Showing posts with label organisations. Show all posts
Showing posts with label organisations. Show all posts

Do you know what they know about you?

Thursday, December 27, 2007

Two computer discs holding the personal details of all families in the UK with a child under 16 have gone missing. The scandal of the 25 million missing records has highlighted the vulnerability of data.

It is easy to develop a sense of creeping paranoia when you begin to contemplate just how many companies, government departments and other organisations know your personal data.

She said it would be naive to think that an encounter with one organisation means one isolated database is queried. Typically data is gathered from many sources before a decision is reached.

For instance the USVISIT border system, which is consulted when Britons cross from the UK to the US, mines about 30 separate databases as it checks identities.

Ms Gallagher and colleague Peter Bradwell will release their report in early December.

"Pretty much every organisation you engage with day-to-day - from clicking your Oyster card to ordering your take away - means sharing personal information."

That sharing of data, she said, has become entwined with modern life and it was a mistake to think that sharing information so often only has a downside.

You are not going to get people complying with data protection on the basis of good will

Anyone that tries to stop their personal data leaking away often find they are denied benefits enjoyed by those that are happier to share.

For instance, paying cash for everything will keep your name off credit checking databases. However, without the re-assurance of that check banks and credit card companies may refuse to issue a loan or mortgage. Data control

And there are a lot of people within companies, government and other organisations that are allowed to use data that can be used to identify you.

According to the 2006/7 annual report from the Information Commissioner there are more than 287,000 data controllers in the UK who have a responsibility for making sure that personal data is used correctly.

Personal data in this sense is information that can be used to identify an individual.

Many of those data controllers will oversee many more who actually do the job of maintaining and expanding the databases holding the data.

And it does not stop there. The web is helping that data take wing and travel farther than ever before.

Computer keyboard, Eyewire
Government departments are increasingly sharing data

What few people realise, said Ms Gallagher, was that handing over data to one organisation can mean that it reaches many others and becomes an entry on the database they maintain.

"There is no awareness of what happens to that data when you give it away," said Ms Gallagher.

"It is not so much the organisations with which you willingly share data," she said, "it is where it goes after that."

Many organisations that collect data, such as credit checking agencies, were under commercial pressure to widen the scope of what they collect, said Ms Gallagher.

No longer are firms just interested in the basic facts about you - now what matters as much as what type of credit card you own is when you go shopping, which stores you visit and what you buy.

That pattern holds as much information as the raw facts about you - it helps companies decide which socio-economic bracket to put you and how to go about tailoring marketing to fit you and your lifestyle.Watching them

Surveillance and the collection of data about people has become so pervasive that it has spawned a dedicated research organisation - the Surveillance Studies Network.

Dr Kirstie Ball, a senior lecturer at the Open University, said that although many social scientists been studied the subject for years the pervasiveness of that scrutiny was prompting an upsurge of interest.

"That personal data held by every organisation you interact with runs the parameters of your existence, your consumption, your entitlements," she said.

Pens in pot, BBC
Almost every time you fill in a form the data makes it to a database

"We're all interested in the collection and application of personal data and its consequences for individual rights and social science concepts such as trust and discrimination," said Dr Ball.

"It merits study and understanding because its consequences can be tangible," she said.

For instance, she said, an employee ticking the wrong box when they enter your data into a database could mean a person ends up labelled as a former criminal or credit liability.

It is possible to ask to see the data that companies and organisations hold about you, but a very small number of people take up this opportunity to vet what is known about them. Making sure all of it is accurate would be a mammoth task.

For Ms Gallagher at Demos beefing up the power of the Information Commissioner to enforce the Data Protection Act would help redress some of the imbalance between the data companies hold about us.

"Organisations and companies should be responding to the way we live," she said.

Only by using those powers will the creeping spread of that data be held stemmed.

"You are not going to get people complying with data protection on the basis of good will," she said. "Data is just too valuable."

  • Her Majesty's Revenue and Customs has set up a Child Benefit Helpline on 0845 302 1444 for customers who want more details.Blow by blow Life in the freezer The year ahead
    Source from: news.bbc.co.uk
  • How firms and fraudsters deal in data

    Wednesday, December 26, 2007

    Compact disk, Eyewire
    Organisations should have policies that govern who does what with data

    The information lost by the HMRC could prove very valuable to fraudsters, computer security experts say.

    "In the fraud underworld the quality of data directly impacts the flexibility with which they can use it," said Andrew Moloney, financial services market director for RSA Security.

    There was no evidence yet that the data was being talked about or sold on the fraud boards and net markets that his company monitors, he said.

    However, most vendors of stolen data rarely mention where they got it from. Instead, they typically only mention its quality.

    Mr Moloney said there was a well-established chain of buyers and sellers who can handle large amounts of data and pass them on to those that wish to use them to commit fraud.Safeguarding data

    "That's partly grown up to protect the anonymous individuals involved," he said, "and partly because we have seen specialisms develop with individuals finding their own niche in that underground economy."

    What also made the data attractive to fraudsters, said Mr Moloney, was that much of the data in it, such as names of children and birth dates, cannot be changed and will be valuable if it reaches criminals in the next week or the next year.

    "Once it's compromised it is compromised for the long term," he said.

    With computerised databases long established in large organisations, a series of policies and practices has grown up to safeguard the sensitive data they contain - in theory.

    In the front line of these safeguards are the strictures laid down by the Data Protection Act which is policed by the Information Commissioner.

    The Act details what workers can and cannot do with sensitive data and how it must be treated as well as what staff should do to ensure it is not compromised.

    In a statement issued after the HMRC data loss was made public Richard Thomas, the information commissioner, said his organisation was already investigating two other breaches at the government department.Data commandments

    "Searching questions need to be answered about systems, procedures and human error inside both HMRC and the National Audit Office," said Mr Thomas.

    Birthday cake, BBC
    Much of the lost data, such as birth dates, cannot be changed

    Beyond data protection laws most organisations develop their own policies which govern how staff should treat such sensitive information, said Paul Simmonds, a board member of the Jericho Forum - a trade association for IT security bosses at the world's largest organisations.

    He said the Jericho Forum had developed a series of "commandments" which organisations should strive to live up to. They detail what organisations should do to ensure data is used appropriately.

    They cover such things as levels of security for different types of data; authentication to ensure data use is appropriate and how to share responsibilities for safeguarding information.

    "The Jericho Forum has long stated that data must be properly protected, both in transit and at rest," said Mr Simmonds. "Effectively this means sensitive data must always be encrypted.

    "This data loss is just another in a long list of organisations who ignore basic security principles," he added.Shore up defences

    Paul Davie, head of database security firm Secerno, said many companies were turning to technology to help shore up their defences.

