Will the US Move to a Federal Privacy Law in 2021?

Will the US Move to a Federal Privacy Law in 2021?

Data privacy trends in the US in light of this year’s election and other recent events were discussed by a panel during the FTI Consulting webinar The New Privacy Landscape: California’s New Law and Prospects for Federal Action.

The significance of the California Privacy Rights Act (CPRA), passed last month to expand the existing California Consumer Privacy Act (CCPA) was firstly highlighted by the panel. Dominique Shelton Leipzig, firmwide co-chair of Perkins Coie’s Ad Tech Privacy and Data Management Practice, explained that this new law will bring about major changes to how data can be used in the state, and “companies really need to start thinking about this now.”

This includes requiring protection for sensitive information such as race, sexual preferences and trade union membership, while consumers also have a right to opt out of information sharing. Additionally, an agency will be set up to help enforce the legislation, including the power to issue fines.

Welcoming the move, Chris Calabrese, Microsoft’s senior director of privacy and data policy, said he expects the legislation to lead to greater trust in companies, and noted that “with the changes to the law we’ve moved closer to the GDPR model.” He also expressed hope that such an approach will be adopted on a wider scale in the future, including at a federal level.

A more co-ordinated approach to data privacy rules worldwide is needed to help companies implement a global strategy, according to Charles Palmer, FTI Consulting senior managing director, outlining the difficulties a lot of smaller businesses have had in staying compliant when operating across different jurisdictions. “We are at a point where there needs to be coalescing around some common standards,” he commented.

There does appear to be some movement by way of a federal privacy law getting enacted in the future, which would help resolve issues such as the ruling this year from the Court of Justice of the European Union (CJEU) that the Privacy Shield scheme for transfers of personal data from the EU to the United States is unlawful. Jason Van Beek, general counsel, Office of the Senate Majority Whip, outlined initial conversations that have taken place between a congress committee and stakeholder groups about this. “If not passing one, then just getting it out of committee would be a positive step forward for a lot of interest groups looking to find a resolution to the issue of the privacy shield,” he noted.

In the current absence of a federal law on this area, the possibility of the state of California alone achieving adequacy to allow data transfers with the US was mooted by Shelton Leipzig. “There’s definitely going to be an attempt to get California designated as an adequate territory,” she said.

Nevertheless, Calabrese argued the Schrems II case, which led to the ruling over the EU-US privacy shield, highlighted that while having a federal privacy law in the US is important, it won’t necessarily guarantee an adequacy decision from the EU. This is because the big issue in this case was about surveillance by law enforcement agencies. He commented: “We’ve got to take both sides of that coin and address both of them,” adding that “there are creative ways to address this.”

In terms of the development of privacy legislation at a federal level in 2021, Van Beek added that while it is an important issue on the agenda, the continuing uncertainty over the congress election result alongside the COVID-19 crisis means it is unclear how this will progress next year and how high it will be on the agenda of law makers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Decade-Long Data Silo to Address Google-Fitbit Privacy Concerns

Decade-Long Data Silo to Address Google-Fitbit Privacy Concerns

The European Commission finally approved Google’s acquisition of Fitbit yesterday, adding some conditions intended to protect user privacy and competition, although campaigners are disappointed in the decision.

The Commission has been mulling the $2.1bn acquisition of the fitness monitoring giant for several months, as distrust over Google’s handling of data and alleged anti-competitive practices is high in the region.

In February, the advisory European Data Protection Board raised concerns about the possibility of the tech giant accessing health and fitness data on tens of millions of users.

“There are concerns that the possible further combination and accumulation of sensitive personal data regarding people in Europe by a major tech company could entail a high level of risk to the fundamental rights to privacy and to the protection of personal data,” it noted.

However, the Commission has stipulated that Google cannot use any Fitbit data to power its advertising business and will have to store the latter in a “data silo” for 10 years, with the option of extending it for another decade.

“The Commission’s investigation found that Google will have to ensure compliance with the provisions and principles of the GDPR, which provides that the processing of personal data concerning health shall be prohibited, unless the person has given explicit consent,” it also noted.

However, Privacy International said it was disappointed at the outcome, arguing that it will further strengthen Google’s capacity to exploit user data.

It argued that any commitments from the tech titan would likely fail to be implemented in a way that upholds users’ privacy rights. In particular, the review failed because it didn’t consider any implications for the region’s digital healthcare sector and markets, which Google could go on to dominate, the rights group said.

“Nothing seems to prevent Google from further enriching their massive data troves with vast quantities of sensitive health data and potentially exploiting our data in ways that go beyond digital advertising markets,” argued Privacy International legal officer, Ioannis Kouvakas.

“Google’s latest leap forward is going to be game-changing in all the wrong ways. Enabling any company, through acquisition and merger, to embed itself so deeply into so many aspects of our lives, is deeply troubling.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Energy Firm Suffers Data Breach Impacting Entire Customer Database

UK Energy Firm Suffers Data Breach Impacting Entire Customer Database

UK energy supplier People’s Energy has suffered a data breach affecting its entire database, including information on previous customers.

Co-founder of the company, Karin Sode, told BBC News that sensitive personal information of its customers, including names, addresses, dates of birth, phone numbers, tariff and energy meter IDs had been stolen by hackers. Following discovery of the breach on Wednesday morning, it has contacted all its 270,000 current customers to inform them of the breach.

Additionally, the hackers accessed the bank accounts and sort codes of 15 small business customers, and People’s Energy said it had contacted them separately by phone. No other customers had their financial information accessed.

The firm added it has informed the Information Commissioners Office (ICO) of the breach, as well as the National Cyber Security Center (NCSC) and the police. It is now working with independent experts to investigate how the breach occurred and identity of the attackers.

Quoted by the BBC, Sode said: “This is a big blow in every way. We want people to feel they can trust us. This was not part of the plan. We’re upset and sorry.”

Most of those affected are unlikely to face any direct financial risk, but will likely be at risk of targeted phishing attacks in the future.

Commenting, Paul Bischoff, privacy advocate at Comparitech.com, said: “Every data breach is cause for concern, but we should be particularly worried about attacks on critical infrastructure. In the coming days, I hope the attacker can be identified so we know whether this was a nation state threat actor or just an independent hacker looking for low-hanging fruit. Thankfully, People’s Energy’s actual service infrastructure was unaffected, and the vast majority of victims had none of their financial information stolen.

“People’s Energy customers should be on the lookout for targeted phishing messages from fraudsters posing as People’s Energy or a related company. They will use the personal information stored in the database to customize messages and make them more convincing. Never click on links or attachments in unsolicited emails, and always verify the sender’s identity before responding.”

Chris Hauk, consumer privacy champion at Pixel Privacy, added: “Data breaches like the one suffered by People’s Energy emphasizes the need for companies big and small to harden their systems against breaches of this sort. People’s Energy should be applauded for not wasting any time in alerting their customers and officials to the breach. This upfront admission could help prevent their customers from being phished by the bad actors that performed the breach.”

People’s Energy is the latest of a number of businesses that have experienced large-scale data breaches this year, including Marriot International, Experian and easyJet.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Bouncy Castle Bug Puts Bcrypt Passwords at Risk

Bouncy Castle Bug Puts Bcrypt Passwords at Risk

A high impact vulnerability has been discovered in a popular Java cryptography library which could allow attackers to more easily brute force Bcrypt hashed passwords.

CVE-2020-28052 is an authentication bypass bug in the OpenBSDBcrypt class of the widely used Bouncy Castle library.

By exploiting it, attackers can effectively bypass password checks in applications using the Bcrypt algorithm for password hashing, explained Synopsys. Although attack complexity is rated high, so is the potential impact on confidentiality, integrity and availability, the vendor claimed.

“An attacker must brute force password attempts until the bypass is triggered. Our experiments show that 20% of tested passwords were successfully bypassed within 1000 attempts,” it explained.

“Some password hashes take more attempts, determined by how many bytes lie between 0 and 60 (1 to 59). Further, our investigation shows that all password hashes can be bypassed with enough attempts. In rare cases, some password hashes can be bypassed with any input.”

The flaw was disclosed to Bouncy Castle on October 20 and fixed in early November, with an advisory published yesterday.

However, 91% of organizations using the at-risk version of Bouncy Castle thus far haven’t patched, according to Sonatype.

CTO Brian Fox claimed that the popular cryptographic Java library is used by developers across 26,000 organizations to secure their applications, and has been downloaded over 170 million times in the past 12 months alone.

This makes it a potentially serious supply chain risk.

“Recent headlines about the massive SolarWinds attack highlighted the importance of software supply chain security and how easy it is for a single vulnerability to be distributed across multiple organizations, from government to security firms,” Fox argued.

“Ensuring the software you’re running across a business is built upon the most secure, updated components, requires maintaining a clean software bill of materials which automatically monitors for updates or malicious packages.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft and 40+ Customers Hit in Russian Espionage Attack

Microsoft and 40+ Customers Hit in Russian Espionage Attack

Microsoft has notified over 40 customers that they have been compromised by malicious SolarWinds updates as part of a massive suspected Russian cyber-espionage campaign.

The attacks, which the US government admitted to for the first time on Wednesday, are thought to have compromised numerous departments including the Treasury and commerce, health, energy and state departments, plus the National Nuclear Security Administration (NNSA).

A malicious SolarWinds Orion update is thought to have been a primary attack vector for the suspected Russian state group, with the vendor claiming as many as 18,000 customers could be affected.

However, the attackers are likely to have targeted far fewer to achieve their strategic objectives. Yesterday, Microsoft president Brad Smith revealed the firm has contacted over 40 customers “targeted more precisely and compromised through additional and sophisticated measures.”

These include governments (18%), NGOs (18%), contractors (9%) and IT companies (44%), although the number of targets is suspected to grow over the coming days and weeks.

“While roughly 80% of these customers are located in the United States, this work so far has also identified victims in seven additional countries,” Smith continued.

These are: Canada, Mexico, Belgium, Spain, the UK, Israel and the UAE.

“This is not ‘espionage as usual,’ even in the digital age. Instead, it represents an act of recklessness that created a serious technological vulnerability for the United States and the world. In effect, this is not just an attack on specific targets, but on the trust and reliability of the world’s critical infrastructure in order to advance one nation’s intelligence agency,” argued Smith.

“While the most recent attack appears to reflect a particular focus on the United States and many other democracies, it also provides a powerful reminder that people in virtually every country are at risk and need protection irrespective of the governments they live under.”

In fact, Microsoft itself was forced to admit that it was also caught up in the attack campaign.

“Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed,” it noted in a statement.

“We have not found evidence of access to production services or customer data. Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.”

However, US security agency CISA has confirmed that the SolarWinds updates were not the only “initial access vectors” used in this campaign.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk