Application Security
12/10/2010
09:57 PM
50%
50%

Connecticut AG Demands Google Street View Data

Attorney General Richard Blumenthal has given Google until Dec. 17 to turn over the data that was wrongfully collected from personal and business Wi-Fi networks.

The Connecticut attorney general is demanding that Google turn over the data its street-mapping vehicles collected from personal and business wireless networks throughout the state.

Attorney General Richard Blumenthal said Friday that he had issued the order in the form of a civil investigative demand, the equivalent of a subpoena, after Google refused to turn over the data to the prosecutor's office. The state Department of Consumer Protection has joined Blumenthal in seeking the data.

Google acknowledged in May that its Street View cars had mistakenly harvested data traveling over unprotected Wi-Fi networks in more than 30 countries. The disclosure prompted multiple lawsuits, Congressional scrutiny in the U.S. and multiple investigations in Europe. Some countries have asked Google to delete the data, while others have asked the company to retain it to facilitate investigations.

Google has apologized for the snafu. The company did not respond to a request for comment Friday.

Blumenthal claimed Google initially said the data gathered in 2008 was fragmented, and has since changed its story, acknowledging that entire emails and other information may have been captured. In light of the disclosure, the attorney general's office wants to verify for itself the kind of data gathered, saying that it could include emails, passwords, Web-browsing, and other private information.

"Verifying Google's data snare is critical to assessing a penalty and assuring no repeat," Blumenthal says in a statement. "Consumers and businesses expect and deserve a full explanation, as well as measures shielding them from future spying."

The attorney general has given Google until Dec. 17 to meet the demand. Blumenthal did not say what the consequences would be, if the data is not turned over.

Blumenthal announced in June that his office would lead a multi-state investigation into Google's data-collection activities, which he called a "deeply disturbing invasion of personal privacy." Other states have yet to announce their participation in the investigation.

The U.S. Federal Trade Commission in October closed its inquiry, saying its was satisfied with changes it had made to prevent future data collection and with the company's promise to delete improperly gathered information as soon as possible.

In Europe, the reaction has been more severe. In Spain, government regulators have embarked on disciplinary proceedings that could lead to fines of several hundred thousand dollars for each infraction. In Germany, Several hundred thousand Germans have asked Google to remove their properties from Street View, an option offered to them as part of the deal Google signed with authorities. And Italian authorities have ordered Google to make sure its Street View cars -- recognizable by their roof-mounted periscope cameras -- are clearly marked and to provide advance notification of the routes the cars will travel.

SEE ALSO:

Connecticut AG Investigating Google Wi-Fi Incident

FTC Ends Google Street View Investigation

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.