    Security systems that oversaw interaction between a database and its users helped to do more than just stop bad guys from the outside stealing data, he said.

    Man using keyboard, BBC
    There are many places online where data is bought and sold

    "They want to understand the way the database is being queried by authorised users and what counts as normal use," said Mr Davie.

    "The technology is there to detect unusual behaviour such as a junior downloading huge amounts of data," he added.

    Evidence suggests that technology has a significant role to play. A University of Washington study released in March 2007 showed that 60% of data breaches were the result of bad practices inside organisations rather than hackers.

    "This is really high quality data," he said.

    Hackers have increasingly targeted databases, he said, because the information inside them was so valuable and well organised.

    By contrast data gathered by other hacker tools such as key logging software installed surreptitiously on PCs that watches what people type can produce reams of information that must be cleaned up before it is useable or saleable.

    Murky world Epic battle Delays, delays

    Source from: news.bbc.co.uk

    Net vigilantes 'should listen more'

    Monday, December 10, 2007

    Regular columnist Bill Thompson wants "net vigilantes" to focus more on customer service.

    Sometime in October a malicious program exploited a security flaw in the Wordpress software I use to host my weblog and injected some extra commands into one of the widgets I use to add features to the site.

    They opened up a connection between the blog and a site that tried to download a malicious piece of software to any site visitor unfortunate enough to be using Microsoft's Internet Explorer.

    Anyone who visited my site would have been prompted to install a clearly unwanted piece of software, although as far as I know nobody was affected. However I can't be sure and hope that I didn't unwittingly cause damage to anyone else's computer.

    I upgrade my installation regularly, and apply new security patches as they come out, but this happened in the few days before the release of a new version and I was caught.

    Yet I only found out about the problem when a kind reader e-mailed me to tell me that Google was warning prospective visitors that my blog might "harm" their computer.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action

    I hadn't noticed the warning because, strange as it may seem, I don't Google my own name that often (searching blogs is a different matter, of course).

    And I hadn't found out from Google, either because they didn't send any emails or because the company that acts as technical contact for my site didn't bother passing them on.

    Once I knew what had happened I searched for and found the offending code, but it has taken three weeks to get the Google warning removed, and the experience has been a salutary one.

    I started off at StopBadware, the organisation Google works with to flag sites hosting malicious code.

    Fighting Badware

    I searched for information about what they had found on my site and discovered that although Google had flagged my blog it hadn't passed any information on to StopBadware.

    So I requested a review using the form provided, hoping to get some information to help me find out what had happened and which pages were affected.

    I had to e-mail them three times before I got a reply, and had to wait 10 days for that, and even then there was no information on exactly what Google had found on my site, so I had to search myself.

    Eventually I discovered that I could find a lot more information and request a review more effectively by signing up for Google's Webmaster Tools.

    This is a great service, but it isn't something my small blog really needs and of course signing up gives Google access to a lot of information about what I'm up to, information I'd rather they didn't have.

    But when the alternative is a blood-red sign saying "All hope abandon, ye who enter here" splashed over Google's search results there really is no choice.

    And now my site is clean and Google likes me again.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action. There is a similar debate going on over e-mail and spam, with groups like Spamhaus creating lists of servers that they believe are sending out spam.

    Other organisations subscribe to the Spamhaus Block List and will block emails from those servers.

    Their approach is pretty effective at closing spam relays, but of course sometimes the listing is wrong and sometimes there is collateral damage, when a server used by an ISP is listed and all of its customers are affected.

    Part of me would like to see this sort of listing done by the appropriate authorities, perhaps even the police, with some degree of judicial overview and a formal appeals process.

    Of course this is not going to happen, at least not on the global basis that would be needed to make it effective.

    And the only real option for anyone who runs their own website is to sign up Webmaster Tools to keep an eye on what the rainbow monster thinks of them.

    But if we're going to live in a world where Google, StopBadware, Spamhaus and all the other private organisations offering to make the net safe have so much power then we have to push them to do a better job, especially when it comes to communication.

    The point is not that this is online vigilantism, although it surely is. The point is about accountability, openness, responsiveness and the other things that we require from state actors but too often leave up to the market to enforce for private companies.

    For many of us our websites, email addresses, personal profiles and the other aspects of our online lives are vital parts of who we are.

    The organisations and companies seeking to fill the gaps left by law enforcement need to tread carefully and must treat those affected with respect and care, or they cannot expect us to support them, however noble their intentions.


    Source from: news.bbc.co.uk

    Net vigilantes 'should listen more'

    Sunday, December 2, 2007

    Regular columnist Bill Thompson wants "net vigilantes" to focus more on customer service.

    Sometime in October a malicious program exploited a security flaw in the Wordpress software I use to host my weblog and injected some extra commands into one of the widgets I use to add features to the site.

    They opened up a connection between the blog and a site that tried to download a malicious piece of software to any site visitor unfortunate enough to be using Microsoft's Internet Explorer.

    Anyone who visited my site would have been prompted to install a clearly unwanted piece of software, although as far as I know nobody was affected. However I can't be sure and hope that I didn't unwittingly cause damage to anyone else's computer.

    I upgrade my installation regularly, and apply new security patches as they come out, but this happened in the few days before the release of a new version and I was caught.

    Yet I only found out about the problem when a kind reader e-mailed me to tell me that Google was warning prospective visitors that my blog might "harm" their computer.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action

    I hadn't noticed the warning because, strange as it may seem, I don't Google my own name that often (searching blogs is a different matter, of course).

    And I hadn't found out from Google, either because they didn't send any emails or because the company that acts as technical contact for my site didn't bother passing them on.

    Once I knew what had happened I searched for and found the offending code, but it has taken three weeks to get the Google warning removed, and the experience has been a salutary one.

    I started off at StopBadware, the organisation Google works with to flag sites hosting malicious code.

    Fighting Badware

    I searched for information about what they had found on my site and discovered that although Google had flagged my blog it hadn't passed any information on to StopBadware.

    So I requested a review using the form provided, hoping to get some information to help me find out what had happened and which pages were affected.

    I had to e-mail them three times before I got a reply, and had to wait 10 days for that, and even then there was no information on exactly what Google had found on my site, so I had to search myself.

    Eventually I discovered that I could find a lot more information and request a review more effectively by signing up for Google's Webmaster Tools.

    This is a great service, but it isn't something my small blog really needs and of course signing up gives Google access to a lot of information about what I'm up to, information I'd rather they didn't have.

    But when the alternative is a blood-red sign saying "All hope abandon, ye who enter here" splashed over Google's search results there really is no choice.

    And now my site is clean and Google likes me again.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action. There is a similar debate going on over e-mail and spam, with groups like Spamhaus creating lists of servers that they believe are sending out spam.

    Other organisations subscribe to the Spamhaus Block List and will block emails from those servers.

    Their approach is pretty effective at closing spam relays, but of course sometimes the listing is wrong and sometimes there is collateral damage, when a server used by an ISP is listed and all of its customers are affected.

    Part of me would like to see this sort of listing done by the appropriate authorities, perhaps even the police, with some degree of judicial overview and a formal appeals process.

    Of course this is not going to happen, at least not on the global basis that would be needed to make it effective.

    And the only real option for anyone who runs their own website is to sign up Webmaster Tools to keep an eye on what the rainbow monster thinks of them.

    But if we're going to live in a world where Google, StopBadware, Spamhaus and all the other private organisations offering to make the net safe have so much power then we have to push them to do a better job, especially when it comes to communication.

    The point is not that this is online vigilantism, although it surely is. The point is about accountability, openness, responsiveness and the other things that we require from state actors but too often leave up to the market to enforce for private companies.

    For many of us our websites, email addresses, personal profiles and the other aspects of our online lives are vital parts of who we are.

    The organisations and companies seeking to fill the gaps left by law enforcement need to tread carefully and must treat those affected with respect and care, or they cannot expect us to support them, however noble their intentions.


    Source from: news.bbc.co.uk

    Do you know what they know about you?

    Thursday, November 29, 2007

    Two computer discs holding the personal details of all families in the UK with a child under 16 have gone missing. The scandal of the 25 million missing records has highlighted the vulnerability of data.

    It is easy to develop a sense of creeping paranoia when you begin to contemplate just how many companies, government departments and other organisations know your personal data.

    She said it would be naive to think that an encounter with one organisation means one isolated database is queried. Typically data is gathered from many sources before a decision is reached.

    For instance the USVISIT border system, which is consulted when Britons cross from the UK to the US, mines about 30 separate databases as it checks identities.

    Ms Gallagher and colleague Peter Bradwell will release their report in early December.

    "Pretty much every organisation you engage with day-to-day - from clicking your Oyster card to ordering your take away - means sharing personal information."

    That sharing of data, she said, has become entwined with modern life and it was a mistake to think that sharing information so often only has a downside.

    You are not going to get people complying with data protection on the basis of good will

    Anyone that tries to stop their personal data leaking away often find they are denied benefits enjoyed by those that are happier to share.

    For instance, paying cash for everything will keep your name off credit checking databases. However, without the re-assurance of that check banks and credit card companies may refuse to issue a loan or mortgage. Data control

    And there are a lot of people within companies, government and other organisations that are allowed to use data that can be used to identify you.

    According to the 2006/7 annual report from the Information Commissioner there are more than 287,000 data controllers in the UK who have a responsibility for making sure that personal data is used correctly.

    Personal data in this sense is information that can be used to identify an individual.

    Many of those data controllers will oversee many more who actually do the job of maintaining and expanding the databases holding the data.

    And it does not stop there. The web is helping that data take wing and travel farther than ever before.

    Computer keyboard, Eyewire
    Government departments are increasingly sharing data

    What few people realise, said Ms Gallagher, was that handing over data to one organisation can mean that it reaches many others and becomes an entry on the database they maintain.

    "There is no awareness of what happens to that data when you give it away," said Ms Gallagher.

    "It is not so much the organisations with which you willingly share data," she said, "it is where it goes after that."

    Many organisations that collect data, such as credit checking agencies, were under commercial pressure to widen the scope of what they collect, said Ms Gallagher.

    No longer are firms just interested in the basic facts about you - now what matters as much as what type of credit card you own is when you go shopping, which stores you visit and what you buy.

    That pattern holds as much information as the raw facts about you - it helps companies decide which socio-economic bracket to put you and how to go about tailoring marketing to fit you and your lifestyle.Watching them

    Surveillance and the collection of data about people has become so pervasive that it has spawned a dedicated research organisation - the Surveillance Studies Network.

    Dr Kirstie Ball, a senior lecturer at the Open University, said that although many social scientists been studied the subject for years the pervasiveness of that scrutiny was prompting an upsurge of interest.

    "That personal data held by every organisation you interact with runs the parameters of your existence, your consumption, your entitlements," she said.

    Pens in pot, BBC
    Almost every time you fill in a form the data makes it to a database

    "We're all interested in the collection and application of personal data and its consequences for individual rights and social science concepts such as trust and discrimination," said Dr Ball.

    "It merits study and understanding because its consequences can be tangible," she said.

    For instance, she said, an employee ticking the wrong box when they enter your data into a database could mean a person ends up labelled as a former criminal or credit liability.

    It is possible to ask to see the data that companies and organisations hold about you, but a very small number of people take up this opportunity to vet what is known about them. Making sure all of it is accurate would be a mammoth task.

    For Ms Gallagher at Demos beefing up the power of the Information Commissioner to enforce the Data Protection Act would help redress some of the imbalance between the data companies hold about us.

    "Organisations and companies should be responding to the way we live," she said.

    Only by using those powers will the creeping spread of that data be held stemmed.

    "You are not going to get people complying with data protection on the basis of good will," she said. "Data is just too valuable."

  • Her Majesty's Revenue and Customs has set up a Child Benefit Helpline on 0845 302 1444 for customers who want more details.Hotel drama Race against time Fantastical feast
    Source from: news.bbc.co.uk
  • How firms and fraudsters deal in data

    Compact disk, Eyewire
    Organisations should have policies that govern who does what with data

    The information lost by the HMRC could prove very valuable to fraudsters, computer security experts say.

    "In the fraud underworld the quality of data directly impacts the flexibility with which they can use it," said Andrew Moloney, financial services market director for RSA Security.

    There was no evidence yet that the data was being talked about or sold on the fraud boards and net markets that his company monitors, he said.

    However, most vendors of stolen data rarely mention where they got it from. Instead, they typically only mention its quality.

    Mr Moloney said there was a well-established chain of buyers and sellers who can handle large amounts of data and pass them on to those that wish to use them to commit fraud.Safeguarding data

    "That's partly grown up to protect the anonymous individuals involved," he said, "and partly because we have seen specialisms develop with individuals finding their own niche in that underground economy."

    What also made the data attractive to fraudsters, said Mr Moloney, was that much of the data in it, such as names of children and birth dates, cannot be changed and will be valuable if it reaches criminals in the next week or the next year.

    "Once it's compromised it is compromised for the long term," he said.

