Search This Blog

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, August 22, 2012

Web Sites Accused of Collecting Data on Children


The following is an excerpt from an article in



The New York Times
Wednesday, August 22, 2012

Web Sites Accused of Collecting Data on Children

By NATASHA SINGER

A coalition of nearly 20 children’s advocacy, health and public interest groups plans to file complaints with the Federal Trade Commission on Wednesday, asserting that some online marketing to children by McDonald’s and four other well-known companies violates a federal law protecting children’s privacy.

The law, the Children’s Online Privacy Protection Act, requires Web site operators to obtain verifiable consent from parents before collecting personal information about children under age 13. But, in complaints to the F.T.C., the coalition says six popular Web sites aimed at children have violated that law by encouraging children who play brand-related games or engage in other activities to provide friends’ e-mail addresses — without seeking prior parental consent.

For more, visit www.nytimes.com.

Saturday, March 31, 2012

Government and advertisers have different ideas about 'Do Not Track' - The Hill's Hillicon Valley

The Obama administration and the technology industry have touted the creation of a "Do Not Track" button to help consumers protect their privacy online, but the government and advertisers are not on the same page about what the button will do.
The Federal Trade Commission first proposed a Do Not Track button in 2010. The concept is modeled on the agency's popular "Do Not Call" list, which allows consumers to opt out of receiving telemarketing calls.
FTC Chairman Jon Leibowitz urged Web companies to voluntarily set up a system for users to opt out of online tracking and warned that legislation could be necessary if they failed to act.

Last month, all of the major Web browsers promised to create a Do Not Track feature, and the Digital Advertising Alliance, a coalition of advertising trade groups, said that by the end of the year, they would stop displaying targeted ads to users who had selected the feature in their browsers.
The commitment was announced as part of the White House's unveiling of its "Privacy Bill of Rights" – a set of principles about how companies should handle users' personal data.
Leibowitz praised the companies for "stepping up" to his challenge and said the feature would ensure "consumers have greater choice and control over how they are tracked online."
But Mike Zaneis, general counsel of the Interactive Advertising Bureau, a member of the Digital Advertising Alliance, said the name "Do Not Track" is a "complete misnomer."
For more, click the link below:

Government and advertisers have different ideas about 'Do Not Track' - The Hill's Hillicon Valley

Tuesday, March 27, 2012

AVG Introduces "Do Not Track" Feature, Actively Protecting Consumer's Online Privacy

