Monday, December 2, 2013

Dutch Regulator Finds Google in Breach of Privacy Law

Dutch Regulator Finds Google in Breach of Privacy Law


01 December 2013

The Netherlands is one of the six EU member states that have undertaken a formal investigation of Google's privacy compliance following the 2012 amalgamation of its various privacy policies. The Dutch Data Protection Authority has now found Google to be in breach of multiple aspects of the the Dutch data protection act.


"Google spins an invisible web of our personal data, without our consent. And that is forbidden by law," says Jacob Kohnstamm, chairman of the DPA. He has not yet decided whether to take formal enforcement action, but has invited Google to attend a further hearing before that decision.
In its findings titled Investigation into the combining of personal data by Google, the DPA defines Google users as either authenticated (signed in with an account), unauthenticated (users of services such as Search that don't require an account) or passive (visitors to sites that deliver Google cookies). It then looked at these users in relation to four specific purposes for which Google collects and combines personal data: "the personalization of requested services, product development, display of personalized ads, and website analytics."
Google's basic arguments for the lawfulness of its data collection are that users imply consent to the collection of personal data, that it is necessary for the company's business model, and that the company provides adequate safeguards for users to protect their data  (such as opt-outs and using the incognito browsing mode in Chrome). Throughout its investigation, however, the DPA concluded that Google failed to meet the underlying legal requirements of proportionality (legitimate, suitable, necessary and reasonable) and subsidiarity (the smallest degree necessary) when collecting personal data.
"Google has not demonstrated and this investigation has not shown that the investigated data processing activities relating to the combining of data about and from multiple services are necessary (i.e. meet the requirements of proportionality and subsidiarity)."
The DPA also points out that 'implied' consent is insufficient in Dutch law, which requires unambiguous consent. "There is no evidence," it says, "of unambiguous consent... since Google does not offer data subjects any (prior) options to consent to or reject the examined data processing activities."
Because of the lack of proportionality, subsidiarity and unambiguity, Google has no legal grounds for collecting personal data in the way that it does; and because of that, "the personal data collected by Google from all three types of users are not being collected for legitimate purposes (as being examined here), with the result that Google is acting in breach of the provisions of Article 7 of the Wbp in this respect as well."
The report's final conclusion for all three types of user and the four specified purposes is, "Google does not obtain unambiguous consent for the examined data processing activities and has no other legal grounds under Article 8 of the Wbp. For this reason, by combining data from and about multiple services for the four examined actual purposes Google is acting in breach of Article 8 of the Wbp."
Before deciding whether to impose enforcement of these findings, the DPA will hold a further hearing with Google. In response, a Google statement said, "Our privacy policy respects European law and allows us to create simpler, more effective services. We have engaged fully with the Dutch DPA throughout this process and will continue to do so going forward."

This article is featured in:
Compliance and Policy
 
http://www.infosecurity-magazine.com/view/35903/dutch-regulator-finds-google-in-breach-of-privacy-law/?utm_medium=referral&utm_source=pulsenews

Tuesday, November 12, 2013

70,000 customers at risk from 'sophisticated criminal attack'


Supervalu customers who took advantage of a holiday offer are at risk

Supervalu customers who took advantage of a holiday offer are at risk

Up to 70,000 people in Ireland who took advantage of a customer loyalty offer could have been victims of a "sophisticated criminal attack".
The company, Loyaltybuild, said it had suffered a security data breach.
Supermarket chain Supervalu has asked 62,500 people involved in its Getaway Breaks scheme to contact their banks - 6,800 of those are in Northern Ireland.
AXA Ireland has said up to 8,000 of its customers may have been affected.
Loyaltybuild has advised the Data Protection Commissioner of Ireland and the police.
In a statement on its website, it added: "As part of our ongoing investigation, into a system breach identified last month, Loyaltybuild has discovered that it has been the victim of a sophisticated criminal attack.
"We are working around the clock with our security experts to get to the bottom of this and to further enhance our security in order to protect our valued customers, who are of paramount importance to us."

Start Quote

We are working around the clock with our security experts to get to the bottom of this”
End Quote Loyaltybuild statement
Customers are advised to check their payment cards for suspicious activity.
The breach was discovered on 25 October and a third party firm has been running forensic tests.
Supervalu said the incident was more extensive than initially thought. Customers who made Getaway Break bookings between January 2011 and February 2012 have been advised to contact their financial institutions.
Customers are also being warned to treat any unsolicited communication claiming to represent Supervalu Getaway Breaks or Loyaltybuild with "extreme caution".
Supervalu said it was continuing to work with Loyaltybuild to resolve the issue as quickly as possible but had also engaged its own IT security consultants to investigate the Loyaltybuild system.
It also emphasised that the breach of security was in data collected and held by Loyaltybuild on Getaway Breaks customers only and did not involve other customers of Supervalu.
AXA Ireland confirmed its customers' data may also have been compromised by the Loyaltybuild breach. Up to 8,000 customers may have been affected.
In a statement, the company said: "Loyaltybuild's forensic team has now advised that there is a high risk that an unauthorised third party accessed details of payment cards used to pay for AXA Leisure Breaks between January 2011 and February 2012.
"This investigation is still ongoing in relation to whether other personal data of customers has been compromised," it added.
AXA said all other customer transactions by payment card were unaffected.

Banken worstelen met kosten compliance en toezicht

Foto bij het bericht Banken worstelen met kosten compliance en toezicht

De krimpende financiƫle sector heeft steeds meer moeite om de honderden miljoenen te verdienen die nodig zijn om te voldoen aan regelgeving uit Brussel en Washington. Ook het toezicht, waaraan de banken meebetalen, wordt ieder jaar duurder.
Een en ander blijkt uit een rondgang langs banken, vermogensbeheerders en handelshuizen door Het Financieele Dagblad. De toezichtskosten van De Nederlandsche Bank (DNB) zijn dit jaar begroot op 149 miljoen euro. Dat was in 2008 nog 98 miljoen euro. AFM zag de kosten stijgen van 68,5 miljoen euro naar 85,3 miljoen euro. Vanaf volgend jaar draagt de overheid niet meer bij aan deze instellingen en moet de sector volledig de kosten dragen.
Wetgevingspakketten als het Brusselse Emir, Mifid-II en het Amerikaanse Dodd-Frank zorgen er bovendien voor dat banken hele teams van consultants en juristen aan het werk hebben om te voldoen aan de regels. Ondertussen is sinds de crisis ongeveer een kwart van de werknemers bij banken en verzekeraars zijn baan kwijtgeraakt.

Sunday, November 3, 2013

Baltimore County workers' personal information stolen

Baltimore County workers' personal information stolen


The personal information of current and past Baltimore County employees was stolen by a former employee of a county information technology contractor.
How many victims? More than 12,000 current and former Baltimore County employees.
What type of personal information? Social Security numbers, home addresses, salaries, leave balances, and county identification numbers.
What happened? The personal information of current and past Baltimore County employees was found on the computer of a man who was a former employee of an information technology contractor hired by the county. County officials believe the information was accessed when the suspect brought a new computer to a county employee who had downloaded the information as part of a work assignment.
What was the response? County officials sent letters to those affected by the breach, informing them that no personal financial information of any current or former employee was found on the computer.
Details: Authorities discovered the data while investigating an unrelated identity theft case in which the alleged perpetrator was involved. In spring of 2013, he was indicted by the Baltimore County state attorney's office after a neighbor filed a complaint that he had made purchases using fake checks and IDs. After authorities executed a search warrant on his home, personal items, including his computer, were seized. He fled the state and wasn't arrested.
On October 15, he was taken into custody in another state and he will now be extradited to Maryland to face identity theft charges that are unrelated to the Baltimore County employees incident.
Quote: “At this time, there is no evidence that any employee's information was misused in any way,” Fred Homan, county administrative officer, wrote in a letter to those affected by the breach.
Source: baltimoresun.com, The Baltimore Sun, “Former employee of contractor obtained Balt. Co. workers' personal data,” Oct. 31, 2013.

http://www.scmagazine.com/baltimore-county-workers-personal-information-stolen/article/319162/

Saturday, October 26, 2013

How the modern world depends on encryption

How the modern world depends on encryption


Credit cards
 
Encryption helps to ensure that credit card transactions stay secure

 
Encryption makes the modern world go round. Every time you make a mobile phone call, buy something with a credit card in a shop or on the web, or even get cash from an ATM, encryption bestows upon that transaction the confidentiality and security to make it possible.

"If you consider electronic transactions and online payments, all those would not be possible without encryption," said Dr Mark Manulis, a senior lecturer in cryptography at the University of Surrey.

At its simplest encryption is all about transforming intelligible numbers or text, sounds and images into a stream of nonsense.

There are many, many ways to perform that transformation, some straightforward and some very complex. Most involve swapping letters for numbers and use maths to do the transformation. However, no matter which method is used the resulting scrambled data stream should give no hints about how it was encrypted.

During World War II, the Allies scored some notable victories against the Germans because their encryption systems did not sufficiently scramble messages. Rigorous mathematical analysis by Allied code crackers laid bare patterns hidden within the messages and used them to recreate the machine used to encrypt them.

Those codes revolved around the use of secret keys that were shared among those who needed to communicate securely. These are known as symmetric encryption systems and have a weakness in that everyone involved has to possess the same set of secret keys.

In the modern era, a need has arisen to communicate securely with people and organisations we do not know and with whom we cannot easily share secret keys, said Dr Manulis. This need has given rise to public-key cryptography. Despite the formidable name it encapsulates a simple idea.

Colossus valves Wartime code-cracking machines such as Colossus broke German encryption systems

Essentially, it allows anyone to send a message that only one person (or company or website or gadget) can unlock. It does this using two keys: one public, one private. The public key is used to lock a message. Anyone can get hold of that public key but once a message is locked with it, that message can only be opened with the corresponding private key.

Typically these keys are large numbers and the security of the system depends on the fact that some mathematical operations are easier than others.

For instance, it is far easier to multiply numbers together (public key and plain text message) to get a result than it is to start with that result (the scrambled message) and work backwards. Complicated mathematics guarantees that the right private key will unscramble a message.

Far harder, even for the fastest computer, is starting with that result (the scrambled message) and searching through all the possible combinations of numbers that could produce it.

"Because of the size of the keys is so huge its impossible for an attacker to search through the key space with the resources they usually have," he said. Such "brute force" attacks are pretty much doomed no matter how much computer power attackers bring to bear, he said

Typically the numbers used in these mathematical encryption systems are tens if not hundreds of digits long. This makes it impossible, to all intents and purposes, to search through all potential keys in a reasonable amount of time.

The web and many other modern communication systems employ a hybrid approach, said Dr Manulis, because public key encryption is not very computationally efficient compared to symmetric key encryption.

Supercomputer Even supercomputers would not break the strongest encryption algorithms

On the web, the relatively slower public key cryptography is used initially to establish a secure connection between you and a website. The symmetric system would be no good for this step because there is no way to securely swap the secret key.

However, with a secure channel in place, the faster symmetric system can be used to share a key and then scramble the data passing back and forth.

On mobiles, a similar system is used and encryption keys are held on a handset's sim card to help keep chatter scrambled.
Vulnerabilities
Attacks on these encryption systems take many forms, said Dr Manulis.

"You do not need to break the communication system if you have some spy software on the end point," he said.

In addition, weaknesses have been found in the software used to encapsulate them on computers and phones.

"The algorithms are mathematically proven," he said, " and if there's any problem then it usually comes in the implementation of the algorithm."

In addition, there have been suggestions that the NSA has subverted the process of creating encryption algorithms, to make them easier for it to break.

Official agencies can also force firms, be they websites or mobile operators, to surrender their private keys so they can eavesdrop on supposedly secure communications.

Some have sought to get make encryption more secure by using a technique known as end-to-end encryption.

This differs from more standard systems which can be vulnerable because their scrambling system is, in software terms, separate from the program used to create a message.

If attackers insert themselves between the message making software and the encryption system at either end of a conversation they will see information before it is scrambled.

End-to-end encryption closes this gap by having the message making software apply the scrambling directly. In addition, many of these systems run a closed network so messages never travel over the public internet and are only decrypted when they reach their intended recipient.

End-to-end encryption Some fear that sending data over public networks makes it more susceptible to surveillance
 

Friday, October 25, 2013

Cloud provider research, due diligence needed to maintain compliance

http://searchcompliance.techtarget.com/tip/Cloud-provider-research-due-diligence-needed-to-maintain-compliance?asrc=EM_ERU_24376772&utm_medium=EM&utm_source=ERU&utm_campaign=20131025_ERU%20Transmission%20for%2010/25/2013%20(UserUniverse:%20580888)_myka-reports@techtarget.com&src=5176213

Christine Parizo, Contributor

Organizations generate more data than ever before through applications, email and other computing tasks. Faced with flat IT budgets, companies are turning to the cloud for storage, software and infrastructure.
This is much to the chagrin of the compliance department, which wakes up in a cold sweat thinking about data security. Experts agree, however, that by conducting due diligence, companies can minimize their cloud-related risk and maintain compliance in the cloud.
"Your security teams have to satisfy themselves that what the cloud provider is doing on a routine basis meets or exceeds what they'd do on-premises," said John Howie, chief operating officer of the Cloud Security Alliance.
But enterprises are limited in how they can conduct this due diligence. For example, a cloud provider audit may not be possible because the provider doesn't want hordes of customers tromping through its data centers. Penetration testing could also shut down an enterprise's service because the cloud provider could view it as a legitimate attack, Howie said.

Because physical audits sometimes aren't possible, reputable cloud service providers should have certifications. In the United States, the two major certifications are ISO/IEC 27001:2005 and SOC 2. The ISO/IEC 27001:2005 certification provides a definition for how to run an information security management system. It does not, however, say whether "you're particularly good at it, and it doesn't say that you have the controls in place [that] are actually working," Howie cautioned. "It just certifies that you have an information security system that understands these problems and is trying to improve."

The SOC 2 certification, which is the replacement for SAS 70 and is based on the audit standard AP 101, contains the five "SysTrust" principles developed by the American Institute of Certified Public Accountants and the Canadian Institute of Chartered Accountants: confidentiality, integrity, availability, security and privacy, according to Howie.
"Privacy is a little bit of a misnomer, because it's not privacy of the customer's data," he said. Rather, it means the privacy of the cloud provider's customer, not the customers of the company that signs up for service.
To ensure the cloud provider's controls are adequate and working, SOC 2 requires an audit by a large firm. An SOC 2 report is then presented that contains detailed information about vulnerabilities and the environment as a whole. These details often make cloud providers hesitant to let customers see the results of SOC 2 reports, Howie said.

Ask providers relevant questions

Before choosing a cloud provider, companies need to ask prospective vendors some hard questions to ensure they'll stay on the right side of regulators. "It's about asking questions around what arrangements are going to be in place to protect your information … from the creation stage to the processing, the storage, the transmission and, of course, destruction," said Steve Durbin, global vice president of the Information Security Forum. Eventually, the contract with the provider will end, and organizations need to know what will happen to their data when that occurs, he added.
Other questions should include how secure the connection is, including whether a VPN is required to connect, and what the availability is, Durbin said. Companies also need to ask encryption-related questions, including whether the data needs to be encrypted, what facilities the cloud provider has to encrypt data and whether data should be encrypted before being transmitted to the cloud service, he added.
Physical security is also important, according to Mac McMillan, current chairman of the HIMSS Privacy and Security Policy Task Force and CEO of Austin, Texas-based IT security consulting firm CynergisTek. Questions should include how the cloud provider controls physical access and how systems are protected from other customers' data in colocation situations.
Finally, companies should check on the status of the cloud provider's insurance, McMillan said. For example, if there's a security breach, it's important to know if the provider will indemnify the customer and pay for the notifications, he said.

Beware the fine print during contract negotiations

The due diligence doesn't stop at the negotiating table. There is no one provision to include in the contract to maintain compliance in the cloud, but careful language can help limit liability, according to Robert Scott, managing partner at Southlake, Texas-based technology law firm Scott & Scott LLP.

More on compliance in the cloud and security

Use cloud SLAs to reduce risk, improve data recovery processes
Risk management approach needed to offset cloud security concerns
"If you outsource to a third-party cloud service provider to handle or store personally identifiable, financial or healthcare information that's regulated in any way, the law has a non-delegable duty that you can't just outsource these legal responsibilities," Scott said. Even changes to payment card industry compliance standards, which now apply to third-party services, do not absolve enterprises of maintaining regulatory compliance in the cloud, he said.
Enterprises need to ensure that their cloud services providers agree to be bound by the same regulations that they are, Scott said. For financial institutions, that means adhering to regulations such as the Gramm-Leach-Bliley Act, for example.
One thing to be wary of in contracts is provisions where the cloud services provider asks the enterprise to agree to limit data breach liability, Scott cautioned. "Such a provision could work to significantly limit the availability of insurance and/or the ability to recover for privacy-related claims that result from a data breach," he said.
Contracts are always negotiable, and any reasonable cloud provider will be willing to negotiate with a customer regarding legitimate regulatory compliance, data security and privacy concerns, Scott said. "They're not going to be a successful cloud service provider without being sensitive to customer concerns in those areas," he said.
About the author:
Christine Parizo is a freelance writer specializing in business and technology. She focuses on feature articles for a variety of technology- and business-focused publications, as well as case studies and white papers for business-to-business technology companies. Prior to launching her freelance career, Parizo was an assistant news editor for SearchCRM.
Let us know what you think about the story; email Ben Cole, associate editor. For more regulatory compliance news and updates throughout the week, follow us on Twitter @ITCompliance.
  

Monday, October 21, 2013

Breaches: Holding Retailers Accountable


Breaches: Holding Retailers Accountable

Vermont's Settlement with Merchant Could Set Bar for Others

By , October 10, 2013.
Breaches: Holding Retailers Accountable The Vermont Attorney General's $30,000 settlement with a breached retailer is significant because it demonstrates that states can play a role in holding retailers accountable for losses associated with card fraud, one banker says.
As a result of this case, more banking institutions may ask state attorneys general to conduct investigations after card fraud is linked to a retailer, says Marjorie Meadors, who oversees card fraud prevention for Louisville-based Republic Bank & Trust, a community bank with $3.2 billion in assets. That's because attorneys general enforce state laws, which may call for timely breach notification and establish security requirements, including compliance with the Payment Card Industry Data Security Standard.

 

Meadors says many banking institutions, including her own, usually report fraud incidents to local and federal law enforcement authorities, rather than state attorneys general. "Maybe we should pursue the breach angle with state agencies in the future," she says. "Some additional fines from the state agencies would further encourage smaller merchants to take a closer look at how they are updating their [point-of-sale] software."

Actions in Vermont

Last month, the Williston, Vt.-based grocery chain Natural Provisions agreed to pay a $15,000 fine to settle allegations that it failed to promptly notify customers of a breach dating back to 2012. Natural Provisions also agreed to spend $15,000 on security upgrades to its point-of-sale system.
According to Vermont Attorney General William Sorrell, Natural Provisions' lax security contributed to the breach that resulted in tens of thousands of dollars in fraud losses linked to compromised cards.
"When banks traced the fraud back to Natural Provisions, the store was informed that it was the likely source of the fraud," Sorrell states in a notice about the settlement. "Under Vermont law, a company must notify the attorney general within 14 days of the discovery of a breach, notify its customers within 45 days, and quickly take steps to remedy the breach. Natural Provisions failed to meet these standards. After it first obtained information that a security breach might have occurred at its store, it did not commence taking remedial action to resolve the security vulnerability for more than a month."
The attorney general's notice also notes: "Some consumers had their credit cards compromised, had cards reissued, and had the new cards compromised after use at Natural Provisions."
In the settlement with Natural Provisions, Sorrell claims Natural Provisions failed address, in a timely manner, security weaknesses that allowed its payments network to be compromised and an undetermined amount of card data was stolen.
Natural Provisions did not respond to Information Security Media Group's request for comment.
But Assistant Attorney General Ryan Kriger says the reason for the enforcement action from the state was Natural Provisions' failure to immediately fix the problem once it was brought to the store's attention.
"It took them more than a month to start taking any steps," Kriger tells Information Security Media Group. "They were notified and did't take steps. We in the Attorney General's office didn't find out about it until even later than that."
Kriger says many small business struggle to maintain adequate POS security, and in Vermont the AG's office has worked with numerous businesses to assist them after a breach. In the case of Natural Provisions, however, so much time passed that the state felt enforcement action had to be taken, he says.
"Hopetufully it will make other small businesses realize this is a serious matter," Kriger says. "As a small business, you need to be thinking about security; you need to have a plan in place; and you need to follow the law. ... State AGs are in best position to enforce more security with these local businesses."

Vendors' Responsibilities?

Meadors of Republic Bank & Trust says breaches at smaller retailers, such as Natural Provisions, which processes approximately 5,500 payment card transactions per month, are relatively common. But it's not just the retailers that are to blame, she contends.

Some [POS] software companies are not properly educating their merchants about the risk and the need to keep the software updated and patched," Meadors says.
"We have been told that often the software companies or their resellers are not sending out patches or updates, even when the merchants have paid for them. It will probably take some merchants bringing lawsuits against their software providers to get any action."
Another recent retailer breach, which was traced back to a POS software vulnerability, affected numerous small merchants in Kentucky and Indiana in early 2013. That software vulnerability led to a malware attack that exposed hundreds of debit and credit accounts in and around Louisville, Ky. (see Retailers Attacked by POS Malware).

Setting an Example

Dan Mitchell, a data security attorney for Maine-based Bernstein Shur, says Vermont's actions against Natural Provisions likely were meant to set an example.
"The interesting thing about this one is that the Vermont breach notification statute has a set deadline by which data breach notification has to be provided," Mitchell says. "There are only a handful of states that have a specific amount of time for notification. And Vermont only recently amended their breach notification statute in May 2012. Prior to that, they had similar requirements like other states that did not specify the 45-day rule."
Given the publicity this case has gotten, other states could soon follow Vermont's lead and amend their breach-notification statutes to include timelines as well, Mitchell says. "I don't think other states are going to look at this and say Vermont is being really strict and unrealistic."
The lesson for other merchants, or any entity that processes cardholder data, is that security has to be taken seriously, Mitchell adds. "If they are transacting data, then, regardless of size, they could potentially do a lot of harm if they are breached. They need to be secure."
David Navetta, who is the co-founder of the Information Law Group and co-chairman of the American Bar Association's Information Security Committee, notes: "What is unique in this case is that it involves a relatively low-profile company. Many regulators are generally less aggressive with smaller organizations because they realize that some of these smaller companies face technical and resource challenges when it comes to security."