Slashdot Mirror


CA Law Demands Public Disclosure Of Break-Ins

AuntieMisha writes "BusinessWeek has an article about a new California law passed that requires businesses to publicly disclose information about break-ins. The only loophole is if there is an ongoing investigation and if the disclosure would harm the investigation. IMHO Big companies will have the resources to set up investigations even when they know it is unlikely to get anywhere, and business will go on as usual for them. Small businesses that don't have the resources to maintain an investigation will have their reputations ruined. Also, the article doesn't mention the contingency where a break-in occurs because of a software/hardware issue for which there is no released technical solution (i.e. anyone else who has software X would be susceptible to the same type of break-in). This is not good."

188 comments

  1. Yay, verily by Anonymous Coward · · Score: 5, Insightful
    I think the California law is long overdue. In far too many instances, companies and governments have kept mum after they were hacked, seeking to preserve their reputations and avoid public outcry while their customers face risk of identity theft. Computer-security breaches must be treated like any other issue of public safety, and people must be informed when they're at risk.

    Most businesses that get hacked surely do the right thing and inform customers. Also, the idea of allowing companies to quietly share technical information on breaches with investigators clearly has merit.

    1. Re:Yay, verily by Anonymous Coward · · Score: 1, Informative
    2. Re:Yay, verily by First_In_Hell · · Score: 3, Insightful
      Is it that hurtful to their reputations? What is the shame at getting hacked? It has happened to the biggest of them (ebay, CNN). I think more damage would be done if the consumers found out that they were withholding the information from them.

      That is more damaging to their reputation than any hack attack.

    3. Re:Yay, verily by BlueUnderwear · · Score: 3, Funny
      Most businesses that get hacked surely do the right thing and inform customers.

      Heck, even some spammers do it. Look at this choice piece from buystainlessonline, it's hilarous:

      From sales@buystainlessonline.com Tue Oct 22 15:46:16 2002
      Return-Path: <sales@buystainlessonline.com>
      Received: from xxxxxx.xxxxxxxx.xx (xxxxxx.xxxxxxxx.xx [xxx.xxx.xx.xxx])
      by xxxxxx.xxx.xx (8.12.3/8.12.3/SuSE Linux 0.6) with ESMTP id g9MDkJVR020365
      for <xxxxxx@xxxxxxxxxx.xxx.xx>; Tue, 22 Oct 2002 15:46:24 +0200
      Received: from linuxpow.com (IDENT:qmailr@linuxpow.com [12.149.2.10])
      by xxxxxx.xxxxxxxx.xx (8.11.6/8.11.6) with SMTP id g9MDkFQ16222
      for <xxxxx@xxxxx.xx>; Tue, 22 Oct 2002 15:46:16 +0200
      Date: Tue, 22 Oct 2002 15:46:16 +0200
      Message-Id: <200210221346.g9MDkFQ16222@xxxxxx.xxxxxxxx.xx&g t;
      Received: (qmail 13748 invoked from network); 22 Oct 2002 12:08:48 -0000
      Received: from buystainlessonline.com (HELO ) (nobody@12.149.2.55)
      by mail.buystainlessonline.com with SMTP; 22 Oct 2002 12:08:48 -0000
      Subject: HACKERS ATTACKED...E-MAILS TO RESUME... PLEASE READ
      To: xxxxx@xxxxx.xx
      From: "BuyStainlessOnline.com" <sales@buystainlessonline.com>
      Content-Type:
      X-UID: 468

      ATTENTION! This email will be sent twice before we resume our weekly newsletter.

      Over the course of the last year, our E-mail system was attacked by HACKERS twice, resulting in the corruption of our marketing system. If you are on this E-mail list and did not request to be, please be ADVISED that this is your opportunity to be REMOVED. We have been going through our E-mail database for the last 3 months to fix errors, this has stopped us from sending our regular e-mail THE STAINLESS STEEL NETWORK. We have done our best to "CLEAN" our list. If you are getting this and wish to be removed, this is your chance. Effective 10/28/02, we will resume sending this email weekly. If you wish to be removed, click the LINK below. If you use AOL, you must COPY and PASTE the link into the browser (http://). This will remove you immediately.


      Thank you for your time!
      Mgmt

      www.BuyStainlessOnline.com
      Your Place for Stainless Today.


      International 215.604.5922
      Fax 215.638.4960

      Click Here to REGISTER!
      https://www.buystainlessonline.com/registration/re gistration.php

      Unsubscribe By clicking below:
      http://www.buystainlessonline.com/email/mail.php?a ction=delete&eval=125410&email=xxxxx@xxxxx.xx

      Seems like some net vigilante typed 'or 1=1-- or something of that ilk into the spammer's remove link, or whatever...

      --
      Say no to software patents.
    4. Re:Yay, verily by Anonymous Coward · · Score: 1, Insightful

      Most businesses that get hacked surely do the right thing and inform customers.

      It's important to note that "right thing" here means after the fact. I currently have no way to research a company to see how often its database was hacked before I gave them my credit card number.

      In some cases when credit card data was taken, the credit card companies proved reluctant to cancel the credit cards and reissue new ones, even when the victim company did the right thing to inform the credit card companies.

      It's not that I disagree with your post, it's just that different companies have different definitions of "right thing". Coding it into law
      solves this problem.

    5. Re:Yay, verily by Anonymous Coward · · Score: 0

      Ah, great, multiple moderators didn't even read the article first.

    6. Re:Yay, verily by _anomaly_ · · Score: 2, Funny
      Computer-security breaches must be treated like any other issue of public safety, and people must be informed when they're at risk.

      Computer security breaches are hardly similar to other issues of public safety. Announcing that a breach has occurred when there is no viable solution to keep it from happening again (either to the same company or other companies using the same software) would put the public's safety at an even greater risk.
      If it involves any of my personal data, then I would rather them keep their mouths shut for damage control until there is a solution to the original problem.
      It is sort of a catch-22 though. Other companies using the same software would be unaware of the vulnerability until a solution to the problem is found by that one company (which could potentially be slower than if many companies were looking for a fix). Maybe what we need is a *trusted* network (not in the ether sense of the word) where vulnerabilities could be posted without getting the word out to the people that would use this information maliciously.

      --
      "I have no special gift, I am only passionately curious." - Albert Einstein
    7. Re:Yay, verily by Anonymous Coward · · Score: 0
    8. Re:Yay, verily by Anonymous Coward · · Score: 0

      Parent's comments are stolen from SecurityFocus: Computer Break-Ins: Your Right to Know

    9. Re:Yay, verily by flossie · · Score: 2
      If it involves any of my personal data, then I would rather them keep their mouths shut for damage control until there is a solution to the original problem.

      Would you really prefer that they don't tell you that your credit card details have been stolen until they have patched their web server?

    10. Re:Yay, verily by Eccles · · Score: 1

      Maybe what we need is a *trusted* network (not in the ether sense of the word) where vulnerabilities could be posted without getting the word out to the people that would use this information maliciously.

      To me, I don't see any indication that the companies need to disclose technical details of the way the break-in was achieved, it's more of an issue of what may have been affected from the break-in. If Fred's Bank reports a breach where crackers may have gotten access to my account info, that doesn't tell me anything about how the breach occured.

      --
      Ooh, a sarcasm detector. Oh, that's a real useful invention.
    11. Re:Yay, verily by DEBEDb · · Score: 2

      The shame is that they will be perceived
      as not secure enough for someone to trust them
      with sensitive info. Sensible enough; and even
      if it weren't, the public will hype themselves
      into believing it is.

      Would you want them to keep it quiet if your
      bank got broken into?

      --

      Considered harmful.
    12. Re:Yay, verily by V.P. · · Score: 2, Insightful
      No. If they can't protect my data, they have no business storing them in the first place. If they do, it's their responsibility to keep them safe, and, at the very least, let me know when they're compromised.

      Not to mention the healthy effect of getting companies to actually pay some attention to security, or face at least some bad publicity if they don't.

    13. Re:Yay, verily by bshanks · · Score: 1

      yeah, i agree with this post. this is a good law.

      i disagree with the submitter's take.

    14. Re:Yay, verily by Yottabyte84 · · Score: 1

      Hacked my ass. This is an excuse to use addresses that they harvested.

    15. Re:Yay, verily by Anonymous Coward · · Score: 0

      h0h0h0, I h4x0r3d j00r telnet server!

    16. Re:Yay, verily by mbogosian · · Score: 2

      ...was attacked by HACKERS twice...please be ADVISED that this is your opportunity to be REMOVED...sending our regular e-mail THE STAINLESS STEEL NETWORK...done our best to "CLEAN" our list...click the LINK below...you must COPY and PASTE the link

      Did anyone else read this and think the author had Turrets?

    17. Re:Yay, verily by Anonymous Coward · · Score: 0

      You are assuming that anyone knows that something has happened.

      You are thinking that computer crime is like crimes in the physical world - bloodstains, footprints, broken windows.

      It's not that obvious when bad things have occurred.

    18. Re:Yay, verily by glesga_kiss · · Score: 2

      And verify that there was someone reading the mail at the other end. Clicking "Remove" is pretty much the worst thing you can do. "Yes, I'm here, and I read all my e-mail, including the SPAM. Please send me more!!"

    19. Re:Yay, verily by Yottabyte84 · · Score: 1

      I usualy send thier ISP a nastygram. There's a tool called ricochet that will automaticaly send out nastygrams based on spam you feed it.

  2. Loophole by First_In_Hell · · Score: 1, Interesting
    The only loophole is if there is an ongoing investigation and if the disclosure would harm the investigation.

    Wouldn't want those wacky hackers to know that people were on to them and actually investigating the crime! Who makes that decision? Chief Moose?

    1. Re:Loophole by Angry+White+Guy · · Score: 3, Funny

      Naw, Chief Wiggum.
      "I'd rather let a thousand criminals go than chase aftert them..."

      --
      You think that I'm crazy, you should see this guy!
  3. Re:post 1001 by Anonymous Coward · · Score: 0
    Damn, posts 1000 and 1001 both logged in first posts. Despite the nazi janitors, CLIT still lives in the hearts of all the trolls and crapflooders.

    In honor of this special day, I am offering a special discount - all mods can lick both my balls for the price of one!

    Your pal, Neal

  4. There will be no more break-ins by Anonymous Coward · · Score: 1, Insightful

    Companies will stop paying any attention to security logs, or will at least make sure that nobody ever speaks of anything as a "break in" or a "security problem".... There will only be "network configuration issues".

  5. But how do you enforce this? by Halo- · · Score: 5, Interesting

    If you don't report a break-in, how is anyone gonna know it happened? (Unless an employee narcs, at which point it becomes a messy paper/email/word-of-mouth trail)

    Seriously, it's not like the CA government is gonna be able to "audit" companies like they do if they suspect fraud in other self reported areas. (Like tax fraud, emissions, etc...)

    1. Re:But how do you enforce this? by Raul654 · · Score: 3, Insightful

      Because the truth has an unforunate tendancy to come out, eventually, Today's most tightly guarded secrets are the stuff tomorrow's headlines are made of.

      --


      To make laws that man cannot, and will not obey, serves to bring all law into contempt.
      --E.C. Stanton
    2. Re:But how do you enforce this? by Fatal0E · · Score: 2

      I suppose it would make a pretty good piece of info to be used as blackmail. There -are- ways to prove that you broke into a system or network. I can see it now...

      Pay me 1 million not release your new product specs to your competition. Or you could pay me 1.5 mill to not anonymously report the break in. For the low low price of 2 mill, you get to keep your trade secrets AND the fact that they were stolen. Act now! Crackers are standing by!

    3. Re:But how do you enforce this? by bovilexics · · Score: 5, Funny

      From the article...

      • Come July 1, 2003, those who fail to disclose that a breach has occurred could be liable for civil damages or face class actions.

      They (the CA government) don't need to audit or enforce anything. It is self-enforcing for those businesses that feel they may be sued and have to pay monetary payments for NOT reporting the incident. If a given company doesn't feel it can be successfully sued due to the incident then there probably wouldn't be a public reporting of it.

      It's just a CYA that would have to be handled on a case by case basis for each company and wouldn't be enforced by auditors and the like.

      --
      Are you bovilexic? Moo!
    4. Re:But how do you enforce this? by BlueUnderwear · · Score: 2
      If you don't report a break-in, how is anyone gonna know it happened?

      Maybe because the hacker himself might have reported it to zone-h?

      --
      Say no to software patents.
    5. Re:But how do you enforce this? by susano_otter · · Score: 2
      Enjoy your job, make lots of money, work within the law. Choose any two.

      Actually, I've got all three. What does that mean?

      --

      Any sufficiently well-organized community is indistinguishable from Government.

    6. Re:But how do you enforce this? by hesiod · · Score: 1

      > Actually, I've got all three. What does that mean?

      Sorry to break it to ya', but you are an anomaly of nature and will promptly vanish. Tough luck...

  6. Sounds good to me... by dfn5 · · Score: 3, Funny
    Small businesses that don't have the resources to maintain an investigation will have their reputations ruined.

    Small businesses can hire me as a security consultant. And I can do my consulting by hacking^H^H^H^H^H^H telecommuting my way into California from my New Hampshire home.

    --
    -- Thou hast strayed far from the path of the Avatar.
    1. Re:Sounds good to me... by Havokmon · · Score: 3, Funny
      Small businesses that don't have the resources to maintain an investigation will have their reputations ruined.
      Small businesses can hire me as a security consultant. And I can do my consulting by hacking^H^H^H^H^H^H telecommuting my way into California from my New Hampshire home.

      Day 1: Begain Searching "Google" for perpetrators (Known hangout for 'haXors').

      Day 5: Still Searching Google. Found many people distributing doctored pics of Natalie Portman, but no perps.

      Day 12: No information found at Google. Now searching internationally, trying AltaVista (personal note, penis +1/4").

      Day 17: Perps deface Nasa site. Personal note:
      1. add more fake entries until Feds nab Nasa perps
      2. Blame break-in on Nasa perps
      3. Profit!

      --
      "I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
  7. The bigger picture by unicron · · Score: 4, Insightful

    What does this law have to do with sticking up for the little guy? If a company that I have a stake in, ESPECIALLY if that stake is a good amount of money, I want to know if they're getting owned. If my investments aren't safe, I have a right to know. Granted, most financial institutions are federally insured, but that won't help me if Bob Hacker over here can make it look like I never invested in the first place. The matter is A LOT more of problem if I'm highly wealthy, in which case I'm SOL on any amount higher than 100k.

    All in all, they have an obligation to tell the world, not just for their current customers, but to let potential future customers aware of the situation so that they can make sound, informed financial decisions.

    --
    Finally, math books without any of that base 6 crap in them.
    1. Re:The bigger picture by Anonymous Coward · · Score: 0


      I want to know if they're getting owned.

      Get with the program, Sparky. It's spelled "0wn3d".

    2. Re:The bigger picture by Kamel+Jockey · · Score: 5, Funny

      that won't help me if Bob Hacker over here can make it look like I never invested in the first place

      For some of us, this could be a very good thing!

      --
      In case of fire, do not use elevator. Use water!
    3. Re:The bigger picture by Alton_Brown · · Score: 1

      Sorry, but if you're "highly wealthy" (sorry, but 100K certainly doesn't qualify for that) chances are that you don't have all your money in one account in a single bank. Hopefully if you were wise enough to amass that kind of money, you learned along the way to diversify. That might mean multiple accounts at multiple banks, other government insured securities, highly rated bonds and any number of other low-risk/no-risk investments. To your point of making it look like it never existed, please tell me you're saving your bank/etrade/whatever receipts when you make your 100K deposits...

      Karma: Mostly tasty due to copious amounts of olive oil and cheese.

    4. Re:The bigger picture by Anonymous Coward · · Score: 0
      I'm posting AC because I don't want to advertise money, and the doubters will doubt whether I post under my account or not.

      I'm not terribly wealthy, but I do have a tad over $3m in the market, and all but $100k or so is invested through one firm, in one account. A hacker breaks in, executes sell orders then transfers the balance to another account, and the only way I get my money back is to hire a lawyer and sue Schwab.

      Remember, accounts are only insured up to $100k by the government, so you don't have to be rich to be at risk these days.

    5. Re:The bigger picture by unicron · · Score: 2

      You don't get rich by investing 50k here or 75k there. You do it with the multi-million dollar deals. And the first thing my firm is going to believe is their computers.

      --
      Finally, math books without any of that base 6 crap in them.
    6. Re:The bigger picture by Yottabyte84 · · Score: 1

      3,000,000 is enough to live comfortably off 1-2%/year intrest. If I were you, I'd pop that stuff in about half a dozen high interst bank accounts.

  8. Why? by websurf.net · · Score: 2, Interesting

    How can California insist that anyone make it public when they are hacked? Do they insist it is made public when a company is physically broken into? I doubt it. This will just cause companies to not even call the police in order to save their reputation.

    1. Re:Why? by unicron · · Score: 2

      Yeah, but if you were storing bundles of cash at some guys house you'd like to know if his house got broken into, right? Your example is flawed because most homes don't contain high amounts of money from the neighbors under the supposed protection of the homeowner, do they?

      --
      Finally, math books without any of that base 6 crap in them.
    2. Re:Why? by First_In_Hell · · Score: 0

      Is it that hurtful to their reputations? What is the shame at getting hacked? It has happened to the biggest of them (ebay, CNN). I think more damage would be done if the consumers found out that they were withholding the information from them. That is more damaging to their reputation than any hack attack.

    3. Re:Why? by websurf.net · · Score: 0

      Well I think it is a good idea for certain institutions (banks, financial, hospitals), but I think for other companies, it does not affect their customers. Besides, government has too much power...

  9. How is this not good. by glrotate · · Score: 5, Insightful

    Information asymmetry leads to inefficency, in this case through adverse selection. If my bank gets hax0r3d every other week their reputation should be tarnished. Also the article states that investigations by the federal government are exempt, not private investigations. This bill was constructed by consumer advocacy groups becasue it is good for consumers.

    1. Re:How is this not good. by Anonymous Coward · · Score: 0

      Somebody pull their heads out of their asses please, and point out the reason they passed this law. The state hr dept. was hacked and for several months their records were available to the hacker. Which means things like names, ssns, bank routing numbers, salaries, etc. for all of the employees of the state of ca. After this was discovered, they didn't report it for a time. During which time the hacker could easily have fucked with thousands of peoples lives.

    2. Re:How is this not good. by Anonymous Coward · · Score: 0

      Dude, get wise.

      Your data is probably in at LEAST 1000 databases. Give up. Your data is public.

  10. Oh thats really useful by jcrb · · Score: 3, Insightful

    So you only have to disclose the break in if you don't have the ablity to investigate it and find out how to stop it from happening again?

    So if you can prevent it from happening again you don't have to tell other people how to protect themselves. But if you can't protect yourself you have to tell the hacker that you don't know how to track them down and they should be sure and hack you again.

    Why is it that when people go into politics they suddenly become stupid?

    --
    -jon
    1. Re:Oh thats really useful by Anonymous Coward · · Score: 0

      I know, this is a bit off-topic, but I'd like to answer your last question:

      It's the other way round: stupid people go into politics. Or: "idle lawyers tend to become politicians, so there's a certain social value in keeping them busy" [from 'Operating System Concepts', by A. Silbershatz, J. Peterson]. :-)

    2. Re:Oh thats really useful by Anonymous Coward · · Score: 0

      Most of them were stupid to begin with, except Joseph Stalin, now there's someone you can look up to.

    3. Re:Oh thats really useful by Anonymous Coward · · Score: 0

      Note: YOU don't get to investigate the break-in (at least not for the purpose of delaying notification). A law enforcement agency make the determination of whether or not the delay takes effect.

      Now, even if a company has the clout to convince law enforcement to prolong the investigation, I think that most companies don't really want to have the FBI (or whoever) poking around their data centers for much longer than truely necessary.

  11. Misread by verloren · · Score: 4, Funny

    Computer Associates is writing laws now? And I thought Microsoft had influence with the gov..

    oh, right, California...

    1. Re:Misread by Nos. · · Score: 1

      I thought it was referring to Canada... remember folks this is an International community.

    2. Re:Misread by Anonymous Coward · · Score: 0

      Of course they do, the corporations running America are: Microsoft, Fox, and Calgon. Microsoft controls the government and all the computers (except ones using Linux), Calgon puts 'long term anti agression compounds' into all their products to help control people, and Fox puts subliminal advertising for the two corporations into all of their TV shows. So now you know.

  12. Con game by failrate · · Score: 1

    I don't trust the expedience with which the law was passed, nor do I trust its conveniently broad sweep. No mention was made of any actual damages or improprieties, nor was it made mention why they didn't disclose about the attacks for two weeks after they were aware of them. So, my conclusion is that if I were wanting to pass another security bill, I would fake an attack on myself and then go bawling to the legislators. They've been waiting, bill in hand, for me to take my cue and play my part. Curtain close. Next act, Orwell-capades!

