Risk
7/2/2008
01:47 PM
50%
50%

California Expands Identity Theft Prosecution

State law now allows identity thieves to be tried in the victims' jurisdictions, rather than only in the places the crimes occur.

California has passed a law that makes it easier to prosecute identity thieves.

Gov. Arnold Schwarzenegger signed Senate Bill 612 into law this week. It allows prosecutors to charge people with identity theft in the jurisdictions where the victims live. Without the bill, prosecutions could only take place where the crime occurred, which is usually in the perpetrators' towns or cities.

"That may make sense if it's in an old-fashioned property crime like a burglary, or even an auto theft," said Sen. Joe Simitian, a Palo Alto Democrat who sponsored the bill. "If an identity thief in Los Angeles goes online and steals the identity of a half dozen people in San Jose, the crime [had] to be prosecuted in L.A. That makes no sense at all, and, of course, it makes prosecution altogether unlikely."

Simitian said that system favored criminals, rather than helped victims.

"Local prosecutors are likely to be more aggressive on behalf of local victims," he said.

The new law does not require prosecution where the victim lives. Instead, it allows a judge to choose where to try identity-theft cases. Simitian and Republican Sens. Dave Cogdill and Bob Margett introduced the law after a "Governor's 2005 Summit on Identity Theft Solutions" highlighted the problem in a report.

Schwarzenegger said he's committed to protecting Californians' personal information and privacy.

"This commonsense legislation will lead to more prosecutions of this terrible crime, and anyone that commits or even thinks of committing identity theft should know that they will be prosecuted to the fullest extent of the law," he said. Lenny Goldberg of Privacy Rights Clearinghouse said the law puts teeth into existing laws.

"Without prosecution, there's no deterrent," he said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7830
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse cap...

CVE-2014-7831
Published: 2014-11-24
lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

CVE-2014-7832
Published: 2014-11-24
mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by vi...

CVE-2014-7833
Published: 2014-11-24
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

CVE-2014-7834
Published: 2014-11-24
mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?