Monday, June 6, 2011

Privacy vs Security - A false choice

Did anyone ever tell you not to flash your cash around in public?

The idea is that showing your roll might attract the attention of would be thieves, pickpockets or muggers.

So in this case keeping your affairs private enhances security. There is no tradeoff.

There are many cases like this. How many of you have heard people say things while on a mobile phone in a public space that would give a malefactor all the information they need to commit a crime with little chance of detection?

How many horrible people have used information about young people they have met online in terrible ways?

We don't value privacy highly because it is the currency with which we purchase security. One of the many reasons we value privacy so highly is that it enhances security even as it is retained.

Now consider the recent data breaches that have led to a loss of privacy and, as a consequence, the reduction of the security of individuals.

Even if the security protocols of the companies involved were weaker than the ones that were actually breached, template-only biometric authentication would provide far more privacy and security than the current username/password regime.

A database including Name, Username, email address and password is far more valuable than one including Name, Username, email address and biometric template. The reasons are somewhat technical, but you can't just type a template into a computer to gain access.

Granted, biometrics are more expensive. But you can trade money for security.