Monday, December 21, 2009

Social Networking and Some Employment Law Snafus (Part I)

Imagine yourself the Human Resource Specialist for a large employer – as the arena of social networking explodes, you are faced with a series of issues that were never even considered before the days of internet insanity. Let’s try out a handful of these situations, and see how you would fare –
1. One of your employees is found to have posted their photo, complete in company logo shirt, on Facebook.

Does it matter that it’s a personal site? How ‘bout that the logo is represented in the photo?

The outcome might be to consider prohibiting the display of a company logo, or product, etc., on even an employees’ personal site. (Keeping in mind that certain businesses may want to have their logos or products given higher exposure.)

2. What if the employee’s photo is of themselves at work in a skimpy bikini?

Certain websites have privacy abilities where such photos may not even be seen, however, coworkers often bring to your attention items that even the employee themselves may not realize is visible. Can someone’s behavior after work hours be monitored? How does such monitoring balance with freedom of speech protections?

In reality, a situation like this is probably best handled in consultation one-on-one with the involved employee. The best case scenario would be the employee didn’t realize the photo was publicly visible and agrees to remove it. However, another outcome might be to consider prohibiting the posting of photos of work area, or on-duty activities. (For certain companies there is a security justification for such posting prohibition.)

3. What if employees take a pay cut because business is down, and then photos are posted by the boss’ wife on Facebook?

And then the employees start circulating a union petition…and demand a raise?? Isn’t there some similarities to the boss driving up to work in a new car?

At its heart, this is all about perception. If workplace executives or managers are counseled on the business impact of personal posts, along with the encouragement of using privacy settings, it should help. Also, it can’t hurt to increase your transparency, so to speak, of business finances. (And possibly gear up for a union election campaign at the same time!)

We want to hear from you – send your social networking and employment law snafu situations to us this week at suebmartines@gmail.com, and stay-tuned for Part II!

Labels: , , , ,

Wednesday, July 23, 2008

Just RANTING

1.

I have been saying for months that the FTC’s “Red Flag Rule” was never intended to be all encompassing. As many of you know there has been a difference of opinion on this subject with some individuals going as far as using the rule as a scare tactic in order to profit. In my opinion, there is enough to worry about as a business owner in regards to identity theft without having such profiteers lurking about. Finally, the FTC is weighing in on this subject. I have included a recent article that addresses this issue.
http://www.consumeraffairs.com/news04/2008/07/red_flag.html

2.

Now, I am speaking to the companies that are out there offering “compliance training” and charging thousands of dollars and to the insurance agents selling identity theft services and products: Be careful and do what is right for the client.

It is only a matter of time before every adult individual in the United States will be carrying an identity theft policy/service in their portfolio. Be patient and offer the best product - not the most convenient one. The sales will come.

Remember, insurance agents make their real money in residual income. If you are seen as a partner of your client instead of seeing your client as a profit center you will realize a long term residual income and more referrals then you alone can handle. NOW go out there and do what is right.

3.

Lastly, keep in mind, “time will promote or expose”. This is very important to all of the companies coming to the market with a new identity theft product. Bring the public the best product you can and the market will reward you. If it is a product like LifeLock or ID Rehab (now Identity Watchdog) you will find out that time will expose their shortcomings. Keep in mind, indecent exposure is still illegal in most places around the world.

The consumer is not STUPID and good advertisement will not conceal the flaws of your product forever.

Labels: , , , , , , , , , ,

Thursday, November 22, 2007

Brit Data Loss Hits 40% of Population; Bureaucrats should be sent to US Guantanamo Bay Military Detention center for Training.

Prof. Steffen Schmidt

The story datelined London, Nov. 21, 2007 opened this way:

The British government struggled Wednesday to explain its loss of computer disks containing detailed personal information on 25 million Britons, including an unknown number of bank account identifiers, in what analysts described as potentially the most significant privacy breach of the digital era. The New York Times, “Data Leak in Britain Affects 25 Million”, by ERIC PFANNER

The data was on two disks that were sent by private delivery service, TNT, unregistered. The disks were apparently protected by a password but the data was not encrypted and were sent by Her Majesty’s Revenue and Customs the tax collection agency to the National Audit Office, which monitors government spending.

It appears to me that the bureaucrats in the British government who handle such sensitive information in such an astounding volume, were never once told about identity theft and were not trained in handling such life changing information. This is not shocking to me at all since identity theft protection data handling has been cavalierly ignored by governments, by private companies and corporations as well as non-profits, clubs, social organizations, educational institutions, insurance, and health care providers.

According to the New York Times,

The data went astray in October, after two computer disks that contained information on families that receive government financial benefits for children were sent out from a government tax agency unregistered, via a private delivery service. The episode is one of three this year in which the agency improperly handled its vast archive of personal data, according to an account by the chancellor of the Exchequer — including the sending of a second set of disks when the first set did not arrive.

This data loss apparently contained personal information on 40 percent of the population of the country. The disks included people’s names, addresses, bank account numbers, and their national insurance numbers, the British equivalent of Social Security numbers. The disks also contained data on almost every child under 16 in Britain.

