<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#187; government</title>
	<atom:link href="https://blog.m-sec.net/tag/government/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.m-sec.net</link>
	<description>When security is not enough</description>
	<lastBuildDate>Tue, 13 Nov 2012 20:58:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>About privacy and data protection (I)</title>
		<link>https://blog.m-sec.net/2011/about-privacy-and-data-protection-i/</link>
		<comments>https://blog.m-sec.net/2011/about-privacy-and-data-protection-i/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 19:39:35 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[CNP]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[PIN]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SSN]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=24</guid>
		<description><![CDATA[Today I&#8217;m going to start a topic about privacy. Even though I&#8217;ll write about some experiences I had in Romania, I&#8217;m pretty sure this can be applied to other countries too. The main subject will be about how hard is to find someone&#8217;s Numerical Personal Code (how it&#8217;s called in Romania) or Social Security Number [...]]]></description>
			<content:encoded><![CDATA[<p>Today I&#8217;m going to start a topic about privacy. Even though I&#8217;ll write about some experiences I had in Romania, I&#8217;m pretty sure this can be applied to other countries too. The main subject will be about how hard is to find someone&#8217;s <a title="CNP" href="http://en.wikipedia.org/wiki/National_identification_number#Romania" target="_blank">Numerical Personal Code</a> (how it&#8217;s called in Romania) or Social Security Number in US.</p>
<p>A few months ago I was googleing a friend&#8217;s name in order to find his email address. While searching I got to <a title="Vrajitorul" href="http://www.vrajitorul.eu" target="_blank">a website</a> which showed his address and telephone number. I was pretty surprised to see that and since the website had a search engine, I started to look for different persons &#8211; for some I got results. This was looking more and more interesting. I notice that there was also possible to create a test account with some free credits and with more search results. After waiting a day or so I finally got my account. Now the information I could find was astonishing. Not only I got the address and the phone, but also the Numerical Personal Code, what bank loans did they have (if any), how much they got ad so on.</p>

<a href="https://blog.m-sec.net/wp-content/uploads/2011/07/vrajitorul_CNP1.png" title="" class="shutterset_singlepic15" >
	<img class="ngg-singlepic" src="https://blog.m-sec.net/wp-content/gallery/cache/15__320x240_vrajitorul_CNP1.png" alt="vrajitorul_CNP1" title="vrajitorul_CNP1" />
</a>

<p>As you can see all the information is there. For privacy reasons I have hidden the data. But from where such a website could get all that information? Is there someone freely submitting the information? The response came quickly:</p>

<a href="https://blog.m-sec.net/wp-content/uploads/2011/07/vrajitorul_datasource.png" title="" class="shutterset_singlepic18" >
	<img class="ngg-singlepic" src="https://blog.m-sec.net/wp-content/gallery/cache/18__320x240_vrajitorul_datasource.png" alt="vrajitorul_datasource" title="vrajitorul_datasource" />
</a>

<p>I was WOW-ed. So <strong>our own government</strong> is publishing all these information to the public? What about data protection? What about privacy? It was kind of hard to believe, but after searching some published papers by the Romanian&#8217;s Official Journal I convinced myself of the reality.</p>

<a href="https://blog.m-sec.net/wp-content/uploads/2011/07/CNP_MOF.png" title="" class="shutterset_singlepic3" >
	<img class="ngg-singlepic" src="https://blog.m-sec.net/wp-content/gallery/cache/3__320x240_CNP_MOF.png" alt="CNP_MOF" title="CNP_MOF" />
</a>

<p>After accessing the <strong>official published paper</strong> I could also find: <strong><em>address, the date when the ID card was issued, the issuer name, ID number, Numerical Personal Code</em></strong>. If this is published freely by the government, then what else could I ask to a private company? Luckily, I knew that there is also an agency which is taking care of such issues &#8211; <a title="ANSPDPC" href="http://www.dataprotection.ro/" target="_blank">ANSPDCP</a> (hard to translate <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). However, how could I contact the agency (which is controlled by the government) and ask them to remove such information?</p>
<p>All that Vrajitorul website does is to get this information and structure it in a way that you can easily find. <strong>BUT</strong> there is hope. In case your personal identification info is somewhere on a website, you can contact the owner of the website and kindly ask to remove all this information as they are breaking the <a title="Data protection law Romania" href="http://www.legi-internet.ro/legislatie-itc/date-cu-caracter-personal/legea-privind-prelucrarea-datelor-cu-caracter-personal-si-protectia-vietii-private-in-sectorul-comunicatiilor-electronice.html" target="_blank">personal data protection law</a> and in case they will not do so, you will contact the ANSPDCP agency. My friend did this and all the data that the website had about him was removed the next day. I strongly suggest you to do the same.</p>
<p>Comments? Next time I&#8217;ll write about some private companies (including a bank) which have problems in protecting sensitive information about their customers.</p>
<p>&nbsp;</p>
<div id="tweetbutton24" class="tw_button" style=""><a href="http://twitter.com/share?url=https%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-i%2F&amp;via=msecnet&amp;text=About%20privacy%20and%20data%20protection%20%28I%29&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=https%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-i%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('https://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>https://blog.m-sec.net/2011/about-privacy-and-data-protection-i/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
