Federal Privacy Bill in the Works, Facebook Abuses Access to Users Phone Numbers, HIPAA Breach Notification for Media




InfoSec ICU show

Summary: What are Gerry and Steve talking about this week?<br> The guys discuss the federal government beginning to engage experts to develop a bill to address citizen’s privacy.  The call out Facebook for offering multi-factor authentication and then using users phone numbers for other means. They round out with the obligation of media outlets to publish breach notifications that are sent to them, as required by HHS and federal law.<br> As always they end with One Cool Thing.<br> <a href="https://podcast.musc.edu/podcast/infosec/e65-infosecicu/" target="_blank" rel="noopener noreferrer">Show Notes</a><br> <br> Resources:<br> InfoSec ICU is a finalist for Best Local Podcast in Charleston. <br> Vote here -&gt; <a class="Hyperlink SCXW91944092" href="http://chscp.co/BestOfArts" target="_blank" rel="noopener noreferrer">http://chscp.co/BestOfArts</a><br> 1. Privacy is solved, the government is involved.<br> <a href="https://www.securityweek.com/us-lawmakers-kick-debate-over-online-privacy" target="_blank" rel="noopener noreferrer">https://www.securityweek.com/us-lawmakers-kick-debate-over-online-privacy</a><br> Hearing: <a href="https://energycommerce.house.gov/committee-activity/hearings/hearing-on-protecting-consumer-privacy-in-the-era-of-big-data" target="_blank" rel="noopener noreferrer">https://energycommerce.house.gov/committee-activity/hearings/hearing-on-protecting-consumer-privacy-in-the-era-of-big-data</a><br> Video with start time: <a href="https://youtu.be/mN1_FVOIA6s?t=1026" target="_blank" rel="noopener noreferrer">https://youtu.be/mN1_FVOIA6s?t=1026</a><br> 2. Give us your phone number, says Facebook. You can trust us.<br> <a href="https://motherboard.vice.com/en_us/article/kzdxjx/facebook-phone-number-two-factor-authentication" target="_blank" rel="noopener noreferrer">https://motherboard.vice.com/en_us/article/kzdxjx/facebook-phone-number-two-factor-authentication</a><br> 3. Media reports of data breaches. Are they required to publish?<br> <a href="http://www.live5news.com/2019/03/01/more-than-k-letters-were-sent-out-patients-after-phishing-attack-roper-st-francis/" target="_blank" rel="noopener noreferrer">http://www.live5news.com/2019/03/01/more-than-k-letters-were-sent-out-patients-after-phishing-attack-roper-st-francis/</a><br> One Cool Things<br> James Veitch: “This is what happens when you reply to spam email”<br> <a href="https://www.youtube.com/watch?v=_QdPW8JrYzQ" target="_blank" rel="noopener noreferrer">https://www.youtube.com/watch?v=_QdPW8JrYzQ</a><br> Wireshark hits 3.0<br> <a href="https://www.wireshark.org/docs/relnotes/wireshark-3.0.0.html" target="_blank" rel="noopener noreferrer">https://www.wireshark.org/docs/relnotes/wireshark-3.0.0.html</a><br>  <br> Contact<br> Email <a href="mailto:infosecicu@musc.edu">infosecicu@musc.edu</a><br> Twitter:<br> <br> * <a href="https://twitter.com/Gerald_Auger" target="_blank" rel="noopener noreferrer">Gerry Auger (@Gerald_Auger)</a><br> * <a href="https://twitter.com/sgcardinal" target="_blank" rel="noopener noreferrer">Steven Cardinal (@sgcardinal)</a><br> <br>