    --
    Voodoo Girl is the bomb!
  13. why not ? It is a good idea by Muad · · Score: 2, Interesting

    I second the point on smaller businesses not having the cash to maintain bogus investigations just to delay the release of information, but this can be easily fixed by establishing a deadline that cannot be easily stretched (something akin to "even with an investigation running, you must notify your customers within one month").

    Special clauses must mention that when sensitive information is compromised (trade secrets, credit card numbers, etc) customers should be notified IMMEDIATELY, barring a judge authorizing a delay of that to protect an investigation for justified, specific reasons - ie no blank checks should be given for non-disclosure.

    --
    --- "I didn't think anyone would understand it" -Prof. Bob Muller
    1. Re:why not ? It is a good idea by n-baxley · · Score: 2

      That's a great idea. Too bad the bill is already passed.

    2. Re:why not ? It is a good idea by OneEyedApe · · Score: 1

      From what (little) I know of the workings of legislative bodies, it would be business as usual to pass a bill that amended a previous bill. The one difficulty lies in getting the appropriate politicans to cooperate (which may just involve giving enough money to the appropriate re-election campaigns).

      --
      Life sucks, but death doesn't put out at all....
      --Thomas J. Kopp
  14. It's about time by EggplantMan · · Score: 5, Insightful
    I'm sorry but I do not side with the submitter on this one. Any sort of forced disclosure in this arena is a step forward. If I am going to be trusting my personal info with a business I would like to know their security record. Just consider the recent scandals with Bell, and AOL for instance.

    It seems like the submitter is a little too polarized on this issue, but I don't feel the compulsion to take every attempt to legislate order into the digital world as an insidious attempt to undermine small business.

    In fact, why is it that Slashdot seems to think that any attempt to introduce order through legislation as a bad thing? Get a grip already. This isn't your 'internet' it's that of those who own the hardware. I find this false sense of ownership childish and tasteless.

    --

    ?-|||-----x<*))))><
    1. Re:It's about time by gnovos · · Score: 2, Insightful

      Look at it this way...

      1) You know publicity about your break-ins will cost you reputation.

      2) You know that there really isn't any way to 100% secure your site from every niggling little security hole, no matter how much money you spend.

      What's stopping you from dumping your ENTIRE network security department and never actually going out and looking for breakins ever.

      If you never SEE a break-in, you can't be obliged to report it, right?

      --
      "Your superior intellect is no match for our puny weapons!"
    2. Re:It's about time by Anonymous Coward · · Score: 0

      the submitter is a myopic toad.

      This is about one of the best things that the state can do.

      Just like how it becomes public record with a police report is filed regarding a burglary, it should be public record when the corresponding "virtual" crime occurs.

    3. Re:It's about time by JordoCrouse · · Score: 1

      Look at it this way...

      1) You know publicity about your break-ins will cost you reputation.

      Hiding the fact that your customers personal data was compromised will cost you reputation. And it will get out - you can't hide it forever.

      2) You know that there really isn't any way to 100% secure your site from every niggling little security hole, no matter how much money you spend.

      Nobody will not hit 100% of the companies in America at the same time with a new exploit. If you monitor the community and mailing lists, the odds of finding and fixing an hole before gets exploited are in your favor.

      --
      Do you have Linux and a DotPal? Click here now!
    4. Re:It's about time by Anonymous Coward · · Score: 0

      you just really don't get it, do you?

      One day, when you finally graduate from elementary school / high school / college, you will learn how the "Real World" works... ...and I'm not talking about that show on MTV.

  15. On the contrary, this is a Good Thing(tm) by b.foster · · Score: 3, Insightful
    This bill is exactly what we need, and it should be adopted by all 50 states. Why? Accountability. Let's look at the facts before we jump to conclusions:
    • 99.4% of all breakins are caused by known, unpatched vulnerabilities. Businesses that cannot take simple steps to keep their systems up to date should be shunned by privacy-conscious consumers. After all, when you hire a business, you are trusting them and their network to keep your data safe and operate reliably.
    • This will hurt Microsoft. Since IIS has the largest market share on web servers, they will be hit hardest when these security breaches come to light. People will realize that Linux is a more secure, easier-to-maintain alternative.
    • This will create jobs. Small businesses who might have otherwise adopted IIS and foregone the overhead of an IT staff will be forced to take a more active role in keeping their systems secure. Although it may hurt some small businesses, the net overall effect is to redistribute wealth into our pockets and increase our pay overall, which is indisputably a Good Thing(tm).
    • Debian will benefit. Debian's "apt" facility is extremely simple for end-users to use and understand, and helps system administrators keep large numbers of boxes up to date without causing RPM hell or any other conflicts that one may experience when using a distribution like RH that does not regression test their patches.
    • Script kiddies will have to find new targets. The logical next step for script kiddies, once e-commerce sites have been secured, is government sites. This will encourage the government to adopt Linux more widely, in place of insecure and unreliable Windows NT systems. In fact, it may even create grounds for breaking their contract with Microsoft.
    1. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 1, Insightful

      It was reasonable till the 'this will hurt Microsoft' part. Who gives a fuck? Does causing Microsoft damage have to be a litmus test for every Good Thing these days?

      Microsoft is not Satan. Bill Gates is not the Anti-Christ. Regardless of their disgusting corporate behaviour, if they disappeared tomorrow, there would be chaos and gnashing of markets.

      Just because you don't like the color or smell of a supporting wall is no reason to blindly knock it down with no preparation.

    2. Re:On the contrary, this is a Good Thing(tm) by Ionizor · · Score: 2, Insightful

      *cough*

      IIS has the biggest market share on web servers? Since when? According to every statistic I've seen, Apache has the biggest market share.

      Also, your line of events ending in everyone adopting Linux and ditching NT is highly unlikely. Most of the NT boxes I've seen are run by morons - morons work cheap(er).

      --

      --
      Todd's Law: All things being equal, you lose!
    3. Re:On the contrary, this is a Good Thing(tm) by EricWright · · Score: 2
      Remind me where you got your numbers for point 2. This seems to say differently, and has for quite some time. Apache is ahead of all other competetion, nearly 2 to 1.

    4. Re:On the contrary, this is a Good Thing(tm) by PhxBlue · · Score: 2

      Points 1, 3, and 5 are all good. Points 2 and 4, however, weaken your argument substantially. Since when do laws exist to arbitrarily punish Microsoft and benefit Debian?

      --
      !#@%*)anks for hanging up the phone, dear.
    5. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 0

      Point taken. But when Microsoft loses market share to a competitor, we realize three benefits: 1) it makes M$ weaker, 2) it creates a new user of an alternative OS, and 3) it lessens the world's dependence on M$. Using induction, one can show that when the day arrives when the majority of users have switched over, Microsoft will no longer have a reason or a means to exist. And that will be a beautiful day indeed.

    6. Re:On the contrary, this is a Good Thing(tm) by n-baxley · · Score: 2

      This will hurt Microsoft. Since IIS has the largest market share on web servers, they will be hit hardest when these security breaches come to light. People will realize that Linux is a more secure, easier-to-maintain alternative.

      I like your thinking, but your logic is screwed up. Since everyone, everyone intelligent to consider switching to Linux, knows that IIS is the market leader, they'll just chalk up the large number of break ins on IIS to their market share. At least that's how your logic makes it sound. Plus with that logic, Apache would be reporting the most breakins of all!

    7. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 0

      Keep your rabid fanaticism to yourself. You're getting slobber on my shoes.

    8. Re:On the contrary, this is a Good Thing(tm) by The+Evil+Couch · · Score: 3, Insightful

      99.4% of all breakins are caused by known, unpatched vulnerabilities. Businesses that cannot take simple steps to keep their systems up to date should be shunned by privacy-conscious consumers. After all, when you hire a business, you are trusting them and their network to keep your data safe and operate reliably.

      Agreed. If a program is a security liability, they need to either fix it or replace it. Electronic deadwood does no-one any good, no matter how pretty it is.

      This will hurt Microsoft. Since IIS has the largest market share on web servers, they will be hit hardest when these security breaches come to light. People will realize that Linux is a more secure, easier-to-maintain alternative.

      It depends on how smart and flexible MS is. They've finally been catching onto doing networking the smart way and if they start getting revealed as unsecure as they actually are, they may just fix themselves, and rake in the public attention, while the open source community whacks themselves on the forehead saying, "BUT WE'VE BEEN DOING IT THAT WAY, FOR FREE FOR YEARS!" Never underestimate MS's spin doctors or the public's gulibility.

      This will create jobs. Small businesses who might have otherwise adopted IIS and foregone the overhead of an IT staff will be forced to take a more active role in keeping their systems secure. Although it may hurt some small businesses, the net overall effect is to redistribute wealth into our pockets and increase our pay overall, which is indisputably a Good Thing(tm).

      I like the concept of IT staff's importance about to take a big step up. Maybe I'll actually be able to get a job when I stop doing this shit for the Army, instead of fighting some kid for a tech support job or some crap like that.

      Script kiddies will have to find new targets. The logical next step for script kiddies, once e-commerce sites have been secured, is government sites. This will encourage the government to adopt Linux more widely, in place of insecure and unreliable Windows NT systems. In fact, it may even create grounds for breaking their contract with Microsoft.

      Speaking as an Army Sys-Admin, I can tell you that most of our users are too tech-stupid to use Linux, no matter how ridiculously easy the distro is. Windows will stay entrenched in the military. Other government sections may be smart enough to swap out to Linux, but the Army won't. We just don't have enough people that can find the "any" key.

      all in all, the IT crowd and the public at large wins with this new law. slap an S or HR on it with a couple of numbers and I'll vote for whoever in Congress sponsors it.

    9. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 0

      I didn't know vulnerabilites do the breaking in. I always thought it was somebody at a keyboard, or a script-bot doing their bidding.

      And btw, patching vulnerabilities is not always simple. As I type, the ISC site is still showing BIND 8.3.3 as current in the 8.x line.

      Legacy systems, boy, do those simplify patching, lemme tell you.

      Don't underestimate the ease of patching for everyone out there. I'm not saying it shouldn't be done, mind you. It's just not always a "simple step".

    10. Re:On the contrary, this is a Good Thing(tm) by FurryFeet · · Score: 2

      99.4% of all breakins are caused by known, unpatched vulnerabilities

      I thought that was the percentage of statistics that are made up on the spot.
      Quite a coincidence, really.

    11. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 0

      So you think all the money in the world should end up in BillG's pocket?

    12. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 0

      Damn put a space in your sig somewhere; it screws up the page formatting

    13. Re:On the contrary, this is a Good Thing(tm) by Anonymous Coward · · Score: 0

      > This will create jobs

      Good point! Now please, will everyone hack CA? I mean, in the name of job security, namely my own :)

  16. I don't see how this would be enforceable by DeadSea · · Score: 2, Interesting
    First of all, who decides what a break-in is? If somebody can access the data who is to say that the admin didn't want it that way? If the admin wanted it accessable, he shouldn't have to report every access to it.

    How about for break-ins that the admin didn't know happened? I can't imagine that this law would require reporting of something you don't know about. Any admin could feign ignorance of something to avoid reporting.

    Who is going to care if stuff isn't reported? If you don't report something, who is going to sue you? I can see a new type of hacker: "I broke in but you didn't report it, so now you owe me One Million Dollars (bwah hah hah)."

    What would the purpose of this law be anyway? For law enforcement to gather data? I didn't read the article or text of the law, so maybe some of my concerns are addressed. I don't see how it would ever work given the Slashdot writeup.

    1. Re:I don't see how this would be enforceable by DeadSea · · Score: 2
      Ah, I read the article, it is for computer-security breaches in which confidential information may have been compromised. That makes a bit more sense. Now I know who you have to notify and why.

      You have to notify those who's information may have been leaked. If you don't and they find out later, they will be the ones that care and can sue you.

    2. Re:I don't see how this would be enforceable by Ionizor · · Score: 1
      Quoth the poster:
      I didn't read the article or text of the law...

      Well, at least you're admitting your ignorance. How can you justify your opinion on something you haven't even researched?

      I don't see how it would ever work given the Slashdot writeup.

      So you're going to base your opinion of a law on a biased posting to a tech website? Please don't ever run for public office.

      --

      --
      Todd's Law: All things being equal, you lose!
    3. Re:I don't see how this would be enforceable by OneEyedApe · · Score: 1

      Sadly, these traits are seen in a disturbing number of public office holders. The individual to whom you are replying would fit in perfectly.

      --
      Life sucks, but death doesn't put out at all....
      --Thomas J. Kopp
  17. Hello? It's only when confidential info is leaked. by island_earth · · Score: 5, Insightful

    From the article:

    California enacted a sweeping measure that mandates public disclosure of computer-security breaches in which confidential information may have been compromised.

    This isn't nearly as bad as the alarmist description at the top of this story. This doesn't say that Company B has to announce that their Web server was hacked to say "1 0wn U!" It says that the people affected by a break in (i.e., the people whose confidential records were exposed) must be notified.

    A couple of years ago, I had to cancel a credit card after some charges from Russia showed up. Eventually it came out that an online retailer had lost a bunch of card numbers. They should have told me when it happened, not after my credit card company was ripped off.

    Seems like a good law to me.

  18. If applied correctly, this could be a good thing. by nystul555 · · Score: 4, Insightful

    I would have to say that this COULD be a good thing. It could provide incentive for companies to tighten security. And most importantly, in my mind, I would want to know as soon as possible if an information with my SSN, credit card numbers, etc had been hacked, so that I could keep a closer eye on my accounts and be ready to provide information to law enforcement and the credit agencies should my identity be stolen.

    Unless I misread the article, I get the feeling that by "investigation" they meant a legal investigation. If that is true, then businesses couldn't just start an internal investigation to put off disclosure forever. If this is not true, then well, it should be restricted to legal investigations only.

    But again, I do think this is a good step in the right direction. When I give my personal data to a company, they need to manage it and secure it. I expect them to inform me if a problem occurs. With laws like this, they will have to.

  19. Not all cyber break ins by sdowney · · Score: 3, Informative
    "[The law] mandates public disclosure of computer-security breaches in which confidential information may have been compromised."

    So if your web server is hacked and defaced, you don't have to reveal anything. If your credit card database is hacked, you do.

    I don't see the problem with this. As it is, confidential information is exposed, and no one knows about it.

    1. Re:Not all cyber break ins by John+Hasler · · Score: 2

      > I don't see the problem with this.

      The problem is with public disclosure rather than notification of those affected. If I have five customers for my consulting service (a sole proprietorship) and a break-in exposes the confidential data of one of them why do I have to tell the world?

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    2. Re:Not all cyber break ins by Anonymous Coward · · Score: 0

      Because those 5000 new customers you might get tomorrow should get a warning, that your security may not be as good as you claim.

  20. This is a good thing by nicodaemos · · Score: 2

    Excellent. Since companies will now fear losing their reputation, perhaps they will put more thought into the operating systems they choose for keeping customer information.

    Up until now many companies don't seem to care that they use insecure MS products to store information since it didn't really matter to them if their customer's privacy was being violated. If this now affects the company's reputation, you bet they will care!

    1. Re:This is a good thing by geekee · · Score: 1

      If you look back a couple of stories on slashdot, you'll see a story on an incident involving trojaned open source software. OSS is not as secure as you might think.

      --
      Vote for Pedro
  21. Some crucial missing words... by Otter · · Score: 5, Informative
    Note that this legislation "mandates public disclosure of computer-security breaches in which confidential information may have been compromised". It doesn't mean that any web server that gets owned has to be publically reported.

    Maybe that's obvious to the submitter, but I was horrified that such a burdensome and unnecessary law was passed. And reading other posts, a lot of others didn't get it either.

    1. Re:Some crucial missing words... by HiThere · · Score: 2

      Unnecessary? As compared to which other laws?

      I can think of better laws than this, but they are vastly outnumbered by those which are worse.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    2. Re:Some crucial missing words... by Otter · · Score: 1
      I'm not sure if you're understanding me correctly...

      The writeup suggests that any intrusion would have to be reported to the California Department of H4x0r1ng. _That_ would be an excessively burdensome and invasive law. It wouldn't be the stupidest law ever, but there's still a large difference between a stupid, counterproductive law and the entirely reasonable protection of privacy that this measure actually is.

  22. I can see it now... by Waab · · Score: 3, Funny

    Microsoft (Nasdaq: MSFT) filed documents with the SEC today relating to a breach of network security.

    According to the filings, at 5:23 AM last Tuesday, Microsoft's network was "owned" by a hacker calling himself "Z3r0 kew10r". While the hacker refered to himself as "1337" in his defacement of Microsoft's webpage, Microsoft CEO Bill Gates indicated that the security breach was very minor.

    In a press release accompanying the filing, Gates said: "t#1s punk th1nks h3's 1337 but h3's just a littl3 scr1p7 k1dd13 and i'm g0nna sh0w h1m what 1337 is when m3 and the M$ haxx0r cr3w crak his b0xx0r!"

  23. New business opportunity by kawika · · Score: 4, Funny

    >> The only loophole is if there is an ongoing investigation

    I would like to point out that ongoinginvestigation.com is still available for registration. Imagine the business you'll get in California! Certainly it will be worth a few bucks a month to a company's reputation to hire you to keep the investigation ongoing.

  24. Small vs. Large by n1ywb · · Score: 1
    IMHO small businesses can be just as shady, if not MORE shady than large businesses. There are fewer chefs in the kitchen, so to speak.

    IMHO this is a good law. Businesses have a responsibility to keep confidential information confidential and failing to do so may be considered negligence. Obviously, "negligence" is subjective.

    Your point about the law not requireing specific details about the type of breach is well taken.

    --
    -73, de n1ywb
    www.n1ywb.com
  25. Mom and Pop by geek · · Score: 3, Insightful

    Mom and Pop shops will be hurt by this. Notice this targets small busniess who probably run free software to reduce costs. Large companies can handle this, even find ways around it.

    I agree with it to an extent. I have a feeling breakins are far more common than any of us truely know. Only by making this public will the problem get better. Constantly pushing it under the rug is how MS has gotten away with security problems for so long.

    On the upside this law will help the IT industry since it'll create more IT jobs for network/security auiditing etc.

    I hate to see goverment medle in business matters, however the tech industry doesn't seem capable/willing enough to handle the security issues alone. I know most people are sick of it, and when people get sick of it, they start passing laws. The tech industry really has no one to blame but itself.

    1. Re:Mom and Pop by branchstudios · · Score: 1

      Mom and Pop shops will be hurt by this. Notice this targets small busniess who probably run free software to reduce costs. Large companies can handle this, even find ways around it. How many mom & pop shops do you know of that keep databases of social security & credit card numbers? This law is seems aimed at corporations & organizations that archive confidential information.

    2. Re:Mom and Pop by pavera · · Score: 1

      I disagree,
      big businesses are the one's with big names and everyone and their mom tries to crack their networks,
      small businesses on the other hand, are relatively unknown hence not very many hackers are going to be busting on the doors of the network, and most probably don't even have the IT staff to even know themselves that they've been cracked, therefore it won't matter, if mom and pop don't know how to read their network logs, they aren't gonna know that someone broke in, and mom and pop don't know how to read the logs, so in the end it doesn't change anything.

  26. How about security auditng? by gnovos · · Score: 3, Interesting

    "Breaking in" is an inherant part of security auditing, isn't it? In order to see if your computers are hackable one must, in fact, hack them. Would this law require that network security companies announce when they find a client's systems vulnerable, becuase technically it is a "break in"? If so, wouldn't the end result of that be companies completely ignoring security all together becuase the less they "know" about the break ins on thier own site, the less they have to report?

    --
    "Your superior intellect is no match for our puny weapons!"
    1. Re:How about security auditng? by mph · · Score: 2, Informative

      It would be a stretch to claim that confidential materials are compromised when the "break-in" was performed by staff (consultants, whatever) who are authorized to do so.

    2. Re:How about security auditng? by El+Volio · · Score: 2
      Would this law require that network security companies announce when they find a client's systems vulnerable, becuase technically it is a "break in"?

      Given that such auditing is either done by authorized internal personnel (I do this for my company), or by authorized external personnel (generally under a pretty draconian NDA), I don't think any confidential material is accessed without authorization. Whether the admin authorized it is besides the point; the directors of the corporation did, and that's what matters.

      --

      "You can never have too many elephants on your team."

  27. Whatever!!! by kevlar · · Score: 1

    If this was a law requiring companies to keep break-ins confidential you'd be bitching about that saying that these things should be made public knowledge!

  28. Hacker Trophy by Xandar01 · · Score: 1

    So now the hackers have a new trophy to go for. Their bragging rites will be "How many investigations failed to find you" Seems to offer the same kind of trophy for virus writers in regards to the virus rating schemes that some anti-virus vendor use.

