Sunday, March 15, 2009

PCI and the Efficacy of Self Regulation

Tucked away in the conclusion of this article is an interesting question: is the PCI Data Security Standard effective? Actually, the question as posed, which was whether the PCI Data Security Standard in its current form is effective, is not particularly interesting (at least to me). The more interesting question is whether the PCI DSS, or any self regulation can be an effective counter to information security threats. I don't know the answer, but the article gives some indication that that answer might be no.

Of course, the article itself did not tackle the question of self regulation versus governmental oversight. The article was devoted to describing a new set of guidelines which is intended to facilitate the process of becoming PCI compliant. Apparently, there is a perception that some businesses look at the PCI requirements, become overwhelmed by what's necessary to comply, and, as a result, do nothing. The hope is that, by breaking things down and ranking them in terms of priority, the new guidelines will make the task more manageable, and therefore increase compliance. The article then mentioned that these new efforts to increase compliance come at a time when the effectiveness of the PCI DSS is being questioned based on recent security breaches such as that at Heartland Payment Systems. The article mentioned that a spokesman from the PCI Security Standards council had said that there wasn't anything wrong with the standards. However, if that's true, it raises a bigger question - why are the breaches still happening?

One possible answer, the one I alluded to at the beginning of the post, is that breaches are still happening because self regulation isn't an effective means of influencing behavior. I think that position is probably too extreme - merchants do care about the PCI DSS. However, the fact that there is a perceived need for the current compliance campaign, and the fact that massive breaches like that at Heartland keep happening indicates that something needs to change. Maybe what that is is to add a dose of federal government enforcement power to the supposedly sufficient requirements of the PCI DSS.

Tuesday, March 10, 2009

What I wouldn't give for some time...

Actually, I know very well what I wouldn't give up for some time. I wouldn't give up my productivity at work, or my relaxing evenings with my wife. However, if I would give those things up, I could write a great blog post on proposed changes to California's security breach notification act. Instead, I'll just mention this article from Computer World, and quickly note that the proposed changes require businesses that suffer breaches to report them to a centralized authority, not just to the people whose data is compromised.

Of course, if I were writing a really good blog, post, I wouldn't just talk about the proposed changes, but instead I'd try and put them in broader context, perhaps by referring to this post from the Threat Level blog, which describes a panel discussion on whether notification laws "work". I might even have some analysis on the proper way to measure the efficacy of notification laws.

As it is though, I'm not writing that blog post, I'm writing this relatively uncreative excuse for a blog post. Oh well. On the bright side, I'm still a good lawyer by day, and I've had a nice evening with my wife.

Sunday, March 1, 2009

Facebook Content Policy

Last month, there was something of a controversy regarding the terms of service for the popular social networking site Facebook. The issue (described in this article) was that Facebook removed a statement from its terms of service that said it couldn't claim rights in original content uploaded by users after they terminated their accounts, and replaced it with a statement saying that Facebook might maintain archived copies of user content. From my perspective, this would not have seemed like a significant event. I assume that everything (including this web site) I put online is archived somewhere, whether its at the site that's hosting the content (e.g., Facebook), some external site (e.g., the internet archive), or the local computers of whoever happens to have looked at whatever I posted (e.g., blog readers). My guess is that the lawyers who recommended that Facebook make the change thought that most Facebook users were about like me, and wouldn't see the modification of the policy as a significant change.

They were wrong.

Facebook's users were outraged. They started a Facebook group (!) to protest, and it quickly signed up 88,000 members. The Electronic Privacy Information Center prepared an FTC complaint. As one user rhetorically asked: "Will I wind up seeing pictures of my niece staring at me from a bus stop at some point and be told I shoulda read the fine print?" (quote via this article).

Anyway, because of the outrage, Facebook backed down, and is now asking users to help define its policies (article here). On one hand, it's a demonstration that consumer pressure actually can have beneficial effects. On the other hand, it's a demonstration that privacy concerns crop up over the most bizarre things. For example, if someone really wants to have their niece's picture taken out of an advertisement, they can sue Facebook for making an unauthorized public display and get an injunction.* Additionally, there have been several cases where people have sued for common law torts such as libel, or false light invasion of privacy for using pictures in advertisements without the subjects' consent (e.g., Virgin, which was sued for using a picture uploaded to Flickr with the tag line "virgin to virgin" - article here). In short, the fears that led to the revolt against Facebook are one of the areas where the law does offer redress for unauthorized use of personal data. Strange that people got outraged over that, rather than something where the law offers little or no protection.

*Copyright protection subsists in any work fixed in a tangible medium of expression. 17 USC 102. That includes computer memory, which means that everything uploaded to Facebook is automatically protected by copyright.**

**Yes, there is a requirement for registration, but you can register after infringement has taken place. 17 USC 408 et seq. While there are significant advantages to registering before an infringement occurs, a discussion of those advantages is way outside the scope of this post.

Sunday, February 22, 2009

A Quick Reminder: If you want legal advice, get a lawyer

As it says in the disclaimer at the bottom of the page (which you should definitely read): "This site is provided for informational purposes only...This site should not be used as a substitute for competent legal advice from a licensed professional attorney in your state."

Data privacy and information security is governed by a patchwork of state laws, and there is massive variation from jurisdiction to jurisdiction. For example, my home state, Ohio, has a data security notification law (ORC 1349.19). However, if I drive 10 minutes south from my office, I'm in Kentucky, which doesn't have an equivalent law (a handy table of what states do and do not have such laws can be found here). Tort remedies, such as trespass to chattels, breach of contract, negligence and intentional infliction of emotional distress (to name 4) are also governed by state law.

This web site does discuss the law surrounding information security and data privacy. However, anyone who has a question about their own information security or data privacy situation should get a lawyer who can apply the law as it exists in their jurisdiction to the facts as it exists in their case - not rely on a web site (this one, or any other).

Monday, February 16, 2009

Massachusetts Extends Compliance with Data Security Rules

We've written previously (e.g., here) about Massachusetts' new data security rules. Briefly, they would have required anyone who owns, stores or maintains the personal data about a resident of Massachusetts who stores data electronically to encrypt the data before transmitting it wirelessly or over a public network. The rules would also have required encryption of data stored on mobile devices. I say "would have" because because their implementation deadline, which had been previously set at May 1, 2009 has been extended till January 1, 2010 (see article here).

Of course, this isn't a big surprise, since regulations having to do with privacy (both strengthening, like the red flag rules and weakening, like Real ID) have a history of getting delayed.

Tuesday, February 10, 2009

Even More Limitations on Private Rights of Action

Previously, I've written about problems with protecting privacy through private civil suits, such as transaction costs, difficulty of proving damages, and a generally hostile court system. However, a recent breach notification by Geeks.com as indicated that even when those factors aren't present, people (or, in this case, businesses) still aren't that interested in enforcing their rights. The story, according to this article from Computer World is that the web site was victimized by an SQL injection attack, and the operators eventually entered into a settlement with the FTC wherein they agreed to undergo audits and not to make any further misleading claims about privacy. So far not particularly notable. However, as the article says, unlike most security breaches:

The breach was notable because the Geeks.com site prominently displayed a "Hacker Safe" seal provided to companies by McAfee Inc. as part of its ScanAlert vulnerability scanning service. However, McAfee officials said at the time that the Hacker Safe certification — since renamed McAfee Secure — had been withdrawn from Geeks.com on multiple occasions during 2007 after scans found vulnerabilities in its systems.

To me this is shocking. Not because a supposedly secure site was compromised, but because they were improperly displaying the "Hacker Safe" seal.

Where was McAfee?

Didn't it care about its good name? I would guess that Geeks.com would have taken down the "Hacker Safe" seal if McAfee simply asked them to. I doubt even a sternly worded letter would have been necessary. Still, if it had been, there are any number of attorneys who could have written it, and who would have been happy to go to court to get the seal removed if Geeks.com wouldn't take it down otherwise. Happily, the FTC stepped up in this case. However, it's a little surprising that they were the ones who ended up doing it, rather than the private actor who one would think would have had both the incentive and opportunity to have taken action earlier.

Sunday, February 1, 2009

A view from the dark side

Via Bruce Schneier, we have a fascinating interview with an adware author. From a technical perspective, it's fascinating - he gives a programmer's eye view of the various mechanisms he used to make sure his adware couldn't be uninstalled or stopped. From a privacy standpoint it's disturbing. When asked the question of whether people had any security or privacy at all, his answer was (essentially) no, but it doesn't matter because most people aren't criminals so you're probably ok.

From a legal standpoint, it had two interesting takeaways. First: End User License Agreements are trouble. The interviewee's opinion was that people don't read EULAs, so you can put anything in them, including agreements by the user that the adware company can install whatever software they want on the user's computer. In the coming years, I would expect to see some limits placed on this (e.g., by the FTC under its authority to police unfair or deceptive trade practices). Second, the legal system can work to curb bad practices, but only once the bad practices are known. The company the interviewee worked for, Direct Revenue, was sued by Elliot Spitzer. The problem is, the suit only happened after the company made the poor business decision to start branding their adware. If they hadn't done that, it's anyone's guess as to whether they even would have shown up on the (now disgraced) attorney general's radar screen.

Also, one final takeaway from the interview: if you want to reduce your susceptibility to adware (or various forms of viruses or other malware) switch off Microsoft products. The interviewee was openly contemptuous of Microsoft products. The money quote: "If you’re using IE [Internet Explorer], then either you don’t care or you don’t know about all the vulnerabilities that IE has." I'm not sure I agree with him, but it's interesting to see how an insider views the world at large.