Legislation urged to protect corporate data, theft of e-mail addresses
Computerworld - WASHINGTON -- A congressional subcommittee exploring the need for new cybercrime legislation was urged today by private-sector officials to back laws protecting the confidentiality of security data shared with the government and to prohibit the "harvesting" of e-mail addresses from Web sites by spammers.
"We are constantly subjected to individuals who come to our site, steal our addresses and then use those e-mail addresses to send illegal spam," said Robert Chesnut, a vice president at online auction site eBay Inc. in San Jose, at a hearing before the House Judiciary Committee's Subcommittee on Crime.
Chesnut said e-mail harvesters are using automated tools to gather e-mail addresses. Calling the activity a "parasitic process" that undermines public confidence in e-commerce, Chesnut urged the committee to outlaw the bulk harvesting of e-mail addresses for the purpose of sending spam. EBay has more than 29 million registered users.
In other testimony, trade group officials said legislation is needed to keep corporate security data that's shared with government agencies from becoming public under the Freedom of Information Act (FOIA).
"Companies worry that if information sharing with the government really becomes a two-way street, FOIA requests for information they have provided to an agency could prove embarrassing or costly," said Harris Miller, president of the Information Technology Association of America, an industry trade group in Arlington, Va.
Sen. Robert Bennett (R-Utah) is expected to introduce legislation before the August recess that would exempt corporate security data from public disclosure. In the House, U.S. Reps. Tom Davis (R-Va.) and James Moran (D-Va.), who co-sponsored similar legislation last year, are also expected to reintroduce the measure before the recess.
Today's hearing was the third and final hearing on cybercrime by the subcommittee, which is looking for legislative ideas on combating this new criminal activity, said U.S. Rep. Lamar Smith (R-Texas), the subcommittee chairman.
"We hope that these hearings will result in some legislation," said Smith. He noted that Congress hasn't updated many of its laws to reflect new technologies and methods of communications since the mid-1980s.
Earlier this week, the committee was urged by Michael Chertoff, a newly confirmed assistant attorney general at the U.S. Justice Department, to toughen penalties for some cybercrimes and to make changes in procedural regulations to clarify the laws used to trace telephone calls so that they can also be applied to e-mail and telephony (see story).
Chertoff, as well as the private-sector officials who testified today, said government must have adequate resources to combat cybercrime.
Underscoring legislative concerns by the private sector



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts