27 April 2016 marked a turning point for a lot of countries as well as a lot
businesses worldwide: EU regulation 2016/679 (going by it’s more widely known
name General Data Protection Regulation and abbreviated GDPR) was adopted by the
European Parliament, the Council as well as the Commission [1]. Especially
readers from countries outside of the EU might ask “Why should this be of
interest for me?”.
The point is: if your business is dealing with data of EU citizens (e.g. because
you are having an online shop selling goods in the EU, or you operate a social
network platform with customers that are EU citizens) you are liable under GDPR
– this is regulated in Article 3, section 2 of the regulation: “This Regulation
applies to the processing of personal data of data subjects residing in the
Union by a controller not established in the Union, where the processing
activities are related to: (a) the offering of goods or services to such data subjects in the Union; or (b) the monitoring of their behaviour.”
I’d guess that if you are reading these lines you become aware (if not have been
so before) that your business might most probably be affected by GDPR as well.
Now, the purpose of this blog post is not to enlighten you on the basics of GDPR
but to discuss one special, interesting aspect of this regulation:
pseudonymisation and how it might support your way to become compliant with
GDPR.
Troopers ’17 – the 10th edition – madness is over and
hopefully all of you are well rested and recovered after this special week. Of
course the rest of the world did not stand still and thus Google lifted the
curtains on a new public portal collecting and promoting the Open Source
Software projects developed by employees of Google:
opensource.google.com. There are a lot of
interesting projects that might incubate new interesting developments. And even
security oriented tools and projects (51 at the time of writing to be precise)
are publically available [1].
TL;DR: Marie Moe talked about security issues of medical devices, especially
implantable devices like pacemakers, but not in overwhelming technological
depth. She wanted to point out the necessity of intensified security research in
the field of medical devices as vendors and medical personnel seem to be lacking
necessary awareness of security of devices, interfaces, services, and even data
privacy.”Get involved, join the cavalry” was
her core message.
Lub-Dub-Lub-Dub-Lub-Dub
Marie started her talk with the sound of a repeating heartbeat. First she
introduced how she came up with the topic of her talk: Marie relies on a
pacemaker herself andsince she got it implanted she was curious how secure this
little device might be. A minimum education of the auditorium followed including
an explanation how a human heart works and what a pacemaker does.