<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Because I am Here</title>
	<atom:link href="http://www.aarontitus.net/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.aarontitus.net/blog</link>
	<description>Aaron Titus&#039; Personal Blog</description>
	<lastBuildDate>Sat, 10 Sep 2011 10:54:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>September 11th, 2011: Create in Bold Defiance</title>
		<link>http://www.aarontitus.net/blog/2011/09/10/september-11th-2011-create-in-bold-defiance/</link>
		<comments>http://www.aarontitus.net/blog/2011/09/10/september-11th-2011-create-in-bold-defiance/#comments</comments>
		<pubDate>Sat, 10 Sep 2011 10:54:46 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Faith]]></category>
		<category><![CDATA[Law and Politics]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=422</guid>
		<description><![CDATA[I was not in Washington DC or New York ten years ago on that shattered Tuesday, but the deaths of thousands weighed heavily on us all.  I spent the day in college and work, physically exhausted and emotionally wounded.  The Eleventh of September was a dark day, and it seemed as though the [...]]]></description>
			<content:encoded><![CDATA[<p>I was not in Washington DC or New York ten years ago on that shattered Tuesday, but the deaths of thousands weighed heavily on us all.  I spent the day in college and work, physically exhausted and emotionally wounded.  The Eleventh of September was a dark day, and it seemed as though the flame and smoke of that morning had choked every source of inspiration.  I had no desire to do anything, and it seemed as though my mind and soul had been smothered.</p>
<p>That afternoon my architecture professor, <a href="http://faculty.arch.utah.edu/julio.htm">Julio Bermudez</a>, gave lengthy instructions about a drawing assignment in his thick Brazilian accent.  I don’t remember a word of that lecture.  None of us cared about drawing, or school, or work.  The very mention seemed trivial and sacrilegious.  At the end of the lecture, he told us to go outside and draw.  For the first time that day, my utter numbness turned to indignation and then anger at his triviality.</p>
<p>Then, sensing our irritation, he paused; and began speaking to us as Architects.  &#8220;Today we have witnessed the most anti-architectural act conceivable…  We are Architects.  We do not believe in death and destruction.  We believe in life.  We create.  I know many of you are angry right now.  I am angry.  You want to retaliate.  Right now it seems trivial to go out there and draw.  But if you really want to retaliate against what happened today, if you really want to take a stand and make a difference, then go out and do Architecture.  Go and create, and you will retaliate in the best way you can.  Now, go out and draw!&#8221;</p>
<p>No more appropriate words were ever said than at that time.  As members of our religions and communities, we do not believe in death and destruction.  We believe in life.  We believe in peace.  We create. Ten years later, that terrible moment inspires me to serve with a purpose, and create in bold defiance of everything that is murderous, destructive and evil.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/09/10/september-11th-2011-create-in-bold-defiance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Build Your Own Hurricane Irene Hand Sump Pump</title>
		<link>http://www.aarontitus.net/blog/2011/08/27/how-to-build-your-own-hurricane-irene-hand-sump-pump/</link>
		<comments>http://www.aarontitus.net/blog/2011/08/27/how-to-build-your-own-hurricane-irene-hand-sump-pump/#comments</comments>
		<pubDate>Sat, 27 Aug 2011 04:30:33 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=394</guid>
		<description><![CDATA[Instructions to Construct a Manual Auxiliary PVC Pipe Sump Pump
UPDATE: 8/28 9:00AM EASTERN: The power went out last night at 2am and didn&#8217;t come back on until 8:15am.  The pump worked well, but I completely underestimated the volume of water entering my basement.  I could not pump fast enough, so we retreated, and [...]]]></description>
			<content:encoded><![CDATA[<h2>Instructions to Construct a Manual Auxiliary PVC Pipe Sump Pump</h2>
<p><strong>UPDATE: 8/28 9:00AM EASTERN</strong>: The power went out last night at 2am and didn&#8217;t come back on until 8:15am.  The pump worked well, but I completely underestimated the volume of water entering my basement.  I could not pump fast enough, so we retreated, and Hurricane Irene gave us an 18-inch indoor swimming pool in our basement.</p>
<p>I made a hand pump to avoid basement flooding, just in case the power goes out and the sump pump stops working. Pictures below. I use the following <strong>Materials</strong>:</p>
<ul>
<li>1 @ Wood 3/4&#8243; wood board suitable to secure the pump and stand on</li>
<li>10 feet 1 1/4&#8243; PVC Pipe</li>
<li>5 feet 1&#8243; PVC Pipe</li>
<li>1 foot 3/4&#8243; PVC Pipe</li>
<li>1 @ 1 1/4&#8243; PVC T-Connector</li>
<li>1 @ 1&#8243; PVC T-Connector</li>
<li>6 feet hose, ~1 1/4&#8243; outside diameter</li>
<li>1-4 @ 1 1/4&#8243; PVC Elbow Connectors</li>
<li>2 @ 1 1/4&#8243; Straight Connectors</li>
<li>2 @ 1 1/4&#8243; Check Valves</li>
<li>2 feet metal straps</li>
<li>4 screws</li>
<li>1 @ 1 1/4&#8243; to 1&#8243; male/female straight PVC adapter</li>
<li>1 @ 1&#8243; to 3/4&#8243; male/female straight PVC adapter</li>
<li>1 @ 3/4&#8243; Female/female PVC threaded adapter</li>
<li>1 @ metal threaded garden hose adapter</li>
<li>1 @ PVC cap with 1&#8243; outside diameter OR large dowel (to fit snugly inside 1&#8243; PVC)</li>
<li>2 @ #18 O-Rings (1 3/36&#8243; O.D)</li>
<li>1 Table saw</li>
<li>1 PVC Cutting Tool</li>
<li>PVC Primer</li>
<li>PVC Glue</li>
</ul>
<p><span id="more-394"></span>
</p>
<h2>Instructions</h2>
<p>The hand pump works by sucking water through one check valve, into a hand-driven piston, then out another check valve, through a garden hose.  I created three different connectors for the intake: A hose (most verisitile, but most expsensive), a straight-down connector for my sump, and a rectangular intake connector for </p>
<p>I wish I had time to give detailed instructions. I don&#8217;t.  Here are some pointers:</p>
<ul>
<li>Cut the piston to about waist height.</li>
<li>Make sure to tighten the compression rings VERY tight on the check valves. They are the first to blow.</li>
<li>You can plug the 3/4&#8243; piston with a dowel, or any random piece of PVC that will fit over the top. I simply glued mine on.</li>
<li>The pump will work without the O-Rings, but it will leak slightly each time you pump.  But in an emergency situation, who cares?</li>
<li>Be careful to not go too deep when cutting the channels for the O-Rings. I used a table saw, and had to cut about 70% into the PVC.</li>
<li>Make the piston shorter than the shaft, or at least make sure to place the O-Rings higher up the piston.  Otherwise, when you push down on the piston, the O-rings will get stuck under the bottom of the shaft, where it enters the T.</li>
<li>I tested it by emptying a pool and pushing water up 8 feet through a garden hose. It works.</li>
<li>There is no need to glue the intake pipe or hose.</li>
<li>Pump was inspired by a design created by a <a href="http://www.youtube.com/watch?v=4-10UKzKolY">6-year-old boy</a>.</li>
<li>Total cost, not including tools was around $50.  The hose cost $23, and was the most expensive part.</li>
</ul>
<div id="attachment_395" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/fig_1.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/fig_1-300x200.jpg" alt="Entire Pump with all attachments" title="Hurricane Irene Manual Sump Pump" width="300" height="200" class="size-medium wp-image-395" /></a><p class="wp-caption-text">Entire Pump with all attachments</p></div>
<div id="attachment_396" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/fig_2.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/fig_2-300x200.jpg" alt="I just wanted to demonstrate that you can attach multiple intakes to the pump. In this case, I have a hose, a straight-down intake, and a rectangular intake that will stay at ground level, and go over a barrier." title="Three Intakes" width="300" height="200" class="size-medium wp-image-396" /></a><p class="wp-caption-text">I just wanted to demonstrate that you can attach multiple intakes to the pump. In this case, I have a hose, a straight-down intake, and a rectangular intake that will stay at ground level, and go over a barrier.</p></div>
<div id="attachment_397" class="wp-caption alignleft" style="width: 210px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1160.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1160-200x300.jpg" alt="A wider view of the hose and straight PVC intake pipes.  You don&#039;t have to glue these on." title="Intake Hose and PVC" width="200" height="300" class="size-medium wp-image-397" /></a><p class="wp-caption-text">A wider view of the hose and straight PVC intake pipes.  You don't have to glue these on.</p></div>
<div id="attachment_398" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1161.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1161-300x200.jpg" alt="I used 3/4&quot;, 1&quot; and 1 1/4&quot; PVC pipe for this project." title="Three Kinds of PVC" width="300" height="200" class="size-medium wp-image-398" /></a><p class="wp-caption-text">I used 3/4&quot;, 1&quot; and 1 1/4&quot; PVC pipe for this project.</p></div>
<div id="attachment_399" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1162.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1162-300x200.jpg" alt="Don&#039;t forget to glue the PVC pipe together. I used metal straps to secure it to the wood.  I used #18 O-Rings." title="PVC Primer, Glue, Metal straps, O-Rings" width="300" height="200" class="size-medium wp-image-399" /></a><p class="wp-caption-text">Don't forget to glue the PVC pipe together. I used metal straps to secure it to the wood.  I used #18 O-Rings.</p></div>
<div id="attachment_400" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1163.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1163-300x200.jpg" alt="I used #18 O-rings. I had to carefully cut channels into the piston, through about 70% of the PVC to get the O-Rings to fit. Be careful when you cut the channels using a table saw.  Sorry the image is turned." title="#18 O-Rings" width="300" height="200" class="size-medium wp-image-400" /></a><p class="wp-caption-text">I used #18 O-rings. I had to carefully cut channels into the piston, through about 70% of the PVC to get the O-Rings to fit. Be careful when you cut the channels using a table saw.  Sorry the image is turned.</p></div>
<div id="attachment_401" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1164.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1164-300x200.jpg" alt="You can use a saw, but these little tools are really handy. They&#039;re about $12 at Home Depot." title="PVC Cutting Tool" width="300" height="200" class="size-medium wp-image-401" /></a><p class="wp-caption-text">You can use a saw, but these little tools are really handy. They're about $12 at Home Depot.</p></div>
<div id="attachment_402" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1165.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1165-300x200.jpg" alt="The 1&quot; Piston fits inside the 1 1/4&quot; pipe.  It&#039;s a pretty snug fit. It will work without O-rings, but will leak.  Then again, if you&#039;re in an emergency, who cares if there&#039;s a little spray? I&#039;m sorry this one is turned, too." title="Piston" width="300" height="200" class="size-medium wp-image-402" /></a><p class="wp-caption-text">The 1&quot; Piston fits inside the 1 1/4&quot; pipe.  It's a pretty snug fit. It will work without O-rings, but will leak.  Then again, if you're in an emergency, who cares if there's a little spray? I'm sorry this one is turned, too.</p></div>
<div id="attachment_403" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1166.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1166-300x200.jpg" alt="This is one of the most important details. You can use anything convenient to cap the end of the 1&quot; diameter PVC interior piston.  A large dowel would work, too.  I just happened to find a miscellaneous piece of round PVC that fit nicely.  I used a table saw to cut channels for the O-Rings.  It&#039;s a very snug fit." title="Piston End" width="300" height="200" class="size-medium wp-image-403" /></a><p class="wp-caption-text">This is one of the most important details. You can use anything convenient to cap the end of the 1&quot; diameter PVC interior piston.  A large dowel would work, too.  I just happened to find a miscelaneous piece of round PVC that fit nicely.  I used a table saw to cut channels for the O-Rings.  It's a very snug fit.</p></div>
<div id="attachment_404" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1167.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1167-300x200.jpg" alt="I just used a simple 1&quot; T connector to make the piston handle." title="Piston Handle" width="300" height="200" class="size-medium wp-image-404" /></a><p class="wp-caption-text">I just used a simple 1&quot; T connector to make the piston handle.</p></div>
<div id="attachment_405" class="wp-caption alignleft" style="width: 210px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1168.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1168-200x300.jpg" alt="You can see the piston and the shaft side-by-side. The piston is inserted into the shaft. With the O-Rings, it&#039;s a snug fit, so you have to make sure to cut the O-ring channels deep enough; but not too deep." title="Piston Shaft" width="200" height="300" class="size-medium wp-image-405" /></a><p class="wp-caption-text">You can see the piston and the shaft side-by-side. The piston is inserted into the shaft. With the O-Rings, it's a snug fit, so you have to make sure to cut the O-ring channels deep enough; but not too deep. <strong>IMPORTANT (and not shown here):</strong> The O-Rings were too low on the piston, and when I pushed down on the piston the O-Rings got stuck on the bottom of the shaft, where the shaft entered the T. I solved the problem by gluing a stopper at the top of the piston.  You can also solve this problem by making the piston shorter than the shaft, or placing the O-Rings higher up the piston.</p></div>
<div id="attachment_406" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1169.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1169-300x200.jpg" alt="Make sure that the check valves are pointed the same direction-- away from the intae and toward the garden hose adaptor.  I found that the check valve compression rings were the weakest part of the pump, and tended to blow out first.  Make sure you TIGHTEN ALL COMPRESSION RINGS very tightly to avoid blowing them out." title="Check Valve" width="300" height="200" class="size-medium wp-image-406" /></a><p class="wp-caption-text">Make sure that the check valves are pointed the same direction-- away from the intae and toward the garden hose adaptor.  I found that the check valve compression rings were the weakest part of the pump, and tended to blow out first.  Make sure you TIGHTEN ALL COMPRESSION RINGS very tightly to avoid blowing them out.</p></div>
<div id="attachment_407" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1170.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1170-300x200.jpg" alt="The T connector connects two 6-inch pieces of 1 1/4&quot; PVC with the check valves. I secured it with two metal straps.  As the piston is lifted, water flows through the intake check valve. As the piston is lowered, the water flows out the outtake check valve." title="Piston T Connector" width="300" height="200" class="size-medium wp-image-407" /></a><p class="wp-caption-text">The T connector connects two 6-inch pieces of 1 1/4&quot; PVC with the check valves. I secured it with two metal straps.  As the piston is lifted, water flows through the intake check valve. As the piston is lowered, the water flows out the outtake check valve.</p></div>
<div id="attachment_409" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1172.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1172-300x200.jpg" alt="The outtake check valve is connected to a 1 1/4&quot; PVC pipe, which is adapted down to a 3/4&quot; PVC pipe. Then I added an extra adapter with a female garden hose connector." title="Garden Hose Adaptor" width="300" height="200" class="size-medium wp-image-409" /></a><p class="wp-caption-text">The outtake check valve is connected to a 1 1/4&quot; PVC pipe, which is adapted down to a 3/4&quot; PVC pipe. Then I added an extra adapter with a female garden hose connector.</p></div>
<p><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1173.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1173-300x200.jpg" alt="Detail of PVC" title="Detail of PVC" width="300" height="200" class="alignleft size-medium wp-image-410" /></a></p>
<p><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1174.JPG"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/08/IMG_1174-300x200.jpg" alt="Detail of Garden Hose Connector" title="Detail of Garden Hose Connector" width="300" height="200" class="alignleft size-medium wp-image-411" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/08/27/how-to-build-your-own-hurricane-irene-hand-sump-pump/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>NSTIC Identity Ecosystem Marketplace Roles and Concepts</title>
		<link>http://www.aarontitus.net/blog/2011/04/28/nstic-identity-ecosystem-marketplace-roles-and-concepts/</link>
		<comments>http://www.aarontitus.net/blog/2011/04/28/nstic-identity-ecosystem-marketplace-roles-and-concepts/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 13:23:10 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[NSTIC]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=387</guid>
		<description><![CDATA[This post is a follow-up to our April 15, 2011 whitepaper and accompanying presentation.
NSTIC envisions a secure “Identity Ecosystem Framework,” or “the overarching set of interoperability standards, risk models, privacy and liability policies, requirements and accountability mechanisms that structure the Identity Ecosystem.”  While the Identity Ecosystem will provide value to any participant which needs [...]]]></description>
			<content:encoded><![CDATA[<p>This post is a follow-up to our April 15, 2011 <a href="http://www.identityfinder.com/Software/Docs/IDF-NSTIC-WP.pdf">whitepaper</a> and accompanying <a href="http://www.identityfinder.com/Software/Docs/IDF-NSTIC-PRES.pptx">presentation</a>.</p>
<p>NSTIC envisions a secure “<a href="http://www.nstic.us/strategy.html#sec6para10item1" title="National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy, April 15, 2011, p. 24">Identity Ecosystem Framework</a>,” or “the overarching set of interoperability standards, risk models, privacy and liability policies, requirements and accountability mechanisms that structure the Identity Ecosystem.”  While the Identity Ecosystem will provide value to any participant which needs to verify a User’s identity, the Ecosystem will provide tremendous opportunities to streamline the further commoditization of human identity.  Without regulation, the NSTIC Identity Ecosystem will create new markets for businesses which thrive on the commoditization of human identity. I identify this resulting market as the “Identity Ecosystem Marketplace.”  An Identity Marketplace already exists, and has been admirably illustrated by <a href="http://www.slideshare.net/tkawaja/luma-display-ad-tech-landscape-2010-1231" title="Display Advertising Technology Landscape, dated March 15, 2011">Luma Partners, LLC</a>  and <a href="http://www.improvedigital.com/wp-content/uploads/DigitalAdvertisingIndustryMap2010_EN_1.2.pdf" title="2010 – Display Advertising Market Map Europe—v. 1.1, English">Improve Digital</a>.</p>
<p>The Identity Ecosystem Marketplace includes at least six major roles, as illustrated here.  A single organization may fill multiple roles in any given Identity Ecosystem transaction. Some of the definitions here may differ or even conflict with <a href="http://www.nstic.us/strategy.html#sec6para2">official NSTIC definitions</a>, usually because the official definitions lack clarity within the context of this analysis.</p>
<p><span id="more-387"></span><br />
<div id="attachment_390" class="wp-caption alignleft" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Identity-Ecosystem-Roles-Close-Icons.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Identity-Ecosystem-Roles-Close-Icons-300x272.png" alt="Major Identity Ecosystem Roles and Concepts" title="Major Identity Ecosystem Roles and Concepts" width="300" height="272" class="size-medium wp-image-390" /></a><p class="wp-caption-text">Major Identity Ecosystem Roles and Concepts</p></div></p>
<ul>
<li>A <strong>Subject</strong> or <strong>User</strong> is an <a href="http://www.nstic.us/strategy.html#sec6list1item1">individual</a> or <a href="http://www.nstic.us/strategy.html#sec6list1item2">Non-Person Entity</a> (NPE) which must assert its identity to a Relying Party in order to receive a benefit such as access to a trusted network, bank account access, or access to premium content online.</li>
<li>An <strong>Attribute Provider</strong> (AP) creates, stores and allows others (such as the Identity Provider and Relying Party) to access or analyze User Attributes, usually under conditions. An Attribute Provider is also usually a Third Party. In the Identity Ecosystem, an Attribute Provider must be trusted as an authoritative source of information.  Typical examples of attribute providers might be a government title registry, national credit bureau, or commercial marketing database.</li>
<li>An <strong>Attribute</strong> is a fact related to a User. Attributes may include traditional PII, information about authority, roles, rights, privileges, or any other fact asserted by a User, Attribute Provider, or Third Party. NSTIC <a href="http://www.nstic.us/strategy.html#sec6list1item4">defines &#8220;Attribute&#8221;</a> as &#8220;a named quality or characteristic inherent in or ascribed to someone or something.&#8221;</li>
<li>An <strong>Identity Provider</strong> (IdP) is an organization certified as trustworthy through an accreditation authority. An IdP issues a credential, which corresponds to a piece of information known to the User (such as a password), a biometric attribute, or information stored on an Identity Medium (not represented herein).  An IdP is responsible for verifying the credential when used as evidence of a User’s identity.  An IdP may collect attributes about the User from Attribute Providers, store those attributes, and compare them against assertions made by the User to a Relying Party.  Identity Providers do not guarantee the correctness of attributes obtained from Attribute Providers, but may instead confirm that a Claim made by a User matches information from Attribute Providers.  Identity Providers may share User attributes, personal information, and Transaction Information with Relying Parties, Third Parties, Parent Companies and Attribute Providers, in accordance with the Data Usage Policy.</li>
