<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>jmones, outdoors</title>
	<atom:link href="http://outdoors.jmones.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://outdoors.jmones.net</link>
	<description>Technology, business, smart cards, information security</description>
	<lastBuildDate>Wed, 29 Dec 2010 15:30:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.1</generator>
		<item>
		<title>Conclusion document on privacy 2.0</title>
		<link>http://outdoors.jmones.net/2010/12/29/conclusion-document-on-privacy-2-0/</link>
		<comments>http://outdoors.jmones.net/2010/12/29/conclusion-document-on-privacy-2-0/#comments</comments>
		<pubDate>Wed, 29 Dec 2010 15:06:19 +0000</pubDate>
		<dc:creator>jmones</dc:creator>
				<category><![CDATA[Briefs]]></category>
		<category><![CDATA[7th Conference on Electronic Signature]]></category>
		<category><![CDATA[CATCert]]></category>
		<category><![CDATA[Collaborative work]]></category>
		<category><![CDATA[Conclusion document]]></category>
		<category><![CDATA[Generalitat de Catalunya]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Jordi Graells]]></category>
		<category><![CDATA[Law enforcement]]></category>
		<category><![CDATA[Marc Garriga]]></category>
		<category><![CDATA[Núria Vives]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy 2.0]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://outdoors.jmones.net/?p=191</guid>
		<description><![CDATA[As I introduced in a previous post Privacy and security, 7th Conference on Electronic Signature triggered a debate on privacy and security. Núria Vives, Marc Garriga and Jordi Graells have prepared a conclusion document which embodies 186 comments from 46 different people. This document tries to be useful. As such, it forgets shining abstractions and [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://outdoors.jmones.net/wp-content/uploads/2010/11/hand_pen_document.jpg" alt="Document" title="Document" width="250" height="166" class="alignleft size-full wp-image-196" />As I introduced in a previous post <a href="http://outdoors.jmones.net/2010/11/29/privacy-and-security/">Privacy and security</a>, <a href="http://www.js-e-bloc.cat/" onclick="pageTracker._trackPageview('/outgoing/www.js-e-bloc.cat/?referer=');">7th Conference on Electronic Signature</a> triggered a debate on privacy and security. Núria Vives, Marc Garriga and Jordi Graells have prepared a <a href="http://graells.wordpress.com/2010/12/27/post-col%c2%b7laboratiu-de-46-persones-conclusions-i-accions-sobre-privacitat-2-0/" onclick="pageTracker._trackPageview('/outgoing/graells.wordpress.com/2010/12/27/post-col_c2_b7laboratiu-de-46-persones-conclusions-i-accions-sobre-privacitat-2-0/?referer=');">conclusion document</a> which embodies 186 comments from 46 different people. This document tries to be useful. As such, it forgets shining abstractions and depicts a list of measures to be implemented by the Administration instead. To all that have been involved in it: thank you.</p>
<h4>Media</h4>
<p><a href="http://www.flickr.com/photos/46632302@N06/4279477491/" onclick="pageTracker._trackPageview('/outgoing/www.flickr.com/photos/46632302_N06/4279477491/?referer=');">Maleís hand writing in the document</a> by <a href="http://www.flickr.com/photos/46632302@N06/" onclick="pageTracker._trackPageview('/outgoing/www.flickr.com/photos/46632302_N06/?referer=');">Damon Duncan</a> licensed <a href="http://creativecommons.org/licenses/by-nc-nd/2.0/deed.en" onclick="pageTracker._trackPageview('/outgoing/creativecommons.org/licenses/by-nc-nd/2.0/deed.en?referer=');">Attribution-NonCommercial-NoDerivs 2.0 Generic</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://outdoors.jmones.net/2010/12/29/conclusion-document-on-privacy-2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Letter to the Editor</title>
		<link>http://outdoors.jmones.net/2010/11/29/letter-to-the-editor/</link>
		<comments>http://outdoors.jmones.net/2010/11/29/letter-to-the-editor/#comments</comments>
		<pubDate>Mon, 29 Nov 2010 18:07:29 +0000</pubDate>
		<dc:creator>jmones</dc:creator>
				<category><![CDATA[Awareness Raising]]></category>
		<category><![CDATA[Ara]]></category>
		<category><![CDATA[EMV]]></category>
		<category><![CDATA[ENISA]]></category>
		<category><![CDATA[Letter]]></category>
		<category><![CDATA[PIN]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Smart Cards]]></category>

		<guid isPermaLink="false">http://outdoors.jmones.net/?p=131</guid>
		<description><![CDATA[Ara is a newborn (crossmedia) newspaper written in Catalan. Its first issue was published just yesterday. Interestingly it contained a letter to the editor about EMV cards in which a confused reader argued they were less secure than magnetic stripe cards! As a ENISA Awareness Raising (AR) Community expert, I couldn&#8217;t leave this poor citizen [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://ara.cat/" onclick="pageTracker._trackPageview('/outgoing/ara.cat/?referer=');">Ara</a> is a newborn (crossmedia) newspaper written in Catalan. Its first issue was published just yesterday. Interestingly it contained a letter to the editor about EMV cards in which a confused reader argued they were less secure than magnetic stripe cards!</p>
<p>As a <a href="http://www.enisa.europa.eu/act/ar" onclick="pageTracker._trackPageview('/outgoing/www.enisa.europa.eu/act/ar?referer=');">ENISA Awareness Raising (AR) Community expert</a>, I couldn&#8217;t leave this poor citizen in such a misconception. <img src='http://outdoors.jmones.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>This is my response to this reader (in Catalan) which was published just today, in the second issue of Ara.</p>
<p><img src="http://outdoors.jmones.net/wp-content/uploads/2010/11/carta_ara_targetes_segures.jpg" alt="Letter to the editor of Ara newspaper on EMV cards PIN" title="Letter to the editor of Ara newspaper on EMV cards PIN" width="400" height="486" class="aligncenter size-full wp-image-134" /></p>
]]></content:encoded>
			<wfw:commentRss>http://outdoors.jmones.net/2010/11/29/letter-to-the-editor/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Privacy and security</title>
		<link>http://outdoors.jmones.net/2010/11/29/privacy-and-security/</link>
		<comments>http://outdoors.jmones.net/2010/11/29/privacy-and-security/#comments</comments>
		<pubDate>Mon, 29 Nov 2010 10:27:17 +0000</pubDate>
		<dc:creator>jmones</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[7th Conference on Electronic Signature]]></category>
		<category><![CDATA[Bruce Schneier]]></category>
		<category><![CDATA[CATCert]]></category>
		<category><![CDATA[Daniel Solove]]></category>
		<category><![CDATA[Eric Schmidt]]></category>
		<category><![CDATA[Generalitat de Catalunya]]></category>
		<category><![CDATA[Human Rights]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Jordi Graells]]></category>
		<category><![CDATA[Law enforcement]]></category>
		<category><![CDATA[Lawrence Lessig]]></category>
		<category><![CDATA[Nothing to hide]]></category>
		<category><![CDATA[PET]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy 2.0]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://outdoors.jmones.net/?p=76</guid>
		<description><![CDATA[Last October CATCert, Catalan Certification Agency, held in Barcelona the 7th Conference on Electronic Signature. Jordi Graells, from Citizen Service Office in the Catalan&#8217;s Government, was one of the speakers. He subsequently published a blog post called &#8220;Privacy 2.0&#8243; (in Catalan) that has generated a lot of debate. Internet was born without a built-in identity [...]]]></description>
			<content:encoded><![CDATA[<p>Last October <a href="http://www.catcert.cat" onclick="pageTracker._trackPageview('/outgoing/www.catcert.cat?referer=');">CATCert</a>, Catalan Certification Agency, held in Barcelona the <a href="http://www.js-e-bloc.cat/" onclick="pageTracker._trackPageview('/outgoing/www.js-e-bloc.cat/?referer=');">7th Conference on Electronic Signature</a>. Jordi Graells, from Citizen Service Office in the Catalan&#8217;s Government, was one of the speakers. He subsequently published a blog post called <a href="http://graells.wordpress.com/2010/10/28/privacitat-2-0-7es-jornades-de-signatura-electronica/" onclick="pageTracker._trackPageview('/outgoing/graells.wordpress.com/2010/10/28/privacitat-2-0-7es-jornades-de-signatura-electronica/?referer=');">&#8220;Privacy 2.0&#8243;</a> (in Catalan) that has generated a lot of debate.</p>
