{"id":2954,"date":"2016-02-05T11:00:44","date_gmt":"2016-02-05T05:30:44","guid":{"rendered":"http:\/\/gtm360.com\/blog\/?p=2954"},"modified":"2021-11-25T15:20:38","modified_gmt":"2021-11-25T09:50:38","slug":"privacy-does-not-equal-security","status":"publish","type":"post","link":"https:\/\/gtm360.com\/blog\/2016\/02\/05\/privacy-does-not-equal-security\/","title":{"rendered":"Privacy Does Not Equal Security"},"content":{"rendered":"<p><a href=\"http:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps01.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-2957\" src=\"http:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps01.jpg\" alt=\"ps01\" width=\"201\" height=\"93\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps01.jpg 492w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps01-200x93.jpg 200w\" sizes=\"auto, (max-width: 201px) 100vw, 201px\" \/><\/a>A few months ago, I&#8217;d posted the following update on social media:<\/p>\n<blockquote><p><strong>Privacy does not equal Security: Privacy is refusing to give out your mobile #. Security is refusing to give out your debit card PIN #. <\/strong><\/p><\/blockquote>\n<p>To which a friend had replied, &#8220;You made it so simple!!&#8221;<\/p>\n<p>Then I thought of bank account numbers and realized it wasn&#8217;t so simple.<\/p>\n<p>If I told you my BAN, it&#8217;d only be a question of privacy in India. But in the USA, you could pull out money from my account only on the basis of this info* &#8211; *T&amp;C applicable &#8211; so it&#8217;d turn into a matter of security!<\/p>\n<p>Adding to the complexity is that the privacy- and security-consciousness of the average John \/ Jane Doe vary from one country to another (if not across different regions within the same country).<\/p>\n<p><a href=\"http:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps02.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-2966\" src=\"http:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps02.jpg\" alt=\"ps02\" width=\"250\" height=\"159\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps02.jpg 482w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps02-200x127.jpg 200w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><\/a>In my observation, America is not so security-conscious. Millions of people are\u00a0willing to share their Online Banking credentials with Mint, Geezeo and the new breed of <strong>Mo<\/strong>bile <strong>M<\/strong>oney <strong>M<\/strong>anagement <strong>A<\/strong>pp<strong>s<\/strong> (MoMMAs) ostensibly in return for tips to save a few $$$ a year.<\/p>\n<p>This is unimaginable in a security-conscious culture like India (apart from being expressly forbidden by banks).<\/p>\n<p>Where, on the other hand, people are not so privacy-conscious and happily give out their mobile phone numbers to virtually anyone who asks for it. Including their banks. Given that so many transactions rely on mobile numbers, I wonder if it&#8217;s even possible to get a bank account in India without a mobile phone connection (I&#8217;ve never tried). But I digress. Because they have their customers&#8217; mobile numbers on file, banks are able &#8211; and mandated &#8211; to send an SMS Alert every time a credit or debit card is used. This is a great way to control card fraud in India.<\/p>\n<p>Such a regulation is unimaginable in a privacy-conscious culture like USA, where customers are not required to share their mobile numbers with their banks. As a result, alternative approaches to detecting card fraud have cropped up. Like <em>BillGuard<\/em>. This approach works in the United States because enough people seem to be ready to hand over their credit card account credentials to third party services like this startup.<\/p>\n<p>This is unimaginable (and forbidden) in India!<\/p>\n<p><a href=\"http:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps-fi-1.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-2965\" src=\"http:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps-fi-1.jpg\" alt=\"ps-fi\" width=\"200\" height=\"89\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps-fi-1.jpg 630w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2016\/01\/ps-fi-1-200x89.jpg 200w\" sizes=\"auto, (max-width: 200px) 100vw, 200px\" \/><\/a>To avoid going around in any more circles, let me just say that, while privacy surely does not equal security, the distinction between the two is perhaps more complex than I&#8217;d made it out to be in my aforementioned post.<\/p>\n<p>Just one more thing that makes life interesting for banks and fintech companies designing and building banking systems in different parts of the world!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A few months ago, I&#8217;d posted the following update on social media: Privacy does not equal Security: Privacy is refusing to give out your mobile #. Security is refusing to give out your debit card PIN #. To which a friend had replied, &#8220;You made it so simple!!&#8221; Then I thought of bank account numbers &#8230; <a title=\"Privacy Does Not Equal Security\" class=\"read-more\" href=\"https:\/\/gtm360.com\/blog\/2016\/02\/05\/privacy-does-not-equal-security\/\" aria-label=\"Read more about Privacy Does Not Equal Security\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":2965,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,1],"tags":[],"class_list":["post-2954","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bfsi","category-mandatory-category"],"_links":{"self":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts\/2954","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/comments?post=2954"}],"version-history":[{"count":14,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts\/2954\/revisions"}],"predecessor-version":[{"id":8693,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts\/2954\/revisions\/8693"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/media\/2965"}],"wp:attachment":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/media?parent=2954"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/categories?post=2954"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/tags?post=2954"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}