150 likes | 249 Views
The Information Technology & Privacy Law Society Presents What are Cookies and Why are they a Threat to Our Privacy ? by Bob Smith Unix Systems Administrator. Cookies. What are they ? How do they work ? The Issue: Pro’s and Con’s Who’s using them ? What can I do about it ?.
E N D
The Information Technology • & • Privacy Law Society • Presents • What are Cookies and Why are they a • Threat to Our Privacy ? • by Bob Smith • Unix Systems Administrator
Cookies • What are they ? • How do they work ? • The Issue: Pro’s and Con’s • Who’s using them ? • What can I do about it ?
What’s a cookie ??? • A cookie is a small piece of information written to the hard drive of an Internet user when he or she visits a website • They’re used by web sites to store information about you on your computer • .barnesandnoble.com TRUE / FALSE 1193255840 userid 2UQEGM4UZN
What’s a cookie ??? Specifications... • 300 total cookies • 4 kilobytes per cookie • 20 cookies per server or domain
What’s a cookie ??? Common Cookie file Contents ... • name of the website • where on the site the user visited • user accounts andpasswords • credit card numbers
How do Cookies Work ? • Sample Browser-Server Cookie transaction ... Client requests a document, and receives in the response: Set-Cookie: CUSTOMER=WILE_E_COYOTE; path=/; expires=Wednesday, 09-Nov-99 23:12:40 GMT Client requests a URL in path "/" on this server, it sends: Cookie: CUSTOMER=WILE_E_COYOTE Client requests a document, and receives in the response: Set-Cookie: PART_NUMBER=ROCKET_LAUNCHER_0001; path=/
What Can I do about it ? ad.doubleclick.net, a different web site than you are currently visiting, would like to read a small file (called a cookie) on your computer. The cookie stores information about your Web visits (for example, to provide targeted ads to you). Click Help below or look up cookies in the Internet Explorer Index for more information. Will you allow the cookie to be read?
Web Bugs, cousins to Internet Cookies • A Web Bug is a graphics on a Web page or in an Email message that is designed to monitor who is reading the Web page or Email message • The code makes it possible to track where a Word document goes when it leaves the author's hands
Medical Records Protection • Nydia Velazquez • Tommy Robinson • As of 1996, 43 states lacked laws criminalizing the release of medical records and no federal law existed Privacy Invasion Privacy Law
Medical Records Protection • Billing records are mailed to Insurance Companies • 50 to 75 people access a patients records during a typical hospital visit • Retailers have access to Pharmacy prescription records - National Data Corp buys a detailed list of every prescription that is filled every day at over 30,000 Pharmacies • Marketing firms are aggressively buying medical records to constructing databases for targeting individual consumers - Metromail’s “Patient Select” database - Contains over 15 million names - Available @ $ .30 / name Scope of the Problem
Medical Records Protection • I authorize any physician, hospital, or other medically related facility, insurance company, or other organization, institution or person, that has any records or knowledge of me, my dependants or our health, to disclose, whenever requested to do so by CAN or its representatives, any and all such information. • Authorizes release of: • tax records • school records/transcripts • bank statements • Enforceable ? The Claim Form
Medical Records Privacy - The MIB • Medical Information Bureau • Referenced in Insurance application forms… • I AUTHORIZE any physician, medical practitioner, hospital, clinic, other medical or medically-related facility, the Medical Information Bureau, Inc., (MIB, Inc.), consumer reporting agency, insurance or re-insuring company, or employer having certain information about me or my dependants to give John Alden Life Insurance Company or it’s legal representative any and all such information. The nature of the information authorized to be disclosed includes information about: (1) physical condition(s), (2) health history(s), (3) avocation(s), (4) age(s), (5) occupation(s), and (6) personal characteristics. This authorization includes information about: (1) drugs, (2) alcoholism, (3) mental illness, or (4) communicable diseases.
Medical Records Protection Database Description AutoCredit Used for approving vehical loans & leases Bankruptcy Computerized models thet predict bankruptcy Business Credit Prescreen Screens mailing lists to find individuals who have a history of paying their bills Business Owner Profile Profiles sole proprieterships Business Profile Produces Credit Reports on Businesses Collection Report Tracks customers who have not paid bills Credit Profile Report Provides consumer credit reports Demographics Band Confirms identities of people not in databases Experian Segmentation System Divides a list of customers/prospects into smaller group segments basd on lifestyle, behavior, wealth, etc… INSOURCE Enhances mailing lists with demographics, property records, motor vehicle listings, answers to surveys, etc… Intelliscore Performs predictive credit risk assessment on small businesses Platelink Links license plates to consumer information Property Link Detailed info on a customer’s property holdings