<li>A <strong>Data Usage Policy</strong> is a contract between a User and Identity Provider, governing the use and disclosure of User information held by the Identity Provider.</li>
<li><strong>Transaction Information</strong> is a record of the benefit provided to the User from the Relying Party, and is analogous to a receipt. Transaction Information may include the name of a product purchased, a log of network access and User activity, or services provided.</li>
<li><strong>Identity Medium</strong> refers to the physical device that stores an NSTIC-compatible identity credential. Examples of Identity Mediums include cell phone apps, smart cards, or USB computer dongles. Identity Media are not visually represented, and are not required for a transaction.</li>
<li>A <strong>Relying Party</strong> (RP) is a person or NPE that requires some degree of identity assurance and possibly User Attributes before it will provide a benefit to the User.</li>
<li>A <strong>Parent Company</strong> is a company which owns or is affiliated with the Identity Provider and/or the Relying Party in such a way that by action of law, ownership or contract, the Parent Company has right to access and use the Identity Provider or Relying Party’s data assets, unless expressly prohibited by law or regulation.</li>
<li>A <strong>Third Party</strong> is any person, organization, system, or device which has no direct affiliation with the User or the transaction in question. A familiar example of a Third Party is an online advertiser.</li>
<li>For purposes of my discussions, I define a <strong>Claim</strong> as an assertion that an Attribute is truthful or correct. A Claim may be made by any party.  Examples of User Claims are, “I am over 18 years old,” “I am a constituent or citizen,” or “I am authorized to enter your network.” Claims are not visually represented here.  In technical circles, a “claim” is an assertion that may be derived by comparing or analyzing one or more Attributes.</li>
<li>According to <a href="http://www.nstic.us/strategy.html#sec6para10item1" title="National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy, April 15, 2011, p. 24.">NSTIC</a>, the <strong>Identity Ecosystem Framework</strong> is “the overarching set of interoperability standards, risk models, privacy and liability policies, requirements, and accountability mechanisms that structure the Identity Ecosystem.” </li>
<li>The <strong>Identity Ecosystem Marketplace</strong> is the Identity Marketplace created by the Identity Ecosystem, where Identity Ecosystem Participants may commoditize and trade User identities and Attributes in exchange for benefits.  Not all Identity Ecosystem transactions necessarily commoditize human identity. The exchange of identity information in many e-commerce transactions is ancillary to the transaction, and the User pays directly for the benefit of the transaction (e.g. a money transfer, music or movie download). Notwithstanding, the Identity Ecosystem Marketplace enables Participants to more easily commoditize identity as an additional source of revenue. NSTIC recognizes that Participants should not be allowed to buy and sell identity information within the Ecosystem, but does not yet identify a credible mechanism to enforce this requirement.</li>
<li><strong>Fair Information Practice Principles</strong> (FIPPs) are Transparency, Individual Participation, Purpose Specification, Data Minimization, Use Limitation, Data Quality and Integrity, Security, and Accountability and Auditing.  NSTIC identifies FIPPs as core requirements in the Identity Ecosystem, but stops short of mandating FIPPs.</li>
</ul>
<p>The NSTIC <a href="http://www.nstic.us/strategy.html#sec3para1">guiding principles</a> are:</p>
<ul>
<li>Identity solutions will be <strong>privacy-enhancing</strong> and <strong>voluntary</strong>.</li>
<li>Identity solutions will be <strong>secure</strong> and <strong>resilient</strong>.</li>
<li>Identity solutions will be <strong>interoperable</strong>.</li>
<li>Identity solutions will be <strong>cost-effective</strong> and <strong>easy to use</strong>.</li>
</ul>
<p>Through these guding principles NSTIC aims to accomplish its <a href="http://www.nstic.us/strategy.html#sec1para6">primary goals</a> of:</p>
<ul>
<li><strong>Privacy</strong></li>
<li><strong>Convenience</strong></li>
<li><strong>Efficiency</strong></li>
<li><strong>Ease-of-use</strong></li>
<li><strong>Security</strong></li>
<li><strong>Confidence</strong></li>
<li><strong>Innovation</strong>, and</li>
<li><strong>Choice</strong>.</li>
</ul>
<p>Future posts will explore the interaction of these roles in the Identity Ecosystem Marketplace, and under what conditions NSTIC will be able to meet its goals.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/04/28/nstic-identity-ecosystem-marketplace-roles-and-concepts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NSTIC as a National ID</title>
		<link>http://www.aarontitus.net/blog/2011/04/26/nstic-as-a-national-id/</link>
		<comments>http://www.aarontitus.net/blog/2011/04/26/nstic-as-a-national-id/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 17:29:46 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[NSTIC]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=374</guid>
		<description><![CDATA[Even outrageous statements on controversial topics often contain flecks of truth.  This is an attempt to pan through the muddy waters of NSTIC media coverage in relation to NSTIC to as a &#8220;National ID,&#8221; identify the golden flecks and nuggets of truth, and frame the debate on this important topic.
As NSTIC develops, we can [...]]]></description>
			<content:encoded><![CDATA[<p>Even outrageous statements on controversial topics often contain flecks of truth.  This is an attempt to pan through the muddy waters of <a href="http://www.nist.gov/nstic">NSTIC</a> media coverage in relation to NSTIC to as a &#8220;National ID,&#8221; identify the golden flecks and nuggets of truth, and frame the debate on this important topic.</p>
<p>As NSTIC develops, we can expect to hear more soundbytes in the public media invoking fear, uncertainty, and doubt (FUD) around NSTIC as a National ID, Internet Passport, Internet ID, or Online Driver&#8217;s License. Some of the fear is warranted. Some of it is not.  All of the risk and uncertainty should be measured to the fullest extent possible, without <a href="http://www.fastcompany.com/1715659/national-identity-cyberspace-why-we-shouldnt-freak-out-about-nstic">freaking out</a>.</p>
<p>Frankly, I do not have a comprehensive definition for a &#8220;National ID&#8221; right now. <a href="http://twitter.com/#!/jim_harper">Jim Harper</a>, director of Information Policy Studies at the <a href="http://www.cato.org/">Cato Institute</a>, and author of <a href="http://www.amazon.com/Identity-Crisis-Identification-Overused-Misunderstood/dp/1930865856"><em>Identity Crisis: How Identification Is Overused and Misunderstood</em></a> would have a much better answers than me. Notwithstanding, I have a few comments which I hope will add some clarity to the discussion:</p>
<p>Instituting any sort of national identification can have serious and unanticipated consequences, and should be the subject of a robust public policy debate. History, present and past, is replete with examples of extreme abuse of government-issued identification.  To give just two examples, identification credentials played key roles in both the Holocaust and Rwandan Genocide. Other, less dramatic forms of abuse exist wherever identity credentials are issued.  For example, the U.S. National ID, commonly known as the Social Security Number, is regularly used to commit crimes we now refer to as &#8220;Identity Theft.&#8221;</p>
<h2>NSTIC is NOT a National ID</h2>
<p>Several commentators have expressed <a href="http://www.cbsnews.com/8301-501465_162-20027837-501465.html" title=" Obama Eyeing Internet ID for Americans , January 7, 2011.">skepticism</a> to <a href="http://www.eff.org/deeplinks/2010/07/real-id-online-new-federal-online-identity-plan" title=" Lee Tien and Seth Schoen,  Real ID Online? New Federal Online Identity Plan Raises Privacy and Free Speech Concerns , July 20th, 2010">downright</a> <a href="http://www.techi.com/2011/01/obamas-national-internet-id/" title=" JD Rucker,  Why Obama's National Internet ID Solution is a Really, REALLY Bad Idea , January 10, 2011.">disdain</a> for NSTIC as a back-door approach to instituting a National ID. NSTIC&#8217;s defense to these accusations is simple and true, but incomplete: <strong>NSTIC is NOT a National ID</strong>.</p>
<p>NSTIC itself is not an identification system, much less a National ID. NSTIC is a framework for setting up a structure of interoperable federated identity systems.  Each system will be owned and operated by various independent private companies and public institutions, using various technologies with various levels of identity assurance, security, and trust levels. NSTIC is policy, not technology or identification credentials.  In fact, I am guilty of a techical <em>faux pas</em> by using the term &#8220;NSTIC credential,&#8221; since no such thing actually exists. But unfortunately I don&#8217;t have a better shorthand way of saying,<br />
<blockquote>&#8220;Voluntary identification credentials issued by an accredited private or government Identity Provider which complies with the &#8216;overarching set of interoperability standards, risk models, privacy and liability policies, requirements, and accountability mechanisms that structure the Identity Ecosystem,&#8217; which are implemented using a range of technologies, mediums, and authentication protocols.&#8221;</p></blockquote>
<p>  So I say <em>&#8220;NSTIC credential&#8221;</em> instead.</p>
<p>I do not attempt to establish a comprehensive definition for a &#8220;National ID&#8221; here.  But when government-issued identification is used to separate individuals into groups, and centralization decreases the transaction costs associated with classifying human identity, bad things can happen.</p>
<p>I decline to call NSTIC a &#8220;National ID.&#8221; Instead, it is much more prudent to discuss attributes which may be similar or dissimilar to a centralized, federal-government-issued National ID card. I hope that the following table can focus the public discussion on this matter, which is currently lacking articulation.</p>
<table border="1" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<th>
<p>How NSTIC is Not Like a National ID</p>
</th>
<th>
<p>How NSTIC Might be Like a National ID</p>
</th>
</tr>
<tr>
<td>
<p>NSTIC credentials are not owned, issued, or managed by the Federal Government, except for IDs issued to government employees.</p>
</td>
<td>
<p>If adopted by a majority of state governments, NSTIC credentials could become standard in State IDs and drivers licenses. The Federal Government could also embed an NSTIC credential in passports.</p>
</td>
</tr>
<tr>
<td>
<p>Identity Provider Databases are not under government control, except for a few run by the Federal Government for government employees.</p>
</td>
<td>
<p>Identity and personal information which enters the Identity Ecosystem Marketplace is subject to very little protection against government search and seizure under the 4<sup>th</sup> Amendment.</p>
</td>
</tr>
<tr>
<td>
<p>NSTIC is voluntary for the private sector and private citizens.</p>
</td>
<td>
<p>If adopted by State governments, which control a substantial portion of the identification market, NSTIC credentials could become mandatory and displace private sector identity competitors.</p>
</td>
</tr>
<tr>
<td>
<p>NSTIC credentials are not yet required to access government benefits.</p>
</td>
<td>
<p>Access to electronic government services may one day require an NSTIC credential.</p>
</td>
</tr>
<tr>
<td>
<p>NSTIC credentials are not primarily designed to classify individuals by a status such as race, religion, age or gender.</p>
</td>
<td>
<p>NSTIC credentials are designed for classifying people by roles and access to resources; the supporting technology could be easily adapted to expand identity profiles compiled by the private sector that may include age, gender, political beliefs, religion, race, socioeconomic status, etc.</p>
</td>
</tr>
<tr>
<td>
<p>Identity and Transaction Information is not stored in a single, centralized government database.</p>
</td>
<td>
<p>Identity and Transaction Information is stored in thousands of private databases which may be centralized by the private sector, purchased by the government, or accessible to law enforcement with little due process.</p>
</td>
</tr>
<tr>
<td>
<p>An NSTIC credential is designed for online transactions only.</p>
</td>
<td>
<p>With more of our lives and business conducted online, widespread adoption of the NSTIC framework could mean that an NSTIC credential may become a functional requirement for participating in online life, with real-life consequences.</p>
</td>
</tr>
</tbody>
</table>
<p>I agree with the Center for Democracy and Technology’s <a href="http://www.cdt.org/blogs/jim-dempsey/new-urban-myth-internet-id-scare" title=" Jim Dempsey,  New Urban Myth: The Internet ID Scare , January 11, 2011.">Jim Dempsey who said</a>,</p>
<p>
<blockquote>The Obama Administration is not planning to create a government ID for the Internet.  In fact, the Administration is proposing just the opposite: to rely on the private sector to develop identities… for online commerce.… [T]he government needs an identity ecosystem or identity infrastructure. It needs it for its own services as well as part of the solution to the broader Cybersecurity problem as well as one of the foundations of eCommerce, but the government cannot create that identity infrastructure. Because if it tried to, it wouldn&#8217;t be trusted.</p></blockquote>
<p>I hope this table helps to frame the discussion about NSTIC as a National ID.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/04/26/nstic-as-a-national-id/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Why I Support Jeremy Grant, and Hope NIST Will Too</title>
		<link>http://www.aarontitus.net/blog/2011/04/18/why-i-support-jeremy-grant-and-hope-nist-will-too/</link>
		<comments>http://www.aarontitus.net/blog/2011/04/18/why-i-support-jeremy-grant-and-hope-nist-will-too/#comments</comments>
		<pubDate>Mon, 18 Apr 2011 16:13:49 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[NSTIC]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=363</guid>
		<description><![CDATA[Those even remotely familiar with Washington politics know that everything is political.  A few agencies such as the Census bureau, attempt to stay above the political fray with varying degrees of success.  The National Institute of Standards and Technology (NIST) is arguably the gold standard of apolitical federal agencies.  NIST has learned [...]]]></description>
			<content:encoded><![CDATA[<p>Those even remotely familiar with Washington politics know that <em>everything is political</em>.  A few agencies such as the Census bureau, <em>attempt</em> to stay above the political fray with varying degrees of success.  The <a href="http://www.nist.gov">National Institute of Standards and Technology</a> (NIST) is arguably the gold standard of apolitical federal agencies.  NIST has learned through experience to remain staunchly apolitical by focusing strictly on standards, science, and technology while keeping their noses and fingers well away from policy.  As a result, NIST enjoys a good deal of transpartisan respect. NIST zealously (and appropriately) guards its reputation by avoiding policy and politics.</p>
<p>That&#8217;s why I&#8217;m both excited and worried about NIST&#8217;s role in the <a href="http://www.nist.gov/nstic/">National Strategy for Trusted Identities in Cyberspace</a> (NSTIC, pronounced &#8220;N-Stick&#8221;).  On one hand, this emerging framework will benefit substantially from NIST&#8217;s knowledge and capability in technology standards development; and let&#8217;s face it, the Department of Commerce was one of the few agencies politically neutral enough to host NSTIC.  NIST&#8217;s NSTIC team includes notable and respected scientists, academics, and technologists.  But as our recent <a href="http://bit.ly/idEbza">Whitepaper</a> on NSTIC&#8217;s policy hurdles illustrates, NSTIC policy requires as much development as the technology.</p>
<p>That&#8217;s what makes NIST&#8217;s role in NSTIC unique: NIST must not only support the development of standards and technology, but must also develop the policy governing the use of the technology.  Or, to paraphrase Scott David, NIST must develop both the &#8220;tools&#8221; and the &#8220;rules.&#8221;  In recognition of these challenges, the NSTIC team also includes respected policymakers and thinkers led by Jeremy Grant, himself a universally respected policymaker.  NSTIC needs both tools and rules to avoid abuse, and the inclusion of policymakers on the NSTIC team is essential to develop both.</p>
<p>In Washington everything is political, especially policy.  Very soon the policy and governance debate will begin, and proverbial political bullets will begin flying from every direction.  I believe that Jeremy Grant and his team will work hard to navigate the impending battlefield of industry, advocates and government interests.  <strong>But even intelligent, dedicated and respected public servants like Jeremy Grant and his team need the support and political cover of their agency, NIST.</strong> And when the negotiations get divisive, political and ugly, NIST has a tendency to wash its hands of such riff-raff and retreat back into its comfort zone of apolitical academic and scientific research.</p>
<p>Among the worst imaginable disasters for NSTIC is if NIST doesn&#8217;t have the stomach for policy development and quietly cajoles the NSTIC team back into NIST&#8217;s comfort zone of standards and technology, ceding the policy to those with the most firepower.</p>
<p>Then truly, the war will be lost.</p>
<p>Advocates must watch carefully for signs of a NIST retreat from its uncomfortable role as policymaker. Mr. Jeremy Grant, we do not envy your position; you have our support, and we hope that NIST will support you too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/04/18/why-i-support-jeremy-grant-and-hope-nist-will-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NSTIC&#8217;s Effect on Privacy</title>
		<link>http://www.aarontitus.net/blog/2011/04/18/nstics-effect-on-privacy/</link>
		<comments>http://www.aarontitus.net/blog/2011/04/18/nstics-effect-on-privacy/#comments</comments>
		<pubDate>Mon, 18 Apr 2011 16:00:02 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[NSTIC]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=358</guid>
		<description><![CDATA[The Department of Commerce released the National Strategy for Trusted Identities in Cyberspace (NSTIC, pronounced &#8220;N-Stick&#8221;).  From a privacy perspective, the 52-page April 15, 2011 Final Draft is a big improvement over the June 25, 2010 Draft.
Also on April 15, 2011, Identity Finder released a 39-page analysis on NSTIC&#8217;s effect on Privacy. I was [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.commerce.gov">Department of Commerce</a> released the <a href="http://www.nist.gov/nstic/">National Strategy for Trusted Identities in Cyberspace</a> (NSTIC, pronounced &#8220;N-Stick&#8221;).  From a privacy perspective, the 52-page April 15, 2011 <a href="http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf">Final Draft</a> is a big improvement over the <a href="http://www.dhs.gov/xlibrary/assets/ns_tic.pdf">June 25, 2010 Draft</a>.</p>
<p>Also on April 15, 2011, <a href="http://www.identityfinder.com">Identity Finder</a> released a 39-page analysis on <a href="http://www.identityfinder.com/Software/Docs/IDF-NSTIC-WP.pdf">NSTIC&#8217;s effect on Privacy</a>. I was the principal author.  The report supports the aspirations of NSTIC, but warns that success is far from assured.  NSTIC faces multiple unresolved hurdles to implementing privacy and security in a de-centralized, national framework of interoperable identity systems.</p>
<p>If done well, an ideal NSTIC Identity Ecosystem could establish:</p>
<ul>
<li>High levels of identity assurance online, increasing trust between Users and service providers</li>
<li>More secure online transactions</li>
<li>Innovation and new services</li>
<li>Improved privacy and anonymity</li>
<li>Increased convenience for Users and savings for service providers</li>
</ul>
<p>Through extensive analysis, Identity Finder has found that to successfully implement its visions of privacy, security, and secure identities, NSTIC cannot rely on the private sector alone.  Identity technologies may be used for profit, or to preserve privacy, but rarely both.  While the private sector is best positioned to develop and maintain the framework of federated identity systems, federal policy must balance individuals&#8217; need for privacy and security.  In order to be successful, NSTIC must be supported by regulations that:</p>
<ul>
<li>Hold all Identity Ecosystem Participants to legal and technical standards which implement Fair Information Practice Principles (FIPPs) and baseline privacy and security protocols</li>
<li>Create incentives for businesses to not commoditize human identity</li>
<li>Compensate for an individual’s unequal bargaining power when establishing privacy policies</li>
<li>Subject Identity Providers to similar requirements to the Fair Credit Reporting Act</li>
<li>Train individuals on how to properly safeguard their Identity Medium to avoid identity theft</li>
<li>Ensure that consumers and advocates have a meaningful voice in the development of NSTIC policy</li>
</ul>
<p>While we&#8217;re concerned about the unsolved techological hurdles, we are even more concerned about the policy and behavioral vulnerabilities that a widespread identity ecosystem would create. We all have social security cards and it took decades to realize that we shouldn’t carry them around in our wallets.  Now we will have a much more powerful identity credential, and we are told to carry it in our wallets, phones, laptops, tablets and other computing devices. Although NSTIC aspires to improve privacy, it stops short of recommending regulations to protect privacy.  The stakes are high, and if implemented improperly, an unregulated Identity Ecosystem could have a devastating impact on individual privacy.</p>
<p>If NSTIC fails to implement the necessary regulations, the resulting Identity Ecosystem could turn into a free-for-all Identity marketplace, and create the following risks:</p>
<ul>
<li>Powerful identity credentials which, if lost or stolen will enable hyper-identity theft</li>
<li>A false sense of control, privacy, and security among Users</li>
<li>New ways to covertly collect Users’ personal information</li>
<li>New markets in which to commoditize human identity</li>
<li>Few consumer protections against abuse or sharing personal information with third parties</li>
<li>No default legal recourse against participants who abuse personal information without consent</li>
</ul>
<p>I&#8217;ll be writing more blog posts in the coming days exploring some of NSTIC&#8217;s unsolved policy hurdles, and why individuals, businesses, and policy-makers should care.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/04/18/nstics-effect-on-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2010 General Conference Themes</title>
		<link>http://www.aarontitus.net/blog/2011/04/10/april-2010-general-conference-themes/</link>
		<comments>http://www.aarontitus.net/blog/2011/04/10/april-2010-general-conference-themes/#comments</comments>
		<pubDate>Mon, 11 Apr 2011 02:09:47 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Faith]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=345</guid>
		<description><![CDATA[After the interest in the Wordle tag clouds I did of the October 2010 General Conference, I decided to analyze themes of the April 2011 General Conference of the Church of Jesus Christ of Latter-day Saints using the same method.  I have posted word clouds here that will help visualize the major themes of [...]]]></description>
			<content:encoded><![CDATA[<p>After the interest in the <a href="http://www.wordle.net/">Wordle</a> tag clouds I did of the <a href="http://www.aarontitus.net/blog/2010/10/03/general-conference-themes/">October 2010 General Conference</a>, I decided to analyze themes of the <a href="http://lds.org/general-conference/sessions/2011/04?lang=eng">April 2011 General Conference</a> of the <a href="http://www.lds.org">Church of Jesus Christ of Latter-day Saints</a> using the same method.  I have posted word clouds here that will help visualize the major themes of each session, and the conference as a whole:</p>
<h2>Entire April 2010 General Conference</h2>
<div id="attachment_346" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/April_2010_Conference.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/April_2010_Conference-300x175.png" alt="Themes of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="175" class="size-medium wp-image-346" /></a><p class="wp-caption-text">Themes of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div><br />
<span id="more-345"></span></p>
<h2>Young Women Session</h2>
<p><div id="attachment_352" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Young_Women_Session_April_2010.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Young_Women_Session_April_2010-300x178.png" alt="Themes of the Young Women Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="Themes of the Young Women Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="178" class="size-medium wp-image-352" /></a><p class="wp-caption-text">Themes of the Young Women Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div>
<h2>Saturday Morning Session</h2>
<div id="attachment_349" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Saturday_Morning_Session_April_2010.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Saturday_Morning_Session_April_2010-300x146.png" alt="Themes of the Saturday Morning Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="Themes of the Saturday Morning Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="146" class="size-medium wp-image-349" /></a><p class="wp-caption-text">Themes of the Saturday Morning Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div>
<h2>Saturday Afternoon Session</h2>
<div id="attachment_348" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Saturday_Afternoon_Session_April_2010.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Saturday_Afternoon_Session_April_2010-300x167.png" alt="Themes of the Saturday Afternoon Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="Themes of the Saturday Afternoon Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="167" class="size-medium wp-image-348" /></a><p class="wp-caption-text">Themes of the Saturday Afternoon Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div>
<h2>Priesthood Session</h2>
<div id="attachment_347" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Priesthood_Session_April_2010.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Priesthood_Session_April_2010-300x138.png" alt="Themes of the Priesthood Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="Themes of the Priesthood Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="138" class="size-medium wp-image-347" /></a><p class="wp-caption-text">Themes of the Priesthood Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div>
<h2>Sunday Morning Session</h2>
<div id="attachment_351" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Sunday_Morning_Session_April_2010.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Sunday_Morning_Session_April_2010-300x149.png" alt="Themes of the Sunday Morning Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="Themes of the Sunday Morning Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="149" class="size-medium wp-image-351" /></a><p class="wp-caption-text">Themes of the Sunday Morning Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div>
<h2>Sunday Afternoon Session</h2>
<div id="attachment_350" class="wp-caption alignnone" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Sunday_Afternoon_Session_April_2010.png"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/04/Sunday_Afternoon_Session_April_2010-300x131.png" alt="Themes of the Sunday Afternoon Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" title="Themes of the Sunday Afternoon Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints" width="300" height="131" class="size-medium wp-image-350" /></a><p class="wp-caption-text">Themes of the Sunday Afternoon Session of the April 2010 General Conference of the Church of Jesus Christ of Latter-day Saints</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/04/10/april-2010-general-conference-themes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 Sources of Data Breaches You’ll Never Hear About: Your Network Drives</title>
		<link>http://www.aarontitus.net/blog/2011/04/05/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-network-drives/</link>
		<comments>http://www.aarontitus.net/blog/2011/04/05/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-network-drives/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 06:09:46 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=335</guid>
		<description><![CDATA[This is the seventh post in a series about data breaches you can prevent. We’ve covered Phones and Personal Computing Devices , Your Browser, Your Inbox, Your Thumb and External Drives, Your Old Computer, and Your Cloud Backup . Finally, we’ll discuss Your Network Drives.
Most companies have an internal corporate network with one or more [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_304" class="wp-caption alignright" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/network_sxc.jpg"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/network_sxc-300x225.jpg" alt="If you think that your tangle of Cat5 in the server room is a mess, wait until you look at your network drive file structure. Licensed from Stock Exchange." title="Network" width="300" height="225" class="size-medium wp-image-304" /></a><p class="wp-caption-text">If you think that the tangle of Cat5 in your server room is a mess, wait until you look at your network drive file structure. Licensed from Stock Exchange.</p></div>
<p>This is the seventh post in a series about data breaches you can prevent. We’ve covered <a href="http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you’ll-never-hear-about-your-phone/">Phones and Personal Computing Devices</a> , <a href="http://www.aarontitus.net/blog/2011/03/17/7-sources-of-data-breaches-you’ll-never-hear-about-your-browser">Your Browser</a>, <a href="http://www.aarontitus.net/blog/2011/03/22/7-sources-of-data-breaches-you’ll-never-hear-about-your-inbox">Your Inbox</a>, <a href="http://www.aarontitus.net/blog/2011/03/24/7-sources-of-data-breaches-you’ll-never-hear-about-your-thumb-drive">Your Thumb and External Drives</a>, <a href="http://www.aarontitus.net/blog/2011/03/29/7-sources-of-data-breaches-you’ll-never-hear-about-your-old-windows-95-computer">Your Old Computer</a>, and <a href="http://www.aarontitus.net/blog/2011/03/31/7-sources-of-data-breaches-you’ll-never-hear-about-your-cloud-backup">Your Cloud Backup </a>. Finally, we’ll discuss <strong>Your Network Drives</strong>.</p>
<p>Most companies have an internal corporate network with one or more shared network drives.  If your company network drive is typical, it’s a layered mess of multiple naming conventions, files from employees who haven’t been around for years, and old documents with unrecognizable file extensions.  Frankly, it’s impossible for anyone to know exactly what’s there.</p>
<p><span id="more-335"></span></p>
<p>Sometimes breaches happen when the internal network is not properly segregated.  Only individuals or departments with a “need to know” should have access to sensitive information.  The Human Resource department should never have access to trade secrets, while the R&#038;D department shouldn’t have access to HR data.  The Executive team should have access to confidential client information, while that information might be best kept away from the Sales department.</p>
<p>Aside from inappropriate network segregation network drives, like all computer devices,  are eventually replaced.  Old hard drives are sometimes donated to schools, sold on Ebay, thrown away, recycled through <a href="http://www.good.is/post/best-buy-s-amazing-e-waste-recycling-program/">Best Buy</a> or a similar program, or just stored and forgotten.</p>
<p>Several researchers, including Simpson Garfinkle, have demonstrated that with a small budget you can recover hundreds of thousands of pieces of personal information from used hard drives. Like other computing devices, old network drives must be scanned and completely wiped of all sensitive personal information before they leave your possession.</p>
<p>Remember the fundamentals rules of all data breaches: 1. If you don’t have it, you can’t breach it. 2. Old, forgotten data is dangerous data. Regularly scan these seven types of devices for personal information so that your next breach doesn’t originate from your own computer.</p>
<p>Article first published on <a href="http://www.securitycatalyst.com/">Security Catalyst</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/04/05/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-network-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 Sources of Data Breaches You’ll Never Hear About: Your Old Windows 95 Computer</title>
		<link>http://www.aarontitus.net/blog/2011/03/29/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-old-windows-95-computer/</link>
		<comments>http://www.aarontitus.net/blog/2011/03/29/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-old-windows-95-computer/#comments</comments>
		<pubDate>Tue, 29 Mar 2011 06:02:47 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=326</guid>
		<description><![CDATA[This is the fifth post in a series about data breaches you can prevent. We’ve covered Phones and Personal Computing Devices , Your Browser, and Your Inbox, and Your Thumb and External Drives. Next we’ll discuss Your Old Windows 95 Computer.
Technology has made it easier than ever to be a digital pack rat. Cheap and [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_305" class="wp-caption alignright" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/open_hd_sxc.jpg"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/open_hd_sxc-300x200.jpg" alt="Digital pack rat: You probably have a backed-up copy of your old 256 MB hard drive, don&#039;t you? Licensed from Stock Exchange." title="Open Hard Drive" width="300" height="200" class="size-medium wp-image-305" /></a><p class="wp-caption-text">Digital pack rat: You probably have a backed-up copy of your old 256 MB hard drive, don't you? Licensed from Stock Exchange.</p></div>
<p>This is the fifth post in a series about data breaches you can prevent. We’ve covered <a href="http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you’ll-never-hear-about-your-phone/">Phones and Personal Computing Devices</a> , <a href="http://www.aarontitus.net/blog/2011/03/17/7-sources-of-data-breaches-you’ll-never-hear-about-your-browser">Your Browser</a>, and <a href="http://www.aarontitus.net/blog/2011/03/22/7-sources-of-data-breaches-you’ll-never-hear-about-your-inbox">Your Inbox</a>, and <a href="http://www.aarontitus.net/blog/2011/03/24/7-sources-of-data-breaches-you’ll-never-hear-about-your-thumb-drive">Your Thumb and External Drives</a>. Next we’ll discuss <strong>Your Old Windows 95 Computer</strong>.</p>
<p>Technology has made it easier than ever to be a digital pack rat. Cheap and plentiful memory probably means that you have backed-up a copy of your old 256 MB hard drive, which you also have stashed somewhere in your basement.  Before blindly making back-up copies of old hard drives, make sure that you first delete any information you don’t want to save. </p>
<p><span id="more-326"></span></p>
<p>I see this problem haunt people across the country.  Once a week a university professor somewhere in the United States copies an archived copy of an old hard drive to a web server, without realizing that the hard drive contained social security numbers of students who graduated a decade earlier.  Within weeks those social security numbers can be available to the world via Google.</p>
<p>If you’re a digital pack rat, make sure you scan those old hard drives for sensitive personal information before making backups.  Your old hard drive is one of the biggest sources of preventable data breaches you’ll never hear about. </p>
<p>Article first published on <a href="http://www.securitycatalyst.com/">Security Catalyst</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/03/29/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-old-windows-95-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 Sources of Data Breaches You’ll Never Hear About: Your Thumb Drive</title>
		<link>http://www.aarontitus.net/blog/2011/03/24/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-thumb-drive/</link>
		<comments>http://www.aarontitus.net/blog/2011/03/24/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-thumb-drive/#comments</comments>
		<pubDate>Thu, 24 Mar 2011 06:49:06 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=322</guid>
		<description><![CDATA[This post is the fourth in a series about data breaches you can prevent. We’ve covered Phones and Personal Computing Devices , Your Browser, and Your Inbox. Here we’ll explore Your Thumb and External Drives.
Just about anything that can store information can be used to store sensitive personal information.  Whether you use an external [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_306" class="wp-caption alignright" style="width: 241px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/open_usb_drive_sxc.jpg"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/open_usb_drive_sxc-231x300.jpg" alt="The Law of Portable Device Breaches says that the risk of losing a device, and the information thereon, is directly proportional to its portability. Licensed from Stock Exchange" title="open_usb_drive_sxc" width="231" height="300" class="size-medium wp-image-306" /></a><p class="wp-caption-text">The Law of Portable Device Breaches says that the risk of losing a device, and the information thereon, is directly proportional to its portability. Licensed from Stock Exchange</p></div>
<p>This post is the fourth in a series about data breaches you can prevent. We’ve covered <a href="http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you’ll-never-hear-about-your-phone/">Phones and Personal Computing Devices</a> , <a href="http://www.aarontitus.net/blog/2011/03/17/7-sources-of-data-breaches-you’ll-never-hear-about-your-browser">Your Browser</a>, and <a href="http://www.aarontitus.net/blog/2011/03/22/7-sources-of-data-breaches-you’ll-never-hear-about-your-inbox">Your Inbox</a>. Here we’ll explore <strong>Your Thumb and External Drives</strong>.</p>
<p>Just about anything that can store information can be used to store sensitive personal information.  Whether you use an external drive to back up sensitive data, or use a thumb drive to transfer large files from one computer to another.  The Law of Portable Device Breaches (which I just made up) says that the risk of losing a device, and the information thereon, is directly proportional to its portability. In real terms, this extremely scientific law means that you’re more likely to leave your cell phone at the bar than your desktop computer.</p>
<p><span id="more-322"></span></p>
<p>Readers of this blog no doubt assiduously delete sensitive information from portable devices on a regular basis.  But simply deleting files doesn’t actually erase the data.  Just like cranberry juice on white linen, personal information stains hard drives.</p>
<p>Simply throwing a stained table cloth in the washing machine won’t remove cranberry juice stains. Likewise, simply hitting the “delete” key and emptying the recycle bin won’t completely remove personal information from your thumb or external hard drive.  The hard drive usually remains stained with the sensitive information, which may be recovered until you proverbially “scrub” the drive.  This scrubbing is called “shredding” the file, and typically requires at least a three-step deletion process whereby each byte is individually overwritten.</p>
<p>You should always think twice before copying sensitive files, such as tax documents, pictures, passwords, or confidential documents to removable media.  Regularly scan removable media forgotten personal information so that when you leave your thumb drive in the taxicab, you don’t accidentally cause your own data breach.</p>
<p>Article first published on <a href="http://www.securitycatalyst.com/">Security Catalyst</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/03/24/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-thumb-drive/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 Sources of Data Breaches You’ll Never Hear About: Your Browser</title>
		<link>http://www.aarontitus.net/blog/2011/03/17/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-browser/</link>
		<comments>http://www.aarontitus.net/blog/2011/03/17/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-browser/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 06:36:22 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=314</guid>
		<description><![CDATA[his post is the second in a series about data breaches you can prevent. We’ve already covered Phones and Personal Computing Devices. The next source we’ll explore is Your Browser.
Laptops, desktop computers and smartphones all have built-in internet browsers.  A typical browser can store hundreds of passwords and usernames, credit card numbers, contact information, [...]]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_299" class="wp-caption alignright" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/browsers_sxc.jpg"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/browsers_sxc-300x208.jpg" alt="Your Stored Passwords: Not exactly secured. Licensed from Stock Exchange." title="Browsers" width="300" height="208" class="size-medium wp-image-299" /></a><p class="wp-caption-text">Your Stored Passwords: Not exactly secured. Licensed from Stock Exchange.</p></div>This post is the second in a series about data breaches you can prevent. We’ve already covered <a href="http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you’ll-never-hear-about-your-phone/">Phones and Personal Computing Devices</a>. The next source we’ll explore is <strong>Your Browser</strong>.</p>
<p>Laptops, desktop computers and smartphones all have built-in internet browsers.  A typical browser can store hundreds of passwords and usernames, credit card numbers, contact information, and browsing history.  Even though we use our smart phone browsers to do a significant number of online transactions, typical smart phone browsers do not allow users the same degree of privacy control as desktop browsers.</p>
<p><span id="more-314"></span></p>
<p>Aside from browser hacks and viruses, it’s important to remember that your browser caches remain intact and accessible even after the machine is lost, stolen, or sold. That’s one reason why it’s important to scan your browsers for personal information and delete unnecessary information, and use a <a href="http://websearch.about.com/od/firefox/ss/firefoxoptions_3.htm">master password</a> whenever possible.</p>
<p>I fancy myself a fairly savvy and privacy-aware individual. I use Firefox and have installed several plugins to help me manage my privacy, including <a href="https://addons.mozilla.org/en-US/firefox/addon/6623/">Better Privacy</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/60333/">GoogleShairng</a>, a few <a href="https://addons.mozilla.org/en-US/firefox/search/?q=PrivacyChoice&#038;cat=all&#038;x=0&#038;y=0">PrivacyChoice Plugins</a>, and Abine’s <a href="https://addons.mozilla.org/en-US/firefox/addon/11073/">TACO</a>. But when I ran an <a href="http://www.identityfinder.com">Identity Finder</a> search, even I was shocked to see the depth of information that my browser stored.  It was very sobering to see that my usernames, passwords, and credit card numbers were accessible in plain text.  Fortunately, Identity Finder allowed me to delete or secure all of that information.<br />
If your browser caches are ever lost, it may represent a significant breach of personal information.  So make sure you are aware what information your browser is storing, because you shouldn’t expect to get a letter in the mail if it ever falls into the wrong hands.</p>
<p>Article first published on <a href="http://www.securitycatalyst.com/">Security Catalyst</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/03/17/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-browser/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 Sources of Data Breaches You’ll Never Hear About: Your Phone</title>
		<link>http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-phone/</link>
		<comments>http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-phone/#comments</comments>
		<pubDate>Tue, 15 Mar 2011 06:31:28 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=309</guid>
		<description><![CDATA[his post is the first in a series about preventable data breaches. Most Americans have received a letter, telling them that their personal information has been breached. But there are many breaches you’ll never hear about, and many of them are right under your nose. The first source we’ll explore is Your Phone and Personal [...]]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_307" class="wp-caption alignright" style="width: 310px"><a href="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/smart_phone_sxc.jpg"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2011/01/smart_phone_sxc-300x225.jpg" alt="Smart phones are now portable computers which just happen to make calls. Licensed from Stock Exchange." title="Smart Phone" width="300" height="225" class="size-medium wp-image-307" /></a><p class="wp-caption-text">Smart phones are now portable computers which just happen to make calls. Licensed from Stock Exchange.</p></div>This post is the first in a series about preventable data breaches. Most Americans have received a letter, telling them that their personal information has been breached. But there are many breaches you’ll never hear about, and many of them are right under your nose. The first source we’ll explore is <strong>Your Phone and Personal Computing Device</strong>.</p>
<p>Remember when cell phones were telephones?  Those days are long gone. The current generation of smart phones are powerful computing devices which just happen to also make phone calls.</p>
<p><span id="more-309"></span></p>
<p>Your personal computing devices perform almost all of the functions of a laptop computer.  Smart phones, iPads, Kindles, and other devices are notoriously easy to lose, and store gigabytes of files, passwords, credit card numbers, social security numbers, digital photos, address books, and email attachments.  Because of the wealth of personal information on a cell phone, most people would rather lose their wallets, and nearly all respondents to a <a href="http://www.pcworld.com/businesscenter/article/166628/bigger_loss_cell_phone_or_wallet.html">2009 survey</a> said they would be “devastated” if they lost their phone.</p>
<p>Upgrading your phone can be as risky as losing it.  Some people donate their old phones to charity or sell them on Ebay, and experts warn that personal information on the phone could easily be mined and re-sold.  Periodically search your cell phone for personal information, and make sure that you digitally shred the entire contents of your mobile device before you get rid of it.</p>
<p>Article first published on <a href="http://www.securitycatalyst.com/7-sources-of-data-breaches-you’ll-never-hear-about-your-phone">Security Catalyst</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2011/03/15/7-sources-of-data-breaches-you%e2%80%99ll-never-hear-about-your-phone/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A Message From Walgreens</title>
		<link>http://www.aarontitus.net/blog/2010/12/12/a-message-from-wallgreens/</link>
		<comments>http://www.aarontitus.net/blog/2010/12/12/a-message-from-wallgreens/#comments</comments>
		<pubDate>Sun, 12 Dec 2010 05:09:19 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=281</guid>
		<description><![CDATA[A friend of mine recently received the following email from Walgreens:
December 10, 2010
Dear Valued Customer,
We recently became aware of unauthorized access to an email list of customers who receive special offers and newsletters from us. As a result, it is possible you may have received some spam email messages asking you to go to another [...]]]></description>
			<content:encoded><![CDATA[<p>A friend of mine recently received the following email from Walgreens:</p>
<blockquote><p>December 10, 2010<br />
Dear Valued Customer,</p>
<p>We recently became aware of unauthorized access to an email list of customers who receive special offers and newsletters from us. As a result, it is possible you may have received some spam email messages asking you to go to another site and enter personal data. We are sorry this has taken place and for any inconvenience to you.<br />
<span id="more-281"></span><br />
We want to assure you that the only information that was obtained was your email address. Your prescription information, account and any other personally identifiable information were not at risk because such data is not contained in the email system, and no access was gained to Walgreens consumer data systems.</p>
<p>We realize you previously unsubscribed from promotional emails from Walgreens, and that will continue. As a company, we absolutely believe that all customer relationships must be built on trust. That is why we believe it is important to inform you of this incident. Online security experts have reported an increase in attacks on email systems, and therefore we have voluntarily contacted the appropriate authorities and are working with them regarding this incident.</p>
<p>We encourage you to continue to be aware of increasingly common email scams that may use your email address to contact you and ask for personal or sensitive information. Always be cautious when opening links or attachments from unsolicited third parties. Also know that Walgreens will not send you emails asking for your credit card number, social security number or other personally identifiable information. So if ever asked for this information, you can be confident it is not from Walgreens.</p>
<p>If you have any questions regarding this issue, please contact us at 1-888-980-0963. We take your privacy very seriously, and we will continue to work diligently to protect your personal information.</p>
<p>Sincerely,<br />
Walgreens Customer Service Team</p></blockquote>
<h1>Translation</h1>
<blockquote><p>Dear Valued Former Customer Who Doesn’t Want to Hear From Us,</p>
<p>We know you have already unsubscribed from our mailing lists. You may have thought that we deleted your email address, but in fact we decided to keep your email in our databases anyway.  Now it was stolen. Sucks to be you, because now you’ll probably get more spam and scam mail. We reported the breach to the police, knowing full well that they don’t care one little bit, but we at least hope do some PR damage control by looking serious about this.</p>
<p>Sincerely,<br />
Wallgreens</p>
<p>P.S. We still don’t plan to actually delete your email address from our systems and eliminate the risk of a future breach.</p></blockquote>
<p>Well, at least I have to give them points for owning up to the breach.  Many companies wouldn&#8217;t even do that much.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/12/12/a-message-from-wallgreens/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Four Most Fundamental Challenges to Privacy of 2010</title>
		<link>http://www.aarontitus.net/blog/2010/10/20/the-four-most-fundamental-challenges-to-privacy-of-2010/</link>
		<comments>http://www.aarontitus.net/blog/2010/10/20/the-four-most-fundamental-challenges-to-privacy-of-2010/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 19:15:24 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=272</guid>
		<description><![CDATA[
EPIC Privacy 2010 Election Campaign Comments Wednesday October 13, 2010; 8:30 – 10:00 AM The Mott House, 122 Maryland Avenue NE
Thank you for having me here today. My name is Aaron Titus. I am an attorney and the Privacy Director for the Liberty Coalition. The Liberty Coalition works with more than 80 partner organizations from [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.aarontitus.net/blog/wp-content/uploads/2010/10/epic_logo.jpg"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2010/10/epic_logo.jpg" alt="Electronic Information Privacy Center" title="Electronic Information Privacy Center" width="260" height="92" class="alignright size-full wp-image-277" /></a>
<p><em><a href="http://www.privacy2010.org/">EPIC Privacy 2010 Election Campaign</a> Comments<br /> Wednesday October 13, 2010; 8:30 – 10:00 AM<br /> The Mott House, 122 Maryland Avenue NE</em></p>
<p>Thank you for having me here today. My name is Aaron Titus. I am an attorney and the Privacy Director for the Liberty Coalition. The Liberty Coalition works with more than 80 partner organizations from across the political spectrum on transpartisan issues to preserve the Bill of Rights, personal autonomy and individual privacy. The Liberty Coalition works with, but does not speak on behalf of our partners.</p>
<p>We have heard about several substantial policy issues today. I would like to focus on some of the underlying reasons that Privacy has an uphill battle. The Four Most Fundamental Challenges to Privacy in 2010 are:</p>
<ol>
<li>The False Notion that one can “Own” Personal Information</li>
<li>The Failed Notice and Consent Legal Regime</li>
<li>Erosion of the Definition of Privacy</li>
<li>The Two Mortal Enemies of Privacy: Convenience and Fear</li>
</ol>
<p> <span id="more-272"></span><br />
<h2>Who Owns My Data?</h2>
<p>The cultural notion that you can “own” personal information is the single biggest threat to privacy because if you can own my personal information, you can own me.  In a very real sense, I am Data. And if I am Data, and Data is Property, then I may become Property.</p>
<h3>We are Data</h3>
<p>As Daniel Solove wrote, you are not much more than “an electronic collage of bits of information, a digital person composed in the collective computer networks of the world.” This collage is our “Data Self:” A digital alter-ego capable of entering contracts, committing crimes, and going into debt.  It’s more than a copy or digital shadow, because you are responsible for the actions of your Data Self.</p>
<p>You are bound by contracts your Data Self signs; you will to jail for crimes your Data Self commits.  If someone forces your Data Self to take out a loan, you must repay it. If your Data Self has an operation, you may no longer qualify for medical insurance.</p>
<p>
<h3>Data is Property</h3>
<p> Intellectual Property Law treats data like property because 1. Data has value, like property. 2. Data is fungible, like property, and 3. Data is alienable, like property. Most types of information (ie, trade secrets, copyrightable or patentable information, etc) are valuable, fungible, and alienable.</p>
<p>If personal information really were property, then I should be able to permanently sell, or “alienate,” it. But unfortunately, I can’t sell personal information like a car. If I sell my car and the new owner runs it into a tree, it’s not my problem. But we all know that if I “sell” my personal information and the new owner “crashes” my identity, I suffer. Unlike all forms of property, personal information is inherently inalienable. You can’t get rid of it. But because personal information is valuable and fungible, it is often treated like property as a practical matter.</p>
<p>But intellectual property rights in personal information have little basis in law. Most personal information, such as names, addresses, phone numbers, and social security numbers are facts. Facts are not copyrightable.2 You can’t patent personal information,3 and it certainly isn’t a trade secret.4 In short, nobody “owns” my name, including myself.</p>
<p>Even if we could invent an imaginary intellectual property right to one&#8217;s personal information, in most cases the most logical owner would be third parties who created it. My parents would most likely “own” my name and DNA, since they made it up.  My mother and her doctor had much more to do with my date of birth than I did. Credit card companies would &#8220;own&#8221; my credit card number. The government would &#8220;own&#8221; my Social Security Number, and the Post Office would &#8220;own&#8221; my address.</p>
<p>Personal information cannot be property.</p>
<h3>We are Property</h3>
<p>But as long as we treat personal information as property, we are faced with an unavoidable dilemma:  If We are Data and Data is Property, then We may become Property. Just yesterday Security Expert Bruce Schneider underlined this fact when he said, “<strong>We&#8217;re not Facebook customers, we&#8217;re Facebook&#8217;s product it sells to its customers [the advertisers].</strong>”</p>
<p>The now popular crime of Identity Theft is the most visible consequence of this trend. In fact, <strong>the term “Identity Theft” epitomizes the problem with treating personal information as property: The very term recognizes that you have an alter-ego “identity” or Data Self. And it acknowledges that your Data Self can be stolen and abused, like property.</strong>
<p><strong>If we are data and data is property, then we may become property.</strong></p>
<p>Facing the possibility of a new class of crimes, we cannot afford to allow personal information to be treated as government or corporate property.  I must have control over my personal information, because I am my personal information.</p>
<h2>Replacement of the Notice and Consent Legal Regime</h2>
<p>The second most fundamental Privacy issue of 2010 is the failed Notice and Consent Legal Regime. At its core, Notice and Consent allows almost all privacy protections to be waived with proper notice and implied consent.  In most cases, Notice and Consent provides no baseline protections, and as Marc Rotenberg has said many times, the Notice and Consent legal regime stands in opposition to Fair Information Practice Principles (FIPPs).  Notice and Consent has failed to protect consumers because the market does not value privacy. </p>
<p>As Fred Cate of the Center for Applied Cybersecurity Research explained, the Notice and Consent model is flawed because some activities should not be consentable.  Just like one may not &#8220;consent&#8221; to be served fraudulent or misleading advertising, some uses of personal information should be prohibited and non-consentable.</p>
