<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Michael Howard's Web Log : Privacy</title><link>http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx</link><description>Tags: Privacy</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Kim Cameron on GOOGs single sign on design vulnerability</title><link>http://blogs.msdn.com/michael_howard/archive/2008/09/15/kim-cameron-on-goog-single-sign-on-their-sso-design-vulnerability.aspx</link><pubDate>Mon, 15 Sep 2008 16:25:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8952545</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/8952545.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=8952545</wfw:commentRss><description>I spoke with &lt;A href="http://www.identityblog.com/" mce_href="http://www.identityblog.com"&gt;Kim Cameron&lt;/A&gt; a few days ago about Google's single sign-on (SSO) &lt;A href="http://www.ai-lab.it/armando/pub/fmse9-armando.pdf" mce_href="http://www.ai-lab.it/armando/pub/fmse9-armando.pdf"&gt;design bug&lt;/A&gt;. I wanted his take on the bug because he's one of the best in the area of identity, single sign-on etc etc... &lt;A href="http://www.identityblog.com/?p=1011" mce_href="http://www.identityblog.com/?p=1011"&gt;his response&lt;/A&gt; can only be described as scathing. &lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8952545" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Rant/default.aspx">Rant</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Reminder: Microsoft Security Intelligence Report - Webcast on Wed 7 Nov</title><link>http://blogs.msdn.com/michael_howard/archive/2007/11/06/reminder-microsoft-security-intelligence-report-webcast-on-wed-7-nov.aspx</link><pubDate>Wed, 07 Nov 2007 02:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5947320</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/5947320.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=5947320</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Calibri size=3&gt;Wednesday, November 07, 2007 10:00 AM Pacific Time&lt;/FONT&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-fareast-theme-font: minor-latin"&gt;&lt;A href="http://support.microsoft.com/kb/942698/en-us"&gt;&lt;FONT color=#0000ff&gt;Support WebCast: Microsoft Security Intelligence Report: Latest trends in vulnerabilities, malware, and potentially unwanted software&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5947320" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Privacy Tip o' the Day</title><link>http://blogs.msdn.com/michael_howard/archive/2007/08/08/privacy-tip-o-the-day.aspx</link><pubDate>Wed, 08 Aug 2007 18:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4294273</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>18</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/4294273.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=4294273</wfw:commentRss><description>&lt;P&gt;I'm stunned at how much private data the average citizen will divulge. I was buying some stuff yesterday, and the clerk at the checkout asked the customer in front of me for her phone #, which she was quite happy to give. Next, I was signing up for gym membership, and the guy in front of me wrote his social security number on the membership form! Why on earth does a gym need your sosh?&lt;/P&gt;
&lt;P&gt;So here's what I do.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Check-out clerk: "Can I please have your phone number?"&lt;BR&gt;Me: "It's unlisted"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I have never had a single issue with this line, and it's not as argumentative as, "no, drop dead."&lt;/P&gt;
&lt;P&gt;As for SSN.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Gym Membership guy: "You didn't complete the form, I need your SSN."&lt;BR&gt;Me: "How will my SSN be used?"&lt;BR&gt;Gym Membership guy: "I don't know."&lt;BR&gt;Me: "I bet it's not needed."&lt;BR&gt;Gym Membership guy: "You're probably right"&lt;BR&gt;Me: "Ok, let's leave it blank for the time being."&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;End of story. Again I'm being civil, and leaving it open ended, even though I have no intention of supplying my National Identity Number, oops, I mean social security number.&lt;/P&gt;
&lt;P&gt;In the rare case where someone thinks they REALLY need my sosh and I don't think they do, I'll enter my SSN but flip a bunch of numbers around, I take advantage of the fact&amp;nbsp;there's no checksum digit in a SSN! :)&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=4294273" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Personal/default.aspx">Personal</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/General/default.aspx">General</category></item><item><title>A Chronology of Data Breaches</title><link>http://blogs.msdn.com/michael_howard/archive/2006/09/22/766875.aspx</link><pubDate>Fri, 22 Sep 2006 23:14:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:766875</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/766875.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=766875</wfw:commentRss><description>&lt;p&gt;A fascinating read http://www.privacyrights.org/ar/ChronDataBreaches.htm.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=766875" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>SDL book is shipping!