Privacy International has released its 2007 International Privacy Rankings. Sadly, the United States ranks last in terms of statutory protections and privacy enforcement of all the countries in the democratic world. Among the points noted about U.S. privacy protection were that state data breach notification laws had proven useful in identifying security faults, but that Congress had approved presidential spying program, and is considering retroactive immunity for telecoms (something I wrote about here, and will almost certainly write more on in the future). One thing I'd like to point out in this is that the problems the report identified (e.g., presidential spying) are coming from the Federal Government, while the bright spots in privacy protection (e.g., data breach notification laws) are implemented at the state level. To my mind, this provides further evidence that we should be cautious in pushing for a federal data breach notification laws, given that they could preempt the state laws which are already in place and have proven to be effective.
(via BoingBoing)
Monday, December 31, 2007
Thursday, December 27, 2007
2008 Budgets Beefed Up for Data Security Expenses
One item that is not getting short shrift in the community bankers' 2008 budgets is expenses for protecting consumer data. While controlling costs has consistently been a top priority for these financial institutions, many report being fearful of an unauthorized infiltration of their bank databases, and are investing security related technology. In an article in the December 21, 2007 American Banker, bankers report that criminals are constantly searching for a weakness in banks' firewalls, and that they must continually monitor such attempts to be certain they have addressed any vulnerabilities. These banks now appear to be keenly aware of the damage to their reputation that could result from a data security breach, particularly where it could be shown that they did not take sufficient preventive steps to stave off an attack. This reputation risk, combined with increased attention being paid to banks' risk management policies and procedures by banking regulators, has caused banks to increase their budgets on fraud detection technology for the coming year. Reports of banks who were unprepared when a hacker "intrusion" occurred, and the resulting financial resources required to address the aftermath, have been a "wakeup call" for many banks. It has been this writer's frustration over the past several years that risk of data security breach has not been taken seriously enough. In the end, however, it appears that it was the plight of these victims of security breaches that finally convinced financial institutions that being penny wise and pound foolish should not be their motto when it comes to securing customer data.
Wednesday, December 19, 2007
Congress Ignores Individual Privacy
"Wider Spying Fuels Aid Plan for Telecom Industry" - that's the headline of this article from the New York Times (via CNET). In a sane world, that type of headline would be appropriate for an article describing legislation designed to help telecoms fight hackers who are spying on their networks, or avoid industrial espionage by unscrupulous rivals. In this world though, the headline is about a plan to grant telecoms retroactive immunity from lawsuits for spying on American citizens. Previously, it had been thought that telecoms had helped the Bush administration spy on American citizens as part of the government's counterterrorism operations - activities that have led to lawsuits being filed (see here for more info). The telecoms, understandably worried about losing in court, lobbied for a bill granting them retroactive immunity from suit. Thanks to some political controversies that I'm not going to get into (though you can get details here), the retroactive immunity bill hasn't gone through - which led to the article about wider spying fueling aid plans for telecoms. Apparently, telecoms weren't just providing information in terrorism investigations, they were providing information on everything. In other words, they were engaging in "wider spying." If I were a senator, I would react with outrage. After all, spying isn't a positive good that should be encouraged. However, I'm not a senator, and the senators we do have apparently feel that wider spying is something to be encouraged, and therefore the wider spying, instead of sinking the telecoms' bid for retroactive immunity, actually aided it, the fact that "wider spying" basically means that individual privacy is routinely violated apparently meaning nothing to our elected representatives. A dark day for people who care about privacy.
PostScript: Happily for supporters of rule of law, the retroactive immunity bill hasn't gone through (again, thanks to the political controversies describes here).
PostScript: Happily for supporters of rule of law, the retroactive immunity bill hasn't gone through (again, thanks to the political controversies describes here).
Are Security Breaches the Cause of Identity Theft?
Frequent news reports in 2007 of data security breaches have heightened the public's and business' concern over the risk of identity theft. The FTC estimates that 9 million Americans will have their identity stolen this year, so there is clearly cause for concern. But in what percentage of these reported incidents does an identity thief actually make use of the information that has been compromised? What if the thief was actually a member of the clan?
