Humans as an entire species are never going to agree 100% on anything, ever.  I don’t care if it’s religion, politics, privacy, or margarine over butter.  There will ALWAYS be people on either side of every fence.  Try to imagine the worst thing in the world, and there will be someone out there doing it, or cheering on those who do.

At best, we can come to a majority agreement, but that will only ever be regionalised by either geographic location, or racial beliefs and bias.

So why has Prism caused such a stir?  Are you actually surprised this was going on? There are those who want access to data, and those who want to protect it.  There are those who want to use the data for the common good, and those who want to use it for their own profit, or worse.  And “Some men just want to watch the world burn.”

I’m not overly interested in your opinion, just as you’re not overly interested in mine.  I’m OK with that.  The only time we have an interest in this stuff is either when people totally agree with us, or – in our arrogance – we feel like trying to change the opinions of others.  Like we’re the ones who are right.

In the end, the bad guys (in whatever form ‘bad’ is for you) only have access to what we gave them.  An exception to that rule is when an organisation loses stuff they should be protecting.  Like in a breach for example.  Preventing this from happening is what I, and many others, have devoted our careers to, but the most we can ever achieve is a slight reduction in the risk to your privacy, and possibly some form of compensation for you if your privacy is lost.

Yes they should protect data, and should be liable for not doing so, but if a thief wants it, it’s gone.

While you have every right to expect privacy, and I agree with the laws and regulations supporting that privacy, you cannot EXPECT privacy given the bad elements.  Analogy; the law protects me against being mugged, but I don’t put myself in places or situations where mugging is more likely.  I may be the victim, and have all the rights of the victim, but I’m still missing my wallet.

This will not apply to the Prism case, where there will be no class action suit against the government, and whatever smoke and mirrors they come up with to reassure you that it will never happen again, it’s just that, smoke and mirrors.

The key to your personal privacy has always, and will always, rest with you.  You are responsible for your data, and whinging about governmental abuse of power is not going to change the fact that you posted stuff on FB, you took inappropriate pictures, and YOU chose to share your bank account details to an online provider of services etc.

Do I think the NSA was right in what they did, or if that moron Edward Snowden was right in what HE did?  That’s irrelevant, because I have nothing online in any form that would embarrass me if it were revealed, or unprotected (by deferred lability) if it was stolen.

Can you say the same?

[If you liked this article, please share! Want more like it, subscribe!]

Thanks to the more unscrupulous vendors, security is becoming as complex as the law. Privacy therefore is at the top of the list of sticky topics because it also involves both the law and security. More countries are effecting privacy laws than ever before, but just like in a regular business, functionality and security must be balanced to be effective.

I’m not going to list all of the ongoing privacy issues in the press, but the biggest two currently are; the Prism/whistleblowing/NSA scandal, and the EUs Data Protection Directive. While worlds apart in their impact and aims, they still raise a question that I’ve not seen addressed very often. Probably because there is no one right answer, but the question of how much privacy is too much should not be ignored or any semblance of balance is impossible. Also, it seems that unless we’re bashing the perceived bullies (Government, big business), there’s not much interest in this side of things.

So, Prism, summarised and paraphrased, is an anti-terrorism program that has unprecedented access to enormous amounts of personal data.

Proponents state that it’s necessary for national security, opponents state that it’s an abuse of power / attack on civil liberties and so on. But who’s right? If you choose a side – and to the extreme – you are either saying it’s OK for the Government to do whatever it takes to defend its people, and that the end justifies the means, or you’re saying that an individuals right to privacy outweighs the security of a nation. Clearly both of these positions are nonsense, but what is the right answer? It has to be somewhere in between., right?

However, to get the middle, both sides need to accept responsibility; Government for not becoming Big Brother-esque, and individual citizens for paying the price in personal privacy for the freedoms and conveniences we frequently take for granted.

