Feeds

Sony hack revives Oz disclosure debate

Calls for disclosure laws and security guidelines

Securing Web Applications Made Simple and Scalable

The Sony PlayStation network breach has revived Australia’s dormant security disclosure debate.

Rob Forsyth, A/NZ managing director of Sophos, says the government must legislate for mandatory disclosure, noting that it has been proposed in a large number of privacy recommendations. If personally identifiable information is lost, he said, companies must notify both the general public and the individuals whose information has been stolen.

He told ABC radio programme The World Today that the theft of address and birth date details – and possibly credit card numbers, although Sony currently maintains that there is no evidence that these were compromised in the breach – highlights Australia’s lack of a disclosure regime.

“Sony was not quick to notify people that there had been a breach of security,” RMIT lecturer and computer networking specialist Dr Mark Gregory told the same programme, even though the speed with which the network was shut down demonstrated that Sony was aware of the problem before it went public.

He backed Forsythe’s call for a disclosure regime: “Government needs to legislate a proper regime for this,” he said.

Dr Gregory also called on the government, via the Australian Communications and Media Authority (ACMA), to establish “best practice” security guidelines that companies can follow. ®

Update: According to journalistic chatter on Twitter, reports are starting to surface of $10 charges appearing against credit cards attached to PlayStation Network accounts. While unconfirmed at this time, the rumours could at least force Sony to make a firm statement as to whether card data was stolen in the breach. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.