Storing Too Much Information
[Commentary] How secure is the Internet? It is perhaps less so than many trusting consumers seem to believe. Two recent privacy infractions involving companies with a global brand name should make users sit up and think. They are a reminder that the voracious appetite of Internet firms for data is not always matched by their ability to keep that information secure.
Apple’s decision to embed location-tracking software in its iPhone without flagging this to customers is a good example. While the resulting data helped the company target advertisements through the handsets, it involved both a careless invasion of privacy and lax data protection. Apple did not offer users an explicit opt-out to its obtaining and logging of the information. Having obtained the data it did not store this securely. Worrying in a different way was the hack-in at Sony’s Playstation network, which may have compromised the personal data of 77m gamers. The lure of such a huge stash of information invites attacks even on big companies. Inevitably some may succeed. The cases highlight a larger security problem.
Consumers have few qualms about giving up a great deal of personal information – as they do, wittingly or unwittingly, on mobile devices and social networking sites such as Facebook. Yet while they store ever more information about themselves online, the effort they make to protect this trove of data has not risen commensurately. People often use the same password for many personal accounts, so it is comparatively easy to piece together a lot of information once one has been breached. These traits make consumers vulnerable if the information they supply goes astray. Consumers rely on companies to protect them. But it is not clear that companies, especially social networks, take these vulnerabilities seriously enough.
Storing Too Much Information