Singapore Government need to do more on Data Privacy
For some time, I am concerned about data privacy in Singapore. Unlike in UK where I lived for 7 years, there seems to be a disregard by corporations with regards to data privacy of the consumers or users of any form of service. Recently, I was so fed up with some banks calling me to take on additional credit (which I have no interest nor intention to take on) that I requested to get my name off their calling list. Sometimes, I wonder where they got my information from (and not likely from Facebook since I set tight privacy controls). Here is the more interesting news I heard from a friend recently about how easy security lapses happen in websites.
Here's the problem: Using Google search, you can find the user name and password of a system administrator of an educational institution (say, a secondary school). Consequently, a spammer armed with such information can easily manipulate the server to send spam messages. The problem is that we have no even reached the realm of hacking, spyware or virus to get such information leakage. I am glad that there is a Singapore Security Meetup Group (SSMG) to perform such tests to show how little effort most organizations and corporations spent on dealing with information leakages. If you find any security lapses with organizations leaking data, you can go to this website (Because i Matter - a Singaporean-based site on getting people to report on security using a Ning social network) to report it.
In fact, I just read today that NUS has beef up their security because of their alumni data lost. I think that it's important for the government start looking into protection of users' privacy with better enterprise security solutions.
Here is what I think that the Singapore Government need to do more about:
* Giving Singaporeans a method to be unsubscribe from the telemarketers' list. In the US, you can register your number onto a list where you are free from being spammed by telemarketers.
* Protecting information leakages in our government agencies and educational institutions. At least, do not allow files about particulars of users being accessed from a Google search.
http://forums.delphiforums.com/sunkopitiam/messages?msg=27436.1
Friday, April 17, 2009
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment