lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <84EA00803F398243AD22BF36134C87D5F5958B@srvexch01.federatedinv.com> From: FederatedInformationSecurity at federatedinv.com (Federated Information Security) Subject: Emailing SSN info Google's a wonderful thing. A quick search on "Social Security Number Privacy Law" brought up the SSN FAQ (http://www.faqs.org/faqs/privacy/ssn-faq/) along with lots of other good links. Here's an excerpt from the FAQ: ----------------- The Privacy Act of 1974 The Privacy Act of 1974 (Pub. L. 93-579, in section 7), which is the primary law affecting the use of SSNs, requires that any federal, state, or local government agency that requests your Social Security Number has to tell you four things: 1: The authority (whether granted by statute, or by executive order of the President) which authorizes the solicitation of the information and whether disclosure of such information is mandatory or voluntary; 2: The principal purposes for which the information is intended to be used; 3: The routine uses which may be made of the information, as published annually in the Federal Register, and 4: The effects on you, if any, of not providing all or any part of the requested information. The Act requires state and local agencies which request the SSN to inform the individual of only three things: 1: Whether the disclosure is mandatory or voluntary, 2: By what statutory or other authority the SSN is solicited, and 3: What uses will be made of the number. -----Original Message----- From: full-disclosure-admin@...ts.netsys.com [mailto:full-disclosure-admin@...ts.netsys.com] On Behalf Of Tony Gettig Sent: Thursday, March 18, 2004 3:45 PM To: full-disclosure@...ts.netsys.com Subject: [Full-Disclosure] Emailing SSN info Hi all, I work for a school district in the USA. Higher management wants to email a zipped data export (presumbably password protected) to a vendor that includes the Social Security Number for employees. I have advised them against this. Shipping a CDROM overnight would be more secure, IMO. Now they want to know if there are any laws pertaining to the emailing of SSN info. (Why they are asking me and not an attorney, I am not sure...though I AM going to tell them to speak to an attorney too.) Can any one point me to a website or cite specific US (or even state) laws regarding this? Even a reply telling me why this is a bad idea would be great. If I am wrong, I am glad to hear that too. Thanks in advance! _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Powered by blists - more mailing lists