    With computerised databases long established in large organisations, a series of policies and practices has grown up to safeguard the sensitive data they contain - in theory.

    In the front line of these safeguards are the strictures laid down by the Data Protection Act which is policed by the Information Commissioner.

    The Act details what workers can and cannot do with sensitive data and how it must be treated as well as what staff should do to ensure it is not compromised.

    In a statement issued after the HMRC data loss was made public Richard Thomas, the information commissioner, said his organisation was already investigating two other breaches at the government department.Data commandments

    "Searching questions need to be answered about systems, procedures and human error inside both HMRC and the National Audit Office," said Mr Thomas.

    Birthday cake, BBC
    Much of the lost data, such as birth dates, cannot be changed

    Beyond data protection laws most organisations develop their own policies which govern how staff should treat such sensitive information, said Paul Simmonds, a board member of the Jericho Forum - a trade association for IT security bosses at the world's largest organisations.

    He said the Jericho Forum had developed a series of "commandments" which organisations should strive to live up to. They detail what organisations should do to ensure data is used appropriately.

    They cover such things as levels of security for different types of data; authentication to ensure data use is appropriate and how to share responsibilities for safeguarding information.

    "The Jericho Forum has long stated that data must be properly protected, both in transit and at rest," said Mr Simmonds. "Effectively this means sensitive data must always be encrypted.

    "This data loss is just another in a long list of organisations who ignore basic security principles," he added.Shore up defences

    Paul Davie, head of database security firm Secerno, said many companies were turning to technology to help shore up their defences.

    Security systems that oversaw interaction between a database and its users helped to do more than just stop bad guys from the outside stealing data, he said.

    Man using keyboard, BBC
    There are many places online where data is bought and sold

    "They want to understand the way the database is being queried by authorised users and what counts as normal use," said Mr Davie.

    "The technology is there to detect unusual behaviour such as a junior downloading huge amounts of data," he added.

    Evidence suggests that technology has a significant role to play. A University of Washington study released in March 2007 showed that 60% of data breaches were the result of bad practices inside organisations rather than hackers.

    "This is really high quality data," he said.

    Hackers have increasingly targeted databases, he said, because the information inside them was so valuable and well organised.

    By contrast data gathered by other hacker tools such as key logging software installed surreptitiously on PCs that watches what people type can produce reams of information that must be cleaned up before it is useable or saleable.

    Fantastical feast Honeymoon over 'St Petersburg clan'

    Source from: news.bbc.co.uk

    Net vigilantes 'should listen more'

    Sunday, November 25, 2007

    Regular columnist Bill Thompson wants "net vigilantes" to focus more on customer service.

    Sometime in October a malicious program exploited a security flaw in the Wordpress software I use to host my weblog and injected some extra commands into one of the widgets I use to add features to the site.

    They opened up a connection between the blog and a site that tried to download a malicious piece of software to any site visitor unfortunate enough to be using Microsoft's Internet Explorer.

    Anyone who visited my site would have been prompted to install a clearly unwanted piece of software, although as far as I know nobody was affected. However I can't be sure and hope that I didn't unwittingly cause damage to anyone else's computer.

    I upgrade my installation regularly, and apply new security patches as they come out, but this happened in the few days before the release of a new version and I was caught.

    Yet I only found out about the problem when a kind reader e-mailed me to tell me that Google was warning prospective visitors that my blog might "harm" their computer.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action

    I hadn't noticed the warning because, strange as it may seem, I don't Google my own name that often (searching blogs is a different matter, of course).

    And I hadn't found out from Google, either because they didn't send any emails or because the company that acts as technical contact for my site didn't bother passing them on.

    Once I knew what had happened I searched for and found the offending code, but it has taken three weeks to get the Google warning removed, and the experience has been a salutary one.

    I started off at StopBadware, the organisation Google works with to flag sites hosting malicious code.

    Fighting Badware

    I searched for information about what they had found on my site and discovered that although Google had flagged my blog it hadn't passed any information on to StopBadware.

    So I requested a review using the form provided, hoping to get some information to help me find out what had happened and which pages were affected.

    I had to e-mail them three times before I got a reply, and had to wait 10 days for that, and even then there was no information on exactly what Google had found on my site, so I had to search myself.

    Eventually I discovered that I could find a lot more information and request a review more effectively by signing up for Google's Webmaster Tools.

    This is a great service, but it isn't something my small blog really needs and of course signing up gives Google access to a lot of information about what I'm up to, information I'd rather they didn't have.

    But when the alternative is a blood-red sign saying "All hope abandon, ye who enter here" splashed over Google's search results there really is no choice.

    And now my site is clean and Google likes me again.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action. There is a similar debate going on over e-mail and spam, with groups like Spamhaus creating lists of servers that they believe are sending out spam.

    Other organisations subscribe to the Spamhaus Block List and will block emails from those servers.

    Their approach is pretty effective at closing spam relays, but of course sometimes the listing is wrong and sometimes there is collateral damage, when a server used by an ISP is listed and all of its customers are affected.

    Part of me would like to see this sort of listing done by the appropriate authorities, perhaps even the police, with some degree of judicial overview and a formal appeals process.

    Of course this is not going to happen, at least not on the global basis that would be needed to make it effective.

    And the only real option for anyone who runs their own website is to sign up Webmaster Tools to keep an eye on what the rainbow monster thinks of them.

    But if we're going to live in a world where Google, StopBadware, Spamhaus and all the other private organisations offering to make the net safe have so much power then we have to push them to do a better job, especially when it comes to communication.

    The point is not that this is online vigilantism, although it surely is. The point is about accountability, openness, responsiveness and the other things that we require from state actors but too often leave up to the market to enforce for private companies.

    For many of us our websites, email addresses, personal profiles and the other aspects of our online lives are vital parts of who we are.

    The organisations and companies seeking to fill the gaps left by law enforcement need to tread carefully and must treat those affected with respect and care, or they cannot expect us to support them, however noble their intentions.


    Source from: news.bbc.co.uk

    Do you know what they know about you?

    Friday, November 23, 2007

    Two computer discs holding the personal details of all families in the UK with a child under 16 have gone missing. The scandal of the 25 million missing records has highlighted the vulnerability of data.

    It is easy to develop a sense of creeping paranoia when you begin to contemplate just how many companies, government departments and other organisations know your personal data.

    She said it would be naive to think that an encounter with one organisation means one isolated database is queried. Typically data is gathered from many sources before a decision is reached.

    For instance the USVISIT border system, which is consulted when Britons cross from the UK to the US, mines about 30 separate databases as it checks identities.

    Ms Gallagher and colleague Peter Bradwell will release their report in early December.

