<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: When Planes Fell From the Sky</title>
	<atom:link href="http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Allan Friedman</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3029</link>
		<dc:creator>Allan Friedman</dc:creator>
		<pubDate>Thu, 04 Jan 2007 09:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3029</guid>
		<description>CSIA puts out some interesting stuff, but one should always take a few grains of salt with research that comes from an industry group with clear benefits from certain findings.
Re: 2006. No hard data, but I would be surprised if none of the sponsors of any of the recent ID Theft bills (no matter how poorly thought out or ineffective) mentioned their efforts while campaigning.  If you were looking for hard evidence, start with the Congressional Register and work backwards through campaign literature.
</description>
		<content:encoded><![CDATA[<p>CSIA puts out some interesting stuff, but one should always take a few grains of salt with research that comes from an industry group with clear benefits from certain findings.<br />
Re: 2006. No hard data, but I would be surprised if none of the sponsors of any of the recent ID Theft bills (no matter how poorly thought out or ineffective) mentioned their efforts while campaigning.  If you were looking for hard evidence, start with the Congressional Register and work backwards through campaign literature.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Molnar</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3028</link>
		<dc:creator>David Molnar</dc:creator>
		<pubDate>Wed, 03 Jan 2007 21:38:57 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3028</guid>
		<description>Adam:
I thought you might have been, but wasn&#039;t sure. I&#039;m still curious as to know whether breach laws were in fact an issue in any November 2006 campaign. Google news isn&#039;t much help as far as I can tell.
</description>
		<content:encoded><![CDATA[<p>Adam:<br />
I thought you might have been, but wasn&#8217;t sure. I&#8217;m still curious as to know whether breach laws were in fact an issue in any November 2006 campaign. Google news isn&#8217;t much help as far as I can tell.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3027</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 03 Jan 2007 10:54:51 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3027</guid>
		<description>David,
I was being sarcastic about our lack of progress.  Thanks for the second article; that&#039;s fascinating and I&#039;d missed it.
</description>
		<content:encoded><![CDATA[<p>David,<br />
I was being sarcastic about our lack of progress.  Thanks for the second article; that&#8217;s fascinating and I&#8217;d missed it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3026</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 02 Jan 2007 21:25:30 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3026</guid>
		<description>@Allan:
As some of these outfits might have thought of it &quot;The loss of your privacy is the cost of my doing business&quot;. :^)
On the typology --&gt; control points idea, it seems somewhat clear even at this early stage that encryption of data at rest outside the perimeter, and more thoughtful consideration of what to store in the first place would put a decent-sized dent in the problem.  That is probably too technical a solution, where you are thinking more from a regulatory standpoint. This is one where the techies, regulators, and politicians need to work together.  All would benefit from better data.  In particular, I am frustrated by the seeming inability (or at least, difficulty) to tie real ID theft likelihoods to breaches.  What could be done to get the data needed for this, while maintaining confidentiality and privacy for those whose records are involved, I wonder?
</description>
		<content:encoded><![CDATA[<p>@Allan:<br />
As some of these outfits might have thought of it &#8220;The loss of your privacy is the cost of my doing business&#8221;. :^)<br />
On the typology &#8211;> control points idea, it seems somewhat clear even at this early stage that encryption of data at rest outside the perimeter, and more thoughtful consideration of what to store in the first place would put a decent-sized dent in the problem.  That is probably too technical a solution, where you are thinking more from a regulatory standpoint. This is one where the techies, regulators, and politicians need to work together.  All would benefit from better data.  In particular, I am frustrated by the seeming inability (or at least, difficulty) to tie real ID theft likelihoods to breaches.  What could be done to get the data needed for this, while maintaining confidentiality and privacy for those whose records are involved, I wonder?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Molnar</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3025</link>
		<dc:creator>David Molnar</dc:creator>
		<pubDate>Tue, 02 Jan 2007 20:22:15 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3025</guid>
		<description>Oh, I just noticed this. The Cyber Security Industry Alliance ran a survey in 2006 on public perception of computer security issues.
&lt;a href=&quot;https://www.csialliance.org/publications/surveys_and_polls/dci_survey_May2006/print/&quot; rel=&quot;nofollow&quot;&gt;https://www.csialliance.org/publications/surveys_and_polls/dci_survey_May2006/print/&lt;/a&gt;
Here&#039;s the interesting part:
&lt;blockquote&gt;
&quot;The key circumstance arises from the fact that strong interests are lining up on both sides of the issue – corporations afraid of burdensome disclosure requirements on one side and consumer activists on the other. The survey shows that the electorate is ready to take sides as well. Americans choose California-strength disclosure even when presented with the caveats that they will be bombarded with worthless notices and that prices will rise as companies pass along the cost of compliance. Seventy-one percent of respondents agree that Congress should pass a law like California’s compared to only 21 percent who think that California’s is too strict.
While Democrats are the most likely to support stronger data security (78 percent), 68 percent of Republicans favor a law like California’s while only 25 percent think it’s too strict. Voters who support stronger data security are prepared to hold candidates accountable.
Among those likely to vote in the 2006 elections, 46 percent say that a candidate’s opposition to a law like California’s would give them serious doubts.
While this does not rise to the level of the silver bullet a challenger would use to take out an incumbent, it is nonetheless a number that suggests that the issue will get more than a passing mention on the campaign trail. If a Member of Congress votes against a strong data security bill this session, the survey suggests that the Member’s opponents will bring up the issue in the fall campaign.&quot;
&lt;/blockquote&gt;
Anyone know if a campaign in 2006 actually did have someone raise breach bills as an issue?
</description>
		<content:encoded><![CDATA[<p>Oh, I just noticed this. The Cyber Security Industry Alliance ran a survey in 2006 on public perception of computer security issues.<br />
<a href="https://www.csialliance.org/publications/surveys_and_polls/dci_survey_May2006/print/" rel="nofollow">https://www.csialliance.org/publications/surveys_and_polls/dci_survey_May2006/print/</a><br />
Here&#8217;s the interesting part:</p>
<blockquote><p>
&#8220;The key circumstance arises from the fact that strong interests are lining up on both sides of the issue – corporations afraid of burdensome disclosure requirements on one side and consumer activists on the other. The survey shows that the electorate is ready to take sides as well. Americans choose California-strength disclosure even when presented with the caveats that they will be bombarded with worthless notices and that prices will rise as companies pass along the cost of compliance. Seventy-one percent of respondents agree that Congress should pass a law like California’s compared to only 21 percent who think that California’s is too strict.<br />
While Democrats are the most likely to support stronger data security (78 percent), 68 percent of Republicans favor a law like California’s while only 25 percent think it’s too strict. Voters who support stronger data security are prepared to hold candidates accountable.<br />
Among those likely to vote in the 2006 elections, 46 percent say that a candidate’s opposition to a law like California’s would give them serious doubts.<br />
While this does not rise to the level of the silver bullet a challenger would use to take out an incumbent, it is nonetheless a number that suggests that the issue will get more than a passing mention on the campaign trail. If a Member of Congress votes against a strong data security bill this session, the survey suggests that the Member’s opponents will bring up the issue in the fall campaign.&#8221;
</p></blockquote>
<p>Anyone know if a campaign in 2006 actually did have someone raise breach bills as an issue?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Molnar</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3024</link>
		<dc:creator>David Molnar</dc:creator>
		<pubDate>Tue, 02 Jan 2007 20:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3024</guid>
		<description>&lt;i&gt;Some people wanted to &#039;save the organization from embarrassment.&#039; I&#039;m so glad we in information security are past that, and are learning lessons from each other&#039;s mistakes.&lt;/i&gt;
&quot;Past that&quot; might be too strong. Yes, we do now have breach laws in some states, most notably California&#039;s SB 1386. Yes, this has changed the landscape. There are still people out there who want to &#039;save the organization from embarassment,&#039; and the federal story has not yet been written. It might be worth keeping an eye on the new Congress to see what happens.
</description>
		<content:encoded><![CDATA[<p><i>Some people wanted to &#8216;save the organization from embarrassment.&#8217; I&#8217;m so glad we in information security are past that, and are learning lessons from each other&#8217;s mistakes.</i><br />
&#8220;Past that&#8221; might be too strong. Yes, we do now have breach laws in some states, most notably California&#8217;s SB 1386. Yes, this has changed the landscape. There are still people out there who want to &#8216;save the organization from embarassment,&#8217; and the federal story has not yet been written. It might be worth keeping an eye on the new Congress to see what happens.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allan Friedman</title>
		<link>http://emergentchaos.com/archives/2007/01/when-planes-fell-from-the-sky.html/comment-page-1#comment-3023</link>
		<dc:creator>Allan Friedman</dc:creator>
		<pubDate>Tue, 02 Jan 2007 18:43:06 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2147#comment-3023</guid>
		<description>Adam, this is an excellent point. Strong, sustained attention to problems often produces a good solution to things that were just accepted as a &quot;cost of business.&quot;  Other examples might include automobile safety (back when Nader was seen as a good guy) and early credit card liability issues.
One interesting thing to consider is the type of solution to the techno-social problems.  Is the solution purely technical? Is there a difference between the source of the solution and the implementation of that solution (i.e. a new liability standard might be set by a single decision, but then implemented by myriad players).
The fun thing about these wide-spread lingering problems is that they span so many different levels of technology, economic incentives, organizational dynamics, etc.  It would be a fun project to put together a set of them and build a typology to suggest where corrective change is easier or harder, and what policy options would be better in different situations.
</description>
		<content:encoded><![CDATA[<p>Adam, this is an excellent point. Strong, sustained attention to problems often produces a good solution to things that were just accepted as a &#8220;cost of business.&#8221;  Other examples might include automobile safety (back when Nader was seen as a good guy) and early credit card liability issues.<br />
One interesting thing to consider is the type of solution to the techno-social problems.  Is the solution purely technical? Is there a difference between the source of the solution and the implementation of that solution (i.e. a new liability standard might be set by a single decision, but then implemented by myriad players).<br />
The fun thing about these wide-spread lingering problems is that they span so many different levels of technology, economic incentives, organizational dynamics, etc.  It would be a fun project to put together a set of them and build a typology to suggest where corrective change is easier or harder, and what policy options would be better in different situations.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

