Showing posts with label personal data protection. Show all posts
Showing posts with label personal data protection. Show all posts

Monday, January 21, 2019

Locking down the Internet of Things

WiFi security on the Internet of Things
Have you gotten all of your new tech gadgets hooked up after Christmas? Seems like every gift that had a plug also had a phone app and connected to Wi-Fi. Throughout the year as new toys or even appliances enter your home, setting up individual devices isn’t that noticeable. But after Christmas rolls through and you start setting up all the new goodies it really makes you sit back and notice-You have entered the new age of a smart home. Without realizing it we have created our own attachment to the Internet of Things (IoT).

That's a lot of things

Leichtman Research Group in 2018 found that 74% of U.S. homes had at least one smart device. Statista estimates that there will be 42.2 million smart homes in 2019. Spending on IoT devices was $23.3 billion (yes, billion) and is estimated to be $75 billion by 2025.  While there are Bluetooth connections, the primary connection for IoTs is Wi-Fi. Statista reported that the average number of connected devices per person, worldwide, in 2015 was 3.47 and is estimated to be 6.58 by 2020. That is connected devices per person. Multiply that by people in your home and the for-the-common-good devices like appliances, cameras, plugs, bulbs, etc, and that’s a lot of connectivity. 

If you want to keep up with technology it is how it’s going to be. I didn’t set out to convert the ol’ analog home to “smart”. It just happened. Garage door opener, a new appliance here and there, TVs, Hey Google, Hey Siri, Alexa, before you know it you’re your home is smart. The router sent me a message, yes it communicates as well, that the network was getting full. You’re aware of connectivity for your phones and computers but forget about the other electronics-appliances/TVs/cameras/power strips/gaming systems/eBooks, etc-that are on all the time and trying to communicate with the mother ship. Not only are these devices taxing on your home network they are all portals for security breaches.

Anyone of these connected devices can be hacked at the source, through the controlling app, or the company that provides the service. All the more reason to review your home network security.  If you haven’t done so recently, with the onset of all your new tech wonderness, you’ll need to upgrade your Internet service.  Most times these types of upgrades come with new routers. 

Security

One of the first actions you should take on all routers and new devices is set up your own logins and passwords. Many people still use the default settings, which cybercriminals are aware. Changing this information will at least slow them down. I say slow down because, as we’ve seen, anyone can be hacked. At least changing the settings will offer some protection.

For all of your connected devices actually, read the setup instructions and pay attention to what you are agreeing to during the process. Data collection is big business and those companies want your data. As consumers get more privacy savvy the product providers are finding counteractions. I recently loaded an app that wanted access to my phone’s camera, microphone, location, and to send user data. Answering no to any of those requests denied the user access. Or sometimes certain features are denied or dampened if the user doesn’t agree to the terms.

Devices that listen, your phone, TV, Echo, Google home, are also collecting data and have been proven to also be recording your conversations. In the interest of improving their service, of course. Again, go through the setup and privacy menus carefully. Understand what the device, i.e.-manufacturer is asking you to allow.

Overall, you have to understand that if you allow “smart” devices into your home you are giving up privacy. It’s hard not to get caught up in the technology craze, but understand that what you’re getting yourself into.

Please see the blog archive for other posts relating to privacy.

Friday, October 19, 2018

Privacy access


Responding to privacy concerns and the EU’s restrictive privacy legislation, Apple launched a new portal on October 17, 2018, that allows users to see what kind of data Apple is collecting and storing. The portal has been available in Europe since May 2018. The portal provides users with a report on tracked data such as App store purchases, support history, calendars, photos, documents, and browser bookmarks.
To access the portal follow these steps.

Sign in with your Apple ID. You may be asked to authenticate the sign in.
You will then be presented with this page

Under the heading, Get a copy of your data, Click on Get Started
You can then select which data you wish to download or you can select all. Keeping in mind that the more or less you select will affect file size and download time.

Google also has an option to download your data. Access by signing in to your Google account.
After signing in, in the top right, click on the checkerboard symbol and receive this drop down


Click on Account. Under the section Personal info & privacy, click Manage your Google activity

Scroll down to Control Your Content and click on CREATE ARCHIVE under Download your Data. 


The next page, select the data you wish to download.



Refer to the blog archive for more articles on privacy and security.

Sunday, June 3, 2018

What we give up for convenience


If you think about it, who is the culprit in the multitude of personal data breaches? The hackers? The companies that failed to protect the data? Or is it ourselves for uploading our personal data in the first place? This really isn’t a proper question because we aren’t the culprits. But the point is that we, ourselves, allow more and more data to be collected by mega corporations. Sometimes it is innocuous as registering on a web site or app, which we cannot always avoid because in order to do business in the digital world we have to. What I mean by allow is two pronged. One, we are not outspoken enough about the Google’s and Facebook’s of the digital world collecting data. Facebook has seen a little backlash recently, but people will continue over sharing every detail of their life. But that’s the really big picture. 

Second, and more specific to personal security, is what we allow by making choices to upload or share personal data. We do this by plugging in the new smart TV without learning about its capabilities and without changing the settings. Or by installing the multitude of other appliances, cameras, digital assistants that we bring into our homes and plug and play. Anything you can talk to on demand and receive a response has to be listening all the time. Creepy? We will allow apps to track our location so that when we are in certain stores or near certain locations we receive notifications. As with listening, these apps aren’t waiting for you to arrive at a certain location, they are tracking and storing your every move until you arrive at the specific location.

How much privacy are we willing to give up?

Last month police and the FBI captured a man suspected of being a serial rapist and murderer in a multitude of cases from forty years ago. The case was broken through the use of DNA. The suspect himself was smart enough not to have his DNA logged into any DNA databases. Smart detectives realized that outside of justice system DNA databases there is a plethora of information being collected by private entities. Ancestral research companies provide DNA collection kits, which allow people to submit their DNA for comparison to other samples in hopes of finding family matches. You guessed it, the profiles are stored in databases so that they can be pinged during searches.

Checking crime scene DNA against public sources of DNA, police were able to get a familial match. That match narrowed the pool of suspects down to one family. Then through traditional police work detectives were able to identify a suspect. As you can imagine privacy watchdogs are all over the issue of law enforcement having access to private sector databases.

For some time Amazon has been offering package delivery inside of your home. Utilizing an Amazon smart lock, with the customer’s permission and knowledge, delivery personnel can unlock your door and drop the package inside. Of course, you are alerted each step of the process. Amazon recently announced package delivery to your vehicle. Currently the service is only offered to owners of GM and Volvo vehicles in certain cities.  The privacy we give for convenience. We allow cleaning and pet sitting services into our vacant homes but more than likely we have met the workers performing the services. I’m sure Amazon does a fantastic job vetting it’s employees. The point is we are giving complete strangers access to our homes and vehicles. We are then shocked and surprised when something bad happens. 

Check yourself

As with corporations and social media we gladly share and upload personal data, even our current location and DNA profiles. Trusting souls that we humans are we don’t cry foul until there is a breach or government overreach. Even though we are the ones that probably share a little too much.

You can’t always avoid uploading data or providing data through registrations. What you can do is be aware of what and to whom you are sharing. Monitor your financial accounts and pay attention to announcements of breaches. You may not be directly affected, but your other accounts may have been compromised through third party links to the breach victim.

Just as we are told to change smoke detector batteries at Daylight Saving Time, maybe we should get in the habit of doing online security checks every time there is a breach announcement.

Please see the blog archive for other posts relating to privacy.
Keys to the vault August 2015

Tuesday, May 22, 2018

There’s been a breach


Note: This post was originally published in 2015. It has been updated with new information relating to the topic. 

Last week Twitter announced a breach of passwords. Twitter claimed that no personal data was released and encouraged users to change passwords. Since the big breaches from the fall of 2014 it seems like every month we have heard about a new breach. If not banks then major retailers or healthcare systems. The private information we entrust others to keep safe is being violated on a regular basis.

Try as you might to stay off the “grid” by paying cash, getting paper statements, or banking in person, eventually you will be a victim of identity theft or some sort of financial intrusion. Either because of convenience or because a company demands you use an electronic system. It is difficult to navigate in today’s world without having some portion of personal data stored on an institution’s computer.

