sigmoid.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A social space for people researching, working with, or just interested in AI!

Server stats:

597
active users

#notification

1 post1 participant0 posts today

The Information and Privacy Commissioner of Ontario has completed a review into Daixin Team's massive cyberattack on five regional hospitals in 2023 and found hospital officials acted “adequately.”

Perhaps the most notable aspect of the report (from my perspective) was that the IPC said the hospitals were obligated to notify patients whose data had been encrypted (and not just those whose data had been exfiltrated). They saw no point in requiring that now, but wanted it noted that it should have happened.

So that seems to be making PHIPA's interpretation clearer for future victims of encryption incidents.

The full report makes an interesting read.

PHIPA Decision 284:
decisions.ipc.on.ca/ipc-cipvp/

IPCDecisions - IPCIn accordance with Ontario’s privacy and access laws, the Commissioner and her delegates issue decisions, orders and privacy investigation reports. This post is also available in: French

American banking groups want the Securities and Exchange Commission (SEC) to revoke its cybersecurity incident disclosure requirements:
pymnts.com/cybersecurity/2025/

One of the problems they cite with the rule is "weaponization by hackers" where they link to my reporting as an example when AlphV tried to pressure a victim by complaining to the SEC that the victim hadn't timely disclosed to the SEC.

Direct link to letter to the SEC: sifma.org/wp-content/uploads/2

PYMNTS.com · Banks Want SEC to Rescind Cyberattack Disclosure Requirements | PYMNTS.comAmerican banking groups want the Securities and Exchange Commission (SEC) to revoke its cybersecurity incident disclosure requirements.  These groups, led

I very seldom see data breach notifications from North Dakota, but it's interesting to note that the state has now enacted HB 1127, overhauling its regulatory framework for financial institutions and nonbank financial service providers.

Read about the law's data protection and breach notification requirements: natlawreview.com/article/north

National Law Review · North Dakota Expands Data Security Requirements and Issues New Licensing Requirements for BrokersBy A.J. S. Dhaliwal
Replied in thread

@ai6yr @briankrebs OFC this targets #TechIlliterates and the only effective means here are:

  1. Teach #TechLiteracy instead of consumerism.
  2. Mandate #confirmation & #notification - #PopUp|s for every use of #Clipboard (similar to #webcam use by websites)...
  3. Ban #JavaScript - seriously!
  4. Ban #Windows, because it's a #Govware, espechally since #Windows10 and even more so on #Windows11 that is *insecure in every configuration!
  5. Put #TechIlliterates before a system they can't feck up. I.e. @tails_live @tails / #Tails for that reason alone (can't run such commands if they neither got #root nor any #persistent #storage to target).
  6. Normalize the use of @torproject #TorBrowser!
  7. #Teach #tech #literacy instead of #consumerism!
  8. Ban #GAFAMs and their shitty products!
  9. Migrate every #TechIlliterate to #Linux and don't give them administrative privilegues.
  10. Teach tech literacy instead of consumerism!