News
3/21/2008
10:38 PM
Terry Sweeney
Terry Sweeney
Commentary
50%
50%

But Cling If You Must To The Illusion Of Privacy

I'm trying to work up a head of steam over the presidential candidate passport snooping. But my contract with TechWeb limits my self-righteousness to certain decibel levels, which, frankly is quite smart when the subject is data privacy.

I'm trying to work up a head of steam over the presidential candidate passport snooping. But my contract with TechWeb limits my self-righteousness to certain decibel levels, which, frankly is quite smart when the subject is data privacy.That, plus I thought I probably emitted all the harrumphs I possibly could over the snooping in Britney Spears' medical files earlier this week. So there won't be any more calling the wrath of justice down on the overly curious.

Instead, the takeaway here is that personal data snooping is common, pervasive, and probably considered a perk by those who do it. As Machiavelli might have said, "What good is access to information if you don't use it?"

A lot of what makes the personal information of pop stars and presidential candidates so enticing is that they're public figures. That information also can be used for blackmail, commercial gain, or political advantage. But my bet is that Medicare files, Social Security contributions, or tax returns get reviewed (and passed around, and talked about) way more often than we care to think about.

The difference is the tabloids don't care about my peccadilloes or yours, and my political opponents are much more obsessed with the wall I built along my driveway. (Built to code or not? Do your own snooping.) And god only knows what your enemies are trying to dig up on you.

Speaking of peccadilloes, this also circles back to former New York governor Eliot Spitzer. His downfall, as we all know now, was triggered by automated reviews of financial transactions he was making. The point: There's a good deal of legal scrutiny that's completely transparent where our bank accounts, credit cards, and phone records are concerned.

So whether you and your big sunglasses appear frequently on page one of the National Enquirer, or you're just another member of the great unwashed, let's save the self-righteousness about infringement on personal privacy. Hooray for well-meaning laws, but they don't lock down the personal bits and bytes any tighter.

In this era of data mining and an information-based economy, personal privacy's no longer a reasonable expectation. Those days are long passed.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-4403
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.ph...

CVE-2012-2930
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers...

CVE-2012-2932
Published: 2015-04-24
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the (1) selitems[] parameter in a copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/...

CVE-2012-5451
Published: 2015-04-24
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.

CVE-2015-0297
Published: 2015-04-24
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methos via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.