Are there potential legal issues with allowing a user to see their full SSN and DL after entering username and SMS pin?

I have an account on the ChexSystems site which allows me to easily view and request my consumer report.*
Once I sign into my account, I can see my full social security number and driver’s license. I can’t delete this information or delete… Continue reading Are there potential legal issues with allowing a user to see their full SSN and DL after entering username and SMS pin?

Tech companies are selling domains suggesting illegal sales of guns, malware

COVID-19-related domains remain a concern.

The post Tech companies are selling domains suggesting illegal sales of guns, malware appeared first on CyberScoop.

Continue reading Tech companies are selling domains suggesting illegal sales of guns, malware

Reproductive rights at risk galvanize calls for federal privacy legislation

Lack of federal privacy protections could make abortion bans a lot more dangerous.

The post Reproductive rights at risk galvanize calls for federal privacy legislation appeared first on CyberScoop.

Continue reading Reproductive rights at risk galvanize calls for federal privacy legislation

Momentum builds to strengthen FTC’s role as privacy enforcer, though hurdles remain

When the White House nominated Alvaro Bedoya, a Georgetown law professor known for his expertise on privacy, for a role on the Federal Trade Commission, privacy advocates interpreted the move as the latest evidence that the agency is looking to expand its work investigating and bringing cases against companies that exploit and mismanage consumer data. Bedoya, a former Senate Judiciary counsel who is known for his work addressing racial and gender bias on facial recognition technology and other surveillance of communities of color, comes with the promise of what privacy advocates envision for the future of the agency. “Just as Lina Khan really sent a strong signal about taking the FTC seriously as an antitrust regulator, I think that the nomination of Alvaro Bedoya should send us the same signal to take the agency seriously as a privacy regulator,” said Christine Bannan, senior policy counsel at the Open Technology Institute, one […]

The post Momentum builds to strengthen FTC’s role as privacy enforcer, though hurdles remain appeared first on CyberScoop.

Continue reading Momentum builds to strengthen FTC’s role as privacy enforcer, though hurdles remain

Cardholder info transmission between issuing and acquiring banks

Which data is actually transmitted between issuing and acquiring banks during various phases of a card payment transaction?

Specifically, does the Issuer tell the Acquirer any info (and which if any?) not originally acquired from the Card… Continue reading Cardholder info transmission between issuing and acquiring banks

How can I know if the cyber-protection offered by my ISP is worth the extra cost?

My ISP offers a “cyber protection” service at an extra cost. They say it “identifies and blocks privacy attacks, credit-card scams, identity thefts and hacker attacks against computers connected to your home network”, but do … Continue reading How can I know if the cyber-protection offered by my ISP is worth the extra cost?

New York updates its breach notification law in response to Equifax, GDPR

Businesses throughout the U.S. will now be required to notify New Yorkers as quickly as possible when their information is compromised in a security incident, under a bill that Gov. Andrew Cuomo signed Thursday. The consumer-friendly data protection law updates New York’s current rules to cover biometric data, and forces firms to alert consumers when their email address, combined with the corresponding passwords or security questions and answers, are compromised. The state legislature quietly passed the Stop Hacks and Improve Electronic Data Security Act, or SHIELD Act, in June. The law, which takes effect March 2020, requires companies to notify individuals “in the most expedient time possible and without unreasonable delay,” a time period that generally means 30 days, state Sen. Kevin Thomas, who re-introduced the SHIELD Act after it failed to pass in 2017, previously told CyberScoop. If the incident affects more than 500 New York residents, the affected business is required to provide written […]

The post New York updates its breach notification law in response to Equifax, GDPR appeared first on CyberScoop.

Continue reading New York updates its breach notification law in response to Equifax, GDPR

Dell Computers Doesn’t Care About Fraud – And Neither Do Most Companies

A declined suspicious attempted purchase sheds an ugly light on company apathy regarding fraud Willie Sutton famously replied to the question, “Why do you rob banks?” with the answer, “Because that’s where the money is.” Same thing with hackers: Why t… Continue reading Dell Computers Doesn’t Care About Fraud – And Neither Do Most Companies