Sunday, February 27, 2011

A Tester's perspective: Privacy in Design by Microsoft

A month ago I promised to blog about privacy solutions the cloud vendors apply at this time.
This post will discuss Microsofts efforts in handling privacy.
When googling for Microsoft the first hit's a bullseye.
A portal about how Microsoft deals with privacy issues and links to relevant information, ordered in a structured way. Regarding usability,a good start.
A portal is nice, but does it have info about how Microsoft deals with privacy issues?
Privacy by Design is a hot topic in the privacy community and also organized in Microsofts business, in both development and operation.
Bold words, but how is this done?
First, Microsoft deals with Privacy by following the Microsoft Privacy Principles, which address Accountability, Notice, Collection, Choice and Consent, Use and Retention, Disclosure of Onward Transfer, Quality Assurance, Access, Enhanced Security, and Monitoring & Enforcement.
An example of the use of these principles is the link Privacy
available at the Windows Live Hotmail-site.
Wow, Privacy Principles, but who assures me, the user, these principles are lived by Microsoft?
Microsoft's Chief Privacy Officer (CPO, I just love those abbreviations), is responsible for managing the risks and business impacts of privacy laws and policies.
The CPO and his team had a great influence on the new Microsoft's U-Prove (former CardSpace) and the Tracking Protections in IE9.
OK, Microsoft is concerned about the user's privacy, are there any negative sides to its policy?
Well, you could say the long development and at the end elimination of CardSpace in favor of U-Prove, but is this privacy-related? The Geneva-project was, IMHO, always a bit mysterious, but when Credentica was bought by Microsoft in 2008 things started to make more sense. Then it's more an issue what to use for identity control and if it's usable?
Believe me, I have enough experience with software projects where the architect says his design is flawless, but that during end-to-end-test the software its performance is just plain lousy.
Another reason to involve testers at the beginning of a project.

Concluding,Microsoft commits itself to privacy, but it's still an evolution of development and process, do not expect miracles!
People at Microsoft are also just people.

Sunday, February 20, 2011

Got the flu last week, what did I miss?

Last week it was my, once in two years, out-of-the-office-because-of-the-flu-week.
More simply said, I was bugged :-(.
No worries, I'm back on my feet and now I'm looking what I missed out on testing, SaaS, security and identity last week.
Fortunately, my fellow bloggers weren't ill and could produce a daily/weekly news for me, like Frank Wray's Identity in the Cloud Weekly,Christophe Primault's The GetApp.com Daily, EPA's blog and Jaap Kuipers his PIMN. Great stuff guys, saves a lot of Googling.

If I would exclude testing now for keeping it short, what did I miss out on SaaS, security and identity?
Well, one nice thing to mention on SaaS/Cloud computing is a webcast Maurice van der Woude, general director EuroCloud Europe, gave on Brighttalk about Managing Hybrid Clouds from a Supplier and User Perspective. Here, next to explaining what a hybrid cloud is, he also discusses the interoperability needed in a hybrid cloud and the privacy issues. A very informative talk, which is suitable for both business and tech-pro's.

Going further to security, well, the biggest news was the RSA-conference held in San Francisco, attended by some of my fellow UMAnitarians and also PIMN-members.
For UMA, Congratulations to the SMART team for their win of an IDDY award in the Proof of Concept category from Kantara for their UMA development work! This is good news for a possible adoption of UMA by the industry.
Another interesting RSA-item to mention is the panel-discussion, co-led by Ikuo Takahashi on Legal issues occurred by international cloud computing. This means, cloud computing is more and more seen by policy-makers as something to happen and legal issues must be attended. It now only depends on how this policy will be governed, and on what geographic scale: globally or per country?
Mr. Takahashi, thank you for your feedback on my questions to this, it gave me a lot of insight, which I will further explore the coming weeks.

So, this is just my humble view of last week. One week knocked-out by the flu, but luckily I can rely on my fellow-bloggers, as they can rely on me, to keep the news posted.

Sunday, February 6, 2011

USA responds to the changing EU Data Privacy Directive, where's Asia?

Last week I blogged about that the EU Data Privacy Directive is going to be changed in response to the adoption and development of Cloud Computing.
IMHO, I thought the USA couldn't lag behind and I was not surprised that the NIST , the U.S. National Institute of Standards and Technology, has issued two new draft documents on cloud computing for public comment, including the first set of guidelines for managing security and privacy issues in cloud computing. Next to this, NIST has developed a Cloud Computing Collaboration site on the Web to enable two-way communication among the cloud community and NIST cloud research working groups.
So, it seems both USA and the EU are initiating efforts to guide the secure adoption of cloud computing by industry and consumer.
Now, I'm wondering about one thing, compared to Europe and the USA, what are the Asian countries doing to guide a secure adoption of cloud computing?
For a testpro like me it is very nice guidelines are being made for the 'Western' countries, but a lot of the 'cloud' is build in the 'East', so this I can't neglect.


Asia is not unified like Europe or the USA, so government guidelines here are not easily made for the many different countries forming Asia.
Private consortia like Asia Cloud Computing Association (see Europe's EuroCloud ) have been developed. But wat about the Asian governments, are they making unified guidelines for Cloud Computing?
John Galligan, Microsoft Asia Pacific's regional director for Internet policy, discusses this, with an emphasis on Singapore, on futuregov.asia and zdnet.asia.

Challenges there still are, one of the sentences made here I want to citate:

'One significant concern regarding cloud technology is the uncertainty over the location where data is stored and how strong data protection is to safeguard against criminal intent.'

This is also the case in the Western world, and as in the West, secure IT-auditing by the Asian governments and private sectors is necessary to test the security of their continuously innovating IT-infrastructure.

Galligan also says :"It's very interesting when people start to look at reliability, the level of redundancy and individual's access to the system, it can move decision makers to understand that maybe their current infrastructure is not as stable and secure as they think it is."

OK, it's a response from an employee of a private firm, but, IMHO, this is the single problem now with Cloud Computing, only with tackling these risks of reliability, redundancy and access, policy makers all over the world can be moved to adopt Secure Cloud Computing.

And that's a mutual challenge for all global parties involved in Cloud Computing: Business, IT-auditing, development and test!!

PS:
I'm no expert on Asian law, this example of cloud computing in Singapore does not have to be the case for other Asian countries, it only wants to illustrate an Asian response to Cloud Computing

Saturday, January 29, 2011

Dealing with privacy in the cloud: the European Data Protective Directive

Yesterday, Friday 28 January 2011, it was Data Privacy Day, an international celebration of the dignity of the individual expressed through personal information.
What a coincidence, the day before I was invited by my dear friend Paolo Balboni to take part in "The Expert Panel on Cloud Computing and the Protection of Personal Data". Considering my critical attitude of a tester towards software and the knowledge of user-centric webprotocols like UMA and OpenID Paolo thought I should have my say here.
I had to be in Amsterdam for another meeting, so I gladly accepted the invitation.
What's it all about then?

The Istituto Italiano Privacy (IIP) together with the European Privacy Association (EPA) have organized "The Expert Panel on Cloud Computing and the Protection of Personal Data"
The IIP together with the EPA published a working paper titled ‘Cloud Computing and the Protection of Personal Data: Privacy and the Global Web, Risks and Resources for the Citizens of the Internet’.
IIP and EPA are aware of the on-going debate on privacy and cloud computing in the Netherlands. Therefore, they want to share their pan-European experience on the matter with the panel and learn about the Dutch experience.
Through presentations it became clear both IIP and IPO want to make a position paper, based on the input from the panel and their working paper to address the issues of all parties involved in Cloud Computing and Privacy in Europe.
This is a very hard nut to crack, because the European Community consists of many different countries with different laws and different privacy regulators.
However, there is the Data Protection Directive (off. Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data), a European Union directive which regulates the processing of personal data within the European Union. All members of the European Union must follow this Directive and implement it in their Privacy Policy.
But what happens when a non-European Community cloud provider is not following the Data Protection Directive? Can he be caught?
No, he can't be caught if the cloud provider, as a data controller, is not based in Europe and not using equipment in the EU.
Hm, data controller, what's that and are there other data parties?
A data controller, according to the Data Protection Directive, is the one who determines purposes and means of the processing of personal data (art. 2d) and there is also a Data processor, who processes personal data on behalf of the controller (art. 2e).
See where I'm going? In cloud computing it remains quite unclear who's the data controller and processor, and the Data Protection Directive is not clear in this yet.
Another privacy issue addressed in the panel discussion is the transfer of data outside the EU.
A EU-customer has no idea or control of where its data is located and fears its data subject rights are not guaranteed.

These are privacy issues to be dealt with.
Therefore the Directive 95/46/EC is under revision to address also the issues of Cloud Computing.
ENISA published a study recently, dealing with the legal and security issues of cloud computing and the CAMM project will deliver in 2011 a new business barometer for the quality of the security profiles of the Cloud Service Providers.

And then there will be the IIP/EPA Position Paper, aimed at addressing concrete data protection issues and suggestions of solutions for a sustainable privacy-friendly cloud framework.
Input from cloud vendors is very much appreciated here.


Interesting times ahead for who's interested in the protection of personal data in the EU.

This post was mainly about solutions for privacy in policies, my next post will be about the privacy solutions the cloud vendors apply at this time.

Sunday, January 16, 2011

Testing UMA means testing controlling an individual's online data by himself!

One of the reasons I joined the UMA-WG, was that I wanted to be involved in a project right from the specs and not when it is time for systemtesting. Next to that, the concept of UMA fascinates me and worth making me sweat!
The active discussions we have about the testability of the specs inspire me to improve my work as a systemtester.
The implementations of UMA can be in legious domains: enterprise, government, education, e-commerce etc. etc.
This makes it a project where IT-architects from different domains can work together making user stories and use cases and improve this user centric authorization protocol.
Yes, we also have OpenID and OAuth, but, IMFO, OpenID is for authenticating the user and OAuth for authorizing it.
UMA let an individual control the authorization of data sharing and service access made between online services on the individual's behalf, as a layer on OAuth. It doesn't involve the authentication, but is very much dependent on OAuth and its possible changes, which are very much monitored by the UMA-WG.

A few years ago I started this blog, because I wanted to share my thoughts on testing SaaS and identity. The latter, because, IMFO, testers were mixing up authentication and authorization, which is disturbing, because it are important elements of web2.0, online user-interactivity.
With OpenID I started, but UMA drives me more because it is fresh, very user-centric and can be interoperable with OpenID through OpenID/AB, melting two of my favorite testsubjects (authentication and authorization) in one.

I wait for the day I can test an online user-interface (say banking :-) ) where an individual, with the help of the UMA-protocol, can control the data he or she wants to share with third parties, on the individual's behalf.

Something worth sweating for!