<p>Internet was born without a built-in identity layer. Despite this and the sense of anonymity that users perceive as a result of it, users are not anonymous at all in the Internet. Identity information is leaked in every connection and service we use. Our identity is traceable from our IP or by analyzing the data we supply to Internet sites or even by analysing our surfing pattern. As users, we must assume that data uploaded to the Internet might become public at anytime and that, once published, there&#8217;s no way to <em>unpublish</em> it.</p>
<p>However, from a law enforcement point of view, Internet is a rough place. Despite all this identity information leaks, it is difficult to identify people responsible of a crime on the Internet. If we want to be able to prosecute criminals using current available identity information, we must accept that we may make mistakes identifying them. Nobody wants that, so officials ask for an identity layer in the Internet.</p>
<p>This debate, which not only belongs to the Internet world, has often been characterized as a privacy versus security trade-off. Not everyone agrees: security expert Bruce Schneier, for instance, thinks that <a href="http://www.schneier.com/blog/archives/2008/01/security_vs_pri.html" onclick="pageTracker._trackPageview('/outgoing/www.schneier.com/blog/archives/2008/01/security_vs_pri.html?referer=');">considering it as a trade-off is a fallacy</a>. Schneier&#8217;s point is that, for each threat, there are options in the countermeasures to be taken to deal with it, and that some of them will not be privacy-invasive.</p>
<p>In my opinion it isn&#8217;t always possible to find solutions to security problems that preserve privacy. At the same time, I think it&#8217;s true that, from all the possible options, privacy-invasive solutions are often taken. Perhaps this is because measures are taken without a good analysis, or perhaps because the security problem, as explained, is only an excuse to implement a pre-taken measure. The truth is that we can improve that.</p>
<p>Additionally to the problem of privacy loss to security officials, nowadays we face a massive privacy loss problem due to data we or our friends upload to multiple services. All this information can be and is used in several ways, sometimes in our benefit, but often irrespectfully and, even more, illegally. Some have tried to downplay its importance using the &#8220;nothing to hide, nothing to fear&#8221; argument, <a href="http://gawker.com/5419271/google-ceo-secrets-are-for-filthy-people" onclick="pageTracker._trackPageview('/outgoing/gawker.com/5419271/google-ceo-secrets-are-for-filthy-people?referer=');">even people as intellectually capable as Google&#8217;s CEO Eric Schmidt</a>. Daniel Solove, George Washington University Law School professor, has a good refutation on this fallacy that is a must-read: an essay called <a href="http://www.tdistler.com/media/docs/privacyandnothingtohide.pdf" onclick="pageTracker._trackPageview('/outgoing/www.tdistler.com/media/docs/privacyandnothingtohide.pdf?referer=');">&#8220;‘I’ve nothing to hide’ and other misunderstandings of privacy&#8221;</a>. We must not forget that privacy is a right recognized by <a href="http://www.un.org/en/documents/udhr/index.shtml#a12" onclick="pageTracker._trackPageview('/outgoing/www.un.org/en/documents/udhr/index.shtml_a12?referer=');">The Universal Declaration of Human Rights, article 12</a>.</p>
<blockquote><p><strong>Article 12</strong></p>
<p>No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.</p></blockquote>
<p>So, from my point of view, we need to find the proper balance between preserving privacy and linking user actions to identity information. We may need to keep some data to do this, but we should put some barriers so that this data is not misused, perhaps by not making it available to a single entity or by raising the cost/time of using it. We must make use of privacy-enhancing technologies (PET), be creative and, most importantly, make careful decisions on best countermeasures to handle each security problem.</p>
<p>To close this post, this is a talk by Lawrence Lessig given at Accenture about the need for an identity layer in the Internet. Take your time because it&#8217;s a long video. Note this video is licensed under a <a href="http://creativecommons.org/licenses/by/3.0/" onclick="pageTracker._trackPageview('/outgoing/creativecommons.org/licenses/by/3.0/?referer=');">Creative Commons Attribution 3.0 Unported license</a>.</p>
