Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, August 29, 2015

The Perfect Crime

When the news first broke about the Ashley Madison data intrusion, I’ll admit that my reaction wasn’t very mature: I regarded it as an amusing example of schadenfreude and watched all of the stories about people threating lawsuits because their lives had been “ruined” with the sort of glee we reserve for other people’s misfortunes. It’s not that I had or have anything against these people – I’m not a prude, and I’m not about to start trying to tell other people how to live their lives – it’s just that the level of naiveté involved was hilarious. All of us have a certain amount of personal information online, and are accepting a corresponding amount of personal risk, but very few people are ever going to share information that could destroy their entire lives with an organization whose business model is based on helping customers betray someone else. A new analysis of the leaked information suggests that the joke may be on the Ashley Madison users in more ways than one, however…

You can pick up Annalee Newitz’s excellent article direct from the Gizmodo website if you’d like to see the actual numbers, but if this report is accurate then less than .03% of the A/M accounts were actually being used by female clients in the first place. The company’s own user data already indicated that male users outnumbered female users by nearly six to one, but the Gizmodo report shows that males outnumber females on the company’s internal chat function by 4,579 to one, while approximately 13,585 men use the company’s message function for every female who does. And those figures don’t even include male users who registered as female when they signed up for the site, which is apparently very common. There is also good evidence that thousands, or possibly tens of thousands, of the nominally female accounts on the site were created in-house by Ashley Madison personnel in order to attract male customers…

If those numbers and accusations seem familiar, it’s probably because we’ve been seeing similar charges leveled at conventional dating sites for almost as long as this category of web businesses has existed. For all of the company’s efforts to market itself as a specialized service for adulterers, it appears to be nothing more than a very expensive dating site. And while criminal prosecution for leaving all of these clients’ personal information vulnerable to data theft seems unlikely, what struck me was that the company’s primary defense against accusations of fraud – and demands for refunds – has just evaporated along with the supposed confidentiality of the users…

Prior to the data breech, the odds of any given Ashley Madison user taking the company to court – or pressing any criminal charges, for that matter – was negligible, not because of the constant disclaimers all over the site, but because any potential disgruntled users would be exposing themselves as adulterers (or would-be adulterers, at least) the moment they publically admitted to joining the site in the first place. The company didn’t even need to create faked accounts, really, other than for marketing purposes (“Look! See how many attractive women there are on our site!”), because who was going to complain?

Now, we should probably acknowledge that running a profitable dating site is a difficult proposition, and doing so without providing a conduit for illicit affairs – or stalkers, predators, thieves, and other criminals for that matter – is going to be impossible given the nature of Internet connections. Maintaining a balance between people of both genders and a variety of other selection factors (e.g. age, income level, location, interests, physical appearance, and other demographics) wasn’t easy even in the pre-Internet days, when a single year of an old-style dating service (face-to-face introductions) cost around $3,600 a year in today’s money. With no personal contact, and therefore no way to tell who was being honest about their identity and who was lying through his or her teeth, there’s no way the company could have prevented a situation where male users outnumbered females 6 to 1 or even 13,000 to one. It seems unfortunate that they should have chosen to obfuscate, rather than just providing the service and letting the cards fall where they might…

I’m not sure how this one is going to end. Will the company go under? Will any of the litigation being filed against them come to anything? Will people learn from their misfortunes, or possibly from the misfortunes of others, and stop putting information online that could cost them everything they have? It is possible that at least some people out there in cyberspace will take this as a wake-up call; it’s even possible that it might make a few people stop and reflect on whether they really want to go through with cheating on their spouse in the first place. Perhaps in the long run people will be more careful, consider the potential consequences of their actions, treat their customers more honestly and deal with each other more openly, and the Internet in general will become a slightly less awful place…

Just between you and me, though, I would not put money on it…

Tuesday, March 22, 2011

Such a Little Snowball

Just for the record, I’ve tried the trick where you roll the snowball down the slope, and it starts picking up more and more snow, eventually turning into a snowball the size of your house, which then also scoops up your enemies and carries them away from you in an amusingly cartoonish fashion that inexplicably fails to hurt anyone or anything despite involving the out-of-control movement of several metric tons of snow. That is, I’ve tried to do it, and after many dozens of attempts over the course of forty or so miss-spent years, I’m forced to conclude that while this works brilliantly as a metaphor for things getting out of control, it doesn’t work that way in the real world. I would like to point out, however, that allowing private companies to palm off security costs onto a Federal agency paid for by tax funds also doesn’t work in the real world…

