Showing posts with label data. Show all posts
Showing posts with label data. Show all posts

Friday, October 18, 2019

Safeguarding personal data

The ease with which our personal data is being sought, the thoughtlessness in handing over the critical data relating to one and the reckless way in which such details are shared in public domain is scary, to say the least.

Recently, I attended a spiritually oriented event of a very popular and revered person who gives discourses on Ramayana, Bhagavatham, Narayaneeyam and other such spiritual activities attracting many devotees. At the event, it was announced that an exclusive group is being formed so that interested people are communicated about further events and to join the group a link was sent. The link led to a web page that asked for many personal data related to the potential member of the group. The page also warned that on submission, the name and photo associated with that particular account will be uploaded! Let me clarify at the outset, I have absolutely no issues in personal data being shared with this particular Group/ Event Management team as they are reliable, reputed and I have no reason to believe that they could leave the data unprotected leading to misuse.

But, the thought occurred as to what would happen, if the data so given is shared unintentionally but as part of further processing to some other third party organization, for maintenance? Or what is the guarantee of that third party keeping such data secure? What if there is a leak somewhere in this process, wherein data could be compromised and if so who is responsible for the same ?

So, while the persons seeking data may not be leaking or misusing it but are they aware of the risks and sensitivity of handling the same? More importantly in a group which is unlikely to be filled with only literates, what is their responsibility in seeking such data? In a belief blinded by other attractions and with some justifiable confidence on this group, many people are likely to share the data. But then, should the data seekers not perform their role and responsibilities in apprising the givers about the risks involved and / or confirming about their safety and security by an assurance of non-sharing with others without their consent ?

Normally with some technical know how, I believe, a reasonable profile outline could be created with one's expanded name, date of birth, contact number, email-id and photo. With the prevailing and proliferating instances of cyber crimes particularly over online banking transactions and with innovative cyber crimes like Sim Swap springing up everyday, while the basic security concern lie with the owner of the data, given the illiteracy and lack of awareness, should the data seekers not apprise the givers about the risks involved, so that the innocence and ignorance of the users are not exploited by some unscrupulous elements?

In another group, filled with bankers who could justifiably boast of atleast three decades of banking service, it is still a task to make them understand the risks in sending a mail to all thousand members and use of BCC in emails ! This is a classic case of the data collector unwittingly leaking personal data, which could have damning consequences !  Well then, can an ignorance be cited as an excuse ?

At the entrance of a popular saree shop in Chennai's busy Pondy bazaar, an young man with a neat neck tie was asking for the mobile number of all visitors under the guise of a free prize scheme!!

When the data collected at such different points are collated by any with crooked intention, will it be a huge task to build their profile? The above instances exhibit how personal data is collected with or without any dubious intention and this is what exactly common man should be aware of  before sharing his data.

I feel, fighting cyber crime must be multi-pronged - while the owners need to keep their personal data safe, the data seekers need to ensure privacy of data collected and also make sure that  before collecting the data, the provider is well informed about the risks involved in sharing. Organizations like Banks and other institutions should not only take up measures to ensure that data collected and also created out of the data provided and out of the business transactions are kept secure, but also subject themselves to security audits by recognized bodies or approved and qualified third party auditors, to gain customer confidence. Right now , these are being held more as a formal exercise towards compliance but the need of the hour is more towards customer protection than formal compliance to satisfy legal requirements

My point is data seekers should be more responsible in asking for data, as such acts could be misused by mischief mongers. For the well intentioned seekers- apprise the givers about the risks involved and the measures taken by them to protect their interest and also better not to ask for such data, unless they have the ways and means to protect them!   More importantly, individuals should be weary of sharing any data , unless absolutely essential or feel secured after a basic personal due diligence.  

Tuesday, June 11, 2013

Sweeping, Seeping and Snooping

Of late, I find many voluntary and service minded organizations indulging in cleaning the surroundings , clearing the lakes of weeds etc., This is a laudable effort in that it shows the involvement and commitment of the individuals towards a better environment that promises a better tomorrow. On the flip side, I also feel whether this could be a solution for the problems littered around us. If some organizations and good hearted people clean the place for a day or two, what lasting benefits is it going to bring? Will this not lull the civic authorities also? I feel that instead of OR in addition to this, such organizations could join hands and pressurize the civic authorities to do do their jobs. It will be better for such organizations to play a supervisory role,  monitor and track their progress instead of taking the brooms themselves. This is with due respect to these organizations and individuals whose efforts I applaud and in no way this is meant to disrespect or degrade their efforts. This is only a thought viewed with a different hat.

It is pathetic to hear about the technical and civil glitches that is surrounding the  newly built  airport terminals at Chennai. It began with the faulty design of the ramp, then a section of the roof or its false ceiling caved in and the latest is the seepage of the  roof. What is surprising is that if the roof seeps for the rain which lashed Chennai for hardly an hour, how will it stand the real fury of the North east monsoon? What happened to the quality standards and controls that are more talked about than implemented? What about the ownership of such misses that could turn costly? It is pathetic because, we talk so much but in reality none of these is observed or implemented.

On to the snooping of the US governmental agencies of one's data through the Gmail, Skype etc., - Shocking to say the least. Particularly from a country which regards high the privacy and rights of individuals, this is the least expected. At the same time, I admire the US President in admitting openly about its attempted peep at others' data, which also show the intentions of the Govt that appears to be genuine.

But, from a layman's perspective I have always wondered as to how on giving your password all the mail, cloud data  etc., are retrieved. This means someone has access to all your data and he goes on to retrieve your personal data even if your security details are lost by you after checking with some personal and private questions. For a query as to why this org which is storing the data of millions of people across the world are not (mis)using them, my conceivable answer is he does not have time to look into all the mails. If this appears naive, remember, my earlier claim of 'layman' here. But, in the unfortunate event of some sensitive data getting into the wrong hands , then you are done and dusted.

But then, it could also be argued that no one pressurized you to store all these data in a public domain protected by private people. It was on your own volition, you chose to believe them as it is without any service charges and so one has to pay for the same. It will be prudent to park only  banal data in such sensitive areas and not your private data such as passwords, bank account details, credit/debit card details, online transaction passwords etc., Prudence is more required and it is the innocent and the gullible and at times even a careless scholar could become a victim here. So, use your discretion.

If you want unhindered services, accesible from across the world with few clicks but with no cost, then one needs to be cautious. You cannot have the cake and eat it too - right ??