<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: matthew]]></title>
    <link>http://securityratty.com/tag/matthew</link>
    <description></description>
    <pubDate>Thu, 10 Jan 2008 09:50:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Waukesha County job applicant data exposed in mailing]]></title>
      <link>http://securityratty.com/article/6efea251f53508bced1039830009ef31</link>
      <guid>http://securityratty.com/article/6efea251f53508bced1039830009ef31</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/13/08

Organization
Waukesha County, Wisconsin

Contractor/Consultant/Branch
Crivello Carlson, S.C

Victims
Job applicants from the year 2006

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/waukesha.jpg" width="149" align="right" height="200"><font size="2"><b>Date Reported: </b><br>7/13/08<br><br><b>Organization: </b><br><a href="http://www.waukeshacounty.gov/">Waukesha County, Wisconsin</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.milwlaw.com/index.aspx">Crivello Carlson, S.C.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Job applicants from the year 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 130"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Job applications including, names, addresses, job and education history, salary, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"More than 130 people who applied for a job with Waukesha County in 2006 had their Social Security numbers, employment and salary information, addresses and phone numbers and other personal information released to one of the women who applied for the job. "<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.jsonline.com/story/index.aspx?id=772046">Milwaukee Journal Sentinel</a> <br><a href="http://www.newrichmond-news.com/articles/index.cfm?id=87905&amp;section=Wisconsin%20News&amp;property_id=19">New Richmond News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Raquel Rutledge, Milwaukee Journal Sentinel<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Taunya Thomas was horrified when she got a call from a stranger who knew almost everything about her.<br><br>The woman on the phone told Thomas she knew her Social Security number, where she lived and worked, how much money she made and where she went to high school and college. She rattled them off, not missing a single digit or fact.<br><br>She promised she wasn't going to use the information.<br><span style="font-style: italic;">[Evan] Yeah.&nbsp; The government body that exposed the information made the promise that "your Social Security number will remain confidential".&nbsp; So much for promises</span>.<br><br>She was calling, she said, because she wanted Thomas and others to know where she had gotten it.<br><br>She hadn't stolen it. <br><br>Waukesha County sent it to her in the mail, along with the same personal information for more than 130 other people who had all applied for a job with the county in 2006.<br><span style="font-style: italic;">[Evan] What's with Wisconsin and mailing confidential information (in error)?&nbsp; This is the third mailing error reported on The Breach Blog coming out of Wisconsin this year.</span><br><br>The woman on the phone, Bernadine Matthews, too had applied for the position as an economic support specialist.<br><br><img src="http://images.quickblogcast.com/95781-88451/matthews.jpg" width="324" border="0"><br><font size="1">This is Matthews displayed holding the applications.&nbsp; Source: Milwaukee Journal Sentinel</font><br><br>When she didn't get it, she filed a complaint with the Equal Employment Opportunity Commission.<br><br>As part of the complaint and the investigation, the EEOC requested copies of all the applications.<br><br>The law firm representing the county, Crivello Carlson, sent the applications to Matthews.<br><span style="font-style: italic;">[Evan] Really?&nbsp; Any second thoughts about the fact that this may put innocent people at risk?</span><br><br>Waukesha County tried to reclaim the documents sent to Matthews, threatening to get a search warrant and send a lawyer to her house, Matthews said.<br><br>When Matthews refused, they insisted she bring the documents to the law firm so they could white-out the private information in the applications.<br><br>Again, Matthews refused.<br><span style="font-style: italic;">[Evan] At what point does Matthews cross a line.&nbsp; The confidential information on those job applications does NOT belong to her.&nbsp; In my opinion, she has no right to maintain possession of the information.&nbsp; For Matthews to knowingly maintain information that does not belong to her almost seems criminal to me.</span><br><br>The applications would be critical to her discrimination suit, she thought.<br><span style="font-style: italic;">[Evan] So risk the disclosure of senstive information belonging to 130 people for your own benefit?&nbsp; If not criminal, it is certainly selfish.</span><br><br>She quickly hired an attorney, copied the documents and sent a set back to the county. She keeps her copies in an oversize safe-deposit box at her bank, she said.<br><span style="font-style: italic;">[Evan] Who authorized her to make copies?&nbsp; The data owners (victims) certainly did not.</span><br><br>"I'm not going to be like the county," Matthews said. "I'm going to protect the privacy of the information in this box. Obviously they didn't give a darn about the applicants' privacy."<br><br>The Waukesha County employment application specifically states it will protect Social Security numbers.<br><br>"Your Social Security Number will remain confidential and will not be copied or released but is required for applicant tracking purposes," the application reads.<br><br><a href="http://www.milwlaw.com/ourpeople/profile.aspx?id=285&amp;name=Raymond%20J.%20Pollen">Ray Pollen</a>, an attorney with Crivello Carlson, at first said it was no mistake that Matthews received the uncensored applications.<br><span style="font-style: italic;">[Evan] So Mr. Pollen sent the information on purpose.&nbsp; Did he stop to think that there might be a problem here?&nbsp; Did it occur to anyone that they should redact the most sensitive information such as Social Security numbers, or names?</span><br><br>He said it was required under federal law that all parties in an EEOC discrimination complaint receive copies of information requested by the agency investigating. He couldn't point to the specific provision.<br><span style="font-style: italic;">[Evan] Does a specific provision exist?&nbsp; I cannot think of a single purpose that a Social Security number would serve in this case.</span><br><br>Several days later, Pollen said the EEOC had no such requirement.<br><br>"The EEOC is silent on the issue," he said.<br><br>Instead it's the state's Equal Rights Division that requires all parties be copied on information requested by the division but even that provision doesn't mandate that attachments - such as the applications - be included. And, Matthew's case was not filed with the state.<br><br>"We followed the state's protocol," Pollen said.<br><br>P.I. asked: So anyone who applies for a job with Waukesha County could have their private information disclosed to a non-governmental third-party?<br>&nbsp;<br>Pollen answered: "We responded to a federal agency's request for information. . . . In my opinion there was no violation of any law or procedure."<br><span style="font-style: italic;">[Evan] Let's give Mr. Pollen the benefit of the doubt.&nbsp; Let's say that there was no violation of any law or procedure here.&nbsp; There certainly seems to be a violation of trust, a violation of good judgment, and a violation of privacy.&nbsp; The "if the law don't state it, then I must be able to do it" mentality is one of the reasons we have so many laws.&nbsp; Maybe if we used a little more common sense.</span><br><br>Taunya Thomas called the release of her information to a stranger shocking. She said at a minimum the county should have notified her that her information had been compromised.<br><br>"I'm devastated that it's that easy for my information to be disclosed," she said. "For someone to call me and tell me where I worked, where I went to school, recite my Social Security number verbatim to me, that's scary."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very frustrating breach to read about.&nbsp; It is frustrating when someone knowingly discloses confidential information and then tries to justify it.&nbsp; Equally frustrating is when a person that has no right to the information refuses to part with it.&nbsp; In the middle of all of this are 130 innocent people.<br><br>I do not claim to know half as much about the law as Mr. Pollen does.&nbsp; His actions may be well within his legal rights for all I know. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/waukesha.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 04:07:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/waukesha county">waukesha county</category>
      <category domain="http://securityratty.com/tag/senstive information">senstive information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/salary information">salary information</category>
      <source url="http://breachblog.com/2008/07/15/waukesha.aspx">Waukesha County job applicant data exposed in mailing</source>
    </item>
    <item>
      <title><![CDATA[Hacker gets 41 months for running rogue botnet]]></title>
      <link>http://securityratty.com/article/6ff9b014360421e804b0a6f2a21997d7</link>
      <guid>http://securityratty.com/article/6ff9b014360421e804b0a6f2a21997d7</guid>
      <description><![CDATA[Robert Matthew Bentley of Florida must also pay $65,000 in restitution for installing a botnet on Newell Rubbermaid's corporate...]]></description>
      <content:encoded><![CDATA[Robert Matthew Bentley of Florida must also pay $65,000 in restitution for installing a botnet on Newell Rubbermaid's corporate network.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=89zHKf"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=89zHKf" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/310490135" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/robert matthew bentley">robert matthew bentley</category>
      <category domain="http://securityratty.com/tag/newell rubbermaid">newell rubbermaid</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/restitution">restitution</category>
      <category domain="http://securityratty.com/tag/florida">florida</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/310490135/article.do">Hacker gets 41 months for running rogue botnet</source>
    </item>
    <item>
      <title><![CDATA[San Quentin visitor and volunteer information lost]]></title>
      <link>http://securityratty.com/article/dbf873f6918086b574c9b46d905b6061</link>
      <guid>http://securityratty.com/article/dbf873f6918086b574c9b46d905b6061</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/29/08

