LINDDUN隐私威胁类型-Identifying 标识(4)
本文继续讨论 Identifying 标识威胁类型,I.2 - I.2.2
Identifying 标识
见前文
I.2 Identifiable information 可标识信息
见前文
I.2.2 Revealing attributes 启发性属性
A number of revealing attributes are included in the data which support the identification of the data subject. A set of different attributes relating to an individual may be provided to the system. While those attributes may individually appear harmless, combining them could be more revealing and lead to the identification of the data subject.
数据中包含一些有助于识别数据主体的启发性(揭示性)属性。系统可能会收到一组与个人有关的不同属性。虽然这些属性单独看似无害,但将它们组合在一起可能会更有启示性,并导致对数据主体的识别。
Criteria 辨识要素
-
User provided inputs
用户提供的输入- Is there free-form user provided data that is received or processed by the system?
系统是否接收或处理由用户提供的自由格式(free-form)的数据?
- Is there free-form user provided data that is received or processed by the system?
-
Revealing data
启发性数据- Is data collected that may reveal the identifying information?
收集的数据是否能揭示身份信息?
- Is data collected that may reveal the identifying information?
Examples 示例
-
Feedback form
反馈表- In a feedback form that receives free text input, the data and particular details in that data could be sufficient to reveal the identity of the individual providing the feedback. 在接收自由文本输入的反馈表单中,数据和数据中的特定细节可能足以暴露提供反馈的个人的身份。
- For example, when a person shares sufficiently detailed data (e.g., location, employer, device type, ...) in a feedback form, the provided data may be sufficiently revealing to be able to uniquely identify that person.
例如,当一个人在反馈表中分享足够详细的数据(例如位置、雇主、设备类型,...),所提供的数据可能足以揭示能够唯一标识该个人的信息。 - For example, if the feedback concerns functionality that was only released to a small set of beta-testers in different application domains, the combination of that functionality, together with a particular use case in which the individual is experiencing a problem, could be sufficient to identify that user.
又如,反馈信息涉及的功能只发布给不同应用程序领域中的一小组测试人员,那么该功能的组合以及个人遇到问题的特定用例就足以标识该用户。
Impact 影响
-
Accidentally revealing identity
意外揭示身份- Providing revealing attributes in user-submitted data may unintentionally lead to the identification of the individual.
在用户提交的数据中提供启发性(揭示性)属性可能会无意中导致个人身份被标识。
- Providing revealing attributes in user-submitted data may unintentionally lead to the identification of the individual.
Additional information 额外信息
-
Data subject
数据主体- The data subject does not necessarily need to be the one providing the data.
数据主体不一定是提供数据的那个人。
- The data subject does not necessarily need to be the one providing the data.
共有 0 条评论