People-Based Privacy Concerns
- caused by people’s actions
- concerns are raised when:
- people compromise others’ privacy
- people take actions that compromise their own data privacy
- information security attacks can result in privacy violations:
- Phishing
- privacy concern for both individuals and organizations
- For the individual
- a successful phishing attack can result in the loss of personal information
- For organizations
- if an employee responds to a scam with username and password information, the organization can experience a large data breach
- can involve customers’ personal information
- Social engineering
- Shoulder surfing
- Dumpster diving involves sifting through trash to discover personal information
- individuals and organizations dispose of personal information in unsecure ways
- Thieves then steal PII to commit identity theft
Social Networking Sites
- People can harm their own privacy by participating in online social networks
- Users often share large amounts of highly personal data on social networking sites
- Social networking has two main privacy concerns:
- Information (over) sharing
- users share lots of information about themselves in a virtually unlimited forum
- Security
- Many sites allow users to add applications and other third-party software to their profiles
- If they do not use proper security practices, personal information can be exposed
Online Data Gathering
- can search the internet for data on their neighbors, coworkers, family members, prospective dates, and public figures