<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: duke]]></title>
    <link>http://securityratty.com/tag/duke</link>
    <description></description>
    <pubDate>Thu, 06 Dec 2007 08:37:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Former NYU personal information exposed at Duke University]]></title>
      <link>http://securityratty.com/article/c7ac0212b7ea0a34816a3630ea9cae15</link>
      <guid>http://securityratty.com/article/c7ac0212b7ea0a34816a3630ea9cae15</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/20/08

Organization
New York University

Contractor/Consultant/Branch
Duke University, Fuqua School of Business

Victims
Former NYU students

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/nyu.jpg" align="right" height="82" width="121"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/20/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.nyu.edu/">New York University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.fuqua.duke.edu/">Duke University, Fuqua School of Business</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Former NYU students<br><br><span style="font-weight: bold;">Number Affected:</span><br>273<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"DURHAM, N.C. - Duke University’s Fuqua School of Business is notifying 273 former New York University students that some of their personal information was inadvertently accessible by targeted Internet searches between July 2007 and April 2008."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.newsobserver.com/news/story/1079337.html">The News &amp; Observer</a> <br><a href="http://www.nbc17.com/midatlantic/ncn/news.apx.-content-articles-NCN-2008-05-20-0016.html">NBC Channel 17 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Eric Ferreri, The News &amp; Observer<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>DURHAM - Duke University's Fuqua School of Business is notifying 273 former New York University students that some of their personal information was inadvertently accessible by targeted Internet searches between July 2007 and April 2008.<br><span style="font-style: italic;">[Evan] The information was public and went unnoticed by school, IT, and information security officials for nine months.</span><br><br>The NYU students were part of a 1997 class taught by a professor who now teaches at the Duke business school<br><span style="font-style: italic;">[Evan] Why would a professor ever need access to Social Security numbers?&nbsp; NYU may use or might have used Social Security numbers as student numbers.&nbsp; Many schools are migrating away from this practice due to obvious (hopefully) privacy implications.&nbsp; It is troubling that a former professor was allowed to leave NYU with confidential information belonging to students.</span><br><br>The professor is not identified<br><br>The personal data included student names and Social Security numbers, and was contained in the faculty member’s NYU research records.<br><span style="font-style: italic;">[Evan] Did the professor not notice that he/she had Social Security numbers as part of his/her research records?</span><br><br>There has been no indication of any unauthorized access or use of the personal information<br><br>Duke’s Internet security team has ascertained that the information could have been accessed only if searched by specific student names, along with a search code for Social Security numbers.<br><span style="font-style: italic;">[Evan] I suppose we could take them at their word although it would be very difficult to state this claim with certainty.&nbsp; Search algorithms are very closely guarded secrets by Google, Yahoo, et. al.</span><br><br>The personal information was removed from Fuqua's public drives within 30 minutes of the school becoming aware of the problem on April 30.<br><span style="font-style: italic;">[Evan] The ability to post information for public consumption must be closely monitored by organizations, and those with permissions must be properly trained.</span><br><br>Within hours, all major search engines had cleared their caches and indexes of the student information<br><br>Fuqua began notifying the former NYU students immediately after receiving addresses from NYU<br><br>Fuqua officials have undertaken a thorough review of the school’s electronic accounts to ensure no personal information is subject to unauthorized access. <br><br>No former or current Fuqua students were affected.<br><br><span style="font-weight: bold;">Commentary:</span><br>Most of my commentary is remarked above.&nbsp; What do the schools plan to do in order to reduce the chances of this happening again? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/21/nyu.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 10:27:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nyu">nyu</category>
      <category domain="http://securityratty.com/tag/nyu students immediately">nyu students immediately</category>
      <category domain="http://securityratty.com/tag/nyu students">nyu students</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/fuqua">fuqua</category>
      <category domain="http://securityratty.com/tag/current fuqua students">current fuqua students</category>
      <category domain="http://securityratty.com/tag/specific student names">specific student names</category>
      <category domain="http://securityratty.com/tag/names">names</category>
      <source url="http://breachblog.com/2008/05/21/nyu.aspx">Former NYU personal information exposed at Duke University</source>
    </item>
    <item>
      <title><![CDATA[Duke School of Law breach affects 3,200]]></title>
      <link>http://securityratty.com/article/26f7b1c688ec864f0ccf677c71a53dcc</link>
      <guid>http://securityratty.com/article/26f7b1c688ec864f0ccf677c71a53dcc</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/4/07

