Indeed, should we do it? Or are we simply creating false needs that need to be met? Yes, we should. Everything tells us that customers are feeling increasingly confused by the variety of possibilities they face. They may not be worried about calls from a telemarketer, but they feel uncomfortable sharing personal information with strangers. eTRUST and P3 aim to give people control to harness the forces created by technology. Also, you can`t find a name from a phone number or email address. You need to know someone`s name before you can go somewhere. However, this has not always been the case. The company licensed its database to Yahoo! last summer. Yahoo! allowed reverse lookup using Four11 data – creating the most visible and commonly used reverse lookup for phone numbers on the network. Yahoo! released it in April last year, and it quickly became one of the most used features in searching for Yahoo! people. Mike Santullo, CEO of Four11, says he felt uncomfortable with the reverse lookup service, but both parties note that it was extremely popular and didn`t really lead to much trouble.
The anonymization of intermediaries and pseudonyms is insufficient for certain types of transactions. For example, imagine a person who wants to buy software on the Internet. The person may have used a pseudonym in their relationship with the Seller, which allows the Seller to maintain a profile of their preferences and obtain information about the status of their virtual shopping cart. It may also have used an anonymization server when visiting the provider`s website so as not to reveal its network location. But these systems can`t help him transfer money from his bank account to the seller without sharing personal information with the seller. There are no standard training criteria for an ethical hacker, so an organization can set its own requirements for this position. Those interested in a career as an ethical hacker should consider a bachelor`s or master`s degree in infosec, computer science, or even math as a solid foundation. It is important to recognize that the technologies presented here only solve part of the problem. Even the most privacy-friendly information policies can be thwarted if data collectors do not protect their communications and databases. Security measures must be taken to prevent interception of communications and compromise of databases. Companies should develop procedures to protect passwords and prevent employees from accessing data for unauthorized purposes. Data and communications security is an important element of all data protection systems, whether the data in question has been collected via the Internet or by conventional means.
The Internet Privacy Task Force independently responded to the same pressure as eTRUST and was convened by the Center for Democracy and Technology in Washington. The intended “product” is a technical standard called P3 for Platform for Privacy Preferences. The IPWG is in many ways a continuation of the group that developed the PICS6 content labeling standard, and includes many of the same players. Members include America Online, Microsoft, Consumers Union, MCI, Dun & Bradstreet, IBM, AT&T, the Direct Marketers Association, the Electronic Frontier Foundation, eTRUST, the Coalition for Advertising-Supported Information and Entertainment, the National Consumer`s League, the Interactive Services Association and, at least indirectly, members of the World Wide Web Consortium (W3C), which developed PICS and is developing P3. Most browsers are PICS compatible now or soon. In this way, technology can contribute to the development of niche markets in the field of data protection. Privacy groups can use PICS to label websites based on their information practices. A user can contract with an Internet Service Provider (ISP) or website owner to allow different amounts of information about themselves to “come out” based on the fees paid by the user.
This could include (micro)royalty payments to the user in exchange for the use of their data [Laudon 1996]. It is a shame that such a valuable service is abandoned and referred to non-traditional providers. The moral of this story – which is not yet over – is that a little self-regulation or finer control over personal data can actually lead to a situation where information is more readily available. But for now, it`s all or nothing. Without a clear benefit for the customer, little is possible. BCG is therefore trying to understand what consumers are worried about privacy, which is often confused with security. Consumers say they would be much more active online if there was privacy, but what does that mean? Are they afraid that a credit card will be stolen? Do they just want to know what happens to their data, or do they really want to prevent it from spreading? In fact, their answers vary widely – depending on the provider, the type of data and subjectively. How much do they want this loan? Are they in a good mood? Individuals sometimes choose to remain anonymous to protect their privacy, for example, when browsing a department store or buying an “adult magazine.” Internet browsing has also been primarily anonymous activity. When you move from the Web to the Internet in general, you can send anonymous messages using an anonymous remailing program. It is now quite easy for a tech-savvy person to remain anonymous and evade responsibility on the internet for questionable or illegal actions, such as sending advertising emails to many newsgroups (spamming), managing a server, or hacking someone else`s website.
Since work began last year, the eTRUST partnership has gained sponsors/partners who will help cover the start-up costs of the free pilot program. Participants in the pilot with different types of participation include InfoSeek, WorldPages, Firefly, EUnet, Four11, Quarterdeck, CMG Direct Interactive, InterMind, Narrowline, Portland Software, TestDrive, Britnet, Perot Systems, USWeb, Switchboard, Boston Consulting Group, and a variety of other business and other organizations. Two leading accounting firms are also involved in designing the program and validating the website`s privacy statements: Coopers & Lybrand (C&L) and KPMG. Ethical hacking refers to the act of locating vulnerabilities and vulnerabilities in computer and information systems by duplicating the intentions and actions of malicious hackers. It is also known as penetration testing, penetration testing or red teaming. Until now, the approaches discussed here have been aimed at preventing the unwanted disclosure of personal data. Another area where technology can play a role is reducing the ability of individuals and organizations to use personal information to invade an individual`s privacy. Nowadays, many people become aware of the extent to which their personal data is bought and sold when they receive unwanted requests over the phone or mail. Some of these requests have already been received by e-mail. Because sending large amounts of email is so inexpensive, email spam is likely to become a significant problem in the future if preventative measures are not taken. Currently, some ISPs filter emails sent from known addresses to send bulk spam.
However, due to the ease with which junk emails can spoofing sender addresses, it`s probably not a long-term solution to the ever-growing spam problem. Another approach to protecting personal data is to minimize the need to collect such information or minimize the number of times information is accessed. This can be done through trusted intermediaries or technologies designed for this purpose. There are a number of ethical hacking certifications and related computer security certifications that help ethical hackers demonstrate their expertise. Industry certifications include: While the approaches described here facilitate the transparent exchange of information about data collectors` information practices and individuals` privacy preferences, they do not guarantee that data collectors properly disclose their information practices. Independent labeling services can flag bad actors once they`ve been identified, but it can be difficult to spot websites that violate their reported practices. An audit can help a website convince consumers of its good information practices and distinguish it from other websites that may dishonestly report their practices. However, traditional audits are likely to be prohibitive for most website operators. It may be possible to use technology to automate the process of auditing information practices to some extent. For example, systems can be developed to systematically share decoy data with websites and monitor the dissemination of this data. Further work is needed to develop techniques to automate the process of auditing information practices. 1-to-1 Exchange: The Service does not share individual or transactional data with third parties.
Individual usage and transaction data can only be used for the customer`s direct response.