Personal data

Ever check out at a store that you shop infrequently and they ask for your address, phone number, or name, and you’re in their system? Freaky right? At some point you’ve provided them with your personal information. Larger companies own smaller companies…your personal data is bought and shared daily.

Tax season just passed and it’s a good bet that when you filed your taxes, electronically of course, your return was rejected by the IRS because, surprise, the return associated with your social security number has already been filed.  

The IRS estimates that more than 122 million returns were filed electronically in 2017. While the IRS has seen a decline in personal tax fraud, falsified business returns have increased. The IRS identified 10,000 compared to 4,000 fraudulent business returns in 2016.  The IRS doesn’t publish everything it is doing to combat tax identity fraud. Some of the public efforts are tightening access to private sector filing software and more thoroughly scrutinizing refunds. When your SSN has been compromised the IRS issues you an electronic identification number for future filings. This solution should keep your tax information safe, as it is a unique number. But so was you’re your SSN at the time it was generated. 

We use to worry about someone stealing a driver’s license or credit card. If that didn’t happen you didn’t have much to worry about. Years ago, while working as an undercover detective, and when I say “years ago” I mean before there was a computer in every home and a world-wide inter web of computers.  A senior administrator had a briefcase stolen that contained contact information for all of the detectives. Not just name and phone numbers but addresses, birthdays and yes the coveted social security number. Not sure what we called it then, but it wasn’t a breach. But in today’s terminology, the breach compromised so much personal information what could one do? You couldn’t completely change everything. In those days though we were more concerned with operational security than identity theft. Yes, identity theft occurred, but not on the level or frequency as today. The criminals at that time weren’t as sophisticated in that skill set as they are today. Plus, copying and sharing was a literal concept. The documents would have to be photocopied and personally distributed. 

We knew that if we worked hard and fast to recover the documents, we could determine the extent at which the information had been distributed. The faster the culprit was caught, the less chance the information could be distributed. Today, your information can be stolen from a third party vendor’s database by a criminal in another country and uploaded to a distribution network all from a keyboard, in a matter of minutes.

Document, document, document

The tenets of the paper world of long ago still hold true. Identify the breach and work fast to stop the leak.
Once you’ve identified a problem, you need to start working to quickly plug the leak. Contact the source in which you became aware of the breach-credit card, driver’s license, IRS, etc. Get that entity started on resolving the issue. File a complaint with the Federal Trade Commission, your State’s Attorney Generals Office, even the FBI if you seem to be apart of a larger breach. File local police reports also. It may seem for naught but you’ll have a record of the report and a case number to go with any other complaint filings. Most of the entities you will deal with, including law enforcement, have online complaint forms. It doesn’t take long and you can get it done in less than a day.

Document, document, document, everything you do and the entities you’ve contacted. Keep your notes for future reference.

Consider a monitoring program. There are lots of companies out there that perform this service. Of course do your research and choose wisely. If the breach occurred from a major retailer, financial, or health institution, they may offer some sort of credit monitoring or identity repair service for free. Take advantage of it.

Update, update, update

If you get notification of a password breach or hear it on the news, such as the recent Twitter breach, don’t ignore it. Like Twitter, companies publicize that no personal data was infiltrated but passwords “may” have been compromised. It is important to regularly change passwords as a matter of routine. However, when a company has had their password database specifically breached it is important to act quickly and update your settings. It is equally important to update other accounts in which you use that same password. Maybe get in the habit of updating passwords whenever there is a breach in the news. 

We should have different passwords for every account but let’s face it no one does that. So when one password is compromised the other accounts that use that same password are now in danger of being hacked. Cyber-criminals have highly sophisticated search processes. They may not be searching for you, specifically, but once they get your logon or password they can use that to find other accounts. Once they have one piece of the puzzle it is isn’t that difficult to break the rest.

Monday, April 2, 2018

How secure are apps?


Every business is pushing their mobile apps. Some are highly interactive, giving access to secure accounts. Others are merely informational almost static platforms. Everyday we become more and more dependent on our phones. The Pew Research Center estimates that 77% of Americans have a Smartphone. A conglomerate of different studies from 2017 reported that Americans average five (5) hours a day using mobile devices and of that time 90% is spent using apps. Now when you allow that everything on your phone is an app of some sort it kind of diminishes the 90%, but the point being is that we are on are phones a lot.

