<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sensitive]]></title>
    <link>http://securityratty.com/tag/sensitive</link>
    <description></description>
    <pubDate>Thu, 26 Jun 2008 11:36:44 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Daily Mail publisher admits to stolen laptop]]></title>
      <link>http://securityratty.com/article/9af68c57ed3f10d814be79e5d395b72b</link>
      <guid>http://securityratty.com/article/9af68c57ed3f10d814be79e5d395b72b</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/4/08

Organization
Daily Mail and General Trust plc

Contractor/Consultant/Branch
Northcliffe Media
Associated Newspapers Ltd

Victims
Staff, suppliers...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dailymail.jpg" width="203" align="right" height="43"><font size="2"><b>Date Reported: </b><br>7/4/08<br><br><b>Organization: </b><br><a href="http://www.dmgt.co.uk/">Daily Mail and General Trust plc</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.thisisnorthcliffe.co.uk/">Northcliffe Media</a> <br><a href="http://www.associatednewspapers.com/">Associated Newspapers Ltd</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Staff, suppliers and contributors<br><br><span style="font-weight: bold;">Number Affected:</span><br>"thousands"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, bank account number and bank sort code"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Daily Mail publisher Associated Newspapers has admitted that a laptop containing financial and personal details of thousands of staff, suppliers and contributors has been stolen."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.computerworlduk.com/management/security/data-control/news/index.cfm?newsid=9904">ComputerWorldUK</a> <br><a href="http://www.guardian.co.uk/media/2008/jul/04/dailymail.dmgt1?gusrc=rss&amp;feed=media">Guardian News (UK)</a> <br><a href="http://www.guardian.co.uk/media/2008/jul/04/dailymail.dmgt?gusrc=rss&amp;feed=media">Guardian News (UK) additional info</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Guardian Newspaper<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Daily Mail publisher Associated Newspapers has admitted that a laptop containing financial and personal details of thousands of staff, suppliers and contributors has been stolen.<br><br>A Daily Mail &amp; General Trust spokeswoman said: "DMGT confirms that a laptop company computer containing certain confidential information was stolen last week.<br><br>After months of criticising "criminally careless" government departments for losing confidential records, the company has been forced to send out an embarrassing letter telling journalists they may now be at risk of identity theft<br><span style="font-style: italic;">[Evan] This is the same Daily Mail managed by Associated Newspapers that according to The Guardian "has been at the forefront of coverage of the recent bank and government department missing data scandals".&nbsp; It would be very difficult for Associated Newspapers to claim that they didn't know any better than to store confidential information on a poorly protected laptop.</span><br><br>Details such as names, addresses, bank account numbers and sort codes were on the laptop<br><br>the laptop was "password protected" but tell recipients to contact their banks and also "consult the government website ... for advice on avoiding or dealing with identity theft"<br><span style="font-style: italic;">[Evan] The mention of password protection is nothing more than an effort to minimize the effect of the breach.&nbsp; It does very little (if anything) to protect the personal information.</span><br><br>In a letter to those who details were affected, Simon Dyson, finance director at Daily Mail publisher Associated Newspapers, and Martyn Hindley, his counterpart at sister company Northcliffe, said it was likely that the details had been erased by the thief.<br><span style="font-style: italic;">[Evan] How is the conclusion drawn?&nbsp; I don't see how there could be enough information to determine what the thief was likely to do.</span><br><br>From the letter to affected persons from the Associated Newspapers group finance director, Simon Dyson, and his Northcliffe counterpart, Martyn Hindley:<br><br>"Unfortunately one of the company's laptops has been stolen."<br><br>"The contents included personal data, some of which related to you."<br><br>"The laptop was password-protected. "<br><span style="font-style: italic;">[Evan] So what?&nbsp; This won't adequately protect the information on the laptop, so why mention it?</span><br><br>"We are writing to you as quickly as possible to alert you to the fact that the theft has happened and to inform you of the data types lost, so that you can take appropriate action."<br><span style="font-style: italic;">[Evan] I guess we should give some credit for the quick notification, if nothing else.</span><br><br>"In your case, your name, address, bank account number and bank sort code were the sensitive information lost."<br><br>"The likelihood is that this theft was carried out in an opportunistic manner by a thief who will not realise that there is any personal data on the laptop and who may just erase what is on the hard disk in order to disguise the fact that the laptop is stolen."<br><span style="font-style: italic;">[Evan] This is nothing more than speculation.&nbsp; I can't imagine that there are any specific facts for which this conclusion is based on.</span><br><br>"We have, of course, notified the police of the theft of the laptop and are talking to the Office of the Information Commissioner about what has happened."<br><br>"On behalf of the company, I would like to offer my sincere apologies for any annoyance and inconvenience to you that this breach of security may cause."<br><br>"I can assure you that we take security of personal data very seriously and have, since this incident, which was inadvertently caused by a technical issue, already further strengthened procedures."<br><span style="font-style: italic;">[Evan] This breach was caused by a "technical issue"?&nbsp; Like what?&nbsp; I presume that the technical aspects surrounding this breach were working exactly as they were designed to in the manner of which that they were implemented.&nbsp; Without further elaboration, "strengthened procedures" is subjective and means little.&nbsp; Organizations should offer details, instead of general statements in order to bolster some sense of confidence.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>This breach must be embarrassing for Associated Newspapers.&nbsp; A breach like this should be embarrassing for any organizations.&nbsp; Unencrypted lost of stolen laptops storing personal (or other confidential) information is a pretty well-known risk nowadays.&nbsp; An unacceptable risk for most. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/05/dailymail.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 05 Jul 2008 08:55:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/daily mail publisher">daily mail publisher</category>
      <category domain="http://securityratty.com/tag/daily mail">daily mail</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/laptop company computer">laptop company computer</category>
      <source url="http://breachblog.com/2008/07/05/dailymail.aspx">Daily Mail publisher admits to stolen laptop</source>
    </item>
    <item>
      <title><![CDATA[Google Open Sources Web Assessment Tool]]></title>
      <link>http://securityratty.com/article/128129d00191a851fc7c17a3ec3f9529</link>
      <guid>http://securityratty.com/article/128129d00191a851fc7c17a3ec3f9529</guid>
      <description><![CDATA[The folks at Google have released their own proprietary web application assessment proxy. The tool is called ratproxy and was authored by Michal Zalewski
From Google Code
Ratproxy is a semi-automated,...]]></description>
      <content:encoded><![CDATA[<p>The folks at Google have released their own proprietary web application assessment proxy. The tool is called ratproxy and was authored by <a href="http://lcamtuf.coredump.cx/">Michal Zalewski</a>.</p>
<p>From Google Code:</p>
<blockquote><p>Ratproxy is a semi-automated, largely passive web application security audit tool. It is meant to complement active crawlers and manual proxies more commonly used for this task, and is optimized specifically for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments.</p></blockquote>
<p>This tool falls into the same family as Burp and Paros, as examples. It will apparently run on Linux, FreeBSD, Mac OS X and Windows if you have Cygwin loaded. Check it out. </p>
<p><a href="http://code.google.com/p/ratproxy/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=NkvSmj"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=NkvSmj" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=El0TEJ"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=El0TEJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=MdpCej"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=MdpCej" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=G6TZLj"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=G6TZLj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=ESE22j"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=ESE22j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=ac9LIj"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=ac9LIj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/324867361" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 08:51:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/tool falls">tool falls</category>
      <category domain="http://securityratty.com/tag/complement active crawlers">complement active crawlers</category>
      <category domain="http://securityratty.com/tag/design patterns based">design patterns based</category>
      <category domain="http://securityratty.com/tag/google code">google code</category>
      <category domain="http://securityratty.com/tag/ratproxy">ratproxy</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/michal zalewski">michal zalewski</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/324867361/">Google Open Sources Web Assessment Tool</source>
    </item>
    <item>
      <title><![CDATA[2% of all laptops sold every year are stolen from airports?]]></title>
      <link>http://securityratty.com/article/1ab2ef6a1d22f817746241dedb95ce77</link>
      <guid>http://securityratty.com/article/1ab2ef6a1d22f817746241dedb95ce77</guid>
      <description><![CDATA[Interesting analogy from NetworkWorld on rising rates of laptop loss , but it works! Apparently laptop loss is giving IHOP a run for its money. From the article

Some of the largest and medium-sized...]]></description>
      <content:encoded><![CDATA[Interesting analogy from <a href="http://www.networkworld.com/news/2008/063008-laptops-lost-like-hot-cakes.html?t51hb">NetworkWorld on rising rates of laptop loss</a>, but it works! Apparently laptop loss is giving IHOP a run for its money. From the article...<br /><br /><span style="font-style: italic;">"Some of the largest and medium-sized U.S. airports report close to 637,000 laptops lost each year, according to the Ponemon    Institute survey released Monday. Laptops are most commonly lost at security checkpoints, according to the survey."</span><br /><br />Over 630K laptops lost each year <span style="font-weight: bold; font-style: italic;">just </span>within airports! From <a href="http://www.idc.com/getdoc.jsp?containerId=prUS20995107">IDC's Quarterly PC tracker</a> (Dec 2007) we see that over 31M laptops were projected to be sold in 2007. This means that over 2% of all laptops sold in the US were lost or stolen from airports!<br /><br />Hard to believe. Am I exaggerating or is this for real? Makes me think about how cold boot can be a weapon of choice for criminals to gain access to sensitive data.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=nv6OGJ"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=nv6OGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=SEPc1j"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=SEPc1j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=gkQ7qJ"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=gkQ7qJ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/324203872" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 12:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/630k laptops lost">630k laptops lost</category>
      <category domain="http://securityratty.com/tag/laptops lost">laptops lost</category>
      <category domain="http://securityratty.com/tag/airports">airports</category>
      <category domain="http://securityratty.com/tag/lost">lost</category>
      <category domain="http://securityratty.com/tag/laptop loss">laptop loss</category>
      <category domain="http://securityratty.com/tag/apparently laptop loss">apparently laptop loss</category>
      <category domain="http://securityratty.com/tag/airports report close">airports report close</category>
      <category domain="http://securityratty.com/tag/31m laptops">31m laptops</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/324203872/2-of-all-laptops-sold-every-year-are.html">2% of all laptops sold every year are stolen from airports?</source>
    </item>
    <item>
      <title><![CDATA[Start-up nexTier debuts data-leak prevention appliance]]></title>
      <link>http://securityratty.com/article/dffb7196ef4b1f548710d3f72c6d92d1</link>
      <guid>http://securityratty.com/article/dffb7196ef4b1f548710d3f72c6d92d1</guid>
      <description><![CDATA[Data-leak prevention gains another market entry with the debut of start-up nexTier Networks, which is touting a DLP appliance that monitors and blocks sensitive and unauthorized transmissions and...]]></description>
      <content:encoded><![CDATA[Data-leak prevention gains another market entry with the debut of start-up nexTier Networks, which is touting a DLP appliance that monitors and blocks sensitive and unauthorized transmissions and learns by crawling the enterprise network to read for information content where data is stored.]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data-leak prevention gains">data-leak prevention gains</category>
      <category domain="http://securityratty.com/tag/start-up nextier networks">start-up nextier networks</category>
      <category domain="http://securityratty.com/tag/information content">information content</category>
      <category domain="http://securityratty.com/tag/enterprise network">enterprise network</category>
      <category domain="http://securityratty.com/tag/dlp appliance">dlp appliance</category>
      <category domain="http://securityratty.com/tag/market entry">market entry</category>
      <category domain="http://securityratty.com/tag/blocks sensitive">blocks sensitive</category>
      <category domain="http://securityratty.com/tag/monitors">monitors</category>
      <source url="http://www.networkworld.com/news/2008/070108-nextier.html?fsrc=rss-security">Start-up nexTier debuts data-leak prevention appliance</source>
    </item>
    <item>
      <title><![CDATA[Japanese military loses data again]]></title>
      <link>http://securityratty.com/article/5c8c6a8f3e371d85ca04e812cdd09386</link>
      <guid>http://securityratty.com/article/5c8c6a8f3e371d85ca04e812cdd09386</guid>
      <description><![CDATA[Japan's Self Defense Force lost sensitive data pertaining to a joint U.S.-Japan military exercise last year, the Ministry of Defense said...]]></description>
      <content:encoded><![CDATA[Japan's Self Defense Force lost sensitive data pertaining to a joint U.S.-Japan military exercise last year, the Ministry of Defense said Tuesday.]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/japan">japan</category>
      <category domain="http://securityratty.com/tag/-japan military exercise">-japan military exercise</category>
      <category domain="http://securityratty.com/tag/defense">defense</category>
      <category domain="http://securityratty.com/tag/joint">joint</category>
      <category domain="http://securityratty.com/tag/ministry">ministry</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://www.networkworld.com/news/2008/070108-japanese-military-loses-data.html?fsrc=rss-security">Japanese military loses data again</source>
    </item>
    <item>
      <title><![CDATA[My Name......is......Neo!]]></title>
      <link>http://securityratty.com/article/2c478999841c979e08f1dd1c0ce66c8a</link>
      <guid>http://securityratty.com/article/2c478999841c979e08f1dd1c0ce66c8a</guid>
      <description><![CDATA[As Keanu would say, &quot;There's a bomb on the bus

I mean, &quot;Whoa&quot;. He might also have said &quot;Excellent&quot;, but that was definitely the wrong film

At any rate, here's an infection from China called...]]></description>
      <content:encoded><![CDATA[
        As Keanu would say, "There's a bomb on the bus".<br /><br />I mean, "Whoa". He might also have said "Excellent", but that was <i>definitely</i> the wrong film.<br /><br />At any rate, here's an infection from China called "Agent.NEO", which probably has some deep seated relevance to the Matrix trilogy. Or maybe not. There aren't tons of screenshots of desktop fireworks, because by and large, this infection doesn't hit you with the pretty whiz-bang effects on your monitor. What it <i>does</i> do, however, is drop a ton of files onto your PC (many of which do <a href="http://www.prevx.com/filenames/X1901356285440341471-0/AVWLAST.EXE.html">strange things</a> - here's a couple from various directories):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="neo3.jpg" src="http://blog.spywareguide.com/images/neo3.jpg" class="mt-image-none" style="" height="107" width="275" /></span></div>
<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="neo4.jpg" src="http://blog.spywareguide.com/images/neo4.jpg" class="mt-image-none" style="" height="68" width="270" /></span></div><br /><br />...slows everything down to a crawl, attempts to detect and disable security programs, contact a remote mail server with network sensitive data, hijack your IE:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="neo1.jpg" src="http://blog.spywareguide.com/images/neo1.jpg" class="mt-image-none" style="" height="190" width="298" /></span></div>
<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/neo2.html" onclick="window.open('http://blog.spywareguide.com/images/neo2.html','popup','width=500,height=363,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/neo2-thumb-300x217.jpg" alt="neo2.jpg" class="mt-image-none" style="" height="217" width="300" /></a></span>
<br />Click to Enlarge<br /></div><br />....and tries to show you a couple of Chinese popup ads (none of those pages were online at time of testing, otherwise there'd be multicoloured screenshots galore below).<br /><br />I'm trying really hard to end this writeup with a really cheesy Matrix reference, but I can't think of any so in conclusion: avoid <a href="http://www.spywareguide.com/product_show.php?id=3503">Agent.NEO</a> at all costs (but watch the films again, they're awesome).<br /><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 12:35:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/neo">neo</category>
      <category domain="http://securityratty.com/tag/pretty whiz-bang effects">pretty whiz-bang effects</category>
      <category domain="http://securityratty.com/tag/chinese popup ads">chinese popup ads</category>
      <category domain="http://securityratty.com/tag/screenshots galore">screenshots galore</category>
      <category domain="http://securityratty.com/tag/avoid agent">avoid agent</category>
      <category domain="http://securityratty.com/tag/cheesy matrix reference">cheesy matrix reference</category>
      <category domain="http://securityratty.com/tag/disable security programs">disable security programs</category>
      <category domain="http://securityratty.com/tag/remote mail server">remote mail server</category>
      <category domain="http://securityratty.com/tag/network sensitive data">network sensitive data</category>
      <source url="http://blog.spywareguide.com/2008/06/my-nameisneo.html">My Name......is......Neo!</source>
    </item>
    <item>
      <title><![CDATA[Service Canada employee loses flash drive]]></title>
      <link>http://securityratty.com/article/0b1145db0ad92794aa6d34d54d9a00ca</link>
      <guid>http://securityratty.com/article/0b1145db0ad92794aa6d34d54d9a00ca</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/27/08

