Welcome to "On the 50 Yard Line" The Blog of Stuart L. Pardau, Attorney, Professor and Observer of Political Economy; It’s not just about football.

Showing posts with label Data Security / Privacy. Show all posts
Showing posts with label Data Security / Privacy. Show all posts

Saturday, January 18, 2014

Target Data Breach Was the Result of BLACKPOS, an "off the shelf" malware created by a 17-year old


The massive data breach at Target during late last year used an inexpensive "off the shelf" malware known as BlackPOS. The same malware may have also been involved in the Neiman Marcus attack.
 IntelCrawler, a Los-Angeles based cyber intelligence company, announced that the age of BlackPOS malware author is close to 17 years old and the first sample of it was created in March 2013


http://intelcrawler.com/about/press08

Tuesday, January 14, 2014

Senator Leahy reintroduces Data Privacy Legislation

Leahy first authored and sponsored the Personal Data Privacy and Security Act in 2005, and he has reintroduced the legislation in each of the last four Congresses. The bill would establish a national standard for data breach notification, and require American businesses that collect and store consumers’ sensitive personal information to safeguard that information from cyber threats.  Leahy’s bill introduction on Wednesday comes just weeks after the department store chain, Target, suffered a major data security breach involving 40 million credit and debit cards used to pay for purchases at its stores during the busy holiday buying season.

http://www.leahy.senate.gov/press/leahy-reintroduces-data-privacy-legislation

Thursday, January 9, 2014

Use of Social Media for Determination of Credit Status



More lending companies are mining social media such as Facebook and Twitter to help determine a borrower's creditworthiness. Is this a problem legally or otherwise? IMHO, no it is not.  In the absence of the affirmative selection of privacy settings, once someone elects to put their information out there in social media, sorry Charlie, you have, in essence "opted-in" to the widespread sharing of your personal information. Information captured that is more broadly captured on the worldwide web presents a related, though slightly more nuanced, difference. Also subject to widespread access and use, likewise expectations of privacy should be reduced accordingly. That said, what to do about information that may be untrue, inaccurate, or downright defamatory? What protections exist there?

http://www.theaustralian.com.au/business/wall-street-journal/concern-in-us-as-social-media-decides-credit-status/story-fnay3ubk-1226799034240#

Wednesday, August 1, 2012

FTC Proposed Modifications to Children Online Privacy Protection Act (COPPA) Rules


The proposed modifications to the definitions of "operator" and "website or online service directed to children" would allocate and clarify the responsibilities under COPPA when third parties such as advertising networks or downloadable software kits ("plug-ins") collect personal information from users through child-directed websites or services. The Commission proposes to state within the definition of "operator" that personal information is "collected or maintained on behalf of" an operator where it is collected in the interest of, as a representative of, or for the benefit of, the operator. This change would make clear that an operator of a child-directed site or service that chooses to integrate the services of others that collect personal information from its visitors should itself be considered a covered "operator" under the Rule.



http://www.ftc.gov/opa/2012/08/coppa.shtm

Monday, June 25, 2012

Cyber Attacks Hit Law Firms

How robust is the network security of most law firms? As I have long-suspected, not very.

http://blogs.wsj.com/law/2012/06/25/dont-click-on-that-link-client-secrets-at-risk-as-hackers-target-law-firms/

Tuesday, June 12, 2012

Hulu, Net Flix and the Video Privacy Protection Act

Hulu users claimed that the subscription-based video streaming service disclosed their viewing history to third parties. Specifically, their complaint alleges that Hulu worked with KISSmetrics, a data analytics company, to track subscribers’ viewing histories and then share that information with third parties such as Facebook. Hulu asserts it is not subject to the VPPA because it is not a “video tape service provider,” which is defined in relevant part as “any person, engaged in the business, in or affecting interstate or foreign commerce, of rental, sale, or delivery of prerecorded video cassette tapes or similar audio visual materials…” The case is headed to mediation.


As to Netflix, they recently settled a class action lawsuit in connection with maintaining viewing history records beyond the allowed time under the statute. 


http://www.huntonprivacyblog.com/2012/06/articles/recent-cases-focus-attention-on-the-video-privacy-protection-act/#more-3062

Sunday, June 10, 2012

Big Apple: Technology Giant Reveals 3-D Mapping Service That Photograph Activity Through A Window or a Skylight

Apple’s military-grade cameras are understood to be so powerful they could potentially see into homes through skylights and windows. The technology is similar to that used by intelligence agencies in identifying terrorist targets in Afghanistan.


