<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>JaBbA's Hut - Privacy &amp; Identity</title>
    <link>http://jalcorn.net/weblog/</link>
    <description>White Hat Liberal Geek Dad</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Thu, 29 Jun 2006 19:37:35 GMT</pubDate>

    <image>
        <url>http://jalcorn.net/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: JaBbA's Hut - Privacy &amp; Identity - White Hat Liberal Geek Dad</title>
        <link>http://jalcorn.net/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Good news, bad news</title>
    <link>http://jalcorn.net/weblog/archives/1006-Good-news,-bad-news.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/1006-Good-news,-bad-news.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1006</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1006</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The good news: The laptop containing the private VA records of 26 million veterans &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jYnNuZXdzLmNvbS9zdG9yaWVzLzIwMDYvMDYvMjkvbmF0aW9uYWwvbWFpbjE3NjM3NTEuc2h0bWw=&amp;amp;entry_id=1006&quot; title=&quot;http://www.cbsnews.com/stories/2006/06/29/national/main1763751.shtml&quot;  onmouseover=&quot;window.status=&#039;http://www.cbsnews.com/stories/2006/06/29/national/main1763751.shtml&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;has been recovered&lt;/a&gt;, and it appears that the thief never got access to the data.&lt;br /&gt;
&lt;br /&gt;
The bad news: This was not a matter of an employee violating policy.  Someone gave this guy permission to take a laptop full of private information home.  Clearly, government entities haven&#039;t gotten the message that identity information protection is critically important.  And if the goverment doesn&#039;t get it, neither does private industry.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Newly discovered documents show that the VA analyst blamed for losing the laptop had received permission in 2002 to work from home on data from included millions of Social Security numbers on a laptop from home.&lt;br /&gt;
&lt;br /&gt;
&quot;From the start, the VA has acted as if the theft was a PR problem that had to be managed, not fully confronted,&quot; said Rep. Bob Filner, D-Calif. &quot;They&#039;re trying to pin it on this one guy, but I think it&#039;s other people we need to be looking at.&quot; &lt;/blockquote&gt; 
    </content:encoded>

    <pubDate>Thu, 29 Jun 2006 15:32:16 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1006-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>If you aren't doing anything wrong...</title>
    <link>http://jalcorn.net/weblog/archives/1000-If-you-arent-doing-anything-wrong....html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/1000-If-you-arent-doing-anything-wrong....html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1000</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1000</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Bruce Schneier has published an article succinctly stating the case for why &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53aXJlZC5jb20vbmV3cy9jb2x1bW5zLzAsNzA4ODYtMC5odG1s&amp;amp;entry_id=1000&quot;  onmouseover=&quot;window.status=&#039;http://www.wired.com/news/columns/0,70886-0.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; title=&quot;Wired&quot;&gt;privacy rights are so important&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;The most common retort against privacy advocates -- by those in favor of ID checks, cameras, databases, data mining and other wholesale surveillance measures -- is this line: &quot;If you aren&#039;t doing anything wrong, what do you have to hide?&quot;&lt;br /&gt;
&lt;br /&gt;
Some clever answers: &quot;If I&#039;m not doing anything wrong, then you have no cause to watch me.&quot; &quot;Because the government gets to define what&#039;s wrong, and they keep changing the definition.&quot; &quot;Because you might do something wrong with my information.&quot; My problem with quips like these -- as right as they are -- is that they accept the premise that privacy is about hiding a wrong. It&#039;s not. Privacy is an inherent human right, and a requirement for maintaining the human condition with dignity and respect.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
JaBbA says &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53aXJlZC5jb20vbmV3cy9jb2x1bW5zLzAsNzA4ODYtMC5odG1s&amp;amp;entry_id=1000&quot;  onmouseover=&quot;window.status=&#039;http://www.wired.com/news/columns/0,70886-0.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Wired&quot;&gt;check it out&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Fri, 16 Jun 2006 13:08:09 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1000-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Opting Out</title>
    <link>http://jalcorn.net/weblog/archives/977-Opting-Out.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/977-Opting-Out.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=977</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=977</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    After doing some research, I&#039;m going to try to see if &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cHM6Ly93d3cub3B0b3V0cHJlc2NyZWVuLmNvbS8=&amp;amp;entry_id=977&quot; title=&quot;https://www.optoutprescreen.com/&quot;  onmouseover=&quot;window.status=&#039;https://www.optoutprescreen.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;OptOutPrescreen.com&lt;/a&gt; really works.  It&#039;s not a phishing scam, it&#039;s a legitimate site run by the credit bureaus.  It asks for a lot of info, but of course, they already have that info.  The Privacy Policy gave me a little pause (see extended entry) but it really doesn&#039;t give them any more rights to your info than they already have.  &lt;br /&gt;
&lt;br /&gt;
I&#039;ll try to track just how many &quot;pre-approved&quot; offers I get over the coming months - word is this will take about 2 months.  Then we&#039;ll see if this really works.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://jalcorn.net/weblog/archives/977-Opting-Out.html#extended&quot;&gt;Continue reading &quot;Opting Out&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 28 Mar 2006 11:03:52 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/977-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>IN HIS FREAKIN' CAR!!!!</title>
    <link>http://jalcorn.net/weblog/archives/957-IN-HIS-FREAKIN-CAR!!!!.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/957-IN-HIS-FREAKIN-CAR!!!!.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=957</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=957</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    It just boggles the mind that &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jb21wdXRlcndvcmxkLmNvbS9zZWN1cml0eXRvcGljcy9zZWN1cml0eS9wcml2YWN5L3N0b3J5LzAsMTA4MDEsMTA4MTAxLDAwLmh0bWw=&amp;amp;entry_id=957&quot; title=&quot;http://www.computerworld.com/securitytopics/security/privacy/story/0,10801,108101,00.html&quot;  onmouseover=&quot;window.status=&#039;http://www.computerworld.com/securitytopics/security/privacy/story/0,10801,108101,00.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;people can be so careless&lt;/a&gt;....&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt; About 365,000 hospice and home health care patients in Oregon and Washington are being notified about the theft of computer backup data disks and tapes late last month that included personal information and confidential medical records.&lt;br /&gt;
&lt;br /&gt;
In an announcement yesterday, Providence Home Services, a division of Seattle-based Providence Health Systems, said the records and other data were on several disks and tapes stolen from the car of a Providence employee at his home. &lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
They say the data is encrypted and in proprietary formats.  I really hope so. 
    </content:encoded>

    <pubDate>Fri, 27 Jan 2006 02:09:08 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/957-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Haven't we heard of this company before?</title>
    <link>http://jalcorn.net/weblog/archives/944-Havent-we-heard-of-this-company-before.html</link>
            <category>Boos</category>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/944-Havent-we-heard-of-this-company-before.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=944</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=944</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The idea of a mega-database is &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2dvdmV4ZWMuY29tL3N0b3J5X3BhZ2UuY2ZtP2FydGljbGVpZD0zMjgwMiZwcmludGVyZnJpZW5kbHlWZXJzPTEm&amp;amp;entry_id=944&quot;  onmouseover=&quot;window.status=&#039;http://govexec.com/story_page.cfm?articleid=32802&amp;amp;printerfriendlyVers=1&amp;amp;&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;www.govexec.com&quot;&gt;Bad Enough&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;To help the government track suspected terrorists and spies who may be visiting or residing in this country, the FBI and the Defense Department for the past three years have been paying a Georgia-based company for access to its vast databases that contain billions of personal records about nearly every person -- citizens and noncitizens alike -- in the United States.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
But the name of that Georgia Company?&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5wcml2YWN5cmlnaHRzLm9yZy9hci9DUFJlc3BvbnNlLmh0bQ==&amp;amp;entry_id=944&quot;  onmouseover=&quot;window.status=&#039;http://www.privacyrights.org/ar/CPResponse.htm&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;PrivacyRights.org&quot;&gt;Choicepoint&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;32,000 consumers personal information including names, addresses and Social Security numbers were illegally accessed by using the user name and passwords of a company that has a contract with the data aggregator.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 18 Nov 2005 18:44:38 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/944-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>But What's the Harm?</title>
    <link>http://jalcorn.net/weblog/archives/941-But-Whats-the-Harm.html</link>
            <category>Hoaxes</category>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/941-But-Whats-the-Harm.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=941</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=941</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    This email has been making the rounds:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;br /&gt;
Check this out:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is upsetting but I thought I should pass it along.  Check your&lt;br /&gt;
drivers license.  Now you can see anyone&#039;s Driver&#039;s License on the&lt;br /&gt;
Internet, including your own!  I just searched for mine and there it&lt;br /&gt;
was.. . picture and all!!  Thanks Homeland Security!   Where are our&lt;br /&gt;
rights?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I definitely removed mine.  I suggest you do the same.&lt;br /&gt;
Go to the web site and check it out.  Just enter your name, city and&lt;br /&gt;
state to see if yours is on file.  After your license comes on the&lt;br /&gt;
screen, click the box marked &quot;Please Remove&quot;.  This will remove it&lt;br /&gt;
from public viewing, but not from law enforcement.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
It&#039;s followed by a URL  Go to the URL, and you get a screen including this form:&lt;br /&gt;
&lt;br /&gt;
&lt;img width=&quot;110&quot; height=&quot;88&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/dlsearch.serendipityThumb.PNG&quot; alt=&quot;&quot;  /&gt;Seems safe enough, just name, state and city, right?  And it&#039;s a joke...&lt;br /&gt;
&lt;br /&gt;
So why has it been reported as a Phishing site?  Why is it blocked by the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3Rvb2xiYXIubmV0Y3JhZnQuY29tLw==&amp;amp;entry_id=941&quot; title=&quot;http://toolbar.netcraft.com/&quot;  onmouseover=&quot;window.status=&#039;http://toolbar.netcraft.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Netcraft Toolbar&lt;/a&gt;?&lt;br /&gt;
&lt;br /&gt;
Well, think about it.  You have just &lt;br /&gt;
&lt;br /&gt;
- Given someone some information about yourself&lt;br /&gt;
- Shown yourself to be willing to click on links in emails sent to you&lt;br /&gt;
&lt;br /&gt;
Spammers and Phishers have a LOT of information about you.  You think they can&#039;t link that info you just gave to your email address?  Dream on.  I&#039;d almost guarantee that spreading this hoax is helping spammers build better, more effective lists.  And I wouldn&#039;t be suprised if a lot of people doing this find themselves the target of a Phishing attack - using a bank specifically in your city.&lt;br /&gt;
&lt;br /&gt;
DON&#039;T forward jokes, you never know what&#039;s behind them. 
    </content:encoded>

    <pubDate>Wed, 09 Nov 2005 12:04:19 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/941-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>SEC Warning</title>
    <link>http://jalcorn.net/weblog/archives/938-SEC-Warning.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/938-SEC-Warning.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=938</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=938</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The SEC has just come out with a warning to &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zZWMuZ292L25ld3MvcHJlc3MvMjAwNS0xNTguaHRt&amp;amp;entry_id=938&quot; title=&quot;http://www.sec.gov/news/press/2005-158.htm&quot;  onmouseover=&quot;window.status=&#039;http://www.sec.gov/news/press/2005-158.htm&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;protect your online investment accounts&lt;/a&gt;.  Apparently people are &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5idXNpbmVzc3dlZWsuY29tL3RlY2hub2xvZ3kvY29udGVudC9ub3YyMDA1L3RjMjAwNTExMDNfNTY1MTUwLmh0bQ==&amp;amp;entry_id=938&quot; title=&quot;http://www.businessweek.com/technology/content/nov2005/tc20051103_565150.htm&quot;  onmouseover=&quot;window.status=&#039;http://www.businessweek.com/technology/content/nov2005/tc20051103_565150.htm&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;losing thousands of dollars&lt;/a&gt; to thieves armed with keyloggers. 