Organization
Government of Canada

Contractor/Consultant/Branch
Service Canada

Victims
Canadian Residents

Number Affected
More than 1,500
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/servicecanada.jpg" width="103" align="right" height="54"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/27/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://canada.gc.ca/home.html">Government of Canada</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.servicecanada.gc.ca/">Service Canada</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Canadian Residents<br><br><span style="font-weight: bold;">Number Affected:</span><br>More than 1,500<br><br><span style="font-weight: bold;">Types of Data:</span><br>Name and <a href="http://www.servicecanada.gc.ca/en/sc/sin/">Social Insurance Number</a><br><br><span style="font-weight: bold;">Breach Description:</span><br>"Service Canada recently sent a letter to 1500 individuals that where affected by a recent incident. It seems that a USB key, containing the names and social security number of 1500 canadians was lost."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.nowpublic.com/tech-biz/service-canada-loses-canadians-data">NowPublic</a> <br><a href="http://www.radio-canada.ca/nouvelles/National/2008/06/23/003-service-canada-donn%C3%A9es.shtml">Radio-Canada (French)</a> <br><a href="http://translate.google.com/translate?u=http%3A%2F%2Fwww.radio-canada.ca%2Fnouvelles%2FNational%2F2008%2F06%2F23%2F003-service-canada-donn%C3%A9es.shtml&amp;hl=en&amp;ie=UTF8&amp;sl=fr&amp;tl=en">Radio-Canada (Google English translation)</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Radio-Canada, via an email from an informed Breach Blog reader<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>An Employee Service Canada has lost in March, a USB stick containing personal information on more than 1,500 Canadians.<br><span style="font-style: italic;">[Evan] This statement was translated from french.&nbsp; An employee of Service Canada lost a flash drive with confidential personal information belonging to more than 1,500 Canadians stored on it.&nbsp; Service Canada is responsible for the security of some very sensitive personal information belonging to thousands (maybe millions) of Canadians.&nbsp; As such, the people that are permitted to access (assuming that role-based access control is enforced at Service Canada) confidential information must be properly trained and made constantly aware of the risks involved with creating, accessing, storing, destroying, and transferring this information.&nbsp; Was this employee aware of the risk of using a flash drive to store this information?&nbsp; If so, then there should be consequences for his/her actions.&nbsp; If not, then Service Canada really needs some help.&nbsp; Training and awareness is only a part of an effective information security program, but it is a very important one.&nbsp; Are flash drives permitted for use at Service Canada?&nbsp; They probably shouldn't be.</span><br><br>The agency sent a letter to the persons concerned to advise them of the situation and asking them to check their bank accounts, their credit file and expenditure on their card.<br><br>Among the information contained in the key, were found including the names of persons and their number of social insurance.<br><br>One of the victims wanted to know why Canada Service data contained on the key, a minidisk drive, were not protected.&nbsp; "They said they did not want to invest to secure customer data," said Queen Fraser.<br><span style="font-style: italic;">[Evan] Obviously, this is an unacceptable response and probably one that wasn't authorized.</span><br><br>There are a few problems with this statement of course... First and foremost, Service Canada employees need training in Security incident management and, in particular, in the important aspect of security incident communications.<br><span style="font-style: italic;">[Evan] Among many other things, I'm sure.</span><br><br>Second, this means that they are either not aware of Governement of Canada <a href="http://www.tbs-sct.gc.ca/pubs_pol/gospubs/tbm_12a/gsp-psg_e.asp">security policies</a> or <a href="http://www.tbs-sct.gc.ca/pubs_pol/gospubs/tbm_128/chap1_1-1_e.asp">Privacy policies</a> as published by Treasury Bord [sic] Secretariat, or they do not care.<br><br>The government agency has opened an investigation and added that no identity theft had been reported.<br><br>It did not specify whether measures have been taken to avoid another incident.<br><span style="font-style: italic;">[Evan] We can only imagine what the current state of information security is at Service Canada.&nbsp; It may be worse than some of us think, and it may be better than others of us think.&nbsp; In my opinion, Service Canada owes a thorough explanation to the victims of this breach and owes detailed assurances to Canadian citizens.</span><br style="font-style: italic;"><br>As anyone with some knowledge of IT security practices can tell you, USB keys should not be used to carry delicate, protected or private information.<br><span style="font-style: italic;">[Evan] In general, I agree.</span><br><br>If it must be done then, at a minimum, a threat and risk assessment must be done and proper encryption of the data must be used.<br><span style="font-style: italic;">[Evan] I absolutely agree.&nbsp; Risk management is critical.</span><br><br>However, mosts organisations that deal with data that is sensitive, protected under privacy laws, such as PIPEDA, commercial trade secrets or of national interest (such as National Defence secrets) AND are serious about IT security would disable floppy disk drives and USB ports on most computers. <br><span style="font-style: italic;">[Evan] Most "organisations" should, but unfortunately most do not.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>I would like to think that this is an isolated incident at Service Canada, but I don't think that it actually is.&nbsp; I would like to see the <a href="http://www.privcom.gc.ca/index_e.asp">Privacy Commissioner of Canada</a> investigate and audit the security program and practices at Service Canada.&nbsp; We'll see if this happens.&nbsp; I don't expect things to change until the people responsible are <span style="font-style: italic;">held</span> responsible.<br><br>How does the Canadian government expect the private sector to provide adequate security measures for the protection of personal information if it does not follow best practices and the law itself? <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Government of Canada:</span><br>November, 2007 - <a href="http://breachblog.com/2007/11/26/servicecanada.aspx">Service Canada stolen laptop affects more than 1,600</a>&nbsp; <br>December, 2007 - <a href="http://breachblog.com/2007/12/05/passport.aspx">Passport Canada web site suffers serious breach</a>&nbsp; <br>June, 2008 - <a href="http://breachblog.com/2008/06/08/ccga.aspx">Canadian farmer personal information on stolen CCGA laptop</a>&nbsp; <br><span style="font-weight: bold;">Service Canada:</span><br>November, 2007 - <a href="http://breachblog.com/2007/11/26/servicecanada.aspx">Service Canada stolen laptop affects more than 1,600</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/28/servicecanada.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 28 Jun 2008 19:18:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service canada">service canada</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/service canada recently">service canada recently</category>
      <category domain="http://securityratty.com/tag/canada">canada</category>
      <category domain="http://securityratty.com/tag/service canada employees">service canada employees</category>
      <category domain="http://securityratty.com/tag/employee aware">employee aware</category>
      <category domain="http://securityratty.com/tag/practices">practices</category>
      <category domain="http://securityratty.com/tag/security practices">security practices</category>
      <category domain="http://securityratty.com/tag/employee service canada">employee service canada</category>
      <source url="http://breachblog.com/2008/06/28/servicecanada.aspx">Service Canada employee loses flash drive</source>
    </item>
    <item>
      <title><![CDATA[Enforceable Policies]]></title>
      <link>http://securityratty.com/article/4b11bc7e086ec29036a0e6147198f36e</link>
      <guid>http://securityratty.com/article/4b11bc7e086ec29036a0e6147198f36e</guid>
      <description><![CDATA[Blogger: Randall Gamby

Across the different security technology presentations given this week at Catalyst, one common theme has been the important role of policy. As people hear about new and better...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby<br /><br />Across the different security technology presentations given this week at Catalyst, one common theme has been the important role of policy. As people hear about new and better technologies and how they can be integrated into their existing infrastructures, they should take the time to examine their policies to make sure they keep up with the solutions being considered.&nbsp; Questions to ask:</p>

<ul><li>When did we review our policies last?</li>

<li>Do we have not enough or too many?</li>

<li>Will they still be valid?</li>

<li>Are there other influencers on them? </li></ul>

<p>But while changes will most likely be needed for many current policies, a question that often isn’t asked is, “Are they enforceable?”&nbsp; As enterprises create policies based upon what users “should do,” can the security team validate that they “did do” what was asked?&nbsp; For example, a common policy is, “All sensitive data at rest must be encrypted.”&nbsp; So this means you must encrypt your Active Directory, your e-mail storage, every production database, yes? That's probably not happening.&nbsp; So if the enterprise has no way to implement the policy, then it ultimately is not a valid policy and needs to either be modified or the enterprise needs money, resources and time to conform to the policy.&nbsp; <br /><br />The social effect on the user population also needs to be considered.&nbsp; Essentially, the enterprise is teaching users that they don’t have to conform to this policy, so maybe they don’t have to be conformant to others on the books.&nbsp; Not a good lesson to teach them.<br /><br />So as the Catalyst attendees go back with “dreams of technology sugar plums dancing in their heads” don’t forget that good governance with valid processes should be skipping around the edge.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/321502595" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 10:23:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/policies">policies</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/valid policy">valid policy</category>
      <category domain="http://securityratty.com/tag/common policy">common policy</category>
      <category domain="http://securityratty.com/tag/policies based">policies based</category>
      <category domain="http://securityratty.com/tag/valid">valid</category>
      <category domain="http://securityratty.com/tag/valid processes">valid processes</category>
      <category domain="http://securityratty.com/tag/current policies">current policies</category>
      <category domain="http://securityratty.com/tag/catalyst attendees">catalyst attendees</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/321502595/enforceable-pol.html">Enforceable Policies</source>
    </item>
    <item>
      <title><![CDATA[Enforceable Policies]]></title>
      <link>http://securityratty.com/article/d8d4776279822d375303e5c33de34f10</link>
      <guid>http://securityratty.com/article/d8d4776279822d375303e5c33de34f10</guid>
      <description><![CDATA[Blogger: Randall Gamby

Across the different security technology presentations given this week at Catalyst, one common theme has been the important role of policy. As people hear about new and better...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby<br /><br />Across the different security technology presentations given this week at Catalyst, one common theme has been the important role of policy. As people hear about new and better technologies and how they can be integrated into their existing infrastructures, they should take the time to examine their policies to make sure they keep up with the solutions being considered.&nbsp; Questions to ask:</p>

