Computerworld
Customer information vulnerable in the hands of corporates
Legislation playing catch up with technology
Darren Pauli  31 March, 2008 15:31

Privacy agreements are being scrapped as fingerprints, iris scans and voiceprints are at risk of being hocked off through business acquisitions.

Industry experts said biometric privacy agreements can be made void once businesses collecting the data are acquired.

Experts also attacked the security measures used to protect biometric data, and said encryption techniques often touted as infallible are rarely used.

Speaking at the Asia Pacific Aviation and Airport Security Summit in Sydney, Australian Biometrics Institute technical committee member Suzanna Lockhart said biometric data is treated as a commodity in private enterprise.

"Biometric data is sold along with the business in acquisitions, and they can then do what they want with it," Lockhart said.

"Private enterprise is much faster [to deploy biometrics] than the government.

"They are less responsible with data than government agencies and do not put the same effort into research and planning.

Lockhart said biometric systems should be designed around customer values, collect only relevant data, and demonstrate a minimum level of reliability.

She said flashy biometric systems will falter if they lack simple features like fall-back mechanisms for disabled customers, or data collection rules to facilitate legal requirements such as compliance audits.

NSW Council of Civil Liberties president Cameron Murphy said regulation is moving too slow to protect customer rights and urged businesses to sign the industry-formed Biometrics Institute Privacy Code.

"Legislation is playing catch-up with biometric technology and the vendors are flying ahead [with biometric development] without any concern for privacy implications," Murphy said.

"It reflects badly on how important privacy is to the industry and will result in a lack of public confidence when it is time for them to give up their information when adopting biometrics."

Murphy said biometric data is vulnerable to function creep where businesses surrender information to law enforcement or use it for marketing campaigns.

Biometrics will be included in upcoming reforms to the Privacy Act under new powers given to the Privacy Commissioner to amend legislation.

A security consultant who requested anonymity said biometric data is vulnerable in the hands of the private sector because there is no minimum security standard.

"They all say their biometric data is untouchable but they aren't as secure as they say," he said.

"You don't get the best security overnight; biometrics in a business with poor security will remain unprotected just like everything else."

He said biometric data such as voice prints should be encrypted and stored in a statistical format, rather than as a more vulnerable audio file.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about IRIS, ACT

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

Wireless LANs: Is My Enterprise At Risk?

This paper details the risks associated with wireless LANs, and offers an overview of the inherent properties of wireless LANs and differences from wired networks. Read about real-life breaches and incidents and strengthen your own defence.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.