Showing posts with label behavior. Show all posts
Showing posts with label behavior. Show all posts

2026-01-16

Sigh

Image from Unsplash

Pssst… Can you keep a secret? I hand you a sealed envelope with a name on it. The secret is inside. You are not allowed to look into the envelope yourself. When the person whose name is on it shows up, you give them the envelope. They look inside, seal it again, and hand it back to you. You keep it until next time. And you do absolutely nothing else with it.

This is roughly how things work when two computer systems communicate in many cases. For example because one system runs a program that needs data stored on another system. System A must then log in to system B, because of course not everyone is allowed to retrieve those data – another computer system included. In the first paragraph, you stored an envelope; system A has a digital equivalent: a digital vault. It stores the password in encrypted form. When A needs to retrieve data from B, it takes the password from the vault, decrypts it, and uses it to log in to B.

The key idea is that no human is involved. And that no human ever sees the password. Which means nobody can misuse A’s account. Just like you didn’t peek into the envelope, no one ever sees the decrypted password. At least, that’s the idea. Some time ago a colleague sent me an email with the subject line: SIGH… He had discovered that someone secretly looked inside the envelope – or its digital equivalent: manually decrypted the password. And then tried to manually log in with that account ‘just to see if it works’. While such an account is really a machine-to-machine account: meaning it is intended for one machine (A) to log in to another (B).

That sigh on the subject line meant something like: do they still not get it? Mind you, we are talking about administrators and developers doing this. You would expect them to understand how it works. That opening an envelope addressed to someone else is simply not allowed. And that manually logging in with a machine account is also not allowed. The sigh was also because this was certainly not an isolated incident. It happens far too often. And that undermines our security. You might ask why this is even possible. But that’s not the point here. Of course, it shouldn’t be possible, but right now it simply is.

If you see a bench in the park with a sign saying WET PAINT, do you touch it to check if it really is? Why would you? You risk getting paint on your fingers and the bench won’t look any better. Most people understand that you're not supposed to touch it. The same goes for those encrypted passwords. That something is possible does not mean it is allowed to do, or wise.

Deep down you know that. But just to be safe, another call to everyone who sometimes takes things a bit too lightly: don’t do it. If only because my sighing colleague is getting grey hairs from it, and because I end up writing in astonishment about something I thought you would understand by now. And of course I’m grateful for all those colleagues who simply do things right <3

*: There are alternatives, but I leave those aside here.

And in the big bad world…

 

2025-02-21

In the waiting room

 

Image from Pixabay

In the rather crowded train I found myself sitting next to a man who was working on his laptop. A quick glance at the device and the open programs identified him as a colleague.

At one point he was in a phone conversation. I wasn't actively listening, but of course I heard something. And what I heard made me very happy. To start with, he spoke softly, and in short sentences. It was actually mostly listening and occasionally responding briefly. I didn't hear him give any information. Neat, colleague!

How different is the experience of a colleague who was sitting in the dentist's waiting room. Well, it wasn’t really a waiting room; in a corner of the reception there were some chairs. Behind the counter worked two assistants. One, Tasha*, was clicking through computer screens with some despair in her eyes and finally said: "I can't find Mrs. Decker's details in TND." Her colleague Cindy asked for Mrs. Decker's date of birth. "Aha," said Cindy, "she's from 1999 and that's why she's not in TND yet. What's her phone number, I’ll give her a call." Tasha read out the phone number and Cindy made the call.

“Good morning Mrs. Decker, this is Cindy, assistant to dentist Crown. I need some information from you to enter your treatment in our system. What are your initials? ABG? Great. And your social security number? Yes of course, I'll wait a moment. (...) Ah, there you are again. Yes, I'll write along. 1-1-2-7 5-5 9-5-0? Thank you. And finally, I need your address. 5 Brace Road? Great, then I have everything complete. Shall we make the first appointment for your root canal treatment right away? Can you come in on Friday at 9 o'clock? Fine. If I can also have your e-mail address, I'll send you a confirmation. marly@decker.com? Fine, then we'll see you the day after tomorrow. Have a nice day!”

Our colleague could hardly believe his ears. He now had a complete set of personal details of someone and he knew when Mrs. Decker would not be home. Thanks to the information about her treatment, he also knew that she would be away for a while.

“Great, with this information I can commit identity fraud.” Or: “Great, I’ll get my burglary tools ready.” I admit that the chance that the unintentionally shared information accidentally ends up in the ears of a cyber or physical criminal is not that great. But still: everyone feels in their bones that this never should have happened. If you hear all this, then you know that they are handling your data in the same way. You wouldn’t feel comfortable with that, would you? And imagine that our waiting colleague was an acquaintance of Mrs. Decker. He runs into her a week later: “Hey Marly, how is your tooth?” That would be strange, wouldn’t it?

Of course there is also a legal problem. The unsuspecting, well-meaning dental assistants have not only leaked personal data, but even medical data. Under the GDPR (the European General Data Protection Regulation) these have the status of special personal data, for which even stricter rules apply than for regular personal data.

Tasha and Cindy were just doing their job. They can't help it that dentist Crown thought a separate waiting room was a waste of money. They couldn't make the phone call elsewhere either, because then Cindy couldn't enter the data into the system. Data leaks are pre-programmed in this situation. Especially when people are not aware of what is happening. A data leak is just around the corner.

I also want to look at what happened on the other end of the line. What if it wasn't the dental assistant who called Mrs. Decker at all, but someone who was out to collect personal data? Of course, the chance that they would call when you’re actually suffering from an aching tooth is small. But if you leave that circumstance out, it's a different story. If someone you don't know asks for data, tell them you'll call back. Then call the general number of the company and ask for the person who just called you. If that's not possible, ask whether they actually needed data. That way, you prevent yourself from leaking your own data.

*) Of course, all personal and system data are the product of my imagination.

 

And in the big bad world…


Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...