Yet another instance of technology racing ahead of the legal and regulatory environment.
http://www.dailymail.co.uk/news/article-2157150/Apple-reveal-3D-mapping-service-week-campaigners-say-privacy-window-thanks-high-resolution-images-spy-home.html

Sunday, March 18, 2012

HHS Announces First Enforcement Action Under HITECH Act Breach Notification Rule

Blue Cross Blue Shield of Tennessee (BCBST) has agreed to pay the U.S. Department of Health and Human Services (HHS) $1,500,000 to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules, Leon Rodriguez, Director of the HHS Office for Civil Rights (OCR), announced today.  BCBST has also agreed to a corrective action plan to address gaps in its HIPAA compliance program.  The enforcement action is the first resulting from a breach report required by the Health Information Technology for Economic and Clinical Health (HITECH) Act Breach Notification Rule.

http://www.hhs.gov/news/press/2012pres/03/20120313a.html

Friday, March 9, 2012

ABA Asks Courts to Consider Foreign Privacy Laws


The American Bar Association’s (“ABA’s”) House of Delegates adopted a non-binding resolution urging courts to consider foreign data protection and privacy laws when resolving discovery issues. The full text of the resolution is as follows:
“RESOLVED, That the American Bar Association urges that, where possible in the context of the proceedings before them, U.S. federal, state, territorial, tribal and local courts consider and respect, as appropriate, the data protection and privacy laws of any applicable foreign sovereign, and the interests of any person who is subject to or benefits from such laws, with regard to data sought in discovery in civil litigation.”


http://www.huntonprivacyblog.com/2012/02/articles/american-bar-association-asks-courts-to-consider-foreign-privacy-laws/

Sunday, February 19, 2012

Mobile Apps for Kids Often Lack Adequate Consents and Disclosures According to the FTC

The Federal Trade Commission today issued a staff report showing the results of a survey of mobile apps for children. The survey shows that neither the app stores nor the app developers provide the information parents need to determine what data is being collected from their children, how it is being shared, or who will have access to it.

http://www.ftc.gov/opa/2012/02/mobileapps_kids.shtm

Tuesday, February 14, 2012

Right of Publicity Class Action Lawsuit Against Facebook


A class of Facebook users who take issue with one of the site’s advertising methods — the “Sponsored Story,” which is created when a Facebook user “likes” a product or service and is shown to that user’s friends. In essence, if a user “likes” a brand, she becomes a spokeswoman for it.
The lawsui was first filed in California state court and removed to federal court in San Jose in March 2011. The named plaintiff didn’t want Facebook using her image and name to advertise products to her Facebook connections without her permission, she said in court documents filed Monday.



http://blogs.wsj.com/law/2012/02/14/suing-facebook-kind-of-sucks-plaintiff-says/

Saturday, February 11, 2012

Digital Espionage in China Requires Some Business Travelers to take Extraordinary Measures

As reported in the New York Times, when Kenneth Lieberthal of the Brookings Institute, travels to China he takes the following steps:


"He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop."

http://www.nytimes.com/2012/02/11/technology/electronic-security-a-worry-in-an-age-of-digital-espionage.html

Thursday, February 9, 2012

Federal Court Grants Electronic Privacy Information Center (EPIC) Accelerated Briefing Schedule in case against FTC re Google

In response to EPIC's complaint and motion to compel the Federal Trade Commission to enforce a consent order against Google, a federal district court judge has ordered an accelerated briefing schedule. The FTC's Response to the EPIC briefs is due February 17, EPIC's reply is due February 21, 2012. The Court's deadlines reflect Google's imminent, substantial changes to the company's business practices. Google intends to consolidate the personal data of Google users across 60 services on March 1. EPIC contends that these changes constitute a violation of the consent order with the Federal Trade Commission. For more information, see EPIC v. FTC (Google Consent Order).


http://epic.org/2012/02/federal-court-grants-accelerat.html

Wednesday, February 1, 2012

What Actually Changed in Google's Privacy Policy?


Per the EFF, here’s what you need to know about the substantive changes in the new policy:
  1. Up until March 1, 2012, the data Google collected on you when you used YouTube was carefully cabined away from your other Google products. So, in effect, Google could use data they collected on YouTube to improve and customize the users’ YouTube experience, but couldn’t use the data to customize and improve user experience on, say, Google+.
  2. The same siloing took place for your search history. Previously, Google search data was kept separate from other products. Even when users were logged in, Google promised not to share the information they gathered about you from your Google search history when customizing their other products. Considering how uniquely sensitive user search history can be (indicating vital facts about your location, interests, age, sexual orientation, religion, health concerns, and much more), this was an important privacy protection. 



https://www.eff.org/deeplinks/2012/02/what-actually-changed-google%27s-privacy-policy

Tuesday, January 17, 2012

Zappos Has Major Data Security Breach

Computerworld reports that Customers' names, e-mail addresses,..addresses, phone numbers,..and their scrambled passwords may have been illegally accessed.

http://blogs.computerworld.com/19584/zappos_security_breach_your_data_hacked

Friday, January 13, 2012

Facebook: More Ads Coming

The social network began rolling out a new kind of advertisement for select users Tuesday which will show up in the main news feed, according to a report from TechCrunch. Prior to this, Facebook's advertisements appeared on the side of the page under the label "Sponsored Stories."

Aside from their placement front and center on the page, this tweak may end up blurring the lines between the promotional and personal content in your feed. As the tech blog points out, Facebook has changed the name from Sponsored Stories to Featured Stories, a subtle change that could mask the fact that the posts have been paid for.


http://money.msn.com/saving-money-tips/post.aspx?post=5ce24eea-5e7f-4298-bbb8-fb6c1dc0bcdb

Tuesday, January 10, 2012

Facebook Gets Grilled Before Congress on Privacy Issues

Despite the recent consent decree and settlement with the Federal Trade Commission on these very issues, the actual and perceived conduct of Facebook in terms of privacy brand promises remain deeply troubled.

http://thehill.com/blogs/hillicon-valley/technology/203167-lawmakers-say-facebook-ducking-privacy-questions

Monday, January 9, 2012

Congress Breaks, SOPA Soap Opera Continues


Sergey Brin, co-founder of Google, has been outspoken against the efforts.
The bills "give the U.S. government and copyright holders extraordinary powers including the ability to hijack DNS (the Internet's naming system) and censor search results (and this is even without so much as a proper court trial)," Brin wrote last month on his Google+ page as Congress was considering the measures. "While I support their goal of reducing copyright infringement (which I don't believe these acts would accomplish), I am shocked that our lawmakers would contemplate such measures that would put us on a par with the most oppressive nations in the world."
The list of companies that signed off on a NetCoalition statement condemning SOPA reads like a who's-who of the Internet. Yahoo, Zynga, Twitter, eBay, Foursquare, AOL, Mozilla, Etsy and LinkedIn are just some of the names


http://www.cnn.com/2012/01/06/tech/web/sopa-web-piracy-act/index.html?hpt=hp_bn6

Sunday, January 8, 2012

Upromise, Inc. Settles with FTC regarding charges that its Web-browser toolbar collected consumer PII without adequate disclosure

A membership reward service aimed at consumers trying to save money for college has agreed to settle FTC charges and will be barred from its allegedly deceptive practice of using a web-browser toolbar to collect consumers' personal information without adequately disclosing the extent of the information it is collecting.
The settlement with Upromise Inc. is part of the FTC's ongoing efforts to make sure that companies live up to the promises they make about privacy and data security. The settlement order will require Upromise to clearly disclose its data collection practices and obtain consumers' consent before installing or re-enabling any such toolbar products, and to notify consumers how to uninstall the toolbars already on their computers. The settlement also will bar misrepresentations about the extent to which the company maintains the privacy and security of consumers' personal information, and require the company to establish a comprehensive information security program and to obtain biennial independent security assessments for the next 20 years.


http://www.ftc.gov/opa/2012/01/upromise.shtm

Saturday, January 7, 2012

American Airlines is Target of Major Phishing Scam

American Airlines is warning consumers to be on the lookout for phishing scams after being forwarded fraudulent emails by other patrons.

http://money.msn.com/saving-money-tips/post.aspx?post=e8ecc606-8f67-46af-8697-2e8733287ebb

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Powered by Blogger