• On MovieTome: The 10 worst movies of 2009 so far!
March 6, 2009 3:54 PM PST

Lawmaker: Consumers need details in data breach warnings

by Elinor Mills
  • Font size
  • Print
  • 6 comments

BERKELEY, Calif.--Six years after California enacted the country's first data breach notification law, many state residents have received letters warning them that their data was exposed by a breach but usually they don't know how or how long, experts said at a privacy conference on Friday.

That would change with the passage of a measure proposed by California State Sen. Joe Simitian, who authored the country's first bill requiring companies to notify customers when a breach has occurred that exposes their data.

Senate Bill 20 would require that notification letters to consumers have a standard set of information such as information about the timing and circumstances of the breach.

It would also require that a state entity be notified at the same time so that law enforcement, lawmakers, and researchers "can spot larger trends and don't have to rely on what they read in the newspaper," Simitian said in a luncheon address at the Security Breach Notification Symposium in Berkeley.

California State Sen. Joe Simitian discusses his proposed data protection legislation at a privacy symposium on Friday.

(Credit: Elinor Mills/CNET)

Some privacy advocates have called for including breaches involving paper in notification laws. But because of the "sheer volume of information and the speed with which it can be moved" with electronic information, digital data remains the priority, Simitian said.

"Paper is a problem," he said. "The ability to move legislation on that subject through the California State Legislature today is questionable at best, but it is an issue I will continue" looking into, Simitian said.

Another area of concern to tackle is biometric and RFID-enabled data, particularly in connection with government-mandated use such as in identification documents like passports, according to Simitian. With government-required use of such technologies there is an obligation to raise the standards for protecting the data to a higher level by limiting the type of data used or requiring encryption, he said.

Simitian said he learned firsthand the dangers of RFID technology during a demonstration showing how easy it is to steal data from his RFID-enabled state Senate ID. A Berkeley student who looked like "central casting for hacker dude, twentysomething, long, scraggly blond hair...glasses, black T-shirt," walked into Simitian's office, he recounted. Simitian handed his Senate ID to the student and the student handed it right back and said he had "read" the data on the card and even cloned it, all in the split second it took to pass it back and forth.

"I can now come into the California State capitol anytime I want to, and even better, people will think I'm California State Sen. Joe Simitian," the student told him.

Joanne McNabb, chief of the California Office of Privacy Protection, said in an interview after she sat on a panel that her office was analyzing the proposed legislation and that she did not have a position on it yet.

Meanwhile, McNabb said something needs to be done to better protect consumers who are victimized by identity fraud involving criminal records, health care, and employment. With financial identity fraud, consumers can put a freeze on their credit, but there are no easy steps someone can take when a scammer gets a criminal record in their name or uses their Social Security number to get a job, she said.

"We don't know how to address this," McNabb said.

In another presentation at the symposium, researchers discussed effects of security breach notification laws around the country.

Surprisingly, identity theft due to data breaches dropped only 2 percent after adoption of the laws, said Alessandro Acquisti, an assistant professor at Carnegie Melon University. However, that rate is in the range of impacts with other types of disclosures, like stock price drops after a company discloses a toxic waste issue, he said.

Of consumers who have been notified that their data may have been exposed during a data breach, 20 percent claim they ended their relationship with the company breached but the actual churn rate is less than 7 percent, said Deirdre Mulligan, assistant professor at the School of Information at the University of California at Berkeley.

The scope of the data breach problem was illustrated when a speaker asked the 90 or so attendees if they had received a data breach notification letter. At least two-thirds of the crowd raised their hand.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Tips for safe online shopping
Big changes in Security Starter Kit 2010
Confidential 9/11 pager messages disclosed
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Cisco launches iPhone security app
Add a Comment (Log in or register) (6 Comments)
  • prev
  • 1
  • next
by ericyen March 6, 2009 4:53 PM PST
When a data breach happen it is usually caused by an IT department NOT practicing Best Practices. Yes, we all know them but often it is difficult to implement them for reason related to cost, politics or resource limitations.

This idea a standard set of data to be in the notification email is EXCELLENT. I hope it includes when the breached happened, what data was compromised, why it happened , and a solution that has been implemented.

Consumers have a right to know !!!
Reply to this comment
by pentest March 7, 2009 11:39 AM PST
Best practices simple feel-good statement that allow a herd mentality.

They rarely offer anything close to actual security.
by amigosito March 6, 2009 5:31 PM PST
Joe S. rocks!!! It pleases me to no end that he's championed this cause. My only hope is that he runs for U.S. Senate/Congress and/or gets DiFi and/or Boxer to push this concept on a national level.
Reply to this comment
by skswave March 6, 2009 5:47 PM PST
It is time for all corporations to Require every new laptop is purchased with an encrypting hard drive. These products are in expensive and highly effective. They impose no Performance impact and are easy to use. Factory integrated Encryption is available from your OEM ASK for it. Dell has a range of great offerings. Also ALL of the corporate PCs have TPMs this device is highly effective in securing a VPN and network access. We could dramatically reduce theft of digital identities if the TPM where more broadly used. The combination of enhancing the laws and good technology can begine to address the issue.

Steven Sprague
CEO
Wave Systems Corp.
Reply to this comment
by pentest March 7, 2009 11:42 AM PST
Wrong, it is time for corporations to not allow data off premises and certainly not allowed on laptops.

If a laptop gets stolen while it is on and the encryption key is stored in RAM, the thief has access to everything.

The notion that encryption in and of itself is security needs to die and the ignorant who parrot it need to find a job flipping burgers.
by jebswan March 13, 2009 9:45 AM PDT
Corporations that don't allow data off premises is definitely a must, but how about the insider threat? Or the hacker that gets through your defenses? pentest, your solution only covers one aspect... not that I'm an ignorant parrot or a burger flipper...
Reply to this comment
(6 Comments)
  • prev
  • 1
  • next
advertisement

The browser battles go on and on

roundup From Firefox to IE and from Chrome to Opera and Safari, there's no sitting still for browser makers looking to keep their products fresh and competitive.

3G wireless still holds promise

The next generation of 4G wireless may get all the headlines, but advanced 3G technology will likely dominate services for the next few years.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right