<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Graves Concerns</title>
	<atom:link href="http://blog.subjunctive.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.subjunctive.com</link>
	<description>Notes on Security, Privacy, and the Law</description>
	<lastBuildDate>Sat, 27 Feb 2010 19:36:17 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='blog.subjunctive.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/008a5f673b3d5ccfcb06052b81eec1cf?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Graves Concerns</title>
		<link>http://blog.subjunctive.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.subjunctive.com/osd.xml" title="Graves Concerns" />
	<atom:link rel='hub' href='http://blog.subjunctive.com/?pushpress=hub'/>
		<item>
		<title>Privacy Seal Provider ControlScan Settles FTC Charges</title>
		<link>http://blog.subjunctive.com/2010/02/27/privacy-seal-provider-controlscan-settles-ftc-charges/</link>
		<comments>http://blog.subjunctive.com/2010/02/27/privacy-seal-provider-controlscan-settles-ftc-charges/#comments</comments>
		<pubDate>Sat, 27 Feb 2010 19:36:17 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=662</guid>
		<description><![CDATA[The FTC announced on Thursday that it had reached a settlement with ControlScan, a provider of so-called &#8220;privacy seals&#8221;&#8212;those small-ish images certifying  a website&#8217;s security or privacy practices.  
The FTC charged that ControlScan had &#8220;misled consumers about how often it monitored the sites and the steps it took to verify their privacy and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=662&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The FTC announced on Thursday that it had <a href="http://www.ftc.gov/opa/2010/02/controlscan.shtm">reached a settlement with ControlScan</a>, a provider of so-called &#8220;privacy seals&#8221;&mdash;those small-ish images certifying  a website&#8217;s security or privacy practices.  </p>
<p>The FTC charged that ControlScan had &#8220;misled consumers about how often it monitored the sites and the steps it took to verify their privacy and security practices.&#8221;  Although the seals claimed that ControlScan had verified the site&#8217;s  privacy practices, ControlScan did &#8220;little or no verification&#8221; of those practices, according to the FTC.  The FTC also took issue with the fact that the seals had current date stamps even though ControlScan did no daily reviews.</p>
<p>The settlement agreement required ControlScan&#8217;s former CEO to give up $102,000 in profits.  It also suspended a $750,000 penalty against the company for inability to pay.</p>
<p>It&#8217;s uncertain whether privacy or security seals mean much.  Even when providers scan daily, how much assurance can one expect for <a href="http://www.trust-guard.com/Hacker-Safe-s/42.htm">$71.50 per month</a>?  McAfee, the big player in the market after it bought (and renamed) the &#8220;HackerSafe&#8221; seal, had its own bit of bad press a couple of years ago when it turned out that <a href="http://www.theregister.co.uk/2008/04/29/mcafee_hacker_safe_sites_vulnerable/">several &#8220;Hacker Safe&#8221; sites were vulnerable to cross-site scripting attacks</a>.   </p>
<p>Even though ControlScan appears to have been in a different category than legitimate privacy seal vendors, the FTC settlement highlights a classic reputation problem with these seals.  The seals look like they mean something, but the only way to know for sure is to check the seal provider&#8217;s practices&mdash;which undermines the point of the badge in the first place.  </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/662/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/662/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/662/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/662/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/662/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/662/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/662/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/662/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/662/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/662/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=662&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2010/02/27/privacy-seal-provider-controlscan-settles-ftc-charges/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>U.S. Supreme Court to Hear Government Employer Privacy Case</title>
		<link>http://blog.subjunctive.com/2009/12/15/u-s-supreme-court-to-hear-government-employer-privacy-case/</link>
		<comments>http://blog.subjunctive.com/2009/12/15/u-s-supreme-court-to-hear-government-employer-privacy-case/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 16:38:21 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=654</guid>
		<description><![CDATA[The U.S. Supreme Court has granted certiorari in City of Ontario v. Quon.  That&#8217;s the new name for Quon v. Arch Wireless Operating Company, the Ninth Circuit case that found that a police officer had a reasonable expectation of privacy in his text pager messages.  
This should be an interesting case to watch. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=654&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The U.S. Supreme Court has granted certiorari in <a href="http://www.scotusblog.com/wp/todays-orders-49/"><i>City of Ontario v. Quon</i></a>.  That&#8217;s the new name for <a href="http://blog.subjunctive.com/2008/06/19/if-you-want-your-aup-to-stick-stick-to-your-aup/"><i>Quon v. Arch Wireless Operating Company</i></a>, the Ninth Circuit case that found that a police officer had a reasonable expectation of privacy in his text pager messages.  </p>
<p>This should be an interesting case to watch.  For a discussion of how this case might affect privacy for government employees, see <a href="http://volokh.com/2009/12/14/will-the-supreme-court-rethink-public-employee-privacy-rights-in-quon/">Orin Kerr&#8217;s post over at the Volokh Conspiracy.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/654/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/654/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/654/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=654&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/12/15/u-s-supreme-court-to-hear-government-employer-privacy-case/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>Cost of Disclosing 179 Social Security Numbers in a Court Filing: $5000</title>
		<link>http://blog.subjunctive.com/2009/10/23/cost-of-disclosing-179-social-security-numbers-in-a-court-filing-5000/</link>
		<comments>http://blog.subjunctive.com/2009/10/23/cost-of-disclosing-179-social-security-numbers-in-a-court-filing-5000/#comments</comments>
		<pubDate>Sat, 24 Oct 2009 03:04:47 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Data Breach]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=648</guid>
		<description><![CDATA[Here&#8217;s a new way of holding someone directly liable for a data breach.  A Minnesota attorney was fined $5000 for filing a federal court document containing the social security numbers and birth dates of 179 people.  Court filings are public, which is why Federal Rule of Civil Procedure 5.2(a) says that a court [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=648&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a new way of holding someone directly liable for a data breach.  A Minnesota attorney was fined $5000 <a href="http://minnlawyerblog.com/2009/10/23/slip-up-in-federal-filing-leads-to-5000-sanction/#comments">for filing a federal court document containing the social security numbers and birth dates of 179 people</a>.  Court filings are public, which is why Federal Rule of Civil Procedure 5.2(a) says that a court filing may only contain the year of birth or last four digits of a social security number.   As Judge Davis wrote in his order:</p>
<blockquote><p>The Court is deeply concerned with the harmful and widespread ramifications associated with negligent and inattentive electronic filing of court documents.  Although electronic filing significantly  improves the efficiency and accessibility of our court system, it also elevates the likelihood of identity theft and damage to personal privacy when lawyers fail to follow federal and local rules.</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/648/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/648/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/648/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=648&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/10/23/cost-of-disclosing-179-social-security-numbers-in-a-court-filing-5000/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>Ninth Circuit Adopts Plain-Language View of &#8220;Authorization&#8221; in CFAA Decision</title>
		<link>http://blog.subjunctive.com/2009/09/30/ninth-circuit-adopts-plain-language-view-of-authorization-in-cfaa-decision/</link>
		<comments>http://blog.subjunctive.com/2009/09/30/ninth-circuit-adopts-plain-language-view-of-authorization-in-cfaa-decision/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 22:34:49 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[CFAA]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=625</guid>
		<description><![CDATA[The Computer Fraud and Abuse Act (CFAA) creates criminal penalties for doing various bad things by intentionally accessing a computer without authorization or by exceeding authorized access.  There&#8217;s been a some debate recently over just what &#8220;authorization&#8221; means.  For example, one of the issues in the Lori Drew case was whether Drew had [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=625&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.law.cornell.edu/uscode/18/1030.html">Computer Fraud and Abuse Act</a> (CFAA) creates criminal penalties for doing various bad things by intentionally accessing a computer without authorization or by exceeding authorized access.  There&#8217;s been a some debate recently over just what &#8220;authorization&#8221; means.  For example, one of the issues in the Lori Drew case was whether Drew had exceeded authorized access, and thus committed a federal crime, by violating MySpace&#8217;s terms of service.  Another frequent issue comes up in employment contexts: is it unauthorized access to use company computers for purposes other than those intended?</p>
<p>For example, suppose an employee has access to an employer&#8217;s computers for regular business purposes, but e-mails confidential data to an outside account.  Later, he leaves the company and uses that confidential data to set up a competing business.  Did the employee access that confidential data without authorization?  The simple answer would be &#8220;no&#8221;: he had an account, he was allowed to use it, that permission had not been revoked, so any access was authorized.</p>
<p>The Ninth Circuit Court of Appeals recently adopted essentially this definition. <a href="http://www.ca7.uscourts.gov/fdocs/docs.fwx?submit=showbr&amp;shofile=05-1522_032.pdf">LVRC Holdings, LLC v. Brekka</a> said that such conduct is not unauthorized for purposes of the CFAA.  The court looked at the language of the statute and a dictionary, and held that an employee has authorization to access a computer when the employer has given permission to use it.   Because Brekka&#8217;s permission to use the computer had not been revoked when he accessed and mailed data to an outside account, the court held that his access was not unauthorized.</p>
<p>The Ninth Circuit rejected the agency-law analysis from a 2006 Seventh Circuit decision, <a href="http://www.ca7.uscourts.gov/fdocs/docs.fwx?caseno=05-1522&amp;submit=showdkt&amp;yr=05&amp;num=1522">International Airport Centers, LLC v. Citrin</a>.  That case had held that an employee&#8217;s authorization to access a computer ended the moment he breached his duty of loyalty to his employer&mdash;in that case, by wiping data from a laptop to hide evidence of misconduct.  But in LVRC, the Ninth Circuit stuck to the text of the CFAA, noting that the CFAA is a criminal statute and should be interpreted in favor of lenience.  Because the Ninth Circuit could find no agency law principles in the text of the CFAA, it held that  a person uses a computer without authorization &#8220;when the person has not received permission to use the computer for any purpose . . . or when the employer has rescinded permission to access the computer and the defendant uses the computer anyway.&#8221;</p>
<p>An aspect of this case that might be of interest to employers is that Brekka did not have a written employment agreement and LVRC had no policies against e-mailing documents to outside accounts.  Such a policy would presumably have made Brekka&#8217;s actions unauthorized.  But it&#8217;s hard to write policies that cover every single thing an employee is not allowed to do.  If a company wrote a policy that &#8220;employees are only authorized to use company computers to the extent that such use is consistent with company interests,&#8221; would that create the Seventh Circuit agency-law definition of unauthorized access?  It seems like it might, but, as always, This Is Not Legal Advice.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/625/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/625/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/625/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=625&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/09/30/ninth-circuit-adopts-plain-language-view-of-authorization-in-cfaa-decision/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>Minnesota&#8217;s Other Data Breach Notification Statute?</title>
		<link>http://blog.subjunctive.com/2009/08/25/minnesotas-other-data-breach-notification-statute/</link>
		<comments>http://blog.subjunctive.com/2009/08/25/minnesotas-other-data-breach-notification-statute/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 16:33:21 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Data Breach Notification Laws]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=560</guid>
		<description><![CDATA[Just about anyone who cares knows by now that most states have data breach notification statutes.  What&#8217;s not as well known, even among security professionals, is that Minnesota has long had another statute that could require reporting of data breaches.  Taken literally, the statute would require reporting even when Minnesota&#8217;s data breach notification [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=560&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Just about anyone who cares knows by now that most states have <a href="http://blog.subjunctive.com/2008/07/23/the-six-states-without-data-breach-notification-laws/">data breach notification statutes</a>.  What&#8217;s not as well known, even among security professionals, is that Minnesota has long had another statute that could require reporting of data breaches.  Taken literally, the statute would require reporting even when Minnesota&#8217;s data breach notification law does not.</p>
<p>The law is in Minnesota Statutes section 609.8911, which was added in 1994.  It reads:</p>
<blockquote><p>A person who has reason to believe that any provision of section 609.88, 609.89, or 609.891 is being or has been violated shall report the suspected violation to the prosecuting authority in the county in which all or part of the suspected violation occurred. A person who makes a report under this section is immune from any criminal or civil liability that otherwise might result from the person&#8217;s action, if the person is acting in good faith.</p></blockquote>
<p>Chapter 609 is Minnesota&#8217;s criminal code, and sections <a href="https://www.revisor.leg.state.mn.us/statutes/?id=609.88">609.88</a>, <a href="https://www.revisor.leg.state.mn.us/statutes/?id=609.89">609.89</a>, and <a href="https://www.revisor.leg.state.mn.us/statutes/?id=609.891">609.891</a> are Minnesota&#8217;s computer crime statutes.  Section 609.8911 therefore says that anyone who &#8220;has reason to believe&#8221; that any successful or attempted unauthorized computer access, damage, or theft has taken place must notify the county prosecutor. </p>
<p>Note what the statute does not say:</p>
<ul>
<li> It&#8217;s not limited to data an organization &#8220;owns or licenses,&#8221; as <a href="https://www.revisor.leg.state.mn.us/statutes/?id=325E.61">section 325E.61</a> is for data breach notification.  </p>
<li>It does not limit the reporting duty to situations where there&#8217;s a reasonable chance that the data was obtained by a third party.  Because Minnesota&#8217;s computer crime statute outlaws attempted acts of computer crime, it seems to be irrelevant whether the attempted computer theft, damage, or unauthorized access was successful.
<li>It&#8217;s not even limited to data the organization handles&mdash;the language of the statute would seem to require telling the county attorney that someone else was hacked.</ul>
<p>That&#8217;s broad.  For example, a literal reading of the statute&#8217;s language would require calling the county prosecutor every time a virus scanner finds a virus.  A virus either accesses a computer without authorization or damages it.  As soon as the virus scanner alerts the user to the the presence of the virus, that user has reason to know that someone committed a computer crime.  Does it matter that the user doesn&#8217;t know who committed the crime, that the county prosecutor can&#8217;t do anything with the information, or that universal compliance with the letter of the law would flood the prosecutor&#8217;s phone line with nothing but &#8220;I just got a virus&#8221; calls?  Maybe in the real world, but there&#8217;s nothing in the statute to suggest that these concerns relieve anyone of the duty to report. </p>
<p>The statute is missing something else: penalty provisions.  Any self-respecting criminal statute has two parts: (1) a list of things not to do, and (2) the penalties for doing those things.  Criminal penalties can be specific, or they can just categorize the crime (as a felony, misdemeanor, etc.), but to have any force, they have to say what the cost of violating the law would be.  There&#8217;s some question whether this is even a criminal statute&mdash;it&#8217;s in the criminal code, but it states an affirmative duty, not a prohibition, and it has no penalty provision.  If it is a criminal statute, it&#8217;s mostly toothless.   </p>
<p>It also appears that the statute has never been used.  A search of Minnesota cases reveals no instance in which the statute was even cited, much less used to convict someone.  </p>
<p>Becuase the statute has no penalties and has never been enforced, can you ignore it?  Maybe.  The stakes of doing so certainly seem low.  But just try to find a lawyer who will say it&#8217;s okay to ignore any statute, even a toothless unenforced statute.   </p>
<p>One reason to comply with the statute is that even a statute without penalty provisions can  form the basis of a negligence per se claim.   Negligence per se is a way for a plaintiff to use a statutory requirement to skip the usual inquiry into whether the defendant used reasonable care.  There are technical requirements for negligence per se claims, but if those are met, a plaintiff&#8217;s case is made much easier.  Here&#8217;s how it might work with section 609.8911: </p>
<ol>
<li>A company sees an attempted attack, but doesn&#8217;t reasonably believe the attacker obtained any personal information, so does not report it.</p>
<li>The attacker, who actually did obtain data, misuses it, harming one of the data subjects.
