Credit Reporting Companies Ruled Against in Recent Case

(Image used under: Creative Commons 3.0 [SRC])

If you have an outstanding debt that you eventually decide to make good on, you may get penalized. The "Date of Last Activity" field on your credit file will get updated if you make a single payment making it appear as if your delinquency was yesterday instead of 3 years ago.

This practice has been challenged and it seems that the consumers are winning.

Tags: ,

43 Privacy Organizations Unite Against REAL ID

Real ID
(Image is in the Public Domain)

Why they don't do this for other issues, I don't know, but several organizations have banded together to fight the implementation of REAL ID.

Now it's up to 50 organizations. Since they've gone through the trouble to make a coilition website, I wonder if they'll tackle more issues together now.
Tags:

Privacy Organizations Unite Against Bush Nominee

George W. Bush
(Image used under: Fair Use doctrine)

In what is hardly news, Bush again picks a poor choice for an important position. Michael Baroody, a high-ranking member of the National Association of Manufacturers, has been nomintated as chair of the Consumer Product Safety Commission (the agency responsible for reigning in manufacturers). What exactly is it about conflict of interest that Bush doesn't understand?

Link to ConsumerAffairs article. Tags:

ID Theft Taskforce Issues Final Recommendations and Strategic Plan

Federal Trade Commission
(Image is in the Public Domain)

On April 23rd, the ID Theft Task Force that's chaired by Alberto Gonzales (the US Attorney General) and co chaired by Deborah Platt Majores (the chairwoman of the FTC) has released their final recommendations for reducing identity theft.

Here are a few of their better recommendations:

  • Decrease the unnecessary use of social security numbers in the public sector
    For example, the federal Office of Personnel Management (OPM) has already done an internal review and realized that they were using SSNs in many cases where it wasn't necessary. They havebegun issuing employee numbers instead of just using SSNs. Dang straight! Stopping data brokering is a very good first step.
  • Develop comprehensive record on private sector use of SSNs
    What they mean by this is that they need to study how SSNs are used in businesses to determine how much is legitimate use and how much should be stopped, controlled, or altered. They plan to have completed this study and made recommendations to the president by first quarter '08. Ditto above: Stopping data brokering is a very good first step.
And here are some of their less-thought-out ones:
  • Educate Federal Agencies on how to Protect Their Data and Monitor Compliance With Existing Guidance
    Okay… Granted, bringing laptops home to get stolen was stupid the first time and got successively stupider as time went. Theoretically, by teaching the agencies obvious security and then monitoring compliance, we should be able to stop or reduce that particular type of data loss. The important point to note here is that if an agency fails to protect data properly, they will be harshly punished by having that fact noted on their PMA scorecard *rolls eyes*. What this means and what the consequences are (if any), I have no idea.
  • Ensure Effective, Risk-Based Responses to Data Breaches Suffered by Federal Agencies
    This means they're going to develop a set of guidelines on how to handle breaches and issue it to all agencies (which they've already done). The guidlines will (emphasis mine):
    set forth the factors that should be considered in deciding whether, how, and when to inform affected individuals of the loss of personal data that can contribute to identity theft, and whether to offer services such as free credit monitoring to the persons affected.
    Ugh. So they might not even tell you that they messed up by losing your data now? That's some good accountability there. And credit monitoring? Are they still going on about this? I find it so hard to trust the opinion of someone who suggests credit monitoring as any kind of response to a data breach.
  • Establish National Standards Extending Data Protection Safeguards Requirements and Breach Notification Requirements
    They want to create a national standard of safeguards that applies to all "private entities that maintain sensitive consumer information". More importantly, they say that all such entities must be required to notify law enforcement and consumers of a breach. Though this requirement would only come into effect if there was "significant risk of identity theft" due to the breach. Their justification for this is that consumers wouldn't want to be "overwhelmed" by breach notifications. That's crap. If a company has to send out an "overwhelming" amount of breach notifications, perhaps enough people would leave that company to make said company actually implement some security. This loophole also fails in that there's a lot of wiggle room in "significant risk". Who decides what's significant risk or not? The company? If so, I bet all breaches will be labeled "low risk". Ah yes, and let's not forget our favorite clause. This legislation will preempt state laws on data breaches.

Where's the Freeze recommendation?

For those who don't know my site, I am a big proponent of credit security freezes. I am severely disappointed in this final set of recommendations in that they softened the language from their initial recommendations from
For residents of states in which state law authorizes a credit freeze, consider placing a credit freeze on their credit file.7 This option is most useful when the breach includes information that can be used to open a new account, such as SSNs. A credit freeze cuts off third party access to a consumer’s credit report, thereby effectively preventing the issuance of new credit in the consumer’s name.
to
Among the state-enacted remedies without a federal counterpart is one granting consumers the right to obtain a credit freeze. Credit freezes make a consumer’s credit report inaccessible when, for example, an identity thief attempts to open an account in the victim’s name. State laws differ in several respects, including whether all consumers can obtain a freeze or only identity theft victims; whether credit reporting agencies can charge the consumer for unfreezing a file (which would be necessary when applying for credit); and the time allowed to the credit reporting agencies to unfreeze a file. These provisions are relatively new, and there is no "track record" to show how effective they are, what costs they may impose on consumers and businesses, and what features are most beneficial to consumers. An assessment of how these measures have been implemented and how effective they have been would help policy makers in considering whether a federal credit freeze law would be appropriate. Accordingly, the Task Force recommends that the FTC, with support from the Task Force member agencies, assess the impact and effectiveness of credit freeze laws, and report on the results in the first quarter of 2008.

This is very weak and isn't even a recommendation of it's own, just a sub-component of "Assess Efficacy of Tools Available to Victims". So it went from the nice, solid (and correctly worded) "effectively preventing the issuance of new credit in the consumer’s name" to "there is no 'track record' to show how effective they are, what costs they may impose on consumers and businesses, and what features are most beneficial to consumers". Alberto Gonzales and Deborah Platt Majores should be ashamed of themselves for putting their names on this worthless report.

Update 9/27/2007

It looks like the credit reporting companies are starting to read the bones and pre-emptively offer credit freezes before they get legislated into having to provide it on worse terms and lower fees. Two out of three have jumped onto the bandwagon with only one holding out so far.

Tags: , , ,

Pentagon Dismantles Database of Peaceful Activits and Religious Groups

(Image is in the Public Domain)

Talon, a Pentagon program that has been used to track and monitor peaceful group and members of some churches is now being dismantled.

Assuming there are protections in place to prevent this kind of thing from happening again and that whoever was responsible for this in the first place is disciplined, then this is a good thing.

Tags: ,

Spyware to be Legalized

Brilliant Plan
(Image used under: Creative Commons 2.0 [SRC])

Congress is now considering a bill similar to the CAN-SPAM act for spyware. Like the CAN-SPAM act, it doesn't actually stop anything, but rather legalizes it instead.

Let's sum up. If the Spy Act become law, hardware, software, and network vendors will be granted carte blanche to use spyware themselves to police their customers' use of their products and services. Incredibly broad exceptions will probably allow even the worst of the adware outfits to operate with legal cover. State attempts to deal with the spyware problem will be pre-empted and enforcement left up almost entirely to the FTC. Gee, what's not to like in that deal?
Tags: , , ,

Montana Rejects REAL ID

REAL ID still unpopular
(Image is in the Public Domain)

While they aren't the first (even though they mysteriously claim to be).

"We also don't think that bureaucrats in Washington, D.C., ought to tell us that if we're going to get on a plane we have to carry their card, so when it's scanned through they know where you went, when you got there and when you came home," said Schweitzer, a Democrat.
Tags: , , ,

Police “Book” Unruly 6 Year Olds

Stories like this give all police a bad name.
(Image used under: Creative Commons 2.0 [SRC])

Tantrum turns to police record.

She flailed away at the teachers who tried to control her. She pulled one woman’s hair. She was kicking.

Unless the kid has a knife or some other kind of weapon, nothing they can do could be counted as dangerous.

Desre’e was charged with battery on a school official, which is a felony, and two misdemeanors: disruption of a school function and resisting a law enforcement officer. After a brief stay at the county jail, she was released to the custody of her mother.

So your kid has a felony and two misdemeanors on record from the time they're 6? What was wrong with the normal way, calling her mother? So now this poor girl, her mother, the community, and most of the Internet all have less respect and trust for police officers. Great work Florida.

Tags: , , , ,

Washington State Rejects REAL ID – That’s Four So Far.

Real ID rejection is the right choice
(Image is in the Public Domain)

According to the The Electronic Frontier Foundation (EFF) newsletter, Washington state has also rejected REAL ID. More info on REAL ID and why it's bad here.

