Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Cybercime bill inadequate, cries consumer advocate

Bill fails to give consumers tools to guard against ID theft, group claims

By Grant Gross, IDG News Service
May 11, 2006
 

New legislation in the U.S. Congress intended to help law enforcement agencies fight cybercrime falls short because it does not give consumers tools to guard against identity theft, a lawmaker and a consumer advocate said Thursday.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

The Cyber-Security Enhancement and Consumer Data Protection Act, introduced Tuesday, would be inadequate as a stand-alone cybersecurity bill because it does not require companies with data breaches to notify affected consumers, and it does not allow consumers to freeze their credit when they've been victims of ID theft, said Susanna Montezemolo, policy analyst for Consumers Union.

"One question we ask when we consider federal legislation is, 'Will this make consumers better off?'" Montezemolo said during a hearing on the bill. "The legislation does address some of the broader consumer issues, such as notifying individuals ... so that they can take steps to avoid or detect, at a much earlier time, identity theft."

The bill, sponsored by House Judiciary Committee Chairman James Sensenbrenner, a Wisconsin Republican, would allow fines or five-year jail sentences for people who fail to report to federal law enforcement authorities large data breaches involving personal information. The bill would triple the maximum jail sentence to 30 years for first-time offenders convicted of computer fraud, and it would allow federal law enforcement officials to charge organized cybercrime groups with racketeering.

The bill would also increase funding for federal cybercrime programs, and it would spell out a prohibition against taking over computers remotely to create so-called botnets.

The legislation is needed because cybercriminals are becoming increasingly inventive, said Representative Howard Coble, a co-sponsor of the bill and chairman of the Judiciary Committee's Crime, Terrorism, and Homeland Security Subcommittee, where the bill was debated Thursday.

"One thing we know about Internet fraudsters is they are a sophisticated and intelligent group of criminals," said Coble, a North Carolina Republican.

But the bill doesn't go far enough, said Montezemolo and Representative Robert Scott, a Virginia Democrat. Scott called for additions that would allow consumers to check the accuracy of the data held by data brokers, credit agencies and other companies, as well as a data breach notification provision.

If the Sensenbrenner bill is married to another breach notification bill, Congress should continue to allow states to pass their own breach notification laws, Scott said. Close to 30 states have passed breach notification bills after a rash of breaches were made public in early 2005.

Other bills before Congress include data breach notification provisions, but a bill approved in March by the House Financial Services Committee would preempt stronger state laws, Scott and Montezemolo said. The Financial Data Protection Act would require companies to report data breaches only after they determine the breaches pose a significant risk to consumers, Montezemolo said.

"We call this the 'don't know, don't tell' policy," she said. "Because if the company doesn't know whether consumers can be harmed, they don't have to notify them."

Others testifying before the subcommittee praised the Sensenbrenner bill. The legislation is a "good first step toward punishing" cybercriminals, said Joseph LaRocca, vice president for loss prevention at the National Retail Federation.





 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




REMOTE ACCESS: MAINTAIN SECURITY AND DECREASE THE BURDEN ON IT
Join this interactive webcast to discover how IT Managers can control access rights, end-user security settings and end-point authorization. Sponsor: Citrix(R) GoToMyPC(R) Corporate

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist