06 Privacy Tools Flashcards

1
Q

Why is it helpful to look for privacy threats in addition to security threat?

A

Privacy is no less important that security. People usually act to protect their privacy given an understanding of the threats and how they can address them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a harm?

A

A harm is a threat with its impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why threat modeling for privacy issues is important?

A

Much like security threats violate a required security property, privacy threats are where a required privacy property is violated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why defining privacy requirements is a delicate balance?

A

First, the organization offering a service may want or even need a lot of information that the people using the service don’t want to provide.

Second, people have very different perception of what privacy is, and what data is private, and those perceptions change with time.

Lastly, most people are “privacy pragmatists” and will make value tradeoffs for personal information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the different tools to threat model privacy?

A
  1. Solove’s taxonomy of privacy harms
  2. IETF’s “Privacy Considerations for Internet Protocols”
  3. Privacy Impact Assessments (PIAs)
  4. Nymity Slider
  5. Contextual Integrity
  6. LINDDUN approach
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does LINDDUN stand for?

A

Linkability
Identifiability
Non-Repudiation
Detectability
Disclosure of information
Content Unawareness
Policy and consent Noncompliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly