Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Privacy vs. Security

March 30, 2018 By Michael Kavka Leave a Comment

The GDPR is coming, The GDPR is coming!!!

Well all know that the GDPR goes into effect in May. As I was listening to the Defensive Security Podcast this week, they started talking a bit about how the privacy laws can affect security and security posture. It is odd to think that something like privacy which we are in favor of, can have a negative effect on security, but it can. If you think long and hard about it, not being able to access logs, to be able to see where people have been on their corporate computers, how secure can we make them? One of the first steps in corporate security is knowing what is on the network, and knowing what data you have. Now you have an employee using their work computer for personal business say online banking, or logging into a patient portal. Now lets say those are phishing sites that look very much like the real site and not only that but after the first login attempt, redirect to the real site. At what point do we have to stop in an investigation of say malware on the machine? At what point are they breaking maybe corporate rules. The corporation cannot compel the individual to opt into being monitored according to the GDP. Maybe the corporation has a policy of no personal stuff being done on the work computer. How do we know without being able to have the insight?

What we seem to be getting into is a sticky situation that really has not been thought through to logical conclusions, or at least most except the best case scenarios were not granted viability. In the end there is a balance required to get best security and privacy at the same time. Right now though, everything tend to be out of balance.

Filed Under: General Tagged With: GDPR, Privacy, Security

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

RSS Taggart Institute Intel Feed

  • Microsoft restricts IE mode access in Edge after zero-day attacks October 13, 2025 Bill Toulas
  • No fix yet for attack that lets hackers pluck 2FA codes from Android phones October 13, 2025 Dan Goodin
  • Fortra cops to exploitation of GoAnywhere file-transfer service defect October 13, 2025 Matt Kapko
  • SimonMed says 1.2 million patients impacted in January data breach October 13, 2025 Bill Toulas
  • Months After Being Notified, a Software Vendor is Still Exposing Confidential and Sealed Court Records October 13, 2025 Dissent
  • Massive multi-country botnet targets RDP services in the US October 13, 2025 Bill Toulas
  • Harvard says ‘limited number of parties’ impacted by breach linked to Oracle zero-day October 13, 2025
  • Ukraine takes steps to launch dedicated cyber force for offensive strikes October 13, 2025
  • Rewiring Democracy is Coming Soon October 13, 2025 Bruce Schneier
  • Heads Up: Scans for ESAFENET CDG V5 , (Mon, Oct 13th) October 13, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP