term, to me at least, “deep packed inspection,” means the Internet service provider can “view every bit of data sent to and from a particular user.” Two links from that site, here and here, are pieces by Saul Hansell of The New York Times. He thinks the technology will become “the mother of all privacy battles.” Two guys with two companies are behind the concept: Robert Dykes, CEO of NebuAd, and Kent Ertugrul, CEO at Phorm. The pair thinks privacy advocates will eventually embrace what they are doing, because they claim their programs give Internet users complete anonymity.

Perhaps, but with this software in place, there is the ability to add private information to the mix later, and somehow data collectors just can’t resist the urge. With an established broad group of categories, these systems build a profile on your surfing habits—they say without even your name or address—documenting everything you do. Apparently our ISPs are enabling all of this data collection because they receive a big cut of the advertising. Once again, the person supplying all the information is left out of the action.

And that brings us back to the FTC new proposed guidelines for behavioral targeting of online advertising. Like most other government agencies, the decision makers at the Federal Trade Commission haven’t an inkling of what predictive modeling/behavioral marketing is all about, so most new rulings will probably be in favor of business, not the consumer. Particularly while Bush is still in office. More on this next week.

Thursday, April 24, 2008


WHO DO YOU TRUST? ALMOST NO ONE WHEN IT COMES TO YOUR NAME AND PERSONAL DATA


There is a site, darkReading, you may or may not have heard of. They say they aren’t licensed therapists, but that they do “deal with an astonishing variety of insecurity each day.” They are talking about the personal data kind that end up in breaches by business and government we hear about almost on a daily basis. In a recent darkReading, they use the headline for a article, “2008 Could Be Record Year for Breaches,” that reveals the latest results from the Identity Theft Resource Center; the fact that in the first three months of 2008, there have been 167 incidents of compromised data, twice the first quarter of 2007.

What worries me most is that I have been predicting for the last year that 2008 will be a record year for identity theft victims, due primarily to the fact that much of the free credit monitoring offered by “breachers” will expire in 2008, leaving the ID thieves open to use the private information they have stolen. If this year will set a new record for breaches, what will the number of victims look like in 2009? Fortunately, many of the companies responsible for losing your sensitive data are now offering two years of free credit monitoring, so, if you do become a victim, demand it.

ITRC also reports that those receiving letters of notification indicating their private information has been exposed have been “given incorrect directions or not enough information,” on what to do. The combination of having your personal data breached, along with the fact that the business responsible doesn’t really know how to help you, has shaken the confidence of the American consumer to the point where they are legitimately refusing to give up any private information. See my earlier post on Safeway.

In another darkReading piece, 31 percent of customers who have become breach victims stopped doing business with the company; 55 percent were notified twice in two years; 8 percent four times or more. These are figures provided by a new study from the Ponemon Institute.

On March 7, of this year I did a post on what we might expect in 2008: “One More Outlook for Data Loss Prevention in 2008.” What it flatly says is that we cannot protect our names and personal data with the means that we have today. That includes both the business or government agency collecting the data, as well as the individual from whom the data is sourced.

Consumers have lost control over their names and private information at a time when the outward appearance is that data collectors do not know how to protect what they collect but continue to collect it, nevertheless, at an alarming rate One of the primary reasons to expect record breaches in 2008. This opinion, shared by many privacy activists, stems in part from a recent statement from a VP of Marketing and Security working at a database security company: "People are saying 'let's step back and realize our data is under siege, what's of value that we need to protect and where is it?'" We’ve waited until now to do this?

If you want to see the number of victims from identity theft drop drastically in 2008, leading eventually to a zero factor, we need to give consumers control over their names and personal data, and compensate them when it is sold to provide incentive to assume this responsibility. Otherwise, I can’t imagine where the ID crisis will have risen to in 2010.

Wednesday, April 23, 2008


CALIFORNIA SENATOR TALKS BIG BUT DOES LITTLE FOR CONSUMER PRIVACY


Dianne Feinstein, the U.S. Senator from California, a Democrat, thinks Americans need identity theft protection after the person has already become the victim of a breach. She said so in an opinion piece to the California Sacramento Bee newspaper. She isn’t alone, either on the state or federal level. Every piece of legislation out there, whether introduced or passed, even the landmark California law that exposed the ChoicePoint breach in February of 2005, is designed to pick up the pieces after your sensitive data has been stolen or lost. If this were the only option, I would say go ahead now and make the legislation federal which would give business and government uniform guidelines to work with. But it isn’t. Feinstein says, “It's time for Congress to take action and give Americans the tools they need to protect themselves.” The problem is, the legislation she introduced five years ago, which still hasn’t passed—having tenure both before and after Democrats took over Congress—works just like all the rest, kicking in only after the damage is done. There’s some good stuff in her bill, just like many others introduced since the data hit the fan in 2005. Requirements like telling victims exactly what happened, and notification of the breach. And she does want to tighten up the controls on government agencies. However, unless the victim is notified immediately—and that is never likely to happen—a stolen Social Security number could be sold by the identity thieves within the hour, and used by the underground buyer to open new credit accounts or drain the resources of current accounts before the company or government agency even discovers the breach. This is exactly what happened in the TJX (TJ Maxx, Marshalls) incident. I’m sorry but I agree with other privacy advocates that even one breach of your private information is too much. The part of the Senator’s opinion piece I like most is when she puts the monkey on the right back…George W. Bush. She commented about the administration’s instructions to federal agencies about breach notification, the culmination of which resulted in Hillary Clinton’s passport file being breached with months passing before she was notified. GWB will go down in history as perhaps our worst president ever for many reasons, not the least of which will be his desertion of, and arrogance toward, the average consumers’ privacy needs. But Democratic Senators like Feinstein could have done much more to help the consumer’s plight. She could have introduced legislation to grant consumers control over their names and personal data, while compensating them when it is sold to offer incentive to shoulder this new responsibility. I even suggested this to her three years ago. No reply.

Tuesday, April 22, 2008


WORK-AT-HOME SCAMS COULD TURN INTO IDENTITY THEFT FRAUD


They have been around for years, and have improved in the sophistication of their approach, but the newest twist is frightening. I am talking about the work-at-home schemes that lure people into thinking they have found a way to make easy money at home. It’s not possible, and I can tell you that from 35 years as a junk mail list/data broker that all of the services these scams are selling you to do at home are done by machines in large facilities run by people trained for the jobs. There are ways to supplement your income, but this isn’t one of them. Actually, I am surprised that after all the bad press on this subject over the years, there are still so many who bite. However, these are days of desperation, and the crooks know it. Unfortunately, the bad guys have found a new way to pull off the fraud that just adds to their total take. In an MSNBC article, work-at-home scams are documented about real people who have suffered real losses. One actually landed a guy in jail because he was accepting and forwarding stolen merchandise. Another is the ploy to deposit the firm’s check as a mystery shopper, and send a portion back to the company. Of course their check is no good, and you are out the amount you sent. As the MSNBC piece indicates, the criminals are often from Soviet Bloc nations who use services such as Western Union to forward payments. In the current scam, you are asked for your bank account number they allegedly need to send you a direct deposit; instead they clean out your account and you never hear from them again. And this is where your identity can be compromised. It is only a matter of time until the ID theft underground connects work-at-home to the art of stealing your identity, both real and synthetic. That will come when they begin to ask you for, in addition to your bank account number, your credit card numbers, driver’s license number and your Social Security number. Of course the crooks will still attempt to make you pay up front for materials necessary to complete the work-at-home jobs as in the past, which you might do by using your credit card or a direct deposit from your bank. There is always a purpose to their madness. In the heat of the moment, you are focused on that extra income you are being promised, and you don’t weigh the circumstances in which you are giving out all this private information. But the old saying still applies: When it sounds too good to be true, it probably is. I have a plan that won’t put a lot of extra money in your pocket now, but could provide help in the future. If you had control over your name and personal data, and if you were compensated when it is sold, many of you could add an average of $607 a month to your retirement income. And you don’t even have to work at home to do it. You can read more about this concept in an earlier post from June 28, 2005.

Sunday, April 20, 2008


PENNSYLVANIA VOTER SITE SENSITIVE DATA LEAK FIXED OR JUST IGNORED?


All is quiet in the Pennsylvania primary regarding the voter registration data leak that was reported back in March. The state had to halt access to the online registration site where some 30,000 personal voter records were made available for all to see. According to Computerworld, it was the online application form designed for simplification that contained a Web programming error which released the voter’s name, date of birth and driver’s license number. In some cases, even the last four digits of the individual’s Social Security number. The primary is tomorrow, and the question arising from this now is how many of the 30,000 will be spooked into a reluctance to vote as a result of the incident? Of course, the damage is already done so that should not be a factor in the decision to go to the polls. But I am sure the citizens of Pennsylvania would like to know if their private voter information is secure once again. Sunday’s edition of The Philadelphia Inquirer, the state’s largest newspaper, had no mention of the data leak on their Web site. If things are back to normal, you would think that headlines would be blasting the fact that voters should feel secure in both the registering and voting event. Beth Givens of Privacy Rights Clearinghouse even said: "When word gets out, it will be one of those things that will deter people from registering to vote." Computerworld points out that in the past voter databases have been made available to political parties for mailings, but all the sensitive data was removed. Today, with it available online, mistakes are bound to happen and obviously it did. It is bad enough to have your private information outed with the chance you could become a victim of identity theft, but when it is done in connection with your right to vote, and it could have an affect on your decision of whether or not to exercise that right, there is real damage done. Maybe I missed it somewhere in my research, but after Googling every search phrase I could come up with relating to the issue, there is no mention of assurances from the state of Pennsylvania that the voting system is now secure. And that reeks of recent personal data breaches in the private sector where TJX (TJ Maxx, Marshalls) and Hannaford Bros. super markets delayed releasing information. This only makes potential victims worry that much more, and delay any necessary protection strategy that might prevent fraud. Incidents like this are being reported on a daily basis, which is currently resulting in business and government simply applying band-aids instead of fixing the problem. The only answer to this dilemma is for the American consumer, and voter, to demand that Congress pass federal legislating to grant individuals control over their names and private information, compensating them when it is sold to provide incentive to take on this new responsibility. If anyone has a better idea I would like to hear about it, but if not, it is time to seriously consider this concept.

