Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Breach-notification laws not working?
Search Topic:
Uniqs:
152
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
HELP -- DoS.Generic.SYNFlood! What the heck is this?? »
« Security Software Updates - 25 Jun 2008  
AuthorAll Replies


Cudni
La Merma - Los De Aca
Premium,MVM
join:2003-12-20
Someshire
·BTOpenworld

Breach-notification laws not working?

from
»www.securityfocus.com/news/11524
"...
"You can put the accountability in two places," Romanosky said. "First the firms: they can improve and they need to improve. The other end is the consumers: Once notified, they need to do something."
.."

I find the 2nd part of the comment slightly disingenuous, because who would ignore a notification

Cudni
--
"Mercifully, he hit him with the soft end of the pistol."
Help yourself so God can help you.
Microsoft MVP, 2006 - 2008


Blue2
Premium
join:2004-04-14
France

Agreed. People may not be careful enough in protecting their confidential information. ("It will happen to the other guy, not to me."). But I'd like to see some evidence that once it happens, they do nothing. I'll bet it's just that the notification they receive is confusing and doesn't make it clear what to do.

Here's a case in point. Several years ago, I received a disclosure notice from a technology supplier to my former employer indicating that one of their laptops went missing. The letter was undated, had no contact info other than a PO Box, no clear information on how to contact the credit bureaus, etc. In sum, it seemed no more than a "Sh-t happens" cover-your-ass memo, to try to limit their liability if sued. I was incensed, looked up who was the CTO and Legal Counsel of this firm and shot back the following letter:

Dear Corporate Compliance Administrator,
Dear Chief Legal Officer,

Please help me to understand. You have informed me that a security breach occured at that may have potentially exposed my personal data to risk. However, despite my numerous written requests over the past several weeks, you have not indicated what were the circumstances regarding this potential theft of data, what data might have been compromised, and what steps you are actively taking to avert further losses.

Let me remind you that your letter to me was undated and provided no address or contact details easily accessible from overseas. As it is not even clear to me that this is data that you should have even been in possesion of in the first place, I hope that you will take my request seriously and not require that I have this issue investigated. Your ignoring of my repeated emails trivializes the seriousness of the situation and is preventing me from taking appropriate steps to limit to potential damage.

I thank you and await your kind reply.

Sincerely,


That finally provoked the merited reply. I imagine that Romanosky would consider that "doing something", but it sure suggests to me that the accountability is where it squarely belongs, on the shoulders of the firms who seem to be more interested in protecting themselves from liability than in protecting the consumer.
-
Forums » Up and Running » Security » SecurityHELP -- DoS.Generic.SYNFlood! What the heck is this?? »
« Security Software Updates - 25 Jun 2008  


Wednesday, 20-Aug 21:03:55 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [93] Was FiOS a Good Idea?
· [77] Landscaping, Courtesy of AT&T?
· [71] ISPs Whine About Network Neutrality 'Paranoia'
· [64] FCC Finally Issues Comcast Throttling Order
· [56] Google Launches White Space Broadband Website
· [53] Craig Moffett: Network Upgrades Are For Ninnies
· [52] Qwest, Unions Strike Deal
· [49] Olympics Didn't Cause The Exaflood
· [49] AT&T Cooking Up New VoIP Product
· [44] First Android Phone Gets FCC Approval
Most people now reading
· [Connectivity] Sandvine kills more than just P2P [Comcast HSI]
· How I Stole Someone's Identity [Security]
· Neighbor Yanks a Power Line & Voltage Overloads the Block [Home Repair & Improvement]
· [iPhone] 2.0.2 firmware is out, Please post outcome [All things Macintosh]
· IMG 1.6 Deployment [Verizon FIOS TV]
· VoIP and the 911 dilemma [VOIP Tech Chat]
· Anyone know how to capture NBCOlympics.com video streams [General Questions]
· How do you file things on your computer? [General Questions]
· Is something missing? (Stove question) [Home Repair & Improvement]