40
©2016 ProQuest LLC. All rights reserved. Security & Privacy: What’s Ahead for 2017 Library Edition Daniel Ayala (@buddhake) Director, Global Information Security, ProQuest ALA Midwinter 2017 Atlanta, Georgia

Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

Embed Size (px)

Citation preview

Page 1: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Security & Privacy:What’s Ahead for 2017

Library Edition

Daniel Ayala (@buddhake)Director, Global Information Security, ProQuest

ALA Midwinter 2017Atlanta, Georgia

Page 2: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.2

First, a story…

Page 3: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Modern technology is amazing.

3

The sky is the limit…

…but there is reason for

caution

Page 4: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Security & privacy go beyond the library

4

Page 5: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.5

Library as Hub of Privacy & Security

Page 6: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Protect the Systems!Protect the Users!Protect the Data!

6

Device Security

Page 7: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Protect the Systems!Protect the Users!Protect the Data!

7

MalwareRansomware

Page 8: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Protect the Systems!Protect the Users!Protect the Data!

8

Phishing

Page 9: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Protect the Systems!Protect the Users!Protect the Data!

9

Browser Security

Page 10: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Protect the Systems!Protect the Users!Protect the Data!

10

Mobile Devices

Page 11: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

A few words on

11

P R I V A C Y

Page 12: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.12

USA Patriot Act

Page 13: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.13

USA Freedom Act

Page 14: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.14

Consumer Services Devour Data

Page 15: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.15

Anonymisation & Tor

Page 16: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.16

Personalisation

Page 17: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.17

Opt-in vs Opt-Out

Page 18: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.18

Net Neutrality Rollback*

*In discussion, not yet submitted for public comment

Page 19: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.19

ISP Browsing Data Privacy Rollback*

*In discussion, not yet submitted for public comment

Page 20: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Tools

20

Ghostery (Chrome) – https://www.ghostery.com

1Blocker (Mac/iOS) - http://1blocker.com

BuiltWith (Chrome) - https://builtwith.com

Malwarebytes - https://www.malwarebytes.com

Deep Freeze - http://www.faronics.com/products/deep-freeze/

Tor - https://www.torproject.org

Let’s Encrypt (SSL) - https://letsencrypt.org

Page 21: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.21

Shared responsibility for privacy

Page 22: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.22

Transparency

Page 23: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.23

Anonymisation

Page 24: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.24

Options & Informed Consent

Page 25: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.25

Sharing Data w/ Others

Page 26: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.26

Support Anonymous Use

Page 27: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.27

Access to One’s own User Data

Page 28: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.28

Accountability

Page 29: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.29

RA21RA21’s mission is to align and simplify pathways to subscribed content across participating scientific platforms. RA21 will address the common problems users face when interacting with multiple and varied information protocols. 

http://www.stm-assoc.org/standards-technology/ra21-resource-access-21st-century/

Page 30: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Balance

30

Security & Privacy Utility

Page 31: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Foundational thinking31

Data will always be collected

Collection != Privacy Violation

Serve the user/patron!

Set principles for use & sharing

If you collect it, use it wiselyand get rid of it when you’re done!

TRUST!(but verify)

Page 32: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Give patrons/users the information, options

to make smart, well-informed privacy decisions32

Page 33: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Security & privacy go beyond the library

33

Give patrons/users the information, optionsto make smart, well-informed privacy

decisions

Page 34: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.34

HTTPS 11 Available Now, +5 More Soon

All new ProQuest products, HTTPS only

HTTPS only - later this summer

http://www.proquest.com/blog/pqblog/2017/Why-Those-HTTPS-Messages-Mean-Something-to-You-.html

Page 35: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.35

http://www.proquest.com/blog/pqblog/2017/Why-Those-HTTPS-Messages-Mean-Something-to-You-.html

ProQuest platform (search.proquest.com)ProQuest Dialog (search.proquest.com/professional) ProQuest Administrator Module (PAM) Legacy RefWorksThe New RefWorksEbook CentralProQuest Research CompanionPi2 Drug Safety TriagerAlexander Street Platform (search.alexanderstreet.com)Alexander Street Academic Video Store (search.alexanderstreet.com/store) Alexander Street Admin Portal

NOW

!

Page 36: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.36

http://www.proquest.com/blog/pqblog/2017/Why-Those-HTTPS-Messages-Mean-Something-to-You-.html

PivoteLibraryCultureGramsSIRSHeritageQuest OnlineProQuest Congressional (congressional.proquest.com)SO

ON!

Page 37: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.37

Privacy Policy Full Update Coming SoonWhat data is collected

How it is usedWith whom it is sharedEU/USA Privacy Shield Compliant

Page 38: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.38

When it comes to privacy and accountability, people always

demand the former for themselves and the latter for everyone else.

– David Brin 

Page 39: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.

Resources & CreditsNISO Consensus Framework to Support Patron Privacy in Digital Library and

Information Systems - http://www.niso.org/topics/tl/patron_privacy/ALA Code of Ethics - http://www.ala.org/advocacy/proethics/codeofethics/codeethics

ALA Library Privacy Guidelines for e-book Lending and Digital Content Vendors - http://www.ala.org/advocacy/library-privacy-guidelines-e-book-lending-and-digital-content-vendors

STM RA21 - http://www.stm-assoc.org/standards-technology/ra21-resource-access-21st-century/

Stock photography via Stocksnap.io and Shutterstock.com

39

Page 40: Cybersecurity & Privacy: What's Ahead for 2017 - ALA Midwinter 2017

©2016 ProQuest LLC. All rights reserved.40

Q&A