Slashdot Mirror


User: Benjamin_Wright

Benjamin_Wright's activity in the archive.

Stories
0
Comments
88
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 88

  1. PCI Law on Huge Credit Fraud Ring Sends Europeans' Data To Pakistan · · Score: 2, Interesting

    A quote in the WSJ article says the hackers are performing at a level of sophistication that rivals foreign intelligence services. The implication: Payment card data security requires much, much more than just forcing merchants to lock down data and comply with the PCI (payment card industry data security standard). Card data security is a national security issue. It requires wholesale rethinking of the credit card system. The Federal Trade Commission misunderstands the magnitude of the problem. The FTC is locked in an old-fashioned belief that data in-security is due to stupid merchants (like TJX) treating consumers (and their privacy) "unfairly" by failing to secure their systems. We need fresh thinking and better leadership on this issue from the FTC. --Ben

  2. e-mail record retention on Choosing a Replacement Email System For a University? · · Score: 1

    East Carolina University recognized that part of e-mail management is to set a policy for the retention of e-mail by important employees. -- Ben

  3. legal terms and conditions on 20 Hours a Month Reading Privacy Policies · · Score: 1

    Imagine all the time businesses would spend if they read (and took the effort to digest) all the legal terms and conditions written on routine documents, like invoices, purchase orders, and bills of lading, from trading partners. Under a legal phenomenon called the "battle of the forms," businesses learned that the best approach was not to read all the terms communicated to them. Instead, they learned to transmit their own terms to their trading partners, using their own documents. By so doing, they sorta blunted or neutralized or adjusted the blizzard of terms coming from trading partners. (The process was never perfect, but if done intelligently it had an effect.) I argue the same phenomenon can occur in the privacy space. I argue people can publish their own terms of privacy. (It's a complex topic, and I'm not giving anyone legal advice here. Topic for more discussion.) --Ben http://hack-igations.blogspot.com/2008/05/google-privacy-policy-terms-of-service.html

  4. hostile workplace lawsuits on Prevent Gmail From Emailing Under the Influence · · Score: 1

    "Hostile workplace" lawsuits show that businesses have good reason to use technical filters and blocks to prevent the transmission of ill-advised e-mail. This link describes a case against the Chicago Police Department: http://legal-beagle.typepad.com/wrights_legal_beagle/2008/10/filter-and-block-pornography-from-workplace-e-mail.html --Ben

  5. EULAs on Give Up the Fight For Personal Privacy? · · Score: 1

    Why can't end user license agreements be turned to advantage? To deter employers (and bill collectors) from viewing social networking pages, employees (or debtors) might post terms of service under which employers (or collectors) agree to scram. This idea should not be taken as legal advice, just something to think about. --Ben http://hack-igations.blogspot.com/2007/11/privacy-advocates-such-as-nyu-professor.html

  6. legislative folly on Nevada Businesses Must Start Encrypting E-Mail By Oct. 1st · · Score: 1

    A lesson from the history of technology law: A legislature is unwise to require a specific technology like "encryption." --Benjamin Wright http://hack-igations.blogspot.com/2008/02/encryption-legislation-goes-overboard.html

  7. legal terms - EULA on 10 Percent of Colleges Check Applicants' Social Profiles · · Score: 1

    To deter colleges from viewing social networking pages, maybe students could post legal terms of service under which colleges agree to go away and ignore the pages. This idea should not be taken as legal advice for anyont, just something to think about. --Ben http://hack-igations.blogspot.com/2007/11/privacy-advocates-such-as-nyu-professor.html

  8. litigation hold on To Purge Or Not To Purge Your Data · · Score: 2, Informative

    Any record destruction policy must include a "litigation hold". A litigation hold means that record destruction must stop when litigation is anticipated or pending. But in a complex enterprise, it is tricky to know what litigation the enterprise anticipates. It was the trickiness of litigation hold that led to the demise of Arthur Andersen. The risks associated with litigation hold give enterprises incentive to store lots more records. --Ben http://hack-igations.blogspot.com/2008/07/document-discovery-litigation-hold.html

  9. endless lawsuits on Judge Rules Defense Can Get DUI Machine Source Code · · Score: 1

    As information technology begets ever-growing oceans of records, all legal investigations and prosecutions grow ever more lengthy, revealing, expensive and difficult to close. --Ben http://hack-igations.blogspot.com/2007/09/endless-investigations.html

  10. what is the definition of a "security breach" on Most Companies Admit Their Data Is At Risk · · Score: 1

    Most all data in commercial and government systems are "exposed" or "compromised" to one degree or another virtually all the time. Should each citizen therefore be mailed 100 breach notices every day? Legally and ethically speaking, we do not have a competent definition of what is and is not a security breach. The result is confusion and excessive anxiety on the part of data holders, data subjects, legal authorities and the media. Ben http://hack-igations.blogspot.com/2007/09/definition-of-data-security-breach.html

  11. legal deterence on One In Five Employers Scan Applicants' Web Lives · · Score: 1

    To deter employers from viewing social networking pages, employees might post terms of service under which employers agree to scram. This idea should not be taken as legal advice, just something to think about. --Ben http://hack-igations.blogspot.com/2007/11/privacy-advocates-such-as-nyu-professor.html

  12. contract law on Privacy Policies Are Great — For PhDs · · Score: 1

    A privacy policy is a type of contract. Contract law is a two-way street. Each party can assert terms. If Google can assert its legal privacy terms just by publishing them (on something less than its homepage), then maybe Internet users can assert their own terms of privacy protection just by publishing them! --Ben http://hack-igations.blogspot.com/2008/05/google-privacy-policy-terms-of-service.html This idea is not legal advice, just something to discuss.

  13. contract law on The 5 Most Laughable Terms of Service On the Net · · Score: 1

    EULAs are governed by contract law. Contract law is a two-way street. Just as web administrators and software vendors can communicate to visitors/customers what they assert to be the legal terms, customers can communicate back. In principle, contract law does not favor either administrators or customers. Individuals may be able to use contract law to assert their legal terms on other parties, such as search engines. --Ben http://hack-igations.blogspot.com/2008/05/google-privacy-policy-terms-of-service.html My ideas are not legal advice for any particular situation; they are just ideas for public discussion.

  14. over-reaction is easy on Should Companies Share Criminal Blame In ID Theft? · · Score: 1

    Best Western now says only a handful of records were compromised, not millions. Data security investigations are complex, and they require patience. As we learned from the TJX experience, it is easy for the press and for authorities to over-react. --Ben http://legal-beagle.typepad.com/wrights_legal_beagle/2008/08/credit-card-iss.html

  15. crypto law and public policy on New Attack Against Multiple Encryption Functions · · Score: 1

    From a public policy perspective: This post reminds us that cryptography is a dynamic and sometimes surprising science. The implication is that to achieve data security with cryptography is not just a simple task. But politicians have recently been writing laws and regulations with the assumption that to "encrypt" data is the end-all be-all of data security. It is not. Lawmakers are unwise to require a specific technology like "encryption" for data security. --Ben Wright http://hack-igations.blogspot.com/2008/02/encryption-legislation-goes-overboard.html

  16. what is a significant breach? on UK Gov't Lost Personal Data On 4M People In One Year · · Score: 1

    Data breaches are more nuanced than the sensational numbers in a story like this would suggest. Data breach announcements and notices have a scalability problem. As the number of announcements and notices soars, we need to better define what is a serious breach and what is not. Otherwise, the public drowns in breach claims, announcements and notices, many of which are insignificant. --Ben http://hack-igations.blogspot.com/2007/12/does-lost-tape-equate-to-lost-data.html

  17. insisting that Google adhere to your EULA on Google Using DoubleClick Tracking Cookies · · Score: 1

    If Google can assert its legal terms just by publishing them (on something less than its homepage), then users can assert their own terms of privacy protection just by publishing them! What do you think? --Ben http://hack-igations.blogspot.com/2008/05/google-privacy-policy-terms-of-service.html [This is not legal advice for anyone, just a topic for public discussion.]

  18. Employer's perspective on Who Owns Your Online Networking Contacts? · · Score: 1

    From the point of view of the employer: If you want to boost your claim that you own stuff like social net contacts, then post lots of notices telling employees that you own it and that they agree. http://hack-igations.blogspot.com/2008/06/employee-imtexte-mailvoicecomputerinter.html --Ben [But if you need legal advice on this, you need to talk to your lawyer.]

  19. taking heat off of retailers on Net Shoppers Bullied Into "Verified By Visa" Program · · Score: 1

    By their nature, merchants are not well-equipped to secure modern payment card transactions and data. As merchants like TJX have (predictably) failed to succeed at tasks they are not qualified to perform, the law has unfairly been punishing them. The punishment and the unfair foisting of burdens on merchants should stop. As an effort to take heat and responsibility off of beleagured merchants, programs like Verified by Visa are wise and necessary. --Ben http://hack-igations.blogspot.com/2008/03/ftc-treats-tjx-unfairly.html

  20. reaction out of proportion on Hacking Ring Nabbed By US Authorities · · Score: 1

    Careful reading of the indictments show that the media, card issuers and Federal Trade Commission over-reacted to the TJX incident. TJX was not as bad as we were led to believe. --Ben http://legal-beagle.typepad.com/wrights_legal_beagle/2008/08/credit-card-iss.html

  21. data security on Face-Swapping Software To Protect Privacy · · Score: 1

    Subterfuge is a tactic of modern data security and privacy. --Ben http://hack-igations.blogspot.com/2007/08/subterfuge-as-security-tactic.html

  22. managing archive email volume on Are There Any Smart E-mail Retention Policies? · · Score: 1

    As the size of e-mail archives swells, corporations can take steps to manage and reduce the volume of what they retain. --Ben http://hack-igations.blogspot.com/2008/04/reducing-volume-of-e-mail-archives.html

  23. anti-employer EULA on Social Networking Sites Becoming Useful For Lawyers · · Score: 1

    I don't know about preventing prosecutors from using photos. However . . . to deter employers from viewing and abusing social networking pages, employees might post legal terms of service under which employers agree to scram. This idea should not be taken as legal advice for anyone, just fodder for public discussion. --Ben http://hack-igations.blogspot.com/2007/11/privacy-advocates-such-as-nyu-professor.html

  24. robots.txt as web EULA? on McCain Campaign Uses Spider/Diff Against Obama · · Score: 1

    CmdrToco says, "Assuming the spider adheres to robots.txt, this is clever and well done." Query whether robots.txt can legally or morally be used, like a web End User License Agreement (EULA), to restrict the policitical conversation the McCain campaign is pursuing here. It is one thing to use a EULA to govern issues like privacy and legal liability. It would be another to employ it to limit free political speech. What do you think? --Ben http://hack-igations.blogspot.com/2008/05/google-privacy-policy-terms-of-service.html

  25. Legal privacy policy on Finding Fault With Google's Privacy Policy · · Score: 1

    If Google can assert its legal terms just by publishing them (on something less than its homepage), then users can assert their own terms of privacy protection just by publishing them! What do you think? --Ben http://hack-igations.blogspot.com/2008/05/google-privacy-policy-terms-of-service.html