Your Contact Info for a Chocolate Bar?

| | Comments (0) | TrackBacks (0)

We've all gotten a chuckle over the drones who would give up their password for a chocolate bar. Are we as security professionals any better? We give up all of our contact information (name, address, phone number, email, company name, job title), information on our company (security initiatives, budget, size, locations), and sometimes even contact information for our co-workers. We give it up for half-baked white papers that may be helpful or may be marketing tripe that will be discarded immediately. We give it up for a one hour webinar that again may be useful or may be worthless. We give it up for a half day seminar that allows us to escape the office temporarily.

Its expected that disclosing this information will result in sales calls. Did you realize that these companies also may be selling your contact information or trading it with other companies? I've been thinking about this since a couple of sales people called, and when told I wasn't interested responded "but you downloaded our whitepaper."

Janis Rose has an article on this in the April 2008 ISSA Journal (membership required). She focuses on the ethical aspect of using disposable email addresses when registering for whitepapers.

When signing up for things online, know that there is no such thing as a free lunch. Even when its a reputable company, you need to be aware of the potential consequences of disclosing data.

I think companies should include choices for how your data will be used. They shouldn't hide it in the fine print of a privacy policy. When they don't do that, we're forced to use temporary email addresses and phone numbers that go straight to voicemail.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Your Contact Info for a Chocolate Bar?.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/714

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on April 20, 2008 12:15 PM.

I can hear you now was the previous entry in this blog.

Rick Rolling for Good Security is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can reach me at blog...@infosecblog.org
Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.1