Digital Identity Protection: Interview with Selva Mª Orejón

17/11/2015
|

Joining us to discuss this topic is Selva María Orejón,
Executive Director and founder of onBRANDING: Reputation, Cyber Investigation, de-positioning, and content removal, as well as a professor at EAE.

Selva begins the interview by asking…

Have any of you had your identity stolen online? 

Are any of you unaware of the extent to which your personal information is exposed on social networks? 

It is relatively easy to impersonate a member of the state security forces, bypass barriers, and physically locate them. Theft, endangering their physical integrity. Metadata to prove the authorship of a photo.

Business concerns:

– Theft – damage to secrets and intellectual/industrial property

– Online fraud

– Identity theft and impersonation

– The cost of these cybercrimes totals billions of dollars and could triple by 2020

Two types of attacks: random and targeted

Sometimes people from the immediate environment are targeted, such as children.

Two-factor authentication / Geolocation disabled / Different password for each network

Content:

Photos / videos /

4 motivations:

– Economic

– Personal / emotional

– Activism

– Psychological issues: very serious, they are not deterred by legality

False beliefs: There is no malware for Apple.

Do not share sessions (not even with your partner). Failing to change passwords is a serious matter.

– What type of information should I hide well if I want to avoid cyberattacks on my company? And on a personal level, are there any differences?
– A: All information that we would not make public or all information that we would not share in a public forum must be as secure as possible. Secure means, from the point of view of access to information. And any information that is sensitive should, if possible, not be digitized. Regarding private information, the following precautions should be taken: you must know how to differentiate between the intimate and private sphere, the family, social, and public spheres… In short, be aware of the different levels of information.  

 

– During the conference, you spoke a lot about how insecure Instagram can be. Do you think it is more dangerous than other social networks?

– A: No, it is due to user behavior, because the platform itself also has the capacity to make the information you are publishing private or to keep it as protected as possible. The problem is that when one is not aware of the risk they may face when that information is public… That is really where the vulnerability lies, not in the platform itself. It’s like saying weapons kill… No. There is a person who pulls the trigger. And if they don’t pull it, nothing happens. Instagram specifically is more dangerous than other networks because you might be geolocating yourself, you might be tagging people in your circle, you might be using very common hashtags, and you might be uploading photographs that say much more than you think. Especially the typical person who takes photos and doesn’t realize that their watch, the type of computer they use, or the car they have parked is visible.

 

– What are the latest trends in cybercrime?

– A: I believe there are some very clear trends and, in the end, everything related to places where there is a significant volume of people has obviously always been attractive. And now the places where we actually spend the most time are social networks; therefore, they are within reach, and much more so than we thought. I believe another trend could be that, today, by publishing and sharing so much information, we often have a physical security problem due to the lack of protection of our privacy. So, this can indeed be a trend: we need to train people who are accessing information much more, especially when they are not aware of what they are publishing, rather than what they are publishing consciously.

 

– What are the steps to recover online reputation after having suffered identity theft on the web?

– A: Reputation management does not exist; it is communication management, because you cannot manage reputation; it is the sum of perceptions that you generate in people. You cannot get inside a person’s head, but you can change your attitude, and you can also change the way you communicate in your daily life, and in different aspects, to your various audiences. Thus, the changes you make in your behavior, plus the changes you make in your communication, can obviously improve the reputation people have of you. In any case, it is very important that when someone has suffered an attack on their digital identity, they are able to first know what information is linked to them, and then outline the strategies they want to follow—whether they want to remove, create, de-position, de-index… And then continuously analyze the changes that are occurring. Monitor continuously to see what is being done.

 

– What are the basic tips to follow to protect your digital identity?

– A: I believe the basic tips should be divided into three sections: the first block would be everything related to user behavior. This involves, for example, basic security measures such as password changes, ensuring privacy is as controlled as possible, and on the other hand, not sharing information—even spoken—with people they do not truly trust. The second pillar would be everything related to device configuration, whether it’s having all software updated, but also access to different antivirus and anti-malware programs, etc. And finally, the last section would be connections, which must be as secure as possible. Avoid connecting to public Wi-Fi or Wi-Fi networks that have had the same password for years, where you don’t know which devices are connecting, and obviously, for the routers you use constantly, at least change the original password and ensure you have to authorize access to that router so it can provide information.

– Not all information thefts occur for personal gain. Edward Snowden, WikiLeaks, the lists of Spanish accounts in Switzerland… What is your opinion on these cases where an illegitimate appropriation of information results in social improvement?

– A: Well, look, I am not going to give my personal opinion, but what I can say is that, like everything in this life, just as it has often been said about the rebellion of the machines, or that machines themselves can change the world… I believe that, deep down, evil and good will be everywhere. 

The fact that it is visible now, because they have more capacity for dissemination, means it will indeed be used as another form of power, and information continues to be power. In whose hands it lies only depends on the protection you can provide it, and what that can contribute to society.  

Therefore, as long as you are committing a crime, you will be committing a crime regardless of the purpose for which you are doing it. And there, you will have to deal with the current legality at that time.

Digital Identity

Methods for analyzing and
assessing online
reputation damage