</title><link>http://blogs.msdn.com/michael_howard/archive/2006/06/02/614434.aspx</link><pubDate>Fri, 02 Jun 2006 20:28:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:614434</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/614434.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=614434</wfw:commentRss><description>&lt;P&gt;I have in my paws a copy of the Security Development Lifecycle book... :) And I am told boxes of books are on the way to warehouses right now! It's always great to see the physical bits!&lt;/P&gt;&lt;BR&gt;&lt;IMG src="http://www.microsoft.com/MSPress/books/imgt/8753.gif"&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=614434" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Privacy Breach Impact Calculator</title><link>http://blogs.msdn.com/michael_howard/archive/2006/05/07/592146.aspx</link><pubDate>Mon, 08 May 2006 08:17:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:592146</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/592146.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=592146</wfw:commentRss><description>&lt;P&gt;Cute!&lt;/P&gt;
&lt;P&gt;&lt;A href="http://searchsecurity.techtarget.com/general/0,295582,sid14_gci1182844,00.html?track=NL-430&amp;amp;ad=551180"&gt;http://searchsecurity.techtarget.com/general/0,295582,sid14_gci1182844,00.html?track=NL-430&amp;amp;ad=551180&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=592146" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>MSN Phishing and Scams site</title><link>http://blogs.msdn.com/michael_howard/archive/2004/12/20/327558.aspx</link><pubDate>Mon, 20 Dec 2004 21:36:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:327558</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/327558.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=327558</wfw:commentRss><description>Just gone live, you should point friends and family to this: &lt;a href="http://safety.msn.com/phishing/"&gt;http://safety.msn.com/phishing/&lt;/a&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=327558" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Finally, a book on Privacy for Developers</title><link>http://blogs.msdn.com/michael_howard/archive/2004/10/13/241890.aspx</link><pubDate>Wed, 13 Oct 2004 18:55:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:241890</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/241890.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=241890</wfw:commentRss><description>&lt;p&gt;My good friend J.C. Cannon has written &lt;strong&gt;&lt;u&gt;the&lt;/u&gt;&lt;/strong&gt; book on Privacy aimed squarely at developers, as well as IT folks. While I, and many others, focus on security, J.C. and his team address privacy issues. I think most people consider the two disciplines kinda the same, they are quite different, and I would urge you to get a copy of the book if your application deals in any way with private data.&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.amazon.com/exec/obidos/tg/detail/-/0321224094"&gt;http://www.amazon.com/exec/obidos/tg/detail/-/0321224094&lt;/a&gt;&lt;/p&gt; &lt;p&gt;BTW, J.C.bought me a very nice bottle of &lt;a href="http://www.wine-lovers-page.com/wines/tn.phtml?id=369"&gt;Cloudy Bay 2003 Sauvignon Blanc&lt;/a&gt;&amp;nbsp;recently.&amp;nbsp;I'll open&amp;nbsp;it in nine months. Yum, yum! And no, I'm not gonna share it with anyone but my wife. So don't ask!&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=241890" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Windows XP SP2 Privacy Statements Released</title><link>http://blogs.msdn.com/michael_howard/archive/2004/08/16/215299.aspx</link><pubDate>Mon, 16 Aug 2004 20:01:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:215299</guid><dc:creator>michael_HOWARD</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/michael_howard/comments/215299.aspx</comments><wfw:commentRss>http://blogs.msdn.com/michael_howard/commentrss.aspx?PostID=215299</wfw:commentRss><description>&lt;p class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;span style="FONT-SIZE: 9pt; FONT-FAMILY: Arial"&gt;The Windows Privacy Statement highlights 27 components that have historically been of interest to privacy advocates and customers, and the 6 page IE Privacy Statement highlights some of the new IE features including “Pop up Blocker”, “Untrusted Publishers”, and “Managed Add-ons”.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;p class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;span style="FONT-SIZE: 9pt; FONT-FAMILY: Arial"&gt;The statements, along with new Group Policy privacy controls are available at the links below.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt; &lt;div class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;a title="http" href="http://www.microsoft.com/windowsxp/downloads/updates/sp2/docs/privacy.mspx"&gt;http://www.microsoft.com/windowsxp/downloads/updates/sp2/docs/privacy.mspx&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;a title="http" href="http://www.microsoft.com/windowsxp/downloads/updates/sp2/docs/privacy_ie.mspx"&gt;http://www.microsoft.com/windowsxp/downloads/updates/sp2/docs/privacy_ie.mspx&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=215299" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/michael_howard/archive/tags/Privacy/default.aspx">Privacy</category></item></channel></rss>