Although complete anonymity is not possible, it is advantageous to display: the sender (who sent this?), the receiver (who is the destination?) and the relational (are sender A and receiver B linked?).
INTRODUCTION
Every day, more and more technologies and strategies are being developed to mitigate some of the risks associated with privacy and cybersecurity. For example: (1) Digital Rights Management (DRM) technologies. These allow conditional access to encrypted information, provide traceability, and enable access based on the authorized user and device. (2) Encryption and steganography technologies. These protect data/programs from unauthorized access by concealing both their content and their existence. (3) Anonymity and pseudonymization technologies. These automatically blur personal information, so that even if authenticated, the information is only what is necessary for the intended purpose; for example, it is sufficient to verify that a channel is secure. (4) Interface technologies. These warn of privacy threats and remind users how to configure their privacy settings. For example, web browsers can be enhanced to display normally hidden information about cookies and P3P settings. It is important to warn users about the risk that client-side P3P may not affect server-side security. In June 2011, it was reported that Sega's website (the Sega video game site) suffered a data breach, with 1.3 million records stolen. In March 2013, the Spanish National Police arrested individuals involved in the trafficking of confidential data. These individuals had illicitly acquired personal information by purchasing it from employees of telephone companies, the Social Security Administration, the Tax Office, the National Employment Institute (INEM), and other agencies. In 2011, the Court of Justice of the European Union moderated data protection regulations in Spain, stating that EU law establishes two requirements for the lawfulness of data processing: that it be necessary to satisfy the legitimate interests of the data controller and that the fundamental rights and freedoms of the data subject be respected; member states cannot add additional requirements. In August 2015, a cyberattack against the British mobile phone company Carphone-Warehouse compromised the data of 2.4 million customers, including names, addresses, dates of birth, bank account information, and other sensitive data.
REASONS TO PROTECT PRIVACY. THREATS TO PRIVACY.
Information privacy refers to the right or ability of individuals to control the collection, use, and disclosure of their personal information by others. The amount of data to be protected is constantly growing: PII (Personally Identifiable Information), web browser and operating system information such as cookies, language information, IP and MAC addresses, data volumes sent and received, traffic timing, and so on. PII, such as name, address, and telephone number, can be biographical, biological, genealogical, historical, transactional, locational, relational, computational, vocational, or reputational—the very material that allows us to construct our modern identity. Privacy is contextual, new, and constantly evolving; it varies between countries and should be considered during application design, implementation, and configuration. Where there is no reasonable possibility of identifying a specific individual, either directly or indirectly through manipulation, linking, or connecting information, there is no privacy issue. An individual can be hidden within a large crowd of people, roads, buildings, and so forth. (k-anonymity) or may have disabled their implanted RFID tag using Faraday cage technology to prevent its execution upon entering a location where a bomb was set to detonate upon identification. J. Craig (1997, “Invasion of Privacy and Charter Values”) identified six reasons for privacy protection: (1) Autonomy. It promotes autonomy by encouraging individuals to make their own decisions. (2) Freedom. Privacy prevents interference in a person's actions. (3) Refuge. It allows individuals to withdraw from the pressures of public surveillance and social norms. (4) Creativity. By protecting individuals from conforming pressures, it fosters creative experimentation that leads to social diversity. (5) Mental health. Privacy has been linked to an individual's mental health. (6) Intimacy. Privacy is a necessary condition for building trust and confiding in others.
The number and severity of threats to privacy are increasing daily. Among others, the following should be highlighted: (1) Unauthorized disclosure of content, identities, addresses, bank details, etc. (2) Misuse or improper use of data. (3) Unauthorized data connection. (4) Inaccurate data, including false identities, erroneous or outdated content. (5) Function creep. This is the process by which the originator's purpose for obtaining the information expands to include purposes other than those originally specified. Function creep can occur with or without the consent or agreement of the person/entity providing the data. Examples include using a national identity card or social security number for new purposes, selling driver's license photos to a private company, or copying all photocopies made in a copy shop onto the owner's or employee's computer hard drive. For example, electronic passports are being used in new areas such as e-commerce. The increasing use of a technology or system beyond its original intended purpose leads to a potential invasion of privacy. (6) Physical privacy. Stigmatization and hygiene. (7) Tracking. Monitoring and traceability. For example, using facial recognition to monitor both legitimate individuals and terrorists and criminals. (8) Perpetrifying discrimination, cyberbullying, etc. (9) Data theft, identity theft. (10) Bureaucratic control over personal information without adequate judicial safeguards. (11) Inaccuracy in the collection, verification, and confirmation of personal data by entities. (12) Mechanisms for compensation, redress, and reparation. (13) False positives.
DIMENSIONS OF PRIVACY. PROTECTION OF DIFFERENT TYPES OF DATA.
Currently, several dimensions of privacy can be identified: (1) Information privacy. This involves establishing rules that govern the collection, capture, and handling of personal data, such as medical information, banking records, and government records. It is also known as data protection. (2) Bodily privacy. This refers to the protection of individuals' physical beings against invasive procedures such as genetic testing, drug testing, searches of body cavities, and chemical, biological, radiological, nuclear, or explosive actions. (3) Communications privacy. This covers the security and privacy of email, instant messaging, telephones, postal mail, and other forms of communication. (4) Territorial privacy. This refers to establishing limits on intrusion into homes and other environments such as public spaces and workplaces. This includes searches, video surveillance, and identity checks. When protecting privacy, several types of data can be identified: (a) Transaction data. Created through interactions between individuals and businesses. There are currently useful privacy-oriented solutions. (2) Author data. Created by social actors. Digital Rights Management (DRM) tools based on watermarks and steganography are used. (3) Sensor data. Represents a growing threat to privacy. The time of creation is unclear. It grows rapidly. Examples of sensor data: surveillance cameras, video surveillance drones (especially at night with facial recognition software); workplace monitoring software (to detect misconduct, misuse, or intrusion with keyloggers or hidden spyware, for example); differential GPS/GLONASS/QZSS transmitters and RFID tags with and without chips/NFC; wireless sensors (for example, for location-based services). Sensor data can be difficult to identify and even for data collectors, allowing them to cross the boundary between the real world and cyberspace. The boundary between transaction data and sensor data can be blurred, for example, with web browsing data.
ANATOMY OF INFORMATION PRIVACY.
Today's society is experiencing exponential growth in the number and variety of data collections containing specific information about individuals and entities. Sharing this collected information is valuable for both research and business. Publishing data can seriously jeopardize the privacy of the individual or entity. Therefore, the goal is to maximize the usefulness of the data while limiting the risk of disclosure to an acceptable level. Currently, there is no clear definition of an acceptable level of disclosure (other than theft, misappropriation, or breach of access control). For medical research, hospitals may possess certain data on specific individuals that they wish to publish in a way that prevents the individuals' identities from being determined, but attackers can infer secret and sensitive data from the published database. Because it is difficult to identify what constitutes personal data, there is no universally agreed-upon definition of privacy, either offline or online. Privacy is contextual. Perspectives on privacy are influenced by culture, economics, society, politics, religion, history, experience, education, and so on.
Privacy can mean different things to different people and can be viewed from very different points of view and perspectives:
(1) It is the desire of individuals and entities to freely choose and control under what circumstances and to what extent they will expose their personal data, geolocation data, etc., and how their behavior will be displayed to others. This has led to a race to develop new technologies and legislation.
(2) It is the claim of individuals... to determine for themselves when, how, and to what extent information about them will be communicated to others (Westin 1967).
(3) It is a fundamental human right defined in Article 8 of the European Convention on Human Rights. Informational privacy has two distinct characteristics: the right to be alone and the right to decide for oneself what to reveal about oneself. Currently, the protection of information privacy for individuals is expressed through various European Union Directives: the Data Protection Directive 95/46/EC (which has two objectives: to create a high level of protection for personal data and to allow the free movement of data within the European Union), the Telecommunications Directive 2002/58/EC, and the Directive on Digital Signatures 99/93/EC. It is a right recognized in the most developed countries, such as the EU and the USA. In Spain, the LOPD (Organic Law on Data Protection) with its corresponding regulations is an Organic Law, etc.
(4) It allows for isolation and desired solitude. The desire to be alone.
(5) It enables ownership. The desire to be remunerated for one's data.
(6) It allows for autonomy. The capacity to act freely.
(7) It is an object of business. To be bought, sold, and paid for.
(8) It is the capacity to control the dissemination, storage, processing, and use of one's personal information.
RULES AND PILLARS OF FAIR INFORMATION PRACTICES.
It is urgent to address privacy by design and architecture (without neglecting privacy in implementation and configuration), working transparently, and simplifying the user's choice. Some key questions to consider when professionally addressing privacy are: (1) Why is this information being requested? Collect and clearly specify the purpose in a simplified manner. (2) How will the information be used? State the primary purposes and limit their uses. (3) What are the possible secondary uses? Announce them, require explicit (not implied) consent, and prohibit any unauthorized disclosure. (4) Who will be able to see my information? Restrict access to unauthorized third parties.
IDENTITY PROTECTORS. DIGITAL PSEUDONYMS.
An identity protector allows you to control the exchange of identity between different identity domains. An identity protector converts a user's identity into a pseudo-identity, which is an alternative digital identity that the user can adopt in a given situation. Examples of pseudo-identities include bank account numbers, social security numbers, national identity cards, SIM card numbers, email addresses, etc. Some of the functions of an identity protector are: (1) Generating pseudo-identities. These can be temporary or permanent depending on the location, context, date, etc. (2) Translating pseudo-identities into real identities and vice versa. (3) Converting pseudo-identities into other pseudo-identities. (4) Combating misuse. (5) Informing and controlling when identity is revealed.
The user can activate the identity protector for different purposes, for example, to keep their identity confidential while using it legitimately, or to reveal their identity only to certain service providers. A digital pseudonym can be represented by a random string of characters (including numbers, letters, and special characters). The Service Provider does not know the user's identity but only through this string of characters. The user can select different digital pseudonyms, one for each Service Provider with whom they interact. Therefore, Service Providers cannot exchange information about each user.
TOR ANONYMITY NETWORK.
The Tor network (based on onion routers) is designed to provide anonymity over the internet. The Tor network consists of a large group of Tor nodes. Client software routes internet traffic, such as web browsing and email, through circuits established within the Tor network. These Tor circuits are connections through three Tor nodes and expire every ten minutes. Establishing a Tor circuit involves four phases: (1) Originator A learns about all available Tor nodes and randomly selects three. That is, A's Tor client obtains a list of Tor nodes from a directory server and selects a random path to the destination node or server. (2) Originator A connects to the first node selected. The node generates a temporary public-private key pair, which it digitally signs with its permanent key. This new public key is then used to exchange a symmetric key. (3) Originator A can now tunnel traffic through node 1 to its second node and again agrees on an ephemeral key. (4) Originator A tunnels traffic through node 1 and node 2 to the third node and again exchanges ephemeral keys. Now originator A is ready to exit the TOR network through the third node and anonymously converses with recipient B. When A sends a message to B, it encrypts it with three layers of encryption using three ephemeral keys agreed upon with the nodes. Each node decrypts one layer of encryption before forwarding the message to the next server node. None of the nodes know who is communicating with whom, and recipient B does not need to know who or where originator A is. The circuits exist for only a few minutes, after which the ephemeral keys are destroyed. Even if the TOR traffic has been logged, the content cannot be recovered due to the size of the keys. Recently, improvements to Tor have appeared, such as HORNET (High-speed Onion Routing at the NETwork layer), which is somewhat more secure. It uses symmetric encryption and encrypts each packet individually, operating at over 90 GBps. Remember that perfect anonymity is not possible, as it requires cooperation, and this link can be broken.
FINAL CONSIDERATIONS.
Our research group has been working for over twenty years in the field of enhanced data protection and information privacy. A key challenge we still face is empowering individuals and organizations to measure their privacy levels and interact effectively and appropriately with the right tools.
LITERATURE.
- Areitio, J. “Information Security: Networks, Computing and Information Systems”. Cengage Learning-Paraninfo. 2015.
- Areitio, J. “Exploration and analysis of cyber-physical systems from a cybersecurity perspective”. Conectrónica Magazine. No. 181. November 2014.
- Areitio, J. “Identity management, a strategic priority for minimizing information security risks”. Conectrónica Magazine. No. 146. April 2011.
- Areitio, J. “Hidden potential of steganography in modern information security”. Conectrónica Magazine. No. 136. April 2010.
- Zeadally, S. and Badra, M. “Privacy in a Digital Networked World: Technologies, Implications and Solutions”. Springer. 2015.
- Laurent, M. and Bouzefrane, S. “Digital Identity Management”. Elsevier. 2015.
- Metadata-Clearner: tool to clear metadata from Office documents: http://www.pointstone.com/products/metadata-cleaner
- Bowman, C., Gesher, A., Grant, JK and Slate, D. “The Architecture of Privacy: On Engineering Technologies that Can Deliver Trustworthy Safeguards”. O'Reilly Media. 2015.
- Foca: tool to delete document metadata: http://www.informatica64.com/Download Foca/
- Herold, R. and Hertzog, C. “Data Privacy for the Smart Grid”. Auerbach Publications. 2015.
- xvi32 hex editor for viewing the hexadecimal representation of images or other files: http://www.chmaas.handshake.de/
- Craig, T. and Ludloff, ME “Privacy and Big Data”. O`Reily Media. 2011.
- Tor tool for network anonymity: https://torproject.org/download
- Cherry, D. “The Basics of Digital Privacy: Simple Tools to Protect Your Personal Information and Your Identity Online”. Syngress. 2013.
Author:
Prof. Dr. Javier Areitio Bertolín,
Professor at the Faculty of Engineering, University of Deusto.
Director of the Networks and Systems Research Group.
