Showing posts with label unintended consequences. Show all posts
Showing posts with label unintended consequences. Show all posts

My ITAD Industry Is Misleading Us about the Dark Web

HIPAA, HDTV, and the Hard Drive: Two 1996 Laws and the Myths They Spawned

Twenty-six years ago I was consulting for the Massachusetts DEP, a couple years removed from being Deputy Division Director, having passed up the Director's chair for a weirder and more interesting assignment: getting the state ready for a wave of cathode ray tubes nobody in government had really priced out yet.

The wave had a birth certificate. The Telecommunications Act of 1996 didn't just deregulate your phone company — it set in motion the reclaiming of analog broadcast spectrum for the wireless industry, which meant every television station in America eventually had to go digital, which meant every television in America was, sooner or later, going to look like a brick next to a flat panel. Add computer monitors following the same LCD gravity, and you had what I'd call an elective upgrade cycle — nothing was actually broken — about to dump tens of millions of perfectly functional CRT TVs and monitors onto a secondary market that had never seen anything like it.  It made possible the critical mass of users who paid for TV broadcasts and internet cable for billions of consumers in the "good enough" or Emerging Market.


"It was Twenty Years Ago Today"

Perfectly functional is the part that got lost. Because a glut of good used electronics is bad news for a specific set of industries: the Planned Obsolescence crowd, who need you buying new; the Big Shred outfits, who get paid by the pound to turn a working monitor into commodity glass and copper; the Haz Waste Disposal industry, which had built permitting and liability empires around leaded glass; and what Peter Buffett labels the charitable-industrial complex, which discovered that "toxic dumping in Africa" made a better fundraising letter than "we shredded a working TV that a family in Lagos would have paid for." Between them, they wrote the overseas dumping narrative — the idea that a container of tested, working CRTs bound for a reuse market overseas was actually poison being smuggled onto a beach. It wasn't nothing — there was real e-waste and real bad actors — but the ratio got inflated by people with a direct financial interest in inflating it, and that ratio became the story.

I bring this up now because the ITAD industry — IT Asset Disposition, the people who take your company's old laptops away — is running a version of the same play today, just with data instead of lead glass. The current bogeyman isn't a container ship, it's the "dark web," and the pitch is the same shape it was in 1999: something terrifying is happening to your stuff after it leaves your hands, and the only responsible answer is destruction, certified, billed by the pound.

HIPAA passed in 1996, the same year as the Telecom Act, and somewhere in its long afterlife it got repurposed as the legal justification for destroying old hard drives, on the theory that deleted health records could be resurrected and sold. That was the story, anyway. The story that didn't get told nearly as loudly was that a wiped hard drive sitting in a ten-year-old PC was also sitting on top of a legitimate Windows license, and often a licensed copy of Intuit, QuickBooks, or MS Office — hundreds of dollars of software the original vendors very much did not want circulating for free on the secondary market. Data destruction as a service solved two problems for two different industries at once, and only one of them had anything to do with your health records.

So here's the question I don't think anyone in the ITAD world wants asked out loud: is there an actual market of people buying decade-old PCs off Goodwill shelves, on the off chance the previous owner forgot to wipe a drive, hoping to find a *.doc file mentioning a diagnosis, so they can resell it on the dark web? Or is the dark web, functionally, 100% populated by data stolen while it was still in active use — phished, breached, skimmed, scraped from a live database — because that's simply where the value is?

I'd put money on the second. Your credit card number is far more likely to walk out the door with a crack-addicted waiter who ran it through a skimmer last Tuesday than with someone who paid forty dollars for your Dell Optiplex at a thrift store and spent a weekend running recovery software on the off chance. But "destroy it anyway, just in case" has been a good business since at least 1996 — first for glass, now for data — and good businesses don't correct their own founding myths.

Which brings me back to the actual thesis, because this isn't the first time this play has been run, and it wasn't invented for the dark web. It was invented — or at least perfected — for HIPAA.

After your hard drive is shredded to little pieces, how do you verify the serial number? Was that 50 hard drives in the shredded pile?  Or was is 49? My industry is increasingly charging you fees to keep that old hard drive info off of the "Dark Web", and we charge $5-15 for a "certificate" for each drive destroyed.  And we have rules on HOW we are allowed to destroy it.

FEAR OF RISK FOR SALE.  Multiple auditors have pointed to our company's pile of hand-disassembled hard drives, the older ones with neodymium magnets, which we take apart by hand... taking them apart by hand recovers valuable gold-bearing circuit boards, platinum platters, and the magnets and aluminum husks, and creates a safe job for differently abled staff we employ from the Counseling Service.  And the serial numbers can be accounted for, still printed on the aluminum backings (unlike a shredded drive). But this "method" wasn't listed by NAID or R2 or whoever, whose standards were transcribed by Blanko or Kobra or Iron Mountain. Multiple auditors point to the platters pictured below, saying that maybe someone will find all the parts and re-assemble these to find out if they were wiped, and sell the data on the Dark Web.



My ITAD industry is hooked on story. Really hooked. It has a monkey on its back, and they won't like this blog. No one is gathering the platters in the photo below to re-construct a hard drive, to see if it was not already wiped, to find current data, about your health information, to sell it to the insurance industry on the dark web. Zero. Big Zero. But every single auditor screams that it's their job to prevent it.

Prevent these "data bearing" disks from being re-assembled to steal your data?  This is like pumping my stomach to put oysters back in their shells and release them back into the wild. I'd need a really heavy dose of something to believe that's a risk.



Hard drive magnets, for sale to the dark web thieves who rebuild obsolete hard drives.

The Spiraling Economy: Double Regulations of A Circular Economy

Here is the recycler's recurring nightmare...
"We'd love to keep using 1,000 tons per day of your recycled material instead of mining and extracting it from forests and mountains. But EPA says we'd need a Waste Facility Perimit in addition to our clean air and water permits.  If we mine from the mountain, we just need 2 permits, not 3"
No good deed goes unpunished. Regulators of city waste insist on tracking processed recyclables in the industrial mineral market, even when they compete as "furnace ready" feedstocks with materials mined from mountainsides.



The best hard rock mining is worse than the worst recycling. And this week, the Wall Street Journal's reporters Mackenzie Knowles-Coursin and Joe Parkinson show us what some of the worst (gold) mining looks like.

CRT Glass Resolution: An "Own Goal" In Slow-Mo

The path of least resistance is to trust our environmental regulators, trust the watchdogs, and assume that profit-driven industry is the villain, the fox in the henhouse.

The path of least resistance is to assume that people questioning environmental enforcement are "apologists" who care less about environmental pollution than the enforcement proponents.

Sometimes those assumptions are 100% right.  I'm not a carbon climate causality denier, and I'm proud of my 9 years of service as a Massachusetts recycling regulator.


But as a former regulator, I can attest regulators are not always right.  Regulatory agency lawyers tend to be more risk-averse than private sector attorneys, for example.  Regulators understandably want to hold themselves to "the highest environmental standard".  But when there is doubt and uncertainty - an engineering problem for example - the regulator can become obfuscated and defend his own reputation.  That is to say, when in doubt, the regulator has to act - in doubt.  And saying "yes" or "no" sometimes boils down to the regulator's own insecurities.

And these lead to unintended consequences.  #OwnGoal

Let me again state that what the agencies do, for the most part, is great.  I'm suggesting an environmental police chief should look at community concerns the way any police chief looks at protest.  You can stonewall and deny mistakes, claim 100% effectiveness in your policy.  Or you can learn from a mistake and adjust your policy.

All Will Be Revealed in Vermont, Postscript on ACA Tea Party

I'm in a tempest in Vermont, very high stakes.  But information is coming out of Montpelier so slowly that it would be a mistake to come to conclusions too early.   Until 10 days ago I thought my company had been underbid... we waited though to see the contract.   Our bid was lower and our qualification score higher.

In court tomorrow.

But my mind is still idling, so let me say a couple of things about ACA, the Affordable Care Act, monikered "Obamacare".
"Half of the population spends little or nothing on health care, while 5 percent of the population spends almost half of the total amount.2 In 2002, the 5 percent of the U.S. community (civilian noninstitutionalized) population that spent the most on health care accounted for 49 percent of overall U.S. health care spending (Chart 1, 40 KB). Among this group, annual medical expenses (exclusive of health insurance premiums) equaled or exceeded $11,487 per person."  Mark W. Stanton, M.A. www.ahrq.gov
In other words, the USA already ate 90% of the public health care apple with Medicare and Medicaid.  The ACA will neither do much for the young (a small percentage of whom need care) nor for costs (we keep doing major intervention on elderly).  Public health care works in Europe because the average person there realizes something most Americans haven't come to grips with.  We are all gonna die some day.   I have had to watch 3 of my 4 grandparents basically be tortured to death with extended care.