<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Surveillance Archives - L2 Cyber Security Solutions Ltd.</title>
	<atom:link href="https://www.l2cybersecurity.com/tag/surveillance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.l2cybersecurity.com/tag/surveillance/</link>
	<description>#SecuritySimplified</description>
	<lastBuildDate>Tue, 28 Aug 2018 08:50:38 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.l2cybersecurity.com/wp-content/uploads/2023/03/cropped-Logo-Only-Favicon-Transparent-32x32.png</url>
	<title>Surveillance Archives - L2 Cyber Security Solutions Ltd.</title>
	<link>https://www.l2cybersecurity.com/tag/surveillance/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Holiday Data Breach Photos.</title>
		<link>https://www.l2cybersecurity.com/holiday-data-breach-photos/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Tue, 28 Aug 2018 08:48:28 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Surveillance]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1361</guid>

					<description><![CDATA[<p>Most normal people go on holidays, forget about work, relax and enjoy themselves. They also, probably take lots of nice photos of the great places they&#8217;ve been and the nice food they&#8217;ve eaten. I went on holiday recently in remote, rural Ireland and I did pretty much all of the above. However, I suffer from&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/holiday-data-breach-photos/">Holiday Data Breach Photos.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Most normal people go on holidays, forget about work, relax and enjoy themselves. They also, probably take lots of nice photos of the great places they&#8217;ve been and the nice food they&#8217;ve eaten. I went on holiday recently in remote, rural Ireland and I did pretty much all of the above.<span id="more-1361"></span> However, I suffer from an affliction, which means I actually have holiday data breach photos because:</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-1362" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/08/I-see-data-breaches.gif" alt="I see data breaches" width="400" height="225" /></p>
<p>I wasn&#8217;t deliberately going looking for data breaches or other data privacy concerns. However these two examples just leapt out at me. Please note that I have redacted sections of these pictures where there were potentially identifying features. I&#8217;ve also removed individual&#8217;s names, just in case you could make them out.</p>
<h3>Staff roster and holiday plans on public display</h3>
<p>I ate and drank in quite a few different establishments on my holiday, but this one had the staff roster and a holiday planner in plain sight, over one of the tills.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-1364" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/08/Holiday-and-roster-on-public-view.jpg" alt="Holiday planner and roster on public display" width="439" height="374" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/08/Holiday-and-roster-on-public-view.jpg 439w, https://www.l2cybersecurity.com/wp-content/uploads/2018/08/Holiday-and-roster-on-public-view-300x256.jpg 300w" sizes="(max-width: 439px) 100vw, 439px" />Because it was dark, the camera struggled to pick it out very clearly, but I could read the names clearly on the holiday planner (on the left). This had the staff names down the left hand side. Then the columns were for June, July and August and this is where the staff obviously noted their holiday plans.</p>
<p>The weekly roster is on the right, where again the staff names were down the left hand side. Then what shifts they were working each day was in the columns. I couldn&#8217;t make this out myself at the distance I was from it &#8211; approximately 2m.</p>
<p>If I had a better camera or better light, there is no doubt I could easily have got the complete staff list, their holiday plans and their work schedule for the coming week.</p>
<p>This is a breach of the staff&#8217;s right to privacy. Any member of the public could see when they were going to be on holiday or when they were going to be at work. This could lead to their home being broken into, as the bad guys know when they are going to be away. Or how about an abusive ex-partner? How much would they love to have this kind of information available to them.</p>
<p>The real shame about this &#8230; this place had a large back-of-house (kitchen and office) that all the staff had access to, but not the public. Why not post these things back there?</p>
<h3>Staff surveillance</h3>
<p>CCTV is used extensively in pubs and restaurants mainly for crime prevention and health and safety purposes. In this pub there was this ONE camera that only had eyes for one thing &#8230; this till</p>
<p><img decoding="async" class="aligncenter size-full wp-image-1365" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/08/CCTV-watching-a-till.jpg" alt="cctv watching a till" width="417" height="600" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/08/CCTV-watching-a-till.jpg 417w, https://www.l2cybersecurity.com/wp-content/uploads/2018/08/CCTV-watching-a-till-209x300.jpg 209w" sizes="(max-width: 417px) 100vw, 417px" /></p>
<p>So obviously they were using this camera to keep an eye on staff to see if they were fiddling the till. This was a very obvious placement of a camera. This would not be considered &#8220;covert&#8221; by any means or standards. That&#8217;s me talking as somebody who notices this stuff for a living. If I was still in school, starting out on my first pub job, I may <em><strong>not</strong></em> notice such things.</p>
<p>Surveillance of staff needs to be declared by the employer. In this instance there should be a point in the staff manual noting that the tills are monitored by cameras. If an employer was to use secret cameras to monitor staff, they should also declare this. They should state that from time-to-time covert surveillance of employees, in the performance of their work, may be implemented.</p>
<h3>Have you any holiday data breach snaps?</h3>
<p>In both of the above situations, I have anonymously (I was on holiday, so I&#8217;m not hunting sales leads) notified the owners of the establishments about my observations.</p>
