Search This Blog

Showing posts with label breach. Show all posts
Showing posts with label breach. Show all posts

Tuesday, August 28, 2012

IMATION MAP OF STATE DATA BREACH NOTIFICATION LAWS SPOTLIGHTS NEED FOR STORING AND PROTECTING SENSITIVE INFORMATION

Press release from Imation:


IMATION MAP OF STATE DATA BREACH NOTIFICATION LAWS SPOTLIGHTS NEED FOR STORING AND PROTECTING SENSITIVE INFORMATION

Compliance Heat Map Illustrates Similarities and Differences in State Laws, with Virginia’s Being Most Strict; Laws Hint at Myr...

Compliance Heat Map Illustrates Similarities and Differences in State Laws, with Virginia’s Being Most Strict; Laws Hint at Myriad of Data Compliance Challenges Facing Businesses of All Sizes
OAKDALE, Minn.--(BUSINESS WIRE)--Aug. 28, 2012-- Imation Corp. (NYSE: IMN), a global scalable storage and data security company, today released results of research into state data breach notification laws and associated penalties. The analysis shows that current state data breach notification laws are strikingly similar but vary in compliance requirements for businesses, with all laws highlighting the need for companies to deploy methods for closely storing, protecting and controlling sensitive information. Imation used publicly available sites (including information obtained via the National Conference of State Legislatures) to analyze state compliance laws in the 46 U.S. states that have such laws, as well as in Puerto Rico, the District of Columbia and the U.S. Virgin Islands.
Imation created a “Compliance Heat Map” to depict the strictness of data breach laws and resulting penalties for breaches. The Compliance Heat Map provides a visual snapshot of the strictness of regulations by state, using a color scale ranging from light yellow (less strict) to dark red (more strict). To view the compliance heat map, click here: www.imation.com/compliancemap.
“What the compliance heat map tells us is that data security needs to be at top of mind for all IT pros, as there are rules in place for nearly all states and territories and non-compliance could mean serious penalties,” saidDavid Duncan, software & security solutions marketing director, Imation. “Yet, companies also are challenged by explosive data growth and state and federal requirements that mandate active archiving, long-term retention and accessibility of that data. Businesses need resources to help navigate laws and develop secure and scalable infrastructures for data storage and protection.”
IT pros today are responsible for managing data, which includes ensuring security, business continuity and regulatory compliance. For small- to mid-sized businesses, the challenge is often to meet compliance requirements with limited resources, which leads to higher risk. In fact, the 2011 Verizon Data Breach report found that businesses with between 11 and 100 employees reported more than six times as many data breaches than businesses with between 101 and 1,000 employees, according to the online websiteBusinessNewsDaily. Further, the loss or theft of an unencrypted notebook, flash drive or removable hard disk drive can expose gigabytes, or even terabytes, of private information. IT professionals should implement strategies to protect their data through network security, data encryption and enforcement of information security policies, while staying well-informed of state compliance laws in the not-unlikely event that a data breach does occur.
Compliance Heat Map Findings
Imation’s research found most state data breach notification laws to offer similar definitions of personally identifiable information and requirements regarding the notification of affected parties. Among the research’s noteworthy findings:
  • Four states have yet to enact a data breach notification law: AlabamaKentuckyNew Mexico and South Dakota.
  • According to Imation’s analysis, Virginia has the most strict law in the nation. The law provides specific requirements on what is to be included in a breach notification, requires government and credit reporting agency notification, and includes a large financial penalty relative to other states.
  • A few states, including Virginia, require notification even if breached data is encrypted—if the encrypted data was stolen along with the encryption keys.
Compliance Heat Map Methodology
To conduct the research, Imation applied to the laws a series of questions, organized to evaluate the laws’ requirements regarding encryption, data that is within scope of the laws, notification of data loss and destruction of data, as well as penalties for non-compliance with the laws. Imation also considered other germane laws, such as those dictating data destruction or allowing for consumer freezing of credit report requests. Imation used publicly available information about the laws, including the legislation itself.
Imation does not intend for this research to constitute a legal review of the laws, and in no way are the results of this research intended to be legal advice. Companies should consult with their legal counsel before making any decisions regarding legal compliance.
For more information, please visit www.imation.com/compliancemap.
About Imation
Imation is a global scalable storage and data security company. Our portfolio includes tiered storage and security offerings for business, and products designed to manage audio and video information in the home.Imation reaches customers in more than 100 countries through a powerful global distribution network and well recognized brands. For more information please visit www.imation.com.

Saturday, March 31, 2012

Chinese Company and Employee Deny Any Involvement in Hacking Attacks

Excerpt from an article in

The New York Times
Saturday, March 31, 2012

Chinese Company and Employee Deny Any Involvement in Hacking Attacks

By DAVID BARBOZA

SHANGHAI — Tencent, a Chinese Internet company, denied on Friday that one of its employees had been involved in a recent breach of computers belonging to Japanese and Indian companies, as well as Tibetan activists.

The company and the employee suggested that his identity might have been confused with someone else’s.

The company released a statement soon after Trend Micro, a computer security company with headquarters in Tokyo, released a report on Friday describing the breach. It was the result of a nearly yearlong effort to hack into computers and steal information from hundreds of companies and individuals in several countries, the report said.

The report never identified a hacker by name. But it linked the attacks to an alias used by a graduate of Sichuan University in western China who wrote several articles on computer hacking and defense. The researchers found the alias through its connection to an e-mail address and a QQ number, the Chinese equivalent of an instant messaging screen name.

The New York Times identified the owner of the alias as Gu Kaiyuan, based on online records of his writing. Mr. Gu is now an employee at Tencent, which offers social networking, instant messaging, online gaming and other online features.

On Thursday, when asked about the attacks, Mr. Gu said, “I have nothing to say.” On Friday, however, he denied involvement.

Visa and MasterCard Investigate Data Breach

Excerpt from an article in

The New York Times
Saturday, March 31, 2012

Visa and MasterCard Investigate Data Breach

By JESSICA SILVER-GREENBERG and NELSON D. SCHWARTZ

Visa and MasterCard are investigating whether a data security breach at one of the main companies that processes transactions improperly exposed private customer information, bank officials said Friday. The event highlighted a crucial vulnerability that could affect millions of credit card holders.

The breach occurred at Global Payments, an Atlanta company that helps Visa and MasterCard process transactions for merchants. One bank executive estimated that about one million to three million accounts could be affected. That does not mean that all those cards were used fraudulently, but that credit card information on the cardholders was exposed.

The bank official, who insisted on anonymity because the inquiry is at an early stage, said that Visa and MasterCard notified his company on Thursday, but that banks had been frustrated with the pace of disclosure by Global Payments. He said that Global Payments, which is one of the biggest transactions processors, had provided little information on where the breaches took place, how accounts were hacked and other details that could indicate which customers might be vulnerable.

Banks said that when they could identify victims, they would notify them and replace credit cards, if necessary.

While far from the largest breach of credit card data in recent years, the latest incident, which is being investigated by major banks and federal authorities as well as the card companies, underscores concerns about the vulnerability of electronic financial data.

Friday, March 30, 2012

Visa & MasterCard Security Breach

Note to Visitors:  We have moved!  For current news and information, please visit us at our successor blogs:  http://JBK-BizTech.blogspot.com and http://JBK-Current-Events.blogspot.com.  Thank you.


CNBC's Mary Thompson has the details on MasterCard and Visa investigating a potential data breach at a 3rd party processor.  To see videos, click the links below:

http://video.cnbc.com/gallery/?video=3000081506

http://video.cnbc.com/gallery/?video=3000081531

Saturday, March 24, 2012

'Hacktivists' Lead Data Breach Threats, Study Finds

A tiny but motivated band of 'hacktivists' are supplanting professional criminals as the biggest single data breach threat to large enterprises, an analysis of hundreds of confirmed incident reports has found.

On the face of it, the numbers in Verizon's 2012 Data Breach Investigations Report (which covers 2011) suggest that hacktivism is more of a nuisance than a major threat, accounting for only 3 percent of the 855 recorded attacks looked at across several countries.

But despite the modest volume of attacks, hacktivist incidents often lead to far more spectacular losses. Verizon found that from a total of 174 million records (individual database entries as well as documents) compromised in the 855 incidents, 100 million were stolen by hacktivists.

This means that hactivism is a theme in only three out of every 100 incidents, but nearly six out of ten of the actual records that are compromised. (See also "Ten Best Practices to Prevent Data and Privacy Breaches.")

For more, click the link below:


http://www.pcworld.com/article/252429/hacktivists_lead_data_breach_threats_study_finds.html#tk.nl_bdx_h_crawl

Thursday, March 22, 2012

2011 Was the Year of the 'Hacktivist'

2011 Was the Year of the 'Hacktivist,' According to the 'Verizon 2012 Data Breach Investigations Report'
Attacks Are Increasingly Motivated by Political and Social Intent; Majority of Breaches Avoidable With Sound Security Measures
News Release ShareThis
NEW YORK – March 22, 2012 –
The "Verizon 2012 Data Breach Investigations Report" reveals the dramatic rise of "hacktivism" -- cyberhacking to advance political and social objectives.

In 2011, 58 percent of data stolen was attributed to hacktivism, according to the annual report released today from Verizon.  The new trend contrasts sharply with the data-breach pattern of past several years, during which the majority of attacks were carried out by cybercriminals, whose primary motivation was financial gain.

Seventy-nine percent of attacks represented in the report were opportunistic.  Of all attacks, 96 percent were not highly difficult, meaning they did not require advanced skills or extensive resources.  Additionally, 97 percent of the attacks were avoidable, without the need for organizations to resort to difficult or expensive countermeasures.  The report also contains recommendations that large and small organizations can implement to protect themselves.

Now in its fifth year of publication, the report spans 855 data breaches across 174 million stolen records - the second-highest data loss that the Verizon RISK (Research Investigations Solutions Knowledge) team has seen since it began collecting data in 2004.  Verizon was joined by five partners that contributed data to this year's report: the United States Secret Service, the Dutch National High Tech Crime Unit, the Australian Federal Police, the Irish Reporting & Information Security Service and the Police Central e-Crime Unit of the London Metropolitan Police.

"With the participation of our law enforcement partners around the globe, the '2012 Data Breach Investigations Report' offers what we believe is the most comprehensive look ever into the state of cybersecurity," said Wade Baker, Verizon's director of risk intelligence.  "Our goal is to increase the awareness of global cybercrime in an effort to improve the security industry's ability to fight it while helping government agencies and private sector organizations develop their own tailored security plans."

The report findings reinforced the international nature of cybercrime.  Breaches originated from 36 countries around the globe, an increase from 22 countries the year prior.  Nearly 70 percent of breaches originated in Eastern Europe, with less than 25 percent originating in North America.

External attacks remain largely responsible for data breaches, with 98 percent of them attributable to outsiders.  This group includes organized crime, activist groups, former employees, lone hackers and even organizations sponsored by foreign governments.  With a rise in external attacks, the proportion of insider incidents declined again in this year's report, to 4 percent.  Business partners were responsible for less than 1 percent of data breaches.

In terms of attack methods, hacking and malware have continued to increase. In fact, hacking was a factor in 81 percent of data breaches and in 99 percent of data lost.  Malware also played a large part in data breaches; it appeared in 69 percent of breaches and 95 percent of compromised records.  Hacking and malware are favored by external attackers, as these attack methods allow them to attack multiple victims at the same time from remote locations.  Many hacking and malware tools are designed to be easy and simple for criminals to use.

Additionally, the compromise-to-discovery timeline continues to be measured in months and even years, as opposed to hours and days.  Finally, third parties continue to detect the majority of breaches (92 percent).

(NOTE:  Additional resources supporting the "2012 Data Breach Investigations Report" are available, including high-resolution charts,  B-roll available upon request.)

Key Findings of the 2012 Report

Data from the 2012 report also demonstrates that:

  • Industrial espionage revealed criminal interest in stealing trade secrets and gaining access to intellectual property.  This trend, while less frequent, has serious implications for the security of corporate data, especially if it accelerates.
  • External attacks increased. Since hacktivism is a factor in more than half of the breaches, attacks are predominantly led by outsiders.  Only 4 percent of attacks implicate internal employees.
  • Hacking and malware dominate. The use of hacking and malware increased in conjunction with the rise in external attacks in 2011.  Hacking appeared in 81 percent of breaches (compared with 50 percent in 2010), and malware appeared in 69 percent (compared with 49 percent in 2010). Hacking and malware offer outsiders an easy way to exploit security flaws and gain access to confidential data.
  • Personally identifiable information (PII) has become a jackpot for criminals. PII, which can include a person's name, contact information and social security number, is increasingly becoming a choice target. In 2011, 95 percent of records lost included personal information, compared with only 1 percent in 2010.
  • Compliance does not equal security.  While compliance programs, such as the Payment Card Industry Data Security Standard, provide sound steps to increasing security, being PCI compliant does not make an organization immune from attacks.
"The report demonstrates that unfortunately, many organizations are still not getting the message about the steps they can take to prevent data breaches," said Baker.  "This year, we have segmented our recommendations for enterprises and small businesses in the hope that this will make our suggestions more actionable. Additionally, we believe greater public awareness about cyberthreats and user education and training are vitally important in the fight against cybercrime."
Recommendations for Enterprises
  1. Eliminate unnecessary data. Unless there is a compelling reason to store or transmit data, destroy it.  Monitor all important data that must be kept.
  2. Establish essential security controls. To effectively defend against a majority of data breaches, organizations must ensure fundamental and common sense security countermeasures are in place and that they are functioning correctly. Monitor security controls regularly.
  3. Place importance on event logs. Monitor and mine event logs for suspicious activity - breaches are usually identified by analyzing event logs.
  4. Prioritize security strategy. Enterprises should evaluate their threat landscape and use the findings to create a unique, prioritized security strategy.
Recommendations for Small Organizations
  1. Use a firewall. Install and maintain a firewall on Internet-facing services to protect data. Hackers cannot steal what they cannot reach.
  2. Change default credentials. Point-of-sale (POS) and other systems come with pre-set credentials. Change the credentials to prevent unauthorized access.
  3. Monitor third parties. Third parties often manage firewalls and POS systems.  Organizations should monitor these vendors to ensure they have implemented the above security recommendations, where applicable.
The DBIR can be downloaded in full at: www.verizon.com/enterprise/2012dbir/us.
The Verizon 2012 DBIR will be available in seven languages. The initial report is in English, and translations will be available June 6 in French, German, Italian, Japanese, Spanish and Portuguese.

Verizon, through its Terremark subsidiary, helps organizations protect their core asset: data.  The company does this through a robust suite of security services -- including governance, risk and compliance solutions; identity and access management solutions; investigative response; data protection services; threat management services; and vulnerability management services -- delivered in the cloud or on premises.  For more information, visit us at verizonbusiness.com/products/security.  For ongoing security insight and analysis from some of the world's most distinguished security researchers, read the Verizon Security Blog at securityblog.verizonbusiness.com.

Verizon Communications Inc. (NYSE, Nasdaq: VZ), headquartered in New York, is a global leader in delivering broadband and other wireless and wireline communications services to consumer, business, government and wholesale customers.  Verizon Wireless operates America's most reliable wireless network, with nearly 108 million total connections nationwide.  Verizon also provides converged communications, information and entertainment services over America's most advanced fiber-optic network, and delivers integrated business solutions to customers in more than 150 countries, including all of the Fortune 500.  A Dow 30 company with $111 billion in 2011 revenues, Verizon employs a diverse workforce of nearly 194,000.  For more information, visit www.verizon.com.

####

Tuesday, March 20, 2012

Negligent Employees Top Cause of Data Breaches

Symantec-Sponsored Ponemon Report Finds Negligent Employees Top Cause of Data Breaches in the U.S. While Malicious Attacks Most Costly

Share on Facebook Tweet
MOUNTAIN VIEW, Calif. –Mar. 20, 2012 – Symantec Corp. (Nasdaq: SYMC) and the Ponemon Institute today released the findings of the 2011 Cost of Data Breach Study: United States, which reveals negligent insiders are the top cause of data breaches while malicious attacks are 25 percent more costly than other types. The study also found organizations which employ a chief information security officer (CISO) with enterprise-wide responsibility for data protection can reduce the cost of a data breach by 35 percent per compromised record. The organizational cost of a data breach was $5.5 million last year. The seventh annual Ponemon Cost of a Data Breach report is based on the actual data breach experiences of 49 U.S. companies from 14 different industry sectors.

Click to Tweet: Ponemon Institute report finds insiders pose greatest data breach threat: http://bit.ly/xoX1jv

“This year’s report shows that insiders continue to pose a serious threat to the security of their organizations,” said Francis deSouza, group president, Enterprise Products and Services, Symantec Corp. “This is particularly true as the increasing adoption of tablets, smart phones and cloud applications in the workplace means that employees are able to access corporate information anywhere, at any time. It is essential for companies to put the proper information protection policies and procedures in place to counterbalance these new realities.”

Additional key findings from the report include:
  • Negligent insiders and malicious attacks are the main causes of data breach. Thirty-nine percent of organizations say negligence was the root cause of the data breaches. For the first time, malicious or criminal attacks account for more than a third of the total breaches reported in this study. Since 2007, they also have been the most costly breaches. Accordingly, organizations need to focus on processes, policies and technologies that address threats from the malicious insider or hacker.
  • Certain organizational factors reduce the overall cost. If the organization has a CISO with overall responsibility for enterprise data protection the average cost of a data breach can be reduced as much as $80 per compromised record. Outside consultants assisting with the breach response also can save as much as $41 per record. When considering the average number of records lost or stolen, all of these factors can provide significant and positive financial benefits.
  • Specific attributes or factors of the data breach also can increase the overall cost. For example, in this year’s study organizations that had their first ever data breach spent on average $37 more per record. Those that responded and notified customers too quickly without a thorough assessment of the data breach also paid an average of $33 more per record. Data breaches caused by third parties or a lost or stolen device increased the cost by $26 and $22, respectively.
  • Detection and escalation costs declined but notification costs increased. Detection and escalation costs declined from approximately $460,000 in 2010 to $433,000 in 2011. These costs refer to activities that enable a company to detect the breach and whether it occurred in storage or in motion.
  • More customers remain loyal following the data breach. For the first time, fewer customers are abandoning companies that have a data breach. However, certain industries are more susceptible to customer churn, which causes their data breach costs to be higher than the average. Taking steps to keep customers loyal and repair any damage to reputation and brand can help reduce the cost of a data breach.
  • The cost of data breach declined. For the first time in seven years, both the organizational cost of data breach and the cost per lost or stolen record have declined. The organizational cost has declined from $7.2 million to $5.5 million and the cost per record has declined from $214 to $194.
“One of the most interesting findings of the 2011 report was the correlation between an organization having a CISO on its executive team and reduced costs of a data breach,” said Dr. Larry Ponemon, chairman and founder of the Ponemon Institute. “As organizations of all sizes battle an uptick in both internal and external threats, it makes sense that having the proper security leadership in place can help address these challenges.”

The U.S. Cost of a Data Breach Study was derived from a detailed analysis of 49 data breach cases with a range of nearly 4,500 to 98,000 affected records. It takes into account a wide range of direct business costs, including engaging forensic experts, outsourcing hotline support and providing free credit monitoring subscriptions and discounts for future products and services. Indirect costs include in-house investigations and communication, as well as the extrapolated value of customer loss resulting from turnover or diminished acquisition rates. The average cost of a data breach does not apply to catastrophic breaches (study excludes data breaches of more than 100,000 records) given they are not typical of those experienced in the United States. Companies analyzed were from 14 different industries, including finance, retail, healthcare, services, education, technology, manufacturing, research, transportation, consumer, hotels and leisure, media, pharmaceutical and communications.

Symantec recommends the following information protection best practices:
  • Assess risks by identifying and classifying confidential information
  • Educate employees on information protection policies and procedures, then hold them accountable
  • Implement an integrated security solution that includes reputation-based security, proactive threat protection, firewall and intrusion prevention in order to keep malware off endpoints
  • Deploy data loss prevention technologies which enable policy compliance and enforcement
  • Proactively encrypt laptops to minimize consequences of a lost device
  • Implement two factor authentication
  • Integrate information protection practices into businesses processes
Companies can analyze their own risk by visiting Symantec’s Data Breach Risk Calculator. Based on seven years of trend data, the calculator takes into account an organization’s size, industry, location and security practices to estimate how much a data breach would cost on both a per record and organizational basis. It is available athttp://www.databreachcalculator.com.

About the Ponemon Institute
The Ponemon Institute is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors and verifies the privacy and data protection practices of organizations in a variety of industries.

About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.

Wednesday, February 22, 2012

News Release from IBM

IBM Advances Security Intelligence to Help Organizations Combat Increasing Threats

To help customers better predict, prevent and detect breaches across an organization, IBM to tap security analytics and threat intelligence from more than 400 sources, including the X-Force Threat Feed
ARMONK, N.Y. - 22 Feb 2012:  IBM (NYSE: IBM) today unveiled new capabilities planned for its security intelligence platform designed to combine deep analytics with real-time data feeds from hundreds of different sources to give organizations, for the first time, the ability to help proactively protect themselves from increasingly sophisticated and complex security threats and attacks using a single platform.
Organizations today are struggling to defend themselves against an onslaught of ever-evolving data breaches, such as theft of customer and employee information, credit card data and corporate intellectual property. To date, many corporations have been unable to create a security defense system because they have cobbled together technologies that don't integrate in an intelligent and automated fashion.  This patchwork approach has created loopholes that hackers can exploit.
The QRadar Security Intelligence Platform, designed by Q1 Labs and acquired by IBM last fall, tackles this problem head-on by serving as a control center that integrates real-time security intelligence data to include more than 400 different sources.
Major breakthroughs planned in the security platform include:
"Trying to approach security with a piece-part approach simply doesn't work," said Brendan Hannigan, general manager, IBM Security Systems. "By applying analytics and knowledge of the latest threats and helping integrate key security elements, IBM plans to deliver predictive insight and broader protection."
With new integrations to be made available, the analytics platform can quickly identify abnormal activity by combining the contextual awareness of the latest threats and methods being used by hackers with real-time analysis of the traffic on the corporate IT infrastructure. For example, the future integrations permit the platform to detect when multiple failed logins to a database server are followed by a successful login and access to credit card tables, followed by an upload to an unknown site.
"We chose the QRadar platform to build on and deliver our vision of a streamlined, highly intelligent platform to serve as our central nervous system for enterprise-wide monitoring," said Ken Major, Information Security Officer at AmeriCU Credit Union. "It enables us to achieve our goals, industry best practices and regulatory compliance."
Threat Intelligence
One of the significant planned integrations for the QRadar platform is IBM's X-Force Intelligence Threat Feed based on the real-time monitoring of 13 billion security events per day, on average, for nearly 4,000 clients in more than 130 countries. The QRadar platform will have visibility into the latest security trends worldwide to help protect enterprises against emerging risks. QRadar will present current IBM X-Force threat feeds in dashboard views for users, and correlate an organization's security and network events with these threats and vulnerabilities in real-time using automated rules.
Broad Coverage
Other planned integrations to allow the QRadar Security Intelligence Platform to help clients more rapidly identify threats by connecting events from the following categories:
QRadar integration modules are also planned for Symantec DLP, Websense Triton, Stonesoft Stonegate and other third-party products, increasing QRadar's ecosystem and continuing Q1 Labs' long-standing approach to multi-vendor heterogeneous environments.
Solutions to Analyze Big Data
In addition, the QRadar platform has been expanded with Big Data capabilities for storing and querying massive amounts of security information, and functionality for helping to secure virtualized infrastructures and providing a new level of visibility that helps clients reduce security risk and automate their compliance processes.
The expansion of security and network data sources is complemented by advanced functionality to help organizations keep pace with their exponential data growth. The new deliverables include:
The planned integration modules (device support modules) are expected to be included with QRadar SIEM and QRadar Log Manager at no additional cost, via automatic updates.
Availability
The Big Data and virtual infrastructure enhancements are available now.  QRadar integration modules for IBM Guardium Database Security are planned to be available in 1Q2012.
Integration modules for IBM X-Force Threat Intelligence, IBM Security Identity Manager, IBM Security Access Manager, IBM Security AppScan and IBM Endpoint Manager are planned to be available in 2Q2012.  For more information, please visit www.q1labs.com.

Monday, February 13, 2012

Anger for Path Social Network

Excerpt from an article in The New York Times
Monday, February 13, 2012

Anger for Path Social Network After Privacy Breach 

By NICK BILTON

Last week, Arun Thampi, a programmer in Singapore, discovered that the mobile social network Path was surreptitiously copying address book information from users' iPhones without notifying them.

David Morin, Path's voluble chief executive, quickly commented on Mr. Thampi's blog that Path's actions were an "industry best practice." He then became uncharacteristically quiet as the Internet disagreed and erupted in outrage. Amid his silence, he did take the time to reply to the actress Alyssa Milano, who was one of hundreds who questioned Path's practices. (His reply to her via Twitter contained his personal e-mail address.)

Mr. Morin seemed unconcerned about how people could be harmed by his company's carelessness. Consider this: Amira El Ahl, a foreign journalist covering the Middle East, said bloggers in Egypt and Tunisia are often approached online by people who are state security in disguise.

The most sought-after bounty for state officials: dissidents' address books, to figure out who they are in cahoots with, where they live and information about their family. In some cases, this information leads to roundups and arrests.

A person's contacts are so sensitive that Alec Ross, a senior adviser on innovation to Secretary of State Hillary Rodham Clinton, said the State Department was supporting the development of an application that would act as a "panic button" on a smartphone, enabling people to erase all contacts with one click if they are arrested during a protest.

Mr. Morin eventually did bow to pressure with an earnest apology on the company's blog. He said that Path would begin asking for permission before grabbing address books and that the company would destroy the data collected.