Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security Privacy

Breaches Exposed 22.8 Million Personal Records of New Yorkers 41

An anonymous reader writes Attorney General Eric T. Schneiderman issued a new report examining the growing number, complexity, and costs of data breaches in the New York State. The report reveals that the number of reported data security breaches in New York more than tripled between 2006 and 2013. In that same period, 22.8 million personal records of New Yorkers have been exposed in nearly 5,000 data breaches, which have cost the public and private sectors in New York upward of $1.37 billion in 2013. The demand on secondary markets for stolen information remains robust. Freshly acquired stolen credit card numbers can fetch up to $45 per record, while other types of personal information, such as Social Security numbers and online account information, can command even higher prices.
This discussion has been archived. No new comments can be posted.

Breaches Exposed 22.8 Million Personal Records of New Yorkers

Comments Filter:
  • by ObsessiveMathsFreak ( 773371 ) <obsessivemathsfreak.eircom@net> on Wednesday July 16, 2014 @09:44AM (#47466091) Homepage Journal

    Perhaps it's time for companies to realise that they cannot keep data secure. That they will never be able to build, much less be willing to pay for, the security required to keep this information under any kind of seal.

    Perhaps it's time for companies to ask themselves: "Do we really need to store this?".

    • Where I live, the security agency was on telly tonight calling for greater hacking powers and data retention.

      (The Terrorism card)

      Why spy on your own citizens when the information is, seemingly, freely available online?

    • This was one big reason why, when New York said they were going to upload students' data into the Bill Gates Foundation's InBloom system, I was opposed. The data (including some very personal info like medical diagnoses) would have been upload to an Amazon cloud drive. As if "cloud drives" are never hackable.

      (The other reason I was opposed was that lawmakers specifically made an exception to the data sharing laws so that data could be uploaded to InBloom whether or not parents wanted it uploaded. Not onl

    • Perhaps it's time for companies to realise that they cannot keep data secure. That they will never be able to build, much less be willing to pay for, the security required to keep this information under any kind of seal.

      Perhaps it's time for companies to ask themselves: "Do we really need to store this?".

      It's beyond that... as you said, data is unsecurable even if they don't store it. So why is it possible for someone from eastern Europe that doesn't even speak English to charge something in my name and have it shipped overseas with nothing more than the info on my Visa card?

      This is entirely the fault of Visa/Mastercard and other credit agencies. They should be eating the costs of this fraud wholesale. They could end it tomorrow but in the name of getting us as far in debt to them as possible, they've throw

    • Perhaps it's time for some litigation. These breaches should fall into an area similar to product liability where the cost of shoddy work is expensive.

  • Say, full damage caused, including $100 per hour the person affected had to spent clearing this up, with at least 10h assumed and no need to prove anything for them. With that, companies might just start to care about the security of customer data. Currently, they basically have no incentives to spend any money on secure coding, security reviews and the like.

    • The problem is what happens when it's a government breach? Have taxpayers fine themselves?

    • That would require some form of privacy legislation.

      And I have my doubts about the willingness of lawmakers to do that.

      Not the least of which because it would limit the ability of companies to make use of your private data, put the onus on them to be competent at data security, and actually bear some responsibility.

      We couldn't possibly curtail what companies do for profit.

      There are barely any laws about what they're allowed to store, and what they're allowed to do with it. Nobody is going to pass laws maki

  • Make debt the responsibility of the lender.

    • Make debt the responsibility of the lender.

      Why, when it's so much more profitable to "securitize" it and sell it off to other people as if it had value?

      Making companies take on their own liability sounds un-American.

    • Make debt the responsibility of the lender.

      In Islamic countries, it's illegal to earn money off debt, and their civilization is growing. It's a perfectly functional way to operate. I went looking for an Islamic bank myself, but there weren't any close enough for me to do business with them.

  • Companies have proved they do not care about your data and are willing to essentially give it away via breaches. And *nothing* is ever done about preventing identity theft, because the burden of fixing it is up to the individual, not the credit card issuer, and not the large faceless corporation that saved $20 on security software, but let the hackers in to take your identity in the first place.

    They then promise to fix the problem, but then never do. And government looks the other way because they are in th

  • isn't time we just ditch the fiction that privacy as we knew it in the 20th century is gone forever and accept that everything we do and say on any digital medium will be collected?

    sheesh...yes I get it already...databases compromised, hacked, sold...NSA spying, collecting...

    good lord how many times do we need to be wack-a-moled before we just stop caring?

  • The costs of attempting to BE compliant to these vague horrible laws is far higher than the cost of losing control over something. This is why HIPAA is a huge waste of time and effort. It costs millions to 'comply' with the law but the downside is near zero because, and this is important

    YOU HAVE TO PROVE INTENT

    So any law is going to be ineffectual on its face when it looks only at intent. And specifically, the intent to profit from it. Target didn't intend to break something. They goofed up. So the law does

  • Because giving people that can't be held accountable unfettered access to all of your data and records will lead to LESS identity theft, right? Right????
  • It's a $1.37 billion dollar boost to the economy! You can't just print money for banksters without spreading it around a little bit!

    When the money gets stolen, its insured by the government that just prints some more, and paper grows on trees!

    Finally we have found a growth industry with real American entrepreneurship that is compatible with current fiscal policy. We can re-hypothecate futures on funny money stolen by criminals that aren't bank executives! Its a new system of cheques and balances

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...