Tuesday, 7 October 2008

EU privacy advisory body looking at e-discovery

The Article 29 Working Party subgroup dealing with E-discovery met in September to discuss this transborder issue. A draft working paper should be proposed for discussion and possible adoption at the next plenary session of the Article 29 Working Party in December.

The Article 29 Working Party on the Protection of Individuals with regard to the Processing of Personal Data is an independent advisory body on data protection and privacy, set up under Article 29 of the Data Protection Directive 95/46/EC. It is composed of representatives from the national data protection authorities of the EU Member States, the European Data Protection Supervisor and the European Commission. Its tasks are described in Article 30 of Directive 95/46/EC and Article 15 of Directive 2002/58/EC. The WP is competent to examine questions covering the application of the national measures adopted under the data protection directives in order to contribute to the uniform application of the directives. It carries out this task by issuing recommendations, opinions and working documents.

http://ec.europa.eu/justice_home/fsj/privacy/workinggroup/index_en.htm

Monday, 6 October 2008

EU to pave way for deployment of smart tags

From Euractiv.com

The French EU Presidency will today (6 October) hold a high-level conference dedicated to building the so-called 'Internet of Things'. The meeting comes as the Commission prepares to present measures aimed at overcoming privacy concerns related to the use of the Radio Frequency Identification (RFID) microchips that are expected to lead the technological revolution.

Brussels considers the creation of the 'Internet of Things' as a key priority as it could provide solutions for a wide range of societal problems, such as ageing populations.

In a future world where ubiquitous tags and sensors would be attached to everything from letters to walls or clothes, the Commission believes many things will be possible. "A blind person might see," said one information society expert at the EU executive.

Indeed, according to the 'Internet of Things' vision, objects could communicate among themselves, for instance allowing a blind person to walk down a street knowing exactly what is around him. "This would be done by using a tag reader, able to detect and read the information contained in tags disseminated everywhere," added the expert.

Elderly people could also benefit from household goods that anticipate their needs and requests, such a fridge which orders more eggs from the supermarket once they have run out, or clothes capable of constantly measuring key health indicators, like blood pressure or heartbeat.

However, the use of RFID chips also raises concerns regarding the privacy and security of carried information, as tags could contain personal details potentially exploitable by anyone equipped with a tag reader.

To address these concerns, the Commission will present, in November, a recommendation to member states encouraging them to adopt initial measures to make people more aware of the existence of RFID embedded in objects or rooms, and to avoid misuse of the new technology.
According to the upcoming recommendation, a draft of which has been circulating since April 2008 (EurActiv 26/02/08), all companies interested in using RFID, from airlines to retailers, will have to draw up a 'privacy impact assessment' to verify the potential privacy-related risks of the devices they are using.

What's more, retailers, such as Carrefour or Metro, will be required to de-activate any tags attached to items they sell once the buyer leaves their stores. However, retailers are already resisting such a measure for fear that it will push up their costs and act as a disincentive to the deployment of tags, EurActiv has learnt.

The Commission will also propose two harmonised logos to indicate the presence of RFID in products and tag-filled environments. Awareness-raising campaigns will also be organised and funding is envisaged for projects aimed at developing privacy and security-friendly tag designs.
But the RFID revolution still appears distant, hampered not only by privacy and security concerns but also by a lack of international standards. Technical skills are also lacking, with the software industry pointing out that Europe would be incapable of coping with massive deployment of RFID due to a lack of qualified engineers to deal with tags.

In September, the EU executive launched a public consultation on the "early challenges of the Internet of Things," which is expected to result in the publication of an official document in the second quarter of 2009.

For more, go to http://www.euractiv.com/en/infosociety/eu-pave-way-deployment-smart-tags/article-175998

Saturday, 4 October 2008

Deutsche Telekom Says Data From 17 Million Customers Was Stolen

Deutsche Telekom has confirmed that personal information from 17 million of its mobile phone customers was stolen in 2006, including secret telephone numbers of high-profile politicians and celebrities.

Deutsche Telekom said the stolen data includes customer mobile phone numbers, addresses, dates of birth and, in some cases, email addresses. Bank information or credit card numbers were not accessed, said the Bonn-based firm.

There has reportedly been no indication that the data has been misused, though the Telekom said "extreme criminal energy" was behind the theft.

German newsmagazine Spiegel reported on Saturday, Oct. 4, that is had obtained access to the missing information via a third party. The news apparently came as a surprise to Deutsche Telekom, where the case was considered closed.

"We had assumed that this data had been fully secured as part of an investigation by the district attorney," Philipp Humm, director of Deutsche Telekom's mobile phone division T-Mobile, said in a statement. Data security measures had been fortified since 2006, he added.

According to media reports Saturday, Oct. 4, Telekom had contacted the appropriate authorities as soon as the data was stolen in 2006 and an investigation has since been underway.

Telekom said it had conducted research after the theft and discovered that copies of the data had been offered on the black market but had apparently not been bought. Few customers brought complaints pertaining to the data mishap, though a special hotline telephone number was set-up.

The public prosecutor's office in Bonn told reporters that pieces of data had been confiscated from private homes, but that the thieves themselves had not yet been detained.

Celebrity customers, including comedian Hape Kerkeling and television moderator Guenther Jauch, high-ranking politicians, billionaires and clergymen were reportedly among those affected by the data breach.

For some of them, it could represent a threat to their security if their secret personal telephone numbers landed in the hands of criminals.

Saturday's revelation is not Telekom's first brush with data scandals. Earlier this year, the firm admitted that calls between journalists and board members had been illegally monitored in 2005 and 2006.

From http://www.dw-world.de/dw/article/0,2144,3690132,00.html

Friday, 3 October 2008

How to prevent on-line manipulation: EU Agency ENISA publishes white paper on ‘Social Engineering’

ENISA, the European Network and Information Security Agency, has launched a white paper on ‘Social Engineering’, (i.e. on-line manipulation, through social networks, email, also known as ‘Nigeria-letters’ or ‘advance-fee frauds’, instant messaging, or Voice Over Internet Protocols (VoIP)). The Agency provides 3 case studies portraying how easy users are manipulated, identifies 5 defence measures and issues a check list, ‘LIST’, for users to counter social engineering. Finally, the Whitepaper includes an exclusive interview with the world famous security author, speaker, and consultant Kevin Mitnick.

What are the risks of on-line manipulation, or “Social Engineering”? Fraudsters frequently manipulate people and exploit human weaknesses through ‘social engineering’. That way, people break their normal security procedures. The scale and sophistication of such fraud is increasing, (27.649/month, Jan.’07-Jan ‘08, according to APWG). Several new ways are used to reach users (e.g. instant messaging, VoIP, and social networking sites apart from emails). Successful social engineering entails:

  • A convincing pretext for contacting the target,
  • Getting the facts right by research,
  • Timing and exploitation of current events, e.g., the Tsunami event, or a Santa Claus mail around Christmas, with a worm included.
  • Exploit human behaviour and psychology.

Three e-mail based case studies portray how easy it is to trick ordinary users:

  • Case 1: 179 respondents assessed 20 messages (11 bogus, and 9 legitimate), and only 42% of the users could correctly classify the mails; (32% were classified incorrectly and 26% as ‘do not know’.)
  • Case 2: Of 152 targeted end-users within an organisation, 23% were tricked into accepting malware infections.
  • Case 3: Over 500 undergraduate students followed embedded links, opened attachments, etc. The rate of failure was 38-50%. The good news is that the failure rate was reduced with training.

The Agency identified 5 defence measures against social engineering. However, the key to success lies in improving users’ awareness. Users should use a checklist of questions to verify the Legitimacy, Importance of the Information, the Source and Timing (LIST) (for full checklist see p 25-26 of the report.) Mr Mitnick underpins the report with the claim that it is much easier to trick someone into revealing their password, rather than making an elaborate hack.

The Executive Director of ENISA, Mr. Andrea Pirotti, comments:
Making staff and users aware of security is of serious concern for Europe. We should all become more aware and ‘responsible on-line EU-citizens’, in our own interest of being able to benefit of the Internet safely

The report has been elaborated with the kind support of the ENISA Awareness Raising Community and is available at: http://enisa.europa.eu/doc/pdf/publications/enisa_whitepaper_social_engineering.pdf

Thursday, 2 October 2008

European Digital Library to soon go online

The vision to make available Europe's cultural diversity in books, music, paintings, photographs, and films to all citizens via one single portal could become reality this autumn.

This vision is the driving force behind all efforts for the establishment of the European Digital Library, Europeana, an initiative within the framework of European Commission’s i2010 strategy. This digital library shall serve as single point of access for digital versions of works from cultural institutions all over Europe, including material from museums, libraries and archives abroad, which users will be able to visit without having to travel or turn hundreds of pages to find a piece of information.