Thursday, April 17, 2008


DUMBING DOWN ON PRIVACY


LifelLock, the identity protection company whose CEO, Todd Davis, flaunts his Social Security number before the public to prove that his service works, is being sued in a class-action suit. The litigation alleges deceptive marketing, according to Reuters.com, and comes less than two months after the Experian Credit Bureau sued LifeLock for false advertising. See my Feb. 25 post. The New Jersey Pasternack family who filed the suit says LifeLock “misled them about the limited level of identity protection the company provides, and failed to warn them about the potential adverse impact those services could have on their credit profiles.” The complaint adds that Davis’ style of advertising “lulls” potential subscribers into a false sense of security by misrepresenting the degree of protection they will receive. The company charges $10.00 a month for services that consumers can do on their own free of charge. Maybe if we get these people fighting among themselves, Congressional leaders will finally realize that something needs to be done, and now. South Carolina decides to get tough with identity theft by passing a stringent law to better protect its citizens. The state becomes one of only two stipulating that residents can place or lift security freezes on their credit reports at no charge, based on a report in the SC Morning News. Additions to the bill include penalties for credit bureaus who don’t correct incorrect information, and a 15-minute lift on a credit report freeze with the consumer’s pin number. States continue to show the federal government how to do it, but an inept Congress can’t see the breaches for the business lobbyists. In another state, Colorado, Jefferson County DA, Scott Storey, also understands the identity crisis and is doing something about it. Based on a piece in YourHub.com, Storey’s fraud alert team is advising consumers to buy a paper shredder, the diamond cut kind which is supposed to be the best. Colorado ranks eighth in the U.S. for ID theft, which is apparently enough to get this DA to start an awareness campaign that is sorely needed across the country. He shows the county residents just how the crooks do it by exposing methods like fake driver’s licenses or chemically altered checks. A local project director for crime prevention, Cary Johnson, holds seminars on the subject and makes an excellent point. The crooks know our lifestyle habits, like writing a check and putting it in the local neighborhood postal box. He also made the comment that, based on Federal Trade Commission statistics indicating that 5 percent of Americans become victims of identity theft each year, in the next ten years 50 percent of the U.S. population will have succumbed. The junk mail whiners are at it again. They are questioning the motives of a New Hampshire state representative who introduced a bill to establish a statewide do-not-call registry on behalf of those who find unsolicited mail intrusive. I looked up “intrusive” on Dictionary.com and found the following definition: “tending or apt to intrude; coming without invitation or welcome.” If that isn’t the perfect description of junk mail, I don’t know what is. The industry article says junk mailers find it “mystifying” why Rep. Suzi Nord would call their work intrusive. After spending 35 years in the business as a junk mail list/data broker, I find it exasperating that these people cannot figure out that when 98 percent of what they produce goes in the trash, what is it if not junk? The feds are still not addressing the problems that caused data breaches like the 26.5 million records lost by the Veterans Administration. MSNBC says that the General Accounting Office has found that most of the two dozen federal agencies examined still haven’t initiated five federal recommendations to protect private information. Eighteen other agencies had complied “to varying degrees.” This is important to the American public because over 20 percent of all data breaches originate in the government sector. We certainly won’t see much shoring up of this issue by the Bush administration, and it is beginning to look like the Democrats have put consumerism on the back burner, perhaps for the upcoming election. It seems to me that the timing is perfect for an Independent candidate to step in and show that he or she will put consumers out front again. Go to Committee for a Unified Independent Party (CUIP) for more on the Independent movement. Any suggestions for candidates?

LATEST PLOY IN DATA COLLECTION: WORK A “JIGSAW” PUZZLE


On the day we made the discovery that names and personal data were worth more than the paper they were printed on—and back in those days the information was typed, sometimes even hand-written, on pieces of paper—a profit-center was created that will someday likely surpass the world’s largest industries. When I entered the junk mail business back in the late sixties, many smaller companies were still maintaining their customer lists on index cards. When it was time to do a mailing, the cards were distributed to home typists who would transcribe the information onto labels or direct to an envelope. Today, everything is computerized to the highest standards of technology, and every aware business spends much of its time figuring out how to capture your private information. The primary reason for that is to sell it; junk mailers alone realize over $4 billion every year in the list business. Now, there’s a new kid on the block with an approach that is unique, although questionable by at least one privacy advocate, Susan Pierce, exec. Director of non-profit PrivacyActivism, according to ERE.net. Jigsaw.com professes to have more than 8 million business contacts on file to be used by sales people, recruiters or marketers; this includes the contact’s full name, title, postal address, e-mail address and telephone number. Their privacy policy mandates the same stipulations as most, meaning they won’t share “personally identifiable information” with anyone but law enforcement, and necessary third parties such as service providers. Included would be the above, plus your credit card number (it’s a paid service), your Internet address and provider, and a profile of your online preferences using the Jigsaw system. There is no indication that they will ever sell this information, but nowhere do they say that they never plan to. In the company’s “Legal Disclaimer,” there seems to be concern that the anonymity set up to protect customers could be jeopardized by “illegal use” of the system. Further, under “Information Security” Jigsaw says it uses “accepted industry standards” to protect all information, but admits that they “cannot guarantee its absolute security.” Of course they can’t, and no business can if the bad guys want to get in and steal your sensitive data bad enough. Pierce says, “The seven-million business cards is causing disruptive change in the way corporate information is gathered because recruiters can buy and sell contact information on people -- who may not have given permission to be contacted.” Jim Fowler, Jigsaw.com founder and CEO, apparently justifies it all with the statement, “You would be amazed how many databases you live on, and you have no clue you're on there.” I am all for the free-enterprise system, but if something isn’t done soon to regulate how names and personal data are collected and used in the marketplace, the identity crisis could reach proportions that no American wants to experience. All you need to do is visit George Orwell’s 1984 novel again to see the possibilities. If you don’t have a copy, go to The Literature Network here. Just search “Big Brother” and read some of the passages. You can also go to the "Search" box at the top of this blog and enter "Big Brother" to read some of my past posts on the subject. And when you’re done, hopefully, you’ll agree that consumers should be granted control over their names and private information as the solution to this issue.

Wednesday, April 16, 2008


TECHNOLOGY PRO SAYS “WE” ARE THE CYBERTHREAT, NOT BIN LADEN


Charles Cooper has covered technology for over 25 years, working with such organizations as PC Week, ZDNet News and now, CNET News.com. So you figure he has the right to some opinions on the subject, and his latest is that “Mr. & Mrs. Computer User” has replaced bin Laden as our biggest cyberthreat. We are the ones who “keep goofing up,” as Cooper puts it, quoting the experts from the 2008 RSA conference on information security in San Francisco. He likens the problem to the movie, Groundhog Day, where Bill Murray keeps waking up to the same morning. Which is precisely what is happening with business and government committing the same mistakes every day with our names and private information resulting in a steady stream of data breaches. And the consumer compounds the problem by not taking proper precautions, and remaining apathetic over the state of their privacy. Some RSA conference highlights:

• 65% of the new code being released into the market is malicious
• The U.S. was the top country of attack origin in the second half of 2007
• The education sector accounted for 24 percent of data breaches that could lead to identity theft
• Government was the top sector for identities exposed, accounting for 60 percent of the total
• The United States had the most bot-infected computers worldwide

Much of this we already knew, but it just points out the fact that it has to be said again at major conferences like RSA to an audience that, based on the organization’s findings, won’t be taking their privacy seriously any time soon. “Apathetics” I call them. Symantec’s CEO, John Thompson, confirms what most privacy advocates have known for some time. The fact that rather than an attack on the infrastructure itself, all the attention has now shifted to just getting the personal data any way possible and rushing it to the underground market in private information. As an example, in a Symantec report, bank accounts are the most promoted for sale in this manner, accounting for 22 percent of activity tracked. And Homeland Security Secretary Michael Chertoff’s appearance at the conference didn’t really add confidence to the possibility there would be any help from the current administration. Cooper sounds skeptical over how many Silicon Valley technologists Chertoff would enlist to come to Washington to work on cyber-security because, as he comments about the Secretary’s department, “Off-the-record interviews with people familiar with the goings-on there have described the situation to me as a bureaucratic mess.” Not that I want to get into politics now, but it is clear that nothing will be done that will enhance consumer privacy until George W. Bush is history. That in itself will be welcomed by many, but, unfortunately, I am not at all sure whoever takes over the Whitehouse and Congress in November will supply the solution the privacy community is looking for.