精品国产_亚洲人成在线高清,国产精品成人久久久久,国语自产偷拍精品视频偷拍

立即打開
監管部門為什么懲罰黑客襲擊受害者

監管部門為什么懲罰黑客襲擊受害者

Verne Kopytoff 2012-07-02
美國政府準備懲罰那些遭受黑客襲擊的公司,因為它們沒有履行職責,采取足夠的措施來保障客戶的信息安全。這一點,或許對中國能夠有所啟示。

????黑客侵入了X公司的電腦系統,盜走了數千名顧客的信用卡賬號。得知此事后,X公司公開道歉,并承諾將加強安全防范。老百姓的公憤喧囂一時后便歸于沉寂,直到同樣的循環又在Y公司身上發生。

????只有少數案例沒有按著這個劇本走。比如上周早些時候,美國聯邦貿易委員會(Federal Trade Commission)將溫德姆國際酒店集團(Wyndham Worldwide)告上法庭,理由是后者沒有采取足夠措施保護客戶信息。亞利桑那州的聯邦法院受理了此案。聯邦貿易委員會在起訴書中稱,過去兩年里,黑客先后三次入侵了溫德姆集團的電腦系統,但在此之后,溫德姆集團并沒有采取足夠措施升級安全系統。

????溫德姆集團回應稱,聯邦貿易委員會的指控缺乏法律依據。

????和溫德姆集團不同的是,大多數遭受黑客襲擊的企業都沒有撞到聯邦貿易委員會的槍口上。就算黑客襲擊造成了非常嚴重的后果,但只要這些公司采取了合理的安全措施,就能躲過懲罰。

????不過一旦聯邦貿易委會員認定一家公司的安全系統門戶大開,使客戶信息處于容易失竊的狀態,這家公司可能就要吃官司了。因為所有企業肯定都承諾過要保護它們收集的消費者信息,遵守標準的行業準則。而對安全系統存在的漏洞視而不見則明顯違反了該隱私政策。

????聯邦貿易委會員隱私與身份保護部的檢察官克里斯汀?科恩指出:“我們一直認為,遭受黑客襲擊不是犯罪。我們只調查那些隱私政策容易誤導顧客的公司——他們可能做了一些有欺騙性或是不公平的事。”

????過去10年里,聯邦貿易委員會已經對大約35家涉嫌虛報、誤報企業數據安全性的公司提起了訴訟或達成和解。例如今年年初,社交游戲網站RockYou就與聯邦貿易委員會達成和解,而Twitter也曾在2010年與聯邦貿易委員會達成了類似和解。

????美國近年的黑客襲擊頻頻得手,與之相比,區區三十多起訴訟與和解顯得十分蒼白。據身份失竊資源中心 (dentity Theft Resource Center)報道,光是去年,美國就發生了419起黑客案件,受影響人數多達2,290萬人。該中心主任雷克斯?戴維斯表示,實際上得手的襲擊次數肯定還要更高,因為很多公司在遭到黑客襲擊后都沒有對外披露。

????溫德姆集團旗下運營著戴斯酒店(Days Inn)、速8(Super 8)和華美達(Ramada)等知名酒店品牌。聯邦貿易委會員在上周二遞交的起訴書稱,溫德姆集團甚至沒有實施基本的安全措施。例如該集團把用戶的信用卡賬號保存在文本文檔里,黑客輕易地就可以讀取到。

????2008年溫德姆集團第一次遭遇黑客襲擊就造成了50萬張信用卡賬戶流出,有數十萬個賬號被發送到注冊在俄羅斯的一個主機上。在接下來的兩年里,溫德姆集團又遭受了兩次攻擊,造成5萬多張信用卡和借記卡賬號失竊。

????聯邦貿易委會員表示,黑客們最多可以利用他們獲得的信息詐騙到1,060萬美元。但溫德姆集團反擊稱,據他們的了解,沒有客戶因此蒙受經濟損失。

????Hackers infiltrate Company X's computers and make off with thousands of customer credit card numbers. After learning of the theft, Company X apologizes and promises to beef up its security. A storm of public indignation builds and then passes until, soon after, the cycle repeats itself when hackers attack another Company Y. And so on.

????Only rarely does the script deviate like it did this week when the Federal Trade Commission sued Wyndham Worldwide (WYN) for failing to do enough to protect its customer information. The complaint, filed in federal court in Arizona, alleged that Wyndham did little to upgrade security after hackers breached its computer system three times in two years.

????Wyndham responded that the case was without merit.

????Unlike Wyndham, most companies that fall victim to hackers never enter the F.T.C.'s crosshairs. As long as businesses have reasonable security measures, they can avoid punishment after even serious breaches.

????What draws the F.T.C.'s attention is when it believes a company left the door wide open to its customer information. Such inattention violates privacy policies in which companies invariably promise that they safeguard the consumer data they collect, using standard industry practices.

????"We have always said that it is not a violation to be hacked," said Kristin Cohen, an attorney in the F.T.C.'s division of privacy and identity protection. "We can only go after companies that have misleading privacy policies -- either they did something that was deceptive or unfair."

????Over the past decade, the F.T.C. has reached settlements or sued around 35 companies for misrepresenting their data security. For example, RockYou, a social game site, settled with the agency earlier this year while Twitter did so in 2010.

????The number of cases pales next to the proliferation of successful hacker attacks in the United States. Last year alone, there were 419 breaches reported affecting 22.9 million people, according to the Identity Theft Resource Center, a group that tracks the problem. The number of successful attacks is almost certainly higher, however, because many companies fail to disclose when their defenses are defeated, said Rex Davis, director of operations for the center.

????In its complaint Tuesday, the F.T.C. said that Wyndham, which operates and franchises Days Inn, Super 8 and Ramada hotels, failed to implement basic security measures. Credit card numbers were stored in text files that hackers could easily read, for example.

????The first hacker attack against Wyndham in 2008 compromised 500,000 credit card accounts, and led to hundreds of thousands of account numbers being sent to a domain registered in Russia. Two more attacks over the next two years accessed another 50,000 credit and debit card numbers.

????The F.T.C. said that the hackers were able to use the information they obtained to make $10.6 million in fraudulent charges. Wyndham countered that it knows of no customers who suffered a financial loss.

熱讀文章
熱門視頻
掃描二維碼下載財富APP

            主站蜘蛛池模板: 南投县| 东安县| 永嘉县| 溧阳市| 吉木萨尔县| 漳州市| 大冶市| 同仁县| 都安| 深泽县| 九龙城区| 丹江口市| 成武县| 喀喇沁旗| 通州市| 永福县| 体育| 高唐县| 湖南省| 喀喇| 浦城县| 拜城县| 绵阳市| 延津县| 姜堰市| 海城市| 台安县| 滦平县| 青田县| 新晃| 苏尼特右旗| 朝阳县| 衡阳市| 盐津县| 鸡西市| 阿勒泰市| 上高县| 克拉玛依市| 洛浦县| 柘城县| 英德市|