Wyndham Settlement: No Fine, But More Power To the FTC (csoonline.com)
itwbennett writes: Earlier this month, Wyndham settled a lawsuit with the FTC over weak security practices that resulted in 3 major data breaches in 2008 and 2009 that compromised the credit card information of more than 619,000 customers and led to more than $10.6 million in fraudulent charges. But all the settlement requires Wyndham to do 'is what any company that handles credit card data is supposed to have been doing for more than a decade, under the Payment Card Industry Data Security Standard (PCI DSS),' writes Taylor Armerding. There was no fine and it seemed as though Wyndham had 'dodged a bullet', says Armerding, But things are not always as they seem. Because the PCI DSS is not a government standard and is not a law 'the case was not about fines for noncompliance, which the FTC doesn't even have the authority to impose,' says Armerding. 'It was instead about power – the authority of the FTC to charge Wyndham with 'unfair and deceptive' practices because of its security flaws.'
I think government is very justified when looking into cases of negligence when it impacts a large number of people. There is very clear case of public interest.
More government regulation of credit bureaus and credit card companies so that no piece of data that can potentially be compromised qualifies as "potentially life-ruining". The problem is not that your SSN can be stolen. The problem is that it actually matters whether your SSN gets stolen, which is entirely an artificial problem caused by credit bureaus treating a non-secret number as though it were some sort of password, allowing people to take out credit using entirely different addresses and phone numbers than they've ever used before without doing due diligence to determine whether that person moved, and fraudulently and libelously report nonpayment of those bogus debts as though they were real.
The credit bureaus are the problem, period. There is no such thing as "identity theft". There is only widespread conspiracy to commit libel resulting from gross criminal negligence on the part of credit bureaus. The only way to fix the problem is to fix the lax regulation that has allowed these companies to libel creditors with near impunity for decades.
On the credit card side:
That's quite literally the only way that has even a prayer of eliminating the risk of compromised payment terminals being used maliciously. The device that authorizes the transaction must be an inexpensive and normally disconnected device, such as a thick credit card, as opposed to a cellular phone, because otherwise you're just moving the attack target around. And the button to authorize the transaction must be part of that device so that it cannot be easily compromised. Otherwise, a compromised reader could potentially show the transaction on the screen, authorize it, and then very quickly show and authorize a second transaction before the customer notices.
And if it isn't mandated by law, the card companies won't implement this, because it is relatively expensive, and they would rather just force merchants to eat the cost of fraud rather than take steps to actually prevent fraud.
On the credit card bureau side:
And more generally:
If government did these things, so-called "identity theft" would just about cease to exist. But they won't, because politicians can win votes by paying lip service to "identity theft" while not actually f
Check out my sci-fi/humor trilogy at PatriotsBooks.