Why have an app?

Phones are now like appendages. We are rarely without them. This is a big reason why companies push apps. That and because the phones create a focal point for data collection. Most apps require some sort of registration. That provides a modicum of security but it is mostly for data collection. Location services on smart phones allow app users to be tracked and pinpointed where they are using the app. This let’s the business collect, not only, your personal information but how, why and where you’re using the app, and what you are buying. All of this data is used to target advertising and reshape sales.

Since 2014 mobile Internet use has been more common on mobile devices than desktops. You can accomplish so much on your phone now you probably could go days without turning on a laptop or desktop. Apple has a cute commercial where the camera follows a girl throughout her day using her iPad.

A neighbor asks her what she is doing on her computer. She answers, “What’s a computer?”
The procession to apps began with the advent of online access to accounts and shopping. To encourage electronic account access, some companies even threatened higher fees for receiving paper documents through the mail. Then everything moved to our phones. Businesses lure customers into their apps with rewards or deals for using them. Some put more effort into their apps than their websites.

Secure?

How secure are all these apps we’re either using voluntarily or “forced” to use by companies? The transmission of data between the users phone and the app servers usually has end-to-end encryption. Meaning the data being sent and received is encrypted. The problems arise from the users lack of security awareness and hacks into the apps servers.

A high percentage of our phone use is in public. If you’re concerned about data usage you’re always looking for a WiFi signal. Logging into public WiFi is one of the most unsecure actions a Smartphone user can do. If you don’t inadvertently log into a hackers signal then you’re sending a signal that your phone is publically available. Once a hacker zeros in on your phone they can intercept your transmissions to and from the apps you are using. Intercepting the phone’s connection to the router is commonly known as “man in the middle”. While that is still a popular hack it is time consuming and much more work than going after the bigger treasure. Company servers.

Why is it important to frequently change passwords? And not use the same passwords or login/password pair for more than one account? More sophisticated cyber criminals know where the money is. It’s in the servers of big companies. If not the financial records then the personal data. Recently, Under Armour announced that their app had been breached. They assured users that no financial data had been accessed only user names and emails. While that may give some a sigh of relief there’s still a problem. Hackers will sell those users names, emails, and passwords on the dark web. They’re valuable because many users will use the same login information across many accounts. Hackers can use the data gleaned from one breach to access your other accounts.

Using apps are as safe as the host makes their server data and how you use the app. Most of the security issues are out of your hands. If you are not compromised in public more than likely the company’s servers or app itself will be hacked, exposing your data. All you can do is be as safe and aware as possible on your end. Monitor accounts and change passwords frequently.

Please feel free to share. Check the archives for other posts about privacy and online security.
Are you being watched? February 2018
Keys to the vault August 2015



Tuesday, February 6, 2018

Are you being watched?


Do you feel safe in your home? Your exterior is probably pretty well defended against intruders with metal doors and deadbolts, locking windows, and maybe an alarm system. How about intruders from within?  “…The call is coming from inside the house”, an oft repeated quote from the 1979 movie, When a Stranger Calls, can still make your skin crawl when you’re all alone, think you heard a noise, and then the phone rings. Just the thought of an intruder with you in your home can be terrifying. There may not be physical intruders inside your home at this moment, but someone may be listening or quite possibly watching.

Internet of things

Kevin Ashton of Procter & Gamble first coined “Internet of things” in 1999. It is defined as network of devices, appliances, vehicles, etc. that connect and exchange data through the Internet. It is estimated the Internet of things will be populated with 30 billion devices by 2020.

Technology has always invaded our homes as we excitedly open the boxes to the latest modern conveniences. In the early days of the 1900’s telephones began appearing in homes. The 1950’s saw televisions showing up in living rooms. People started bringing home desktop computers in the 1980’s. Those computers were connected to the Internet in the 1990’s.  Phones went on our belts and into our pockets in the 2000’s and then became handheld computers. The first Internet connected appliance was a LG refrigerator released in 2000. According to Statista.com, there were nearly 36 million smart home devices sold in the U.S. in 2017. Over 40 million smart TV’s were sold in the U.S. in 2016 and 244 million worldwide.

Privacy

The remote accessibility of household devices creates new security issues everyday. As appliances get “smarter” their vulnerability also increases. Smart devices only work to their full capability if they are connected to the Internet. Once that occurs they are searchable and hackable. When the device reaches out to the web it declares itself open for business. Hackers are always looking for unsecure networks and devices to exploit. If not for gain then just because then can.

We first heard about these types of intrusions in 2015 two years after consumers starting bringing home smart TV’s.  Samsung released TV’s in 2013 that could listen to voice commands from their owners. The problem? The TV has to be listening all the time to pick up the commands. What was “heard” was being transmitted via the Internet. Samsung warned consumers, through privacy policies, that spoken words are being captured and transmitted through the voice recognition system. Consumers were further warned not to hold personal conversations in front of the television. But who read or reads the privacy policies, right?

Another popular device entering our homes are web accessible cameras. We set these up to watch the nanny, housekeeper, or house in general. There are even petcams available that not only allow owners to watch their pets but speak to them and deliver treats remotely. The first cameras imbedded in teddy bears, sold as a “nanny cams”, began appearing on the market in 1992. The first cameras to transmit remotely via IP were sold by Axis Communications in 1996. Today, the market is flooded with cameras and phone apps that allow web transmission of live video. It’s fun to watch Mr. Snugglekins romp around the house. But if you can access your webcam remotely, so can someone else.

Hacking

The device most people have heard stories about and are aware is the camera on your computer. Yes, they can be used against you. Unlike the movies, your home computer usually has to be “infected” with malware that you allowed in my clicking on a link or visiting a sketchy website. As with all of your devices, locally, you have to let someone in for them to be monitored. Not to say that you and your devices could not be specifically targeted and intruded. With the effort it could be done. Hackers and, yes, governments have the capability to access the television microphones, computer and remote cameras, turning them on and off and recording at will. However, most likely you’ve been the victim of malware.

The privacy and security issue with smart appliances is the collection and transmission of data. First, your viewing habits, conversations, actions are being collected. Second, the data is being transmitted to the Internet and held on third party servers. All of which can be hacked. So no matter the security measures you take at home, your personal data is vulnerable once it hits the WWW.

The thing is, you allow them into your home with the purchase, unpacking, and setup to connect to your network. Data transmissions you are unaware of because you have most likely allowed the device to set itself up per the manufacturer’s settings. Any warning or setup recommendations were clicked through and unread. Admit it. You’ve done it. Who reads the privacy settings on a new device? Or whenever you allow an update? That’s what the manufacturers are counting on. The key word in the previous paragraph is “allow”. You’re inviting the snooping by purchasing the device, bringing it into your home, and allowing self setup.

Your appliances aren’t the only ones listening. There’s been conspiracies floated the last couple of years that Facebook is listening to your conversations to better target ads. While feasible it is unlikely and has been debunked by several sources. Facebook may not be overhearing conversations but they, as is Google, “listening” by recording your search habits and even communications in messaging and emails apps to better address advertising. Netflix was recently caught by tweeting about the number of times a few viewers had watched one of its programs, trying to be funny. Netflix admitted that it did track viewing habits of subscribers.

Security

When you invite smart appliances into your home you give up your privacy. You have to consider these devices as other persons and guard your privacy accordingly. Take the time to read the manufacturer privacy policies. Read the manual setup instructions and adjust the device settings accordingly. Block cameras in sensitive areas or turn them towards the wall when you’re home.

This reads like an Orwellian or tinfoil hat conspiracy. It wasn’t meant to be or to keep you from enjoying the conveniences of technology. Just be aware of the surroundings you’ve created. Any smart device has to be considered to be listening or watching. Alexa, Siri, Google, they all have to be listening all the time to be able to pick up your commands.

Please feel free to share. Read other posts about security in the blog archive.

Monday, September 11, 2017

Cleaning Up Your Online Presence


Ever been asked at checkout for your phone number? You haven’t been in the store for a long time, if ever by your recollection, but the clerk wants to know if you’re in the system. You provide a phone number and surprise surprise you are in there! Phone number, name, and address. It’s probably not a retail conspiracy to create a super database of shared data. What it does reveal is how our lives and personal data are intertwined within the world of information.

When information was written on paper there was less of it and it was more fragile. Tear it up, burn it, poof it’s gone. Carbon paper, mimeographs, and copy machines (Younger readers will have to look those up) changed that. Documents were being copied and filed in triplicate. Computers, of course, made it all easier but it wasn’t until the ol’ World Wide Web came along that hiding in plain sight became difficult.

In the old days it was easy to disappear. You simply moved to another town. Started using a new name and slowly built your new persona. As technology progressed information began being stored on computers. Those computers could be accessed for information stored about you, but only for the specific information the entity had stored. Once computers became connected one entity could access another’s information. Then they began sharing information between each other and saving the data locally. The more digitally involved you are the bigger your online presence. As young people enter adulthood they have little to no digital footprint in the context of financial databases. What they do have is a social footprint, more on that later.

Google yourself

Have you ever searched your name? If not, give it a try. You might be surprised what pops up or how many of you are out there. The more you are in the public eye the more information that is going to be out there and, thus, the harder to clean up your online presence. A regular Joe should have limited occurrences as the result of a search. But even regular Joe’s can have an online presence depending on their interaction with social sites and images associated to their name. And that is what you need to be controlled.

Information for sale

Think about the seed system of a watermelon. You can take out a portion from the middle, but there are going to be all those strands extending throughout the melon. That is how it is in the digital world. Things truly do live forever on the Internet. You can have a record expunged from a database, but any reference to or sharing of that record in other databases is going to give it new life. Data has become a big commodity. Everything is for sale on the Internet. Data is being collected on every interaction you have on the Internet. The data collected by brick and mortar businesses is sought after. Once government databases went online (real estate, court information, etc) information brokers snatched up this data. All of this information is bought and sold and resold. The original purveyor of the data may have deleted it but the new entity has it saved and published it their own way.

Everyone that has data is looking for revenue sources, especially governments. Data mining companies buy data from phone companies (landline and wireless) and the government (real property and court records). The information is legitimately offered for sale on the Internet through pay sites or resold. Ever get those mailings and wonder how Joe Realtor knows how long you’ve lived in your house and what you can sell it for?

Your Job image

Younger people may not be in databases for real estate or financial institutions but they are using social media and sharing the media. Even someone with little life experience will pop up in a simple Google search, most likely under images. This is what haunts the 20-somethings when they start their job searches. Over the last few years’ different surveys have revealed that 40% of college admission offices and 40% of HR professionals research social media regarding applicants. Staying aware of your online presence is especially import when trying for a job.

Cleaning up online presence

You’re first step should be stop the flow of information. Review and change your social media privacy settings. Remove information from online shopping and other accounts that are old or unnecessary.

Whether it’s the garage, the basement, or the Internet before starting any clean up job you have to assess the situation. Start by searching your name and then different variations with your name, town, occupation, and any other identifier that you feel has a strong attachment to your name. Would suggest using Google as it is the most powerful, but using other search engines wouldn’t hurt. You’ll probably get different results.

Make note of the sites in which you pop up and what they are referencing. Find the source of the material you want removed and contact the source directly. Many will want sound reasoning why the post/picture should be removed. May want to read the companies privacy statements before you make the call to know where you stand and/or how to make the request.

Even though the source removes the post once it has been shared it lives on in other sites. You’ll have to track the posts digital trail and contact those companies as well. The tedious part is finding every link that’s associated with your name and going through the process each time. As with any situation where you are fighting an issue Document Document Document. Keep copious notes of your efforts in case you need to prove your attempts later or make subsequent requests.

After all that you are still going to be able to “find yourself” on government public access sites like real property and courts. People search sites and phone number search sites sell the information you are trying to keep private. Matters of public record like newspaper articles in which you’ve been mentioned are going to pop up.

To get your name removed from marketing lists there are organizations that can help. Similar to the national do not call registry, these services allow consumers to opt of marketing offers. You would be adding your name to another database, which may be counterproductive to what you’re trying to accomplish, but it does keep marketers from contacting you. Maybe. Who knows if it really works?

