Substantiating trust

BY J. CARLTON COLLINS, CPA

Q: When introduced to new privacy solutions (such as DuckDuckGo or Disconnect), what assurances do we have that these solutions aren’t themselves stealthily tracking our computing or internet activities?

A: Before trusting a lesser-known privacy solution, at a minimum make sure that it meets the following criteria:

  1. The company makes definitive public statements confirming it will not collect your data (which could subject it to lawsuits if it does).
  2. The company undergoes annual or periodic security audits by reputable auditors, and those findings are made public.
  3. The company is endorsed by well-known, high-profile companies that have a vested interest in protecting their reputations.

J. Carlton Collins ( carlton@asaresearch.com ) is a technology consultant, CPE instructor, and a JofA contributing editor.

Note: Instructions for Microsoft Office in “Technology Q&A” refer to the 2013, 2010, and 2007 versions, unless otherwise specified.

Submit a question
Do you have technology questions for this column? Or, after reading an answer, do you have a better solution? Send them to jofatech@aicpa.org. We regret being unable to individually answer all submitted questions.

SPONSORED REPORT

Why cybercriminals are targeting CPAs

This free report expands on the most commonly found scams, why education and specialized IT knowledge help to lessen security vulnerabilities, and why every firm should plan carefully for how it would respond to a breach.

PODCAST

How tax reform — and Excel — are changing the CPA Exam

Mike Decker, the vice president of examinations at the AICPA, discusses changes being made to the exam as a result of tax reform — and about how Excel will now be available for use on the test.