According to Viviane Reding, EU Commissioner for Information Society and Media, "The European Digital Library will be a quick and easy way for people to access European books and art – whether in their home country or abroad. It will, for example, enable a Czech student to browse the British library without going to London, or an Irish art lover to get close to the Mona Lisa without queuing at the Louvre."

However, according to the Communication from the Commission of August 2008, further efforts by the EU Member States are needed, on making available digital versions of works from cultural institutions all over Europe. In particular, the vision of a European Digital Library needs substantial investment from national institutions. However, at present most countries only provide small scale, fragmented funding for digitisation. Therefore, The Commission called on Member States to raise digitisation capacities to make their collections available for Europe's citizens, team up with the private sector, and address the following priorities:
  • More funding needs to be allocated to digitisation, along with plans for how much material will be digitised.
  • Most countries still lack methods, technologies and experience for the preservation of digital material, vital so that content remains accessible to future generations.
  • Common standards need to be implemented to make different information sources and databases compatible for and usable by the European Digital Library.

The Commission itself confirmed its commitment to help Member States bring their valuable cultural content online. To this purpose, in 2009-2010 € 69 million from the EU's research programme will go to digitisation activities and the development of digital libraries, while approximately another € 50 million will be allocated by Europe's Competitiveness and Innovation Programme to improve access to Europe's cultural content.

The launch of Europeana is expected to take place in November 2008.

Further information:
Rapid Press release
European Commission’s Communication - Europe’s cultural heritage at the click of a mouse COM(2008) 513
Europeana

From http://www.epractice.eu/document/5068

Wednesday, 1 October 2008

ARMA International's 53rd Annual Conference and Expo in Las Vegas October 20-23

Is the management of electronic records and information keeping you awake at night? Have litigation demands driven you to distraction? Do you wish you had solutions to the information management issues facing your organization? There's only one place to go for help...ARMA International's 53rd Annual Conference and Expo in Las Vegas October 20-23. Yes, this world-renown event is where professionals go for real business solutions, best practices, technology tools and innovative ideas. Professionals like yourself who are
  • Records and information management professionals
  • General and inside counsels
  • Legal administrators
  • RIM and IT consultants
  • CIOs and IT managers

Fact is, if you're involved in managing records and information, this is the place to go to become inspired, educated, connected. You'll get to choose from more than 100 sessions. You'll see the latest technology products and services from 200 of the industry's top providers, including CA, Oracle, IBM, Google, Iron Mountain, and so many more. Plus, you'll be able to meet and talk with an estimated 3,000 colleagues from around the world.You won't find a better opportunity anywhere else. Come for the weekend and play. Or better yet, attend one of the Pre-Conference seminars on Saturday, October 18 and Sunday, October 19. Then prepare yourself, because things really start rockin' and rollin' on Monday.

For more, please visit http://www.arma.org/conference/2008/

Swedes and Dutch best EU broadband performers

Sweden and the Netherlands are the best EU performers when it comes to broadband internet, while Bulgaria and Cyprus come last, according to a report by the European Commission.

"Both countries [Sweden and the Netherlands] have a favourable socio-economic context, with a high propensity to use advanced services and a competitive environment that has ensured affordable prices and high speeds," says the commission in its paper on broadband performance in the EU member states.To measure that performance, Brussels is using a so-called Broadband Performance Index (BPI) based on a series of factors, including speed, rural coverage, affordability, innovation, as well as socio-economic dimensions.

Denmark, the UK, France and non-EU member Norway follow Sweden and The Netherlands, while Poland, Romania, Cyprus and Bulgaria come last.

"Their performance is limited in most dimensions by the socio-economic context and by high prices" in some of the countries, reads the paper.

Poor competition, lack of digital skills and limited PC penetration are among the other cited factors.

On average, some 36 percent of EU households currently enjoy high-speed internet access, although the figures vary widely among the member states.

The commission's aim is "to make broadband Internet for all Europeans happen by 2010," EU telecoms commissioner Viviane Reding stated last week.

Brussels also believes Europe could take the lead in the next internet generation - or Web 3.0 - as it is "already well placed to exploit [the] broadband opportunities, thanks to an open and competitive environment for investments."

"Web 3.0 means seamless 'anytime, anywhere' business, entertainment and social networking over fast reliable and secure networks … Europe has the know-how and the network capacity to lead this transformation," Ms Reding said.

"We must make sure that Web 3.0 is made and used in Europe," she added.
The commission launched a public consultation on Monday (29 September) on its strategy "to respond to the next wave of the Information Revolution" and on the private sector's possible responses to the developing situation.

From: http://euobserver.com/9/26831