Episode Details
Back to EpisodesPrivacy and Security with Rebecca Herold
Description
Due to the coronavirus pandemic, we've rapidly changed the way we work, how we play, and how we're educated. This sudden shift leaves us and our families exposed to privacy and security risks we previously hadn't thought about or planned for. Listen up for any blindspots you might have.
Our guest today is Rebecca Herold. Rebecca, also known as The Privacy Professor, has over 25 years of experience in system engineering, information security privacy, and compliance. She has authored 19 books with the 20th on its way. She has been a member of the NIST CyberSecurity IOT Development Team, and was an adjunct professor for Norwich University's Masters of Science in Information and Security and Assurance Program for 9 years. Today she will share with us her experiences with privacy and security and will also share things for you to keep in mind when using various apps and services.
Show Notes:- [1:06] - Rebecca started out as a systems engineer in 1988 and around 1990 got into system security and established security systems for banks.
- [3:50] - Rebecca created her own consulting company and began teaching as an adjunct professor at Norwich University. Her adjunct professor position helped her learn even more about the practicality and various needs in security.
- [6:40] - When you have a career in which you use technology that is constantly changing, it keeps things interesting. Rebecca has had to constantly adapt and learn.
- [7:20] - Risks don't go away. You just accumulate new ones that you have to keep addressing. That's something that many security and privacy practitioners forget. They keep up to date on new risks but sometimes forget the existing ones.
- [9:32] - Privacy tends to be an afterthought and we need to shift our thinking to start setting up security and privacy controls from the beginning.
- [12:30] - Throughout the COVID-19 pandemic, Rebecca has gotten a lot of questions from business owners regarding their employees and how to gain information on them to remain safe and help manage their self-insured expenses.
- [13:40] - Some business owners are trying to bypass doctors and healthcare professionals because they are self-insured. They also want to know where their employees have been to avoid them coming in with COVID-19. These are huge privacy issues.
- [16:24] - "COVID tracker apps" may be used by business owners to try to avoid their insurance rates going up. These examples show the problem with tracker apps not being used transparently.
- [17:01] - There are hundreds of these COVID tracking apps and some were built with privacy and security integrated but many were not.
- [18:24] - Always think about apps and what data they might be collecting.
- [19:23] - Rebecca gives examples of apps asking for information that is unnecessary for tracking COVID-19, such as your exact date of birth.
- [21:42] - There are situations where apps are being portrayed and communicated to users that privacy and security are built in, however a lot of privacy features have been overlooked.
- [22:22] - We need to get this pandemic under control and have insights, but we don't want to create other problems. There has to be a balance. What can we do to track this but keep people's privacy safe?
- [23:35] - Always ask yourself why is this information necessary when signing up for various apps and websites.
- [26:62] - If people are asking you for information and it's not necessary for the purpose in which you are using a service or pr