Organization
Duke University

Contractor/Consultant/Branch
School of Law

Victims
Current and prospective Law School applicants

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/duke.jpg" align="right" height="88" width="197"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>12/4/07<br><br><span style="font-weight: bold;">Organization: </span><br>Duke University<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>School of Law<br><br><span style="font-weight: bold;">Victims:</span><br>Current and prospective Law School applicants<br><br><span style="font-weight: bold;">Number Affected:</span><br>3,200*<br><font size="1"><br>*1,400 in one database containing applicant data and some Social Security numbers, 1,800 in a second database containing applicant data and passwords used by applicants tracking their applications.</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, phone numbers, Social Security numbers, and passwords<br><br><span style="font-weight: bold;">Breach Description:</span><br>The Duke University School of Law reported that they detected unauthorized and illegal activity on a their web site.&nbsp; An investigation revealed that two databases were exposed in the attack that contained sensitive personal information about some current and prospective Law School applicants and students.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.law.duke.edu/incident" target="_blank"> Duke School of Law Incident Web Page</a><br><a href="http://www.newsobserver.com/news/story/811800.html" target="_blank"> The News and Observer Story</a><br><a href="http://www.upi.com/NewsTrack/Top_News/2007/12/05/hacker_may_have_stolen_duke_students_data/2789/" target="_blank"> United Press International Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Melinda Vaughn, Executive Director of Communications at Duke University<br><br><span style="font-weight: bold;">Response:</span><br>From the official incident web page and sources cited above:<br><br><img src="http://breachblog.com/images/95781-88451/duke2.jpg" border="0" width="298"><br><font size="1">On the Duke University home page</font><br><br>Thank you very much for your patience as we continue to work to restore our web site and understand the full ramifications of the attack on our web site and server. The attack was a criminal act, and it is now being investigated by law enforcement officials.<br><br>Earlier this evening, the Law School sent emails to about 3,200 prospective and current applicants notifying them that some of their personal information was exposed during the recent attack on our web site.<br><br>We have no evidence that the intruders actually downloaded or acquired any of this information. Nonetheless, we know the intruders had the opportunity and the tools to do so, and we therefore felt it was important to notify those who might have been affected as quickly as possible.<br><span style="font-style: italic;">[Comfyllama] A good forensic analysis should provide clues if the proper trail exists.&nbsp; You would think that a web server containing sensitive information would employ extensive logging.</span><br><br>On Thursday, Nov. 29, at about 3:30 p.m., we detected unauthorized links and coding in our web site. As soon as a breach was confirmed, we took the site offline and launched our investigation.<br><br>By Friday, it appeared that we had removed the unauthorized content, and we reposted the web site.<br><span style="font-style: italic;">[Comfyllama] Ugh.&nbsp; Thursday afternoon until Friday was all it took to re-certify the site?&nbsp; Doesn't seem like a good incident response.&nbsp; If a site is compromised, it is usually a better practice to replace it with a new rebuilt server so that the original can be thoroughly examined.</span><br><br>Our continuing investigation, however, found that the web server had been compromised, and that the attack had penetrated more deeply than originally thought.<br><span style="font-style: italic;">[Comfyllama] In incident response, it's not a bad idea to hope for the best but assume the worst.</span><br><br>We took the web site down again by Saturday morning pending a more complete security scan by the university’s IT Security Office. We do not believe that any new problems were introduced during the short time that the site was reposted.<br><br>As we further evaluated the site, we found that several databases stored on the server were exposed during the attack.<br><span style="font-style: italic;">[Comfyllama] Databases on a web server?&nbsp; Bad.</span><br><br>There were two databases containing sensitive or potentially sensitive information. The first held records containing information submitted by prospective applicants who were requesting information from the admissions office.<br><br>A small percentage of those prospective applicants had provided Social Security numbers when they completed our online request form. That group of 1,400 prospective students received notifications this afternoon about the security breach.<br><span style="font-style: italic;">[Comfyllama] Social Security numbers in a database on a web server? Worse.</span><br><br>The second database in question included contact information and self-generated passwords for about 1,800 current applicants who were using our web site to track the status of their law school applications.<br><br>Even though our second database did not contain Social Security numbers, we also have notified this group of the security breach, in case the passwords they used on our site are the same as the passwords they use on other sites.<br><span style="font-style: italic;">[Comfyllama] Prudent decision on the part of the school.</span><br><br>the first intrusion occurred in early November, when a directory of foreign files was inserted into the site. Another set of files was deposited on Thanksgiving Day. We believe that nothing was done with these files until the attack began on the afternoon of Nov. 29.<br><span style="font-style: italic;">[Comfyllama] Write access to the web server, and the responders didn't think that the compromise "had penetrated more deeply than originally thought"?</span><br><br>Duke University has a policy not to gather Social Security numbers, except in a limited number of circumstances including some transactions with applicants and prospective applicants.<br><span style="font-style: italic;">[Comfyllama] This is a good policy.</span><br><br>The Social Security numbers in this database were no longer being used, and we had in fact stopped collecting them from applicants earlier this fall. But the database had not been purged of old data.<br><span style="font-style: italic;">[Comfyllama] Lack of audit and review.</span><br><br>We are reviewing our policies to ensure we are in full compliance with all policies that pertain to the handling of Social Security numbers.<br><span style="font-style: italic;">[Comfyllama] Sometimes it takes a breach to spur additional audit and review that should have been conducted regularly all along.&nbsp; Unfortunately, there are people affected already.</span><br><br>What has been done to secure the web site and prevent this from happening again?<br>Over the weekend, we moved the site off our web server to allow us to install a completely new operating system and new software. While that was being done, we also reviewed all the data from the old server’s system for remnants of the intrusion.<br><br>The application status tracker is being restructured so that it will not require passwords. Social Security numbers have been removed and will not be stored on our web server.<br><br>We are continuing our investigations into how this attack occurred and what additional steps can be taken in the short and long term to further secure our web site and all our electronic data. We will update you on our progress in coming weeks, and we will provide a full report to the community once the investigation and security planning is complete. In the meantime, if you have any questions or concerns, please feel free to contact me **email address removed**, Liz Gustafson **email address removed**, or Jill Miller **email address removed**.<br><span style="font-style: italic;">[Comfyllama] We (meaning The Breach Blog) removed the email addresses because we are still a little "old school" in this regard and think that publishing email addresses without obfuscation increases the likelihood of increased spam.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>This has to be one of the best incident disclosure announcements I have ever seen in terms of depth.&nbsp; The explanation of what occurred is clear, Duke's response is clear, and what they plan to do is clear.&nbsp; I am impressed.<br><br>Now, what I am not impressed about is the decision to store confidential information on a web server.&nbsp; More often than not, this is bad news.&nbsp; Common information security practice is to place publicly accessible servers in a DMZ, segmented from more secure systems that contain databases.&nbsp; Extensive monitoring is then placed on both systems and in between.&nbsp; I am curious how the server itself was compromised.&nbsp; Was it not patched, was it not configured well, was the code written poorly, was someone surfing the web on the server and downloaded malicious code, etc.?&nbsp; I am also curious about whether or not the University conducts regular audits of these systems and runs intrusion detection.&nbsp; Even after such a wonderful announcement by the school, so many questions still remain! <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/06/duke.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Thu, 06 Dec 2007 08:37:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/duke school">duke school</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/comfyllama social security">comfyllama social security</category>
      <category domain="http://securityratty.com/tag/complete">complete</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/complete security scan">complete security scan</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <source url="http://breachblog.com/2007/12/06/duke.aspx">Duke School of Law breach affects 3,200</source>
    </item>
  </channel>
</rss>
