<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Glen Turpin: The Identity Question &#187; bozeman</title>
	<atom:link href="http://www.glenturpin.com/tag/bozeman/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.glenturpin.com</link>
	<description>Who am I? Why am I here? What's this all about?</description>
	<lastBuildDate>Wed, 01 Sep 2010 01:21:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Update: Bozeman backs down on password requests</title>
		<link>http://www.glenturpin.com/2009/06/update-bozeman-backs-down-on-password-requests/</link>
		<comments>http://www.glenturpin.com/2009/06/update-bozeman-backs-down-on-password-requests/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 18:48:16 +0000</pubDate>
		<dc:creator>Glen</dc:creator>
				<category><![CDATA[identity]]></category>
		<category><![CDATA[bozeman]]></category>
		<category><![CDATA[broken]]></category>
		<category><![CDATA[employment]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.glenturpin.com/?p=1285</guid>
		<description><![CDATA[Following a flurry of negative media attention, the City of Bozeman, Mont. has stopped asking job candidates for web site user names and passwords.
According to the press release :
Effective at 12:00 p.m. today, Friday June 19, 2009, the City of Bozeman permanently ceased the practice of requesting candidates selected for City positions under a provisional [...]]]></description>
			<content:encoded><![CDATA[<p>Following a <a href="http://news.google.com/news?pz=1&amp;ned=us&amp;hl=en&amp;q=bozeman+password">flurry of negative media attention</a>, the City of Bozeman, Mont. has stopped asking job candidates for web site user names and passwords.</p>
<p>According to the <a href="http://www.bozeman.net/bozeman/upcoming%20events/hire/06-18-09/Background%20Check%20Press%20Release%20June%2019%202009.pdf" target="_blank">press release <img class="alignbottom" title="PDF icon" src="http://www.glenturpin.com/wp-content/uploads/icons/pdf.png" alt="" width="16" height="16" /></a>:</p>
<blockquote><p>Effective at 12:00 p.m. today, Friday June 19, 2009, the City of Bozeman permanently ceased the practice of requesting candidates selected for City positions under a provisional job offer to provide user names and passwords for the candidate&#8217;s internet sites.</p></blockquote>
<p>They said in a <a href="http://www.bozeman.net/bozeman/upcoming%20events/hire/06-18-09/Social%20Networking%20Commission%20Memo.pdf" target="_blank">memo to the mayor and city commission <img class="alignbottom" title="PDF icon" src="http://www.glenturpin.com/wp-content/uploads/icons/pdf.png" alt="" width="16" height="16" /></a> that it was an honest mistake and that they believed it was consistent with their core values. I believe them. And I give them some credit for realizing the severity of the situation they created for themselves and acting quickly to fix it.</p>
<p><a href="http://www.glenturpin.com/2009/06/privacy-disaster-in-the-making/">But they still don&#8217;t get it.</a> City Manager Chris Kukulski made a point that only certain staff had access. They still don&#8217;t appear to understand the risks associated with asking for that information, using it or securing it. Which brings me to&#8230;</p>
<p>After reading the press release and the memo I was also concerned that they were still not addressing how the information they already have on hand is stored and secured, but that concern is addressed in the video of the <a href="http://www.bozeman.net/bozeman/upcoming%20events/hire/06-18-09/hiring.wmv" target="_blank">press conference</a> (WMV) with City Manager Chris Kukulski.</p>
<blockquote><p>&#8220;Yes, that is protected, confidential information and it is held in the same cabinet, in the same information where all other protected human resource or personnel items are.&#8221;</p></blockquote>
<p>The information is safe in the cabinet. I guess I&#8217;m relieved. But I hope it&#8217;s a sturdy cabinet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.glenturpin.com/2009/06/update-bozeman-backs-down-on-password-requests/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://www.bozeman.net/bozeman/upcoming%20events/hire/06-18-09/hiring.wmv" length="13699154" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Privacy disaster in the making</title>
		<link>http://www.glenturpin.com/2009/06/privacy-disaster-in-the-making/</link>
		<comments>http://www.glenturpin.com/2009/06/privacy-disaster-in-the-making/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 16:45:41 +0000</pubDate>
		<dc:creator>Glen</dc:creator>
				<category><![CDATA[identity]]></category>
		<category><![CDATA[bozeman]]></category>
		<category><![CDATA[broken]]></category>
		<category><![CDATA[employment]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.glenturpin.com/?p=1257</guid>
		<description><![CDATA[
Ars Technica reports that the city of Bozeman, Mont. is asking job applicants for their user names and passwords to all web services and communities in order to perform pre-employment screening.* Applicants are required to sign a form  that says:
&#8220;Please list any and all, current personal or business websites, web pages or memberships on [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/rattodisabina/2460905893/"><img class="alignnone size-full wp-image-1273" title="Key" src="http://www.glenturpin.com/wp-content/uploads/2009/06/Key.jpg" alt="Key" width="500" height="375" /></a></p>
<p><em>Ars Technica</em> reports that the city of Bozeman, Mont. is <a href="http://arstechnica.com/web/news/2009/06/city-to-job-applicants-facebook-myspace-log-ins-please.ars">asking job applicants for their user names and passwords to all web services and communities</a> in order to perform pre-employment screening.* Applicants are required to sign a <a href="http://www.bozeman.net/bozeman/humanResource/forms/Background_Check_Form_Interview_MASTER.pdf" target="_blank">form <img class="alignbottom" title="PDF icon" src="http://www.glenturpin.com/wp-content/uploads/icons/pdf.png" alt="" width="16" height="16" /></a> that says:</p>
<blockquote><p>&#8220;Please list any and all, current personal or business websites, web pages or memberships on any Internet-based chat rooms, social clubs or forums, to include, but not limited to: Facebook, Google, Yahoo, YouTube.com, MySpace, etc.&#8221;**</p></blockquote>
<p><strong>This is a monumentally bad idea.</strong></p>
<p>Under U.S. law, employers must not discriminate against members of several <a href="http://en.wikipedia.org/wiki/Protected_class">protected classes</a>. Having direct access to a prospective employee&#8217;s account gives access to a limitless supply of risky information.</p>
<h2>Everything is connected.</h2>
<p>You can use your Google, Yahoo or Facebook*** account with to log in to countless web sites, so even if the city of Bozeman isn&#8217;t explicitly asking for access, they would have the credentials to access a mind-boggling amount of personal information.</p>
<p>Let&#8217;s say you apply for a job and give your prospective employer your Google login information. That gives them access to your e-mail, including access to any correspondence with other prospective employers, your chat history, your search history, your image library, your calendar, your address book, the RSS feeds you subscribe to, the locations you&#8217;ve mapped, your health information,**** administrative control of your blog, your news alerts&#8230;.</p>
<p>There&#8217;s no end to the number of ways that one account could be abused. The city of Bozeman wants access to <em>all </em>your accounts.</p>
<p>&#8220;One thing that&#8217;s important for folks to understand about what we look for is none of the things that the federal constitution lists as protected things, we don&#8217;t use those,&#8221; city attorney Greg Sullivan told KBZK. <em>We don&#8217;t use those? </em>I&#8217;d like to hear how that argument stands up when the first discrimination suit is filed.</p>
<h2>That&#8217;s not all.</h2>
<p>Bozeman is asking for access to current business web sites as well. Can they really be asking applicants who are employed elsewhere to give the city access to their company business systems? If they are, then the the city is selecting employees based in part on their willingness to violate their employment agreements and provide unauthorized access to confidential business information.</p>
<p>According to KBZK, city attorney Sullivan said that no one has ever removed his or her name from consideration for a job due to the request. It appears that the city of Bozeman wants to hire people who are absolutely clueless about data privacy and no regard for confidentiality &#8212; and put them in charge of protecting applicants&#8217; login data.</p>
<p>This can&#8217;t end well.</p>
<h2>But wait, there&#8217;s more.</h2>
<p>There&#8217;s nothing on the form to suggest that the city of Bozeman is asking for passwords to access to online banking or other financial data, but by asking for account data like Google and Yahoo that gives access to e-mail, they&#8217;re essentially asking for the ability to obtain personal financial data. With access to e-mail, someone can take over your bank account and transfer your funds elsewhere before you realize what&#8217;s happening.</p>
<p>But let&#8217;s assume for a moment that all city employees are beyond reproach. By compiling user names and passwords, they&#8217;re creating a honey pot for identity thieves. Let&#8217;s hope the city of Bozeman has world-class data security programs in place***** because that much personal information is sure to attract unwanted attention.</p>
<p>I have to stop. I&#8217;m stunned by the staggering lack of judgment behind the city of Bozeman&#8217;s decision and the potential spiderweb of unintended consequences.</p>
<p><strong>Photo credit:</strong> <a href="http://www.flickr.com/photos/rattodisabina/">Mirko Macari</a></p>
Notes:<ol class="footnotes"><li id="footnote_0_1257" class="footnote" style="list-style-type:none;"><span class="symbol">*</span> Local TV station KBZK <a href="http://www.montanasnewsstation.com/Global/story.asp?S=10551414&amp;nav=menu227_3#poll84472">broke the story</a>. The Associated Press has <a href="http://www.google.com/hostednews/ap/article/ALeqM5j8jn3O0JgrEGN8znw-q2Y5-FcldAD98TQPT80">picked it up</a> as well.</li><li id="footnote_1_1257" class="footnote" style="list-style-type:none;"><span class="symbol">**</span> Heh. Three lines for any and all logins. Three pages, maybe?</li><li id="footnote_2_1257" class="footnote" style="list-style-type:none;"><span class="symbol">***</span> Among others. I wonder if they&#8217;re asking for OpenID credentials as well.</li><li id="footnote_3_1257" class="footnote" style="list-style-type:none;"><span class="symbol">****</span> Assuming anyone actually uses Google Health. Bear with me. I&#8217;m making a point.</li><li id="footnote_4_1257" class="footnote" style="list-style-type:none;"><span class="symbol">*****</span> I know this is a stretch, since it appears that the city only wants to hire rubes who don&#8217;t know or care about privacy or data security.</li></ol>]]></content:encoded>
			<wfw:commentRss>http://www.glenturpin.com/2009/06/privacy-disaster-in-the-making/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
