funsec mailing list archives

Re: Trying to hide a breach?


From: Paul Ferguson <fergdawgster () gmail com>
Date: Mon, 5 Apr 2010 18:19:18 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Apr 5, 2010 at 6:03 PM, <robert_mcmillan () idg com> wrote:


b)  Gee, those disclosure laws work really well, don't they?


Have you ever heard of anyone prosecuted for not doing a notification?
Have you ever heard of anyone who investigates possible violations of
these
laws? It's the state AGS' responsibility, but my sense is that nobody is
really making sure these laws are being obeyed.

On the other hand, I do think the laws have worked remarkably well.


Part of the problem is that there is no U.S. National Breach Notification
Mandate, so what we are stuck with is an ad hoc set of state laws which
just doesn't cut it:

http://www.circleid.com/posts/more_provocative_reasons_for_a_mandatory_nati
onal_breach_disclosure/

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)

wj8DBQFLuowGq1pz9mNUZTMRAmUDAKCHwHFrEpDGGoMc0DfdPLq3V9jojwCggAOJ
gVivY+GHg9mqBYjHRicXcEk=
=OCuX
-----END PGP SIGNATURE-----



--
"Fergie", a.k.a. Paul Ferguson
Engineering Architecture for the Internet
fergdawgster(at)gmail.com
ferg's tech blog: http://fergdawg.blogspot.com/
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: