<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: firefighters]]></title>
    <link>http://securityratty.com/tag/firefighters</link>
    <description></description>
    <pubDate>Mon, 17 Mar 2008 07:27:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Apple on Fire!]]></title>
      <link>http://securityratty.com/article/691fddaa0bedb949ad12d80f6e1b5b0d</link>
      <guid>http://securityratty.com/article/691fddaa0bedb949ad12d80f6e1b5b0d</guid>
      <description><![CDATA[Its not just sales burning in Apples pockets one of the Apple buildings in Cupertino caught fire today and burned for 3 hours before being extinguished there was considerable damage
The incident...]]></description>
      <content:encoded><![CDATA[<p>It&#8217;s not just sales burning in Apple&#8217;s pockets &#8212; one of the <a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=210003601">Apple buildings</a> in Cupertino caught fire today and burned for 3 hours before being extinguished &#8212; there was considerable damage. </p>
<blockquote><p>The incident appeared to be connected to a construction crew working in the area where the blaze started, Darron Pisciotta, captain of operations for the Santa Clara County Fire Department, told InformationWeek. The work crew was the first to report the fire. More than 60 firefighters responded to the alarms.</p></blockquote>
<p>I have a friend who&#8217;s been contracting down there, so glad to hear that no one was hurt!<br />
I hope this doesn&#8217;t set development on the iTablet back;) </p>
<p>Hey, if you have construction workers in your area, tell them to be careful, okay?</p>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 10:45:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fire">fire</category>
      <category domain="http://securityratty.com/tag/crew">crew</category>
      <category domain="http://securityratty.com/tag/construction crew">construction crew</category>
      <category domain="http://securityratty.com/tag/considerable damage">considerable damage</category>
      <category domain="http://securityratty.com/tag/apples pockets">apples pockets</category>
      <category domain="http://securityratty.com/tag/set development">set development</category>
      <category domain="http://securityratty.com/tag/apple buildings">apple buildings</category>
      <category domain="http://securityratty.com/tag/construction workers">construction workers</category>
      <category domain="http://securityratty.com/tag/darron pisciotta">darron pisciotta</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/364276548/">Apple on Fire!</source>
    </item>
    <item>
      <title><![CDATA[City of Minneola firefighters exposed on web]]></title>
      <link>http://securityratty.com/article/bbdbaf1cacadf9db3887337e699a9799</link>
      <guid>http://securityratty.com/article/bbdbaf1cacadf9db3887337e699a9799</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/16/08

