Robert Thibadeau, Copyright It’s not what IT does to Privacy it’s what Privacy does to IT Robert Thibadeau, Ph.D
Robert Thibadeau, Copyright Information Privacy Technology Law No matter how much you want to, you can’t get technology out of privacy or the law out of privacy
Robert Thibadeau, Copyright Reasons There is no technically perfect solution possible : Thomas Jefferson’s notion of public and private. –Therefore the Law becomes Indispensible, and the LAW is always at Fault if it is not there providing protection. Technology – actually the computer – will always surprise you : The Turing Principle –Therefore Technology cannot be frozen to a form, and the LAW is responsible, not technology Technology – you need locks on the doors, systems to facilitate privacy, and systems for policing of the laws –This requires Technology
Robert Thibadeau, Copyright Negotiating Privacy in a Millisecond A HARD PROBLEM FOR IT DICTATED BY PRIVACY
Robert Thibadeau, Copyright Privacy Server Protocol now the basis for the European JAVA Demonstrator Port-based, not (necessarily) HTTP –Scope : Persistence in Time and Scoping across Modality P3P Vocabulary (as excellent starter) Negotiated Privacy –Persona Driven Bilateral Privacy –Museums - Universal Studios – Ford Have Privacy Needs Too Non-Repudiate-able Contracts –Utilizing ASN.1/SMPTE 298M/DVBX Globally Unique Contract Names without central servers.
Robert Thibadeau, Copyright CMU PERSONA MODEL Schwab StockPicker Client Browser User Agent Web Site Server Agent Amazon Shopper DoubleClick User BN Shopper BUY Shopper Database System Privacy Policy Agreements Amazon Shopper DoubleClick User CMU Shadow
Robert Thibadeau, Copyright CMU PERSONA MODEL Schwab StockPicker Client Browser User Agent Web Site Server Agent Amazon Shopper DoubleClick User BN Shopper BUY Shopper Database System Amazon Shopper DoubleClick User CMU Shadow I want the Shopping Cart Need to be a Shopper I ‘m an Amazon Shopper OK, Sign Here OK, Now you Sign Done, Come on In!
Robert Thibadeau, Copyright CMU PERSONA MODEL *ALT Schwab StockPicker Client Browser User Agent Web Site Server Agent Amazon Shopper DoubleClick User BN Shopper BUY Shopper Database System Amazon Shopper DoubleClick User CMU Shadow I want the Shopping Cart Need to be a BN Shopper Can I be an Amazon Shopper? OK, Sign Here OK, Now you Sign Done, Come on In! What’s That? It’s This P3P Policy
Robert Thibadeau, Copyright CMU PERSONA MODEL *ALT Schwab StockPicker Client Browser User Agent Web Site Server Agent Amazon Shopper DoubleClick User BN Shopper BUY Shopper Database System Amazon Shopper DoubleClick User CMU Shadow I want the Shopping Cart Need to be a Shopper Can I be an Amazon Shopper? OK, Now You Sign OK, Sign Here Done, I’m Coming In! OK, But you need to be DoubleClick User TOO!
Robert Thibadeau, Copyright cmu persona A Persona is a Set of Credentials of which a Proper Subset is distinguished for Authorizing Access To the Remainder of the Set Name : Credit Card Number : Card Expiration : Mailing Address : Mothers Name : Child Persona : … Username : Password : Credentials as Other Persona Recogniz-er : FillerIn-er : Communicat-er : HowToUse-er : P3P APPEL :
Robert Thibadeau, Copyright cmu persona interface IE/Netscape Plugin is EMPTY PERSONA EDIT OR APPLY ENGINE Fill it with actual person in different ways: CMU PERSONA PLUGIN Active Persona Storage REMOTE BASESTATION WEB SERVER : PORT 80 (Web Page Activates Persona) AMAZON SHOPPER THIRD PARTY WEB SERVER : PORT 80 MY OTHER SHOPPER My Secure Hard Disk OR My Floppy Disk MY OTHER SHOPPER Like to Use Amazon Shopper
Robert Thibadeau, Copyright