Partner Perspectives  Connecting marketers to our tech communities.
10/13/2016
11:42 AM
Carl Woodward
Carl Woodward
Partner Perspectives
50%
50%

Access, Trust, And The Rise Of Electronic Personal Assistants

App and device makers are working hard to deliver user control over privacy.

“You should leave in five minutes for your next appointment.”

“Traffic is heavy, leave at 11:30 for your flight to San Francisco.”

“Remember to buy bread and eggs.”

All of these reminders are commonplace today, thanks to electronic personal assistants on your phone, tablet, and computer. These aides get information from your emails, calendar entries, location, and other observations about you, your environment, and the immediate context. The more integrated they are with other apps and sources of data, the more effective they can be. But what about your privacy?

A human personal assistant can be the most valuable and trusted person in your life. The ultimate assistant not only knows your preferences, but can anticipate your needs. Like the emerging electronic ones, human assistants read all of your correspondence, know the full details of your calendar, and are privy to most aspects of your business and personal lives. But they have also been a source of gossip and intimate details for centuries. Non-disclosure agreements and lawsuits are still no guarantee of trust or confidentiality, and they cannot un-publish the tell-all book or interview. Trust is developed over time, based on experience and our personal judgment.

Electronic assistants are not really much different. What is different is their level of access and our control over the information and privacy settings. How do you give access and trust to a personal assistant app and its extended ecosystem, especially one whose priorities may be different from yours?

A fun and only slightly futuristic example could be asking your assistant to “Please book a skydiving experience for my anniversary.” In order for the personal assistant to make a good choice, it needs to know:

  • How much money you have in your bank accounts
  • If you have any bills or commitments coming up
  • What your calendar looks like for the suggested date
  • If you have any health issues that would prevent you from participating safely
  • If your partner is likely to think this is a good way to celebrate

Obviously, a security breach when there is this much data involved could be catastrophic.  App and device makers are working hard to deliver user control over privacy. There is a long list of settings available, as well as pop-up approvals for some types of data access. Using this power is an essential part of building a trustworthy relationship.

Next is data sharing among the ecosystem. Unlike your human assistant who is paid by you, your electronic one generates income from multiple sources, including ads, sales commissions, and selling your information to third parties. When you ask for dinner reservations, travel bookings, or other services, are you getting the best deal for you or the optimal deal for the ecosystem of partners? Does your assistant isolate different types of data, or are advertisers able to determine what you are doing, where, and with whom, perhaps to your detriment or embarrassment?

Finally, there is the role of personal assistant as gatekeeper. We are all familiar with human assistants that have controlled access to their principals, unnecessarily influenced information flow, or isolated them from their surroundings. An electronic assistant may be able to do this not only more subtly, but at the direction of ecosystem partners to their benefit.

Carl builds the future with the Office of the CTO's Innovation Pipeline Team in Intel Security. He is a security veteran with five years of top secret UK government experience, five years with his own company Sanctuary Software Limited, and over six years with McAfee/Intel. ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8423
PUBLISHED: 2019-02-18
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
CVE-2019-8424
PUBLISHED: 2019-02-18
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
CVE-2019-8425
PUBLISHED: 2019-02-18
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
CVE-2019-8426
PUBLISHED: 2019-02-18
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
CVE-2019-8427
PUBLISHED: 2019-02-18
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.