8353 research outputs found
Sort by
How Much Should We Spend to Protect Privacy?: Data Breaches and the Need for Information We Do Not Have
A cost/benefit approach to privacy confronts two tradeoff issues. One is making appropriate tradeoffs between privacy and many goals served by the collection, distribution, and use of information. The other is making tradeoffs between investments in preventing unauthorized access to information and the variety of other goals that also make money, time, and effort demands. Much has been written about the first tradeoff. We focus on the second. The issue is critical. Data breaches occur at the rate of over three a day, and the aggregate social cost is extremely high. The puzzle is that security experts have long explained how to defend better. So why does society tolerate a significant loss that it has the means to avoid?Some may object that society does not tolerate breaches. Laws—current and proposed—impose requirements aimed at improving information security. However, as Thomas Smedinghoff notes, most of the laws “simply obligate companies to establish and maintain ‘reasonable’ or ‘appropriate’ security measures, controls, safeguards, or procedures, but give no further direction or guidance.” The approach has so far failed to provide an adequate incentive to improve information security. As one commentator notes, the “bad guys basically go where they want to go and do what they want to do, and they\u27re not being stopped. Maybe for every one organization that\u27s effectively stopping attacks, there are 100 that are being breached.”We argue that the problem is not so much a lack of legal guidance as it is a lack of information. A standard cost/benefit approach is particularly suitable here. In the information security context, a business should adopt the following risk management goal: choose the most effective defense meeting the condition that the defense cost is not greater than the expected (business and relevant third-party) losses thereby avoided (over some appropriate short- or long-term time period). Businesses fall far short of a good approximation to business risk management goal. Applying this standard requires reasonably accurate information about the probability of a breach and the losses that will occur if it happens. Unfortunately, we are currently very far from having adequate information about either. The World Economic Forum report paints an accurate, if disturbing, picture of the consequences: “businesses are increasingly delaying the adoption of technological innovations due to inadequate understandings of required countermeasures. . . . A vicious circle results: uncertainty regarding proper levels of preparedness leads to forestalled investments in safeguards as interconnection expands exponentially.”A lack—even a severe lack—of objective information about probability and cost does not imply a complete inability to make better and worse decisions about information security. One can turn to subjective expert judgments and a variety of sophisticated analytic techniques that make use of them. Security outsourcing companies like AllClearID, BayDynamics, Healthguard Cyber Risk Management, and FireEye take this approach. Whatever its virtues, the “subjective judgment” approach can still spend far less or far more than the risk management goal requires. It is not a reliable guide to the optimal investment.We think the best course is to turn the unanswerable question into an answerable one by taking steps to discover the information need to adequately approximate the risk management goal. We see no alternative to the slow road of discovering the necessary information. This solution may seem singularly unappealing. Isn’t there a quicker fix? Data breach notification laws may seem to offer just that. There are at least two reasons to have breach notification laws. One is that the notifications are a source of precisely the information we need. The second is—so it is claimed—that they improve security. We focus on the second claim, which we argue is likely false. Indeed, such laws may make security worse (by focusing resources on avoiding reportable breaches, not on meeting the risk management goal). Breach notification laws are at best an uncertain road to improving risk management.The more certain, if longer, road is to get the information risk management needs. We argue for mandatory anonymous report by businesses of relevant information about data breaches
Stategraft