    </content:encoded>

    <pubDate>Thu, 03 Nov 2005 15:57:38 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/938-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>The Root Identity</title>
    <link>http://jalcorn.net/weblog/archives/936-The-Root-Identity.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/936-The-Root-Identity.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=936</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=936</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The news in the ID Management world for some months now has been the UK Government&#039;s plans for a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2VjbGVjdGVjaC5jby51ay9jbGFya2VpZGNhcmRzLnBocA==&amp;amp;entry_id=936&quot; title=&quot;http://eclectech.co.uk/clarkeidcards.php&quot;  onmouseover=&quot;window.status=&#039;http://eclectech.co.uk/clarkeidcards.php&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;National Identity Database&lt;/a&gt;.  It is almost universally reviled for it&#039;s obvious potential for abuse and the fears of using the wrong technology.&lt;br /&gt;
&lt;br /&gt;
I just finished reading a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jaGktcHVibGlzaGluZy5jb20vP3N0YXRpY0lEPTA=&amp;amp;entry_id=936&quot; title=&quot;http://www.chi-publishing.com/?staticID=0&quot;  onmouseover=&quot;window.status=&#039;http://www.chi-publishing.com/?staticID=0&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;fascinating article&lt;/a&gt;, in plain english, about the need for, and characteristics of, a &lt;i&gt;Root Identity&lt;/i&gt; system.  Talking about what an eID &lt;i&gt;should&lt;/i&gt; be:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;If you adopt this line of reasoning you find that in order to function in this capacity the eID must have some specific properties:&lt;br /&gt;
&lt;br /&gt;
    - it must be able to bind out to other processes&lt;br /&gt;
    - it must specifically be able to facilitate an irrefutable link between its user and itself&lt;br /&gt;
    - it must be able to participate in authorisation procedures, in my view without leaking any identity information - helping to answer the question: is this individual allowed to do this in this context? In most cases you do not need identification to answer this type of question&lt;br /&gt;
    - it should be able to facilitate authentication processes without compromising identity - allowing anonymity or pseudonymity most of the time is a fundamental requirement of any eID system in a free society&lt;br /&gt;
    - it should be able to uniquely represent the legitimate holder (and only the legitimate holder) in public key cryptographic protocols - a consequence of the two points above&lt;br /&gt;
    - it should be able to participate in identification processes if identification is required and legitimate&lt;br /&gt;
    - it must not depend on irreplaceable personal characteristics, in the sense that the system as such must be able to cope with the problem of compromised or lost/changed characteristics&lt;br /&gt;
    - the token containing the eID must be replaceable without unwanted consequences, or as a corollary, theft or loss of a token must not enable impersonation&lt;br /&gt;
    - all its functions, including any disclosure of information in the token, must be fully controlled by the owner&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
Basically, an eID should provide &lt;i&gt;Authorization&lt;/i&gt; for most activities (buying Alcohol, Using a credit card) and &lt;i&gt;Authentication&lt;/i&gt; when appropriate (Applying for credit, questioning by authorities) without ever giving out &lt;u&gt;any&lt;/u&gt; information without the holder&#039;s consent.  A huge challenge.&lt;br /&gt;
&lt;br /&gt;
At the same time, the token needs to be able to be used by the owner, under any circumstances.   The conclusion is that there is only one biometric that is unchanging through life, will not be affected by injury or age, and is irrefutable - &lt;i&gt;DNA&lt;/i&gt;.  There are huge security and technological challenges to using DNA as the bases for an eID, but it will eventually become the only solution.&lt;br /&gt;
&lt;br /&gt;
JaBbA says check it out.  From &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5pZGVudGl0eWJsb2cuY29tLzIwMDUvMTAvMzAuaHRtbCNhMzYz&amp;amp;entry_id=936&quot; title=&quot;http://www.identityblog.com/2005/10/30.html#a363&quot;  onmouseover=&quot;window.status=&#039;http://www.identityblog.com/2005/10/30.html#a363&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Kim Cameron&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Thu, 03 Nov 2005 10:18:56 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/936-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Stolen personal data found on spyware server</title>
    <link>http://jalcorn.net/weblog/archives/919-Stolen-personal-data-found-on-spyware-server.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/919-Stolen-personal-data-found-on-spyware-server.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=919</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=919</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zdW5iZWx0LXNvZnR3YXJlLmNvbS8=&amp;amp;entry_id=919&quot; title=&quot;http://www.sunbelt-software.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.sunbelt-software.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Sunbelt Software&lt;/a&gt; has &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jb21wdXRlcndvcmxkLmNvbS9zZWN1cml0eXRvcGljcy9zZWN1cml0eS9zdG9yeS8wLDEwODAxLDEwMzczNywwMC5odG1s&amp;amp;entry_id=919&quot; title=&quot;http://www.computerworld.com/securitytopics/security/story/0,10801,103737,00.html&quot;  onmouseover=&quot;window.status=&#039;http://www.computerworld.com/securitytopics/security/story/0,10801,103737,00.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;handed over to the FBI&lt;/a&gt; a large file it recovered from a server which contained large amounts of very sensitive data stolen by CoolWebSearch spyware:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Sunbelt&#039;s research showed that the information being uploaded to the remote server included chat sessions, user names, passwords and bank information, he said. The bank information included details on one company bank account with more than $350,000 in deposits and another belonging to a small California company with over $11,000 in readily accessible cash, he said.&lt;br /&gt;
&lt;br /&gt;
Many of the records being uploaded also contained eBay account information, he said. Among the highly personal bits of information Sunbelt was able to retrieve from the server were one family&#039;s vacation plans, instructions to a limo driver to pick up passengers from an airport and details about one computer user with a penchant for pedophilia. &lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 09 Aug 2005 12:25:11 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/919-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Confused about why a National ID card is a bad thing?</title>
    <link>http://jalcorn.net/weblog/archives/912-Confused-about-why-a-National-ID-card-is-a-bad-thing.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/912-Confused-about-why-a-National-ID-card-is-a-bad-thing.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=912</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=912</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Well, Mr. Doghorse has an &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2VjbGVjdGVjaC5jby51ay9jbGFya2VpZGNhcmRzLnBocA==&amp;amp;entry_id=912&quot; title=&quot;http://eclectech.co.uk/clarkeidcards.php&quot;  onmouseover=&quot;window.status=&#039;http://eclectech.co.uk/clarkeidcards.php&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;entertaining comment&lt;/a&gt; - and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5pZC11bmtub3duLmNvLnVrLw==&amp;amp;entry_id=912&quot; title=&quot;http://www.id-unknown.co.uk/&quot;  onmouseover=&quot;window.status=&#039;http://www.id-unknown.co.uk/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;an informative site&lt;/a&gt; - on the British National ID Card.&lt;br /&gt;
&lt;br /&gt;
Link from &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vYmxvZy9hcmNoaXZlcy8yMDA1LzA3L2FfY29tbWVudF9vbl90aC5odG1s&amp;amp;entry_id=912&quot; title=&quot;http://www.schneier.com/blog/archives/2005/07/a_comment_on_th.html&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/blog/archives/2005/07/a_comment_on_th.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Bruce Schneier&lt;/a&gt;, and then his next entry was on how hard it is to actually find out if &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vYmxvZy9hcmNoaXZlcy8yMDA1LzA3L25vdGljaW5nX2RhdGFfbS5odG1s&amp;amp;entry_id=912&quot; title=&quot;http://www.schneier.com/blog/archives/2005/07/noticing_data_m.html&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/blog/archives/2005/07/noticing_data_m.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;database data is misused&lt;/a&gt;, which is of course a wholly appropriate followup. 
    </content:encoded>

    <pubDate>Tue, 05 Jul 2005 16:32:33 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/912-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>FTC kills Spykiller</title>
    <link>http://jalcorn.net/weblog/archives/910-FTC-kills-Spykiller.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/910-FTC-kills-Spykiller.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=910</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=910</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The &quot;Free&quot; spyware scans advertised on the Internet, which I&#039;ve been warning about for years, have &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50aGVyZWdpc3Rlci5jby51ay8yMDA1LzA3LzAxL2FudGlfc3B5d2FyZV9ydWxpbmcv&amp;amp;entry_id=910&quot; title=&quot;http://www.theregister.co.uk/2005/07/01/anti_spyware_ruling/&quot;  onmouseover=&quot;window.status=&#039;http://www.theregister.co.uk/2005/07/01/anti_spyware_ruling/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;finally been shut down&lt;/a&gt;.  The FTC has frozen all the assets of Trustsoft, whose Spykiller product has been ripping people off for a long time.&lt;br /&gt;
&lt;br /&gt;
JaBbA says about freakin&#039; time. 
    </content:encoded>

    <pubDate>Fri, 01 Jul 2005 11:52:35 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/910-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Nitpicking</title>
    <link>http://jalcorn.net/weblog/archives/890-Nitpicking.html</link>
            <category>Privacy &amp; Identity</category>
            <category>Words</category>
    
    <comments>http://jalcorn.net/weblog/archives/890-Nitpicking.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=890</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=890</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    As long as I&#039;m nitpicking, I had to put this in.&lt;br /&gt;
&lt;br /&gt;
Kim Cameron&#039;s very interesting whitepaper &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5pZGVudGl0eWJsb2cuY29tL3N0b3JpZXMvMjAwNC8xMi8wOS90aGVsYXdzLmh0bWw=&amp;amp;entry_id=890&quot; title=&quot;http://www.identityblog.com/stories/2004/12/09/thelaws.html&quot;  onmouseover=&quot;window.status=&#039;http://www.identityblog.com/stories/2004/12/09/thelaws.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;The Laws of Identity&lt;/a&gt; gives those of us dealing with Identity Management a great place to start the conversations.  An excellent read, and some good points (although as &quot;Architect of Identity&quot; for Microsoft Corporation, I keep seeing Kim in a Sith cloak &lt;img src=&quot;http://jalcorn.net/weblog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
But there is one ironic word mistake.  Talking about how Enterprises use identity:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;The differing contexts of discreet enterprises lead to a requirement&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Now as much as I like to think that Enterprises have my privacy in mind:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;disÂ·creet   Pronunciation Key  (d-skrt)&lt;br /&gt;
adj.&lt;br /&gt;
&lt;br /&gt;
   1. Marked by, exercising, or showing prudence and wise self-restraint in speech and behavior; circumspect.&lt;br /&gt;
   2. Free from ostentation or pretension; modest.&lt;br /&gt;
&lt;br /&gt;
[Middle English, from Old French discret, from Medieval Latin discrtus, from Latin, past participle of discernere, separate, to discern. See discreet.]&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
I think Kim meant that the enterprises were distinct, not circumspect:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;disÂ·crete  Pronunciation Key  (d-skrt)&lt;br /&gt;
adj.&lt;br /&gt;
&lt;br /&gt;
   1. Constituting a separate thing. See Synonyms at distinct.&lt;br /&gt;
   2. Consisting of unconnected distinct parts.&lt;br /&gt;
   3. Mathematics. Defined for a finite or countable set of values; not continuous.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Middle English, from Old French, from Latin discrtus, past participle of discernere, to separate. See discreet.]&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 25 May 2005 10:52:37 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/890-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Password Maintenance</title>
    <link>http://jalcorn.net/weblog/archives/888-Password-Maintenance.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/888-Password-Maintenance.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=888</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=888</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    One of the biggest problems web surfers struggle with on a daily basis is the multitude of identities we have to maintain.  At every web site we are asked to create a username and password.  The email address has become a defacto Globally Unique Identifier (GID) by it&#039;s very nature.  Unfortunately, people tend to reuse familiar passwords, often based on dictionary words  and people&#039;s names.  Those passwords, reused over many websites, make us vulnerable if any one of the webmasters maintains those passwords in an insecure manner.  One online community gets hacked, and the next thing you know your credit card has charges run up or your bank account is empty.&lt;br /&gt;
&lt;br /&gt;
The solutions available to the average web surfer have usually involved some kind of &quot;key chain&quot; - a password keeper like &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50cmFuZ2xvcy5jb20vZnJlZS8=&amp;amp;entry_id=888&quot; title=&quot;http://www.tranglos.com/free/&quot;  onmouseover=&quot;window.status=&#039;http://www.tranglos.com/free/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Oubliette&lt;/a&gt; that can keep hundreds of different passwords encrypted. (BTW, I highly recommend Tranglos&#039; KeyNote too).  But you still have to invent good passwords, and if you don&#039;t have your computer it doesn&#039;t do you any good.&lt;br /&gt;
&lt;br /&gt;
Enter Eric Jung and his Firefox Extension &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3Bhc3N3b3JkbWFrZXIubW96ZGV2Lm9yZy8=&amp;amp;entry_id=888&quot; title=&quot;http://passwordmaker.mozdev.org/&quot;  onmouseover=&quot;window.status=&#039;http://passwordmaker.mozdev.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;PasswordMaker&lt;/a&gt;.  This awesome little program allows you to remember exactly ONE password, and will generate a unique password for every website.  It does this by combining your strong password with the domain name of the website, then taking the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zcGl0em5lci5uZXQvbWQ1Lmh0bWw=&amp;amp;entry_id=888&quot; title=&quot;http://www.spitzner.net/md5.html&quot;  onmouseover=&quot;window.status=&#039;http://www.spitzner.net/md5.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;hash&lt;/a&gt; of the combined string.  Hashes, by their nature, are one-way algorithm - it is impossible to predict which strings will generate a specific hash, and it is impossible to get the original string back from the hash.  So, for example, if my password is &quot;Password Maker is a Wonderful Program&quot; (nice and long, but definitely not very strong), the generated password for jalcorn.net is 344b3201, but the same password generates the hash 145a8088 for microsoft.com.   Unpredictable, non-reversible, and secure.&lt;br /&gt;
&lt;br /&gt;
As a firefox extension, it&#039;s always available - hit Ctrl-`, type in the master password, and the domain password is copied to the clipboard for entering into the site. But what if you&#039;re not using your own machine?&lt;br /&gt;
&lt;br /&gt;
No problem.  There&#039;s a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3Bhc3N3b3JkbWFrZXIubW96ZGV2Lm9yZy9wYXNzd29yZG1ha2VyLmh0bWw=&amp;amp;entry_id=888&quot; title=&quot;http://passwordmaker.mozdev.org/passwordmaker.html&quot;  onmouseover=&quot;window.status=&#039;http://passwordmaker.mozdev.org/passwordmaker.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;javascript version of the program&lt;/a&gt;.  Because it&#039;s javascript, it&#039;s client-side only, and your master password is never submitted over the internet.  Need a command-line version?  I use this perl script:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;code&quot;&gt;#!/usr/bin/perl&lt;br /&gt;
# md5hash.pl - generates a passwordmaker-compatible has from the string on the &lt;br /&gt;
#      command line and the password typed at the prompt.  No error checking.&lt;br /&gt;
#      replicates passwordmaker with default settings: no l33t, 8 characters, MD5 algorithm&lt;br /&gt;
&lt;br /&gt;
use Term::Prompt;&lt;br /&gt;
use Digest::MD5 qw(md5 md5_hex md5_base64);&lt;br /&gt;
&lt;br /&gt;
$site = shift;&lt;br /&gt;
$pw = &amp;prompt(&quot;p&quot;,&quot;Master Password:&quot;,&quot;&quot;,&quot;&quot;);&lt;br /&gt;
$data = $pw.$site;&lt;br /&gt;
print &quot;\n&quot;.substr(md5_hex($data),0,8).&quot;\n&quot;;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
I highly recommend the use of this utility to generate unique passwords for every website.  &lt;br /&gt;
&lt;br /&gt;
JaBbA says do more than check it out - install it, use it.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 25 May 2005 09:58:57 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/888-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>NY AG indicts Spyware company</title>
    <link>http://jalcorn.net/weblog/archives/558-NY-AG-indicts-Spyware-company.html</link>
            <category>Applause</category>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/558-NY-AG-indicts-Spyware-company.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=558</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=558</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    From the SANS Newsbites, some good news for once:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;New York state Attorney General Eliot Spitzer has filed a lawsuit against Intermix Media Inc. for allegedly installing spyware and adware on people&#039;s computers without their knowledge.  According to the lawsuit, New York residents downloaded 3.7 million programs, including games and screen savers, from Intermix web sites, but they were not properly notified that the downloads also contained spyware and adware. Intermix senior VP and general counsel Christopher Lipp said such practices are part of Intermix&#039;s past, and were established under prior leadership and that the company has ceased distributing the programs in question of its own volition in April 2005.  The lawsuit follows a six-month investigation.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
This will set precedent for all future spyware prosecution, so it&#039;s important they get this right. 
    </content:encoded>

    <pubDate>Wed, 04 May 2005 15:12:42 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/558-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Who's protecting your identity?</title>
    <link>http://jalcorn.net/weblog/archives/512-Whos-protecting-your-identity.html</link>
            <category>Privacy &amp; Identity</category>
    
    <comments>http://jalcorn.net/weblog/archives/512-Whos-protecting-your-identity.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=512</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=512</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Apparently, prisoners in Oregon are &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53d2Vlay5jb20vc3RvcnkucGhwP3N0b3J5PTU4MDg=&amp;amp;entry_id=512&quot; title=&quot;http://www.wweek.com/story.php?story=5808&quot;  onmouseover=&quot;window.status=&#039;http://www.wweek.com/story.php?story=5808&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;more clueful than the people running the prisons&lt;/a&gt;:&lt;br /&gt;
&lt;blockquote&gt;Here&#039;s another twist on identity theft: They&#039;re doing it from behind bars. Until recently, visitors to the Oregon State Penitentiary had to give prison officials their Social Security numbers and other information for background checks, but now it appears inmates gained access to the info and sold it. The state Department of Corrections has placed at least two inmates in disciplinary segregation and continues to look for more, and little birds say inmate clubs have been shut down after visitors&#039; personal information was found in their offices. So far, the known civilian victims include volunteers from North Portland&#039;s Overstreet Powerhouse Temple who were doing Bible outreach inside the prison. Not only that, but the union representing corrections officers at the prisons, AFSCME, says three of its members have also been victimized; the union is pushing legislation to combat the problem.&lt;/blockquote&gt;&lt;br /&gt;
Here&#039;s a simple rule.  Don&#039;t store information if you can&#039;t secure it. 
    </content:encoded>

    <pubDate>Fri, 10 Dec 2004 14:20:42 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/512-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>

</channel>
</rss>