Live data from Hacker News

If your database has Mass. residents, you need a security plan per Massachusetts

sqlmag.com

11–19 of 19 posts

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#11
post #3

Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.

It would be the US Constitution, where it gives all rights that are not explicitly enumerated to the states.

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#12
post #3

Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.

It would be the US Constitution, where it gives all rights that are not explicitly enumerated to the states.

"... or to the people." Let's not forget that. (Not that it's terribly relevant to your point.)

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#13
post #3

Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.

It would be the US Constitution, where it gives all rights that are not explicitly enumerated to the states.

True, but the commerce clause is enumerated in the constitution.

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#14
After reading the law, I'm either missing the part where data has to be encrypted in all databases or (more likely) the article is misleading. As I read it, the data in question has to be encrypted during transmission (SSL, no big deal) or while stored on a portable device. Nowhere did I get the sense that a web application must maintain encrypted database records at all times.

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#15
post #3

Ummm, what's the legal theory that allows a US state to regulate out of state commerce like this? On the other hand, I wouldn't want to be a web company based in Massachusetts and this might have more than a small effect on the Boston area's attractiveness to many startups.

--article snip-- I could wax eloquently on about the potential battle of states’ rights versus federal oversight and the potential for a Supreme Court challenge based on the Commerce Clause, but, this is an article for geeks, so I won’t go there. Instead, I’ll simply say once again: yikes. --snip--

It seems silly to state legalities are out of scope when you're talking about a law, even if (or, especially if!) you're not writing for lawyers.

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#16
post #7
post #6

Earlier quoted context omitted.

Well - that's enough to make it relevant whenever there's a card transaction... that's going to affect a lot of people. This however "and perhaps the rest of the world" is complete FUD - noone outside of US cares about US state laws (unless you have some branch there of course - but then you already know you have a lot more paperwork to do).

There's no need to store any of those things in your database in order to allow card transactions.

This is not my field, but don't you have to store card card numbers in order to do things like issue refunds?

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#17

I do like the idea of encrypting user names across the wire, but "to maintain a Written Information Security Plan (WISP) and file it with the state of Massachusetts" goes way too far, imho. I am not a lawyer nor a database geek, so perhaps your take will differ... UPDATE: "Massachusetts does not require that written information security programs be filed at this time, just that they exist," according to a second arti…

For reference, the law's URL, which was cited in slantyyz's reference, was out of date. Here is the current link; http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#18
post #16
post #7

Earlier quoted context omitted.

There's no need to store any of those things in your database in order to allow card transactions.

This is not my field, but don't you have to store card card numbers in order to do things like issue refunds?

Correct that, partial refunds.

Re: If your database has Mass. residents, you need a security plan per Massachusetts

#19

I do like the idea of encrypting user names across the wire, but "to maintain a Written Information Security Plan (WISP) and file it with the state of Massachusetts" goes way too far, imho. I am not a lawyer nor a database geek, so perhaps your take will differ... UPDATE: "Massachusetts does not require that written information security programs be filed at this time, just that they exist," according to a second arti…

There is absolutely no need to "file" the WISP with the state. The WISP is an internal document that state officials would likely look for in the event of a data security incident (i.e., a breach or report of lost data such as a missing laptop).
Post reply on HN