Personal Data Exposed! Can Legislation Fix It?
rabblerouzer writes "Millions have had their personal information stolen because of lax security and may not even know it because of the patchwork of state laws that fail to mandate timely notification of victims. Boston-based law firm Mintz Levin is seeking feedback on what you would like to see included in draft legislation."
I know we're just one law short. With one more law, nothing will ever go wrong and everyone will live forever. Just one more law.
I'm sure this is the one. No one will accidentally release anyone's private details when it's illegal.
Why haven't they made getting in a car accident illegal?
Televised ritualistic testicular hangings as punishment. Two strikes and you're sterile.
Why you shouldn't force notifications to customers
-Zero day exploits: crooks will rush to do zero day exploits as an official confirmation will prove they've got good data (so more sophisticated gangs will buy it from them, most fraud happens in the first 24 hours)
-Honeytrap: When identity theft occurs law enforcement agencies may wish to honeytrap the thieves by letting them use the say credit card details & thus tracking them.
-White Noise Defense: smart companies ought have "white noise" dud systems, easily hacked containing white noise data with honeytrap triggers (eg a valid credit card number but one that belongs to say FBI) in it !
- and so on.
But they should be forced to notifiy law enforcement agencies.