Organization
State of California

Contractor/Consultant/Branch
Department of Corrections and Rehabilitation
San Quentin State Prison

Victims...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/caldoc.jpg" align="right" height="162" width="162"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.ca.gov/">State of California</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.cdcr.ca.gov/index.html">Department of Corrections and Rehabilitation</a> <br><a href="http://www.cdcr.ca.gov/Visitors/Facilities/SQ.html">San Quentin State Prison</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Volunteers and visitors<br><br><span style="font-weight: bold;">Number Affected:</span><br>3,500+<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, birth dates and driver's license numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A flash memory drive containing names, birth dates and driver's license numbers of more than 3,500 people who either volunteered or visited San Quentin State Prison in a group tour has been lost, a prison official said Friday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/03/29/BA4KVSJ9O.DTL">The San Francisco Chronicle</a> <br><a href="http://www.kcbs.com/Personal-Information-of-Prison-Visitors-Missing/1909845">KCBS 740 AM News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Matthew Yi, The San Francisco Chronicle<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A flash memory drive containing names, birth dates and driver's license numbers of more than 3,500 people who either volunteered or visited San Quentin State Prison in a group tour has been lost, a prison official said Friday.<br><br>The flash drive was used to move the data each evening from the prison's administrative office near the parking lot to computers at the two entrance gates to the facility to allow guards to identify volunteers or groups, such as college students, that tour the prison, said Samuel Robinson, a San Quentin spokesman.<br><span style="font-style: italic;">[Evan] Huh?&nbsp; How about a network employing encryption?&nbsp; They have this new technology called WPA2 (</span><a style="font-style: italic;" href="http://www.wi-fi.org/knowledge_center/wpa2">Wi-Fi Protected Access 2</a><span style="font-style: italic;">).&nbsp; It would be much more efficient, secure and cost effective to network this securely.</span><br><br>"What happens is that we have to transport that information out to individual areas where we let people through" onto prison grounds, he said. "It's our security measure to walk the flash drive."<br><br>The flash drive did not contain Social Security numbers, but the personal information on visitors was not encrypted, he said, adding that the prison has since decided to encrypt the data.<br><span style="font-style: italic;">[Evan] It's too bad that it took a breach before prison officials noticed the risk of carrying confidential information on unencrypted mobile devices.&nbsp; Going forward this is a good decision by the prison, but this is what we call "reactive security".</span><br><br>Prison officials have not received any reports of identify theft tied to this incident<br><br>Sen. Gloria Romero, D-Los Angeles, chairwoman of the Senate Public Safety Committee, criticized the Corrections Department for losing such sensitive information, and said she will call prisons secretary James Tilton to address the issue.<br><br>"This is how cavalier the Corrections Department can be with private information," she said. "There has been a breach of security."<br><br>The unit was discovered missing March 4 and a preliminary investigation shows that it was last used on March 3, Robinson said. It's yet unclear how the flash drive was lost or if it may be somewhere on prison grounds, he said. There is no indication that the flash drive was stolen for malicious reasons, such as identity theft<br><br>Prison officials recently sent out letters alerting the individuals whose information is believed to be on the flash drive.<br><br>Anyone who has visited San Quentin and is concerned their personal information could be on the flash drive may call Sgt. Rudy Luna, administrative assistant, at (415) 455-5000 or Laura Bowman, community partnership manager, at (415) 454-1460, extension 5400.<br><br><span style="font-weight: bold;">Commentary:</span><br>Thankfully, the flash drive did not contain Social Security numbers.&nbsp; Can names, addresses and driver's license numbers be used for identity theft, directly?<br><br>Carrying confidential information on mobile devices is risky.&nbsp; Not encrypting it is reckless.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font>
<br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/31/caldoc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 31 Mar 2008 07:14:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prison official">prison official</category>
      <category domain="http://securityratty.com/tag/prison">prison</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/prison officials">prison officials</category>
      <category domain="http://securityratty.com/tag/san quentin">san quentin</category>
      <category domain="http://securityratty.com/tag/prison officials recently">prison officials recently</category>
      <category domain="http://securityratty.com/tag/flash drive">flash drive</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://breachblog.com/2008/03/31/caldoc.aspx">San Quentin visitor and volunteer information lost</source>
    </item>
    <item>
      <title><![CDATA[NSM-Console and HeX update]]></title>
      <link>http://securityratty.com/article/23ca43a9d7f75783982ad6ad9ad47b34</link>
      <guid>http://securityratty.com/article/23ca43a9d7f75783982ad6ad9ad47b34</guid>
      <description><![CDATA[While researching the HeX System for the pending February toolsmith , I was extremely pleased to discover NSM-Console , from Matthew Lee Hinman. I've not yet seen such an efficient, useful, all...]]></description>
      <content:encoded><![CDATA[While researching the <a href="http://www.rawpacket.org/projects/hex">HeX System</a> for the pending February <span style="font-style:italic;">toolsmith</span>, I was extremely pleased to discover <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a>, from Matthew Lee Hinman. I've not yet seen such an efficient, useful, all encompassing framework for offline packet analysis. NSM-Console includes modules for:<br /># aimsnarf<br /># ngrep (gif/jpg/pdf/exe/pe/ne/elf/3pg/torrent)<br /># tcpxtract<br /># tcpflow<br /># chaosreader<br /># bro-IDS<br /># snort<br /># tcpdstat<br /># capinfos<br /># tshark<br /># argus<br /># ragator<br /># racount<br /># rahosts<br /># hash (md5 & sha256)<br /># ra<br /># honeysnap<br /># p0f<br /># pads<br /># fl0p<br /># iploc<br />Consider giving both <a href="http://www.rawpacket.org/projects/hex">HeX System</a> and the included <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a> an immediate look.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html&title=NSM-Console%20and HeX%20update" title="NSM-Console and HeX update del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="NSM-Console and HeX update at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html" title="NSM-Console and HeX update "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg NSM-Console and HeX update "></a>]]></content:encoded>
      <pubDate>Thu, 10 Jan 2008 09:50:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nsm-console">nsm-console</category>
      <category domain="http://securityratty.com/tag/nsm-console includes modules">nsm-console includes modules</category>
      <category domain="http://securityratty.com/tag/hex system">hex system</category>
      <category domain="http://securityratty.com/tag/matthew lee hinman">matthew lee hinman</category>
      <category domain="http://securityratty.com/tag/discover nsm-console">discover nsm-console</category>
      <category domain="http://securityratty.com/tag/offline packet analysis">offline packet analysis</category>
      <category domain="http://securityratty.com/tag/february toolsmith">february toolsmith</category>
      <category domain="http://securityratty.com/tag/tcpflow">tcpflow</category>
      <category domain="http://securityratty.com/tag/ngrep">ngrep</category>
      <source url="http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html">NSM-Console and HeX update</source>
    </item>
  </channel>
</rss>