AVG INTRODUCES “DO NOT TRACK” FEATURE, ACTIVELY PROTECTING CONSUMER’S ONLINE PRIVACY

- AVG putting control over online privacy back in the hands of users -
AMSTERDAM 27 March, 2012 – AVG Technologies (NYSE: AVG), the provider of Internet and mobile security to approximately 108 million active users, today launched its active “Do Not Track” feature to the mainstream Internet security marketplace.
“This new feature is all about putting control of online privacy in the consumer’s hands. At AVG, we help provide Internet users with peace of mind---and today, making users aware of issues with online privacy is a logical extension of our community centric platform,” said JR Smith, CEO of AVG Technologies. “We believe all Internet users are entitled to know how their online data is collected and used---and they should have possible solutions available. At AVG, we are proud to continue to work on innovative technologies focused at supporting Internet users to protect and stay in control of their own online privacy.”
Today, it is common place for websites to collect data about users. While not inherently bad, some sites share user data with third parties---and consumers as well as policy makers, are growing increasingly concerned about this practice. For example, some forms of tracking allow advertisers to follow users around the Internet and deliver targeted advertising across multiple websites in ways consumers are unaware.
“We continue to listen to our approximately 108 million-strong community and we are constantly focused and driving our research and development to the creation of innovative technologies,” added AVG Technologies CEO JR Smith. “Today we deliver another important milestone with an active Do Not Track feature available in the latest version of AVG 2012 and through our latest product update for existing customers. This feature is available for free because we believe all consumers have the right to take back control of their online privacy.”
Last month, the Obama administration proposed a “Consumer Bill of Rights” for privacy and the EU has previously proposed similar initiatives. AVG’s Chief Policy Officer, Siobhan MacDermott, added: “AVG is assuming a leadership role in the future of consumer privacy, and is involved in policy discussions on both sides of the Atlantic. The reason AVG launched “Do Not Track” is that we believe consumers have a right to worry-free protection and control over their own online privacy.”
Passive “Do Not Track” was introduced by the World Wide Web Consortium (W3C) and relies on users’ voluntary adherence to this feature notification. This W3C Service Pack adds passive Do Not Track and is on by default. However, because compliance is voluntary, it doesn’t give the consumer real control over data collection. By contrast, AVG’s additional new and active “Do Not Track” feature brings online privacy control to mainstream consumers by informing them and offering the choice to block tracking directly or turn it on and off as desired.
New customers who purchase AVG's 2012 product and current customers who update AVG’s free and paid 2012 consumer security products with the new Service Pack will be automatically protected from sites and networks that invade their online privacy. At the same time, users can modify this default setting from within the user interface ---putting control firmly in the hands of consumers.
Another new Service Pack feature is WiFi Guard---offering protection from unknown WiFi access points. Laptops that are set to automatically connect to any available WiFi network are convenient when roaming, but can expose users to security risks. For example, cybercriminals can set up rogue WiFi access points using the name of a popular coffee shop chain, hotel or public WiFi provider, and then eavesdrop and breach consumer security. Now, after installing AVG’s 2012 Service Pack, a pop-up window automatically warns users if their device attempts to connect to a never-before-used public WiFi access point.
The Service Pack for AVG 2012 is available for free from www.avg.com/download for the following products:
  • AVG Premium Security 2012 - The only premium security software that actively seeks out identity theft.
  • AVG Internet Security 2012 - Ultimate protection for everything you do online.
  • AVG Anti-Virus 2012 - Exceptional protection that won’t get in your way.
  • AVG Anti-Virus FREE - The original FREE virus protection.
For more information on tracking, Do Not Track, WiFi Guard and other changes in the AVG 2012 Service Pack, please visit the AVG blog: blogs.avg.com/product-news
Visit the AVG Newsroom at: www.avg.com/press-releases-news
About AVG Technologies (NYSE: AVG)
AVG’s mission is to simplify, optimize and secure the Internet experience, providing peace of mind to a connected world. AVG’s powerful yet easy-to-use software and online services put users in control of their Internet experience. By choosing AVG’s software and services, users become part of a trusted global community that benefits from inherent network effects, mutual protection and support. AVG has grown its user base to approximately 108 million active users as of December 31, 2011 and offers a product portfolio that targets the consumer and small business markets and includes Internet security, PC performance optimization, online backup, mobile security, identity protection and family safety software.

F.T.C. Seeks Privacy Legislation

Excerpt from an article in

The New York Times
Tuesday, March 27, 2012

F.T.C. Seeks Privacy Legislation

By TANZINA VEGA and EDWARD WYATT

The government’s chief consumer protection agency said on Monday that it intended to take direct aim at the vast industry that has grown up around the buying and selling of information about American consumers.

The agency, the Federal Trade Commission, called on Congress to enact legislation regulating so-called data brokers, which compile and trade a wide range of personal and financial data about millions of consumers from online and offline sources. The legislation would give consumers access to information collected about them and allow them to correct and update such data.

The agency also sent a cautionary signal to technology and advertising companies regarding a “Do Not Track” mechanism that allows consumers to opt out of having their online behavior monitored and shared. It warned that if companies did not voluntarily provide a satisfactory Do Not Track option, it would support additional laws that mandate it.

The recommendations, part of a sweeping set of guidelines in an F.T.C. report on Monday, represent the government’s latest move to address the issue of consumer privacy.

On one side of the debate are data brokers like Experian and Acxiom, which collect and sell information, and the huge ecosystem of technology and online advertising companies — including Google, Microsoft and Facebook — that target consumers based on their personal preferences.

On the other side are consumer groups and privacy advocates that are concerned about the volume of data being collected and how little control consumers have over that information.