    --
    Life moves pretty fast; if you don't stop and look around once in a while, you could miss it. -FB
  29. A good start, but flawed by Duderstadt · · Score: 3, Interesting
    I support the general idea of informing people theat their supposedly confidential or private information has been leaked or stolen.

    Even though I don't think it will do any good for the prevention of such crimes as identity theft, perhaps it will send a message that a tighter grip is required for confidential data.

    However, I see some problems. As one poster already noted, how do you enforce this if an admission has to be made voluntarily?

    Also, the 'loophole' is wide enough to drive a Mack truck through. It would prove very handy to business or government entities that did not want to disclose that they had been hacked.

    Of course, if the goverment really wants to help people who have had their private stuff lifted, perhaps the Feds should change the law so it is possible to get a new Social in case of theft. Your SSN can be used to create all sorts of havoc, but the Gov't will not give you another one, even if you can prove that someone is ruining your life with it. Very sad.

    1. Re:A good start, but flawed by Jaysyn · · Score: 1

      Can't you just tell them that your card was stolen/lost?

      Jaysyn

      --
      There is a war going on for your mind.
    2. Re:A good start, but flawed by trapvector · · Score: 1

      However, I see some problems. As one poster already noted, how do you enforce this if an admission has to be made voluntarily?

      wait a second. If I read the article correctly, if company X does not declare themselves h4x0r3d, they will be fair game for civil penalty.

      I ph33r 1337 14wy3rz. I would imagine that most business entities do as well. This might even give victims of identity theft some sort of recourse when their lives are still being ruined four years after they tried to clean up the mess that resulted from bungled security.

      There is no excuse for a person's vital records to be "accidentally" spilled out like so much sugar from a sugar-filled semi truck. Any legislation that would keep things like what happened to the state of CA from happening again is fine in my book; even if it doesn't pass the judiciary, it will at least stimulate discussion.

      on a side note, why do we even have the FOIA? so the bushies can make exceptions for the things that the act was supposed to let us see?

    3. Re:A good start, but flawed by Duderstadt · · Score: 1
      Yes, but with a caveat...

      The Social Security Administration will require that you prove to an administrive board that the use of your SSN by an identity thief is severe enough to merit the issue of a new SSN and the deactivation of your old one.

      I was told after someone had stolen my SSN and used it to acquire a Driver's license and a slew of credit cards that that was not good enough. Nothing is good enough. The official I talked to came out and clearly stated that the review board was a formality, and that no one ever got a new SSN.

      The reason is simple. The government and major credit institutions use Socials to identify individuals uniquely for life. The government especially is loathe to remove that identifier.

      Hell, my kids were issued Socials on the days they were born. The only way to escape a Social is to die.

  30. Need an investigation done? by Bald+Wookie · · Score: 1

    I'll investigate any break in or security breach for ten bucks a day. The following terms and conditions may apply:

    Minimum length of investigation: 20 years
    No more than 1 byte processed per day.
    Results cost extra.

    How about it? For a little over $3000 a year, you'll never have your reputation damaged by a hacker again.

    1. Re:Need an investigation done? by Xandar01 · · Score: 1

      Sneaky and underhanded like a lawyer but better. I like it. What's the URL of your consulting firm??

      --
      Life moves pretty fast; if you don't stop and look around once in a while, you could miss it. -FB
  31. Be very careful, i.e. slippery slope by geek · · Score: 3, Insightful

    Playing ignorant with law enforcment and the legal eagles is a dangerous path to take. I wouldn't advise anyone on it. They have much more time to screw with you than you do with them, and they play hardball. Not to mention they have the final word.

    A break in is unauthorized access. Period. It isn't even decided by the admin. What the admin wants is irrelevant, it's what the corporate executives want. If the execs don't want something open to the public, then someone publicly access it, the admin gets fired/sued and the person who broke in goes to jail. It's a very simple concept many of todays prima donna admins don't grasp.

    1. Re:Be very careful, i.e. slippery slope by oyenstikker · · Score: 2

      So if the admin puts something on the front page of the company's web site that the execs didn't want there, and I access it, I'm a cracker? Or more realisticaly, if I hit http://somecomputerat.somecompany.com:75248/ladeda /546415467534567/54556454.html wich has something the execs didn't want out, am I a cracker?

      --
      The masses are the crack whores of religion.
    2. Re:Be very careful, i.e. slippery slope by mindstrm · · Score: 1

      No, you aren't a cracker... the admin would perhaps be responsible.. but either way, if it's personal information that shouldn't be there, the company should report the breach.

    3. Re:Be very careful, i.e. slippery slope by oyenstikker · · Score: 2

      but there was no breach. just a bad decision on the part of the admin.

      --
      The masses are the crack whores of religion.
  32. Re:post 1001 by Anonymous Coward · · Score: 0
    It does my heart good to see an upstanding citizen such as yourself keeping the CLIT traditions alive. I salute you, sir!

    ---
    YourMissionForToday

  33. What constitutes an investigation? by teamhasnoi · · Score: 3, Interesting
    If I look at logs every other day? If I run Zone Alarm? Look at the screen with a magnifying glass? If I hang out on IRC and talk to script kiddies? An email to Steve Gibson? Call Encyclopedia Brown? Invite the Hardy Boys over (or Nancy Drew...grrrrr;)? Ask the kids? Call the cops weekly? Write my congressman? Watch Mystery Science Theatre 3000? Type 'Hacker +"My Computer"' in Google? Dust for prints? Listen to Prince? Buy a fedora? Tape the X-Files? Eat a unidentified mushroom? Hang out near the computer books at Barnes & Noble? Watch '20/20'? Puzzle over a "Where's Waldo" Sunday comic? Post to alt.are.you.hacking.me? Hide some X10 cameras in my floppy drive? Respond to "FIND OUT ANYTHING ABOUT ANYONE!!!!!!!" spam? Read the label? Check behind me occasionally? Smelling my shirt to see if it's clean? Submit an Ask Slashdot?

    Sounds like I could have an 'ongoing investigation' for the rest of my life.

    1. Re:What constitutes an investigation? by Anonymous Coward · · Score: 0

      as long as you wash your shirt every now and then, no one will mind...

    2. Re:What constitutes an investigation? by Anonymous Coward · · Score: 0

      The text of the law states:

      (c) The notification required by this section may be delayed if a
      law enforcement agency determines that the notification will impede a
      criminal investigation. The notification required by this section
      shall be made after the law enforcement agency determines that it
      will not compromise the investigation.

      So at the very least they need to notify law enforcement.

    3. Re:What constitutes an investigation? by Anonymous Coward · · Score: 0

      Just look at OJ's "search for the true killer" http://worldwidemart.com/sapienza/html/oj/

  34. Why is their reputation that important? by rebill · · Score: 2, Interesting

    <Quote>

    Small businesses that don't have the resources to maintain an investigation will have their reputations ruined

    </Quote>

    I'm sorry, but if the choice is between their reputation and not knowing that some joker out there can steal my hard-earned cash at a moment's notice because he has my credit card information, I think I'd choose wrecking their reputation.

    --

    Chivalry is not dead, it's just frequently misspelt. - M. Langley

  35. Could have the opposite effect.. by EvilStein · · Score: 4, Interesting

    Companies might just pour millions into Microsoft's own services. After all, Microsoft has pledged to make security its #1 priority these days.

    Microsoft may just sell companies its own security and consulting services, or companies will simply hire any one of the thousands of unemployed paper MCSE drones that are now floating around.

  36. Kind of slanted viewpoint, isn't it? by ethereal · · Score: 5, Insightful

    First off: I submitted this yesterday with a much less biased writeup. "Luck of the editor", I guess. My overall /. submission record is now 2 and 16.

    Second: the problem is not big business vs. small, or even public sector vs. private. The issue is confidential data about the public and what expectation the public should be able to place on those who promise confidentiality. I don't think it's unreasonable for the legislature to define what that expectation is, the same way they define what the expectations on a company are in terms of pollution or accounting or workplace safety. Businesses have to meet certain standards to operate in a particular region; doing what they say with respect to confidential customer data is just one more standard, and probably a more important one than some of the other standards a business has to meet.

    The argument that disclosure harms enforcement and education is only true as long as disclosure isn't mandatory for all. Once there's no longer a choice about disclosure, the public will quickly learn who can be trusted, and law enforcement and the business community will quickly learn what are the most common security issues to address. The marketplace will quickly put an appropriate premium on security once this law forces information about lax security out into the open. It's an effective way of letting the public determine how important security is - this is a much better solution than the state just requiring a particular patch level or certification or something like that. We say we don't want the state dictating how software is written - ensuring full disclosure of software faults is a great way to allow the public more voice in determining the right tradeoff, rather than having the state do it.

    And if a vulnerability is discovered for which there isn't a patch yet, some people ask whether the company should be in trouble for not taking their systems off the 'net and getting 0wn3d. Of course they should! Their inability to plan a secure and maintainable computing infrastructure should not necessitate the exposure of my personal data to all and sundry. Just like the BIA, if you can't show that you're secure, you need to be off the 'net. This will have the effect of placing a premium on computing platforms that are quicker to patch when security problems are found, likely making Open Source solutions more popular. All in all, it's a win-win-win situation once the adjustment period is complete.

    --

    Your right to not believe: Americans United for Separation of Church and

  37. See No Evil by RAMMS+EIN · · Score: 2

    ``This is not good''
    And ``see no evil, hear no evil, speak no evil'' is?

    Break-ins are a reality. It happens. IMO it's better to be open about it. If I were a customer of a company whose network got cracked, I would rather know that it happened and what measures are being taken to prevent this in the future than to be told nothing and later find out by different means (possibly painful).

    Openness could also result in a better understanding of what software/people/practices lead to lower or higher risks of break-in, and improve security accross the board.

    I also disagree that this law favors large businesses. Small businesses can carry out investigations just as well, and even investigations carried out by large companies come to an end, after which the break-in has to be disclosed. Bogus investigations aren't harmed by disclosure, so that's not a real option. Wealthy corporations _do_ mess with laws to the detriment of small businesses in Real Life, but I don't see this law making it much worse.

    --
    Please correct me if I got my facts wrong.
  38. And In Other News... by Tha_Big_Guy23 · · Score: 1

    Yahoo is planning to move their entire company to Grand Forks, North Dakota....Company representatives were unavailable for comment at this time.

    --
    If you're looking here for something insightful or thought provoking, you're probably looking in the wrong place.
    1. Re:And In Other News... by trapvector · · Score: 1

      YES!!!

      I told the world that we could be the next Silicon Valley... but nobody listened...

      (maniacal laugh) ...ahem.

  39. Oh great... yippie... wahoo... whatever by Xiver · · Score: 1

    Hmmmm... So if I don't like the company I work for I can just do a little inside hacking job to ruin their reputation and move on. Sounds great.

    I wonder how many times Slashdot has been hacked that we don't know about.

    --
    10: PRINT "Everything old is new again."
    20: GOTO 10
    1. Re:Oh great... yippie... wahoo... whatever by Anonymous Coward · · Score: 0

      Not if their security is good enough, no.

      Most attacks come from the inside anyway, so you'll just be one among many.

  40. Lawmaker Cluelessness and Double-Standard by limekiller4 · · Score: 4, Funny

    On one hand you have lawmakers calling hackers 'thugs' and 'criminals' because -- and this is generally after months of reporting the problem to, say, Microsoft -- they notify the public that there is a security hole.

    NOW they're going to make it illegal to not notify the public. Is telling the world about a security breach irresponsible or isn't it?

    Yeesh. I feel like the whole gang from Bloom County who didn't know if they were watching "F Troop" or CNN and thus whether they should be enjoying the carnage or not.

    --
    My .02,
    Limekiller
    1. Re:Lawmaker Cluelessness and Double-Standard by John+Hasler · · Score: 2

      > NOW they're going to make it illegal to not
      > notify the public. Is telling the world about a
      > security breach irresponsible or isn't it?

      But they are not required to reveal any details. The typical "disclosure" will appear in the legal notices section of a newspaper of record or some such thing and will look like this:

      "There was a break-in at Amazon some time in the
      last two weeks. Some customer data may have
      been compromised."

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    2. Re:Lawmaker Cluelessness and Double-Standard by limekiller4 · · Score: 2

      John Hasler writes:
      But they are not required to reveal any details. The typical "disclosure" will appear in the legal notices section of a newspaper of record or some such thing and will look like this: "There was a break-in at Amazon some time in the last two weeks. Some customer data may have been compromised."

      If it is that vague, what is the difference between forcing the people running the software to admit there was a break-in and forcing those who created the software from admitting there was a breach in their product? Why not require software manufacturers to release known security holes? That's closer to the root than this initiative is.

      If you take the position that the admin should have secured the software, how do you know that? The information is sufficiently vague as to leave the culpability an unknown variable.

      The end-result is "Some Company, Inc. was broken into and data was compromised," which looks terrible for Some Company, but you won't hear "...because of an unpatched and unacknowledged bug in Win2k that the admin couldn't either know or do anything about" because revealing the exploit is illegal, or at least professionally dangerous.

      Look, I'm not flaming you and I'm VERY big on letting people know when their data has been compromised but why does the fan poop only get as far as the victim? That just seems inherently unfair unless the blame does turn out to be theirs.

      --
      My .02,
      Limekiller
    3. Re:Lawmaker Cluelessness and Double-Standard by John+Hasler · · Score: 2

      > If it is that vague, what is the difference
      > between forcing the people running the software
      > to admit there was a break-in and forcing those
      > who created the software from admitting there
      > was a breach in their product?

      None. Neither would do a damn thing but complicate the lives of those required to comply. That's why I oppose such laws.

      > That just seems inherently unfair unless the
      > blame does turn out to be theirs.

      The blame _is_ theirs. They selected the software, they put up the site, they administered it, and they put the confidential data on it. They may have a claim against their software supplier if he misled them, but that does not lessen their liability for their own actions.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  41. Trolling for Karma by nege · · Score: 3, Funny

    Microsoft.

    0 break-ins reported, 7,435 break-ins currently being investigated.

  42. Get your facts straight by Duderstadt · · Score: 2, Interesting
    This will hurt Microsoft. Since IIS has the largest market share on web servers, they will be hit hardest when these security breaches come to light. People will realize that Linux is a more secure, easier-to-maintain alternative.

    What? Since when did IIS overtake Apache in web server market share?

    This will create jobs. Small businesses who might have otherwise adopted IIS and foregone the overhead of an IT staff will be forced to take a more active role in keeping their systems secure. Although it may hurt some small businesses, the net overall effect is to redistribute wealth into our pockets and increase our pay overall, which is indisputably a Good Thing(tm). Never opened a small business, eh? Let me enlighten you. Most small business (under 50 employees) are sole proprietorships or partnerships started by either a single person or a small group of individuals with limited resources.

    These shops use MS Windows and IIS for the following reasons:
    1: It is similar to the machine used at home. For someone who has used Win9x or NTx Workstation, Windows Servers are pretty easy to get started with.
    2: Most of the services (file sharing, email, web) are free as in beer with Windows.
    3: It is prety easy to set up a decent site with Front Page.

    Debian will benefit. Debian's "apt" facility is extremely simple for end-users to use and understand, and helps system administrators keep large numbers of boxes up to date without causing RPM hell or any other conflicts that one may experience when using a distribution like RH that does not regression test their patches.

    Only in Linux Land. Since when did apt become easier than Windows Update?

    Script kiddies will have to find new targets. The logical next step for script kiddies, once e-commerce sites have been secured, is government sites. This will encourage the government to adopt Linux more widely, in place of insecure and unreliable Windows NT systems. In fact, it may even create grounds for breaking their contract with Microsoft.

    Wrong again. I have contracted for the Fed and much of their critical stuff not only runs on MS, it is secure as all hell. In fact, the biggest vulnerabilty in the gov't systems I have seen has been the fact that several different platforms and apps are in use - a network admin's nightmare. (e.g. MS Windows of all vintages, SOLARIS, AS/400, OS/390, a dozen different databases, etc.)

    Please, not everything in the world that takes place is related to Linux. Give it a rest.

    1. Re:Get your facts straight by dmaxwell · · Score: 2

      "Only in Linux Land. Since when did apt become easier than Windows Update? "

      It really can be. It is very easy to hit Windows Update watch it download and install a few things and think you're OK. At least, this is true for nontechnical users. For a new install of Windows 2000 or 98, it will be necessary to hit Update several times. Once to get the current service pack (reboot) then it's time to get the Critical security patches. Ooops, one of them has a run-time dependency so we have reboot again to get the last critical update. Now we have to get IE's service pack (reboot) and the fixes since the update came out (reboot). One can count on at least four reboots for 98 and probably three for 2000. I wouldn't be surprised if XP takes at least two visit Update and reboot cycles. What's so fricken easy about that? On Debian machines it apt-get update, apt-get upgrade, answer some easy questions, and done. Only kernel updates necessitate rebooting. Any admin who thinks that is difficult is too dangerous to expose machines to the net.

      "Please, not everything in the world that takes place is related to Linux. Give it a rest."

      Agreed, but admit Windows ease-of-use isn't what it's cracked up to be. Many Windows cheerleaders trumpet how "easy" Windows is but when issues are pointed out say "but that doesn't happen if you know what you're doing" thus kicking the legs out from under their "easy" argument. A properly adminned Windows no easier or harder to deal than Linux or one of the BSDs. It IS much easier to mismange Windows since it papers over necessary details with pretty buttons and wizards.

  43. These should be reported. by fanatic · · Score: 2

    the article doesn't mention ...where a break-in occurs because of a(n) ... issue for which there is no released technical solution (i.e. anyone else who has software X would be susceptible...).

    So companies/whatever which can't be bpthered to patch their holes get a buy? I don't think so.

    --
    "that's not encryption - it's a new perl script that I'm working on..." - from some Matrix parody
    1. Re:These should be reported. by perp · · Score: 1

      >> the article doesn't mention ...where a break-in
      >> occurs because of a(n) ... issue for which there
      >> is no released technical solution (i.e. anyone
      >> else who has software X would be susceptible...).

      > So companies/whatever which can't be bpthered to
      > patch their holes get a buy? I don't think so.

      The poster was talking about vulnerabilities for which there is *no* solution. A patch is a technical solution.

      People who don't patch in a timely way *should* get into trouble, but that doesn't apply to the first site that gets 0wn3d via a previously unknown exploit.

      Nevertheless, if the customers' private information has been compromised, the customer should be informed no matter who is to "blame".

      --
      There are two kinds of sysadmins: paranoids and losers. I'm both kinds.
    2. Re:These should be reported. by fanatic · · Score: 2

      The poster was talking about vulnerabilities for which there is *no* solution. A patch is a technical solution.

      I was referring to the case where the maker of the software goes weeks or months before producing a patch or even acknowledging the problem. These should be disclosed, as people should not be using this software, long term.

      Even the first occurrence should be disclosed. How many "first times" will we permit before expunging wu-ftpd from the planet?

      The point this raises is that not all cracks are the admin's fault for not patching - but software choice also is a factor.

      --
      "that's not encryption - it's a new perl script that I'm working on..." - from some Matrix parody
    3. Re:These should be reported. by perp · · Score: 1

      Actually, I'm right with you on all of this, but I don't think there's an easy solution. I run bind on my external servers, one of which is still at a version that uses bind8. It's easy to say that I "should" have upgraded it to a more recent OS that uses bind9 (which seems to be quite a bit better) or "should" have installed some other named (thereby breaking the auto-updating that does more for system security than anything else).

      I can (and do) keep things patched, but I don't have the time to maintain custom installs or upgrade the OS version on all my servers every time there's a minor release. If ISC doesn't notify SuSE of bind exploits, *I'm* the one that gets it in the shorts. I am really angry at ISC and am looking forward to an explanation. Grr.

      OTOH, people who run wu-ftp on external servers are clearly not paying attention. They're not reading BugTraq and they're not reading this thread. Eventually, all these boxes will get 0wn3d and then reinstalled with something more secure, but that seems like a really slow and painful way to increase overall security. Enough of this and either the authors will fix an app or vendors will stop shipping it. As a matter of fact, that's what happened with bind - a total rewrite due to hot and cold running exploits in the original code base.

      --
      There are two kinds of sysadmins: paranoids and losers. I'm both kinds.
  44. You want the truth? by Anonymous Coward · · Score: 2, Insightful

    You can't handle the truth!

    Every day I stand on my wall watching for intruders and protecting my web servers. Web logs indicate that my servers survive a constant barrage of attacks.

    Most attacks fail however every once in a while some lucky script kiddy, or spammer finds a chink in the armour.

    Where do you draw the line on what needs to be reported? Last week a spammer found that a poorly configured formmail.pl script on one of my servers and used it to send their spam.

    If the law allows judgement calls where a company is only required to report serious breaches then a company would try to have everything classified as trivial.

    On the other hand if a company is required to report every possible breach then the company might try to flood the public with a bunch of trivial information like a formmail script that was abused for a few hours, and then try to bury a serious problem inside the noise.