<div style="text-align: center;">
<embed src="http://lessig.blip.tv/play/lG372wMC" type="application/x-shockwave-flash" width="480" height="390" allowscriptaccess="always" allowfullscreen="true"></embed>
</div>
<h4>References</h4>
<p>CATCert (2010) CATCert &#8211; Agència Catalana de Certificació [online], <a href="http://catcert.cat" onclick="pageTracker._trackPageview('/outgoing/catcert.cat?referer=');">http://catcert.cat</a><br />
CATCert (2010) <a href="http://www.js-e.cat/site/eng/index.htm" onclick="pageTracker._trackPageview('/outgoing/www.js-e.cat/site/eng/index.htm?referer=');">The 7th Electronic Signature Congress</a><br />
Graells, J. (2010) <a href="http://graells.wordpress.com/2010/10/28/privacitat-2-0-7es-jornades-de-signatura-electronica/" onclick="pageTracker._trackPageview('/outgoing/graells.wordpress.com/2010/10/28/privacitat-2-0-7es-jornades-de-signatura-electronica/?referer=');">&#8220;Privacitat 2.0&#8243;</a>, Graellsbloc, 28 October<br />
Schneier, B (2008) <a href="http://www.schneier.com/blog/archives/2008/01/security_vs_pri.html" onclick="pageTracker._trackPageview('/outgoing/www.schneier.com/blog/archives/2008/01/security_vs_pri.html?referer=');">Security vs. Privacy</a><br />
Solove, D. (2007) <a href="http://www.tdistler.com/media/docs/privacyandnothingtohide.pdf" onclick="pageTracker._trackPageview('/outgoing/www.tdistler.com/media/docs/privacyandnothingtohide.pdf?referer=');">&#8220;‘I’ve nothing to hide’ and other misunderstandings of privacy&#8221;</a>, San Diego Law Review, Vol. 44, p. 745, 2007<br />
Tate, R. (2009) <a href="http://gawker.com/5419271/google-ceo-secrets-are-for-filthy-people" onclick="pageTracker._trackPageview('/outgoing/gawker.com/5419271/google-ceo-secrets-are-for-filthy-people?referer=');">Google CEO: Secrets Are for Filthy People</a>, Gawker<br />
United Nations General Assembly (1948), <a href="http://www.un.org/en/documents/udhr/index.shtml" onclick="pageTracker._trackPageview('/outgoing/www.un.org/en/documents/udhr/index.shtml?referer=');">The Universal Declaration of Human Rights</a></p>
]]></content:encoded>
			<wfw:commentRss>http://outdoors.jmones.net/2010/11/29/privacy-and-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Warming up engines</title>
		<link>http://outdoors.jmones.net/2010/03/26/warming-up-engines/</link>
		<comments>http://outdoors.jmones.net/2010/03/26/warming-up-engines/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 00:11:28 +0000</pubDate>
		<dc:creator>jmones</dc:creator>
				<category><![CDATA[Meta]]></category>

		<guid isPermaLink="false">http://outdoors.jmones.net/?p=5</guid>
		<description><![CDATA[Welcome to the header of my bit stream related to anything I have fun with at work. At this moment I don&#8217;t know if I&#8217;ll zoom in to information security and smart cards or out to technology and business. Will it be news? Opinion? Neither do I know if I&#8217;ll post once a week or [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome to the header of my bit stream related to anything I have fun with at <a title="Idoneum Electronic Identity" href="http://www.idoneum.net" onclick="pageTracker._trackPageview('/outgoing/www.idoneum.net?referer=');">work</a>. At this moment I don&#8217;t know if I&#8217;ll zoom in to information security and smart cards or out to technology and business. Will it be news? Opinion? Neither do I know if I&#8217;ll post once a week or every month. I begin in English and may well end in Python. I just hope that after first ups-and-downs, it stays.</p>
<p>There&#8217;s a chance that I know you personally, and perhaps I tend to have you in my <a href="http://www.facebook.com/jmones" onclick="pageTracker._trackPageview('/outgoing/www.facebook.com/jmones?referer=');">Facebook</a> but not in my <a href="http://es.linkedin.com/in/jmones" onclick="pageTracker._trackPageview('/outgoing/es.linkedin.com/in/jmones?referer=');">LinkedIn</a>. In this case you may prefer to go <a href="http://indoors.jmones.net" onclick="pageTracker._trackPageview('/outgoing/indoors.jmones.net?referer=');">indoors</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://outdoors.jmones.net/2010/03/26/warming-up-engines/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

