<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dickson]]></title>
    <link>http://securityratty.com/tag/dickson</link>
    <description></description>
    <pubDate>Mon, 03 Dec 2007 12:51:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Dickson County School District employee information stolen]]></title>
      <link>http://securityratty.com/article/c547b25ca5d443005c23b781eb42d2ae</link>
      <guid>http://securityratty.com/article/c547b25ca5d443005c23b781eb42d2ae</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/11/08

Organization
Dickson County School District

Contractor/Consultant/Branch
None

Victims
employees who worked for Dickson County schools in the...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dickson.jpg" align="right" height="153" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.dicksoncountyschools.org/index.html">Dickson County School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>"employees who worked for Dickson County schools in the 2006-2007 school year"<br><br><span style="font-weight: bold;">Number Affected:</span><br>850<br><br><span style="font-weight: bold;">Types of Data:</span><br>Payroll information including names, addresses and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"DICKSON, Tenn. -- A laptop computer containing personal employee information disappeared over the weekend from the office of Dickson County's top school official."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wsmv.com/news/16573465/detail.html">WSMV Channel 4 News</a> <br><a href="http://www.wztv.com/newsroom/top_stories/vid_1944.shtml">WZTV Channel 17 News</a> <br><a href="http://www.tennessean.com/apps/pbcs.dll/article?AID=/20080612/COUNTY03/806120370">The Tennessean</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Chris Tatum, WSMV Channel 4 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A laptop computer containing the Social Security numbers and payroll information of all the employees of the Dickson County school system has been stolen, and authorities are warning school officials to watch their bank accounts.<br><span style="font-style: italic;">[Evan] Is a physically and technically unsecure mobile device a good place to store confidential information?&nbsp; You probably know the answer to this already.</span><br><br>The computer belongs to the new director of schools and was loaded with the name and Social Security number of every school employee from the 2006-2007 school year, a total of 850.<br><br>"It's all public record except for the Social Security numbers," Johnny Chandler<br><span style="font-style: italic;">[Evan] Well yeah, except for the Social Security numbers!&nbsp; What the &amp;@*#?</span><br><br>"It came up missing over the weekend, sometime between Friday until Monday," said Dickson County school superintendent Johnny Chandler.<br><br>Chandler became the district's school superintendent last week and said that the laptop was on this desk when the office closed Friday evening.<br><span style="font-style: italic;">[Evan] I couldn't find any mention of whether or not the office itself was locked or secured.&nbsp; I presume that it was not.&nbsp; This is not a very good start to Mr. Chandler's tenure.</span><br><br>Police have launched an investigation, but found no signs of a break-in and haven't ruled out someone within the building being the cause of the theft.<br><br>Employees at the Board of Education and police investigators believe the person who stole the laptop walked right through the door without forced entry. <br><br>Chandler admits that a cleaning crew, several staff and students for a retirement party came into the building over the weekend.<br><br>He has warned all school employees to keep a close eye on their credit reports.<br><br>We sent letters to everyone that was on that database in '06 and '07<br><br>Chandler assures school employees that he'll make sure this never happens again.<br><span style="font-style: italic;">[Evan] How?</span><br><br>"All of our laptop computers will not be allowed to have any personal information concerning any employee or student," said Chandler.<br><span style="font-style: italic;">[Evan] This is one good step.&nbsp; Will this be in policy?&nbsp; Will employees be trained and made periodically aware of this mandate?&nbsp; How will this be enforced?&nbsp; Will this mandate include other mobile devices and media such as CDs, thumb drives, etc.?</span><br><br>He said the laptop is double password protected.<br><span style="font-style: italic;">[Evan] Sounds impressive, doesn't it.</span><br><br>"It has a double password so it would take a computer genius to get into it."<br><span style="font-style: italic;">[Evan] I am certainly no genius, but I am pretty sure I could get into it!</span><br><br>Chandler said he plans to upgrade the security system at the school board building.<br><br>In the meantime, workers will lock up any equipment that contains sensitive information when they're not using it.<br><br>Dickson police said they are notifying local pawn shops to be on the lookout for the stolen laptop.<br><br>Director Vivian McCord says, "I really wish they would return it."<br><br>"The office it was taken from was next to the computer office and there were multiple computers next door in that room. So I really feel like it was just a quick little taking of a computer."<br><br>Anyone with information should call the Dickson Police Department at (615) 441-9592<br><br><span style="font-weight: bold;">Commentary:</span><br>We see these kinds of breaches all the time, but why?&nbsp; It is frustrating.<br><br>Too many people collect and store personal information and are oblivious to the risks.&nbsp; A laptop computer + confidential information + unlocked office - encryption = unacceptable risk for most prudent people.&nbsp; A simplistic point, but you get it. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/12/dickson.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 07:52:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/store personal information">store personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/dickson county">dickson county</category>
      <category domain="http://securityratty.com/tag/dickson police">dickson police</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/school board">school board</category>
      <source url="http://breachblog.com/2008/06/12/dickson.aspx">Dickson County School District employee information stolen</source>
    </item>
    <item>
      <title><![CDATA[A downside to being a Billionaire]]></title>
      <link>http://securityratty.com/article/d4b02ee119f372cc4722b1e0f50eb642</link>
      <guid>http://securityratty.com/article/d4b02ee119f372cc4722b1e0f50eb642</guid>
      <description><![CDATA[I guess the grass isn't always greener on the other side. Even if the other side is you having a couple billion dollars. I dug into the archives for this post by Ed Dickson, which described how NYC...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_jCJICLQ1WVs/RuMWgzaiV9I/AAAAAAAAARM/s1WbfS3cqEA/s320/michael_bloomberg.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px;" src="http://bp2.blogger.com/_jCJICLQ1WVs/RuMWgzaiV9I/AAAAAAAAARM/s1WbfS3cqEA/s320/michael_bloomberg.jpg" alt="" border="0" /></a><br />I guess the grass isn't always greener on the other side. Even if the other side is you having a couple billion dollars. I dug into the archives for this post by Ed Dickson, which described how <a href="http://fraudwar.blogspot.com/2007/10/how-was-mayor-bloombergs-bofa-account.html">NYC Mayor Bloomberg was victimized twice</a>, almost simultaneously, by thieves trying to get at his multi-billion dollar wallet.<br /><br />Check out Ed's post for the details, but let's take a quick look at what we can learn from these attacks. The first was a pretty standard check counterfeiting attack. Not much you can do about that. If someone gets a copy of your check, with the routing number and account number, then they can produce a likeness that could be accepted by any number of merchants out there.<br /><br />The banks invest a lot in anti-counterfeiting marks on the checks, but in the end it's up to the merchant and your bank as to whether they will accept the fake. Most of the time they won't, but other times they may. That's why it's so important for you to keep on top of your finances and check your balances daily. Then you'll know if unauthorized charges are showing up. This is discussed in detail in Step 6 of <a href="http://www.securitymike.com/">Security Mike's Guide to Internet Security</a>.<br /><br />The second attack involved the criminal logging into Mr. Mayor's bank account and transferring money to a 3rd party financial institution. How did someone get his login and password? Who knows? It could have been anything. This is another example where staying on top of your account balances would have shown a weird transfer and you could have investigated it.<br /><br />I'm sure Bloomberg has people to look into this. That's how they found the issues and with a high profile victim like the Mayor, the banks and law enforcement will work hard to bring the perpetrators to justice.  It makes for good PR. I'm sure the bank also returned the money right where they found it, and no one but the criminals are any worse for wear.<br /><br />So I guess the grass is greener after all for the Billionaires out there. If it's not, you certainly can afford a lot of spray paint, sod or whatever else you want to use to make your grass seem greener.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/SecurityMike?a=xLYP6pC"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=xLYP6pC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/SecurityMike?a=3caoD7c"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=3caoD7c" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/SecurityMike?a=JnZvmdc"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=JnZvmdc" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecurityMike/~4/194579717" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Dec 2007 12:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/bank account">bank account</category>
      <category domain="http://securityratty.com/tag/pretty standard check">pretty standard check</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/nyc mayor bloomberg">nyc mayor bloomberg</category>
      <category domain="http://securityratty.com/tag/bloomberg">bloomberg</category>
      <category domain="http://securityratty.com/tag/mayor">mayor</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/greener">greener</category>
      <source url="http://feeds.feedburner.com/~r/SecurityMike/~3/194579717/downside-to-being-billionaire.html">A downside to being a Billionaire</source>
    </item>
  </channel>
</rss>
