Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

what is private data and what is not?

Faizel: If we render "private" data so it is of no value to criminals, then we don't have to work so hard to prevent unauthorized access to it. For example, the credit card system could change so authentication relies more on user behavior and less on the secrecy of re-usable codes. What do you think? --Ben

hack-igations.blogspot.com...behavior-as-authentication.html

Click to read the article this is in response to.

Response: What is private data and what is not?

0

Ben: I agree that fixed format privacy data is more easily protectable when it is not fixed format. This certainly solves the problem of privacy data, but what about company secrets and non-fixed format information. Back to my Apple example I think the impact of leakage of iPhone 2 details could have been as damaging to the apple stock as the leakage of CCN of people on the itunes site. Now the question is "What is iPhone 3" and how does apple protect it?

It's all a matter of cost

0

If you make private data breaches significantly more expensive than protecting that data in the first place, the breaches will pretty much stop.

The way businesses look at this is cost: it costs me X to pay for a breach but 2X to protect from it in the first place. I'll do some superficial things, pay security some lip service, but that'll be about it. If a breach costs a business 10X, then the 2X needed to protect the data in the first place would look attractive.

This is somewhat simplistic but it speaks to the heart of business reality: securing personal data is an overhead function that doesn't produce any profit. Why should the business invest in measures to protect such data when it only ends up costing more money? When a breach costs the business significantly more than preventing it, the business will take steps to prevent it as this then becomes a cost avoidance issue.

Will this stop data breaches? Of course not; they will still occur. But their frequency and severity will drop significantly as businesses and vendors provide solutions to better manage this aspect of the business.

Respinse: Preventing data breaches not a technology issue

0

Protecting credit card, social security and bank account numbers is not obvious to you?

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: