<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Law &amp; Policy on Rietta Cybersecurity</title>
    <link>https://rietta.com/categories/law-policy/</link>
    <description>Recent content in Law &amp; Policy on Rietta Cybersecurity</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>1999-2026 Rietta Inc. All Rights Reserved.</copyright>
    <atom:link href="https://rietta.com/categories/law-policy/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Threat Modeling for ADA/WCAG Compliance</title>
      <link>https://rietta.com/blog/threat-modeling-ada-wcag-compliance/</link>
      <pubDate>Tue, 28 Jul 2026 14:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/threat-modeling-ada-wcag-compliance/</guid>
      <description>Why Accessibility Belongs in Your Threat Model Most organizations treat digital accessibility as a content problem: someone finds a missing alt tag, fixes it, and moves on. I think that&amp;rsquo;s the wrong frame entirely. Digital accessibility is an organizational risk and governance gap, and once you see it that way, the right tool for the job isn&amp;rsquo;t a content checklist. It&amp;rsquo;s the same discipline we already use for application security: threat modeling and continuous technical monitoring.</description>
    </item>
    <item>
      <title>The Five Pillars of Information Security (And Why We Audit Accessibility)</title>
      <link>https://rietta.com/blog/five-pillars-infosec-ada-accessibility/</link>
      <pubDate>Sat, 25 Jul 2026 15:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/five-pillars-infosec-ada-accessibility/</guid>
      <description>Rietta is a cybersecurity firm. So why have the last three posts on this blog been about missing document titles, undefined languages, and metadata fields in government PDFs? My reasoning comes down to this: accessibility failures are security failures, specifically, they&amp;rsquo;re availability failures, and detecting them at scale is exactly the discipline our industry already practices.&#xA;To explain why, it helps to back up and lay out the actual model we use to reason about security in the first place.</description>
    </item>
    <item>
      <title>Metadata in WordPerfect: ADA and WCAG 2.1 Compliance</title>
      <link>https://rietta.com/blog/metadata-in-wordperfect-ada-wcag-compliance/</link>
      <pubDate>Fri, 24 Jul 2026 10:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/metadata-in-wordperfect-ada-wcag-compliance/</guid>
      <description>Courts throughout the United States still use WordPerfect. So why is metadata still being ignored?&#xA;In our work with State courts, we have come across WordPerfect files, or PDF documents generated from them, with metadata deficiencies: no title (or subject), no author, and so forth. Now that WCAG 2.1 requirements are enforced through ADA Title II, documents without sufficient metadata to assist a user with disabilities using assistive technology are non-conformant with federal law.</description>
    </item>
    <item>
      <title>Real ADA Title II Findings for Government Documents</title>
      <link>https://rietta.com/blog/real-ada-title-ii-findings/</link>
      <pubDate>Tue, 07 Jul 2026 15:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/real-ada-title-ii-findings/</guid>
      <description>I recently wrote about the upcoming ADA Title II deadline for governments with 50k or more residents in their jurisdiction.&#xA;Overview As we continue to work with Government organizations, Rietta is providing plain language reporting on the issues and tying them directly back to the requirements. Our reports cover a lot of ground, some of which is not talked about in accessibility circles quite enough. For example, we have a very strong argument that using the same title over and over again is not compliant even though accessibility vendors will do that as they seem to be looking at documents one at a time and not corpus wide.</description>
    </item>
    <item>
      <title>297 Days: The Real ADA Title II Deadline for Government Documents</title>
      <link>https://rietta.com/blog/real-ada-title-ii-deadline/</link>
      <pubDate>Fri, 03 Jul 2026 06:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/real-ada-title-ii-deadline/</guid>
      <description>As a government agency, do you know how many of your documents will soon be a litigation risk under the ADA?&#xA;In our cybersecurity work, Rietta has the pleasure of working with a number of government entity clients. In the last few years, a new risk has appeared linked with web content accessibility. Last year, we worked with one particular client to ensure their thousands of PDF documents were ready by the deadline with appropriate alternate content and an accommodation workflow.</description>
    </item>
    <item>
      <title>Stop Thinking about GA SB 315 in Terms of &#34;Digital Homes&#34;</title>
      <link>https://rietta.com/blog/sb-315-public-business-not-digital-homes/</link>
      <pubDate>Wed, 25 Apr 2018 21:55:46 -0400</pubDate>
      <guid>https://rietta.com/blog/sb-315-public-business-not-digital-homes/</guid>
      <description>&lt;p&gt;Throughout the &lt;a href=&#34;https://www.google.com/search?q=georgia+sb+315&amp;amp;source=lnms&amp;amp;tbm=nws&amp;amp;sa=X&amp;amp;ved=0ahUKEwjFst6E9dbaAhVxU98KHUW8AlkQ_AUIDygA&amp;amp;biw=1221&amp;amp;bih=1241&#34;&gt;public debate over Georgia SB 315&lt;/a&gt;, a bad analogy has been repeated by others that a public business or institution&amp;rsquo;s website server is like an online home. And, because nobody lets strangers just walk into their own home, Georgia should set the expectation that no one, criminal or ethical, should be allowed to come into an organization&amp;rsquo;s digital &amp;ldquo;home&amp;rdquo; without permission. &lt;strong&gt;But this analogy does not match reality!&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Governor Deal, veto SB 315 because white hat security researchers should be thanked not jailed!</title>
      <link>https://rietta.com/blog/letter-to-governor-nathan-deal-to-veto-ga-sb-315/</link>
      <pubDate>Thu, 19 Apr 2018 07:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/letter-to-governor-nathan-deal-to-veto-ga-sb-315/</guid>
      <description>&lt;p&gt;Friday, April 13, 2018&lt;/p&gt;&#xA;&lt;p&gt;Governor Nathan Deal&lt;br/&gt;&#xA;Office of the Governor&lt;br/&gt;&#xA;206 Washington Street&lt;br/&gt;&#xA;111 State Capitol&lt;br/&gt;&#xA;Atlanta, Georgia 30334&lt;br/&gt;&lt;/p&gt;&#xA;&lt;p&gt;Dear Governor Deal:&lt;/p&gt;&#xA;&lt;p&gt;I am writing you today on behalf of my Georgia-based security firm, asking that you veto &lt;a href=&#34;http://www.legis.ga.gov/Legislation/en-US/display/20172018/SB/315&#34;&gt;SB 315&lt;/a&gt;. I am a long term Georgia resident, raised in the Atlanta area, and earned a B.S. in Computer Science and an M.S. in Information Security at Georgia Tech. My wife Danielle is a Mercer University alumna, and we are both conservative Christians who voted for you. My interests in computer security started early after I founded AtlantaWebHost.com eighteen years ago and started to see first hand how websites and servers were under continuous attack by malicious hackers. This first hand experience was the catalyst for pursuing a career dedicated to protecting websites and web applications from attackers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Georgia SB 315, set to criminalize most independent security threat research, heads to Georgia Governor Nathan Deal for signature or veto</title>
      <link>https://rietta.com/blog/georgia-sb-315-to-make-threat-research-criminal/</link>
      <pubDate>Tue, 27 Mar 2018 13:55:53 -0400</pubDate>
      <guid>https://rietta.com/blog/georgia-sb-315-to-make-threat-research-criminal/</guid>
      <description>This article has been updated since originally published to reflect the current status of SB 315, which is now heading to the Governor&#39;s desk.) The Georgia House of Representatives voted 107 to 63 to approve GA SB 315 (LC 29 8107S) (PDF / legis.ga.gov) on Tuesday, March 27, 2018, on the Senate voted 42 to 7 to accept the House changes in the last hours of the session on Thursday, March 29, 2018.</description>
    </item>
    <item>
      <title>Georgia SB 315 anti-hacking law dangerously misses the mark of protecting people, making us all less safe</title>
      <link>https://rietta.com/blog/georgia-sb-315-anti-hacking-bill/</link>
      <pubDate>Mon, 26 Mar 2018 12:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/georgia-sb-315-anti-hacking-bill/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.legis.ga.gov/Legislation/20172018/177608.pdf&#34;&gt;GA SB 315 (LC 29 8107S)&lt;/a&gt;&#xA;(PDF / legis.ga.gov) just passed the House Judiciary Non-Civil Committee and&#xA;will be voted on this week.&#xA;While significantly improved through the committee process, it still creates a&#xA;dangerously broad definition of Criminal Unauthorized Computer Access that is so&#xA;sweeping, people will need permission before visiting any website.&lt;/p&gt;&#xA;&lt;p&gt;This bill was drafted because Georgia law enforcement and the U.S. FBI could not&#xA;find any law broken by a professional security researcher. This researcher&#xA;tried to alert Georgia election officials of voter data inappropriately&#xA;published publicly on the Internet by Kennesaw State University, a contractor for&#xA;the Georgia Secretary of State&amp;rsquo;s Office. What he discovered through ordinary&#xA;Google searching was that voters&amp;rsquo; names, addresses, and other private&#xA;information was indexed by Google and accessible by anyone. After months, he&#xA;and another researcher discovered that the data was still available on the&#xA;public Internet and brought it to the attention of the media. Only under&#xA;the daylight of public attention was the data removed from the Internet&#xA;in an embarrassing scandal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troubling ISP Privacy Repeal: The Data Will be Breached</title>
      <link>https://rietta.com/blog/isp-privacy-repeal/</link>
      <pubDate>Thu, 18 May 2017 11:59:59 -0400</pubDate>
      <guid>https://rietta.com/blog/isp-privacy-repeal/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://rietta.com/images/posts/2017/05/troubling-isp-privacy-repeal.jpg&#34; alt=&#34;The U.S. Congress &amp;amp; The President&amp;rsquo;s Troubling Repeal of Internet Privacy Protections - Photo Credit: &amp;amp;copy; 2013 Frank Rietta. &#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Your Internet Service Provider has direct access to the type of information on you and your family that the National Security Agency uses for spying.&lt;/p&gt;&#xA;&lt;p&gt;Your ISP knows when you are at home and when you are not, when your kids are doing their homework. They know or can know what you&amp;rsquo;re watching on Netflix (&lt;a href=&#34;#reed-kranch&#34;&gt;even when its encrypted&lt;/a&gt;) and YouTube. If any member of your household ever views pornographic content, your ISP knows how much and at what times such content is accessed. They can infer through traffic analysis how many people are living at your home and even know how many iPhone and Android devices that you have. And even though they cannot see into your encrypted search queries on Google, your ISP knows every medical website that you visited to research a condition that you think you have or are looking into a drug that your doctor has prescribed to you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Americans&#39; Access to Strong Encryption is at Risk, an Open Letter to Congress</title>
      <link>https://rietta.com/blog/americans-access-to-strong-encryption-is-at-risk/</link>
      <pubDate>Wed, 03 May 2017 19:34:59 -0400</pubDate>
      <guid>https://rietta.com/blog/americans-access-to-strong-encryption-is-at-risk/</guid>
      <description>&lt;p&gt;Dear Honorable Members of the United States Congress:&lt;/p&gt;&#xA;&lt;p&gt;I work in application security in the cybersecurity field to make software more secure from attack. The cybersecurity threats that face our nation are very important to my wife and me. As Americans, our private data is in great jeopardy because of increased cybersecurity threats. Our infrastructure is prone to being hacked, and major data breaches of both private and government networks are routinely in the news. The best way to prevent these breaches is to increase the use of strong encryption with &lt;em&gt;no backdoors&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The track record of data breaches demonstrates an uncomfortable truth: when sophisticated adversaries want to hack a network, they will ultimately win. Among the few tools known to computer science that can prevent a data breach is strong encryption. This means that there is no backdoor and no backup key. Either the original user needs to enter the password, or the data is un-retrievable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Calls to Ban Effective Encryption Continue Despite Data Breach Crisis</title>
      <link>https://rietta.com/blog/calls-to-ban-encryption-despite-data-breach-crisis/</link>
      <pubDate>Fri, 22 Apr 2016 09:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/calls-to-ban-encryption-despite-data-breach-crisis/</guid>
      <description>&lt;p&gt;The continued calls for the U.S. Congress to ban effective encryption despite the current computer security crisis in which data breaches are regular news is dangerous, shortsighted, and destined to harm all Americans. The two most effective tools that we have capable of helping prevent data breaches are encryption and reducing the attack surface of computer systems that handle sensitive or private data. Under the proposed legal framework, both will be sacrificed for a false sense of safety.&lt;/p&gt;&#xA;&lt;p&gt;The latest installment of Congressional hearings was held by the Energy and Commerce Committee on April 19, 2016, and was titled &lt;em&gt;Deciphering the Debate Over Encryption: Industry and Law Enforcement Perspectives&lt;/em&gt;. The calls for Congress to ban effective encryption are repeated with little variance from the past. Some Members of Congress are expressing frustration that the debate is repeating itself without law enforcement suggesting any particular middle ground that would be workable for the tech community. But what is most chilling is that those in law enforcement continue to demand exceptional access despite years of back and forth and the parade of high profile data breaches both within government and the private sector. We&amp;rsquo;re losing the cybersecurity battle and the government is calling for a ban on one of the most effective tools that computer science has at its disposal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>U.S. Senate Bill Seeks to Ban Effective Encryption, Making Security Illegal</title>
      <link>https://rietta.com/blog/feinstein-burr-encryption-bill/</link>
      <pubDate>Fri, 08 Apr 2016 10:11:33 -0400</pubDate>
      <guid>https://rietta.com/blog/feinstein-burr-encryption-bill/</guid>
      <description>&lt;p&gt;The anticipated Feinstein-Burr &lt;em&gt;Compliance with Court Orders Act&lt;/em&gt;, an anti-security bill, would&#xA;&lt;a href=&#34;https://www.scribd.com/doc/307378123/Burr-Encryption-Bill-Discussion-Draft&#34;&gt;require the provision of data in an intelligible format to a government pursuant to a court order&lt;/a&gt; (scribd.com). A draft copy was&#xA;uploaded by The Hill reporter &lt;a href=&#34;https://twitter.com/Cory_Bennett&#34;&gt;Cory Bennett&lt;/a&gt;, though whether&#xA;it has been submitted officially within the Senate is &lt;a href=&#34;https://motherboard.vice.com/en_ca/read/leaked-burr-feinstein-encryption-bill-is-a-threat-to-american-privacy&#34;&gt;not yet clear&lt;/a&gt; (vice.com).&lt;/p&gt;&#xA;&lt;p&gt;This bill essentially says you can not have any conversation or data exchange that the government can not access if it wants to.&#xA;It is the legal culmination of what the FBI has been lobbying Congress for years. If Feinstein-Burr&#xA;becomes law, it will be illegal to deploy strong encryption &lt;em&gt;without key escrow&lt;/em&gt; maintained by each company. Cryptographers and computer scientists near-unanimously assert key backup systems are insecure at scale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wikipedia *blackout* tomorrow in protest to SOPA/PIPA</title>
      <link>https://rietta.com/blog/wikipedia-blackout-tomorrow-in-protest/</link>
      <pubDate>Tue, 17 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://rietta.com/blog/wikipedia-blackout-tomorrow-in-protest/</guid>
      <description>&lt;p&gt;Tomorrow (Jan 18) &lt;a href=&#34;http://wikimediafoundation.org/wiki/English_Wikipedia_anti-SOPA_blackout&#34; target=&#34;_blank&#34;&gt;Wikipedia will be shut down for 24 hours in protest of Congress&amp;rsquo; continuation of consideration of the Stop Online Privacy Act (SOPA) and Protect IP Act (PIPA)&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The Wikipedia blackout demonstrates the chilling nature of what can happen when websites can be shutdown on mere accusation without due process. The new requirements could even stifle early-stage investment in internet startup companies.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