A press release issued last week by the U.S. Travel Association details the findings of a blue-ribbon panel comprised of former DHS officials (including former Chairman Tom Ridge), congressmen and industry experts on the effect that the increases in baggage fees and similar games have had on air travel, and the industry in general. This isn’t necessarily the most impartial organization on the face of the planet; the USTA is an organization of boosters for the travel industry, and it is primarily made up of and supported by people who make money off of tourists and travelers of all types. But at the same time, this panel isn’t anybody’s choice for leftists and anti-business hippies; most of the roster is big-business Republicans and actual government officials – and they don’t have anything nice to say about the way the crackpot TSA screenings are affecting their industry…

Consider, for example, the depressing effect the TSA screenings have had on non-essential travel. We’ve all heard stories about people deciding not to fly – or to avoid travel at all – because they can’t abide the thought of being groped and probed on their way to the gate. The USTA panel’s findings suggest that the average traveler has cancelled two to three trips per year, resulting in a loss in business of $85 billion in business and 900,000 jobs. Now, granted that this does not consider jobs gained in the automobile, bus and train building companies, petroleum companies, or businesses that provide roadside assistance; nor does it acknowledge the fact that TSA behaving like buffoons appears to be the key turn-off, not anything the airlines have done. It is still a mind-boggling idea, and all the more so since all of the international experts who have been asked to comment on the TSA enhanced screenings have claimed that these business-destroying routines are also completely useless in terms of preventing actual terror attacks on airplanes…

It remains to be seen if the remedies the USTA panel is suggesting will do any good; certainly, removing the first-bag baggage fee might encourage people to carry on less baggage, shortening the search times and speeding up the checkpoints. It’s also possible that a “trusted flyer” express lane program, at least a completely voluntary one, might speed up these lines without turning our entire nation into the Orwellian nightmare its opponents like to describe. But the reason I’m calling it to your attention in a business blog – and comparing it to a cartoon snowball in the first place – is that this isn’t just a security threat imposed by foreign enemies or a profit-boosting stunt installed by the airlines to help make a fast buck. The truth is, the failure of our airline security systems on September 11, 2001 can be directly blamed to the airline industry fighting tooth and nail against anything resembling proper security laws for over fifty years, and then imposing the new baggage fees to try and recover some of the cost when the consequences of their lobbying actions finally blew up in their faces…

And whether your chosen metaphor involves snowballs, birds coming home to roost, or anthropomorphic bunnies and puppies playing basketball, nothing is going to change until we start demanding accountability from our governments (as citizens), from our business leaders (as stockholders), and from the companies themselves (as customers), and hold the people responsible for these crimes against intelligence and occasionally sanity responsible when things go horribly wrong, in the sky or in our economy…

Sunday, April 26, 2009

The Obvious Approach

Like most of you, I’ve been watching the Somali pirate saga developing, and wondering what could be done about it. Getting the Somali government to do anything about these relatively low-tech ocean-going thieves is probably futile, since the pirates are held in higher regard than any of the countries demanding their suppression, both by what passes for an official government in Somalia, and also by the Somali people themselves. Generally, these efforts have resulted in the “government” agencies siding with the pirates…

Unfortunately, so far at least, simply avoiding the area would still be more expensive than paying the increase insurance premiums (and occasionally ransom) in order to get your ships back. And frankly, asking the shipping companies to make less money because of the principle of the thing ignores the reality of business: shipping companies exist to make money, not hold firmly to their principles. The only way the situation is going to change is either for the various navy units (ours and those of other nations who are fed up with these criminals) to hunt down the pirates or for someone to come up with a lower-cost solution to the problem…

I was therefore very glad to read about an Italian cruise line that appears to have found just such an answer. In a story being reported by The Associated Press, it would appear that a group of Somali pirates attempted to attack one of the line’s passenger ships on Saturday, only to be driven off by gunfire and water cannon fire from the ship’s Israeli security personnel, who had in fact been hired for just such a contingency. While the security force was limited to handguns and fire hoses, it’s difficult to climb a ladder while someone is shooting at you (or blasting at you with a hose), and the pirates eventually gave up…

It remains to be seen if this will work out on a larger scale, however. Putting extra personnel on a cargo ship isn’t likely to be cost-effective (there are too many ships), and the various shipping companies have to worry about violating local gun laws when their ships make port. Still, I can’t help wishing that we could put small Marine detachments aboard every U.S.-flagged ship that passes through the area for a year or so. Or even every 10th or 12th one. With orders to kill any pirate who comes into range and sink their miserable little boats, too. I suspect that as soon as word got around, no one would be attacking anything flying a U.S. flag…

