PRIVACY + SECURITY BLOG

News, Developments, and Insights

high-tech technology background with eyes on computer display

TSA’s Broken Promise About Secure Flight

TSA

Remember CAPPS II, the program for screening airline passengers by using databases of personal information?  This program was scrapped because the Transportation Security Administration (TSA) of the Department of Homeland Security (DHS) was concerned that it posed an increasing threat to privacy and civil liberties.  Replacing CAPPS II was the nicely-monikered “Secure Flight.”  (EPIC’s website has a good history and set of links about the history of the program.)  After names like Carnivore and Total Information Awareness, government officials have learned to rename things with soothing happy titles.   Secure Flight was to be a kindler, gentler version of CAPPS II, with more limited uses of information and with more limited information gathering and retention.  Privacy advocates were skeptical of Secure Flight, but TSA insisted that Secure Flight was genuinely nicer, not just nicer in name.  According to TSA’s final order on its testing of Secure Flight:

Continue Reading

How HIPAA Was Undermined

HIPAA

The Office of Legal Counsel (OLC) of the DOJ has issued a highly suspect interpretation of the original HIPAA that seriously undermines the enforceability of HIPAA.

Some background: In 1996, Congress Passed the Health Insurance Portability and Accountability Act (HIPAA).  The Act, at 42 U.S.C. § 1320d-6, provided in part for the protection of medical privacy – although it left the specific details to the Department of Health and Human Services (HHS) to establish via a rulemaking.  HIPAA contained civil and criminal penalties for when:

A person who knowingly and in violation of this part–

(1) uses or causes to be used a unique health identifier;

(2) obtains individually identifiable health information relating to an individual; or

(3) discloses individually identifiable health information to another person

Continue Reading

Identity Theft Fears and Online Shopping

Your Evil Twin Beyond the Idenitity Theft Epidemic

From a recent survey:

Nearly half of U.S. voters say they don’t shop online because they fear identity thieves may capture their bank-account information, according to a survey released on Wednesday by a technology-industry trade group.

These fears are heightened because of the rash of security breaches in recent months.   I previously posted about these breaches here and here.

Continue Reading

Biometrics and the “Titanic Phenomenon

Biometric Privacy and the Titanic Phenomenon

Washington Post article discusses the growing use of biometric identification, which involves authenticating identity by using immutable characteristics of the human body.  Some methods include fingerprint readers, iris scanners, and facial recognition systems.  According to the article:

Continue Reading

Soup for Me at $5 but No Soup for You (Or Maybe at $10)

Behavioral Targeting

There is still more interesting grist from the national telephone survey by the Annenberg Public Policy Center at the University of Pennsylvania.  The report has an extensive discussion of price discrimination – offering different prices for the same product or service to different customers based on behavioral profiling.

This practice is already happening.  Supermarket discount cards are an example of price discrimination.  The report notes: “[B]eing a loyal customer doesn’t automatically mean getting the lowest prices.  Computer analyses of shopping histories might determine that a person’s allegiance to some products means he or she would buy them even without the discounts, or with smaller discounts than others might get for the same items at the same time.”

Continue Reading