Personal Data Exposed! Can Legislation Fix It?
rabblerouzer writes "Millions have had their personal information stolen because of lax security and may not even know it because of the patchwork of state laws that fail to mandate timely notification of victims. Boston-based law firm Mintz Levin is seeking feedback on what you would like to see included in draft legislation."
I know we're just one law short. With one more law, nothing will ever go wrong and everyone will live forever. Just one more law.
I'm sure this is the one. No one will accidentally release anyone's private details when it's illegal.
Why haven't they made getting in a car accident illegal?
Currently, vendors losing data typically offer 3 months of identity detection, as if that does anything. Criminals can simply wait 3 months and begin stealing identities freely, as most people cannot afford to purchase these costly (and largely useless) services. Unless vendors are presented with liability, as are most other businesses, data will continue to be lost all the time. There is virtually no cost to losing data.
Why you shouldn't force notifications to customers
-Zero day exploits: crooks will rush to do zero day exploits as an official confirmation will prove they've got good data (so more sophisticated gangs will buy it from them, most fraud happens in the first 24 hours)
-Honeytrap: When identity theft occurs law enforcement agencies may wish to honeytrap the thieves by letting them use the say credit card details & thus tracking them.
-White Noise Defense: smart companies ought have "white noise" dud systems, easily hacked containing white noise data with honeytrap triggers (eg a valid credit card number but one that belongs to say FBI) in it !
- and so on.
But they should be forced to notifiy law enforcement agencies.