Slashdot Mirror


Cybersecurity and the Tylenol Murders

HughPickens.com writes: Cindy Cohn writes at EFF that when a criminal started lacing Tylenol capsules with cyanide in 1982, Johnson & Johnson quickly sprang into action to ensure consumer safety. It increased its internal production controls, recalled the capsules, offered an exchange for tablets, and within two months started using triple-seal tamper-resistant packaging. Congress ultimately passed an anti-tampering law but the focus of the response from both the private and the public sector was on ensuring that consumers remained safe and secure, rather than on catching the perpetrator. Indeed, the person who did the tampering was never caught.

According to Cohn the story of the Tylenol murders comes to mind as Congress considers the latest cybersecurity and data breach bills. To folks who understand computer security and networks, it's plain that the key problem are our vulnerable infrastructure and weak computer security, much like the vulnerabilities in Johnson & Johnson's supply chain in the 1980s. As then, the failure to secure our networks, the services we rely upon, and our individual computers makes it easy for bad actors to step in and "poison" our information. The way forward is clear: We need better incentives for companies who store our data to keep it secure. "Yet none of the proposals now in Congress are aimed at actually increasing the safety of our data. Instead, the focus is on "information sharing," a euphemism for more surveillance of users and networks," writes Cohn. "These bills are not only wrongheaded, they seem to be a cynical ploy to use the very real problems of cybersecurity to advance a surveillance agenda, rather than to actually take steps to make people safer." Congress could step in and encourage real security for users—by creating incentives for greater security, a greater downside for companies that fail to do so and by rewarding those companies who make the effort to develop stronger security. "It's as if the answer for Americans after the Tylenol incident was not to put on tamper-evident seals, or increase the security of the supply chain, but only to require Tylenol to "share" its customer lists with the government and with the folks over at Bayer aspirin," concludes Cohn. "We wouldn't have stood for such a wrongheaded response in 1982, and we shouldn't do so now."

2 of 74 comments (clear)

  1. Re:1982 is an interesting comparison in other ways by Anonymous Coward · · Score: 4, Interesting

    Orwellian commercial and governmental surveillance, censorship by various nations, ad-infestment of everything, etc, would simply not have been tolerated on the 1982 internet.

    Yeah, right.

    Meet Executive Order 12333: The Reagan rule that lets the NSA spy on Americans

    ...the executive order [EO 12333] authorizes collection of the content of communications, not just metadata, even for U.S. persons. Such persons cannot be individually targeted under 12333 without a court order. However, if the contents of a U.S. person’s communications are “incidentally” collected (an NSA term of art) in the course of a lawful overseas foreign intelligence investigation, then Section 2.3(c) of the executive order explicitly authorizes their retention. It does not require that the affected U.S. persons be suspected of wrongdoing and places no limits on the volume of communications by U.S. persons that may be collected and retained.

    Now you say that that only pertains to data that is scooped up in foreign communications, but you have to realize that in modern telecommunication networks, data often transverses borders as packets are routed to phone switches that may be physically located in, say, Canada. So call from you in Nevada to your mom in Michigan may be recorded if your call is routed through a phone switch in Toronto, Canada.

  2. Re:why do people get this wrong? by Snotnose · · Score: 3, Interesting

    Nope. The guy they caught wrote a ransom note demanding $$$ to stop poisoning the bottles. He got caught and sent away for extortion. AFAIK they never did charge anyone with the actual murder.