Data Risk Governance

Exploring the intersection between information security, privacy, technology and the law.

Archive for July, 2009

Amazon Kindle – Purchasing A Right To View, Sometimes

Posted by Matt on July 21, 2009

http://volokh.com/posts/1248045949.shtml

Amazon screws up twice: 1- for not having proper controls in place to ensure that only properly licensed material is uploaded to the Kindle Store, and 2- by failing to design controls in the their digital content distribution system to enforce their legal obligations:  apparently when a Kindle book is removed from the central database, all copies of that book out on Kindle user’s devices were also deleted.   It was either a lack of system controls or over-reacting by Amazon management.  This likely violates their own Terms of Service with Kindle users.

Great write up on Volokh.com

Posted in Controls, Legal Duty | Leave a Comment »

Organized Computer Crime

Posted by Matt on July 20, 2009

We’ve known about this for some time. Here is a recent indictment revealing a mob-related data theft:

http://www.bankinfosecurity.com/articles.php?art_id=1632&pg=1

Posted in News | Leave a Comment »

North Dakota Missile Crew Members Discharged for Falling Asleep – Local News | News Articles | National News | US News – FOXNews.com

Posted by Matt on July 14, 2009

North Dakota Missile Crew Members Discharged for Falling Asleep – Local News | News Articles | National News | US News – FOXNews.com

This story is interesting in the sense that 1-) a primary control broke down, and 2-) the layered mitigating controls are described. Good view of defense in depth techniques.

Posted in Information Security | Leave a Comment »

Two Centuries On, a Cryptologist Cracks a Presidential Code – WSJ.com

Posted by Matt on July 2, 2009

Two Centuries On, a Cryptologist Cracks a Presidential Code – WSJ.com

Posted using ShareThis

Posted in Information Privacy, Information Security | Leave a Comment »

ATM Vendor Halts Researcher

Posted by Matt on July 1, 2009

ATM Vendor Halts Researcher’s Talk on Vulnerability

Posted using ShareThis

Posted in Information Privacy, Information Security | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.