Experts said the information could allow crimes beyond identity theft. Some people use the name of a child or part of an address as a password on a bank account, so the combination of these details could allow someone to break their code.
Apparently the government also waited an ungodly time before informing banks so that they could put higher levels of security in place and monitor unusual activity on people’s accounts.

The British Prime Minister Gordon Brown apologized and the head of the tax agency resigned. Oh goody! That will calm the nerves of half of the population of Britain who are now faced with years of anxiety over their personal information.

Government Information Commissioner Richard Thomas said he was shocked at the scale of the security breach.

“It's almost certain that they have broken the data protection law. This is a shocking case. I'm at a loss to find out what happened in this situation,” he told BBC radio.

He also said his office had been issuing warnings about data protection to organizations for years.

“We've been all the time saying that the more you are collecting personal data, for understandable reasons, the more the risks increase and the more you must be aware of what can go wrong.” Globe and Mail

The irony is that in Europe it is illegal to collect and sell personal information of people but of course that does little to stop a “junior” staff member of the tax collection agency from sending disks with all this vital data. I find it mind boggling to begin with that a “junior” staff member would be allowed to even touch such data. I also find it criminally neglectful that so much vital information would all be aggregated in a single location.

What can we learn?

First of all, this example is proof positive that we need massive and highly intrusive data protection training for employees who handle such information.

Secondly, this tragedy demonstrated clearly that encryption is not an option but should be an absolutely required, mandated, and it’s omission a punishable offense.

Third, the case suggests that my computer and information geek friends need to develop a radical new best practice for data storage and management. I would suggest a system of distributed and disaggregated data storage, where filed are NOT all kept together on data bases and where piece of identity information for each file are also not stored together. The algorithms for managing this information would be written in such as way that when data is needed it seeks the required information, and then temporarily assembles the pieces of each persons record for specific use. When the operation is finished the assembled data evaporates and the encrypted system goes back to disaggregated storage.

One side effect of the data loss was to deal a blow to Britain’s plan to issue a national ID card.

Critics of Britain's plans for compulsory identity cards said on Wednesday the multi-billion pound scheme should be ditched after the data loss.

Opposition politicians and opponents said loss showed the government could not be trusted to bring in ID cards, which would involve one of the world's biggest IT schemes.

The Globe and Mailhttp://www.theglobeandmail.com/servlet/story/RTGAM.20071121.wukdatalosss1121/BNStory/International/home

Labels: , , , , , , , , , , , , , ,

Monday, November 19, 2007

Information Protection and Behavior Modification


In 2006-2007 the National Science Foundation (NSF) and the Iowa State University Center for Information protection (CIP) funded a study on information and identity theft protection of which I am the PI (Principal Investigator). The NSF-CIP project is directed at identifying factors that lead to data and critical information loss and then designing targeted and appropriate educational/training programs that change people’s behavior and lead to more “Security Consciousness” – (SEC-CON).

As a result of this research we are now developing best practices for information and ID protection. Our colleagues in computer science, computer engineering, mathematics, and management information systems (MIS) are working on parallel discoveries that will make information more secure and personal identities less vulnerable. Their work and ours will be incorporated into corporate, government, non-profit organizations and into individual practices.

I am delighted to report some preliminary findings which can help secure information.

Individuals need to have personal security of personal data high on their “awareness” list. In fact research shows that ID security needs to become a “second sense”. It should never be something we do once a month or quarterly.

There is now significant evidence that there is an “Unwarranted Trust” - UT -factor which basically “disarms” people’s behavior when it comes to securing and protecting sensitive data. Understanding UT as a sociological and psychological behavioral phenomenon, we feel, is THE single most critically important factor in successful “Security Behavior Modification” – SBM.

The second phase of the NSF-CIP project is designed to modify and improve and develop a continuous improvement paradigm for training systems for employees who have access to critical information. As one of our sponsors who is with a large multinational company pointed out at a recent briefing SBM is invaluable not only for the protection of traditional data of concern such as Social Security and Credit Card numbers and birth dates but also as a means of sensitizing employees to the risk of revealing or losing proprietary information, business plans, patents, and other information that should be secured and protected.

For more information on the National Science Foundation/Center for Information Protection project please contact us at ---
Michael McCoy - 559 Ross Hall Ames, IA. 50011-1204 or email: mrmccoy@iastate.edu


Steffen Schmidt

Labels: , , , , , , , , , , ,

Friday, May 04, 2007

England Has Their Problems As Well

Experian Inc. a credit checking agency on Thursday reported that identity theft cases in England have increased by 69% between 2005 and 2006.

In England over 2,000 people contacted the Experian victims of identity theft hotline for in the last six months of 2006 alone.

According to Experian, about 45 percent of those victims were alerted to a problem by a financial services company that noticed unusual activity. Forty-one percent found out through their credit report. The rest found out either after a refusal of credit, a theft or through notices they were being awarded credit they had not personally requested.

Watch out when companies like these start offering you services to protect your good name. Isn't there a small conflict of interest?

Labels: , , , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft