It’s official: security and privacy are dead. And as there’s a vested interest on minimizing privacy from government on down, kiss your private information goodbye.
I have for years said that there is no such thing as absolute security. Any system designed to provide access to a resource, even under a very limited set of conditions, can be broken. Our objective, then, is to make security so tough for the unauthorized that they move on to softer targets. While this is actually fairly easy to do today, I remain concerned that too few really take security seriously. Reports of last week’s compromise of credit card data and what should have been confidential data at the Massachusetts Registry of Motor Vehicles sparked little outrage – undoubtedly, most saw these events as simply more par for the course. Perhaps action will be taken when one of the idiots in charge of security at these esteemed organizations has his or her identity stolen. But I wouldn’t count on it – and, keep in mind, once confidential data is compromised, it’s compromised forever.
The political arm of security is privacy, and now things get really complex. Many assume that the Fourth Amendment to the Consitution of the United States of America protects us from unauthorized access to our information, but, alas, the Constitution only regulates the relationship between the government and the governed, and not activities in the private sector. One cannot blame marketers from trying to learn all they can about us and hopefully sells us tons of crap we really don’t need, but there are few laws against this. Whether there even should be such is the subject of much debate.
I have in the past argued that any information about an individual not explicitly put into the public domain by that individual (e.g., by posting it on Facebook) or required to be published by law (e.g., real-estate records) belongs to that individual and may not be published or otherwise disseminated without the expressed, explicit permission of the individual. Period. Credit reports, op-out policies, etc.? Sorry, marketers have to ask permission even to post data to a confidential file, let alone access it. Privacy comes first – or, at least, it should. But, for now, privacy and security are both abstract, theoretical concepts. And, of course, there’s little interest on the part of government or industry in fixing this situation, as marketers, crime fighters, and many others (like criminals, for example) prefer to minimize the amount of work on their plate.
But can this sorry state of affairs be fixed? I’ve argued for more secure operating environments. I worry that complex, clunky, fundamentally-insecure operating systems like Windows are entirely the wrong direction if we’re really interested in security, integrity, and privacy. Windows, after all, was written as tool to counter competition in the operating-systems space, and it largely accomplished that goal. Most users, I still contend, would be better off with Linux or OS X, and not just for reasons of security and integrity. I worry that malware disguised as an otherwise intrinsic DLL will cause great harm to many in the future, but that certainly isn’t the only attack vector to worry about. An end-user-friendly system verification tool would be lovely.
Or maybe the legislative route will work. Senator Charles Schumer of New York has called for a Federal Trade Commission investigation into what information a mobile OS can access without a user’s permission. Now, to be fair, Google has a Privacy Policy, but who has the time to plow through all of the ins and outs of that, let make decisions and alone take action of any form as a consequence? While I often disagree with Senator Schumer on many issues, and while I in general favor a limited role for government in most affairs, it likely is time for legislation here. Without it, privacy and security are most certainly dead. I personally consider them to be such already.
So that leaves the Easter Bunny, whom I am convinced is absolutely real. How else to explain the Russell Stover Coconut Cream Egg that mysteriously appears on my desk the day after Easter every year? Any why is believing in a rabbit with the powers of Santa Claus any less preposterous than believing that my information or privacy is secure?