<h2>Eroding Definition of Privacy</h2>
<p>The third most fundamental Privacy issue of 2010 is an Eroding Definition of Privacy.  As an attorney, I have learned the importance of definitions. I can promise you the world, but if I define the term “world” as “pocket lint,” you can guess who wins.</p>
<p>I fear that the public doesn’t really know what privacy is.  And elected officials have done little to advance the public discourse.  Instead, the public discussion has been dominated by DHS, the TSA, Google, Facebook, and others.  These entities have drastically narrowed the definition of privacy, often attempting to narrow it to nothing more than “security.”  We are losing the world and ending up with pocket lint.</p>
<p>With a narrow or ambiguous definition of privacy, promises to “protect civil rights, civil liberties, and privacy” become either superfluous or illusory.  The reason is simple:  Without knowing what exactly we’re protecting, it’s impossible to know whether or when we’ve succeeded. It’s almost like saying “We’re going to make the world a better place:” Fluffy goodness that means nothing.</p>
<p>Elected officials must insist on a risk-assessment approach when developing strategies to mitigate the risks to civil liberties, civil rights, and privacy.  The first step in that process is to enumerate all of those liberties and rights. We need to talk more about privacy, Anonymity, Freedom of speech, and Rights against searches and seizures, for example.</p>
<p>Next, define each of those liberties.  Third, identify the risks to those liberties.  Fourth, identify strategies to mitigate those risks. And finally, weigh the cost of implementing the strategies against the benefits.  When we do not evaluate what civil rights and liberties are threatened, we are at greater peril of losing them.</p>
<p>We cannot expect the public to stand up for privacy when they do not understand what they’re fighting for. We need public officials who will remind the public what their civil liberties and civil rights are.</p>
<h2>The Two Mortal Enemies of Privacy: Convenient Technology and Fear of Insecurity</h2>
<h3>Private Sector: Convenience</h3>
<p>In the private sector, within the context of the Notice and Consent Legal regime, Convenience and Technology continue to be the mortal enemies of Privacy.</p>
<p>It turns out that much of the privacy we have enjoyed for generations did not have roots in constitutional law, but convention reinforced by high transaction costs.  As technology has reduced transaction costs, practical privacy protections have diminished or disappeared altogether.</p>
<p>Take Identity Theft, for example.  Identity Theft is when someone pretends to be you, does something bad, and you get blamed.  Identity theft has always existed. But 15 years ago, you had to drive down to the county courthouse, walk up to the third floor, get a copy of a birth certificate, then walk up to the 5th floor, then drive over to the DMV… The transactional costs for stealing an identity were very high.</p>
<p>Medical records were far more confidential when they were written on paper. It’s not that the legal privacy protections were any greater than they are now, but the cost of sharing the information was prohibitive.  Technology universally increases efficiency and decreases transactional costs.  Medical information is more efficiently shared with researchers, leading to better treatments.  Detailed profile information is efficiently, instantly and cheaply shared with a three dozen affiliate companies. Breaches of enormous proportion and identity theft have never been cheaper or more efficient.</p>
<h3>Government: Fear of Insecurity</h3>
<p>Counterterrorism in this country is more about mitigating terror, or fear, than saving lives.  We hold to a false notion in this country that perfection is somehow attainable, and that when something goes wrong it was because someone failed, and someone is to blame.</p>
<p>As Americans we are very bad at weighing risk, which is why we demand to feel secure.  And our lawmakers deliver:  The American people now (arguably) demand to be digitally strip searched and groped every time they walk onto an airplane.  We take off our shoes. We’re all pretty sure that someone over at the NSA could read our emails if they wanted to. We are all familiar with the term, “warrantless wiretapping,” “National Security Letters,” and “Warantless GPS tracking.”  But we are mollified by telling ourselves either we have “nothing to hide,” or “I’m too boring for anyone to pay attention to.”  After all, most antelope in the herd never get eaten.</p>
<p>We are terrorizing ourselves.</p>
<p>When people say, &#8220;I have nothing to hide,&#8221; they really mean, &#8220;I am not ashamed of anything.&#8221;  The truth is, we all have a lot to hide, and shame is just one of many reasons to keep information private or confidential.  Having something to hide is not an admission of guilt, and it doesn&#8217;t mean you have anything to be ashamed of.</p>
<p>We keep Social Security Numbers private not because we&#8217;re ashamed of the number, but because we fear identity theft.  Sometimes medical conditions remain confidential because others may react irrationally to them. The Census now zealously guards its information because during World War II, the Federal government acted irresponsibly with truthful census data about the location of Japanese-American citizens.</p>
<p>The need for privacy is the recognition that individuals and institutions act unreasonably and irresponsibly, to the detriment of individuals and society, when in possession of certain truthful facts.  In short, humans aren’t always equipped to handle the truth. We are biased.</p>
<h2>Conclusion</h2>
<p>Again the Four Most Fundamental Challenges to Privacy of 2010 are:
<ol>
<li>The False Notion that one can “Own” Personal Information</li>
<li>The Failed Notice and Consent Legal Regime</li>
<li>Erosion of the Definition of Privacy</li>
<li>The Two Mortal Enemies of Privacy: Convenience and Fear</li>
</ol>
<p> Thank you for having me.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/10/20/the-four-most-fundamental-challenges-to-privacy-of-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP Code to Select an Option After a Form Post</title>
		<link>http://www.aarontitus.net/blog/2010/10/09/php-code-to-select-an-option-after-a-form-post/</link>
		<comments>http://www.aarontitus.net/blog/2010/10/09/php-code-to-select-an-option-after-a-form-post/#comments</comments>
		<pubDate>Sat, 09 Oct 2010 15:37:39 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Code]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=262</guid>
		<description><![CDATA[I have a couple of php pages with $_POST[] forms which I validate (using PHP).  If the form fails validation (ie, the user fails to enter an email address), then the user is brought back to the same page, where he is asked to re-submit the missing or incorrect information.  The form also [...]]]></description>
			<content:encoded><![CDATA[<p>I have a couple of php pages with $_POST[] forms which I validate (using PHP).  If the form fails validation (ie, the user fails to enter an email address), then the user is brought back to the same page, where he is asked to re-submit the missing or incorrect information.  The form also has radio buttons and drop-down forms, and I don&#8217;t want to make the user re-select those radio buttons or drop-down entries.  So this is my solution:<span id="more-262"></span></p>
<h2>Re-Select a Drop-Down Entry</h2>
<p><code>
<pre>
#####################################################################
# FUNCTION: Select a previously selected option in a drop-down list #
function option_selected($name, $value) {
$v=$_POST[$name]; // Retrieve the $_POST[] value of the just-submitted drop-down selection
	if ($v == $value) {
		$selected = "selected";
	}
//echo $selected; // use this if you're embedding the function as a php call within an html file.
return $selected; // use this if you want to dump the results to a php variable.
}
</pre>
<p></code></p>
<p>This is how to implement the code in PHP/ HTML:<br />
<code>
<pre>
&lt;form action=&quot;&lt;?php echo $PHP_SELF;?&gt;&quot; method=&quot;post&quot;&gt;
Send To:
	&lt;select name=&quot;sendTo&quot;&gt;
	&lt;option value=&quot;None&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;None&quot;); ?&gt;&gt;&amp;mdash;WHOM?&amp;mdash;&lt;/option&gt;
	&lt;option value=&quot;Boss&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;Boss&quot;); ?&gt;&gt;A Boss or Supervisor&lt;/option&gt;
	&lt;option value=&quot;Teacher&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;Teacher&quot;); ?&gt;&gt;A Teacher&lt;/option&gt;
	&lt;option value=&quot;Client&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;Client&quot;); ?&gt;&gt;A Client&lt;/option&gt;
	&lt;option value=&quot;Friend&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;Friend&quot;); ?&gt;&gt;A Friend or Peer&lt;/option&gt;
	&lt;option value=&quot;Child&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;Child&quot;); ?&gt;&gt;A Child&lt;/option&gt;
	&lt;option value=&quot;Self&quot; &lt;?php echo option_selected(&quot;sendTo&quot;, &quot;Self&quot;); ?&gt;&gt;Yourself (ie, reading a book)&lt;/option&gt;
	&lt;/select&gt;
&lt;/form&gt;
</pre>
<p></code><br />
So, if the person selected &#8220;Teacher&#8221; before submitting the form, then the word &#8220;selected&#8221; will be printed in the Teacher option, causing it to be pre-selected:</p>
<p>Send To:<br />
<select name="sendTo"> <option value="None" >&mdash;WHOM?&mdash;</option><br />
<option value="Boss" >A Boss or Supervisor</option><br />
<option value="Teacher" selected>A Teacher</option><br />
<option value="Client" >A Client</option><br />
<option value="Friend" >A Friend or Peer</option><br />
<option value="Child" >A Child</option><br />
<option value="Self" >Yourself (ie, reading a book)</option><br />
</select>
<h2>Re-Select a Radio Button or Checkbox Entry</h2>
<p>The code is almost identical to the function above, except that we use the word &#8220;checked&#8221; to pre-select a checkbox or radio button:<br />
<code>
<pre>
##########################################################################
# FUNCTION: Select a previously selected option in a radio or check list #
function option_checked($name, $value) {
$v=$_POST[$name];
	if ($v == $value) {
		$checked = "checked";
	}
//echo $selected; // use this if you're embedding the function as a php call within an html file.
return $selected; // use this if you want to dump the results to a php variable.
}
</pre>
<p></code></p>
<p>This is how to implement the code in PHP/ HTML:<br />
<code>
<pre>
&lt;?php $gender = $_POST['gender'] ?&gt;
&lt;form action=&quot;&lt;?php echo $PHP_SELF;?&gt;&quot; method=&quot;post&quot;&gt;
Choose Study Partner Gender: 
	&lt;input type=&quot;radio&quot; name=&quot;gender&quot; value=&quot;Either&quot; id=&quot;either&quot; &lt;?php if (empty($gender)) {echo &quot;checked&quot;;} else {echo option_checked(&quot;gender&quot;, &quot;Either&quot;);} ?&gt; /&gt; No Preference &lt;br /&gt; 
	&lt;input type=&quot;radio&quot; name=&quot;gender&quot; value=&quot;Female&quot; id=&quot;female&quot; &lt;?php echo option_checked(&quot;gender&quot;, &quot;Female&quot;); ?&gt; /&gt; Female &lt;br /&gt; 
	&lt;input type=&quot;radio&quot; name=&quot;gender&quot; value=&quot;Male&quot; id=&quot;male&quot; &lt;?php echo option_checked(&quot;gender&quot;, &quot;Male&quot;); ?&gt; /&gt; Male &lt;br /&gt;
&lt;/form&gt;
</pre>
<p></code></p>
<p>Note that I check to see if $gender has been set. If not, I choose a default.  This is important because unlike a drop-down, check boxes and radio buttons don&#8217;t automatically select a default unless you tell them to. If the user had selected &#8220;Female&#8221; before submitting the form, she would see this when the page re-loaded:</p>
<p>Choose Study Partner Gender:<br />
<input type="radio" name="gender" value="Either" id="either" /> No Preference </p>
<input type="radio" name="gender" value="Female" id="female" checked /> Female</p>
<input type="radio" name="gender" value="Male" id="male" /> Male </p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/10/09/php-code-to-select-an-option-after-a-form-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

