Tuesday, October 22, 2013

Quantum Cryptology


Following Eric Snowden’s leaking of NSA privacy breaches, there has been an increase in interest in quantum cryptology -- the securing of data via streams of light.  Because quantum cryptology is thought to be uncrackable, it is understandable that many businesses are interested in its potential.

For organizations, the notion of such security is something that cannot be ignored. But how much should a company be willing to invest researching costly theoretic technology when history is littered with cracked “uncrackable” codes.  Just peruse the comments section of The Verge’s article on quantum cryptology to see how quickly the pursuit to crack it manifests.

While the potential ROI on quantum technology is arguably limitless.  But so, then, is the risk of failure.  Who will be the first to attempt to implement quantum security into their organizational systems?

Monday, October 14, 2013

Private Getaway



There is a battle being waged between the web startup, Airbnb, and New York State. According to its website, Airbnb.com is a trusted community marketplace for people to list, discover, and book unique accommodations around the world.” At issue is the concern that landlords might be using the website to circumvent New York State rental laws, specifically, renting out properties for less than 30 days unless a permanent resident is present.

According to a Bloomberg Business Week online article, Airbnb is refusing to comply with a subpoena to hand over the names of all of its 15,000 users.  They argue that the law should not apply to “ordinary, everyday people who occasionally share their homes.” They also feel the subpoena is “unreasonably broad” given the fact that Eric Schneiderman, the New York State Attorney General has said that they are only concerned with “a small number of bad actors who abuse the Airbnb platform.”

This battle raises privacy questions for both individuals and organizations in terms of how far the government can reach to enforce legislation.  While the intent of the legislation according to the Bloomberg article – that residents of an apartment building “shouldn’t have to worry about the apartment next door turning into a de facto hotel room” – is valid, does the government have the right to collect information on all users?  In essence, simply by being a user on a website where someone might be violating a law, all users become suspects and subject to investigation.  And beyond that, should the government be the sole arbiter of who is subject to prosecution in a marketplace where occasional home shares are growing in popularity due to the ease of it on the web.

For organizations, where do they draw the line when a small percentage of users are abusing the platform to circumvent legislation?  They are caught between privacy that they guarantee to their users and being party to illegal activity.  If they do not wish to relinquish all information, then they either become the arbiter of who is subject to investigation or they, to some extent, become complicit.

As social media continues to grow and new ideas for web services and apps appear every day, the implications of such questions increase.  It may not be long before benchmark cases of online privacy and constitutional rights find themselves much more frequently on the steps of the Supreme Court.

Sunday, October 6, 2013

Renewable Email

Email addresses have become part of our identity.  Much like a long-possessed phone number, we identify them with our friends, families and ourselves.  But unlike phone numbers, our email addresses are repositories for highly personal information.  We think little about relinquishing a phone number, assuming without great concern that someone will have that phone number again at some point in the future, but what about relinquishing an email address…or not relinquishing it, but having it repossessed by a service provider.  While one's personal emails and profile information may be erased, it is possible that email sent to the email address might contain personal information for the previous user.

That concern was raised in a mashable article detailing how Microsoft and other service providers recycle email addresses.  The article explains that Microsoft requires users to log into their email accounts at least once every 270 days.  If not, they risk having their account deleted.  Following the deletion, the account will be made available again after 360 days.

It may seem that 270 days of inactivity is a reasonable amount of time to give someone to keep their account active.  However, it is not uncommon to have to create multiple email accounts for different purposes, and it becomes difficult sometimes to track these or remember all of them.  For individuals, this may just be a case of personal accountability.  But for organizations, there might be greater privacy concerns.

 I’ve had to create different google accounts for emergency communication, for wiki access and for file sharing.  Not all of these are needed continually and some I’ve forgotten.  Large organizations could have countless inactive Google, Yahoo! or Microsoft accounts with private or sensitive information of which they are unaware.  It may be that it is highly unlikely that such a breach of privacy could occur, but the implications of such a breach should be enough for organizations to think more about setting guidelines for creating email and web accounts for business purposes.