Welcome | Sign In
ECommerceTimes.com
Security

Credit Reporting Companies Co-Opt Encryption

Print Version
E-Mail Article
Reprints
Credit Reporting Companies Co-Opt Encryption

"The issue we've been considering is whether a security breach, based on identification laws, should exclude data that's encrypted," Electronic Privacy Information Center senior counsel Chris Hoofnagle told TechNewsWorld. "That's a key hole in the law."


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Equifax, Experian and TransUnion have revealed plans to collaborate on encryption standards to strengthen their protection of sensitive consumer data, which has increasingly become the favorite target of attackers motivated by profit.

There was praise for the agencies' increased protection plan, which will include coordination on industry encryption standards and 128-bit key encryption. However, there was also concern that the credit reporting companies were leveraging a loophole in breach disclosure laws that means compromises of encrypted databases do not have to be made public.

"The issue we've been considering is whether a security breach, based on identification laws, should exclude data that's encrypted," Electronic Privacy Information Center senior counsel Chris Hoofnagle told TechNewsWorld. "That's a key hole in the law."

Progressive and Necessary

Against the backdrop of several high-profile credit card information breaches -- including last June's fiasco involving nearly four million CitiFinancial customers whose data was in danger following a faulty transfer of of unencrypted information to Experian -- the credit reporting companies called the cooperation an advance for consumer data protection.

The companies said the coordinated approach -- employing Advanced Encryption Standard (AES) and Triple Data Encryption Standard (3DES) algorithms -- would give "data furnishers" the choice of a single, standard encryption for reporting to Equifax, Experian or TransUnion.

"This cooperative effort to simplify, clarify and accelerate the use of industry-level encryption standards is progressive and necessary," said Consumer Data Industry Association President and CEO Stuart Pratt in a statement.

Encrypting Off the Hook

EPIC's Hoofnagle said although making it easier for furnishers to submit sensitive data in encrypted form was a "net good" for consumers, the collaboration may also represent the companies' effort to sidestep breach disclosure laws, such as California's, which had to be reconsidered in light of the loophole.

"On the one hand, the more companies using encryption the better," he said. "On the other hand, employing encryption may result in the public not being told about database breaches, even if they're significant."

Hoofnagle also indicated the cooperation among the credit reporting companies was likely a direct result of recent breaches where encryption would have better safeguarded consumer data.

"We assumed those banks were big and sophisticated enough that encryption would regularly be performed," he said.

Best Practices, Inside Threats

Verisign iDefense senior engineer Ken Dunham told TechNewsWorld the encryption standards that the credit reporting companies referred to were basic "best practices" for information security.

While he praised the effort, Dunham also added all companies must take a holistic view of their policies and procedures, especially concerning internal threats, which represent the biggest risk today.

"Whenever we have collaboration to improve security, and when we're looking at core components such as encryption, it's good," he said. "The danger of any such program is, you have to realize it has to be a comprehensive plan. An insider might steal information and compromise the entire database."


Print Version E-Mail Article Reprints More by Jay Lyman


More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network