<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>T3 Blog (Entries tagged as privacy)</title>
    <link>http://t3technet.com/blog/</link>
    <description>Rants, Informations, &amp; Things Probably Best Left Unsaid</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2 - http://www.s9y.org/</generator>
    <pubDate>Sun, 16 Dec 2007 05:35:56 GMT</pubDate>

    <image>
        <url>http://t3technet.com/blog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: T3 Blog - Rants, Informations, &amp; Things Probably Best Left Unsaid</title>
        <link>http://t3technet.com/blog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Happy Bill of Rights Day</title>
    <link>http://t3technet.com/blog/index.php?/archives/9-Happy-Bill-of-Rights-Day.html</link>
    
    <comments>http://t3technet.com/blog/index.php?/archives/9-Happy-Bill-of-Rights-Day.html#comments</comments>
    <wfw:comment>http://t3technet.com/blog/wfwcomment.php?cid=9</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://t3technet.com/blog/rss.php?version=2.0&amp;type=comments&amp;cid=9</wfw:commentRss>
    

    <author>nospam@example.com (Tom Johnson)</author>
    <content:encoded>
    The Bill of Rights was ratified on this day in 1791. Arguably the Founders should have been more specific in certain regards, but the Ninth and Tenth Amendments &lt;strong&gt;&lt;em&gt;should&lt;/em&gt;&lt;/strong&gt; have cleared up any questions. However, these Amendments have been pretty well disregarded as not having any effect or bearing on anything, and most of the others have been manipulated to have little effect as well.&lt;br /&gt;
&lt;br /&gt;
For more on the Bill of Rights and its celebration visit these links:&lt;br /&gt;
&lt;a href=&quot;http://billofrightsinstitute.org/borday/&quot; title=&quot;http://billofrightsinstitute.org/borday/&quot;&gt;http://billofrightsinstitute.org/borday/&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.jpfo.org/smith/smith-bor-07.htm&quot;&gt;http://www.jpfo.org/smith/smith-bor-07.htm&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.lewrockwell.com/gregory/gregory49.html&quot;&gt;http://www.lewrockwell.com/gregory/gregory49.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Surprisingly, the President has even &lt;a href=&quot;http://www.whitehouse.gov/news/releases/2007/12/20071206-10.html&quot;&gt;issued a proclamation&lt;/a&gt;.&lt;br /&gt;
I say surprisingly as the Bill of Rights seems to be largely ignored and chipped away by the fed.gov in general. &lt;br /&gt;
&lt;br /&gt;
Hopefully this trend reverses.&lt;br /&gt;
&lt;br /&gt;
&quot;Those who make peaceful revolution impossible will make violent revolution inevitable.&quot;   --  John F. Kennedy 
    </content:encoded>

    <pubDate>Sat, 15 Dec 2007 22:35:56 -0700</pubDate>
    <guid isPermaLink="false">http://t3technet.com/blog/index.php?/archives/9-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license><category>government</category>
<category>news</category>
<category>politics</category>
<category>privacy</category>

</item>
<item>
    <title>Hushmail not secure as advertised</title>
    <link>http://t3technet.com/blog/index.php?/archives/6-Hushmail-not-secure-as-advertised.html</link>
            <category>Security &amp; Privacy</category>
    
    <comments>http://t3technet.com/blog/index.php?/archives/6-Hushmail-not-secure-as-advertised.html#comments</comments>
    <wfw:comment>http://t3technet.com/blog/wfwcomment.php?cid=6</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://t3technet.com/blog/rss.php?version=2.0&amp;type=comments&amp;cid=6</wfw:commentRss>
    

    <author>nospam@example.com (Tom Johnson)</author>
    <content:encoded>
    This just came to my attention. I don&#039;t keep as up to date with Slashdot news as I used to. &lt;img src=&quot;http://t3technet.com/blog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.itnews.com.au/News/65213,hushmail-turns-out-to-be-anything-but.aspx&quot; title=&quot;http://www.itnews.com.au/News/65213,hushmail-turns-out-to-be-anything-but.aspx&quot;&gt;http://www.itnews.com.au/News/65213,hushmail-turns-out-to-be-anything-but.aspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Hushmail uses PGP encyption but apparently what allowed such a thing to become a news issue is in the way their system works, and the fact that a court order was involved.&lt;br /&gt;
&lt;br /&gt;
Phil Zimmerman defends Hushmail in their actions, see: &lt;a href=&quot;http://blog.wired.com/27bstroke6/2007/11/pgp-creator-def.html&quot; title=&quot;http://blog.wired.com/27bstroke6/2007/11/pgp-creator-def.html&quot;&gt;http://blog.wired.com/27bstroke6/2007/11/pgp-creator-def.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
This also does not indicate a vulnerability in PGP. I have seen it stated that Hushmail had the private keys which enabled the snooping and that the Java process used puts the correspondence to the server side in unencrytped form. I don&#039;t know really what process allowed it, but one would think that any implementation of PGP that was not fully in control of the user could be compromised in a way such as this. 
    </content:encoded>

    <pubDate>Fri, 30 Nov 2007 20:14:40 -0700</pubDate>
    <guid isPermaLink="false">http://t3technet.com/blog/index.php?/archives/6-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license><category>pgp</category>
<category>privacy</category>
<category>security</category>
<category>security &amp; privacy</category>

</item>
<item>
    <title>Using PGP (or some similar method) for private, secure, trusted ID's</title>
    <link>http://t3technet.com/blog/index.php?/archives/3-Using-PGP-or-some-similar-method-for-private,-secure,-trusted-IDs.html</link>
            <category>Security &amp; Privacy</category>
    
    <comments>http://t3technet.com/blog/index.php?/archives/3-Using-PGP-or-some-similar-method-for-private,-secure,-trusted-IDs.html#comments</comments>
    <wfw:comment>http://t3technet.com/blog/wfwcomment.php?cid=3</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://t3technet.com/blog/rss.php?version=2.0&amp;type=comments&amp;cid=3</wfw:commentRss>
    

    <author>nospam@example.com (Tom Johnson)</author>
    <content:encoded>
    I actually started thinking about this sort of thing about a week or two ago and a post on the &lt;a href=&quot;http://www.mdshooters.com&quot; title=&quot;Maryland Shooter&#039;s Forum&quot;&gt;Maryland Shooter&#039;s Forum&lt;/a&gt; about the proposed Real ID and RFID &lt;a href=&quot;http://www.dhs.gov/xprevprot/laws/gc_1172767635686.shtm&quot; title=&quot;Real Id proposed guidelines&quot;&gt;guidelines&lt;/a&gt; brought it up again.&lt;br /&gt;
&lt;br /&gt;
I was thinking of keeping this hush and actually developing a system for this and obtaining relevant patents. However, searching through patents and the whole application process can be rather costly and consuming, not to mention the difficulties in enforcing patents. Besides, I tend to agree with the philosophies of Open Source Software and Creative Commons licensing of works. There&#039;s some discussion on this over at the &lt;a href=&quot;http://www.instructables.com/forum/EEMFZXN1G5EXCFLKHF/&quot; title=&quot;instructables.com forums&quot;&gt;instructables.com forums&lt;/a&gt; that covers this topic as it relates to patentable works. So since I&#039;ve posted my idea to the MD Shooter&#039;s forum, I figure I&#039;ll also post it here with some more details.&lt;br /&gt;
&lt;br /&gt;
Based on my brief research I have concluded that this is overall an original idea, though pieces, or general concepts, may have been previously proposed. So, if this idea, in whole or in part, is stolen and shows up on the market before I get around to fully developing it and selling/marketing it myself, I expect to be credited, consulted and receive fair compensation. I still have the opportunity to apply for patents and if anyone sees any of this in a patent application let me know. &lt;img src=&quot;http://t3technet.com/blog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt; In the recent past I had an idea that I believe very well may have been stolen from me which I&#039;ll get into another time.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;On with the show...&lt;/strong&gt;&lt;br /&gt;
Some of this is related to security/privacy policy which I think should be implemented regardless, but the system would require it.&lt;br /&gt;
&lt;br /&gt;
All databases are to be devoid of personal identifying information.&lt;br /&gt;
There may be certain exceptions to this based on reasonably justified need, but any personal ID information should be kept out of all database systems to the greatest extent possible such that it cannot be used for things such as ID theft or other nefarious purposes. This would make the data relatively useless if compromised by crackers or to any unscrupulous employee or other person that normally is allowed access to the data.&lt;br /&gt;
&lt;br /&gt;
I&#039;ll go off on a little side tangent here and throw in that SSN&#039;s should only be found in databases at the SSA, they don&#039;t belong anywhere else (well the IRS hijacked SSN&#039;s as TIN&#039;s but that&#039;s another story), &lt;a href=&quot;http://www.cpsr.org/issues/privacy/SSNAddendum#NewDBs&quot; title=&quot;Why SSNs Make Bad Keys in Databases&quot;&gt;they make bad database keys&lt;/a&gt;, and are completely useless and unreliable for identification purposes (it even says so right on the card). I&#039;ll leave my arguments and opinions on why SS shouldn&#039;t exist at all for another time. The misuse of SSN&#039;s by companies and, probably to a lesser extent due to pertinent laws, government agencies has become so common that now it&#039;s finally being realized how vulnerable to abuse this practice is. For too many reasons, an SSN cannot be trusted for verifying or authenticating a person&#039;s ID. &lt;br /&gt;
&lt;br /&gt;
In place of this should be something like a PGP public key. The only way to get the personal info is directly from the individual. An alternative is to encrypt the stored data with the public PGP key, but this could make for some messy and/or more resource intensive database systems.&lt;br /&gt;
&lt;br /&gt;
The individual whose personal information is stored controls their own personal ID information and decides who can access what pieces of it.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;How it Works&lt;/strong&gt;&lt;br /&gt;
The system requests the info from say an RFID chip (I&#039;m not sure these would really be suitable for this application, but possibly as RFIDsec has come up with secure RFID devices with privacy features which I haven&#039;t fully looked into).&lt;br /&gt;
My first thoughts were of something like a USB memory stick, such as the &lt;a href=&quot;http://www.securestix.co.uk/&quot; title=&quot;SecureStix&quot;&gt;SecureStix&lt;/a&gt;, (&lt;a href=&quot;http://www.f-secure.com/weblog/archives/archive-082007.html#00001263&quot; title=&quot;Sony USB stick insecurites at F-Secure blog &quot;&gt;but not a Sony product&lt;/a&gt;) with a fingerprint reader to represent the passphrase for the private key, though something a little more sophisticated may be necessary.&lt;br /&gt;
&lt;br /&gt;
Anyway, the request is encrypted with the public key on file and signed with the requester&#039;s key, the individual accepts the request with their passphrase (fingerprint?) and the allowed data for that particular requester is provided to them encrypted with their public key and signed by the individual&#039;s key. The pertinent data shows up on the requester&#039;s screen but does not get stored in any way. This could still potentially be abused, I haven&#039;t thought through all of the details far enough yet, but the system would work something like this. Maybe some reliable auditing certification could be part of ensuring that the ID data is secure, but it should be possible to do this within the program. It would have to verify that the OS isn&#039;t compromised in such a way as to allow for grabbing the data as it&#039;s routed from post-decryption to the video display. Hmmm... there&#039;s of course other issues as well.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Trust of the ID&lt;/strong&gt;&lt;br /&gt;
As long as the individual&#039;s key is signed by some acceptable authority it is considered to be trusted valid information (ie. the person is who they say they are), no need to worry about what two or three forms of ID are acceptable for which entity that requires ID because the ID info for that key has already been verified either by that entity itself or a valid third party (eg. the local courthouse, state police, State Dept., etc.). Additionally, the key/passphrase info is &lt;em&gt;almost&lt;/em&gt; impossible to forge and the primary ID (ie. name) is tied to the PGP key and cannot be changed. Some good info on PGP and the web of trust theory, which I haven&#039;t bothered to get into, can be found at &lt;a href=&quot;http://www.rossde.com/PGP/&quot; title=&quot;David Ross&#039;s PGP pages&quot;&gt;David Ross&#039;s site&lt;/a&gt; and of course at &lt;a href=&quot;http://www.gnupg.org/&quot; title=&quot;GNU PGP&quot;&gt;GNUPG&lt;/a&gt; and PGP.com.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are still some points that need a little work in this idea, and the .gov would probably never adopt such a system fully without it&#039;s own exceptions (there&#039;s still too many control-freak--nanny-state--power-trip politicians in office), but with wide usage it could certainly cut down, or eliminate for the most part, ID theft, and many other crimes which are facilitated by the improper use of personal data. Plus maybe it could restore some sense of privacy and security in a world where there isn&#039;t much left without removing oneself from at least most of civilization and technology.&lt;br /&gt;
&lt;br /&gt;
Maybe I&#039;ve watched &quot;The Net,&quot; &quot;Enemy of The State,&quot; and similar movies too many times, or maybe I&#039;ve just been involved in computer networking and security too long. 
    </content:encoded>

    <pubDate>Tue, 27 Nov 2007 02:23:00 -0700</pubDate>
    <guid isPermaLink="false">http://t3technet.com/blog/index.php?/archives/3-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/2.5/</creativeCommons:license><category>privacy</category>
<category>security</category>
<category>security &amp; privacy</category>

</item>

</channel>
</rss>