One such service is run by the Direct Marketing Association and allows consumers to have their names and addresses removed from direct marketing mailing lists. There is a fee-$2 for 10 years if you register online. The site can be found at www.dmachoice.org. The second removes the consumer from credit card and insurance offers. The service is provided in a joint venture between Experian, Equifax, Innovis, and Transunion. The site can be found at www.optoutprescreen.com.

You won’t be able to eradicate everything. If you’re serious about removing yourself from the Internet you’ll have to have as much as possible redacted. The rest will have to get buried in the voluminous amount of data filling the Internet. The less that is out there the more specific the search will have to be to find you. Not gone but harder to find.

Your personal information may be in myriad retail databases but at least you can try to keep what others read about you to a minimum. You can’t just completely disappear but can clean up your online presence so that you’re not easily searched.


See our blog archive for more posts about online presence.

Tuesday, February 14, 2017

Tax [Fraud] Season


Once the calendar year turns over thoughts of filing taxes begin. So do the warnings of tax fraud and prevention tips. Having been the victim of tax fraud I know the inconvenience of proving your true identity to the IRS; now having to file under a number rather than your true name. As the digital world expands, so does tax refund fraud. It’s a good bet that you know someone who has been a victim or that you, yourself, are a victim.

Theft

Most people will file their tax returns electronically, either themselves or through a tax preparer. It’s quick, it’s easy, you get your refund faster. Unless you get an error saying that you have already filed. You’re first reaction is that there is a mistake, but you soon realize that you have been the victim of identity theft. Someone has obtained your name and social security number and filed your taxes on your behalf.

It may not have been a direct theft in the classic sense. It could have happened during an electronic data breach of a larger scale or someone hacked your computer, any number of ways. Your information is uploaded to the dark web (it’s a real thing that criminals use to conduct their business or exchange information) and resold many times. The criminal then fills out an electronic tax return with your information and bogus financial information and has the refund sent to a direct deposit or PO Box. The IRS does compare information against past filings but that doesn’t occur until well after the refund has been issued. Software is in place to try and stop fraud, but, again, the refunds are issued so quickly it happens before any alarms go off.
You then have to go through an arduous process to prove yourself to the IRS, file the fraud report, and wait for the IRS to investigate your claim. If they find that you are a victim they will then issue your return and assign you an identification number to use for future filings. The whole process takes several months. Other than the waiting, it really wasn’t an unpleasant experience and the refund was issued in a timeframe shorter than expected. It’s also interesting to request a copy of the fraudulently filed return from the IRS. You get to see what deductions your other self made and the amount some PO box received.

Prevention

One school of thought of being susceptible to fraud is filing returns late in the season, near the April 15 deadline. This gives the criminals time to file their fake returns and receive the refunds before you file. Tax regulators say to file early to get a refund as quickly as possible, thus beating the criminals to your money. States have even made the effort to streamline the process so that refunds are received as quickly as possible after the return is filed.

Law enforcement doesn’t comment on the timing of the filing, but rather to delay the issuance of the refund so that fraudulent returns can be identified.  At a recent tax security summit, the U.S. Attorney for Maryland, Rod Rosenstein, commented from the panel, “The quicker you are on paying refunds, the greater the risk of not finding fraud.”

Hawaii, Illinois, Louisiana, Minnesota, Montana, North Dakota, South Carolina, and Utah are some of the states that are slowing returns to further prevent fraud. Maryland issues refunds within two days of receipt of the return. The comptroller’s office relying on analytical software to detect digitally filed fraudulent returns. Additionally, Maryland will not issue refunds until the comptroller’s office has a W-2 on file. With these methods in place the comptroller’s office hopes to combat fraud while at the same time efficiently serving the taxpayers.

The Maryland legislature this year is considering a bill named the Taxpayer Protection Act of 2017. This bill would give the comptroller’s office broader authority to build criminal cases against fraud and extend the statute of limitations for prosecution to six years.

There is no way to know if your personal data has been stolen. Regarding taxes it is best to file early. If you do become a victim, report it to the comptroller’s office and IRS as soon as you are aware. Document everything you do and who you speak to. Secondarily, begin looking into your banking and credit cards as they may have been breached as well. Review statements and set up alerts.

Be sure to read our others posts related to identity theft.

