Presentation is loading. Please wait.

Presentation is loading. Please wait.

Copyright JNT Association 2009NorduNET, 18 th September 20091 Protecting Privacy in Global Networks Andrew Cormack Chief Regulatory Adviser, JANET(UK)

Similar presentations


Presentation on theme: "Copyright JNT Association 2009NorduNET, 18 th September 20091 Protecting Privacy in Global Networks Andrew Cormack Chief Regulatory Adviser, JANET(UK)"— Presentation transcript:

1 Copyright JNT Association 2009NorduNET, 18 th September 20091 Protecting Privacy in Global Networks Andrew Cormack Chief Regulatory Adviser, JANET(UK) Andrew.Cormack@ja.net

2 Copyright JNT Association 2009NorduNET, 18 th September 20092 Privacy or Secrecy “On the Internet no one knows you’re a dog” – Right? Secrecy = no use of information Privacy = person-controlled use of information But sometimes we want people to know stuff

3 Copyright JNT Association 2009NorduNET, 18 th September 20093 Controlled disclosure “Animal” “Dog” – so I get the right food in a bar – attribute “Same dog” – so I get into the apartment – recognition “Fido” – so I get fed at home – identification

4 Copyright JNT Association 2009NorduNET, 18 th September 20094 ? What is Privacy, anyway?

5 Copyright JNT Association 2009NorduNET, 18 th September 20095 ?

6 Copyright JNT Association 2009NorduNET, 18 th September 20096 Real-world privacy leaks! “Dog” + “Alsatian”

7 Copyright JNT Association 2009NorduNET, 18 th September 20097 Real-world privacy leaks! “Can pay” + Name + Affiliation

8 Copyright JNT Association 2009NorduNET, 18 th September 20098 Real-world privacy leaks! “Can drive” + Name + Date of Birth + Where born + Where living + Signature = Theft kit = Identity theft kit

9 Copyright JNT Association 2009NorduNET, 18 th September 20099 On-line: can do better Give me access Save stuff for my next visit Find me in other systems Bill me? Punish me? js56 cfa1 2e0b

10 Copyright JNT Association 2009NorduNET, 18 th September 200910 How to use privacy tools? Real world experience is a poor guide –Don’t import “leak and label” Law may say how to use technology –“how fast can I drive in Denmark?” –“which side of the road?”

11 Copyright JNT Association 2009NorduNET, 18 th September 200911 Lots of Privacy Law, but... Is amount of tax paid private data? YES!NO!

12 Copyright JNT Association 2009NorduNET, 18 th September 200912 YES!NO! Lots of Privacy Law, but... Is a web server log private data?

13 Copyright JNT Association 2009NorduNET, 18 th September 200913 Lots of Privacy Law, but... Who owns your private data? ME!YOU!

14 Copyright JNT Association 2009NorduNET, 18 th September 200914 Doing Privacy Right Privacy = “subject-controlled use” So, from that definition –Don’t cause of loss of control Either deliberately or accidentally Data/use minimisation => risk minimisation –Tell subject what you will do What uses they control and what they don’t –Build privacy into systems Identification as last (exceptional) resort

15 Copyright JNT Association 2009NorduNET, 18 th September 200915 Separation of Roles Separating identification is good Maybe separate credential issue too? –First get a (generic) on-line credential –Then use it to enrol with a particular service –As in PGP, sort of Result: SSO with better privacy –No “central database” of attributes or links –Services choose own enrolment standard Up to limit set by credential issue/use

16 Copyright JNT Association 2009NorduNET, 18 th September 200916


Download ppt "Copyright JNT Association 2009NorduNET, 18 th September 20091 Protecting Privacy in Global Networks Andrew Cormack Chief Regulatory Adviser, JANET(UK)"

Similar presentations


Ads by Google