Feeds

No effect seen in US hack disclosure law

'Nobody's telling anybody anything'

  • alert
  • submit to reddit

Protecting users from Firesheep and other Sidejacking attacks with SSL

Consultants are using it in pitches, lawyers are lecturing on it, and in Washington, it's been used as a model for proposed federal legislation. But nearly four months after it took effect, California's unique security breach disclosure law has yet to see any enforcement action.

"Our office is not aware of any, nor are we aware of any DA or local offices or private parties bringing them," says Hallye Jordan, a spokesperson for California attorney general Bill Lockyer. "It may be that there have not been any security breaches that the consumers have not been informed about."

The law, called SB 1386, passed on September of last year and took effect July 1st. It obligates companies doing business online to warn their customers in "the most expedient time possible" about any security breach that exposes certain types of information: specifically, customers' names in association with their social security number, drivers license number, or a credit card or bank account number. It can be enforced by state officials, or consumers can sue for damages if they become fraud or identity theft victims as a result of an undisclosed breach. Attorneys have warned that the law applies to e-commerce companies nationwide, whenever residents of the Golden State have their information exposed.

But observers say that SB 1386 hasn't opened a floodgate of security breach disclosures. "Thus far I have not seen a lot of examples of people notifying," says Scott Pink, deputy chair of the American Bar Association's Cybersecurity Task Force. "My guess is people are either not familiar with the law, or are handling it discreetly."

"I can tell you right now, nobody's telling anybody anything," says Dan Clements of CardCops.com. "I don't see it being effective right now. Consumers are still not getting notified."

Clements offers consumers a paid notification service, in which he'll warn his customers if he spots their information in the chat rooms and websites frequented by credit card thieves. He says this month alone he traced stolen credit card information to breaches at five different online merchants, ranging from mid-sized businesses to modest mom-and-pop operations. When he contacted a sample of the exposed consumers, he was, in each case, the first to give them the bad news. "They were not informed," says Clements.

But the law only requires disclosure when personal information is "reasonably believed to have been" stolen; these merchants may not have known. One of them, an online store that sells collectable sculptures, had detailed order information for forty customers plastered on a public website devoted to credit card fraud. But proprietor James Hunter says he was ignorant of the leak until Clements tipped him off, and that he warned his customers five days later -- delaying that long only at the request of his hosting company, Philadelphia-based Datarealm, which also hosts another merchant exposed on the same carding site. (A Datarealm representative did not return phone calls on the breaches.) "They asked me to wait to let them find out what the problem was so we'd have something positive to say," says Hunter.

Pink says it's too early to pass judgment on the California law. "I think the test will be somewhere between six months and a year," he says. Meanwhile, a proposed federal version of SB 1386 called the Notification of Risk to Personal Data Act is stalled in committee, according to a spokesman for senator Dianne Feinstein, who introduced the bill this year.

For his part, Clements has begun reporting breaches to the New York Attorney General's office, which has had some success enforcing website privacy policies under existing state consumer protection laws. Disclosure laws, he says, fight merchants' and hosting companies' natural fear of losing of customer confidence if they admit security breaches, and that merchants can face financial penalties from credit card companies when they've been hacked. "I've been doing this for four years, and I've seen over four hundred hacked merchants, and they have one thing in common: they don't want to tell anybody," says Clements.

Copyright © SecurityFocus

The next step in data security

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.