The government’s Do Not Track efforts are likely to collide with the desire of companies to continue the lucrative business of collecting, using and sharing information about the people who use their services. Although these businesses say they support limits on using this information, they generally still want to be able to collect it.

Monday, March 26, 2012

Senators Want Employers’ Facebook Password Requests Reviewed

Excerpt from an article in

The New York Times
Monday, March 26, 2012

Senators Want Employers’ Facebook Password Requests Reviewed

By THE ASSOCIATED PRESS

Two Democratic senators are asking Attorney General Eric H. Holder Jr. to investigate whether employers asking for Facebook passwords during job interviews are violating federal law, their offices announced Sunday.

Troubled by reports of the practice, Senators Charles E. Schumer of New York and Richard Blumenthal of Connecticut said they were calling on the Justice Department and the Equal Employment Opportunity Commission to begin investigations. The senators are sending letters to the heads of the agencies.

The Associated Press reported last week that some private and public agencies around the country were asking job seekers for their social media credentials. The practice has alarmed privacy advocates, but its legality remained murky.

On Friday, Facebook warned employers not to ask job applicants for their passwords, presumably so they could view applicant profiles on the site. The company threatened legal action against applications that violated its longstanding policy against sharing passwords.

A Facebook executive cautioned that if an employer discovered that a job applicant is a member of a protected group, the employer might be vulnerable to claims of discrimination if it did not hire that person.

Personal information such as gender, race, religion and age are often displayed on a Facebook profile — all details that are protected by federal employment law.

Not sharing passwords is a basic tenet of online conduct. Aside from the privacy concerns, Facebook considers the practice a security risk.

Friday, March 23, 2012

Google Faces Class-Action Lawsuits Over New Privacy Policy

Google faces consumer complaints in federal courts in New York and California that claim that its new privacy policy violates the company's earlier policies which promised that information provided by a user for one service would not be used by another service without the consumer's consent.
The Internet company is being charged in both lawsuits for violation of the Federal Wiretap Act, for wilful interception of communications and aggregation of personal information of its consumers for financial benefit, and the Stored Electronic Communications Act for exceeding its authorized access to consumer communications stored on its systems. Google is also charged with violation of the Computer Fraud Abuse Act, and other counts including state laws.
The plaintiffs in both suits seek to bring nationwide class action on behalf of holders of Google accounts and owners of Android devices from Aug. 19, 2004 to Feb. 29, 2012, who continued to maintain the Google accounts and own the devices after the new privacy policy came into effect on March 1 this year.

For more, click the link below:


http://www.pcworld.com/article/252332/google_faces_classaction_lawsuits_over_new_privacy_policy.html#tk.nl_bdx_h_crawl

Friday, March 16, 2012

House Dems demand meeting with Apple over privacy policy for iPhone, iPad apps - The Hill's Hillicon Valley

Two prominent House Democrats demanded a briefing with Apple over its privacy policies for mobile device applications in a letter to CEO Tim Cook on Thursday.
Apple had responded to questions from the two Democrats, Reps. Henry Waxman (Calif.) and G.K. Butterfield (N.C.), earlier this month, but the lawmakers were not satisfied.
For more, click the link below:

House Dems demand meeting with Apple over privacy policy for iPhone, iPad apps - The Hill's Hillicon Valley

Friday, March 2, 2012

Et Tu, Google?

The New York Times
Friday, March 02, 2012

Et Tu, Google? Android Apps Can Also Secretly Copy Photos 

By BRIAN X. CHEN and NICK BILTON

It's not just Apple. Photos are vulnerable on Android phones, too.

As Bits reported this week, developers who make applications for Apple iOS devices have access to a person's entire photo library as long as that person allows the app to use location data.

It turns out that Google, maker of the Android mobile operating system, takes it one step further. Android apps do not need permission to get a user's photos, and as long as an app has the right to go to the Internet, it can copy those photos to a remote server without any notice, according to developers and mobile security experts. It is not clear whether any apps that are available for Android devices are actually doing this.

The Apple and Android problems are a reminder of how hard it can be to ensure security on complex mobile devices that can run a vast array of apps. Android apps are required to alert users when they want to retrieve other kinds of personal data - like e-mail, address book contacts or a phone's location - so the lack of protection for photos came as a surprise to some experts.

