A security awareness trainer is creating content for employees about mobile security. She wants to explain why 'I have nothing to hide' is an insufficient reason to ignore mobile privacy settings.
Which of the following identifies the 'aggregation problem' in mobile privacy, and why does it make seemingly innocuous data collections individually acceptable but collectively concerning?
- A.Individually harmless data points (location check-in at a coffee shop, purchase at a pharmacy, contact name, browsing a medical information site) combine into a highly sensitive profile: the pharmacy purchase + health site browsing + GPS at a specific medical clinic reveal a medical condition the person would not voluntarily disclose. Mobile devices collect all of these simultaneously, and data brokers aggregate cross-app data - each app's individually 'nothing to hide' data becomes a comprehensive sensitive behavioral profile
- B.The problem arises in surveillance-heavy jurisdictions alone, and a person in a country with strong data protection law is outside it (the regulators there restrict what a broker can combine): individually harmless points stay harmless, and every profile a broker assembles is limited by statute, with the trainer better served explaining the legal position than the technical one, and the settings on the handset largely irrelevant to the outcome for that population, and the argument sound for anyone living under such a regulatory regime