<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Virginia gets it</title>
	<atom:link href="http://emergentchaos.com/archives/2008/04/virginia-gets-it.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2008/04/virginia-gets-it.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Reader X</title>
		<link>http://emergentchaos.com/archives/2008/04/virginia-gets-it.html/comment-page-1#comment-4550</link>
		<dc:creator>Reader X</dc:creator>
		<pubDate>Mon, 21 Apr 2008 13:00:18 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2723#comment-4550</guid>
		<description>Agreed.  Once again the law presumes all encryption is equally strong.
There&#039;s a partial remediation in that disclose must occur if the key is compromised and the entity determines that there is intent to commit ID theft, but the effectiveness of this clause is entirely dependent on the AG&#039;s ability to smell a rat.
&lt;i&gt;C. An individual or entity shall disclose the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form, or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such a breach has caused or will cause identity theft or other fraud to any resident of the Commonwealth.&lt;/i&gt;
A better approach is to force the entity to assess the risks in front of the AG and disclose if abuse of the data is reasonably possible (not probable) as does GLBA.
</description>
		<content:encoded><![CDATA[<p>Agreed.  Once again the law presumes all encryption is equally strong.<br />
There&#8217;s a partial remediation in that disclose must occur if the key is compromised and the entity determines that there is intent to commit ID theft, but the effectiveness of this clause is entirely dependent on the AG&#8217;s ability to smell a rat.<br />
<i>C. An individual or entity shall disclose the breach of the security of the system if encrypted information is accessed and acquired in an unencrypted form, or if the security breach involves a person with access to the encryption key and the individual or entity reasonably believes that such a breach has caused or will cause identity theft or other fraud to any resident of the Commonwealth.</i><br />
A better approach is to force the entity to assess the risks in front of the AG and disclose if abuse of the data is reasonably possible (not probable) as does GLBA.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DF</title>
		<link>http://emergentchaos.com/archives/2008/04/virginia-gets-it.html/comment-page-1#comment-4549</link>
		<dc:creator>DF</dc:creator>
		<pubDate>Wed, 16 Apr 2008 12:09:28 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2723#comment-4549</guid>
		<description>Apparently a simple XORing of the data counts as encryption:
&quot;...or the securing of the information by another method that renders the data elements unreadable or unusable.&quot;
Have I understood that correctly?
</description>
		<content:encoded><![CDATA[<p>Apparently a simple XORing of the data counts as encryption:<br />
&#8220;&#8230;or the securing of the information by another method that renders the data elements unreadable or unusable.&#8221;<br />
Have I understood that correctly?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2008/04/virginia-gets-it.html/comment-page-1#comment-4548</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 15 Apr 2008 10:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2723#comment-4548</guid>
		<description>Agree.
</description>
		<content:encoded><![CDATA[<p>Agree.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dissent</title>
		<link>http://emergentchaos.com/archives/2008/04/virginia-gets-it.html/comment-page-1#comment-4547</link>
		<dc:creator>Dissent</dc:creator>
		<pubDate>Tue, 15 Apr 2008 09:52:57 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2723#comment-4547</guid>
		<description>Yeah, I like that part, but they&#039;re setting a high standard for triggering notification:
&quot; &quot;Breach of the security of the system??? means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth.&quot;
&quot;Access&quot;  is better (in my opinion) than &quot;access and acquisition.&quot;
I&#039;m still in communications with two states, trying to get them to post their notifications online like NH does.
</description>
		<content:encoded><![CDATA[<p>Yeah, I like that part, but they&#8217;re setting a high standard for triggering notification:<br />
&#8221; &#8220;Breach of the security of the system??? means the unauthorized access and acquisition of unencrypted and unredacted computerized data that compromises the security or confidentiality of personal information maintained by an individual or entity as part of a database of personal information regarding multiple individuals and that causes, or the individual or entity reasonably believes has caused, or will cause, identity theft or other fraud to any resident of the Commonwealth.&#8221;<br />
&#8220;Access&#8221;  is better (in my opinion) than &#8220;access and acquisition.&#8221;<br />
I&#8217;m still in communications with two states, trying to get them to post their notifications online like NH does.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