Alternately, I suppose, various countries could just contract the work out to the Israelis, who would probably be happy for both the positive foreign exchange and the public relations benefits. It has the potential for huge savings, improved international relations, and safer high seas travel, with the Somali pirates as the only losers, even potentially. And it would certainly be cheaper than the 60-ship international naval task force the experts are saying would be necessary to actually patrol the sea lanes in that part of the world…

Of course, the fact that the cruise line hired Israeli security personnel because “they are the best trained” is an excellent example of how a brand name works – in this case, the “brand” being an entire nation of people who have earned their reputation for being tough customers who don’t put up with much. But that’s a post for another day…

Friday, December 5, 2008

Hotel Security

Suppose for a moment that you owned and operated a hotel in a costal city, possibly even somewhere near a harbor or a marina. Suppose a boatload of heavily-armed idiots washes up on your beachfront and attacks your hotel, apparently just because some rather more charismatic idiot has told them that Americans are bad, killing innocent people without warning is good, and God wants them to do this. What, exactly, are you going to do about it?

That seems to be the question on a lot of people’s minds following the attacks in Mumbai, at least according to articles being reported on USA Today Online. Police in New York City are running training exercises based on a similar scenario, while people in Miami are worried because not only is the entire city accessible by water, they already have dozens (scores? Hundreds? Thousands? No on really knows) of unauthorized boats coming ashore every week. If you can smuggle a large bale of South American agricultural products into this country whenever you want to, then getting a few people and a few hundred pounds of weapons and explosives ashore doesn’t sound all that difficult. Nor can you expect the Coast Guard to completely seal off a coast as large as ours, even with help from the Navy…

Taken at face value, of course, it’s a silly question: there is no way you can equip your hotel with bomb-proof walls, bullet-resistant windows, bunkers for your guests to sleep in, or platoons of armed guard roaming the grounds looking for invading terrorists, nor should you try to do so. Matters of national security are best left to the government agencies charged with those matters, and no private citizen or business owner is going to be able to take those matters into their own hands. The degree to which this remains a serious question is, to what extent will your customers EXPECT you to protect them from armed threats? And if you don’t, how will this affect your business?

Banks have employed armed security guards for decades, not because these worthies (often retired police officers) are expected to engage and defeat groups of armed bank robbers, but rather because they provide a reassuring presence for the law-abiding customers – and because there is always a chance that a lone bank robber will fail to notice the bank guard in time, of course. If people become concerned enough about violent crime it may become financially prudent for hotels to re-introduce the position of Hotel Detective onto their staff, as well as beefing up security measures like locked doors and closed-circuit cameras…

None of which will do the bottom line any good, of course – especially during a time of economic downturn, when most people are already curtailing all non-essential travel. But if the choice is implementing such security measures or losing business (potentially all of your business) to competitors that have, we might very well start seeing increased security as a standard feature in high-class hotels. One could easily imagine these security measures becoming a selling point (featured in the advertising, perhaps?) as hotels compete to become your safest holiday option.

Which brings me back to my original point: you might regard the attacks on Mumbai to be unfathomable goings-on from the other side of the world. You might believe that just because you don’t live in India (or Miami) your business will never have to deal with boatloads of sea-borne murderous idiots. You might even be completely correct in these beliefs. But if your customers do not share in your optimism, then these attacks may impact your business, too, even if you run a Holiday Inn somewhere in the middle of Kansas…

Tuesday, November 25, 2008

The Ethics of Litigation

Last week I ran across one of those news stories that makes you wonder if somebody out there is just making this stuff up: a guy left his cell phone in a McDonalds, and is now suing the employees of the restaurant, the franchise owner, and the parent corporation because the naked pictures of his wife that were stored on the phone’s internal memory have been stolen and posted on the Internet. You can read the story here on MSNBC if you want to verify that I am not, in fact, making any of this up…

The lawsuit alleges that the reason the guy should be able to recover damages from McDonalds is that the employees at the restaurant promised they would secure the phone until he could return and collect it, and therefore one of them must have stolen the files and posted them online. The company won’t comment on pending litigation (and the employees would be insane to open their mouths about this), so there is no confirmation of that; we’re not clear on how long the phone was sitting around the dining area before anyone found it, how many other people might have had access to it, or even if any employee ever made any such promise. For all we know, the owner uploaded those pictures himself as a prelude to a lucrative lawsuit against a huge deep-pockets corporation…

But let’s leave the legal insanity of the case out of it for a moment; let’s not even comment on the mind-numbing stupidity of not only carrying around picture files of your spouse naked but then also leaving the device containing those files unattended in a public place. The business-related question here is, if you were the franchise owner (or senior management for McDonalds) what would you do about this issue, and how would you try to keep it from happening again? Because if this case recovers even the price of a Big Mac, you can better your last dime that dozens (or thousands) of other scam artists will try the same trick…

Of course, this is why so many businesses have signs posted that say “We are not responsible for any articles lost, stolen, sold on eBay or posted onto the Internet because you’re too stupid to know better,” and we can safely assume that if those actually help, every McDonalds that doesn’t already have one will be sporting one very soon now. In theory, you could also use closed-circuit TV cameras to record what goes on in the store, and in fact a lot of retail and food service companies do, but this won’t tell you if somebody left their phone behind as a scam or just forgot about it. It won’t even tell you whether one of your employees copied, saved or emailed the pictures unless you monitor the cameras every moment of the day – which we’ve established you can’t if you want to also run a business…

From an ethics standpoint, the question is really this: Do you, as the owner of a business (franchise) have any responsibility to prevent your customers from being damaged, humiliated or otherwise injured as the result of their own carelessness and lack of common sense? And if you do, how much responsibility for your customers’ welfare can you reasonably be expected to take on when all you did for those customers was sell them a cheap food item? Are you also responsible for ill-advised business decisions, stupid career choices, disastrous marriage proposals, or other lapses in judgment (or sanity) made while on your premises? And by the same token, should every customer in every public place have to live as if everyone else in the room was waiting for the chance to do them harm the moment their back is turned? What expectation of safety in the event of unwise behavior does the public have, and who has to take that responsibility?

It’s worth thinking about…

Sunday, May 4, 2008

Take Your Gun to Work Day

It had to be Florida, didn't it? There's a news story out of West Palm Beach about two supermarket employees who foiled what turns out to be not so much a robbery attempt or a takeover/hostage situation as a "shopping rage" incident because they were both carrying guns while on the job. You can read about it above if you want to. Now, I will admit that I have spent a few hours in retail management, down at the pointy end of a general merchandise retailer (a drug store), and in that position you find out very soon -- usually within hours of manning the Customer Service desk for the first time -- why the uniforms do not come with side arms...

In fact, this is a big part of why so many companies do not permit employees (other than licensed security personnel) to bring ANY weapons to work with them; because no matter how good you are at customer service, managing stress and holding your temper, eventually there will be at least one customer so obnoxious that you will have all you can manage not to shoot him or her. Admittedly, the company is probably also worried about the possibility of you accidentally shooting someone, shooting an annoying coworker, "accidentally" shooting someone who stands between you and that promotion, or doing in a supervisor who you think has torpedoed your career, and then being sued down to their underpants for failing to provide a safe working environment, but annoying customers and "street justice" are definitely on the list...

I'm not going to argue in favor of an armed workforce; as with society as a whole, gun ownership only works if the owners are responsible people, and I have worked with (and continue to this day to work with) people I wouldn't trust to operate a pea shooter in a responsible manner, let alone a firearm. I'm just going to point out that either of the gun-toting grocers in this story could easily have been killed if they hadn't been armed; that the night manager of the convenience store next to my drug store WAS killed during a robbery in 1995 while unarmed; that a single Sky Marshall with a single firearm could have prevented any one of the 9/11 hijackings from succeeding; that a single professor with a single firearm might have stopped the Virginia Tech killer in his tracks...

I’ll also point out that while this is something of a slippery slope argument (if we start allowing some employees in some companies to come to work armed, where will it end?) the lines are not as easy to draw, and the solutions are not as easy to invent, as people seem to think. No one wants to have armed security personnel everywhere in our society; I certainly don’t want them in my office while I’m working, or in the classroom if I’m teaching (or studying). Many small businesses could not afford such protection in the first place, and even if they could this type of solution takes us one step away from converting our society into one giant open-air prison. One quite small step, in fact.

Of course, there are security measures short of actual armed security guards that a business can take, such as the bulletproof partitions you see in some banks and gas stations, for example. A company can install silent alarms, make sure employees do not carry cash, and make sure that cash is collected from the registers and dropped into the safe on a regular basis. But there’s really not much you can do about some lunatic walking into your place of business, becoming offended by some kind of “rudeness” (real or imagined) and deciding to retaliate by shooting you or some of your employees. The only thing you can really be sure of in that situation is that everybody who hears the story will know exactly what you should have done to prevent the situation.

And that none of it will make a bit of difference after the fact...