Although sometimes difficult to detect, governmental power abuses can have detrimental impacts. Property tax assessments provide an effective lens to examine this phenomenon because, given the complexity of calculating property tax assessments, it is difficult for citizens to know when local government has exceeded its legitimate taxing authority and crossed into the realm of illegal extraction. Michigan is an ideal case study because it protects property owners by making assessment-related power abuses more visible through a unique state constitutional provision: property tax assessments cannot exceed 50 percent of a property’s market value. Abuses have persisted nevertheless. Between 2011 and 2015, one in four properties in Detroit were subject to property tax foreclosure, and inflated property tax assessments that violate the Michigan Constitution are the unseen thread in this complex tapestry of foreclosure.Against this backdrop, this Article makes three primary contributions. First, no other article has argued and proven that property tax assessments in Detroit are illegal. Using assessment and sales data from 2009–2015 for the entire City of Detroit, we find that property tax assessments are substantially in excess of the state constitutional limit, and this illegality is most pronounced for lower-valued properties. Second, to remedy inflated assessments, in 2014 and 2015 Detroit’s assessor implemented assessment decreases ranging from 5 percent to 20 percent for select districts, but we find that systemic assessment inequity persisted for lower valued properties despite these reductions. Third, this Article uses the case of illegal property tax assessments in Detroit to develop a new theoretical concept called “stategraft,” which is when state agents transfer property from residents to the state in violation of the state’s own laws and to the detriment of a vulnerable group. Although the concept was developed using the Detroit case, stategraft applies beyond Detroit to many other cases, including the discriminatory fines imposed and enforced by the police and courts in Ferguson, Missouri; broken treaties with Native Americans; and abuses of civil forfeiture laws
Tactful Inattention: Erving Goffman, Privacy in the Digital Age, and the Virtue of Averting One\u27s Eyes
Dignity and Discrimination: Employment Civil Rights in the Workplace and in Courts
Employment civil rights and the litigation associated with enforcing them are a complex interplay of public and private employers, regulatory agencies, and federal courts. When an employee loses a job or their position in an employing organization, the financial effects are very real. If the employee makes a claim of discriminatory treatment using the employer’s human resources complaint processes or with the EEOC or state equivalent, they often face workplace retaliation and even termination. Using interviews conducted with parties to employment civil rights lawsuits, this article argues that the regime of employment civil rights in the United States can be conceived as perpetuating dignity takings (and occasionally dignity restorations) because (1) the state sanctions/permits/gives deference to management in ways that allow discrimination and loss of earnings and (2) does it in a way that allows and perpetuates dehumanizing infantilization which demonstrates that plaintiffs face dehumanizing stereotyped treatment in the workplace and in courts
Vol. 35, No. 4
Managing Public Employee Speech in the Age of Social Media – Instituting Policies Regulating Public Employee Conduct While Balancing Access to the “Democratic Forums of the Internet”, by Roxana M. Underwood
Recent Developmentshttps://scholarship.kentlaw.iit.edu/iperr/1106/thumbnail.jp
When Borders Dissolve
Scholars have long sought to apply principles from U.S. bankruptcy law to sovereign debt restructurings. Chapter 9 of the U.S. Bankruptcy Code, used to adjust the debts of municipalities, has been a particular source of inspiration, and several proposals currently exist to adapt chapter 9 to address the challenges of sovereign debt restructuring.
The difficulties of applying chapter 9 in practice, however, have demonstrated the limitations of a one-size-fits-all solution to municipal distress. Similarly, attempts to adapt chapter 9 to apply uniformly to a broad range of sovereign states may be ineffective. A recurring problem lies in the fact that bankruptcy principles are focused primarily on debt adjustment, while the problems that sovereign states (and, indeed, municipalities) face combine both financial and political aspects.
This Article seeks to encourage scholars to look beyond the municipal bankruptcy comparison and offers a study of the challenges and results that occur when municipalities merge. Studying city-county consolidations offers unique insight into possible techniques to address the fiscal and political problems resulting from significant governmental financial distress. The distinct differences between city-county consolidations and sovereign governments have perhaps obscured the benefits of studying these two areas together. This Article will demonstrate, however, that looking beyond the surface differences can provide valuable insight into new ways to address key fiscal and political challenges faced by government debtors
Survey of (Mostly Outdated and Often Ineffective) Laws Affecting Work-Related Monitoring
This article reviews various laws that affect work-related monitoring. It reveals that most of our privacy laws were adopted well before smartphones and the Internet became ubiquitous; they still hunt for physical secluded locations; and, because they are based on reasonable expectations of privacy, they can easily be circumvented by employer policies that eliminate that expectation by informing workers they have no right to privacy in the workplace. This article concludes that the future—indeed the present—does not bode well for worker privacy