Showing posts with label p. Show all posts
Showing posts with label p. Show all posts

Wednesday, April 2, 2008

Seeking Out Problematic Sources In Biometrics Early Instead Of Waiting To Treat Its Symptoms

In all of my blogs about biometrics, I address an ongoing concern that the use of biometrics as an "identity document" or in personal identification is being deployed without further research and analysis on the potential magnitude of its implications. I find this topic very interesting in addition to the privacy issues surrounding databases. Therefore, I continued researching and reading articles about the subject of biometrics implementation as a more efficient security measure. I weighed the pros and cons of what I discovered before finding a document in which a public policy forum on biometrics was held. I am sure this is not likely to be the first or the last time a group convenes to determine the best approach to defining an appropriate policy for implementing biometric systems for various identity verification applications. I thought, "Whew! Finally, a collective, diverse group of intellectual individuals have taken measures in the interest of biometrics implications seriously enough to intiate the development of a suitable public policy." It is obvious that we will not be able to avoid every potential problem that comes with the use of biometrics, but how we may be able to minimize the impacts if we seek to find sources to the problem instead of waiting to treat symptoms.

I like the seeking the cure before the disease or at least analyzing and researching the issue to discover the source of problems. It is an approach that is taken in Project Quality Management and in healthcare as a natural, approach called homeopathy. If we can get to source of the disease or problem, we can prevent it instead of treating the symptoms which perpetuates the existence of the disease or problem. The public forum discussions on biometrics seem to be focused on taking the holistic approach as they sought diverse perspectives for meeting the challenges of biometrics in advance. In the article, a list of major concerns and recommendations have been proposed. I summarized them as the following:


1. Concern for the potential abuse of biometric systems
2. Using "biometrics in an immigration and citizenship context could create
we-versus-them mentality."
3. Trading off security with privacy concerns
4. Implementation of biometrics without establishing an identity policy
5. Failure to perform a proper assessment of biometric implications
6. Concern that "technology will drive policy if we don't ensure that policy
imperatives are driving the development of technology."
7. Addressing the need for "a business case for using biometric applications in
identity documentation, including a national identity card."
8. Concern for that the "perceived dichotomy between security and privacy is false."
9. "Use of biometrics in identity documentation presents genuine issues that merit
serious public discussion."
10. Monitoring and controlling quality and performance of such systems

Reference Article or Link:
http://www.cic.gc.ca/english/pdf/pub/biometrics.pdf

Enhanced Driver Licenses In Washington, Does This Arouse Suspicions For Anyone?

Reference Article or Link:
http://www.dmv.org/news-alerts/enhanced-driver-license.php

"Why Enhance the Driver License?
In a continued effort to develop alternative forms of identification compliant with the Western Hemisphere Travel Initiative, the Department of Homeland Security came up with the idea for these voluntary licenses and ID cards. The hope is that the EDL/ID―which denotes identity and citizenship―will make travel across land and sea ports of entry much more convenient.

Benefits of the EDL/ID
Using Radio Frequency Identification Tags (RFIT) and other measures that make forgery more difficult, EDL/IDs are encoded with the proper information to replace passports at border crossings. Furthermore, the EDL is less expensive and easier to tote around than a traditional passport. Washington Governor Chris Gregoire described EDLs as "a way to boost security at our border without hampering trade and tourism." If all goes as planned in Washington, we just might see these alternative forms of identification across all states.

Part of the Intelligence Reform and Terrorism Prevention Act of 2004, the The Western Hemisphere Travel Initiative requires travelers to carry passports when crossing the borders into Canada and Mexico (as well as Bermuda and the Caribbean). EDLs would take the place of a passport for U.S. citizens crossing at these land and sea ports of entry, but not for international air travel. This represents a savings to consumers, with passports costing $97 and EDLs $45 (DMV-Washington 1998-2008)."

I read this piece after I searched for more information on the Department of Motor Vehicles in Washington, D.C. I was just looking for information about traffic light cameras and tickets for traffic violations via mail for my blog due to my experience regarding the topic. After reading it,I recalled all of the information in Database Nation and articles and my blogs on the use of biometrics with respect to our national security. I began to think "Uh-oh. It's happening. They are deploying these systems in spite of further research and analysis of their implications on accurate personal identification."

Then, I thought perhaps the Enhanced Driver License despite an effort to protect our national security is just another way to track our traveling habits. I became suspicious of what might actually be done with the information. If our spending and driving behaviors are already being tracked by collecting data from credit and discount shopping cards and smart tags, then this is just another way for them to find out even more about us. Could this type of license be used as a GPS enabled tracking device? Or could it be another way for the DMV to collect information about our travelling habits and then sell them to third parties who then inundate us with travel promotions and credit card solicitations with frequent flyer programs?

