Vulnerabilities / Threats
12/30/2013
10:00 AM
Martin Lee
Martin Lee
Commentary
Connect Directly
LinkedIn
Twitter
RSS
E-Mail

Security, Privacy & The Democratization Of Data

Data gathering and profiling capabilities that today are only available to nation states will eventually be at the disposal of everyone. What then?

The View From The Top
(Source: Norman Kuring, NASA/GSFC/Suomi NPP)

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Li Tan
50%
50%
Li Tan,
User Rank: Apprentice
1/3/2014 | 3:39:16 AM
Re: Reputation Management
This fact holds true across different races and tribal groups. It's quite common in China as well - the people build the rudimentary mutual trust from traditional ancestral relationships. The people living around the same community become a kind of gang. This is not common in modern cities nowadays but still holds true in those rural area and small villages.
byock981
50%
50%
byock981,
User Rank: Apprentice
1/2/2014 | 8:56:22 PM
Controlling our online reputation profile?
In addition to democratization of data another reason it is easy for governments, companies and other citizens to form these "reputation profiles" is because we do not currently have great ways of controlling our online presence.  The Internet2 Scaleable Privacy Project is attempting to help citizens protect their privacy and strength the nations identity ecosystem.  It is attempting to put the "Informed" into Informed Consent with creation of privacy manager tools.  With these types of privacy manager tools our reputation profiles will become more targeted and relevant depending on the context of our digital interactions.  Without them I worry our digital interactions will be mis-understood and hence our reputations tarnished. 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/2/2014 | 10:54:00 AM
Re: Reputation Management
That doesn't surprise me. My husband is a financial investigator who works for an arm of the judicial system that investigates white collar crime by lawyers against clients. He sees a lot of cases that exploit that tribal mentality of trust, where "no one  in my (fill in ethnic group) would take advantage of me or steal from me." 

 
MartinL923
50%
50%
MartinL923,
User Rank: Apprentice
1/2/2014 | 10:34:52 AM
Re: Reputation Management
Marilyn: A few years ago I had the honour of conversing with a law enforcement officer who was investigating a gang of internet fraudsters. The gang only recruited members from a specific ethnic group who spoke a particular dialect and whose family origin could be verified. This made infiltration  by law enforcement almost impossible since their reliance on tribal ties facilitated the detection of imposters. Even in this day and age, internet fraudsters abusing the global village rely on their ancestral villages to filter out imposters.

Martin Lee
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/2/2014 | 10:09:47 AM
Re: Reputation Management
I really like the comparison between our ancestral village and today's connected global village. Back in the day when people knew each other because they lived next door, or went to the same school, or were related through marriage and family friendships that crossed generations, reputations were well known and frequently entrenched and hard to change when they were wrong). Today many of our personal and professional relationships start with email or social media: a resume to a prospective employer, a response to a rental listing on Craigslist,  a comment on a product review.

While it is fairly easy undertake a rudimentary reputation check through LinkedIn, Facebook Google, etc. the con artists, predators and bullies are expert at creating attractive --and false -- public personas. So in addition to making sure our personal digital reputation is, like Caesar's wife, above reproach. We must also make sure that those we encounter in our virtual village are who they say they are. 
WKash
50%
50%
WKash,
User Rank: Apprentice
1/2/2014 | 10:03:59 AM
Re: Reputation Management
 
Rate It
50%
50%
 

MartinL923 

MatiniL923, I agree. It's worth noting how safety regulations evolved in the auto industry and with the likes of Underwriters Laboratory. It's not a perfect example, I know, since flaws in software and online systems don't kill people. But there is an argument that people need more safeguards and resources to protect themselves in cyberspace than the commercial market currently provides them.  
MartinL923
50%
50%
MartinL923,
User Rank: Apprentice
1/2/2014 | 4:55:13 AM
Re: Reputation Management
Every advance has its disadvantages too. Your comments are entirely correct. Unfortunately the remedies for the downsides of inventions tend to lag. We're still trying to come up with ways to remedy many of the unforeseen consequences of the Internet, the importance of security being one of these. I'm sure that our future successors will wonder at how we could possibly work and live without invention X that solves problem Y which currently plagues our existence. The good news is that fame and hopefully fortune awaits the person who does invent and build the tools that will help us solve these issues.
WKash
100%
0%
WKash,
User Rank: Apprentice
12/31/2013 | 1:12:30 PM
Reputation Management
The democratization of digital tools may be make it easier to assess the reputation of individuals and businesses, but it also creates new opportunities for abuses that we're not yet fully equipped to deal with. One of the sad undercurrents of this digital democratization is the amount of social media trashing and abuse being inflicted today on teens by their peers -- sometimes with tragic effect.  Then there are the challenges of setting the records straight after having your digital identity stolen.  In both cases, reputations can be completely and wronglfully compromised. Yet we still lack the tools needed to help individuals recover quickly when the digital ill-will of others strikes us or our kids.
asksqn
100%
0%
asksqn,
User Rank: Ninja
12/30/2013 | 11:20:49 PM
Hot diggety
Imagine the day when Americans are able to browse the vast digital dossiers kept on us by the NSA.
MartinL923
50%
50%
MartinL923,
User Rank: Apprentice
12/30/2013 | 5:55:07 PM
Re: Reputation Management
I agree entirely. I think as the world got bigger doing that due diligence became more difficult. However I suspect that technology advances are going to make following someone's history a whole lot easier.
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Five Things Every Business Executive Should Know About Cybersecurity
Don't get lost in security's technical minutiae - a clearer picture of what's at stake can help align business imperatives with technology execution.
Flash Poll
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Social engineering, ransomware, and other sophisticated exploits are leading to new IT security compromises every day. Dark Reading's 2016 Strategic Security Survey polled 300 IT and security professionals to get information on breach incidents, the fallout they caused, and how recent events are shaping preparations for inevitable attacks in the coming year. Download this report to get a look at data from the survey and to find out what a breach might mean for your organization.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Security researchers are finding that there's a growing market for the vulnerabilities they discover and persistent conundrum as to the right way to disclose them. Dark Reading editors will speak to experts -- Veracode CTO and co-founder Chris Wysopal and HackerOne co-founder and CTO Alex Rice -- about bug bounties and the expanding market for zero-day security vulnerabilities.