Tags: , ,

Forced RFID Implantation Illegal in North Dakota

(Image used under: Creative Commons 2.0 [SRC])

From the "don't forget we're people, not products" department, North Dakota is the second state to ban forced RFID implantation. However, even if this is a step in the right direction, does it do enough? It doesn't ban voluntary implantation and last I checked a lot of things that aren't really "voluntary" are treated such under law:

But Michael Shamos, a professor who specializes in security issues at Carnegie Mellon University in Pittsburgh, believes the law is too vague to do much good. For instance, it only addresses situations where a chip is injected, even though RFID tags can also be swallowed. And it doesn't clearly define what a forced implant really is; someone could make chipping a requirement for a financial reward.

"Suppose I offer to pay you $10,000 if you have an RFID [chip] implanted?" he asked. "Is that 'requiring' if it's totally voluntary on your part?"

It's a poor example, but the right idea. Instead, what if you are offered a high paying job and move your family to a new state, get settled and begin the orientation process for your new job. You find out that they require RFID implants for "security" (which has been proven to weaken security). How much free will do you have in this instance? Can you really afford not to take the job now?

Another example, perhaps not so drastic. Companies push and push and finally get most everyone to use RFID implants as identification and method of payment. Because you're smart enough to know what a bad thing this is, you refuse, but find yourself inconvenienced everywhere. You can only shop at certain stores that still have non-RFID checkout. You pay an extra "cash handling" fee for not using the new methods. You have to drive 20 miles away to the only gas station around that's equiped to take non-RFID transactions.

Is it still a choice?

Note that both Spychips.com and Privacy.org are carrying this story and that Spychips lists Ohio, Colorado, Oklahoma, and Florida as more states with anti-implantation bills in the works. The first state to pass such a bill was Wisconsin (note the same flaw as the ND bill).

Tags: , , ,

Loading...

If you want to learn more about my professional background, click here to learn more.

Check out one of my guides/tutorials:

email Tutorial
|INDEX|next: E-mail Viruses

E-mail Dangers

Until we find out who the people are who actually buy things from spammers and kick them off the Internet, you're going to have to learn how to deal with and prevent spam.
E-mail Viruses - Learn how viruses are spread through e-mail and how to stop them
Phishing - Spot and avoid lures that pull you into the dark side of the web
Don't be one of those people that loses thousands of dollars to the classic Nigerian Scam.

E-mail Etiquette

Use CC only when necessary and BCC the rest of the time.
Use Reply-All when you mean to and never when you don't.
Practice proper E-mail Forwarding to protect privacy and make e-mails more readable.
Always personalize your e-mails to make it obvious to your recipient that it's valid.

E-mail Tips and Tricks

Using E-Mail Aliases Properly - Be careful about using sensitive data (like your real name) in an e-mail account.
Remember to treat your e-mail account with the security it deserves.
Use a decoy e-mail account to keep your main e-mail account free of spam.
Avoid using any Internet provider's default e-mail.

... or check out any of my other guides and tutorials by clicking here!

Preventing Spam

Spam is annoying and worthless, but you still see it every single day. Here are some tips for preventing and reducing spam.

[Click for full description]

E-mail Viruses

Make sure that viruses don't sneak onto your computer through your e-mails. Read some simple tips to prevent that from happening.

[Click for full description]

Phishing

By far the most dangerous thing you'll find in e-mails is a lie. Sending a bogus e-mail to someone is generally called phishing, but can also be referred to as a Nigerian scam (depending on the goal of the e-mail). Learn to recognize and deal with phishing before it's too late.

[Click for full description]

Nigerian Scam

Many people have lost thousands and even hundreds of thousands of dollars to the classic Nigerian Scam. Don't fall for it!

[Click for full description]

How to Use "CC" Properly

Don't violate people's privacy and invite spam into their accounts by CC'ing all your contacts. Learn the proper way to send mass e-mails first.

[Click for full description]

Reply-All

It's easy to embarass yourself or harm your career when you don't know how to use Reply-All appropriately.

[Click for full description]

How to Forward E-mails Properly

Don't forward e-mails carelessly or you risk looking foolish as best and violating the privacy of all your contacts at worst.

[Click for full description]

Personalize E-mail

Follow this simple rule of e-mail etiquette to help prevent your friends and family from falling for phishing scams.

[Click for full description]

Using E-Mail Aliases Properly

It can be hard to find a good name to use in an e-mail account that hasn't been used and doesn't give away too much information about you.

[Click for full description]

Protecting E-mail Passwords

Your e-mail account is the most important online account you have. Remember to treat it as such!.

[Click for full description]

Using a Decoy E-Mail Account

Why it's very important to use a buffer e-mail account to shield your main account from people and companies that you don't trust.

[Click for full description]

The ISP E-mail Trap

Don't fall for the trap of using the free e-mail account provided to you by your Internet service!

[Click for full description]