<p>When you are looking through your photos from your vacation, can you find any holiday data breach pictures? If you think you have, send them in confidence to <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener">info@L2CyberSecurity.com</a> and I&#8217;ll let you know, but please don&#8217;t tell me the name of the place or the location.</p>
<p>If you would like to know more about different data breaches under the GDPR, check out the videos available on the <a href="https://www.l2cybersecurity.com/gdpr/" target="_blank" rel="noopener">GDPR section</a> of my website.</p>
<p>#LetsBeCarefulOutThere</p>
<p>#SecuritySimplified</p>
<p>The post <a href="https://www.l2cybersecurity.com/holiday-data-breach-photos/">Holiday Data Breach Photos.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>State agency wants to track tourists.</title>
		<link>https://www.l2cybersecurity.com/state-agency-wants-track-tourists/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Tue, 18 Jul 2017 15:05:59 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[CSO]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Location]]></category>
		<category><![CDATA[Mobile Phone]]></category>
		<category><![CDATA[Surveillance]]></category>
		<category><![CDATA[Tourism]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=803</guid>

					<description><![CDATA[<p>A story was published in the Irish Times yesterday about a long running debate between the Central Statistics Office (CSO) of Ireland (the state agency for government statistics) and the Data Protection Commissioner (the state agency for the protection of personal data) in regards to a request that the CSO had submitted to get Irish&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/state-agency-wants-track-tourists/">State agency wants to track tourists.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-804" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/07/CSO-spying-on-Mobile-users-150x150.jpg" alt="state agency wants to track tourists" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/07/CSO-spying-on-Mobile-users-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2017/07/CSO-spying-on-Mobile-users.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />A <a href="https://www.irishtimes.com/news/ireland/irish-news/regulator-and-cso-in-stand-off-over-mobile-data-1.3156892?mode=amp">story was published</a> in the Irish Times yesterday about a long running debate between the Central Statistics Office (CSO) of Ireland (the state agency for government statistics) and the Data Protection Commissioner (the state agency for the protection of personal data) in regards to a request that the CSO had submitted to get Irish mobile telephone operators to hand over roaming data on tourists visiting the country, including such information as the dates and times of calls made by the visitors.<span id="more-803"></span></p>
<p>This has actually been going on, quietly in the background, for some 9 years at this stage and is certainly the first I have heard about it &#8230; and it concerns me greatly.</p>
<p>The CSO state that the reason for gathering the data is such that it &#8220;may significantly enhance our statistics on tourism and international travel&#8221;. How does knowing when a visitor to our country makes a phone call enhance tourism statistics? I don&#8217;t know. <img loading="lazy" decoding="async" class="" src="https://www.facebook.com/images/emoji.php/v9/fd3/1/28/1f615.png" alt="?" width="15" height="15" /></p>
<p>Gathering such call details would require them to also capture some unique identifier for that handset, as otherwise they would have no way of identifying whether a call was a single call made by one tourist or whether it was one of twenty calls made by that same tourist. Guess what? Every mobile phone has a unique identifier. The International Mobile Equipment Identity (IMEI) and this ties back to a person, and so is personal data.</p>
<p>Also noted in the article was</p>
<blockquote><p>&#8230; the Court of Justice of the European Union held that traffic and location data was liable to allow &#8216;very precise conclusions&#8217; to be drawn about the private lives of individuals.</p></blockquote>
<p>in other words knowing where somebody is at all times is effectively spying on somebody &#8230; state sponsored surveillance even.</p>
<p>The CSO had even gone as far as having a Statutory Instrument drafted by the Attorney General&#8217;s office (another state agency), which would have enabled the government to sign off on it, thereby compelling the mobile operators to hand over the personal data on visiting tourists, without their knowledge or permission. Fortunately the DPC raised concerns</p>
<blockquote><p>The “extraordinary” project would, in effect, “track the movements of visitors to this country and will in turn, affect tourists’ privacy rights, in that their entire holiday will have been recorded and analysed, albeit anonymously”.</p></blockquote>
<p>The CSO still appear to be continuing with this &#8220;project&#8221; as stated at the end of the article, but Helen Dixon, the current Commissioner with the DPC, has stated her office would expect to be consulted before any Statutory Instrument is signed off.</p>
<p>In this, the era of the General Data Protection Regulation (<a href="https://www.l2cybersecurity.com/gdpr/">GDPR</a>), I would expect that state agencies have to follow the same rules that apply to all other businesses in the EU. I cannot for the life of me think of a single legal justification for the CSO to gather such granular data on private citizens (no matter what country the come from).</p>
<p>This could be the thin end of the wedge &#8230; what&#8217;s next &#8230; if they can do it to tourists, will Irish residents be next?</p>
<p>&lt;googles &#8220;tinfoil hat creation&#8221;&gt; <img loading="lazy" decoding="async" class="" src="https://www.facebook.com/images/emoji.php/v9/f7c/1/28/1f575_200d_2642.png" alt="?️‍♂️" width="20" height="20" /></p>
<p>The post <a href="https://www.l2cybersecurity.com/state-agency-wants-track-tourists/">State agency wants to track tourists.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