Most of the breach incidents reported concern lost or stolen laptops containing sensitive personal information, unencrypted backup data tapes, careless document disposal and destruction, and inadequate security procedures related to database and document protection. In fact, most of these breaches have not resulted in identity theft, as reported in recent testimony by the FTC. The greater risk of identity theft, says the FTC, arises in the case of deliberate criminal action, such as insiders who take a bribe to reveal sensitive personal information or to use it themselves. Companies would be well-advised to focus their attention on their internal security processes by restricting access to personal information of their customers, clients and employees, and adopting other measures to prevent insider abuse. According to some reports, one in three cases of identity theft are the work of employee insiders who have taken workplace records, in most cases of a customer or client.
Certain industries are more vulnerable to identity theft than others. The retail industry holds the highest number of incidents of employee theft, where by some estimates nearly 60% of workers steal personal information to commit identity theft. The financial services industry is second, with 22%. The reason for the difference between the two industries is likely due to the safeguards that are mandated by the Gramm-Leach-Bliley Act and government regulations.
Most of the thieves who have been apprehended did not have a prior criminal history, so that background checks would not provide a solution. The FTC recommends that companies take five security measures to help protect information from insider theft:
1) Take stock of what personal information is in company files and track where it goes within the company
2) Reduce wherever possible the personal data of customers and employees that is stored
3) Protect the information kept by the company by both physical and technological controls
4) Dispose of unneeded information using appropriate means
5) Plan ahead for responding to security incidents, closing off threats to personal information, and evaluating whom to notify in case of an incident.
FTC Guidance
Most of the breach incidents reported concern lost or stolen laptops containing sensitive personal information, unencrypted backup data tapes, careless document disposal and destruction, and inadequate security procedures related to database and document protection. In fact, most of these breaches have not resulted in identity theft, as reported in recent testimony by the FTC. The greater risk of identity theft, says the FTC, arises in the case of deliberate criminal action, such as insiders who take a bribe to reveal sensitive personal information or to use it themselves. Companies would be well-advised to focus their attention on their internal security processes by restricting access to personal information of their customers, clients and employees, and adopting other measures to prevent insider abuse. According to some reports, one in three cases of identity theft are the work of employee insiders who have taken workplace records, in most cases of a customer or client.
Certain industries are more vulnerable to identity theft than others. The retail industry holds the highest number of incidents of employee theft, where by some estimates nearly 60% of workers steal personal information to commit identity theft. The financial services industry is second, with 22%. The reason for the difference between the two industries is likely due to the safeguards that are mandated by the Gramm-Leach-Bliley Act and government regulations.
Most of the thieves who have been apprehended did not have a prior criminal history, so that background checks would not provide a solution. The FTC recommends that companies take five security measures to help protect information from insider theft:
1) Take stock of what personal information is in company files and track where it goes within the company
2) Reduce wherever possible the personal data of customers and employees that is stored
3) Protect the information kept by the company by both physical and technological controls
4) Dispose of unneeded information using appropriate means
5) Plan ahead for responding to security incidents, closing off threats to personal information, and evaluating whom to notify in case of an incident.
FTC Guidance
Tuesday, December 18, 2007
New North Carolina Privacy Protection Law
North Carolina has a new law protecting individual privacy. The law adds to North Carolina's existing identity theft protection act by making it a violation of the act for any person to
So what's behind these consumer friendly features of the North Carolina law? I think there are two forces at work. The first is an individual named Glenn Hagele (web site here), who lobbied for this specific law to help address a specific fact pattern - where an individual's personal information was made available on the Internet as a reprisal for that individual's public statements. Without Glenn's work on the law, there is simply no reason to think it would exist. The second force I see is more systemic. Identity theft is still a significant concern for consumers (e.g., this article from the AARP describing identity theft concerns of older Americans) and with a seemingly endless stream of high profile incidents taking place, legislators are probably feeling pressure to do something about it. While data breach notification acts revealed that there is a problem with personal information being revealed, the repeated failures of consumers in court have shown that current law doesn't really give individuals the tools they need to protect themselves. Laws like that in North Carolina, which explicitly give consumers a right to sue for statutory damages, could be a step that more legislatures will take in the future to remedy that situation.
knowingly broadcast or publish to the public on radio, television, cable television, in a writing of any kind, or on the Internet, the personal information of another with actual knowledge that the person whose personal information is disclosed has previously objected to any such disclosure.Looking at its text, the North Carolina law seems to have been written to actually be enforced by aggrieved individuals. Indeed, the North Carolina law explicitly states that it can be enforced by individuals, rather than limiting the right to bring suit under the law to the state attorney general. Also, the North Carolina law includes a statutory damages provision, which addresses difficulties that individuals have had showing actual damage in previous data exposure cases. See, e.g., here and here.
So what's behind these consumer friendly features of the North Carolina law? I think there are two forces at work. The first is an individual named Glenn Hagele (web site here), who lobbied for this specific law to help address a specific fact pattern - where an individual's personal information was made available on the Internet as a reprisal for that individual's public statements. Without Glenn's work on the law, there is simply no reason to think it would exist. The second force I see is more systemic. Identity theft is still a significant concern for consumers (e.g., this article from the AARP describing identity theft concerns of older Americans) and with a seemingly endless stream of high profile incidents taking place, legislators are probably feeling pressure to do something about it. While data breach notification acts revealed that there is a problem with personal information being revealed, the repeated failures of consumers in court have shown that current law doesn't really give individuals the tools they need to protect themselves. Laws like that in North Carolina, which explicitly give consumers a right to sue for statutory damages, could be a step that more legislatures will take in the future to remedy that situation.
Labels:
North Carolina,
state enforcement,
state legislation
Thursday, December 13, 2007
Privacy Red Tape
One argument I often hear (and not just in the privacy context) is that regulation is just red tape - it imposes costs on businesses, it doesn't achieve it's stated goals, and we'd be better off without it. However, a new study of Chief Security Officers from the University of California-Berkeley School of Law indicates that (at least on the context of security breach notification laws), that argument is simply wrong. Among the study's other findings:
In any case, probably not a big surprise to those of us who are already concerned about privacy, but something to keep in mind if confronted with arguments that privacy regulation won't help consumers in any case.
Via Schneier on Security.
Breach notification laws have significantly contributed to heightened awareness of the importance of information security throughout all levels of a business organization and to development of a level of cooperation among different departments within an organization that resulted from the need to monitor data access for the purposes of detecting, investigating, and reporting breaches. CSOs reported that breach notification duties empowered them to implement new access controls, auditing measures, and encryption. Aside from the organization's own efforts at complying with notification laws, reports of breaches at other organizations help information officers maintain that sense of awareness.
In any case, probably not a big surprise to those of us who are already concerned about privacy, but something to keep in mind if confronted with arguments that privacy regulation won't help consumers in any case.
Via Schneier on Security.
Wednesday, December 12, 2007
Data Breach Notification Prioritized over Identity Theft Restitution
According to this article from SC Magazine the House Judiciary Committee is likely to give precedence to a bill making it a federal crime to fail to notify law enforcement in the event of a major security breach. The alternative proposal, which is not expected to be voted on before the end of the year, would have made it easier for victims of identity theft to recover compensation and also would have facilitated prosecution of individuals deploying botnets. Based on my understanding of the legislation, I'm not sure that either bill would have any real effect. State data breach notification statutes already have the effect of forcing businesses to disclose when a security breach takes place, so I'm not sure what would be accomplished by having a separate federal law which requires only notification of law enforcement. Regarding the bill which would help victims of identity theft recover compensation, victims of identity theft can get compensation now (or more than compensation, as described here) - assuming they can find the thief. The reason people end up having to eat costs of identity theft isn't because the law won't help them, it's because they can't find the perpetrator. Similarly, when it comes to prosecuting individuals who maintain botnets, I don't see the problem as being one with existing law. Instead, finding people controlling botnets can be difficult, end even if they are found, there is no guarantee they will be within the reach of U.S. courts.
With that having been said, I think the mere existence of these bills is a positive step. The federal government is way behind the states when it comes to protecting privacy, and privacy protection is something that (ideally) should be approached in a manner that isn't limited by state borders.
With that having been said, I think the mere existence of these bills is a positive step. The federal government is way behind the states when it comes to protecting privacy, and privacy protection is something that (ideally) should be approached in a manner that isn't limited by state borders.
Subscribe to:
Posts (Atom)