Organization
City of Minneola (FL

Contractor/Consultant/Branch
None

Victims
City firefighters

Number Affected
10

Types of Data
names,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/minneola.jpg" align="right" height="76" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/16/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.minneola.us/">City of Minneola (FL)</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>City firefighters<br><br><span style="font-weight: bold;">Number Affected:</span><br>10<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses, phone numbers and social security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The city of Minneola is being accused of violating federal, state and local laws. A union representative said several firefighters' personal information was posted on the city's web site for more than three days."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.cfnews13.com/News/Local/2008/3/16/firefighters_personal_information_published_on_citys_web_site.html?refresh=1">Central Florida News 13</a> <br><a href="http://www.wftv.com/news/15616068/detail.html">WFTV Channel 9 News</a> <br><a href="http://www.myfoxorlando.com/myfox/pages/News/Detail?contentId=6048929&amp;version=2&amp;locale=EN-US&amp;layoutCode=TSTY&amp;pageId=3.2.1">my FOX Orlando</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Central Florida News 13<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The city of Minneola is being accused of violating federal, state and local laws. A union representative said several firefighters' personal information was posted on the city's web site for more than three days.<br><br>The Mayor of the Minneola says the personal addresses, phone numbers and Social Security numbers of ten firefighters were unknowingly made public after they were published on the city's website late last week.<br><span style="font-style: italic;">[Evan] Although this breach only affects 10 individuals, it should not be minimized or considered insignificant.&nbsp; One is too many.</span><br style="font-style: italic;"><br>The city clerk accidentally published the information.<br><span style="font-style: italic;">[Evan] We just discussed a breach concerning a county clerk last week in the "</span><a style="font-style: italic;" href="http://breachblog.com/2008/03/13/oklahomacty.aspx">Oklahoma County Social Security numbers online</a><span style="font-style: italic;">" article.&nbsp; Now we have a city clerk error.&nbsp; Clerks have to be able to balance the need to disclose public information while ensuring that the private information stays confidential.&nbsp; No easy task and not a task to be taken lightly.</span><br style="font-style: italic;"><br>The city clerk was updating the agenda for this week's city council meeting where the city will vote on recognizing the new union.<br><br>"The city clerk in this case, she does hundreds of thousands of pieces of document. This one slipped by. It's nothing intentional. We apologize," said Minneola Mayor David Yeager.<br><br>"A man called one of our firefighters. The firefighter called the Chief who called the City Manager. The City Manager called myself and advised us that this was on the website and that it was not allowed to be on the website," said Minneola Mayor David Yeager.<br><br>The data was taken from applications that the firefighers had submitted to the city for union recognition.<br><br>According to Mayor Yeager, those applications were accidentally scanned by a city clerk and published by personnel in the IT (Information Technology) Department.<br><span style="font-style: italic;">[Evan] It would be a good idea to have a quick information security review of information posted to the web site before it is published.&nbsp; I understand how human error just happens, but I think a second review by trained eyes could go a long way towards preventing similar circumstances in the future.</span><br style="font-style: italic;"><br>"The Privacy of Information Act was breached. There is not a counter, that we know of, as far as how many hits are on that website. As far as how many people got access to that or what type of people got access to that, we don't know," said a firefighter union spokesman, Joe Garbaravage.<br><span style="font-style: italic;">[Evan] There is on most web servers.&nbsp; Almost all web servers log access attempts.&nbsp; It may be possible that logging were not enabled (bad practice).</span><br style="font-style: italic;"><br>"I'm not sure how many people actively search the website," said Minneola firefighter Bradley Mattingly, responding to whether or not he was concerned about his personal information getting into criminal hands. "But there's also the unknown," he added.<br><br>Some firefighters said they're satisfied with the city's quick response to fix the problem, but sources told Eyewitness News that other firefighters feel like the incident is retaliation.<br><span style="font-style: italic;">[Evan] Interesting.&nbsp; Purposeful personal information disclosure as a weapon.&nbsp; I doubt that this is the case with this breach, but an interesting angle that I hadn't really given much thought to.</span><br style="font-style: italic;"><br>The mayor said no one will be reprimanded since the mistake was a case of human error. The city also said it will give firefighters one free year of a credit monitoring service.<br><br><span style="font-weight: bold;">Commentary:</span><br>Given the two breaches attributed to clerks (one county and one city) in the past week, it is obvious that they hold a very important role in keeping personal information private.&nbsp; How many clerks would you guess receive formal information security training?&nbsp; Do you suppose that only one person is responsible for all of the information management including the determination of what should be public and what should be private?&nbsp; This seems like a heckuva lot of responsibility for one person.<br><br>My thoughts are mixed on the "disclosure as a weapon" concept.&nbsp; Could happen, but probably not very likely.&nbsp; Other causes of disclosure are much more probable. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/17/minneola.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 17 Mar 2008 07:27:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/city">city</category>
      <category domain="http://securityratty.com/tag/city clerk error">city clerk error</category>
      <category domain="http://securityratty.com/tag/city clerk">city clerk</category>
      <category domain="http://securityratty.com/tag/city firefighters">city firefighters</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/firefighters">firefighters</category>
      <category domain="http://securityratty.com/tag/city council">city council</category>
      <category domain="http://securityratty.com/tag/information act">information act</category>
      <source url="http://breachblog.com/2008/03/17/minneola.aspx">City of Minneola firefighters exposed on web</source>
    </item>
  </channel>
</rss>
