Several short items – The battle over NSA spying is not over, the OPM breach is better or worse than we thought, The first ruling on net neutrality is here, Senator McConnell is trying to insert the cyber protection bill CISA inside the defense appropriations bill in a way that does not allow for debate. […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
Gene Kaspersky, head of the Russian anti-malware vendor and security research labs reported yesterday that the malware that infected his labs last year was also found … drum roll … at the hotels for the delegates to the Iranian nuclear talks (see article). Kaspersky reported yesterday (see article) that their lab was the victim of […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
The government seems to be avoiding telling us what information was taken. This could be because they don’t know – or because they do know. One speculation that keeps coming up, and that the OPM has not denied, is that the hackers got SF-86 data. If that is true, that is a problem. I will […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
It is common, if not automatic, for companies that have their information systems breached to offer credit monitoring services, and this includes medical record breaches. Consumers can also pay companies like Lifelock to provide the same services. The question is do they work and the answer is, for the most part, not really. Brian Krebs […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
Peter Swire, was a member of the President’s intelligence review team that was formed after the Snowden leaks. Today he wrote a guest column for the International Association of Privacy Professionals on what the Act did and did not change. The article is linked on the References page or you can go to it directly […]
Continue reading →
[DISPLAY_ACURAX_ICONS]
Columbia Casualty paid Cottage Health System a little over $4 million after a breach in December 2013. Columbia wants their $4 million back, plus attorney’s fees and expenses because, they say, Cottage “did not follow minimum required practices for protecting information and did not truthfully attest to its security controls” (see article). Here is more […]
Continue reading →
[DISPLAY_ACURAX_ICONS]