Remember the breach reported by New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E) back in January? Jeff Platsky reports the results of an investigation into the utilities’ security: A potential data breach at New York State Electric & Gas Corp. not only drew the ire of customers but is now…
Category: Commentaries and Analyses
EU wants breach notification for certificate authorities
Stewart Mitchell reports: European authorities plan to clamp down on certificate authorities, demanding security signing organisations speak up if hit by hackers. Certificate authorities – either private or government backed – issue digital certificates that verify web pages and code, and are a key component of the web running smoothly and securely. But as last…
Cybercrime disclosures rare despite new SEC rule
Embedded in revisions to a proposed cybersecurity law are some provisions on mandatory breach notification. Richard Lardner reports: The chairman of the Senate Commerce, Science and Transportation Committee, Sen. Jay Rockefeller, D-W.Va., is adding a provision to cybersecurity legislation that would strengthen the reporting requirement. The SEC’s cybersecurity guidance issued in October is not mandatory. It was…
Old law puts school data at risk
Susan Palmer reports: An obscure state regulation — one that requires districts to keep student records for decades — is one reason several thousand Eugene School District students are at risk of having their Social Security numbers hijacked following a security breach of the district’s electronic records. School districts must retain student records for 75…
Should we send in CSI to figure out the source of a data dump?
Here’s a great example of the perils in trying to report on hacks or breaches disclosed on Twitter or Pastebin. A hacker who self-identified as Reckz0r initially claimed to have hacked Visa and MasterCard and to have dumped 50GB worth of data (without credit card numbers). I had my doubts, and wasn’t surprised to read…
Is network offense the best network defense?
Stewart Baker responds to Joseph Menn’s recent report on companies fighting back against attackers. He comments on the different offensive strategies: Here’s the problem. A generation of computer crime lawyers at the Justice Department has devoted their careers to discouraging the reaction that Menn describes. That’s because the fundamental law in this area, the law…