Thursday, October 25, 2018

Unauthorised access to "confidential" information

Unauthorized access to data seems to be quite common. It is quite difficult to control.

Cathay Pacific is the latest victim. SingHealth was an earlier victim. This will not be the last. I expect more to follow.

The authorized staff is allowed to access the data to serve the customer. There could be hundreds or thousands of staff who have the right of access.

It may be impossible to ensure that their login credentials are kept secret. It could be hacked. It could also be sold for a fee.

I personally think that the confidential information is not so confidential or important. I don't mind someone knows my birthday. They can send me a gift for my birthday, OK?

I don't mind that they know my bank account No. They see it on the cheque that I write to them.

I am more worried that they know my credit card No. But when I give my credit card to a restaurant, they have a receipt with my credit card No, right? So, it is unavoidable.

Of course, I will check my credit card statement to make sure that all the charges are genuine. I like the banks to introduce a stronger process to handle credit card charges, such as entering a secret PIN. In the meantime, I accept the risk.

I do not mind that other people know my email address and mobile No. I make them available anyway. It is not a secret information.

If I get spam messages, I delete them. I also block the sender. That is enough for me.

There is no need to be paranoid about the access to "confidential" information. Frankly, it is not that confidential.

Tan Kin Lian

No comments:

Blog Archive