<li>The data subjects file a class-action against the company, claiming that the company was negligent in not telling them about the breach.  To establish negligence, the plaintiffs point to section 609.8911, which says the company should have reported the attempted breach to the county prosecutor.</ol>
<p>And&mdash;voila&mdash;a statute with no penalty provision has just become a problem for the company.  Admittedly, that&#8217;s a stretch, and there are those &#8220;technical requirements&#8221; referred to earlier, but lawyers have advised their clients to avoid less probable risks.  </p>
<p>The language of the statute, the lack of a penalty, and its immunity provision might make one wonder about the original purpose of the statute.  It turns out that it was actually an early attempt at requiring data breach notification.  In Minnesota House Judiciary Committee hearings held March 18, 1994, Rep. Phyllis Kahn, author of the original Minnesota computer crime law and the duty-to-report provision, said that her bill was an attempt to force banks and financial institutions to report computer crimes they might otherwise prefer to hide.  It was “generally believed,” she said, that computer crimes were under-reported because these institutions preferred maintaining an appearance of security that could be hurt by disclosing a breach.  She acknowledged that the section did not include any penalties for failing to report, but said that her bill would be a “good step forward,” and that she couldn&#8217;t imagine what a good penalty would be.  </p>
<p>A few states have similar duties to report computer crimes, including <a href="http://codes.ohio.gov/orc/2921.22">Ohio</a> and <a href="http://le.utah.gov/~code/TITLE76/htm/76_06_070500.htm">Utah</a>.  Georgia had a similar statute that was repealed in 1991.   A handful of other states have general duties to report any crimes (or sometimes felonies), but in most states, there is no duty to report that one has seen a crime.  The computer duty-to-report statutes appear to be isolated exceptions to this general rule.</p>
<p>Minnesota has a real data breach notification statute for a few years now.  Perhaps it is time for the legislature to repeal or substantially modify section 609.8911.  But until that happens, the safest course for any organization is to send the county prosecutor notice of any attempted data breach.  It may seem silly (partly because, in many cases, it is), but that&#8217;s the letter of the law.  With any luck, the busy prosecutor will respond with, &#8220;Thanks, but please don&#8217;t bother me again.&#8221;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/560/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/560/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/560/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/560/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/560/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/560/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/560/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/560/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/560/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/560/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=560&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/08/25/minnesotas-other-data-breach-notification-statute/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>North Carolina Updates its Data Breach Notification Law and Credit Reporting Laws</title>
		<link>http://blog.subjunctive.com/2009/08/04/north-carolina-updates-its-data-breach-notification-law-and-credit-reporting-laws/</link>
		<comments>http://blog.subjunctive.com/2009/08/04/north-carolina-updates-its-data-breach-notification-law-and-credit-reporting-laws/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 14:31:22 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Data Breach Notification Laws]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=575</guid>
		<description><![CDATA[On July 17, North Carolina amended its data breach notification law and changed some credit freeze and credit monitoring requirements.
The new law, S.B. 1017, makes two small changes to North Carolina’s notification requirements.  First, it requires telling the state Attorney General about breaches of any size, not just those that affect more than one [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=575&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>On July 17, North Carolina amended its data breach notification law and changed some credit freeze and credit monitoring requirements.</p>
<p>The new law, <a href="http://www.ncleg.net/Sessions/2009/Bills/Senate/PDF/S1017v7.pdf">S.B. 1017</a>, makes two small changes to North Carolina’s notification requirements.  First, it requires telling the state Attorney General about breaches of any size, not just those that affect more than one thousand people.  Second, it requires the notifications to include contact information for the consumer reporting agencies (CRAs), the FTC, and the North Carolina Attorney General’s office.  </p>
<p>The statute still has the same notification triggers as before:  it applies to any business that “owns or licenses”  personal information.  The law applies to businesses that own or license data, but the statute’s definition of a “security breach” is not limited to breaches of  information the business owns or licenses.  It may just be a quirk of wording, but it looks like the law requires any business that owns or licenses data to notify people affected by <i>any</i> security breach.  In fact, there’s nothing in the language saying that companies only have to disclose their own breaches:</p>
<blockquote><p>N.C. Gen. Stat. § 75-65(a): Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. . . .</p></blockquote>
<p>I doubt that’s the intention of the law, but there’s the language: companies that own or license data shall notify the affected person that “there has been a security breach.”  So, maybe it’s a business’s duty to inform consumers that a competitor has been breached?</p>
<p>Also note the statute’s broad interstate reach, pulling in “any business that conducts business in North Carolina that owns or licenses personal information in any form.”  It doesn’t even bother to limit the reach of the statute to businesses that own or license personal information about North Carolina residents.  </p>
<p>The law’s big changes are to consumer credit reporting.  It made quite a few changes to the state’s security freeze law.   It reduced the time Consumer Reporting Agencies (CRAs) can take to initiate or remove a freeze from five days to three, gives CRAs fifteen minutes to temporarily lift a freeze once the consumer has requested a temporary lift by phone or e-mail (if the request is by mail, the CRA has three days), prohibits the CRAs from charging for placing, removing, or temporarily lifting a credit freeze unless the request was by mail (the old law allowed charging $10 per request), and requires that credit reports under a freeze say that the freeze does not reflect a negative score, history, report, or rating.  </p>
<p>Finally, the law adds a “Credit Monitoring Services Act,” which might as well be titled the “freecreditreport.com” act.  It requires anyone who provides credit monitoring or obtains a credit report on behalf of a consumer for a fee to give clear and conspicuous notice of the consumer’s right to a free credit report.   </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/575/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/575/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/575/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=575&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/08/04/north-carolina-updates-its-data-breach-notification-law-and-credit-reporting-laws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>Missouri Joins the List of States with Data Breach Notification Laws</title>
		<link>http://blog.subjunctive.com/2009/07/24/missouri-joins-the-list-of-states-with-data-breach-notification-laws/</link>
		<comments>http://blog.subjunctive.com/2009/07/24/missouri-joins-the-list-of-states-with-data-breach-notification-laws/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 02:33:21 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Data Breach Notification Laws]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=563</guid>
		<description><![CDATA[Missouri finally passed a data breach notification law this year as part of an omnibus crime bill, H.B. 62.  That brings the number of states without data breach notification laws to five: Alabama, Kentucky, Mississippi, New Mexico, and South Dakota.  
The law itself is pretty standard, at least as much as anything with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=563&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Missouri finally passed a data breach notification law this year as part of an omnibus crime bill, <a href="http://www.house.mo.gov/billtracking/bills091/biltxt/truly/HB0062T.HTM">H.B. 62</a>.  That brings the number of <a href="http://blog.subjunctive.com/2008/07/23/the-six-states-without-data-breach-notification-laws/">states without data breach notification laws</a> to five: Alabama, Kentucky, Mississippi, New Mexico, and South Dakota.  </p>
<p>The law itself is pretty standard, at least as much as anything with fifty-five versions can be called &#8220;standard.&#8221;    It requires anyone with personal information about a Missouri resident to notify the resident of a breach of security, defines &#8220;personal data&#8221; as any of the usual suspects plus a name (although, as <a href="http://isc.sans.org/diary.html?storyid=6856&amp;rss">John Bambenek</a> points out, a name isn&#8217;t actually needed to steal money from someone&#8217;s checking account  with ACH), requires the notice to be made &#8220;without unreasonable delay,&#8221; and allows safe harbors for encryption and cases where the data handler determines identity fraud is not likely.  Notification can be written, by phone, or with certain electronic notice.  The law allows substitute notice if personal notice would cost over $100,000, if more than 50,000 people are affected, or if there isn&#8217;t enough contact information to contact people directly.  A data handler who has to notify more than one thousand people also has to alert the media, the attorney general&#8217;s office, and the credit reporting agencies.  Enforcement is by the attorney general, with a civil penalty of $50,000 per breach for willful violations. </p>
<p>Senator Feinstein&#8217;s national data breach notification bill <a href="http://blog.subjunctive.com/2009/01/10/sen-feinstein-reintroduces-federal-data-breach-notification-bill/">hasn&#8217;t emerged from committee</a> since she introduced it in January.  It&#8217;s now a bit of a race to see which happens first: a nationwide breach notification bill, or the remaining states passing their own versions.  </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/563/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/563/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/563/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=563&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/07/24/missouri-joins-the-list-of-states-with-data-breach-notification-laws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>Nevada Updates Encryption Law; Adds PCI Requirement</title>
		<link>http://blog.subjunctive.com/2009/06/23/nevada-updates-encryption-law-adds-pci-requirement/</link>
		<comments>http://blog.subjunctive.com/2009/06/23/nevada-updates-encryption-law-adds-pci-requirement/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 15:52:19 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=548</guid>
		<description><![CDATA[Last October, a Nevada law took effect that requires encryption of all personal information in transit.    Perhaps in response to criticisms of that law, Nevada just updated the law&#8212;and added a PCI compliance requirement.
The new law repeals the previous encryption statute, and adds a new one to Nevada Revised Statutes section 603A. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=548&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Last October, a Nevada law took effect that <a href="http://leg.state.nv.us/Statutes/73rd/Stats200525.html#Stats200525page2506">requires encryption of all personal information in transit</a>.    Perhaps in response to <a href="http://www.realtime-itcompliance.com/laws_regulations/2007/10/new_nevada_law_explicitly_requ.htm">criticisms</a> <a href="http://www.itbusinessedge.com/cm/community/news/gov/blog/nevada-encryption-law-called-too-vague/?cs=20372">of</a> that law, Nevada just updated the law&mdash;and added a PCI compliance requirement.</p>
<p>The <a href="https://www.leg.state.nv.us/75th2009/Bills/SB/SB227_EN.pdf">new law</a> repeals the previous encryption statute, and adds a new one to <a href="http://www.leg.state.nv.us/Nrs/NRS-603A.html">Nevada Revised Statutes section 603A</a>.  The previous law was criticized for not clearly defining &#8220;encryption;&#8221; the new law tries to fix that by defining encryption as something adopted by NIST or any other &#8220;established standards setting body&#8221;:</p>
<blockquote><p>(b) “Encryption” means the protection of data in electronic or optical form, in storage or in transit, using:<br />
    (1) An encryption technology that has been adopted by an established standards setting body, including, but not limited to, the Federal Information Processing Standards issued by the National Institute of Standards and Technology, which renders such data indecipherable in the absence of associated cryptographic keys necessary to enable decryption of such data; and<br />
    (2) Appropriate management and safeguards of cryptographic keys to protect the integrity of the encryption using guidelines promulgated by an established standards setting body, including, but not limited to, the National Institute of Standards and Technology. </p></blockquote>
<p>Although &#8220;adopted&#8221; is not necessarily the word I&#8217;d use to describe FIPS approval of encryption protocols, the Nevada legislators should get credit for paying some attention to key management.</p>
<p>Unfortunately, Nevada did not do so well when it decided to add a PCI DSS requirement to the law.  Unlike Minnesota, <a href="http://blog.subjunctive.com/2008/06/08/minn_dss/">which requires compliance with a specific narrow provision of PCI DSS</a>, Nevada simply mandated compliance with the whole standard:</p>
<blockquote><p>If a data collector doing business in this State accepts a payment card in connection with a sale of goods or services, the data collector shall comply with the current version of the Payment Card Industry (PCI) Data Security Standard, as adopted by the PCI Security Standards Council or its successor organization, with respect to those transactions, not later than the date for compliance set forth in the Payment Card Industry (PCI) Data Security Standard or by the PCI Security Standards Council or its successor organization.</p></blockquote>
<p>In computer programming lingo, that&#8217;s PCI by reference, and it&#8217;s a huge delegation of power by the Nevada legislature to the PCI Standards Council.  The PCI Standards Council is not elected, nor is it appointed by elected officials.  Giving the force of law to anything the PCI Standards Council says raises constitutionality questions.  At least the law said &#8220;with respect to those transactions,&#8221; so the PCI Standards Council only has the power to enact laws related to payment processing.  If the Standards Council decides that all payment processors must pay the Standards Council $1 billion per year, that would only have the force of Nevada law if the payments are related to transactions.  Maybe.</p>
<p>The other problem with the new law is that still applies to any &#8220;data collector doing business in&#8221; Nevada.  It does not apply only to transactions through Nevada, or to transactions involving Nevada residents, but to anyone with business in Nevada.  Suppose my business is located in Missouri, but sets up a booth at a Las Vegas trade show every year.  Is that &#8220;doing business&#8221; in Nevada?  Are my Missouri-only transactions now subject to the Nevada law?  </p>
<p>Nevada&#8217;s law lacks the penalties prescribed in Minnesota&#8217;s law.  The Minnesota law allows card issuers to recover the cost of replacing cards due to a data breach; Nevada&#8217;s law includes no such provision.  Instead, the penalties for not complying with PCI DSS are the same as for a data breach: the breached entity can sue the data thief, and the attorney general can get an injunction against anyone violating the statute.  </p>
<p>Even without that penalty, however, the official codification as a statutory requirement could make PCI DSS the basis of a negligence <i>per se</i> claim.  When it applies, negligence <i>per se</i> allows a plaintiff to skip the whole &#8220;reasonable person&#8221; evaluation of a standard of care in a negligence suit by pointing to a statute.  For example, a pedestrian hit by a driver running a red light could point to the statutes requiring people to obey traffic signals as showing that the driver was negligent <i>per se</i>.  The statutory PCI DSS requirement might do the same thing for that standard: allow plaintiffs to say that PCI DSS itself establishes the standard of data security due care.  In practice, however, it may not matter, because plaintiffs have had too much problem showing cause-in-fact and harm to ever reach the standard-of-care questions.  </p>
<p>Even so, the PCI DSS requirement-by-reference is troubling, and a little sloppy.    Legislating technology is hard: write something that&#8217;s too general, and it can become meaningless; write something that&#8217;s too specific, and you have to re-write the law every year.  But that&#8217;s no excuse for giving up by pointing to a private standard and saying, &#8220;do that.&#8221;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/548/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/548/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/548/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/548/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/548/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/548/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/548/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/548/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/548/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/548/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=548&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/06/23/nevada-updates-encryption-law-adds-pci-requirement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>Court Rules that LifeLock Violates California&#8217;s Unfair Competition Laws</title>
		<link>http://blog.subjunctive.com/2009/05/30/court-rules-that-lifelock-violates-californias-unfair-competition-laws/</link>
		<comments>http://blog.subjunctive.com/2009/05/30/court-rules-that-lifelock-violates-californias-unfair-competition-laws/#comments</comments>
		<pubDate>Sun, 31 May 2009 04:22:48 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Fraud Alerts]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[LifeLock]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=529</guid>
		<description><![CDATA[A federal district court in California has granted partial summary judgment in Experian Information Services, Inc. v. Lifelock, Inc., holding that LifeLock violates the state&#8217;s Unfair Competition Law.  
