<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>expōnere &#187; data breach</title>
	<atom:link href="http://exponere.com/tag/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://exponere.com</link>
	<description>stuff that @barneyc finds interesting</description>
	<lastBuildDate>Mon, 10 Oct 2011 09:36:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Carphone Warehouse You Have a Duty of Care With Customer&#8217;s Privacy!</title>
		<link>http://exponere.com/2011/cpw_customer_privac/</link>
		<comments>http://exponere.com/2011/cpw_customer_privac/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 12:59:36 +0000</pubDate>
		<dc:creator>barneyc</dc:creator>
				<category><![CDATA[commentary]]></category>
		<category><![CDATA[my writings]]></category>
		<category><![CDATA[consumer issues]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://exponere.com/?p=707</guid>
		<description><![CDATA[Filling time whilst in a shopping centre with one&#8217;s family is a well learnt male skill. For those with more middle of the road interests it&#8217;s off to WH Smith&#8217;s for a browse of the car magazines, for those of us with more geek&#8217;fu it&#8217;s a trawl of the mobile shops to toy with the [...]]]></description>
			<content:encoded><![CDATA[<p>Filling time whilst in a shopping centre with one&#8217;s family is a well learnt male skill. For those with more middle of the road interests it&#8217;s off to WH Smith&#8217;s for a browse of the car magazines, for those of us with more geek&#8217;fu it&#8217;s a trawl of the mobile shops to toy with the latest shiny goodies.</p>
<p>At the weekend I happened to be in <a href="https://twitter.com/#!/cpwcares" target="_blank">Carphone Warehouse&#8217;s</a> big open store at <a href="http://www.bluewater.co.uk/" target="_blank">Bluewater </a><a href="http://www.bluewater.co.uk/contentimages/storefinder/BW_SF_Carphone_Warehouse_lower.jpg"><img class="alignright" title="CPW at Bluewater" src="http://www.bluewater.co.uk/contentimages/storefinder/BW_SF_Carphone_Warehouse_lower.jpg" alt="" width="153" height="117" /></a>for one such time wasting fondle session and happened upon a wall full of working phones ripe for a quick look see.  It is all too rare to find phone shops with a happy attitude towards breaking boxes and sticking real working phones out there for customers to try, sadly reverting to the stock compressed cardboard or hollow shell imitations. So given such choice it the  HTC Sensation was an obvious place to start, it is basically an updated version of my current Desire HD so a comparison seemed fair.</p>
<p>What didn&#8217;t seem right was that when the screen came to life it was showing someone&#8217;s Facebook wall.  Odd but not it&#8217;s not unheard of for a fellow fiddler to have used an instore demo device to have a sneaky poke and forget to log out.</p>
<p>I did the decent thing and left a &#8220;you muppet&#8221; type post on his wall and logged the phone out.  But when the homescreen came up it was obvious something far more worrisome was going on. <a href="http://exponere.com/wp-content/uploads/2011/09/cpw_privacy_fail.jpg"><img class="alignleft size-medium wp-image-709" title="CPW Leave a Customers Details for All to See" src="http://exponere.com/wp-content/uploads/2011/09/cpw_privacy_fail-179x300.jpg" alt="" width="179" height="300" /></a></p>
<p>The homescreen wasn&#8217;t a stock HTC Rosie layout with loads of widgets and apps being moved, there were update and email notifications in the status bar, their were matched contacts awaiting approval.</p>
<p>A quick and very discreet look around pointed to this phone having actually been setup from new by someone. Not setup as in just having a play in a shop, but setup by someone sitting around with enough time on their hands to get the phone how they wanted it.  This was obviously a customer returns phone that had been stuck back on display with no thought.</p>
<p>There were of course a number of things I could do. I could have notified one of the half a dozen bored looking staff chatting to each other in the middle of the store whilst customers stood around idle; but honestly if those same staff couldn&#8217;t have been bothered to check a returns phone what hope was there now.  I could have had a proper play with his &#8220;Scott&#8217;s&#8221; accounts or even hijacked a few of them. I didn&#8217;t, I took the kinder option and hit the magic half a dozen keys strokes to wipe the SD care and factory reset the phone.</p>
<p>The point of this is our smartphones contain a wealth of personal information from our intimate sharings with loved ones through to our TV preferences through to the keys to our email and bank accounts.   It&#8217;s all too easy nowadays to pick up a new phone, log into the cloud and for the handset to be automagically populated with our stuff.  BUT retailers have a duty of care when handling those devices, whether it&#8217;s for repair or return in ensuring that personal information goes no further.</p>
<p>What appears to have happened here is akin to giving your plumber with house keys to fix a leaky tap and them walking away leaving the front door wide open.</p>
<p>It&#8217;s not acceptable.</p>
<p>Anyone from Carphone Warehouse around because I&#8217;d love to hear your thoughts?</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://exponere.com/2011/cpw_customer_privac/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hell – The Right Approach to a Data Breach</title>
		<link>http://exponere.com/2010/hell-approach-data-breach/</link>
		<comments>http://exponere.com/2010/hell-approach-data-breach/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 09:53:34 +0000</pubDate>
		<dc:creator>barneyc</dc:creator>
				<category><![CDATA[commentary]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.exponere.com/?p=527</guid>
		<description><![CDATA[There are any number of approaches to data breaches in business today.  Whilst regulation is ever trying to get to the point where notification of breach is mandatory there are still plenty of businesses out there who will go to all sorts of lengths to sweep things under the carpet rather than own up. Not [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hellpizza.co.nz" target="_blank"><img style="display: inline; border: 0px;" title="hell" src="http://exponere.com/wp/wp-content/uploads/Hell.co.nzTheRightApproachtoDataBreaches_95EB/hell.jpg" border="0" alt="hell" width="497" height="388" /></a></p>
<p>There are any number of approaches to data breaches in business today.  Whilst regulation is ever trying to get to the point where notification of breach is mandatory there are still plenty of businesses out there who will go to all sorts of lengths to sweep things under the carpet rather than own up.</p>
<p>Not so <a href="http://twitter.com/HELLpizza666" target="_blank">Hell </a>– a truly rocking pizza company in New Zealand.  Certainly no stranger to controversy – some of their marketing campaigns have been widely criticised, Hell seems to be taking the bull-by-the-horns and going all out to keep people happy.</p>
<p>Today I received an email from them…</p>
<blockquote><p>Dear Valued Hell Customer,</p>
<p>We have been approached by a party claiming to be in possession of<br />
customer details from the previous Hell website which is no longer in<br />
operation.  The samples that we received included details of four customers<br />
from 2006, including phone numbers and email addresses and order<br />
information. We can confirm that credit card data was not at risk as this<br />
is held independently on a secure banking website.</p>
<p>Whilst we are still investigating the matter, we can confirm that the<br />
information was obtained without our knowledge and we have approached the<br />
New Zealand Police with a view to lodging a formal complaint.  Hell<br />
recognises the importance of protecting customer information and additional<br />
security measures were implemented earlier this year when our new website<br />
was rolled out (again, we reiterate that this is not an issue affecting the<br />
new website). As a further security measure your may wish to consider<br />
changing your passwords on other sites if they were the same as the old<br />
Hell Pizza website.</p>
<p>We apologise for the incident and any inconvenience that this may have<br />
caused.</p>
<p>Sincerely,<br />
Stu McMullin – Director Hell Pizza</p>
<p>We acknowledge that some of you have asked to be removed from the database<br />
and we have only included you for the purposes of this notification.</p></blockquote>
<p>No mucking about, no bull just a straight forward there might be a problem, we know, the police know so go do this just to be safe.</p>
<p>This IS the right approach to notification in my opinion.</p>
<p>I’m not totally up to date on NZ privacy law (a couple of years out of date), so it could well be that by now notification is mandatory.  Even if it is, props to Hell for getting it out there.</p>
<p>FYI: Hell pizza really is very very good.  Think PIzza Express with attitude.  Even better you can get them in the <a href="https://www.hellpizza.co.uk/" target="_blank">Hell Pizza UK</a> – well London with branches in Fulham, Shepherds Bush and Clapham.</p>
]]></content:encoded>
			<wfw:commentRss>http://exponere.com/2010/hell-approach-data-breach/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