  45. Sure, scare the bejezus out of the llama cash cows by Killall+-9+Bash · · Score: 3, Funny

    I'm Mr. Average Invester.
    I find out that my #1 favorite stock i dumped thousands into on the advice of my dentist has recently fallen victim to a 11 year old IRC junkie.

    Do I:
    a. invest more money in my company, showing appreciation for the companies candor.
    b. Murmur something very Zen to myself about the strongest tree bending in the wind, while noteing the fact that no real damage was done.
    c. put a humming bird to shame franticly clicking the refresh button on IE6, neuroticly waiting for the stock to move a tick up or down.
    d. scream "SELL SELL SELL" into my cellphone while barely avoiding a headon collision in my SUV.
    e. dump all of my money into precious metals and move to an obscure island nation in preperation for the inevitable global ecconomic collapse.


    and.... pencils down.

    --
    "Prediction: within 10 years, Windows will be a Linux distribution." Me, 7-6-2016
  46. Why aren't you at the beach right now? by teamhasnoi · · Score: 2

    AppAssure lets you watch your data center 24 x 7,
    even when you're not there. More Info

  47. Why the complaints? by mao+che+minh · · Score: 2

    Laws like these will force companies away from overly insecure Microsoft products and force them to actually care about security. With a more concerted effort towards IT security, our personal data will become safer, and alot of high paying security and Linux related jobs should open up. Why would anyone here complain?

    1. Re:Why the complaints? by brickbat · · Score: 1

      Why would anyone here complain?

      I probably wouldn't, if the law applied only to government-controlled systems. The government should notify the public of such incidents--particularly if they compromise the records of its citizens.

      But to force private businesses to meet the same level of disclosure is just another misguided attempt to protect our privacy--and hypocritical, too, considering how individual privacy is violated by the government on a daily basis. Businesses do have an ethical obligation to inform customers if their personal information has been compromised--but it needs to be done after an investigation indicates that such is the case. Some script kiddie who manages to replace a company's home page with "w3 own joo!!" shouldn't raise the same alarm as a breach of the state's payroll system--but it seems that is precisely what this law would do. Broad attempts at protecting the public interest usually comes at the expense of private rights.

  48. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  49. Where do you live? by DAldredge · · Score: 1

    Where do you live that has logical thinking consumers?

  50. pwn3d j00!! by Anonymous Coward · · Score: 0

    mebbe *you* should get with the pr0ngram, bizzitch. It's 'pwn3d!!'

  51. Re:Sure, scare the bejezus out of the llama cash c by susano_otter · · Score: 2

    1. Buy Microsoft products
    2. Exploit MS security holes
    3. Disclose information about the break-in
    4. ???
    5. Profit!

    May I be excused, now?

    --

    Any sufficiently well-organized community is indistinguishable from Government.

  52. Security Darwinism by Senator_B · · Score: 1

    What this will do is weed out companies that lack the responsibility to maintain safe and secure computers. Responsibility doesn't cost money, any company can afford to keep their servers updated and properly patched. The size of the company does not matter either, if the company is small, chances are they don't have massive server farms that need 20 man teams watching them around the clock. Ideally the amount spent on computer security should be proportional to the annual revenue.

  53. RTFA, lackwit by Anonymous Coward · · Score: 0

    nuff said.

  54. hmmm by Anonymous Coward · · Score: 0

    At first this slant slashdot has taken to program the slashbots to think this law is bad seemed odd.

    Then i remembered they just moved to the west coast.

    Slashdot wouldn't want to have to public post reminders of all the times it got hacked.

    The best one was when they didn't even use a vulnerability! The shit was just configured so fucking poorly that they did it without exploiting anything but stupidity!

    HAha! Slashdot likes to laugh at other companies that get hit by some kiddie with a 0 second spoilt but when slashdot gets hacked becuase they completed misconfigured the fucking site they just laugh sheepishly and no one hears anything about it ever again unless you had the good fortune to catch the defacement before it was covered up.

  55. Text of new California security/privacy law by (ok.whatever) · · Score: 1

    The new California computer security/privacy law referred to in the Business Week article is available here: http://info.sen.ca.gov/pub/bill/sen/sb_1351-1400/s b_1386_bill_20020926_chaptered.html

  56. Loopholes by overshoot · · Score: 2
    Big companies will have the resources to set up investigations even when they know it is unlikely to get anywhere, and business will go on as usual for them.

    No, because

    The only loophole is if there is an ongoing investigation and if the disclosure would harm the investigation.

    Emphasis added.

    --
    Lacking <sarcasm> tags, /. substitutes moderation as "Troll."
    1. Re:Loopholes by Anonymous Coward · · Score: 0

      Oh ya i'm sure some huge corporation could never get a lawyer to make that case...

      duh, let's not be fucking naive mmmkay.

  57. Re:Hello? It's only when confidential info is leak by Anonymous Coward · · Score: 0

    Well the quickest way to compliance is to purge all social security, credit card and user info (could be a good thing) or maybe put the info on a system with an "air gap" between it and the internet and in a secure room. (not all that useful) The reality is that businesses will ignore it till one of them gets busted with it. They'll watch and see what happens then decide if they want to take steps or live with the consequences. Since the gov't sites are just soooo secure I can see how the gov't is in misery and they want company. Should be interesting to see how fanatical they are about disclosure when they get held to their own law. Maybe they should purge their records. Why exactly do they need that info. Oh Right! Control the public, rather then serve. hmmm... Now why did the OLD social security cards used to have the words "not to be used for identification" printed on them again? hmmm... need social security for job or no money. no money equals ineffective voice. hmmm... present papers at checkpoints. Yup! free country alrighty. Oh well too many deep thoughts. Ignorance is bliss ahhh...

  58. Personally by Anonymous Coward · · Score: 0

    I have thought about owning some stock in several large companies who run MS and then waiting for a break-in. Once it happens, start a law suit about bad management.

  59. Text of bill available online by Anonymous Coward · · Score: 0
    From the description in the report I'm guessing the legislation being discussed is Bill No. AB 700, "An act to amend, renumber, and add Section 1798.82 of, and to add Section 1798.29 to, the Civil Code, relating to personal information."

    Here's the text of the bill

    I haven't read all the way through, but one important point right at the top says:

    The bill would
    permit the notifications required by its provisions to be delayed if a law enforcement agency determines that it would impede a criminal
    investigation.

    which means that internal "investigations" to conceal security incidents probably won't work.

    That doesn't mean there's no bias against the little guy, though... big companies are more likely to be able to get long, involved criminal investigations going. But still, when the investigation is over, the info becomes available.
  60. Stupid... by DannyO152 · · Score: 2, Insightful

    Like a fox. Jane Legislator has to show the constituents that she's getting things done and preferably things that look good in the newsletter (because there is no significant news coverage of state legislative affairs.) Constituents are worried about their credit cards being stolen over the internet, so what to do? Make it against the law to steal the info? Been done. Make it against the law to enter into the servers? Been done. Make it against the law to not report that you've had a break-in? Bingo!!

    So, it sails through committee, the floor, the other house because John and Joe Legislator want to be on record (and show in their newsletters) that they are doing something(tm) about that internet id theft.

    After it's on the books, people look at it and realize that it is unclear, misguided, and not enforceable, but that wasn't the ultimate purpose was it? Plus fixing it or adding more practical legislation gives Joe, John, and Jane something to do next year.

  61. Interactions with Berman cyber-vigilante billl? by extremecenter · · Score: 4, Funny

    So if Ca. Congresscritter Berman's cyber vigilante bill passes, there will be a surefire method of dealing with pesky business competitors: attack their systems on the pretext that they might have some of your copyrighted data. If they report the breakin, they'll get bad publicity. If they don't report it, have your lawyers point out that fact to the appropriate authorites and they get busted for not reporting the breakin, also generating bad publicity for them. On the upside, this looks like a full-employment bill for security types.

  62. Big businesses vs. small businesses by allism · · Score: 1

    It's just as easy for a small business to say, "Yes, we are still investigating this" as it is for a big business to do so--I didn't notice anywhere that concrete proof of an ongoing investigation was necessary. Matter of fact, it may be easier for a small business to argue that their investigation is still ongoing, since they could easily contend that their resources to investigate are limited.

    Your 'special clauses' solution also provides a bias for big business, since larger businesses are more likely to be able to afford the attorneys to get the court orders every time they are hacked - whereas mom and pop businesses could easily go out of business just from the legal fees, not to mention that the mom and pop businesses are more likely to abide by the letter of the law instead of playing fast and loose.

    Besides, it is much more likely that a big corporation would have a judge in their pocket than a small company.

  63. What makes an "attack" or "break-in"? by Anonymous Coward · · Score: 0

    So where's the cut off for how severe an attack is before it has to be reported? Do I have to report that some WaReZ vendors guessed our FTP password (it's really not hard and we give it out to customers all the time) and uploaded some software? Do I have to report when someone vandalizes our site? What about if they break into a database that contains non-vital data? Or data that has been encoded? There are many types of attack that are mere annoyances. Do these need to be reported?

  64. Because. by mindstrm · · Score: 2

    I believe the assumption is that if there is any kind of personal/private information on customers stored there, people should have a right to know that it has been potentially stolen.

    If the video store is broken into, and someone steals some tapes, I don't care.

    If their database of customers and credit card info, identification, lending habits, etcetera, is stolen, I want to know about it.

    1. Re:Because. by Anonymous Coward · · Score: 0

      Your data doesnt come with little tags that say "hey I've been read by someone!"

  65. I was hacked by... by ADRA · · Score: 2



    Take that, US Gov!

    --
    Bye!
  66. Re:Hello? It's only when confidential info is leak by unicron · · Score: 2

    What's funny/scary is that someone used your card to buy a wife, opium, or a suitcase nuke..possibly all 3 depending on your limit.

    --
    Finally, math books without any of that base 6 crap in them.
  67. Re:post 1001 by Anonymous Coward · · Score: 0

    Life does not stop and start at your convenience, you miserable piece of shit.

  68. The consequence is simple... by Kindaian · · Score: 2, Funny

    Big corporations will have an internal investigation department and thrus never reveal nothing...

    Small corporations will simply classify the event as "computer malfunction" and reinstall all the software and document the event as such...

    In the end, California will be the only place in the world where there isn't any break in at all... at least reported publicly...

    Cheers...

  69. Better than you think by karlm · · Score: 2
    Also, the article doesn't mention the contingency where a break-in occurs because of a software/hardware issue for which there is no released technical solution (i.e. anyone else who has software X would be susceptible to the same type of break-in). This is not good."

    It's almost never in the public's best interest to hide vulnerabilities from them, even if there's no solution. If one person has exploited one system, there are almost certainly other victims and the numbers will almost certainly continue to grow. Most are probably undetected.

    Even if there is no fix out there, it gives people the option to reevaluate the need to run the system, and also consider switching solutions/vendors. The "bad guys" are going to know if you say somethign or not, while telling all of the innocent bystanders lets at least some of them protect themselves.

    --
    Copyright Violation:"theft, piracy"::Anti-Trust Violation:"thermonuclear price terrorism"<-Overly dramatic language.
  70. Misleading by krangomatik · · Score: 4, Informative

    After reading the text of SB1386 (the Bill referenced in this article) I think the Slashdot blurb on this was a bit misleading. California isn't demanding "Public Disclosure Of Break-Ins." This makes it sound like whenever there is a break in it must be disclosed. This isn't really the case. Notifications only have to take place when the following criteria is met: "personal information" means an
    individual's first name or first initial and last name in combination
    with any one or more of the following data elements, when either the
    name or the data elements are not encrypted:
    (1) Social security number.
    (2) Driver's license number or California Identification Card
    number.
    (3) Account number, credit or debit card number, in combination
    with any required security code, access code, or password that would
    permit access to an individual's financial account.
    (f) For purposes of this section, "personal information" does not
    include publicly available information that is lawfully made
    available to the general public from federal, state, or local
    government records.


    As for this "investigation" loophole this only applies to ongoing investigations being conducted by law enforcement agencies. I know that a large company may have a bit more clout in getting an investigation started, but even so they can only delay disclosure if "a
    law enforcement agency determines that the notification will impede a
    criminal investigation."
    So I'm not sure how big of a "loophole" this is.

    As for the notification methods, it doesn't look like full public disclosure is what the bill is aiming at. It looks more like they just want the people who's information was compromised to be notified. Here is the section on notification:
    (g) For purposes of this section, "notice" may be provided by one
    of the following methods:
    (1) Written notice.
    (2) Electronic notice, if the notice provided is consistent with
    the provisions regarding electronic records and signatures set forth
    in Section 7001 of Title 15 of the United States Code.
    (3) Substitute notice, if the agency demonstrates that the cost of
    providing notice would exceed two hundred fifty thousand dollars
    ($250,000), or that the affected class of subject persons to be
    notified exceeds 500,000, or the agency does not have sufficient
    contact information. Substitute notice shall consist of all of the
    following:
    (A) E-mail notice when the agency has an e-mail address for the
    subject persons.
    (B) Conspicuous posting of the notice on the agency's Web site
    page, if the agency maintains one.
    (C) Notification to major statewide media.
    (h) Notwithstanding subdivision (g), an agency that maintains its
    own notification procedures as part of an information security policy
    for the treatment of personal information and is otherwise
    consistent with the timing requirements of this part shall be deemed
    to be in compliance with the notification requirements of this
    section if it notifies subject persons in accordance with its
    policies in the event of a breach of security of the system.

    So there doesn't appear to be what I would consider a "full disclosure" requirement anywhere in this. It looks like you've got to notify the people who's info got out, which seems reasonable to me.

  71. CA is far more influential than MS by mangu · · Score: 2

    How often do you read about new laws from Mississippi?

  72. DCMA and EULA conflicts??? by djfatbody · · Score: 4, Insightful

    Consider the recent RedHat patch that boiled down to "you should run this patch but we can't tell you why" and the lawsuits where large software giants have threatened lawsuits because possible exploits were released before they the company was notified and allowed to investigate internally. Is it possible that a company may disclose the details of its incident and end up in violation of the DCMA or their EULA's?

    1. Re:DCMA and EULA conflicts??? by crusher-1 · · Score: 1

      As far as conflicts with the DMCA, we're dealing with a possible conflict between federal and state laws. EULA's are a different matter IMHO. Normally, any statute will superside most business contracts or licensing conditions that come into conflict. It's like, a license stipulates that you agree to "X" condition in order to use/install a given piece of software. Essentially the user is ceding a right in order to use a product. However if the law, either implicitally or explicitally states that certain violations of certain rights or prohibits certain actions that one would find in an EULA, i.e. as stated before, you relinquish a right by agreeing to condition "X". then condition "X" is non-enforceble in the license because it essentially violates the conditions of a statute.

      Now, the question arises - Who is the one that has the mandate to disclose? One would presume that the "public business" would be the one - as per the mandate of the statute. However I wonder just how one would know when a said break in happened?

      So, company Y was broken into, hacked, cracked, and/or pilferred (let's say for user/member info - e.g. personal info or credit cards #'s). How exactly is this info about the break in or breach to be released?

      I would like to point out why companies don't like to do this. While in security training a tale about a major bank a how they got ripped of was told.

      A security guard that was stationed at a major deposit/holding vault decided to take one $1 million bearer bond for 30 days. The guard had worked at this particular vault for quite a few years and had explicit knowledge of it's workings and routines (e.g. the cycle of audits, how often certain products and materials were used). So the guard understood that his chance of success was high. After 30 days (translated into $30 million in bearers bond) the guard took the 1st flight to Brazil, deposited the $30 million at 100% interest (yes, that's right 100% annual) and laid back (and low) for a year. After that year he hired the best lawyer money could but (which one would presume was a pretty good lawyer) and had the lawyer contact said bank. Mind you the man has now $300 million dollars in a Brazilian bank. He offered to return the original $30 million plus a nice percentage on top to the bank if they agreed not to pursue the matter. The bank was more than happy to do so - they got the money back and made a nice little extra on top. As soon as the deal was done the man returned to the United States to live in the lap of luxury. The bank never reports the incident in the 1st place due to embarassment - would you deposit you money in a bank that had such lax security (the bank reasoned).

      The point is that most major companies or corporations avoid this kind of bad press like medival Europeans avoided the Black Death. I can't see how any company would be anywhere near compliant with this statute. Like wise the law would be best used for whistle blowers. A security flaw is uncovered that the institution would like to keep a lid on. And, as is often the case, it puts it's investors and member/client's at some risk. So, the fineties of this statute are going to be of interest. Will it help to secure investors and consumers or just be a paper tiger?

  73. There IS _Always_ A Technical Solution by John+Hasler · · Score: 2

    > Also, the article doesn't mention the contingency
    > where a break-in occurs because of a
    > software/hardware issue for which there is no
    > released technical solution (i.e. anyone else who
    > has software X would be susceptible to the same
    > type of break-in). This is not good."

    If "software X" (e.g., IIS) is broken quit using it. If you can't figure out any way to secure your system short of taking down your server, tough shit. "We can't figure out any other way to do it" is no excuse for compromising your customer's confidential information.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  74. Re:Sure, scare the bejezus out of the llama cash c by Anonymous Coward · · Score: 0

    1. Kick susano_otter's arse
    2. ???
    3 Profit!

  75. What sets the Jurisdiction? by QuantumRiff · · Score: 2

    Does the company have to be incorporated in CA, have offices there, or just their servers? Also, does the break in have to happen in California, or do they have to report it if the CA companies datacenter in New York gets hacked?

    --

    What are we going to do tonight Brain?
  76. Please engage mind before putting mouth in gear. by Animats · · Score: 2

    It may be too much to ask that people submitting items that reference published articles read the articles first. But, as often seems to happen, the Slashdot "editors" didn't read the article either. This isn't going to improve their job prospects after VA Linux/Software/Burgers/whatever finally tanks..

  77. IT IS ABOUT TIME by Anonymous Coward · · Score: 0

    Now a company can point to a DAMAGE that has LONG been accepted by the courts. I think this is just the 1st step in holding software companies to the same liabilty all other products have.

  78. There's no accounting for taste, by twitter · · Score: 2
    but IQ is heriditary. You say:

    This isn't your 'internet' it's that of those who own the hardware. I find this false sense of ownership childish and tasteless.

    I say, bullshit. The net is mostly built on public right of way. That makes it mine, yours too unfortunately. The order of slavery is enforced by brute repression. In any case, the net will be worthless without mass participation or it becomes a one way push fest like TV or something. Oh yeah, we own the airwaves too, I keep forgeting that.

    Eggplant man, does that mean "eat me"?

    --

    Friends don't help friends install M$ junk.

  79. Disincentive for Regular Internet? by Anonymous Coward · · Score: 0

    Perhaps, they are afraid of the TRUTH.. If you've been following c-span lately, you'll notice that there is a hidden war going on. This war on terrorism is really a spiritual battle of "arthodox catholic views" and the true Gospel of our lord and savior Jesus Christ, which is against the catholic view of "under the law, under the law, SIN, SIN, SIN!" People should know by now that works of the law are fruitless! For as many as have sinned without law shall also perish without law: and as many as have sinned in the law shall be judged by the law; 13. (For not the hearers of the law are just before God, but the doers of the law shall be justified. What exactely is the law now people, sin unto death or obediance unto righteousness! 10. For with the heart man believeth unto righteousness; and with the mouth confession is made unto salvation. 11. For the scripture saith, Whosoever believeth on him shall not be ashamed. 12. For there is no difference between the Jew and the Greek: for the same Lord over all is rich unto all that call upon him. 13. For whosoever shall call upon the name of the Lord shall be saved. 14. How then shall they call on him in whom they have not believed? and how shall they believe in him of whom they have not heard? and how shall they hear without a preacher? 15. And how shall they preach, except they be sent? as it is written, How beautiful are the feet of them that preach the gospel of peace, and bring glad tidings of good things! 19. Now we know that what things soever the law saith, it saith to them who are under the law: that every mouth may be stopped, and all the world may become guilty before God. 20. Therefore by the deeds of the law there shall no flesh be justified in his sight: for by the law is the knowledge of sin. Governments need to be be very careful on how they are to "isolate and torture" those who don't bow down to their ways of SIN AND DEATH and do just as "johnny should do", these people are nothing more than "salt of the earth", to be cast out, and trodden under the foot of men who are in authoritative positions in governments around the world. So take heed those who believe the TRUE OXYMORON of "separation of church in state", if you dare preach a different gospel than the ones the states and catholic churces endorse(works unto death), you will be cast out and discriminated against way worst than the blacks had during the sixties.

  80. Re:Sure, scare the bejezus out of the llama cash c by hawkfan · · Score: 2, Funny

    1. Buy Microsoft products
    2. Exploit MS security holes
    3. Short MSFT
    4. Disclose information about the break-in
    5. Profit!