Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Saturday, February 21, 2009

Fight Big Brother!

While the Internet Safety Act is not the first bill to propose forced record retention of Internet traffic logs, it is by and large the most far reaching and demanding of such bills. While this lengthy bill has laudable provisions for the supposed prevention of child endangerment, it's requirement that virtually ever Internet access point in the country keep two years worth of utilization records is not just highly invasive it is ridiculously burdensome to small businesses and individuals.

Just because the European Parliament is comfortable with this level of potential privacy invasion does not mean that freedom-loving Americans should become so complacent on the issue. Proponents of such bills say that requiring Internet Service Providers to maintain activity logs for two years allows law enforcement to review past behavior once someone comes to their attention as a potential threat to young children. What ever happened to 'just cause'?

Now, let's talk about the REAL duck on the table. Have you read about any electronic records breaches lately? Hmmm??? So, the Government wants providers to keep two years of records on everyone's activities in case THEY need them to investigate your past history. Isn't it more likely that other savvy hackers will steal those records for malevolent purposes? Identity theft? Blackmail?

Oh, BTW, stop thinking that secure-HTTP will prevent data thieves from stealing your banking, health, and other private information. It was announced this week that the bad guys are improving their ability to sneak their way into your private HTTPS sessions

The Senate bill is S.436. The House bill is H.R.1076. Note them. Contact your representatives. Oppose them. I have written my own Representative, both my Senators, and the President. I've only done this three other times in the last 28 years.

Tuesday, February 13, 2007

Too bad TJMX wasn't an ISP

According to SANS: "US Congressman Lamar Smith (R-TX) has introduced the Safety Act, which
would require Internet Service Providers (ISPs) to retain all customers' web surfing, IM conversations and email traffic indefinitely. ISPs failing to comply would face fines and a one-year prison term."
See: News story.

The point of the legislation is to facilitate investigations by law enforcement. However, this is potentially another slap in the face of privacy.

But on another note, have Smith and his supporters not been paying attention to what's been going on in the financial industry? TJ Maxx is in trouble for holding onto data that it did not need, and that it was legally bound not to. Holding on to masses of private data "just in case" is a recipe for disaster. Rarely will that data be utilized for the "just in case" scenario that it was intended to be kept for. It is more likely that such data will fall into the wrong hands and be utilized for nefarious purposes.

Representatives Bobby Rush (D-Ill.) and Cliff Stearns (R-Fla.) do get it. Last week they introduced the Data Accountability and Trust Act, which would authorize the Federal Trade Commission (FTC) to establish data privacy requirements for businesses. Companies would be required to conduct vulnerability assessments and develop and implement policies for eliminating data they no longer need.

Mr Smith's family obviously did not have any dealings with TJ Maxx. Or maybe he's just a narrow minded idiot. ... Or MAYBE it really wasn't Smith who sponsered this bill, but someone who stole his identity and is promoting this ridiculous legislation in his name to ruin his reputation!