Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

n2doc

(47,953 posts)
Sun Nov 9, 2014, 09:22 AM Nov 2014

Federal sites leaked the locations of people seeking AIDS services for years

By Craig Timberg

Two federal government Web sites that help people find AIDS-related medical services have begun routinely encrypting user data after years in which they let sensitive information -- including the real-world locations of site visitors – onto the Internet unprotected.

Until the change, these sites had risked exposing the identities of visitors when they used search boxes to find nearby facilities offering HIV testing, treatment and other services, such as substance abuse and mental health counseling, say security experts. Government smartphone apps associated with one of the Web sites, AIDS.gov, also transmitted the latitude and longitude of users seeking services, after collecting those details from the phones of users.

The sites and apps did not themselves track visitors, but their data was handled in ways that could have enabled monitoring by employers, universities or others with access to the data flowing between individual devices – such as computers and smartphones – and the Internet. Even using a public wifi signal, offered by a coffee shop or airport, could have allowed a nearby hacker to learn that an individual user, wielding a particular type of smartphone, was seeking treatment for HIV or drug addiction.

Privacy advocates long have argued that routine encryption – using a popular protocol called SSL – should be standard for Web sites or apps handling potentially sensitive information, especially when it relates to personal medical concerns. Government officials, in response to questions posed by The Washington Post, said they came to agree that their sites created privacy risks for those seeking AIDS-related services.

more
http://www.washingtonpost.com/blogs/the-switch/wp/2014/11/07/federal-sites-leaked-the-locations-of-people-seeking-aids-services-for-years/

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Federal sites leaked the locations of people seeking AIDS services for years (Original Post) n2doc Nov 2014 OP
The Federal Government has always acted as an ardent enemy of people with AIDS. Bluenorthwest Nov 2014 #1
Military Intelligence, Jumbo Shrimp, Old Nick Nov 2014 #2
 

Bluenorthwest

(45,319 posts)
1. The Federal Government has always acted as an ardent enemy of people with AIDS.
Sun Nov 9, 2014, 11:36 AM
Nov 2014

It's part of the Reagan tradition.

Latest Discussions»General Discussion»Federal sites leaked the ...