Tuesday | 14 October, 2008
Computerworld
Customer information vulnerable in the hands of corporates
Legislation playing catch up with technology
Darren Pauli 31/03/2008 14:31:04

Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Privacy agreements are being scrapped as fingerprints, iris scans and voiceprints are at risk of being hocked off through business acquisitions.

Industry experts said biometric privacy agreements can be made void once businesses collecting the data are acquired.

Experts also attacked the security measures used to protect biometric data, and said encryption techniques often touted as infallible are rarely used.

Speaking at the Asia Pacific Aviation and Airport Security Summit in Sydney, Australian Biometrics Institute technical committee member Suzanna Lockhart said biometric data is treated as a commodity in private enterprise.

"Biometric data is sold along with the business in acquisitions, and they can then do what they want with it," Lockhart said.

"Private enterprise is much faster [to deploy biometrics] than the government.

"They are less responsible with data than government agencies and do not put the same effort into research and planning.

Lockhart said biometric systems should be designed around customer values, collect only relevant data, and demonstrate a minimum level of reliability.

She said flashy biometric systems will falter if they lack simple features like fall-back mechanisms for disabled customers, or data collection rules to facilitate legal requirements such as compliance audits.

NSW Council of Civil Liberties president Cameron Murphy said regulation is moving too slow to protect customer rights and urged businesses to sign the industry-formed Biometrics Institute Privacy Code.

"Legislation is playing catch-up with biometric technology and the vendors are flying ahead [with biometric development] without any concern for privacy implications," Murphy said.

"It reflects badly on how important privacy is to the industry and will result in a lack of public confidence when it is time for them to give up their information when adopting biometrics."

Murphy said biometric data is vulnerable to function creep where businesses surrender information to law enforcement or use it for marketing campaigns.

Biometrics will be included in upcoming reforms to the Privacy Act under new powers given to the Privacy Commissioner to amend legislation.

A security consultant who requested anonymity said biometric data is vulnerable in the hands of the private sector because there is no minimum security standard.

"They all say their biometric data is untouchable but they aren't as secure as they say," he said.

"You don't get the best security overnight; biometrics in a business with poor security will remain unprotected just like everything else."

He said biometric data such as voice prints should be encrypted and stored in a statistical format, rather than as a more vulnerable audio file.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about ACT, IRIS
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Email Archiving 101—Customer Case Study

Join Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links