Showing posts with label identify theft. Show all posts
Showing posts with label identify theft. Show all posts

Thursday, March 20, 2008

The Problem of Compensation

In my last post, I addressed what is a proper measure of damages for exposure of a person's private information. In response, the Dunning Letter put up a post responding to it, and providing some interesting statistics about the cost ($5720/victim) and prevalence (top complaint reported by FTC ID theft and consumer fraud survey) of identity theft. At that time, I considered preparing a responsive post, essentially playing devil's advocate and pointing out that providing compensation via lawsuits was really a poor way to combat the problem of information exposure, because, even if you could get the proper measure of damages, most people wouldn't take the trouble to file a lawsuit. Further, even if people did file lawsuits, the transaction costs associated with litigation (i.e., attorneys' fees) mean that, even if you did provide incentives to avoid data exposure, there would be a ton of lost effort involved.
However, this post brings the problem into even sharper focus, by describing the situation of a young woman who states the she reported an identity theft, which took between 20 minutes to an hour, and that she got NOTHING in return. If doesn't think it's worth an hour of her time to report an ID theft (and she's undoubtedly not alone in that), then you can bet there will be very few consumers who would be willing to spend the time (years) and money (thousands of dollars) which are necessary to go to court. The bottom line: while providing compensation is worthwhile, it isn't enough.
So what is enough? My proposal is regulation, clearly written and consistently enforced. Part of the problem is that businesses simply don't know what they need to do to avoid having security breaches. Also, businesses know that, even if there is a breach, there isn't much chance that individual plaintiffs will be able to successfully bring suit for damages. Clear regulation which is consistently enforced could solve those problems, both by providing clear guidance for businesses, and by providing a strong incentive (threat of government penalties) for following that standard. At the moment though, the U.S. model seems to be notification followed by individual litigation, which is, as set forth above, a highly suboptimal solution.

Thursday, August 23, 2007

PCI DSS Compliance Makes Slow Progress

The challenges that faced by merchants in their efforts to comply with the Payment Card Industry (PCI) Data Security Standards (DSS) have received a great deal of publicity, especially since Visa U.S.A. had announced its intent to levy penalize noncompliant merchants beginning in October, 2007. see here However, recently Visa has backed off of its aggressive stance, and announced that instead of denying merchants the right to participate in its tiered fee structure, it will simply downgrade noncompliant merchants one tier, and require them to pay higher fees. This softened approach was announced in a memo issued by VISA and Fifth Third Processing Solutions earlier this month. Practicality vs. SecurityThey also announced that merchants who are in compliance by September 30, 2008 may be eligible for lost interchange discounts and other incentives. While the Payment Card Industry is to be lauded for its efforts to increase security and reduce the potential for identity theft and credit card fraud, the draconian measures it attempted to use in order to speed up the DSS compliance process did not recognize the difficulties and costs encountered by merchants in attempting to comply with the 140 requirements for protecting credit card data. Not only are the smaller retailers encountering challenges and obstacles to compliance, but recent estimate indicate that more than half of Visa's top tier merchants have not yet achieved full compliance. Visa and MasterCard must find a way to keep the pressure on, but not such a pace as to hurt retailers financially.

Thursday, July 12, 2007

Pressure on CEOs for Information Security

According to this article in ComputerWorld, the Information Commissioner in the UK is blaming CEOs for data security breaches. "How", he asks, "can laptops holding details of customer accounts be used away from the office without strong encryption? How can millions of store card transactions fall into the wrong hands?" Of course, there are any number of ways that "millions of store card transactions" can fall into the wrong hands even if a business does have an effective information security policy in place (e.g., they can be stolen by an employee, such as described here). Also, how productive it would be to make CEO's responsible for information security is anyone's guess, as most CEOs aren't (and aren't expected to be) knowledgeable enough about information security to contribute effectively to the conception or implementation of an information security policy. Whether the commissioner's comments are a harbinger of regulations targeting CEOs, or whether they are simply another statement of outrage from a government official about identify theft is another open question. However, whether followed by regulation or not, there is no reason to believe that targeting CEOs will positively contribute to reducing identify theft or incidence of data security breaches.

Sunday, February 4, 2007

Wired.com currently has a very interesting series of articles up on the world or criminal carders (individuals who steal, sell, and use credit card and identify information of others). Largely, the articles are interesting because they provide a fascinating look into a world that most law abiding citizens don't even know exists. However, they also provide some helpful advice for businesses seeking to reduce their vulnerability (e.g., when information is changed on an on-line account, have a substantial waiting period before the assets in the account can be withdrawn).

Bottom line: an interesting read for anyone who uses or issues credit cards.