<ul><li>When did we review our policies last?</li>

<li>Do we have not enough or too many?</li>

<li>Will they still be valid?</li>

<li>Are there other influencers on them? </li></ul>

<p>But while changes will most likely be needed for many current policies, a question that often isn???t asked is, ???Are they enforceable????&nbsp; As enterprises create policies based upon what users ???should do,??? can the security team validate that they ???did do??? what was asked?&nbsp; For example, a common policy is, ???All sensitive data at rest must be encrypted.???&nbsp; So this means you must encrypt your Active Directory, your e-mail storage, every production database, yes? That's probably not happening.&nbsp; So if the enterprise has no way to implement the policy, then it ultimately is not a valid policy and needs to either be modified or the enterprise needs money, resources and time to conform to the policy.&nbsp; <br /><br />The social effect on the user population also needs to be considered.&nbsp; Essentially, the enterprise is teaching users that they don???t have to conform to this policy, so maybe they don???t have to be conformant to others on the books.&nbsp; Not a good lesson to teach them.<br /><br />So as the Catalyst attendees go back with ???dreams of technology sugar plums dancing in their heads??? don???t forget that good governance with valid processes should be skipping around the edge.</p></div>
]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 10:23:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/policies">policies</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/valid policy">valid policy</category>
      <category domain="http://securityratty.com/tag/common policy">common policy</category>
      <category domain="http://securityratty.com/tag/policies based">policies based</category>
      <category domain="http://securityratty.com/tag/valid">valid</category>
      <category domain="http://securityratty.com/tag/valid processes">valid processes</category>
      <category domain="http://securityratty.com/tag/current policies">current policies</category>
      <category domain="http://securityratty.com/tag/catalyst attendees">catalyst attendees</category>
      <source url="http://srmsblog.burtongroup.com/2008/06/enforceable-pol.html">Enforceable Policies</source>
    </item>
    <item>
      <title><![CDATA[Right Wing Israeli Hackers Deface Hamas's Site]]></title>
      <link>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</link>
      <guid>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</guid>
      <description><![CDATA[Compared to historical hacktivism tensions between different nations, Israeli and Palestinian hacktivists seem to be most sensitive to &quot;virtual fire exchange&quot; like this one, and consequently, just...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s1600-h/hamas_hacked.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s200/hamas_hacked.png" alt="" id="BLOGGER_PHOTO_ID_5216261237759367394" border="0" /></a>Compared to historical hacktivism tensions between different nations, <a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Israeli and Palestinian hacktivists</a> seem to be most sensitive to "virtual fire exchange" like this one, and consequently, just like in real-life, always look and find for an excuse to engage in a conflict. <a href="http://www.ynetnews.com/articles/0,7340,L-3560756,00.html">Israeli hackers penetrate Hamas website</a> :<br /><br />"<span style="font-style: italic;">Israeli hackers boasted Thursday about breaking into the website of Izz al-Din al-Qassam, Hamas’ military wing, which now displays a white screen and words in Arabic announcing technical difficulties. The hacker group, which calls itself Fanat al-Radical (the fanatical radicals), also said that it broke into additional terror organizations’ sites and those of various leftist movements.  In a Ynet interview, a group representative who refused to reveal his name said, “We searched for relevant sites with the criteria we look for, whether leftist or anti-Zionist, and looked for loopholes. Our emphasis was always on the al-Qassam site. "The criteria are defined as anti-Zionist or anti-Jewish sites that support or assist in harming Zionism and the existence of Israel as a Zionistic, Jewish state.</span>"<br /><br />The message they left :<br /><br />"<span style="font-style: italic;">Hacked by XcxooXL and FENiX from Fanat Al Radical Greets: Sn4k3 Contact: Fanat.al.Radical@gmail.com </span>"<br /><br />These script kiddies using SQL injection vulnerabilities within the affected sites, since they indeed managed to deface several other as well, seem to have also participated in the 2006 cyber conflict sparkled due to the <a href="http://www.mfa.gov.il/MFA/MFAArchive/2000_2009/2004/1/Israeli%20MIAs">the kidnapping of three soldiers</a>. One of their defacements remains still active (<span style="font-weight: bold;">aviv.perffect-x.net/deface.html</span>)<br /><br />"<span style="font-style: italic;">We will stand against the Islam until the kidnapped soldiers, Gilad Shalit, Eldad Regev and Ehod Goldvaser will be return, We will attack arabic servers and site which support the Islam and protest against the zionism</span>"<br /><br />What if every script kiddie with a SQL injection scanners goes into politics? It's a mess already.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br /><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br /><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html"></a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ryWbnI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ryWbnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=frccjI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=frccjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yec9Yi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yec9Yi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdpmYi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdpmYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOanxI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOanxI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XjskfI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XjskfI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MXrvxi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MXrvxi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/320791816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 11:36:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/israeli">israeli</category>
      <category domain="http://securityratty.com/tag/israeli hackers">israeli hackers</category>
      <category domain="http://securityratty.com/tag/anti-jewish sites">anti-jewish sites</category>
      <category domain="http://securityratty.com/tag/al-qassam site">al-qassam site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/hacktivism tensions">hacktivism tensions</category>
      <category domain="http://securityratty.com/tag/historical hacktivism tensions">historical hacktivism tensions</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/320791816/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</source>
    </item>
  </channel>
</rss>