For example, if you ask any victim of a terrorist attack, a hate crime, harassment, or a stalker-ex, whether or not they would have traded complete loss of privacy to avoid their pain, and I think the answer is a given.

However, now ask ME whether or not I would entirely relinquish MY privacy to prevent this from happening to someone else – which I would do in a heartbeat -, and you now have the gist of why this issue is so contentious (some are already calling it – terribly un-originally – Prism-gate). People want security, but they don’t want to accept the cost for it, which in todays plugged-in/online/Internet/information age, that cost is their privacy.

As for the EU Data Protection Directive, that’s about the far less glamorous subject of making sure organisations protect the data in their possession, and while less life-threatening, leads to the same question. This time it’s about [for example] the ability of an organisation to sell you stuff that you want, or didn’t even know you wanted but now you can’t live without (like the iPhone). They want to sell you stuff, you want your data protected or removed altogether.

Personally I want organisations to know EXACTLY what I like and don’t like. That way I’ll get less spam and pop-up ads regarding adult nappies/diapers and erectile dysfunction, and more on amazing gadgets and toys that will make my life complete. This requires absolutely enormous amounts of data, and is a true use of Big Data.

Not everyone agrees.

However, WE choose to plug in, we’re not forced. I have Linkedin, Facebook, Twitter, and more online bank / credit card accounts than I know what to do with. Sadly the accounts are mostly empty, but that’s not the point, which is why I have chosen these methods of communication and convenience to make my life better. Which they do…vastly.

We are not owed this functionality, we have a choice to use it or not. If you want it, you must pay for it.

How many of you read the privacy notices, or terms & conditions when you sign up for online services? No, me either, so I’m not going to complain if they go ahead and do exactly what they told me they were going to do.

I cannot speak to the law or politics, nor can I wax philosophically on human nature, but what I can talk to is personal accountability. You are owed nothing, except that which you earn. From your income, to your rights, to your karma, you get back what you put in. So perhaps what we should all do instead of complain, or demand that heads roll, is be a little more circumspect in our online interactions:

  1. Don’t post inappropriate comments on FB/Twitter or ANY form of social media or email. Assume that this information will NEVER go away;
  2. Limit your online banking and purchasing to known-good sites, check for HTTPS in the URL (secure transmission) , and CHOOSE A GOOD PASSWORD!;
  3. Make sure ALL of your online credit card / bank accounts have fraud and theft protection;
  4. Sign up for credit and identity monitoring services (I have two running, one US and one UK);
  5. Read the Terms & Conditions!;
  6. Do not even TAKE revealing or compromising pictures of yourself, or others, on any online-capable device …EVER (I think if I was to do that it would qualify as an offence against humanity, or maybe even a WMR (Weapon of Mass Revulsion));
  7. When you’re done with an online vendor, delete the account, and write to them invoking your right to erasure;
  8. Read my blog! 🙂

Personally, I LOVE the fact that London is full of cameras, I’m doing nothing wrong, and I feel better about my wife being out when it’s dark. I don’t care if some spotty geek in Fort Mead, MD is reading my personal email, or my FB posts, I’m not being seditious, or inappropriate, and if they derive pleasure reading about my wife and me discussing our 2012 taxes, good luck to him/her.

I want safety in the streets, safety for my country, AND the convenience of all that being online gives me, and if my privacy is the price I must pay, so be it. I trust the ‘official’ watchers infinitely more than the criminals or terrorists, but it’s MY responsibility to give NO-ONE access to more than I can afford to lose.

[If you liked this article, please share! Want more like it, subscribe!]

Finally, some common sense is starting to prevail;

http://www.huntonprivacyblog.com/2013/06/articles/hunton-webinar-on-the-proposed-eu-regulation-developing-a-more-creative-approach/

Detractors say that this is diluting the original intent of the directive, but as I have seen so many times in PCI, if you don’t make it achievable, you cannot enforce it fairly.

Risk based approach is always the way…