Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

US Lawmakers Grapple with Warrantless Surveillance as Spy Laws Near Expiration

As US spy laws approach their expiration date, lawmakers are divided on how to protect American citizens from warrantless surveillance. This debate highlights the ongoing tension between national security interests and individual privacy rights, particularly concerning government access to communications data. The outcome will significantly shape the legal framework for intelligence gathering and its oversight for years to come. Privacy advocates are pushing for stronger safeguards to prevent potential abuses of power.

Today's question

A breach involving the loss of an encrypted USB drive containing personal data:

  1. Always requires notification to all data subjects, as required under the breach notification provisions
  2. Always requires notification to the supervisory authority, in accordance with the security obligations framework
  3. Qualifies as a security incident but falls below the notification threshold established for supervisory authority reporting
  4. May not require notification if the encryption was strong enough to make the data unintelligible to unauthorized persons and the key was not compromised

Answer this question on the site

Worth knowing

  1. Textbook Giant McGraw Hill Exposed 13.5 Million Records in Ransomware Attack

    Educational publisher McGraw Hill has reportedly fallen victim to a ransomware attack, resulting in the exposure of 13.5 million records. This incident underscores the critical vulnerability of large organizations holding sensitive personal data. The breach highlights the pervasive threat of ransomware and the extensive impact it can have on data privacy.

  2. Google Chrome Lacks Protection Against Advanced Browser Fingerprinting

    A report indicates that Google Chrome offers insufficient protection against sophisticated browser fingerprinting techniques, a common method for tracking users online without cookies. This vulnerability allows for persistent, unconsented user tracking across websites and sessions. It raises significant concerns about user privacy and the effectiveness of existing browser privacy settings.

  3. Anthropic Fails to Address Security Vulnerability in AI, Exposing 200,000 Servers

    Anthropic, an AI company, has reportedly not taken responsibility for a 'design flaw' in its products that could put 200,000 servers at risk. This alleged neglect highlights the critical need for robust security by design in AI systems and the potential for widespread vulnerabilities when AI developers do not prioritize security. The incident raises questions about accountability when AI systems introduce significant security risks.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.