Application Security
12/10/2010
09:57 PM
Connect Directly
RSS
E-Mail
50%
50%

Connecticut AG Demands Google Street View Data

Attorney General Richard Blumenthal has given Google until Dec. 17 to turn over the data that was wrongfully collected from personal and business Wi-Fi networks.

The Connecticut attorney general is demanding that Google turn over the data its street-mapping vehicles collected from personal and business wireless networks throughout the state.

Attorney General Richard Blumenthal said Friday that he had issued the order in the form of a civil investigative demand, the equivalent of a subpoena, after Google refused to turn over the data to the prosecutor's office. The state Department of Consumer Protection has joined Blumenthal in seeking the data.

Google acknowledged in May that its Street View cars had mistakenly harvested data traveling over unprotected Wi-Fi networks in more than 30 countries. The disclosure prompted multiple lawsuits, Congressional scrutiny in the U.S. and multiple investigations in Europe. Some countries have asked Google to delete the data, while others have asked the company to retain it to facilitate investigations.

Google has apologized for the snafu. The company did not respond to a request for comment Friday.

Blumenthal claimed Google initially said the data gathered in 2008 was fragmented, and has since changed its story, acknowledging that entire emails and other information may have been captured. In light of the disclosure, the attorney general's office wants to verify for itself the kind of data gathered, saying that it could include emails, passwords, Web-browsing, and other private information.

"Verifying Google's data snare is critical to assessing a penalty and assuring no repeat," Blumenthal says in a statement. "Consumers and businesses expect and deserve a full explanation, as well as measures shielding them from future spying."

The attorney general has given Google until Dec. 17 to meet the demand. Blumenthal did not say what the consequences would be, if the data is not turned over.

Blumenthal announced in June that his office would lead a multi-state investigation into Google's data-collection activities, which he called a "deeply disturbing invasion of personal privacy." Other states have yet to announce their participation in the investigation.

The U.S. Federal Trade Commission in October closed its inquiry, saying its was satisfied with changes it had made to prevent future data collection and with the company's promise to delete improperly gathered information as soon as possible.

In Europe, the reaction has been more severe. In Spain, government regulators have embarked on disciplinary proceedings that could lead to fines of several hundred thousand dollars for each infraction. In Germany, Several hundred thousand Germans have asked Google to remove their properties from Street View, an option offered to them as part of the deal Google signed with authorities. And Italian authorities have ordered Google to make sure its Street View cars -- recognizable by their roof-mounted periscope cameras -- are clearly marked and to provide advance notification of the routes the cars will travel.

SEE ALSO:

Connecticut AG Investigating Google Wi-Fi Incident

FTC Ends Google Street View Investigation

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2413
Published: 2014-10-20
Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie parameter to html/modules.php.

CVE-2012-5244
Published: 2014-10-20
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to...

CVE-2012-5701
Published: 2014-10-20
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project ...

CVE-2012-5865
Published: 2014-10-20
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action.

CVE-2012-5866
Published: 2014-10-20
Cross-site scripting (XSS) vulnerability in include.php in Achievo 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.