<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sumeet Singh &#187; privacy</title>
	<atom:link href="http://sumeetsingh.net/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://sumeetsingh.net</link>
	<description></description>
	<lastBuildDate>Wed, 18 Feb 2009 15:12:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Facebook Privacy Update</title>
		<link>http://sumeetsingh.net/2009/02/18/facebook-privacy-update/</link>
		<comments>http://sumeetsingh.net/2009/02/18/facebook-privacy-update/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 15:12:35 +0000</pubDate>
		<dc:creator>sumeet</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://sumeetsingh.net/?p=293</guid>
		<description><![CDATA[Finally after couple of protests, few thousand lost members and coverage on CNN, Facebook Privacy policy is back to where it was. Not that the earlier one was any good &#8211; but better than &#8220;Facebook owns all your data&#8221; statement. (0)]]></description>
			<content:encoded><![CDATA[<p>Finally after couple of protests, few thousand lost members and coverage on CNN, Facebook Privacy policy is back to <a href="http://blog.facebook.com/blog.php?post=54746167130">where it was</a>. Not that the earlier one was any good &#8211; but better than &#8220;Facebook owns all your data&#8221; statement.</p>
<a href="http://sumeetsingh.net/2009/02/18/facebook-privacy-update/" rel="bookmark" class="asides-permalink" title="Permanent Link to Facebook Privacy Update">(0)</a>]]></content:encoded>
			<wfw:commentRss>http://sumeetsingh.net/2009/02/18/facebook-privacy-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chertoff idea of Privacy</title>
		<link>http://sumeetsingh.net/2008/04/21/chertoff-idea-of-privacy/</link>
		<comments>http://sumeetsingh.net/2008/04/21/chertoff-idea-of-privacy/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 04:16:39 +0000</pubDate>
		<dc:creator>sumeet</dc:creator>
				<category><![CDATA[test]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://sumeetsingh.net/2008/04/21/chertoff-idea-of-privacy/</guid>
		<description><![CDATA[As if appointment of Rod Beckström as director of National Cyber Security Center (NCSC) was not foolish enough, Bush administration couldn&#8217;t help tolerating Mr Chertoff&#8217;s ideas of privacy. In a public appearance at Canada, he attempted to explain how fingerprints are not his idea of personally identifiable information (personal data). What people, especially those who [...]]]></description>
			<content:encoded><![CDATA[<p>As if appointment of <a href="http://beckstrom.com/Bio">Rod Beckström</a> as <a href="http://www.securityfocus.com/brief/708">director of National Cyber Security Center (NCSC) was not foolish enough</a>, Bush administration couldn&#8217;t help tolerating Mr Chertoff&#8217;s ideas of privacy. In a public appearance at Canada, he attempted to explain how fingerprints are not his idea of personally identifiable information (personal data). What people, especially those who handle security, must understand that personal data can not be described by confidentiality alone. </p>
<p>What most people do not understand is the difference between personally identifiable information and confidential information, or as Schneier puts it &#8216;the difference between personal data and secret data. To put it simply, personally identifiable Information (PII) refers to any information that identifies or can be used to identify, contact, or locate the person to whom such information pertains. It has little to do with confidentiality of the information on its own. Postal codes/ zip codes and fingerprints are few such examples of less-confidential personal data. </p>
]]></content:encoded>
			<wfw:commentRss>http://sumeetsingh.net/2008/04/21/chertoff-idea-of-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blackberry In India: Beware!</title>
		<link>http://sumeetsingh.net/2008/03/18/blackberry-in-india-beware/</link>
		<comments>http://sumeetsingh.net/2008/03/18/blackberry-in-india-beware/#comments</comments>
		<pubDate>Mon, 17 Mar 2008 20:33:49 +0000</pubDate>
		<dc:creator>sumeet</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[test]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[india]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://sumeetsingh.net/2008/03/18/blackberry-in-india-beware/</guid>
		<description><![CDATA[Indian government either needs a session on risk perception. It has this tremendous capacity to recognise a threat from a cow to a smartphone. The way things are turning out in India, we will soon see DoT ordering NIC to maintain a national mail server where all our emails will be mirrored and scanned for [...]]]></description>
			<content:encoded><![CDATA[<p>Indian government either needs a session on risk perception. It has this tremendous capacity to recognise <a href="http://news.bbc.co.uk/1/hi/world/south_asia/6970305.stm">a threat from a cow to</a> <a href="http://in.news.yahoo.com/financialexpress/20080315/r_t_fe_bs_india/tbs-need-to-shadow-blackberry-dot-tells-e247859.html">a smartphone</a>.</p>
<p>The way things are turning out in India, we will soon see <a href="http://www.dot.gov.in/">DoT</a> ordering <a href="http://home.nic.in/">NIC</a> to maintain a national mail server where all our emails will be mirrored and scanned for keywords that reflect terrorism. Atleast people can look up to NIC to snoop around in other&#8217;s email and ask for backup just incase an email is deleted from their servers! </p>
]]></content:encoded>
			<wfw:commentRss>http://sumeetsingh.net/2008/03/18/blackberry-in-india-beware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Learnings from India: How not to secure personal data</title>
		<link>http://sumeetsingh.net/2008/02/05/learnings-from-india-how-not-to-secure-personal-data/</link>
		<comments>http://sumeetsingh.net/2008/02/05/learnings-from-india-how-not-to-secure-personal-data/#comments</comments>
		<pubDate>Mon, 04 Feb 2008 20:36:31 +0000</pubDate>
		<dc:creator>sumeet</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[test]]></category>
		<category><![CDATA[india]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://sumeetsingh.net/2008/02/05/learnings-from-india-how-not-to-secure-personal-data/</guid>
		<description><![CDATA[The last few years have seen alarming rise in demand for security products and services within India especially related to data security. Be it firewalls, VPN boxes and encryption solutions, or ISO 27001 and SOX consulting, the demand has only increased. There is not one reason amounting to this growth. Contractual clauses for BPO segment [...]]]></description>
			<content:encoded><![CDATA[<p>The last few years have seen alarming rise in demand for security products and services within India especially related to data security. Be it firewalls, VPN boxes and encryption solutions, or ISO 27001 and SOX consulting, the demand has only increased. There is not one reason amounting to this growth. Contractual clauses for BPO segment have become harsher. Fear of data breach within companies has increased. Salesmen (or Pre-Sales consultant as they are known these days) have mastered the art of selling expensive yet ineffective solutions. And so on. But do the solutions protect private data of consumers better than before? Probably not to the extent it should be protected. And yet, there are not as many cases of privacy violation in cyberlaw courts in India as one thinks there would be. The problem with Indian way of securing information and assuring privacy is many folds.<span id="more-226"></span></p>
<p>First, the casual attitude infecting our system day after day seems to have spread to our use of technology. Walk into a transport department office and you will find servers containing sensitive personal information about license holders lying next to dustbins, under the table as a foot rest and if better, under a heap of files. It is not difficult to steal such information. It is just that this information has been made public through so many channels that its not even worth stealing it anymore. The hospitals do not feel responsible for protecting personal and sensitive information about its patients. Information that is supposed to be confidential, is conveniently passed on to the media for few minutes of fame. </p>
<p>Second, we, as Indians, take great pleasure in enjoying personal lives of fellow country men/women. Be it Mr Pandher or Mr Telgi, we all have enjoyed their sub-conscious talks. For no other reason, the media, rebuking all social norms of privacy of individuals, takes great pride in showing the tapes which are ideally supposed to be classified. Now this has nothing to do with data security in general, but does hint at the possible privacy violations in India going untouched. Infact, What Mr Pandher did in Noida did not demand his psycho-analysis test to be aired on national television. Similarly, Mr Telgi&#8217;s status of HIV+ had nothing to do with his stamp paper scam. </p>
<p>Third, the biggest challenge in India yet remains &#8220;people&#8221;. Each of the data breaches, barring one, that have occurred in the past 5 years in India has an element of <a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)">social engineering</a>. With an open, multi-cultural society, people have started trusting others with information a bit more than the acceptable level. So much so, that it is a routine for most of us to share our personally identifiable information with unauthorized individuals. Stand outside a call centre with a bunch of fancy credit card forms, and 25 year olds will throng the place carrying their salary slip, driving license and just about every other personal information. Most of them would not know the name of the agent who is collecting the forms. All of them actually wouldn&#8217;t care. </p>
<p>Not too behind in the &#8220;private information made public&#8221; race are the DSA agents for telecom companies that companies appoint to collect information and feed into their system for various legitimate purposes such as new connections, up-selling/cross-selling, retention and collections.<br />
As a bonus, we are also blessed with sharing of out personal information with 250 odd domestic call centres in and around Delhi at no extra cost. I haven&#8217;t really come across a descent chap who hasn&#8217;t got a grudge against telemarketers. Initiatives such as Do Not Call registry are bound to fail in absence of strict penalties. The regulatory bodies have clearly not come down on telemarketers for implementing Do Not Call. If that was not enough, the database propagation of a number into Do Not Call registry takes about 30-45 days &#8211; another example of redundant technology.</p>
<p>As our country grows and generates electronic information, the demands for security and privacy increase. Regulatory bodies and law enforcement bodies need to be brought up to the mark for information security acts. A comprehensive data protection law is required at the least to safeguard privacy of individuals. And last, each one of us needs to understand repercussions before sharing sensitive information online,  and get ready for information age.</p>
]]></content:encoded>
			<wfw:commentRss>http://sumeetsingh.net/2008/02/05/learnings-from-india-how-not-to-secure-personal-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
