That Was Close! Reward Reporting Of Cybersecurity “Near Misses”,
2018
University of Colorado Law School
That Was Close! Reward Reporting Of Cybersecurity “Near Misses”, Jonathan Bair, Steven M. Bellovin, Andrew Manley, Blake Reid, Adam Shostak
Publications
Building, deploying, and maintaining systems with sufficient cybersecurity is challenging. Faster improvement would be valuable to society as a whole. Are we doing as much as we can to improve? We examine robust and long-standing systems for learning from near misses in aviation, and propose the creation of a Cyber Safety Reporting System (CSRS).
To support this argument, we examine the liability concerns which inhibit learning, including both civil and regulatory liability. We look to the way in which cybersecurity engineering and science is done today, and propose that a small amount of ‘policy entrepreneurship’ could have substantial positive impact. …
A Free Ride: Data Brokers'rent-Seeking Behavior And The Future Of Data Inequality,
2018
Vanderbilt University Law School
A Free Ride: Data Brokers'rent-Seeking Behavior And The Future Of Data Inequality, Krishnamurty Muralidhar, Laura Palk
Vanderbilt Journal of Entertainment & Technology Law
Historically, researchers obtained data from independent studies and government data. However, as public outcry for privacy regarding the government's maintenance of data has increased, the discretionary release of government data has decreased or become so anonymized that its relevance is limited. Research necessarily requires access to complete and accurate data. As such, researchers are turning to data brokers for the same, and often more, data than they can obtain from the government. Data brokers base their products and services on data gathered from a variety of free public sources and via the government-created Internet. Data brokers then recategorize the existing …
Prescriptions At A Price: America's Opioid Crisis And The Increasing Toll On Drug Record Privacy,
2018
Vanderbilt University Law School
Prescriptions At A Price: America's Opioid Crisis And The Increasing Toll On Drug Record Privacy, Reem Blaik
Vanderbilt Journal of Entertainment & Technology Law
How should the US Constitution govern patient privacy in the face of a public health emergency? Declaring the United States' opioid crisis as a public health emergency may put the already-compromised integrity of drug record privacy at higher risk by virtue of emerging administrative responses, existing Supreme Court precedent, and acquiescent state laws. The White House convened a summit on opioids where the then-US attorney general discussed law enforcement responses to the crisis. Although the Fourth Amendment protects against unreasonable searches and seizures, the Supreme Court's third-party doctrine generally grants state and federal actors access to records released to third …
Corporate Cybersecurity: The International Threat To Private Networks And How Regulations Can Mitigate It,
2018
Vanderbilt University Law School
Corporate Cybersecurity: The International Threat To Private Networks And How Regulations Can Mitigate It, Eric J. Hyla
Vanderbilt Journal of Entertainment & Technology Law
Cyberattacks are occurring at an accelerating pace. Foreign nations are increasingly utilizing hacking as a tool for economic gain, acts of aggression, or international political expression. At risk are US consumers'personal data, private firms' bottom line, and the economies'integrity. In response, federal and state lawmakers have issued a series of disparate, uncoordinated policies seeking to strengthen cybersecurity practices. However, recent events indicate that these policies are less than ideal. This Note suggests that a unified response to cybersecurity is required and calls for the establishment of a single, central federal agency with authority over all cybersecurity regulations. Such an agency …
Designing Without Privacy,
2018
New York Law School
Designing Without Privacy, Ari Ezra Waldman
Articles & Chapters
In Privacy on the Ground, the law and information scholars Kenneth Bamberger and Deirdre Mulligan showed that empowered chief privacy officers (CPOs) are pushing their companies to take consumer privacy seriously, integrating privacy into the designs of new technologies. But their work was just the beginning of a larger research agenda. CPOs may set policies at the top, but they alone cannot embed robust privacy norms into the corporate ethos, practice, and routine. As such, if we want the mobile apps, websites, robots, and smart devices we use to respect our privacy, we need to institutionalize privacy throughout the corporations …
Table Of Contents,
2018
The Catholic University of America, Columbus School of Law
Table Of Contents
Catholic University Journal of Law and Technology
No abstract provided.
Public Authority Liability And The Regulation Of Nanotechnology: A European Perspective,
2018
Schulich School of Law, Dalhousie University
Public Authority Liability And The Regulation Of Nanotechnology: A European Perspective, Nina Natalia Baranowska
Canadian Journal of Law and Technology
This paper argues that in certain circumstances public authorities should be liable for regulating nanotechnology. Nanotechnology is an emerging field of technology that enables to control shape and size of various structures, devices and systems at nanometer scale on which one nanometer is equal to one-billionth of a meter. In spite of being a nascent field of science and technology, its scope of application – in the food, pharmaceuticals, cosmetics, construction, textile, electronics, and agricultural industries – is expanding rapidly. The risks associated to nanotechnology, however, and its long-term consequences are still largely unknown, particularly in regards to its health …
The Aleph Bet: Debating Metaphors For Information, Data Handling And The Right To Be Forgotten,
2018
Schulich School of Law, Dalhousie University
The Aleph Bet: Debating Metaphors For Information, Data Handling And The Right To Be Forgotten, Chris Prince, Micheal Vonn, Lex Gill
Canadian Journal of Law and Technology
Court rulings in the European Union (EU) have now established that individuals may seek erasure of personal information posted online. Typically, this involves de-indexing a website from search results, and in some instances the removal of content from primary sources sites. This has, in turn, led to debate around both the logistics and the unintended consequences of removing information online, and subsequent discussions have grappled with a range of images and metaphors to map that new legal reality. This essay surveys that debate, the imagery it employs, and the various logics associated with these metaphors.
A Long-Standing Debate: Reflections On Risk And Anxiety: A Theory Of Data Breach Harms By Daniel Solove And Danielle Keats Citron,
2018
University of Washington School of Law
A Long-Standing Debate: Reflections On Risk And Anxiety: A Theory Of Data Breach Harms By Daniel Solove And Danielle Keats Citron, Ryan Calo
Articles
This jointly-authored Article contributes mightily to our understanding of a critical aspect of privacy: harm. As Professors Solove and Citron carefully evidence, courts are reticent to countenance the harms that flow from a violation of privacy, even as they compensate similar harms in other contexts. Thus while exposing a plaintiff to an environmental or health risk may be compensable, few decisions vindicate victims of a data breach unless or until they experience actual identity theft. Courts have recognized subjective harms such as fear since the night W de S threw his fateful axe at M de S. But courts seldom …
A Drone’S Eye View: Why And How The Federal Aviation Administration Should Regulate Hobbyist Drone Use,
2018
Touro University Jacob D. Fuchsberg Law Center
A Drone’S Eye View: Why And How The Federal Aviation Administration Should Regulate Hobbyist Drone Use, Alexandria Tomanelli
Touro Law Review
No abstract provided.
An Unstoppable Force And An Immoveable Object? Eu Data Protection Law And National Security,
2018
Indiana University Maurer School of Law
An Unstoppable Force And An Immoveable Object? Eu Data Protection Law And National Security, Fred H. Cate, Christopher Kuner, Orla Lynskey, Christopher Millard, Nora Ni Loideain, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Data Localization The Unintended Consequences Of Privacy Litigation,
2018
American University Washington College of Law
Data Localization The Unintended Consequences Of Privacy Litigation, H Jacqueline Brehmer
American University Law Review
No abstract provided.
Body Cameras And The Path To Redeem Privacy Law,
2018
Boston University School of Law
Body Cameras And The Path To Redeem Privacy Law, Woodrow Hartzog
Faculty Scholarship
From a privacy perspective, the movement towards police body cameras seems ominous. The prospect of a surveillance device capturing massive amounts of data concerning people’s most vulnerable moments is daunting. These concerns are compounded by the fact that there is little consensus and few hard rules on how and for whom these systems should be built and used. But in many ways, this blank slate is a gift. Law and policy makers are not burdened by the weight of rules and technologies created in a different time for a different purpose. These surveillance and data technologies will be modern. Many …
The Case Against Idealising Control,
2018
Boston University School of Law
The Case Against Idealising Control, Woodrow Hartzog
Faculty Scholarship
Seemingly everyone, from scholars, industry, and privacy advocates to lawmakers, regulators, and judges seems to have settled on the idea that the key to privacy is control over personal information. But in practice, there is only so much a person can do. Control is far too precious and finite of a concept to meaningfully scale. It will never work for personal data mediated by technology.
Now we have an entire empire of data protection built around the crumbling edifice of control. The idealisation of control in modern data protection regimes like the GDPR and the ePrivacy Directive creates a pursuit …
Saving Face: Unfolding The Screen Of Chinese Privacy Law,
2018
Boston University School of Law
Saving Face: Unfolding The Screen Of Chinese Privacy Law, Tiffany Li, Jill Bronfman, Zhou Zhou
Faculty Scholarship
Privacy is often a subjective value, taking on meaning from specific social, historical, and cultural contexts. Western privacy scholars have so far generally limited academic study to focus on Western ideals of privacy. However, privacy – or some notion of it – can be found in almost every culture and every nation, including the growing economic powerhouse that is the People’s Republic of China. Focusing on China as a case study of non-Western privacy norms is important today, given the rapid rise of the Chinese economy and its corresponding impact on worldwide cultural norms and law. Simply put, it is …
Borders And Bits,
2018
Vanderbilt University Law School
Borders And Bits, Jennifer Daskal
Vanderbilt Law Review
Our personal data is everywhere and anywhere, moving across national borders in ways that defy normal expectations of how things and people travel from Point A to Point B. Yet, whereas data transits the globe without any intrinsic ties to territory, the governments that seek to access or regulate this data operate with territorial-based limits. This Article tackles the inherent tension between how governments and data operate, the jurisdictional conflicts that have emerged, and the power that has been delegated to the multinational corporations that manage our data across borders as a result. It does so through the lens of …
Blockchain Versus Data Protection,
2018
Indiana University Maurer School of Law
Blockchain Versus Data Protection, Fred H. Cate, Christopher Kuner, Orla Lynskey, Christopher Millard, Nora Ni Loideain, Dan Jerker B. Svantesson
Articles by Maurer Faculty
No abstract provided.
Così Fan Tutte: A Better Approach Than The Right To Be Forgotten,
2017
Syracuse University, School of Information Studies
Così Fan Tutte: A Better Approach Than The Right To Be Forgotten, Martha Garcia-Murillo, Ian Macinnes
School of Information Studies - Faculty Scholarship
In this article, we argue in favor of a macro-societal approach to protect people from the potential harms of personal information online. In the tension between information and privacy, “the right to be forgotten” is not an appropriate solution. Such a micro, individual-based answer puts the burden of protection on each person instead of on external entities that can abuse such knowledge. The personal responsibility to delete personal data is challenging because of the leakage of data that happens through the connections we have with others, many of whom do not share the same privacy preferences. We show that effective …
The Fourth Amendment Disclosure Doctrines,
2017
William & Mary Law School
The Fourth Amendment Disclosure Doctrines, Monu Bedi
William & Mary Bill of Rights Journal
The third party and public disclosure doctrines (together the “disclosure doctrines”) are long-standing hurdles to Fourth Amendment protection. These doctrines have become increasingly relevant to assessing the government’s use of recent technologies such as data mining, drone surveillance, and cell site location data. It is surprising then that both the Supreme Court and scholars, at times, have associated them together as expressing one principle. It turns out that each relies on unique foundational triggers and does not stand or fall with the other. This Article tackles this issue and provides a comprehensive topology for analyzing the respective contours of each …
Touch Dna And Chemical Analysis Of Skin Trace Evidence: Protecting Privacy While Advancing Investigations,
2017
William & Mary Law School
Touch Dna And Chemical Analysis Of Skin Trace Evidence: Protecting Privacy While Advancing Investigations, Mary Graw Leary
William & Mary Bill of Rights Journal
This Article addresses touch DNA, chemical analysis of skin traces, and the implications for crime scene investigation, arguing that changes in how trace evidence is analyzed require alterations in the law’s approach to its use. Part I discusses the history of traditional DNA analysis. Part II examines the emergence of touch DNA and related technologies and how they differ from traditional DNA analysis. Part III outlines the specific risks created by the collection and storing of results under the current outdated jurisprudence. Part IV focuses on specific risks to suspects and victims of crime. Part V proposes a legal framework …