"We can confirm that there is no special permission required for an app to read pictures," said Kevin Mahaffey, chief technology officer of Lookout, a company that makes Android security software. "This is based on Lookout's findings on all devices we've tested."

In response to questions, Google acknowledged this and said it would consider changing its approach.

Wednesday, February 29, 2012

Apple Loophole Gives Developers Access to Photos


Excerpt from an article in

The New York Times
Wednesday, February 29, 2012

Apple Loophole Gives Developers Access to Photos

By NICK BILTON

SAN FRANCISCO - The private photos on your phone may not be as private as you think.

Developers of applications for Apple's mobile devices, along with Apple itself, came under scrutiny this month after reports that some apps were taking people's address book information without their knowledge.

As it turns out, address books are not the only things up for grabs. Photos are also vulnerable. After a user allows an application on an iPhone, iPad or iPod Touch to have access to location information, the app can copy the user's entire photo library, without any further notification or warning, according to app developers.

It is unclear whether any apps in Apple's App Store are illicitly copying user photos. Although Apple's rules do not specifically forbid photo copying, Apple says it screens all apps submitted to the store, a process that should catch nefarious behavior on the part of developers. But copying address book data was against Apple's rules, and the company approved many popular apps that collected that information.

Apple did not respond to a request for comment.

The first time an application wants to use location data, for mapping or any other purpose, Apple's devices ask the user for permission, noting in a pop-up message that approval "allows access to location information in photos and videos." When the devices save photo and video files, they typically include the coordinates of the place they were taken - creating another potential risk.

"Conceivably, an app with access to location data could put together a history of where the user has been based on photo location," said David E. Chen, co-founder of Curio, a company that develops apps for iOS, Apple's mobile operating system. "The location history, as well as your photos and videos, could be uploaded to a server. Once the data is off of the iOS device, Apple has virtually no ability to monitor or limit its use."

