<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rudy]]></title>
    <link>http://securityratty.com/tag/rudy</link>
    <description></description>
    <pubDate>Wed, 16 Jan 2008 11:17:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[San Quentin visitor and volunteer information lost]]></title>
      <link>http://securityratty.com/article/dbf873f6918086b574c9b46d905b6061</link>
      <guid>http://securityratty.com/article/dbf873f6918086b574c9b46d905b6061</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/29/08

Organization
State of California

Contractor/Consultant/Branch
Department of Corrections and Rehabilitation
San Quentin State Prison

Victims...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/caldoc.jpg" align="right" height="162" width="162"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.ca.gov/">State of California</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.cdcr.ca.gov/index.html">Department of Corrections and Rehabilitation</a> <br><a href="http://www.cdcr.ca.gov/Visitors/Facilities/SQ.html">San Quentin State Prison</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Volunteers and visitors<br><br><span style="font-weight: bold;">Number Affected:</span><br>3,500+<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, birth dates and driver's license numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A flash memory drive containing names, birth dates and driver's license numbers of more than 3,500 people who either volunteered or visited San Quentin State Prison in a group tour has been lost, a prison official said Friday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/03/29/BA4KVSJ9O.DTL">The San Francisco Chronicle</a> <br><a href="http://www.kcbs.com/Personal-Information-of-Prison-Visitors-Missing/1909845">KCBS 740 AM News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Matthew Yi, The San Francisco Chronicle<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A flash memory drive containing names, birth dates and driver's license numbers of more than 3,500 people who either volunteered or visited San Quentin State Prison in a group tour has been lost, a prison official said Friday.<br><br>The flash drive was used to move the data each evening from the prison's administrative office near the parking lot to computers at the two entrance gates to the facility to allow guards to identify volunteers or groups, such as college students, that tour the prison, said Samuel Robinson, a San Quentin spokesman.<br><span style="font-style: italic;">[Evan] Huh?&nbsp; How about a network employing encryption?&nbsp; They have this new technology called WPA2 (</span><a style="font-style: italic;" href="http://www.wi-fi.org/knowledge_center/wpa2">Wi-Fi Protected Access 2</a><span style="font-style: italic;">).&nbsp; It would be much more efficient, secure and cost effective to network this securely.</span><br><br>"What happens is that we have to transport that information out to individual areas where we let people through" onto prison grounds, he said. "It's our security measure to walk the flash drive."<br><br>The flash drive did not contain Social Security numbers, but the personal information on visitors was not encrypted, he said, adding that the prison has since decided to encrypt the data.<br><span style="font-style: italic;">[Evan] It's too bad that it took a breach before prison officials noticed the risk of carrying confidential information on unencrypted mobile devices.&nbsp; Going forward this is a good decision by the prison, but this is what we call "reactive security".</span><br><br>Prison officials have not received any reports of identify theft tied to this incident<br><br>Sen. Gloria Romero, D-Los Angeles, chairwoman of the Senate Public Safety Committee, criticized the Corrections Department for losing such sensitive information, and said she will call prisons secretary James Tilton to address the issue.<br><br>"This is how cavalier the Corrections Department can be with private information," she said. "There has been a breach of security."<br><br>The unit was discovered missing March 4 and a preliminary investigation shows that it was last used on March 3, Robinson said. It's yet unclear how the flash drive was lost or if it may be somewhere on prison grounds, he said. There is no indication that the flash drive was stolen for malicious reasons, such as identity theft<br><br>Prison officials recently sent out letters alerting the individuals whose information is believed to be on the flash drive.<br><br>Anyone who has visited San Quentin and is concerned their personal information could be on the flash drive may call Sgt. Rudy Luna, administrative assistant, at (415) 455-5000 or Laura Bowman, community partnership manager, at (415) 454-1460, extension 5400.<br><br><span style="font-weight: bold;">Commentary:</span><br>Thankfully, the flash drive did not contain Social Security numbers.&nbsp; Can names, addresses and driver's license numbers be used for identity theft, directly?<br><br>Carrying confidential information on mobile devices is risky.&nbsp; Not encrypting it is reckless.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font>
<br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/31/caldoc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 31 Mar 2008 07:14:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prison official">prison official</category>
      <category domain="http://securityratty.com/tag/prison">prison</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/prison officials">prison officials</category>
      <category domain="http://securityratty.com/tag/san quentin">san quentin</category>
      <category domain="http://securityratty.com/tag/prison officials recently">prison officials recently</category>
      <category domain="http://securityratty.com/tag/flash drive">flash drive</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://breachblog.com/2008/03/31/caldoc.aspx">San Quentin visitor and volunteer information lost</source>
    </item>
    <item>
      <title><![CDATA[Rudy Giuliani on Terrorism Security]]></title>
      <link>http://securityratty.com/article/6951ab85725267ca6a3c580fb3ee57c0</link>
      <guid>http://securityratty.com/article/6951ab85725267ca6a3c580fb3ee57c0</guid>
      <description><![CDATA[A longish article by Rudy Giuliani on his philosophy to secure the nation from terrorism. I may write a long blog post on the article after I read it, but I wanted to post the link as soon as I saw...]]></description>
      <content:encoded><![CDATA[<p>A <a href="http://www.city-journal.org/2008/18_1_homeland_security.html">longish article</a> by Rudy Giuliani on his philosophy to secure the nation from terrorism.  I may write a long blog post on the article after I read it, but I wanted to post the link as soon as I saw it. </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qVHOK1D"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qVHOK1D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=kNedTSD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=kNedTSD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=woVOYcD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=woVOYcD" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 16 Jan 2008 11:17:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rudy giuliani">rudy giuliani</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/longish article">longish article</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <category domain="http://securityratty.com/tag/philosophy">philosophy</category>
      <source url="http://www.schneier.com/blog/archives/2008/01/rudy_giuliani_o.html">Rudy Giuliani on Terrorism Security</source>
    </item>
  </channel>
</rss>
