Helping you organise and protect your personal information

Saturday, June 25, 2011

Google to retire Google Health

It was interesting to hear today that Google has decided to close down it’s Google Health service. This service was set to be a great service to individuals that wanted to create an online health record and to get advice online that would help them manage their health.

There has been much discussion over the last few years regarding what Google’s motivation was in creating such a service, with many leaning towards the standard view that Google was just interested in gaining the advertising revenues associated with marketing of products to people who use this service. There was also concern about compliance of Google health with such laws as HIPPA (Health Insurance Portability and accountability Act). I also remember signing up for the service when it launched in 2008 and being told the service only applied to American citizens which I thought was a bit limiting.

It is great to see that Google has allowed users to extract their data in certain formats (CSV, Excel, PDF etc) which gives me encouragement that Google is taking the view that personal information belongs to the individual not to Google. The service will continue to operate until January 2012 so you have a few months to extract your data.

Microsoft’s HealthVault on the other hand shows no sign of stopping. It seems that Microsoft’s implementation has found more favour with health professionals and is being adopted on in the UK and other countries. Thos familiar with the health industry will know that the best way to get things working in this space is to make sure you are on side with the health professionals.

Regarding our own health record in myINFOSAFE, we are looking to move the format of health data stored towards open portable data standards so users have the option to import data from other compliant services or similarly export their data if they choose to. Watch this space.
Some relevant links for further dialogue on this subject for those that are interested:

Monday, June 13, 2011

Privacy of Personal Information

How private is information you post on the internet? Is it more secure than if you store that information on your PC?

The reality is that information can be very secure or very insecure on both platforms.
In regards to the Web, I found a helpful view in David Siegel's book "PULL". He states that there are three basic levels to the Web and area findable by public search engines like Google and Bing.

The Public Web which we normally see when searching and browsing for information online.
The Deep Web which includes large data repositories that public search engines usually do not see. E.g. Craigslist, Grainger etc.
The Private Web which we can only get access to if we qualify or have access rights. E.g. Corporate intranets or subscription based services. Again, this information is not searchable by public search engines.

So your data is more secure in the private web than the public web, but, in all these systems there are people that have the ability to access your information if they wish to. There is always a systems administrator or similar with super admin rights to each database and can just about always get to see what data is stored anywhere.
On your PC you may think your data is safe, but there are two main ways that people can gain access to information on your PC.

Remotely - If your PC is connected to the internet, even if you have firewall protection or security software, there are ways that people can gain access to your PC and search your information.
Physically - If someone gains physical access to your PC, and even if your PC is password protected, people who know how can access your PC and search your information. This can also be that case if they get hold of any of your back up devices for your PC.

On either platform the best way to ensure that your data is not compromised is to have it encrypted with a strong cryptographic key that is kept confidential (and separated from any systems administrator). This way, even if information is found it cannot be read or understood as all the information is encoded using this key.

The cracking of a strong encryption key of about 192 or 256 bits is considered infeasible.

So, be careful what you do with your information. If you want it shared then that is fine. If you want it safe and protected, encrypt it – end of story.

Monday, May 30, 2011

Linkability?

So you post some information on your website, your blog, or post some pictures on the internet for friends to see. What happens to it then? Can this information be copied, re-used, modified? Yes it can. This is less than ideal as you soon lose control of your information and it is off into cyberspace somewhere for who knows what purpose.

Some would say this is no different to talking to someone and them talking to someone else and soon you do not know who is talking about you. This is OK if it is about things you are happy for people to talk about, in fact this can often be beneficial. But what if you share something personal with someone in confidence and others get to know. You feel your confidence and trust in that person has been breached and this is not OK.

How can we set up similar confidence rules for information we share on the internet to protect ourselves from the openness of the internet when we need it?

Some would say that if you do not want your personal information spread on the internet, then do not put it up there. That may be right sometimes (e.g. just do not put those pictures from the office party up on Facebook). Others will say, make sure you submit such information in password protected areas. But what is stopping other members copying that info and distributing it outside of the protected area.

There are times you need to share information on a confidential matter and discuss it with people you trust. Due to geographical location or the need for input from multiple people, the internet is often the best mechanism in which to do this.

So, in the mean time, you are left with using a search engine to see what is being said about you on the internet and how information about you is being treated, then trying to correct it. Perhaps what we need is some mechanism to link (Linkability?) us to our information or protect sensitive information we do post or submit to the internet. Is there such a mechanism?

Look forward to learning about what views people have in this regard and what initiatives are underway to move us forward in this area.

Wednesday, May 25, 2011

What is our identity in the digital world?

As with any new system, it will evolve over time and hopefully improve the way it operates. The Internet has evolved primarily by the construction of individual websites that view the people they interact with as "their" customers and so have set up userID's and passwords to let users enter "their"system.
Of course as more and more websites have been built we the users have had to have more and more UserID's and Passwords the we have to remember to enter each website we want to make use of. Of course each website has different rules and processes for setting userID's and passwords. Some ask you to use your email address, some ask for a unique identifier for you that may not be able to be your name. The passwords can be short or long, capitalised, include symbols etc. which makes it impossible to have the same password (not that we should be using the same password should we).
What we need to evolve to is the Internet seeing individuals as real people who need to access more than one site. This is where the Open ID was formed. The Open ID allows you to use an existing account to sign into multiple websites, without needing to create new passwords.
Click here to find out more about Open ID http://openid.net/get-an-openid/what-is-openid/
More and more websites are adopting Open ID or something like it, including some of the big players like Google and Yahoo. This will help users have a better experience on the Internet over time. Bring it on!
Please let me know if you have used Open ID of something similar and let me know if it is improving the experience on the Internet or if it is creating issues for you.

Sunday, May 15, 2011

There must be a better way!

Today we all have many social networking sites we are connected to, Facebook, LinkedIn, Plaxo, You tube, as well as many other sites we may subscribe to. We sign up for each one and they all ask us for more or less the same personal information - Name, email address, credit card details, Zip Code etc.
With each duplication, it increases the number of user-IDs and passwords we you have to remember, the data we need to keep up to date and the risk of that data being out of date or even compromised.
There should be a place where your personal information is stored once, kept up to date once and called on by these various applications rather than having to re enter it each time in each application. For example, if you need to change your address or credit card number you currently need to go to all your sites and change this information. It would be so powerful if we could update this information in one place and it was updated in all sites you use automatically.
I am aware of some attempts at Digital ID's or passports in the past. Is anyone aware of any working versions of this or any info on why that have not worked in the past?
More importantly who would like a service like this?

Tuesday, May 10, 2011

Check out this video - Will this be the future?

At the recent Mediasense conference in New Zealand, US futurist David Siegal (purportedly the worlds first Blogger) presented the concept of a Personal Data Locker. Not only did he describe the concept of what our lives could be like if we better managed our personal information, but he presented a video to help us visualise it. As they say, a picture is worth a thousand words, so what is this video worth?
Click on this link to start the video :
Lets get some discussion going on this. What do you think, is his vision achievable? Desirable?

Saturday, January 8, 2011

How private is our personal information?

We have all heard about Wikileaks. I noticed this article today that made me think about all personal information stored on the web in cloud based solutions that you may think is private and secure but can be clearly accessed under legal process as required.

http://nz.news.yahoo.com/a/-/world/8615201/u-s-orders-twitter-to-hand-over-wikileaks-records/

We considering this as part of the design of myINFOSAFE. If we were ever asked to provide details of account codes and encryption keys for customers by the court, we would have to do this. But we could not provide any of the customers personal information stored in myINFOSAFE as we do not have access to it as it is stored locally on the users PC and is protected by a password that we do not know. (assuming the user has changed it from the default). The customer has control of their information and they can protect it, back it up or delete it in any way they want.

It makes you think that while there are many benefits of cloud based systems there are weaknesses that you need to be aware of in relation to your personal information.

Look forward to some discussion on this please.