Tuesday, February 28, 2012

Security, Privacy & Reliability

Microsoft Outlines Evolved Security, Privacy and Reliability Strategies for Cloud and Big Data
Trustworthy Computing Next advocates for continued focus amid new computing inflection points.
SAN FRANCISCO — Feb. 28, 2012 — Today at the RSA Conference 2012Scott Charney, corporate vice president of Microsoft Trustworthy Computing, shared his vision for the road ahead as society and computing intersect in an increasingly interconnected world. In a new paper, “Trustworthy Computing (TwC) Next,” Charney encouraged industry and governments to develop more effective privacy principles focused on use and accountability, improve end-to-end reliability of cloud services through increased fault modeling and standards efforts, and adopt more holistic security strategies including improved hygiene and greater attention to detection and containment.
Ten years ago, the computing ecosystem was at a crossroads when Bill Gates introduced TwC and called for industry collaboration. Today, technology and society are more interconnected than ever. Big data’s strain on privacy protection, the shifting relationship between government and the Internet, and the evolving threat model all raise new challenges for industry and governments globally.
“We are at another inflection point, with expectations for better security, privacy and reliability growing at an exponential rate,” Charney said. “Now is the time for industry and governments to develop and adopt strategies and policies that balance business and societal needs with individuals’ choices.”
The Cloud and Big Data
The proliferation of devices and cloud services has resulted in a massive aggregation of global data, also known as big data. While offering many potential societal benefits, this collection of data poses unique challenges. From a security perspective, big data represents a valuable target for attackers. As the cloud and devices become more integrated with society, people also become increasingly dependent on the reliability and availability of data and services to function. Finally, the massive increase in the amount and types of data available for collection, analysis and dissemination has strained traditional rules to protect privacy.
One solution for the privacy challenge is for government, industry, academia and consumer groups to collaborate in updating current privacy principles to address the world of big data. These revised principles should place a greater focus on appropriate uses of data. They should also include an “accountability” principle to help ensure organizations use and protect data in ways consistent with individual and societal expectations. Together, these principles can help reduce the burden on the consumer and shift greater responsibility to the data collector.
“Microsoft has long been a contributor to the global debate and discussion on the future of privacy,” said Malcolm Crompton, managing director of Information Integrity Solutions Pty Ltd. “The global framework proposed by Scott Charney tackles head-on many of the difficult realities of today’s environment. It’s a great contribution to the dialogue.”
The Role of Government
The advent of big data has also been challenging for governments. Any transformative technological change that recasts the way people live will engender deeper government engagement. This is because governments’ relationship with the Internet is a complex one. In the TwC Next white paper, Charney said governments globally are simultaneously users of the Internet, protectors of individual users as well as the Internet itself, and exploiters that capitalize on the power of technology for a variety of purposes.
In times of need, governments may use online services to keep citizens informed, and first responders can react more effectively than those not using cloud-based services because they have GPS devices, mapping capabilities, street views, videoconferencing and other cloud-based services. Such benefits only materialize, however, if these systems meet reasonable expectations of overall service reliability.
Recognizing this fact, governments may play an increasingly active role in many aspects of the Internet. Some nations are looking at legislatively mandating the adoption of information risk-management plans for those managing information and computing systems.
The Evolving Threat Landscape
While the quality of code has improved and infection rates have declined for products developed under Microsoft’s Security Development Lifecycle, the threat landscape continues to evolve. Opportunistic threats have been supplemented by attacks that are more persistent and, in many cases, far more worrisome. While some of these attacks have been called “Advanced Persistent Threats,” that term is often a misnomer. Some are advanced, but many are not; attack vectors are often traditional and unsophisticated. What marks these attacks is that the adversary is willing to persist over time and is firmly resolved to penetrate a particular victim.
“The new security challenges today are to some extent the same as the old security challenges. They’ve just been magnified,” said Alan Levine, chief information security officer at Alcoa Inc. “An organization may be targeted by a determined adversary who has the time, skills and tenacity to prevail.”
Companies must improve their basic hygiene approach to counter the opportunistic threats and make even persistent and determined adversaries work harder. This can be accomplished by designing systems not just to prevent attacks and recover from them, but also to detect successful attackers quickly and contain them so that their unauthorized access or disruption is limited. This new paradigm of protect, detect, contain and recover can serve as a practical foundation for managing risk in the age of persistent and determined adversaries.
More information about Microsoft’s vision for TwC Next is athttp://www.microsoft.com/presspass/presskits/security.
Founded in 1975, Microsoft (Nasdaq “MSFT”) is the worldwide leader in software, services and solutions that help people and businesses realize their full potential.

Monday, February 27, 2012

Facebook: Risk & Riches

Excerpt from an article in

The New York Times
Monday, February 27, 2012

For Facebook, Risk and Riches in User Data

By SOMINI SENGUPTA

SAN FRANCISCO — It is Facebook’s biggest conundrum. As the world’s largest social network, it faces intense scrutiny from consumers, courts and regulators worldwide over how it handles the data it collects from its 845 million users. But as a company preparing to go public, it is under pressure to find new ways to turn that data into profit.

The scrutiny is at its most intense in Europe. Regulators in Ireland, where Facebook has its European headquarters, have already demanded that it give users greater control over their information. A proposed Europe-wide law goes much further by requiring Facebook, along with every other online business, to expunge every bit of personal data at a consumer’s request.

In the United States, Facebook faces government audits for the next 20 years about how it collects and shares data, along with an assortment of lawsuits that accuse the company of tracking users across the Web. Even the White House stepped into the fray last week, demanding that Web companies give users more say in how their personal data is used.

Facebook is not the only company dealing with these issues, but it is especially vulnerable because its very business model relies on the fire hose of information that its users willingly share. “We are in very turbulent and unpredictable times when it comes to privacy regulations,” said J. Trevor Hughes, a lawyer who leads the International Association of Privacy Professionals. “We see regulators with a sense that something needs to be managed better, but without the tools.”

The result is a cloud of uncertainty for Facebook, which is expected to go public this spring. Among the risk factors listed in Facebook’s filing for a public offering is the prospect of “adverse changes in our products that are mandated by legislation, regulatory authorities, or litigation, including settlements or consent decrees.”

Monday, February 20, 2012

And the Privacy Gaps Just Keep On Coming

Excerpt from an article in The New York Times
Monday, February 20, 2012

And the Privacy Gaps Just Keep On Coming 

By NICK BILTON

SAN FRANCISCO -- Another week. Another privacy debacle.

This time, Apple is to blame. Yes, the company that has promoted itself as more private and secure than the other guys, with its stringent app approval process, has actually been handing out people's address books as if they were sausage samples on a toothpick at the supermarket.

Next week there will be another privacy slip. And again the week after. Like the movie "Groundhog Day," where the day repeats itself. Where the day repeats itself. Where the day repeats ... you get the point.

It might be Google, Amazon, Sony, Facebook or Apple, again. Or perhaps a small Silicon Valley start-up in such a rush to get its product out in the face of competition that it will focus more on designing the icon of its app, than ensuring users' privacy.

Imagine if a bank paid more attention to the color of the carpet in its lobby than the type of safe it uses to store its customers' valuables. No one would want to store anything there, that's for sure.

During the time it took to write this column, yet another privacy violation was reported. The Wall Street Journal said Friday that Google and other advertising companies bypassed privacy settings in Apple's Safari browser in order to track people's online behavior; three legislators called on the Federal Trade Commission to investigate. Google said it immediately moved to address the concerns.

Whose fault is all of this? We can't just point fingers at the companies that make iPhones, apps, social networking services and Web sites - although there are a lot of fingers that can be aimed in their direction. We're all somewhat to blame.

Monday, February 13, 2012

Anger for Path Social Network

Excerpt from an article in The New York Times
Monday, February 13, 2012

Anger for Path Social Network After Privacy Breach 

By NICK BILTON

Last week, Arun Thampi, a programmer in Singapore, discovered that the mobile social network Path was surreptitiously copying address book information from users' iPhones without notifying them.

David Morin, Path's voluble chief executive, quickly commented on Mr. Thampi's blog that Path's actions were an "industry best practice." He then became uncharacteristically quiet as the Internet disagreed and erupted in outrage. Amid his silence, he did take the time to reply to the actress Alyssa Milano, who was one of hundreds who questioned Path's practices. (His reply to her via Twitter contained his personal e-mail address.)

Mr. Morin seemed unconcerned about how people could be harmed by his company's carelessness. Consider this: Amira El Ahl, a foreign journalist covering the Middle East, said bloggers in Egypt and Tunisia are often approached online by people who are state security in disguise.

The most sought-after bounty for state officials: dissidents' address books, to figure out who they are in cahoots with, where they live and information about their family. In some cases, this information leads to roundups and arrests.

A person's contacts are so sensitive that Alec Ross, a senior adviser on innovation to Secretary of State Hillary Rodham Clinton, said the State Department was supporting the development of an application that would act as a "panic button" on a smartphone, enabling people to erase all contacts with one click if they are arrested during a protest.

Mr. Morin eventually did bow to pressure with an earnest apology on the company's blog. He said that Path would begin asking for permission before grabbing address books and that the company would destroy the data collected.

Thursday, February 9, 2012

Safer Internet Day


News release from IBM:


IBM Releases Free Internet Security Training Tools to Educate Students, Teachers and Parents on Digital Responsibility

IBMers Volunteer to Teach Students How to Protect their Personal Data in an Online Environment


