Add Comment on:
Computer Crime Laws Chill Discovery of Customer Privacy Threats
Friday, May 30, 2008 :Have you ever wanted to test whether an e-commerce website is keeping your data secure? The federal Computer Fraud and Abuse Act -- and state statutes modeled on that law -- are so overbroad and vague that your curiosity could get you in deep legal water. When you access your account with an online retailer, the URL often contains a series of numbers. What if those numbers, instead of being randomly generated, appear to be unencrypted personal information, like the last four digits of your credit card, or your California Bar number. What would happen if you edited the URL to contain a different credit card or Bar number? Perhaps it would give you access to someone else's account. That's something you'd want to know because it means your information is also unsecured and the company has something important to fix.
Friday, May 30, 2008 :Have you ever wanted to test whether an e-commerce website is keeping your data secure? The federal Computer Fraud and Abuse Act -- and state statutes modeled on that law -- are so overbroad and vague that your curiosity could get you in deep legal water. When you access your account with an online retailer, the URL often contains a series of numbers. What if those numbers, instead of being randomly generated, appear to be unencrypted personal information, like the last four digits of your credit card, or your California Bar number. What would happen if you edited the URL to contain a different credit card or Bar number? Perhaps it would give you access to someone else's account. That's something you'd want to know because it means your information is also unsecured and the company has something important to fix.
×
Previews not available for media files.
Short description of the image used by screen readers.
Guidelines for commenting on news articles:
Thanks for contributing to Indybay's open publishing newswire. You may use any format for your response, from traditional academic discourse to subjective personal account. Please, keep it on topic and concise. Read our editorial policy, privacy, and legal statements before continuing. Or go back to the article.