Skip to content
The Cyber Security Place

Identity Theft

Seven actions for the “digital me”

By Dr. Ron McFarland, CISSP, PMP

We live in an electronically chronicled society. Like it or not, our recorded society, fostered by computers, databases and analytics, provides each of us with many benefits and several potential hazards. It’s a pretty well understood fact that emails, online shopping information, cell phone calls, and Internet traffic is recorded – by someone on a database located somewhere. Whether it’s your Internet Service Provider, Cell phone provider, your bank or utility company, someone is storing your information, your data, and the “digital you” is recorded.

It is important for each one of us to understand the fundamental aspects of how much data is collected, why it is collected and how it is generally shared. By developing awareness of how your information is stored, collected, collated and shared, we can address any errors or assumptions made by vast databases and programs about who we are, increasing our benefits for living in a digital society and reducing the risks that can occur.

Many organizations record, save, and share pieces of data about you. Information and data known about you and your buying patterns, web-surfing behaviors is retained by the conglomeration of vendors where you do your online shopping, banking, credit card transactions, and a host of other online activities. Collection of this information is necessary for organizations to provide you with access to their large databases of products and services. Also, collection of your information is essential to provide you with some level of information security that protects your information from the prying eyes of highly trained and ill-intentioned hackers.

Demographics, Psychographics, and Trends – oh my!

Most of us may be familiar with the field of demographics. Just to clarify what demographics are, it is the quantifiable characteristics about you. For example, your name, age, and address are demographic attributes that are collected and stored in databases. Beyond demographics, companies also save psychographic information about you. Psychographics is more formally described as the collection of information about your interests, opinions, and even your lifestyles. I’m interested in guitar playing, for example, so my psychographic profile indicated that I prefer acoustic guitars.

Here’s another example how a company, say my local chain store grocery store might use my information. When I signed up for a discount card at my grocers, they asked me to fill out a simple form. The form asked for the usual information: name, address, phone number, email, and a few other demographic pieces of data (data about me), which I gladly provided to obtain the weekly discounts that the store offers. The demographic information that I provided is stored on a large database file containing demographic information for everyone who signed up for the discount card. In that way, the store can send out a weekly email flyer containing store specials to email addresses or a printed flyer to the physical address of store customers.

Demographic and psychographic information can be used in a more robust approach to provide the grocery store chain with marketing information for their customers. For example, when I go into my local store every Friday to purchase my usual one-pound of wild-caught salmon and favorite Irish beer, the grocery store’s database will recognize my purchasing trends and note these as my shopping preferences. The store can actually send out a coupon to my email address when salmon or my favorite Irish beer goes on sale.

The combination of demographic and psychographic information collected by our example grocery store chain, can also help a grocery store chain with their overall individual store planning. Trend information, what customers are purchasing at a given store, can provide a store chain with valuable analytics to shape individual stores in a way to meet their customer needs. Have you noticed that in the past fifteen years or so that some grocery store chains have created a few isles of health food products as an offering to their customers? How this has been done is that grocery stores recognized the trend for health food products over the past few decades. Several chains examined their demographic information, which provided them with maps of where their customers live for a particular store and cross-referenced this information with the stored psychographic information that were trending in both the store and within the region. Analytics revealed if a store could support a health food section by examining the trends. Demographics also determine if the addition of a few aisles of health food products, which tend to run at a premium, could be added to the store’s inventory mix.

Databases and Analytics – more of the techie stuff.

Databases are the essential background technology used by companies to store information about you, transaction information about what you’ve purchased, consumed or traded. With today’s technology, your information, saved by a given company, is usually not stored at one location. Today’s highly sophisticated databases use analytics to meet the needs of their customers with the intention to expand their customer base and consumer markets that the company serves. However, the push is on for companies to share information about their consumers with each other to further expand markets with complimentary products. So much information is shared about you between companies with highly distributed databases located around the globe that organizations can with reasonable accuracy, predict what you will purchase in the near future. This is referred to a predictive analytics. Amazon, for example, is using predictive analytics (demographics, psychographics and current trends) to predict or “shape” their inventory at their warehouses based on projected future sales. Every Amazon warehouse has a particular mix of products kept on the shelves for the area that the warehouse serves which will allow for quicker shipping. Imagine Austin Texas and the music scene. Because of all of the guitar players around Austin, I can only imagine that the Amazon warehouses that sever the area probably store more guitar strings than many of the other Amazon warehouses around the country.

The cloud is everywhere.

Data about you is not only stored and shared on massive databases that organizations maintain, but are also stored in large data pools hosted in diverse locations around the US and world. The current method of storing and distributing data that many commercial organizations use is cloud technology. Cloud technology allows for an organization to distribute your information anywhere in ever-growing databases, typically in a private networks of databases that span United States or even the globe. Your information is literally scattered around multiple sites that an organization hosts.

The catch in cloud-based services is that not all organizations can afford their own vast ever-growing networks of hardware to host and maintain their databases. Instead, many large, medium, and small organizations will rent cloud space with a third-party cloud-based services company that have the infrastructure to lease large amounts of space to companies. I liken this to my garage. I, like many Americans, have quite a bit of storage in my garage. When I’ve run out of space, at times, I’ve rented a storage space to hold my treasures. The catch is that with space for data or for your things, you release control and trust of your assets to a third party.

Aside from the massive amount of data that a particular organization will keep and share about you, whether on their own databases or on leased cloud-based services, information about you can also be found on the various social media sites. Facebook, Twitter and YouTube, to name a few, provide a rich source of data about you. We upload our pictures, videos, our poems and papers in order to share these with our online friends and community. Our pictures, posts and papers provide information about our preferences. I don’t know how many political posts I’ve responded to in the past month, but this alone can provide certain information about my likes and dislikes as it pertains to an event or political interest. In addition, files that are uploaded typically contain meta-data, which is simply information about our location, earth coordinates, and other information about the file, picture, or video. Meta data is like a fingerprint. In fact, the sheer volume of data that is uploaded hourly on social sites is astounding. Over 300 hours of video alone is uploaded per minute to YouTube. That’s a lot of video content that may contain telltale information about you. And the social media companies, also willing to make a buck off of your information, gladly share information about you to other social media companies and to businesses.

So where is the digital me?

The sharing of information about the “digital me” is at a fever pitch. Billions of dollars per year are spent on sharing, collating, sorting, and relating information gathered from many sources. The “digital me” is a composite of all data collected about my activities, purchases, preferences, and activities scattered throughout social media, third-party cloud services and private organizations. It is no wonder that security agencies have a hand into our profiles as they can project who may be more prone to illegal and terrorist activities.

But there is a more fundamental problem with the conglomeration of information about the “digital me.” Is the information about me accurate? A few years ago, I set up two profiles on my favorite social media site. One of the account profiles I set up was for my very conservative side and another account profile suggested that I was quite liberal. Of course, I pointed each of these accounts to a different email that I had, and I used my first name for one account and my middle name for the second account, so the setup was quite legit at the time. As I anticipated, based on my profile information, I started receiving more conservative information to the conservative-leaning account and more liberal information to the other account. The point is that marketing companies obtained my preference information and my demographic information (email address, age, etc.) from the social media website. My bet is that the social media site sold my information for a few pennies and the digital me (both side of me) were sold to a third party company.

Decisions by algorithm, not people.

As noted earlier, many decisions are made by databases. Automated decision making and predictive analytics is done by a set of programmed algorithms that most organizations use. When I want to purchase a car, the credit agencies will use an algorithm that checks the “digital me” including my credit risk and worthiness, with fairly good accuracy.

Algorithms are only as good as they are designed. Algorithms make an assumption that the data is accurate. And there are bad algorithms that can be downright harmful. When an algorithm is designed and used for decision-making, the algorithm will read in the data to its process that it has access to. The algorithm typically does not determine the quality of the information, the accuracy of the information nor the context of the information. In most cases, algorithms that make decisions for us do not determine if mistakes have been made to the data that is being review if the data is correct or not, the quality or verifiability of the accuracy of the information is, for the most part, not considered. Imagine a scenario where your healthcare information is hijacked by a hacker. If the hijacker can alter your information about who you are to your healthcare provide and receive services, you may be on the hook for the services that you’ve received.

Keep the “digital me” clean.

Correction of data is difficult at best. It is hard to clean up our own digital data and to make corrections. From this standpoint, digital data spreads like a disease. There are, however, some precautionary measures that we can take to better assure that our data is more accurate. It takes some effort and I recommend these actions:

As a result of the massive amounts of data collected by computers, we each have a digital profile – a “digital me” that identifies who we are, what we do, what we like and how we interact in the world. The “digital me” is rapidly evolving by the rapid collection of information that you’ve provided over the Internet to your banks, favorite shopping web sites, social media sites, and other web sites that you visit weekly. Large massive databases that operate in the background share your demographic, psychographic and trend information as well as your location and other related meta-data. The soup of information that is collected about each of us creates a unique “digital me.” It is essential that we constantly monitor what data is put into the process and clean up any data that is incorrectly stored on databases like credit reporting data.

About the author.

Dr. Ron McFarland, CISSP, PMP is the Dean of Applied Technologies at the College of the Canyons in Valencia, California, that has a robust Computer Networking and Cyber Security program. He received his doctorate from Nova Southeastern University’s School of Engineering and Computer Science. He also holds multiple security certifications including the prestigious Certified Information Systems Security Professional (CISSP) certification and several CISCO certifications. Dr. McFarland can be reached at: [email protected]