ARMONK, N.Y. - 07 Feb 2012:  IBM (NYSE: IBM) today announced that in conjunction with Safer Internet Day, (#SID2012) it will release free Internet safety training tools for students and have thousands of volunteers working to help raise awareness and educate students and businesses on Internet safety and digital responsibility.
IBM is unveiling three free volunteer kits to better educate students, parents and teachers on Internet safety:
  • Control Your Online Identity  - A volunteer education kit, it is designed to help teenagers learn to protect personal data online and reputation online. Teenagers are typically savvy about how to use the Internet, but often unaware about what happens to personal data once it's shared. This presentation and volunteer information helps students learn how to protect personal data and control how they present themselves online.
  • Internet Safety Coaching - Aimed at teachers or adults working with children, this is a general primer on Internet safety providing basic information about common Internet activities by young people including instant messaging and social networking.   This kit is designed to raise awareness of Internet safety and how to have a meaningful and open dialogue with children on this topic.
  • Cyberbullying -- Aimed at parents or adults who work with children, this activity helps adults learn about how young people use the Internet today and how to recognize cyberbullying symptoms, how to prevent online bullying from happening and how to intervene if it does happen.
"IBMers are committed to helping educate people on ways to safely and securely use the Internet," said Harriet Pearson, IBM Security Counsel and Chief Privacy Officer. "The resources we are donating will help teachers and parents raise awareness that most Internet-based threats to individual and computer security can significantly be reduced by actions that informed users take themselves."
In conjunction with today's announcement, IBM volunteers around the world are educating communities about Internet safety. Some select activities include:
  • In Italy, an IBM team will conduct events in local schools using both the IBM materials and afilm from Safer Internet Day to discuss Internet safety and cyberbullying.
Last year IBM employees donated more than three million hours of volunteer service.  The company has donated 34 volunteer kits to help both IBMers as well as community members have meaningful activities and dialogues in the community about various issues.
Since its inception in 2004, Safer Internet Day interest has grown to reach all five continents and almost 80 countries, from Canada to South Korea and Russia to Kenya, including all 27 countries of the European Union. The goal of the day is to help make the Internet a better place for our children and young people.
About IBM
For more information on IBM volunteer and citizenship efforts, please visit www.citizenibm.com
About InsafeInsafe is the European Safer Internet awareness-raising network co-funded by the European Commission. It comprises national contact centres across the European Union and in Iceland, Norway and Russia, with partner organisations around the world. Insafe aims at empowering users to benefit from the positive aspects of internet whilst avoiding the potential risks. Further information is available at www.saferinternet.org or contact info-insafe@eun.org.
About Safer Internet Day
Safer Internet Day is part of a global drive by awareness-raising partners to promote a safer Internet for all users, especially young people. It is organised by INSAFE in the framework of the European Commission's Safer Internet Programme.

Sunday, January 29, 2012

Atlanta Man Sentenced on Computer Hacking Charge

Press release from the FBI, Atlanta Division:


Atlanta Man Sentenced on Computer Hacking Charge
McNeal Illegally Accessed Database of Competitor’s Medical Practice

U.S. Attorney’s Office January 10, 2012
  • Northern District of Georgia (404) 581-6000


ATLANTA—ERIC McNEAL, 38, of Atlanta, Georgia, was sentenced today by United States District Judge Willis B. Hunt, Jr. for intentionally accessing a protected computer of a competing medical practice without authorization, including personal information of the patients, in order to send marketing materials to these patients.

United States Attorney Sally Quillian Yates said, “Anyone who gives their personal information to a doctor or medical facility does not expect that their information will be hacked and used to make money. The cost of medical care is already high enough without patients having to pay a heavier cost with the loss of their privacy. This is cybercrime. Electronic information is bought, sold and stolen, often by someone who knows a system and, with a few keystrokes, makes our community vulnerable.”

McNEAL was sentenced to one year and one month in prison, to be followed by three years of supervised release, and was ordered to perform 120 hours of community service. McNEAL pleaded guilty to the charge on September 28, 2011.

According to United States Attorney Yates, the charge,s and other information presented in court: McNEAL worked as an information technology specialist for “A.P.A.,” a perinatal medical practice in Atlanta.

McNEAL separated from employment with A.P.A. in November 2009, and subsequently joined a competing perinatal medical practice, which was located in the same building as A.P.A. In April 2010, MCNEAL used his home computer to hack into A.P.A.’s patient database without authorization. MCNEAL downloaded the names, telephone numbers, and addresses of A.P.A.’s patients, and then “wiped” A.P.A.’s database, deleting all the patient information from A.P.A.’s system. McNEAL subsequently used the patient names and contact information to launch a direct-mail marketing campaign for the benefit of his new employer. There is no evidence that McNEAL downloaded or misused specific patient medical information.

This case was investigated by special agents of the Federal Bureau of Investigation.