    "Pretty much every organisation you engage with day-to-day - from clicking your Oyster card to ordering your take away - means sharing personal information."

    That sharing of data, she said, has become entwined with modern life and it was a mistake to think that sharing information so often only has a downside.

    You are not going to get people complying with data protection on the basis of good will

    Anyone that tries to stop their personal data leaking away often find they are denied benefits enjoyed by those that are happier to share.

    For instance, paying cash for everything will keep your name off credit checking databases. However, without the re-assurance of that check banks and credit card companies may refuse to issue a loan or mortgage. Data control

    And there are a lot of people within companies, government and other organisations that are allowed to use data that can be used to identify you.

    According to the 2006/7 annual report from the Information Commissioner there are more than 287,000 data controllers in the UK who have a responsibility for making sure that personal data is used correctly.

    Personal data in this sense is information that can be used to identify an individual.

    Many of those data controllers will oversee many more who actually do the job of maintaining and expanding the databases holding the data.

    And it does not stop there. The web is helping that data take wing and travel farther than ever before.

    Computer keyboard, Eyewire
    Government departments are increasingly sharing data

    What few people realise, said Ms Gallagher, was that handing over data to one organisation can mean that it reaches many others and becomes an entry on the database they maintain.

    "There is no awareness of what happens to that data when you give it away," said Ms Gallagher.

    "It is not so much the organisations with which you willingly share data," she said, "it is where it goes after that."

    Many organisations that collect data, such as credit checking agencies, were under commercial pressure to widen the scope of what they collect, said Ms Gallagher.

    No longer are firms just interested in the basic facts about you - now what matters as much as what type of credit card you own is when you go shopping, which stores you visit and what you buy.

    That pattern holds as much information as the raw facts about you - it helps companies decide which socio-economic bracket to put you and how to go about tailoring marketing to fit you and your lifestyle.Watching them

    Surveillance and the collection of data about people has become so pervasive that it has spawned a dedicated research organisation - the Surveillance Studies Network.

    Dr Kirstie Ball, a senior lecturer at the Open University, said that although many social scientists been studied the subject for years the pervasiveness of that scrutiny was prompting an upsurge of interest.

    "That personal data held by every organisation you interact with runs the parameters of your existence, your consumption, your entitlements," she said.

    Pens in pot, BBC
    Almost every time you fill in a form the data makes it to a database

    "We're all interested in the collection and application of personal data and its consequences for individual rights and social science concepts such as trust and discrimination," said Dr Ball.

    "It merits study and understanding because its consequences can be tangible," she said.

    For instance, she said, an employee ticking the wrong box when they enter your data into a database could mean a person ends up labelled as a former criminal or credit liability.

    It is possible to ask to see the data that companies and organisations hold about you, but a very small number of people take up this opportunity to vet what is known about them. Making sure all of it is accurate would be a mammoth task.

    For Ms Gallagher at Demos beefing up the power of the Information Commissioner to enforce the Data Protection Act would help redress some of the imbalance between the data companies hold about us.

    "Organisations and companies should be responding to the way we live," she said.

    Only by using those powers will the creeping spread of that data be held stemmed.

    "You are not going to get people complying with data protection on the basis of good will," she said. "Data is just too valuable."

  • Her Majesty's Revenue and Customs has set up a Child Benefit Helpline on 0845 302 1444 for customers who want more details.Spy wars In pictures It's quiz time!
    Source from: news.bbc.co.uk
  • How firms and fraudsters deal in data

    Wednesday, November 21, 2007

    Compact disk, Eyewire
    Organisations should have policies that govern who does what with data

    With computerised databases long established in large organisations, a series of policies and practices has grown up to safeguard the sensitive data they contain - in theory.

    In the front line of these safeguards are the strictures laid down by the Data Protection Act which is policed by the Information Commissioner.

    The Act details what workers can and cannot do with sensitive data and how it must be treated as well as what staff should do to ensure it is not compromised.

    In a statement issued after the HMRC data loss was made public Richard Thomas, the Information Commissioner, said his organisation was already investigating two other breaches at the government department.

    "Searching questions need to be answered about systems, procedures and human error inside both HMRC and the National Audit Office," said Mr Thomas.Data commandments

    Beyond data protection laws most organisations develop their own policies which govern how staff should treat such sensitive information, said Paul Simmonds, a board member of the Jericho Forum - a trade association for IT security bosses at the world's largest organisations.

    He said the Jericho Forum had developed a series of "commandments" which organisations should strive to live up to. They detail what organisations should do to ensure data is used appropriately.

    They cover such things as levels of security for different types of data; authentication to ensure data use is appropriate and how to share responsibilities for safeguarding information.

    "The Jericho Forum has long stated that data must be properly protected, both in transit and at rest," said Mr Simmonds "Effectively this means sensitive data must always be encrypted.

    "This data loss is just another in a long list of organisations who ignore basic security principles," he added.

    Birthday cake, BBC
    Much of the lost data, such as birth dates, cannot be changed

    Security systems that oversaw interaction between a database and its users helped to do more than just stop bad guys from the outside stealing data, he said.

    "They want to understand the way the database is being queried by authorised users and what counts as normal use," said Mr Davie.

    "The technology is there to detect unusual behaviour such as a junior downloading huge amounts of data," he added.

    Evidence suggests that technology has a significant role to play. A University of Washington study released in March 2007 showed that 60% of data breaches were the result of bad practices inside organisations rather than hackers.

    Data sale

    Although there is no evidence that the lost data has got in to the hands of criminals, anyone who did get hold of it, said Mr Davie, would be able to make great use of it.

    Man using keyboard, BBC
    There are many places online where data is bought and sold

    Hackers have increasingly targeted databases, he said, because the information inside them was so valuable and well organised.

    By contrast data gathered by other hacker tools such as key logging software installed surreptitiously on PCs that watches what people type can produce reams of information that must be cleaned up before it is useable or saleable.

    Andrew Moloney, financial services market director for RSA Security, said the data lost by HMRC could prove very valuable.

    "In the fraud underworld the quality of data directly impacts the flexibility with which they can use it," he said. "The more data you have around a subject the more different ways you can use that to commit fraud."

    There was no evidence yet, said Mr Moloney, that the data was being talked about or sold on the fraud boards and net markets that RSA monitors.

    Mr Moloney said there was a well-established chain of buyers and sellers who can handle large amounts of data and pass them on to those that wish to use them to commit fraud.

    "That's partly grown up to protect the anonymous individuals involved," he said, "and partly because we have seen specialisms develop with individuals finding their own niche in that underground economy."

    What also makes the data attractive to fraudsters, said Mr Moloney, was that much of the data in it, such as names of children and birth dates, cannot be changed and will be valuable if it reaches criminals in the next week or the next year.

    "Once it's compromised it is compromised for the long term," he said.Importing workers Dollar's dazzle Day in pictures

    Source from: news.bbc.co.uk

    When work becomes a game

    Sunday, November 18, 2007

    Young men playing games, AP
    A generation is growing up playing immersive online games
    Video games are big business and soon they could be big in business too.

    A whole generation is growing up for whom video games are a key part of how they relax, whether it be fragging friends in a first person shooter or backing up the main tank in a Warcraft raid.

    And it is not just youngsters. There are plenty of older folks who shake off the dust of the working day in many different virtual worlds.

    Statistics from the the US Entertainment Software Association (ESA) back this up. It claims that the average player is 33 and has more than a decade of gaming under their belt.

    All of a sudden, say academics and researchers, companies have realised that all the time employees spend gaming in virtual worlds is changing them.

    Ian Hughes, IBM's metaverse evangelist, said many organisations were considering ways of harnessing the skills and familiarity their employees have with virtual environments.

    This familiarity has driven many organisations to consider virtual worlds as places where employees can meet, mix and get on with the job.

    "A lot of people are more accepting of that way of working just because of games," he said.

    "It's about harnessing that ability to play to get work done."

    The formidable organisational skills needed to run a game team or guild, organise raids involving perhaps 40 people and co-ordinate their different abilities to defeat a game's strongest foes are all relevant to work, said Mr Hughes.Game gear

    But it is not just the skills that gamers hone in futuristic or fantasy worlds that businesses want to co-opt. Some are taking their inspiration directly from the way that online games are structured.

    Screenshot from World of Warcraft, Blizzard
    Skills learned on raids in games could apply to work too

    "The problems associated with distributed teams, collaboration and information overload right now are so severe, and the opportunities so good, that they are willing to look at anything," he said.

    Dr Reeves has founded a company called Seriosity that applies game elements to workplaces.

    It was working with five or six unnamed Fortune 500 companies to harness the efficiencies of those game mechanics, said Dr Reeve.

    One of the programs developed by Seriosity adds a virtual currency element to e-mail in a bid to help people cope with information overload.

    Anyone sending a message adds some of their limited supply of virtual coins, called Serios, to show how important they consider that e-mail to be.

    It was a more finely grained grading system than the low, medium or high importance flags found in most e-mail programs, said Dr Reeves.

    It had other benefits too, he said. It revealed not just the flow of messages but also started to show who people pay attention to and who did a good job of getting responses.

    Some companies were starting to adopt even more of the elements familiar from games.

    "There are people right now trying to map it one-to-one," said Dr Reeves. Level playing field

    Convinced that games can help them thrive some companies have turned work groups into guilds, rewarded staff with experience points when they complete tasks, giving out titles and badges when a guild finished a project and portraying objectives as quests.

    Screenshot from Second Life, AP
    Virtual worlds could become key to future business life

    None, so far, he said, were tying wages to how people performed in the quests and against other guilds.

    "Mapping levels and points on to wages is the most extreme application," he said.

    Companies were adopting game mechanics for several reasons, said Dr Reeves.

    Partly because workers were so familiar with this structure, he said, and because people become powerfully motivated when they know how they compare to their contemporaries.

    The main reason was for the transparency it gave to the way workplaces were organised and for revealing who got things done.

    "It exposes those that do and do not play well," said Dr Reeves. "There is a leader board and you know the rules."

    It had the potential to turn workplaces into meritocracies where the most accomplished are easy to spot because they have racked up all rewards, achievements and levels required for a particular post.

    While it may not sweep away systems of privilege or end nepotism it had the potential to make workplaces fairer and take some of the grind out of the day job, he said.

    "The whole idea here is to get the objectives of the individual players aligned with the objectives of the organisation," said Dr Reeves. "Do that and you have something good."

    Angela Barron, an advisor at the Chartered Institute of Personnel and Development, said games had long been used in training to expose personal preferences and prejudices.

    Many organisations also used courses that revolve around games to help make teams work together better or expose power structures among workers.

    She said this was the first time she had heard of elements of online games being used in a similar way.

    "I would not have thought enough people play games for it to be a great motivator," she said.

    But, she said, anything that helped staff develop a better working relationship and promote team work was likely to be a good thing.Deadly gems Climate dilemma All eyes on Koroma

    Source from: news.bbc.co.uk

    Net vigilantes 'should listen more'

    Regular columnist Bill Thompson wants "net vigilantes" to focus more on customer service.

    Sometime in October a malicious program exploited a security flaw in the Wordpress software I use to host my weblog and injected some extra commands into one of the widgets I use to add features to the site.

    They opened up a connection between the blog and a site that tried to download a malicious piece of software to any site visitor unfortunate enough to be using Microsoft's Internet Explorer.

    Anyone who visited my site would have been prompted to install a clearly unwanted piece of software, although as far as I know nobody was affected. However I can't be sure and hope that I didn't unwittingly cause damage to anyone else's computer.

    I upgrade my installation regularly, and apply new security patches as they come out, but this happened in the few days before the release of a new version and I was caught.

    Yet I only found out about the problem when a kind reader e-mailed me to tell me that Google was warning prospective visitors that my blog might "harm" their computer.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action

    I hadn't noticed the warning because, strange as it may seem, I don't Google my own name that often (searching blogs is a different matter, of course).

    And I hadn't found out from Google, either because they didn't send any emails or because the company that acts as technical contact for my site didn't bother passing them on.

    Once I knew what had happened I searched for and found the offending code, but it has taken three weeks to get the Google warning removed, and the experience has been a salutary one.

    I started off at StopBadware, the organisation Google works with to flag sites hosting malicious code.

    Fighting Badware

    I searched for information about what they had found on my site and discovered that although Google had flagged my blog it hadn't passed any information on to StopBadware.

    So I requested a review using the form provided, hoping to get some information to help me find out what had happened and which pages were affected.

    I had to e-mail them three times before I got a reply, and had to wait 10 days for that, and even then there was no information on exactly what Google had found on my site, so I had to search myself.

    Eventually I discovered that I could find a lot more information and request a review more effectively by signing up for Google's Webmaster Tools.

    This is a great service, but it isn't something my small blog really needs and of course signing up gives Google access to a lot of information about what I'm up to, information I'd rather they didn't have.

    But when the alternative is a blood-red sign saying "All hope abandon, ye who enter here" splashed over Google's search results there really is no choice.

    And now my site is clean and Google likes me again.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action. There is a similar debate going on over e-mail and spam, with groups like Spamhaus creating lists of servers that they believe are sending out spam.

    Other organisations subscribe to the Spamhaus Block List and will block emails from those servers.

    Their approach is pretty effective at closing spam relays, but of course sometimes the listing is wrong and sometimes there is collateral damage, when a server used by an ISP is listed and all of its customers are affected.

    Part of me would like to see this sort of listing done by the appropriate authorities, perhaps even the police, with some degree of judicial overview and a formal appeals process.

    Of course this is not going to happen, at least not on the global basis that would be needed to make it effective.

    And the only real option for anyone who runs their own website is to sign up Webmaster Tools to keep an eye on what the rainbow monster thinks of them.

    But if we're going to live in a world where Google, StopBadware, Spamhaus and all the other private organisations offering to make the net safe have so much power then we have to push them to do a better job, especially when it comes to communication.

    The point is not that this is online vigilantism, although it surely is. The point is about accountability, openness, responsiveness and the other things that we require from state actors but too often leave up to the market to enforce for private companies.

    For many of us our websites, email addresses, personal profiles and the other aspects of our online lives are vital parts of who we are.

    The organisations and companies seeking to fill the gaps left by law enforcement need to tread carefully and must treat those affected with respect and care, or they cannot expect us to support them, however noble their intentions.


    Source from: news.bbc.co.uk

    Net vigilantes 'should listen more'

    Monday, November 12, 2007

    Regular columnist Bill Thompson wants "net vigilantes" to focus more on customer service.

    Sometime in October a malicious program exploited a security flaw in the Wordpress software I use to host my weblog and injected some extra commands into one of the widgets I use to add features to the site.

    They opened up a connection between the blog and a site that tried to download a malicious piece of software to any site visitor unfortunate enough to be using Microsoft's Internet Explorer.

    Anyone who visited my site would have been prompted to install a clearly unwanted piece of software, although as far as I know nobody was affected. However I can't be sure and hope that I didn't unwittingly cause damage to anyone else's computer.

    I upgrade my installation regularly, and apply new security patches as they come out, but this happened in the few days before the release of a new version and I was caught.

    Yet I only found out about the problem when a kind reader e-mailed me to tell me that Google was warning prospective visitors that my blog might "harm" their computer.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action

    I hadn't noticed the warning because, strange as it may seem, I don't Google my own name that often (searching blogs is a different matter, of course).

    And I hadn't found out from Google, either because they didn't send any emails or because the company that acts as technical contact for my site didn't bother passing them on.

    Once I knew what had happened I searched for and found the offending code, but it has taken three weeks to get the Google warning removed, and the experience has been a salutary one.

    I started off at StopBadware, the organisation Google works with to flag sites hosting malicious code.

    Fighting Badware

    I searched for information about what they had found on my site and discovered that although Google had flagged my blog it hadn't passed any information on to StopBadware.

    So I requested a review using the form provided, hoping to get some information to help me find out what had happened and which pages were affected.

    I had to e-mail them three times before I got a reply, and had to wait 10 days for that, and even then there was no information on exactly what Google had found on my site, so I had to search myself.

    Eventually I discovered that I could find a lot more information and request a review more effectively by signing up for Google's Webmaster Tools.

    This is a great service, but it isn't something my small blog really needs and of course signing up gives Google access to a lot of information about what I'm up to, information I'd rather they didn't have.

    But when the alternative is a blood-red sign saying "All hope abandon, ye who enter here" splashed over Google's search results there really is no choice.

    And now my site is clean and Google likes me again.

    Malware on websites isn't the only area where private organisations are taking on this sort of police action. There is a similar debate going on over e-mail and spam, with groups like Spamhaus creating lists of servers that they believe are sending out spam.

    Other organisations subscribe to the Spamhaus Block List and will block emails from those servers.

    Their approach is pretty effective at closing spam relays, but of course sometimes the listing is wrong and sometimes there is collateral damage, when a server used by an ISP is listed and all of its customers are affected.

    Part of me would like to see this sort of listing done by the appropriate authorities, perhaps even the police, with some degree of judicial overview and a formal appeals process.

    Of course this is not going to happen, at least not on the global basis that would be needed to make it effective.

    And the only real option for anyone who runs their own website is to sign up Webmaster Tools to keep an eye on what the rainbow monster thinks of them.

    But if we're going to live in a world where Google, StopBadware, Spamhaus and all the other private organisations offering to make the net safe have so much power then we have to push them to do a better job, especially when it comes to communication.

    The point is not that this is online vigilantism, although it surely is. The point is about accountability, openness, responsiveness and the other things that we require from state actors but too often leave up to the market to enforce for private companies.

    For many of us our websites, email addresses, personal profiles and the other aspects of our online lives are vital parts of who we are.

    The organisations and companies seeking to fill the gaps left by law enforcement need to tread carefully and must treat those affected with respect and care, or they cannot expect us to support them, however noble their intentions.


    Source from: news.bbc.co.uk

    When work becomes a game

    Sunday, November 11, 2007

    Young men playing games, AP
    A generation is growing up playing immersive online games
    Video games are big business and soon they could be big in business too.

    A whole generation is growing up for whom video games are a key part of how they relax, whether it be fragging friends in a first person shooter or backing up the main tank in a Warcraft raid.

    And it is not just youngsters. There are plenty of older folks who shake off the dust of the working day in many different virtual worlds.

    Statistics from the the US Entertainment Software Association (ESA) back this up. It claims that the average player is 33 and has more than a decade of gaming under their belt.

    All of a sudden, say academics and researchers, companies have realised that all the time employees spend gaming in virtual worlds is changing them.

    Ian Hughes, IBM's metaverse evangelist, said many organisations were considering ways of harnessing the skills and familiarity their employees have with virtual environments.

    This familiarity has driven many organisations to consider virtual worlds as places where employees can meet, mix and get on with the job.

    "A lot of people are more accepting of that way of working just because of games," he said.

    "It's about harnessing that ability to play to get work done."

    The formidable organisational skills needed to run a game team or guild, organise raids involving perhaps 40 people and co-ordinate their different abilities to defeat a game's strongest foes are all relevant to work, said Mr Hughes.Game gear

    But it is not just the skills that gamers hone in futuristic or fantasy worlds that businesses want to co-opt. Some are taking their inspiration directly from the way that online games are structured.

    Screenshot from World of Warcraft, Blizzard
    Skills learned on raids in games could apply to work too

    "The problems associated with distributed teams, collaboration and information overload right now are so severe, and the opportunities so good, that they are willing to look at anything," he said.

    Dr Reeves has founded a company called Seriosity that applies game elements to workplaces.

    It was working with five or six unnamed Fortune 500 companies to harness the efficiencies of those game mechanics, said Dr Reeve.

    One of the programs developed by Seriosity adds a virtual currency element to e-mail in a bid to help people cope with information overload.

    Anyone sending a message adds some of their limited supply of virtual coins, called Serios, to show how important they consider that e-mail to be.

    It was a more finely grained grading system than the low, medium or high importance flags found in most e-mail programs, said Dr Reeves.

    It had other benefits too, he said. It revealed not just the flow of messages but also started to show who people pay attention to and who did a good job of getting responses.

    Some companies were starting to adopt even more of the elements familiar from games.

    "There are people right now trying to map it one-to-one," said Dr Reeves. Level playing field

    Convinced that games can help them thrive some companies have turned work groups into guilds, rewarded staff with experience points when they complete tasks, giving out titles and badges when a guild finished a project and portraying objectives as quests.

    Screenshot from Second Life, AP
    Virtual worlds could become key to future business life

    None, so far, he said, were tying wages to how people performed in the quests and against other guilds.

    "Mapping levels and points on to wages is the most extreme application," he said.

    Companies were adopting game mechanics for several reasons, said Dr Reeves.

    Partly because workers were so familiar with this structure, he said, and because people become powerfully motivated when they know how they compare to their contemporaries.

    The main reason was for the transparency it gave to the way workplaces were organised and for revealing who got things done.

    "It exposes those that do and do not play well," said Dr Reeves. "There is a leader board and you know the rules."

    It had the potential to turn workplaces into meritocracies where the most accomplished are easy to spot because they have racked up all rewards, achievements and levels required for a particular post.

    While it may not sweep away systems of privilege or end nepotism it had the potential to make workplaces fairer and take some of the grind out of the day job, he said.

    "The whole idea here is to get the objectives of the individual players aligned with the objectives of the organisation," said Dr Reeves. "Do that and you have something good."

    Angela Barron, an advisor at the Chartered Institute of Personnel and Development, said games had long been used in training to expose personal preferences and prejudices.

    Many organisations also used courses that revolve around games to help make teams work together better or expose power structures among workers.

    She said this was the first time she had heard of elements of online games being used in a similar way.

    "I would not have thought enough people play games for it to be a great motivator," she said.

    But, she said, anything that helped staff develop a better working relationship and promote team work was likely to be a good thing.Challenges ahead No rush for gold Survivors' stories

    Source from: news.bbc.co.uk

    When work becomes a game

    Sunday, November 4, 2007

    Young men playing games, AP
    A generation is growing up playing immersive online games
    Video games are big business and soon they could be big in business too.

    A whole generation is growing up for whom video games are a key part of how they relax, whether it be fragging friends in a first person shooter or backing up the main tank in a Warcraft raid.

    And it is not just youngsters. There are plenty of older folks who shake off the dust of the working day in many different virtual worlds.

    Statistics from the the US Entertainment Software Association (ESA) back this up. It claims that the average player is 33 and has more than a decade of gaming under their belt.

    All of a sudden, say academics and researchers, companies have realised that all the time employees spend gaming in virtual worlds is changing them.

    Ian Hughes, IBM's metaverse evangelist, said many organisations were considering ways of harnessing the skills and familiarity their employees have with virtual environments.

    This familiarity has driven many organisations to consider virtual worlds as places where employees can meet, mix and get on with the job.

    "A lot of people are more accepting of that way of working just because of games," he said.

    "It's about harnessing that ability to play to get work done."

    The formidable organisational skills needed to run a game team or guild, organise raids involving perhaps 40 people and co-ordinate their different abilities to defeat a game's strongest foes are all relevant to work, said Mr Hughes.Game gear

    But it is not just the skills that gamers hone in futuristic or fantasy worlds that businesses want to co-opt. Some are taking their inspiration directly from the way that online games are structured.

    Screenshot from World of Warcraft, Blizzard
    Skills learned on raids in games could apply to work too

    "The problems associated with distributed teams, collaboration and information overload right now are so severe, and the opportunities so good, that they are willing to look at anything," he said.

    Dr Reeves has founded a company called Seriosity that applies game elements to workplaces.

    It was working with five or six unnamed Fortune 500 companies to harness the efficiencies of those game mechanics, said Dr Reeve.

    One of the programs developed by Seriosity adds a virtual currency element to e-mail in a bid to help people cope with information overload.

    Anyone sending a message adds some of their limited supply of virtual coins, called Serios, to show how important they consider that e-mail to be.

    It was a more finely grained grading system than the low, medium or high importance flags found in most e-mail programs, said Dr Reeves.

    It had other benefits too, he said. It revealed not just the flow of messages but also started to show who people pay attention to and who did a good job of getting responses.

    Some companies were starting to adopt even more of the elements familiar from games.

    "There are people right now trying to map it one-to-one," said Dr Reeves. Level playing field

    Convinced that games can help them thrive some companies have turned work groups into guilds, rewarded staff with experience points when they complete tasks, giving out titles and badges when a guild finished a project and portraying objectives as quests.

    Screenshot from Second Life, AP
    Virtual worlds could become key to future business life

    None, so far, he said, were tying wages to how people performed in the quests and against other guilds.

    "Mapping levels and points on to wages is the most extreme application," he said.

    Companies were adopting game mechanics for several reasons, said Dr Reeves.

    Partly because workers were so familiar with this structure, he said, and because people become powerfully motivated when they know how they compare to their contemporaries.

    The main reason was for the transparency it gave to the way workplaces were organised and for revealing who got things done.

    "It exposes those that do and do not play well," said Dr Reeves. "There is a leader board and you know the rules."

    It had the potential to turn workplaces into meritocracies where the most accomplished are easy to spot because they have racked up all rewards, achievements and levels required for a particular post.

    While it may not sweep away systems of privilege or end nepotism it had the potential to make workplaces fairer and take some of the grind out of the day job, he said.

    "The whole idea here is to get the objectives of the individual players aligned with the objectives of the organisation," said Dr Reeves. "Do that and you have something good."

    Angela Barron, an advisor at the Chartered Institute of Personnel and Development, said games had long been used in training to expose personal preferences and prejudices.

    Many organisations also used courses that revolve around games to help make teams work together better or expose power structures among workers.

    She said this was the first time she had heard of elements of online games being used in a similar way.

    "I would not have thought enough people play games for it to be a great motivator," she said.

    But, she said, anything that helped staff develop a better working relationship and promote team work was likely to be a good thing.Australian election Diplomatic deficit Fleeing the flood

    Source from: news.bbc.co.uk