Tuesday, May 17, 2016

Workplace monitoring


 The messaging software company Slack is working on software that will install manager bots to monitor employee production. The bots will be plugged into company networks to monitor an employee’s work. The bots will ask for updates, check employees work status, and even ask what tasks are currently being worked. Managers won’t have to roam the cube farms to keep everyone on point. The bots will do it.

Does this help or hurt employee morale and productivity? Do companies that are constantly looking over employee shoulders getting the results they want?

Many in the workforce have been exposed to a micro manager. Constantly overlooking every detail of an employee’s work. Workers usually respond with frustration or task-to-task completion without innovation. Doing only what has to be done to satisfy the manager, waiting to be told what to do next. The last decade has seen the use of technology to replace that micro manager.

Long before the idea of manager bots technology enabled companies to monitor almost every aspect of a worker’s day. Most, if not all, companies that have computer networks monitor employee email traffic and Internet use. Some even capture keystrokes and keyboard activity, such as how long a keyboard has been inactive. Software enables managers to monitor telecommuters-are they actively working or just logged in to the network? Companies that utilize vehicles track employees through GPS, recording location and length of stay. Hospitals track nurses through the use of sensors embedded to monitor their location and patient visits. And let’s not forget about cameras. With or without using a computer, workers are constantly tracked. How the use of monitoring occurs and is communicated to workers can have varied results.

Hawthorne Effect

Workers who are knowingly being observed tend to be more productive due to what has been called the Hawthorne effect. The Hawthorne effect is used to describe the tendency of observed employees to work harder due to the attention they are receiving from researchers rather than because of individual work habits.

The Hawthorne Effect is named for the location where worker productivity experiments took place in the 1920’s and 1930’s, Western Electric’s Hawthorne Works near Hawthorne, Illinois. The electric company had commissioned research to determine if there was a relationship between productivity and the work environment. The focus of the studies was to determine if increasing or decreasing the amount of light that workers received would have an effect on worker productivity. Employee productivity seemed to increase due to the changes but then decreased after the experiment was over. Researchers suggested that productivity increased due to attention from the research team and not because of changes in the experimental variables.

Transparency Trap

Ethan Bernstein, assistant professor of business administration at Harvard Business School has extensively researched employee monitoring. Bernstein believes that it is difficult for employees to be at their best when they know they are being watched and evaluated at every moment. Bernstein wrote in the Harvard Business Review, “Wide open workspaces and copious real time data on how individuals spend their time can leave employees feeling exposed and vulnerable.” For his paper, The Transparency Trap, Bernstein conducted several experiments to help prove his theory. In one, Bernstein embedded five Chinese born Harvard undergraduate researchers into the lines of the world's second largest mobile phone factory in China. Controls were added to allow for the Hawthorne Effect.

This particular experiment showed that employees acted and behaved differently when they were being watched. Basically, observed employees followed the policies of the company to the letter while unobserved employees did not. Unobserved employees innovated ways to make their tasks easier, tending to hide process improvements from managers. Two examples were scanning multiple bar codes at once instead of one at time as per policy and crossed trained themselves on breaks. The intent was to improve the process without having the inefficiency of explaining their actions to managers.

Overall, those shielded from observation were more productive than the observed. Experimentation, shared problem solving, and focus flourished.

Communication

There are many examples of employee monitoring. Done improperly, with poor communication to employees may cause resentment and a feeling of “Big Brother” is watching. Letting workers know that data is being collected to improve efficiency may alleviate skewed results. UPS has saved millions and improved their schedules by collecting delivery data and providing the analysis back to drivers. You may have heard of how UPS routes were made more efficient by reducing left turns.

Letting employees know that monitoring is taking place, how the data is being used, and how that will improve their workday goes a long way is establishing trust between employer and employee.

Will employees do their best when being observed? Or are they so hindered by the constant oversight that they do the minimum required. If left to themselves would they perform better, working more efficiently with less fear of messing up and being corrected by managers?


These questions that are still being studied. From what is known, it seems that communication between management and the workforce about the use of technology to monitor productivity is a key factor for improvement. Technology will always continue to improve. Innovators will figure out how to apply technology to the workplace. But while people are still involved they need to be kept in the loop.