<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1913143473082500114.post8787303193425649136..comments</id><updated>2008-06-23T15:34:21.567-07:00</updated><title type='text'>Comments on Ephemerallaw: Measuring the Effect of Security Breach Notificati...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ephemerallaw.blogspot.com/feeds/8787303193425649136/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1913143473082500114/8787303193425649136/comments/default'/><link rel='alternate' type='text/html' href='http://ephemerallaw.blogspot.com/2008/06/measuring-effect-of-security-breach.html'/><author><name>William Morriss</name><uri>http://www.blogger.com/profile/09679044599000737422</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1913143473082500114.post-7976169218649109031</id><published>2008-06-23T15:34:00.000-07:00</published><updated>2008-06-23T15:34:00.000-07:00</updated><title type='text'>I am also curious as to the scope fo these notific...</title><content type='html'>I am also curious as to the scope fo these notification laws. As in California (sb1386), the majority of them are limited to unencrypted data held on computers. The Massachusetts law seems to be much broader and includes hard copy data. From what I have seen "investigative" language in most instances allow the company to delay notification almost indefinitely if an investigation is ongoing to find the source of the breach. It seems to me that these are largely toothless laws if the thrust is to notify potential victims in a timely manner so they can be on guard to protect themselves.&lt;BR/&gt;&lt;BR/&gt;As gratelful as I am that these laws exist I can't help but to be frustrated by the shortsightedness regarding identity theft. Ideally we should have laws that are designed to protect the individual victim while at the same time provide for a penalty to the company for not acting in a timely fashion when a breach or loss occurs. Like anything it is sad to say that business will not take this seriously until the 800 pound gorilla sits on them first.&lt;BR/&gt;Just a thought,&lt;BR/&gt;John</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1913143473082500114/8787303193425649136/comments/default/7976169218649109031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1913143473082500114/8787303193425649136/comments/default/7976169218649109031'/><link rel='alternate' type='text/html' href='http://ephemerallaw.blogspot.com/2008/06/measuring-effect-of-security-breach.html?showComment=1214260440000#c7976169218649109031' title=''/><author><name>John Taylor</name><uri>http://www.blogger.com/profile/15220821369172645158</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://ephemerallaw.blogspot.com/2008/06/measuring-effect-of-security-breach.html' ref='tag:blogger.com,1999:blog-1913143473082500114.post-8787303193425649136' source='http://www.blogger.com/feeds/1913143473082500114/posts/default/8787303193425649136' type='text/html'/></entry></feed>