Imagine Monster put a click-through license on the malware, adjusted the privacy policy a tad (include an opt-out for additional "services"), and voila! It's not a privacy breach, it's an additional revenue stream! The 1.6M bits of Monster job hunter data is at least as hot as the Glengarry leads.
Imagine that Certegy/Fidelity records were not sent in wild cascading romp through the land of data brokery by the actions of a rogue database administrator, but through a perfectly legal contract. (As Mr. Certegy assures us, the data was sold to legitimate data brokers.) So the whole thing is a just a crossed "T" or dotted "I" away from being 110% on the up and up. Instead of class action, we'd be talking steak knives and Eldorados!
It's just semantics. "Data broker" = "Identity Thief." "Lead Generation" with "Privacy Breach."
It's all the same. But the Yukon keeps me up all night, and it feels like it's almost crime.
Monday, August 20, 2007
I Feel That It's Almost Crime
Posted by
Dutcher Stiles
at
4:14 PM
0
comments
Labels: breach notification, consumer, disclosure laws, identity theft, privacy, singalong
Wednesday, April 4, 2007
One Man's Trash
The righteous fury of Texas Attorney Abbott was last month stymied by an elite cadre of county clerk ninjas who conjured a shambling legislative behemoth to crush his valiant effort to protect the privacy of Texans.
Abbott screwed his courage to the sticking place, and was not to be denied.
Laying down the latex gauntlet, and taking a dog-eared chapter from a 1987 hacker's playbook, he strikes a meaty vein of SSN laden paydirt in the dumpsters of Radio Shack, a beauty school and a talent agency.
Having done of bit of professional dumpster diving myself, I laud the AG's efforts. Nothing increases a man's disposal awareness more than seeing a dude in a suit digging through garbage.
No doubt the most disturbing part of the story is the sample recovered receipt displayed on the AG's website. I mean, $99.97 for a 2 GB portable drive? With $17.99 for a 12 month warranty? Now that's obscene.
Illustration courtesy Speas.
Posted by
Dutcher Stiles
at
5:00 PM
0
comments
Labels: consumer, identity theft, internal auditing, physical security, texas
Tuesday, March 13, 2007
Charts 'n Graphs
From Pogo, this article from Physorg on the classic Evil Hacker v. Evil Suit dilemma. From the article:
If Phil Howard’s calculations prove true, by year’s end the 2 billionth personal record – some American’s social-security or credit-card number, academic grades or medical history – will become compromised, and it’s corporate America, not rogue hackers, who are primarily to blame. By his reckoning, electronic records in the United States are bleeding at the rate of 6 million a month in 2007, up some 200,000 a month from last year.
Goodness. This article seems to do more damage than good in increasing awareness of the privacy issue. The key bit of data that seems to be missing is the damage. More from the article:
Malicious intrusions by hackers make up a minority (31 percent) of 550 confirmed incidents between 1980 and 2006; 60 percent were attributable to organizational mismanagement such as missing or stolen hardware; the balance of 9 percent was due to unspecified breachesSo, how many fraudulent charges were made, fake IDs manufactured or reputations horribly disfigured by each category? The author of the study adds:
"And the surprising part is how much of those violations are organizationally prompted – they’re not about lone wolf hackers doing their thing with malicious intent."
So, would you rather Big Nameless Credit Card Company notify you:
A. that your name/credit card/SSN/date of birth were lost at an airport while stored on an encrypted laptop hard drive
OR
B. that Lone Wolf Hacker sniped your digits of their server (running unpatched IIS 2.0 on unpatched Win98)
Of course I can't prove that either scenario is inherently more dangerous for the consumer. I can just shake my angry fist at the data.
Posted by
Dutcher Stiles
at
3:54 PM
0
comments
Labels: breach notification, consumer, disclosure laws, privacy, sb1386
Thursday, February 8, 2007
Stupid, powerless, uneducated.
Infoworld on a session at RSA: The Cybercrime Blame Game.
Although a conference center ballroom may not be conducive to rational discourse (see: US Political Party Conventions), this discussion appears a bit over the top:
- More people complaining about identity theft does not necessarily mean there is more identity theft. I'm sure there was a dramatic increase in complaints about anthrax without a corresponding increase in anthrax attacks. (See the corresponding stat later in the article citing an 11.5% decrease in dollar losses due to identity theft.)
- FTC Gorman is right: Calling people stupid doesn't solve anything. I've never been a fan of Winkler's ideas nor his rhetorical method.
- The job of an ISP is to move packets, not to sit in loco parentis for everyone with a broadband connection. (Why was this applauded? Were all the NANOG guys still in Toronto?)
- What makes an empowered consumer is not education, but power. Give the consumer the right and responsibility to take care of their own data. Not the credit bureau, federal law enforcement, the ISPs or Wal-Mart. The consumer. Build an infrastructure around that idea. The consumer isn't stupid, he just doesn't care and when he does care, he has no standing. Maybe the empowered consumer idea is just too European.