LifeLock&#8212;infamous for its TV ads in which the founder puts his Social Security Number on the side of trucks&#8212;exploits an opportunity in fraud protection law.  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=529&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A federal district court in California has <a href="http://jtgraves.files.wordpress.com/2009/05/lifelock.pdf">granted partial summary judgment</a> in Experian Information Services, Inc. v. Lifelock, Inc., holding that LifeLock violates the state&#8217;s Unfair Competition Law.  </p>
<p>LifeLock&mdash;infamous for its TV ads in which the founder puts his Social Security Number on the side of trucks&mdash;exploits an opportunity in fraud protection law.   <a href="http://www.law.cornell.edu/uscode/html/uscode15/usc_sec_15_00001681---c001-.html">15 U.S.C. § 1681c-1</a> allows &#8220;a consumer, or an individual acting on behalf of or as a personal representative of a consumer&#8221; to put a free ninety-day fraud alert on her credit file.  This &#8220;initial&#8221; fraud alert requires the consumer to claim &#8220;a suspicion that [she] has been or is about to become a victim of fraud or related crime.&#8221;   The law also allows for an &#8220;extended&#8221; alert, which lasts for seven years, but requires that the consumer have suffered actual fraud.  What LifeLock does is place and renew initial fraud alerts every ninety days on behalf of customers, creating a sort of permanent initial fraud alert.  </p>
<p>Experian doesn&#8217;t like that, partly because it has to expend resources processing all those repeating fraud alerts.  So it sued LifeLock, claiming unfair competition, among a host of other complaints.  The court agreed.  </p>
<p>Its reasoning, in a nutshell, was this: the credit freeze law only allows fraud alerts to be placed by the consumer or an <i>individual</i> acting on her behalf.  According to the legislative history of § 1681c-1, the word &#8220;individual&#8221; was specifically chosen over &#8220;person&#8221; so that individuals such as family members, attorneys, and guardians could place fraud alerts, but not companies (which are legally considered to be &#8220;people&#8221;).  The court found that language to show a public policy against companies placing fraud alerts.  Because the &#8220;unfair&#8221; business practices prohibited by California&#8217;s Unfair Competition Law include not only illegal practices, but also those contrary to public policy, the court found LifeLock&#8217;s placement of initial fraud alerts on behalf of individuals to be an unfair business practice, and thus illegal. </p>
<p>What&#8217;s interesting about this ruling&mdash;other than its implications for LifeLock&mdash;is that it reached its result without ever considering whether permanent initial fraud alerts themselves are contrary to the statute.  It only says that organizations cannot place fraud alerts.  But what about the practice of continually renewing an &#8220;initial&#8221; fraud alert so that it&#8217;s essentially permanent?  The statute seems to contemplate specific remedies under specific situations: if you think you might be at risk of fraud, you get a ninety day alert that puts some restrictions on anyone who pulls your credit report.  If you have been the victim of fraud, you get a seven-year alert with stricter restrictions.  <a href="http://volokh.com/posts/1243621417.shtml">Arguably</a>, if Congress had intended to allow for a permanent fraud alert, it would have provided for one.  This ruling doesn&#8217;t address that issue.    </p>
<p>This doesn&#8217;t seem to slam the door on all permanent initial fraud alerts.  An individual consumer could always call all three credit reporting agencies every ninety days to place the fraud alert herself.  She could also have an attorney, acting as her personal representative, do it for her.  What this ruling says is that organizations can&#8217;t place fraud alerts: only individuals.   It also effectively outlaws LifeLock&#8217;s business in California&mdash;or will, once the appeals are exhausted.  </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/529/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/529/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/529/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/529/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/529/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/529/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/529/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/529/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/529/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/529/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=529&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/05/30/court-rules-that-lifelock-violates-californias-unfair-competition-laws/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
		<item>
		<title>IT Consulting Firm Sued for Certifying CardSystems as CISP Compliant</title>
		<link>http://blog.subjunctive.com/2009/05/27/it-consulting-firm-sued-for-certifying-cardsystems-as-cisp-compliant/</link>
		<comments>http://blog.subjunctive.com/2009/05/27/it-consulting-firm-sued-for-certifying-cardsystems-as-cisp-compliant/#comments</comments>
		<pubDate>Thu, 28 May 2009 00:07:40 +0000</pubDate>
		<dc:creator>Jim Graves</dc:creator>
				<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://blog.subjunctive.com/?p=479</guid>
		<description><![CDATA[There&#8217;s a new variety of post-breach lawsuit.  We&#8217;ve seen consumers sue merchants, banks sue merchants, and banks sue banks.  Now, a bank has sued an IT consulting firm for certifying CardSystems as CISP compliant.  Professional malpractice suits are nothing new in medicine or law practice, but we have not yet seen many [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=479&subd=jtgraves&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a new variety of post-breach lawsuit.  We&#8217;ve seen <a href="http://www.boston.com/business/globe/articles/2007/01/30/tjx_faces_class_action_lawsuit_in_data_breach/">consumers sue merchants</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9001391">banks sue merchants</a>, and <a href="http://op.bna.com/pl.nsf/id/dapn-6hxkj9/$File/BJsdecision.pdf">banks sue banks</a>.  Now, a bank has sued an IT consulting firm for certifying CardSystems as CISP compliant.  Professional malpractice suits are nothing new in medicine or law practice, but we have not yet seen many security consultants sued for malpractice.  That may change as standards and certification become more important.  </p>
<p>CardSystems was a payment processor that experienced <a href="http://datalossdb.org/incidents/110">a massive security breach</a> in 2005.  Intruders compromised tens of millions of credit card numbers, leading to millions of dollars in fraudulent charges.   In the wake of the breach, banks canceled and re-issued thousands of credit cards.  Mastercard and Visa terminated their contracts with CardSystems, and CardSystems eventually filed for bankruptcy.  It was the first example of a data breach killing a major company.  </p>
<p>Merrick Bank is an acquiring bank, which means that it contracts with merchants to handle their credit card sales.  Merrick used CardSystems to process those payments.  Because the card association operating agreements make acquiring banks reimburse losses created by card processors, Merrick paid about $16 million to the associations after the CardSystems breach.  </p>
<p>But Merrick does not just blame CardSystems for the breach.  It also blames Savvis, the IT consulting firm that certified CardSystems&#8217;s compliance with Visa&#8217;s Cardholder Information Security Program (CISP).  In May 2008, Merrick sued Savvis for negligence and negligent misrepresentation in certifying CardSystems as CISP compliant.  Last week, the federal district court in Missouri transferred the case to Arizona and joined it with some similar cases, which is why a year-old case is <a href="http://www.finextra.com/fullstory.asp?id=20067">being reported</a> as if <a href="http://www.courthousenews.com/2009/05/26/Merrick_Bank_Seeks_$16M_for_Hacking.htm">it were new</a>.  </p>
<p>New or not, the lawsuit is another example of an unfortunate tendency to equate compliance with security.  I <a href="http://blog.subjunctive.com/2009/02/16/security-is-not-a-checklist/">blogged before</a> about a PCI DSS trainer who said that no one who was PCI DSS compliant had ever been breached&mdash;implying, if not directly stating, that PCI DSS compliance creates perfect security.  Unfortunately, that seems to be the official line: Robert Russo, Director of the Payment Card Industry Data Security Standards Council, <a href="http://homeland.house.gov/SiteDocuments/20090331142034-90056.pdf">said much the same thing in Congressional testimony in March</a> (p. 8: &#8220;[No] entity that has been subject to a data breach&nbsp;.&nbsp;.&nbsp;.&nbsp;was also in full compliance with the PCI DSS at the time of the breach&#8221;).  Calling something a magic cure-all is a sure sign of <a href="http://www.schneier.com/crypto-gram-9902.html">snake oil</a>; the PCI Council would do well to stop selling PCI DSS as a magic elixir.  </p>
<p>Security assessment malpractice suits could have a long-term effect on the way assessments are conducted.  Version 1.1 of PCI DSS started allowing compensating controls that permit compliance even when some requirements are not met.  An assessor that requires strict adherence to PCI DSS requirements, with no allowance for compensating controls, can always point to those requirements when faced with a negligence claim.  But when an assessor certifies compliance using compensating controls, it exercises more independent judgment, creating room for a negligence claim.  The result could be less use of compensating controls.          </p>
<p>There could also be some positive effects.  Compliance requirements without liability for assessors make it too tempting for both parties to rush through the process.  Sloppy consultants will assess as quickly as possible then hop to the next paying assessment.  Some clients, more interested in the certification than security, will shop for the lowest-priced certification they can find.  Not all assessments are like that, but security certifications make them more likely.  Malpractice liability gives the consultant something to think about other than how quickly he can get paid for calling someone secure.  But even security consultants who do things right need to be careful about how they structure engagement contracts, because these lawsuits will probably become more common.</p>
<p>One lesson for security consultants, and especially PCI assessors, is to be careful with engagement contracts.  Savvis is not being sued by a client, but by a customer of a client&mdash;someone with whom Savvis had no contractual relationship.  A limitation of liability and disclaimer of warranty have no force against someone who is not a party to the contract.  A consulting firm would therefore want an indemnification clause in its contract, which would require the client to protect the consultant against anyone else in a claim arising from the engagement.  But indemnification clauses aren&#8217;t always possible, and the client probably wants the assessor to indemnify it.  </p>
<p>Of course, the risks are lower if the negligence claims fail.  Negligence cases against processors and merchants have not fared well overall; it would seem even harder to recover against an assessor who certified a breached organization.  The assessor could always raise the &#8220;Richard Russo defense&#8221; by blaming the breached organization for post-assessment changes.  The basic negligence case is also harder: the plaintiff would have to show not only that the breached organization was negligent, but that the assessor knew or should have known that the breached organization was non-compliant at the time of the assessment, and that certification of the organization rose to the level of negligence.  Proximate cause is probably harder to show, because the causality chain is the breached organization&#8217;s chain plus whatever was wrong with the assessment.  Apportionment of fault could also be an issue: how much fault lies with the assessor for certifying compliance, and how much lies with the company for being non-compliant?  The answer would be fact-specific, but the issues suggest that a case against an assessor would not be an easy win.    </p>
<p>Issues like these are probably why PCI DSS assessors must carry cyber-risk and privacy liability insurance (<a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_validation_requirements_for_qualified_security_assessors_QSAs_v1-1.pdf">QSA Validation Requirements v.1.1a, p. 40</a>).  The more people think that certification is all there is to security, the more the firms who provide those certifications will have to deal with lawsuits like these.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jtgraves.wordpress.com/479/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jtgraves.wordpress.com/479/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jtgraves.wordpress.com/479/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jtgraves.wordpress.com/479/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jtgraves.wordpress.com/479/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jtgraves.wordpress.com/479/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jtgraves.wordpress.com/479/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jtgraves.wordpress.com/479/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jtgraves.wordpress.com/479/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jtgraves.wordpress.com/479/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.subjunctive.com&blog=3852229&post=479&subd=jtgraves&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.subjunctive.com/2009/05/27/it-consulting-firm-sued-for-certifying-cardsystems-as-cisp-compliant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Jim Graves</media:title>
		</media:content>
	</item>
	</channel>
</rss>