Beyond the collection of travel data, I worry that the issues surrounding biometrics will become more abundant with the issuance of such a license. This could defintely lead to big business for identification card counterfeiters, which in turn magnifies the problem of identity theft. We will have to worry about malicious individuals seeking and gaining employment at organizations or agencies that maintain biometric data for their own personal gain. What about data collected that may be used to inaccurately accuse someone of a crime simply because they were at the wrong place at the wrong time? I think that we are asking for trouble here despite all of the potential benefits. The deployment of Enhanced Driver's Licenses as a more efficient passport seems to be in effect already, which means I will stay alerted to the good and potential bad this program may cause. Who knows? Maybe it will be successful; there will be no mistaken identities; and the worst we will endure is an increase in junk mail.

Tuesday, April 1, 2008

Should We Be Concerned About Biometrics?

Referencing Article:http://www.eff.org/wp/biometrics-whos-watching-you

"Why be concerned about biometrics? Proponents argue that:

A) biometrics themselves aren't dangerous because all the real dangers are associated with the database behind the biometric information, which is little different from problems of person-identifying information (PII) databases generally;

B) biometrics actually promote privacy, e.g., by enabling more reliable identification and thus frustrating identity fraud.

But biometric systems have many components. Only by analyzing a system as a whole can one understand its costs and benefits. Moreover, we must understand the unspoken commitments any such system imposes (EFF Sep 2003)."

I read this and was moved by the idea that a system that could have significant implications on personal identification data is being prematurely recommended for broad based deployment without significant analysis of its advantages and disadvantages.

The advantages of biometrics seem to create a false sense of security I believe in part because we have relied on them for so long in other applications. Biometrics have been used in law enforcement where we fingerprint criminals and maintain that information in records to possibly identify repeat offenders, update current records with new information about individuals, or for use in otherwise pertinent applications. As far as I know, fingerprints have been very reliable in identifying individuals and solving criminal cases and now with the advancement in forensic science we are able to use DNA and DNA databases to close cases that would otherwise be deemed cold or open indefinitely. This biometric data has also been very useful in exonerating the falsely accused and getting justice for these individuals and their families.

It seems simple enough that we could rely on "bio" samples unique to each individual to perform check constraints against "live" samples in biometric databases (EFF Sep 2003). Yet, I have to wonder what would happen in the case of individuals who share similar DNA characteristics particularly in the case of twins, parents, other siblings, and family members. Now, the argument could be made that each individual's fingerprints are unique, but what about in the case of scanning faces and other body parts for personal identification? I have lost count of the number of times someone has mistaken me, my mother, and or my sister for someone else. Most of the times it was because we look so much like other members of our family, which is to be expected, when someone just glances at your face and recalls a familiar image. I can see this also being a potential problem for a database system as well. The possibility for potential errors seem to exceed the scope of biometrics particularly when you factor in identical twins. I am just curious to know how we could prevent mistakes in that instance. These are just one or two potential disadvantages of biometrics. Obviously, we need to rethink early adoption of these systems as primary tools for personal identification.

I agree with the Electronic Frontier Foundation in that we need a realistic model to build the most efficient biometric systems before we can implement this technology instead of promoting it as a cure all solution for personal identification and the most accurate way to combat crimes that rely on biometric resolutions. We do not know enough about the impacts of relying too heavily on such systems. It is very easy to allow the pros to outweigh the cons when we approach advancements in technology. It is almost like kids who are easily persuaded by the promotion of all these innovative and technologically advanced toys or gadgets so they easily adopt them via persuading their parents of the surface benefits. For example, the continuous stream of video games and cell phones that saturate the market. We do not realize that with the early adoption of these systems and gadgets that we ultimately pay the price of systems and phones that become outdated almost the moment we buy them or poor behaviors that result of not understanding the full extent of product adoption (e.g. laziness on the behalf of children who would rather sit and play games all day instead of being active or excessive text messaging that leave us paying exorbitant fees associated with cell phone bills). We may get more than we bargained for if we act prematurely in the adoption of new technologies instead of thinking things through before we act.

It all comes down to asking ourselves the question of whether we should be concerned about biometrics, gathering data about that question, and evaluating and analyzing that data before we rush into deploy a system that may do more harm than its proposed good.

Wednesday, February 20, 2008

Could "End User Buy-In And Support For Accurate Data" Resolve The "Garbage In, Garbage Out" Issues of Databases?

In a previous blog, I referenced a database privacy quotable "Garbage In, Garbage Out" to address not only the concerns for data privacy, but the accuracy of that data. Database accuracy is such a big concern because information about every aspect of our lives continues to be recorded and stored in infinite datawarehouses to be accessible by individuals who have the power to grant or deny us privileges. It is not enough that our ability to make decisions is no longer an autonomous process, but that which should be our sole right is now dictated by powerhouses of information that could be dangerously inaccurate. We see the effects of bad data maintained in businesses when individuals experience identity theft; a keeper of the data stored about us makes a clerical error; and or when a company never continuously validates the integrity or quality of data it stores.

I recall reading an excerpt of Database Nation (Simson Garfinkel) in which he discusses how outdated data is at a lot of the companies who continuously collect and store data about individuals. This old or bad data may be rarely updated or never validated in a lot of companies whose sole function is to share information for the purpose of conducting business. We know this to be true because of the credit reporting, billing, and mailing errors that many of us have to live with daily. How many times have you received someone else's mail? And how many times have you received calls at your residence for the same wrong person-wrong phone number even after the passage of multiple years? Someone or some company simply is not, properly, maintaining the data being stored. This failure to validate and update data is not only annoying, but can be detrimental if this bad data is used to make critical business decisions.

We recognize this problem obviously, but what can we do about it? How do we begin to tackle this problem when it seems like an infinite one that will take infinite lifetimes to resolve? When companies maintain bad data while simultaneously collecting and storing new data, how can they reasonably expect to achieve data accuracy and consistency? It is possible we may never solve this problem, but if we choose to tackle the problem then we might minimize the number of errors and their impacts. There are companies who have taken steps toward approaching a solution.

In the article that is referenced below, "The Secret to Successful Business Intelligence A Top Notch Data Warehouse" Rensselaer Polytechnic Institute seeks to gain end-user endorsement and support for achieving accurate data. An essential first step for the institution was to review how data was being defined, stored, and used by various entities within the institution. It appeared that data was being managed with no real guidelines in place. There was chaos in a sense because no "data definitions" were established (Daniel 1). Different departments and business functions used their own definitions and methods for looking at data (Daniel 1). This presented a lot of problems for Renassler as the following excerpt reveals.

"...Finally, the admissions staff needed more timely demographic information about its applicants to inform student selection decisions.

Getting a handle on the data has been critical because higher education today is a tough arena. Government funding is down, requests for financial aid are up and admitting a diverse student body—in terms of gender, geography, ethnicity and academic achievement—has become more challenging. All these factors make balancing the supply of enrollment acceptances and financial aid with the demand from student applicants more challenging than in the past. The better Rensselaer could optimize its administrative resources and time, the more revenue it would have for courses and scholarships to attract the best and the brightest.

The answer was a business intelligence and enterprise data warehouse implementation (Daniel 1)."


Ultimately, Renassler decided to "create enterprisewide processes for collecting and using data (Daniel 1)" which included communication, training, and support for end users (Daniel 1). They implemented this new process via the following focused steps as listed in the article:

1. Create cross-functional support.
2. Think big, start small, deliver quickly.
3. Create one version of data truth.
4. Provide support for new behaviors.


I like Renassler's approach to solving an ongoing business intelligence problem. It showed some maturity (e.g. as it applies to Capability Maturity Model® Integration) on the part of the institution to go from chaos to at least recognizing the problem and trying to find a valid solution. Also, I believe that their new approach of putting more value on the keepers of data by providing "broad user support (Daniel 2)" could serve as a best practices methodology for other companies seeking to improve the quality of their information they store. Renassler's redirection serves as a good best practices because "enterprise data warehouse and business intelligence projects' success depends on broad user support and because consequential business decisions are made on the faith that information is accurate (Daniel 2)."

If every datawarehouse infrastructure applies this ideal of continuous proces improvement (CPI) or total quality management (TQM) of data, then we may get closer to weeding out the garbage that could potentially go into databases thus minimizing the garbage that goes out of them as well. It looks like it did well for Renassler in terms of ROI and "optimized expenses (Daniel 4)." See the section titled "An A+ for Rensselaer's Business Intelligence" on page 4 of the article.


Referencing Article:
http://www.cio.com/article/151601/The_Secret_to_Successful_Business_Intelligence_A_Top_Notch_Data_Warehouse
"Outdated information and disagreement over data definitions was impeding Rensselaer Polytechnic Institute's progress. To the rescue: a business intelligence plan that emphasized end user buy-in and support for accurate data"

Privacy Issues Surrounding Databases

This topic is one of an infinite nature once you begin to explore all the instances of privacy piracy. I got more information about how our privacy gets compromised by databases than I could ever have imagined. When I discover the ways that databases or database technologies, can be used and are being used to capture information about us as we go about our daily lives I am in awe that more is not being done to regulate these acts.

When I speak of these acts I am referring to how easily we get tricked into providing information about ourselves to individuals who use it for their own internal purposes or to sell or share it with third parties without our consent. As I read more excerpts of Simson's Database Nation I could not believe that I was not more guarded with my information.

There are certain instances where I questioned the collection of my information e.g. in hospitals, doctor's offices, and other cases where the collection of my personal data might seem more pertinent to my well-being. Yet, I discovered the gross abuse of my personal information even in places where I least expected infringement upon my privacy (e.g. medical records). I was not aware that when I signed consent to release my medical information to what I believed were eligible third parties like the providers of my medical insurance, that other third parties for which I never knowingly would have given consent also have permission to access my medical data. Who knew that the keepers of medical records could sell that information to insurance companies, current and potential employers, and anyone else who could use that information to make critical decisions about individuals.

It is like we do not even own our information any more once we give consent to collect our personal data whether in awareness or ignorance to third parties. When I think of how I use my Visa check cards instead of cash and sign up for discount programs in grocery stores in the quest to be frugal, I feel silly now each time I go to my mailbox and am uninundated in junk mail or solicitations. Then, I think of all my efforts to opt-out of marketing promotions and credit card offers and see them as wasted when there is no way to eliminate each group of individuals responsible for the intricate web of advertising. Who has time to call each company that sells their information to stop doing so or to remove their names from the proverbial list. I even get ads faxed to me now, which is such a gross waste of paper. It angers me to think that not only am I paying the price for someone else's careless mishandling of my information, but also incur costs in terms of paper and other printer supplies not to mention the infinite cost of privacy lost.

The privacy issues surrounding databases are so infinite and coupled with the ever increasing advances in technologies that assist the neglectful transmissions of our personal information that we may never see an end to this problem. At best we can only expect that technology will exacerbate the problem thus allowing it to get worst before it gets better. Who decides on when things get better ultimately is not up to the keepers, seekers, and senders of our information, but up to the us, the victims of database privacy abuses.









References:
Database Nation: The Death of Privacy In The 21st Centruy by Simson Garfinkel
ISBN 0-596-00105-3

Monday, February 11, 2008

Exploiting Children Via Databases (Database Nation Discussion)

In Chapter 7 "Buy Now!: Selling It To Our Youngest Consumers", Simson Garfinkel talks about this exploitative practice of collecting data from children while they use the Internet to be stored in databases for marketing purposes. I was unaware for some odd reason that sites that I once deemed child-friendly because of the age-appropriate content, were equally as harmful to my children. I now know why I have received all types of marketing offers in the mail for various children's magazines, toys, and other products for which I did not personally seek.

It is not enough that we have to deal with all of the commercials marketing to kids and other child predators. Now, we have to start screening the sites that our children frequent on the Internet that appear harmless. Who preys on children's ignorance of data gathering methods anyway? Are companies so concerned with increased profits that they will stop at nothing to entice a child to provide personal information about themselves and sometimes other members of their families?
I wonder if they realize that in their attempts to gain information for marketing campaigns geared toward children that they might be putting children in harms way. There is no way to guarantee that some malicious individuals are not intercepting the same personal data that they see as harmless.


Where is the social responsibility in all of these ploys to collect information? Who will protect the information that they are gathering about children? I do not want to even think about what type of malicious individuals could be working for the companies who collect address information from children via mandatory product or site registrations. I think that we really need tougher regulations in place to sanction any company who attempts to collect information from children without their parents' consent despite disclaimers and acceptance agreements. There needs to be some way to protect our kids from further exploitation.

I read that some regulatory efforts have been made toward minimizing how data can be gathered, but not prohibiting or completely outlawing data collection from minors. We as parents will simply continue to regulate this practice. Such a task will require continuous monitoring and trying to control what information is allowed into our homes and what is allowed to go out of them. A Database Nation is definitely where we reside today, but you would think they would take a little easier on the parents---the decision and purchase makers. It's like our jobs as parents are not difficult enough now we must learn to navigate around this intricate mess.