<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ywca]]></title>
    <link>http://securityratty.com/tag/ywca</link>
    <description></description>
    <pubDate>Tue, 11 Dec 2007 09:23:19 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[YWCA Retirement Fund participants exposed in stolen computer]]></title>
      <link>http://securityratty.com/article/2e5799582306cfe7453bce0221b53e76</link>
      <guid>http://securityratty.com/article/2e5799582306cfe7453bce0221b53e76</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
10/9/07 (backdated

Organization
The Young Women's Christian Association (YWCA) Retirement Fund, Inc

Contractor/Consultant/Branch
None

Victims
Active...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/ywcarf.jpg" align="right" height="60" width="158">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>10/9/07 (backdated)<br><br><span style="font-weight: bold;">Organization: </span><br>The Young Women's Christian Association (YWCA) Retirement Fund, Inc.<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Active fund participants between January 1st, 2002 and September 28th, 2007<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Name and Social Security number.<br><br><span style="font-weight: bold;">Breach Description:</span><br>On Monday, October 1st, 2007 YWCA Retirement Fund employees noticed that a computer had been stolen from the Fund's office in New York.&nbsp; The computer contained sensitive personal information including names and Social Security numbers for active fund participants from January 1st, 2002 to September 28th, 2007.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/ywca.pdf" target="_blank"> State of New Hampshire Attorney General's Breach Notification</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the official breach notification and letter to victims:<br><br>We are writing to inform you that some of your personal identification information may have been compromised recently.<br><span style="font-style: italic;">[Comfyllama] "May have been compromised"?&nbsp; No, no, no.&nbsp; If you do not have a reasonable assurance that data confidentiality, integrity, and availability remain intact, then the data <span style="font-weight: bold;">IS </span>compromised.</span><br><br>On Monday, October 1 when The Young Women's Christian Association Retirement Fund, Inc. staff arrived at the Fund's office we discovered one computer had been stolen.<br><br>The stolen computer contained the names and Social Security numbers of individuals who were active Participants in the Fund at anytime during the period from January 1, 2002 to September 28, 2007.<br><span style="font-style: italic;">[Comfyllama] We couldn't find any information to give us an idea of how many people this refers to, but we didn't look long.</span><br><br>The stolen computer did not contain addresses, telephone or email contact points and most importantly no account balances.<br><span style="font-style: italic;">[Comfyllama] Unauthorized access to any of this information is bad, but "most importantly no account balances"?&nbsp; If I had a choice, I think I would rather have my account balance disclosed than I would my name and Social Security number.</span><br><br>Several factors lead us to believe that the risk to your personal data is rather low.<br><br>Here is further information about what occurred and these facts should help you assess the risk to your personal identification information:<br></font><br><font size="2">1.&nbsp; only the computer was stolen, not the monitor, nor the mouse, not the power pack</font><br><font size="2"><span style="font-style: italic;">[Comfyllama] I am confused.&nbsp; What does this have to do with the risk of unauthorized data access?</span><br></font><br><font size="2">2.&nbsp; the stolen computer was of a type that requires a power pack, not a power cord.&nbsp; Power packs are not sold through retail outlets but must be ordered from the computer manufacturer which requires the computer's serial number, the customer's account number and name.&nbsp; Dell has been notified of the theft.&nbsp; Any attempted order will be flagged, the caller id will be recorded and forwarded to both the Fund and the New York Police Department with whom we met Monday afternoon, October 1.</font><br><font size="2"><span style="font-style: italic;">[Comfyllama] This is simply untrue and useless information.&nbsp; If you need a Dell power cord for a laptop, go to Dell and order one without proving a serial number, customer account number and name, or go to one of many of </span><a style="font-style: italic;" href="http://www.nextag.com/dell-laptop-computer-power-cord/search-html" target="_blank"> retail outlets that DO sell them</a><span style="font-style: italic;">. </span><br><br>3.&nbsp; a passcode is required to access the personal identification information stored on the stolen computer.<br><span style="font-style: italic;">[Comfyllama] This "passcode" is nothing more that a momentary nuisance to anyone with simple computer skills.</span><br><br>The fund has reviewed the pertinent 24-hour surveillance tapes from the week-end and they have been turned over to the NYPD.<br><br>We have already purchased and installed DEFCON cable locks on all computers.<br><br>In the next few weeks the Fund will consult with a security firm to evaluate our entire operation.&nbsp; It is the intent of the Fund to implement the security firm's recommendations for improving data protection.<br><span style="font-style: italic;">[Comfyllama] Let's hope that the "security firm" is worth at least half the price.</span><br><br>We sincerely apologize for causing you concern<br><br>Please be assured that we will be ever more vigilant in protecting your data.&nbsp; If you have any questions, or if we may be of any further assistance at anytime, please call us toll-free at 1-800-222-4738.<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach occurred not just as a result of a break-in and theft of a computer.&nbsp; This breach occurred as a result of a fundamental failure of information security.&nbsp; We don't have the privilege of looking at the YWCA Retirement Fund's information security program (assuming one exists), so we don't know much more than what we read in the Fund's response.&nbsp; From reading the Fund's response, we can judge that the YWCA Retirement Fund is a poor custodian of sensitive information.&nbsp; The response is one of the most clueless that we have seen to date.<br><br>I sincerely hope that the security firm eluded to in the response will recommend some serious changes, one of which would include encryption of data at rest.&nbsp; I am sure the list will be long (assuming the security firm knows what they are doing). <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/11/ywcarf.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Tue, 11 Dec 2007 09:23:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ywca retirement fund">ywca retirement fund</category>
      <category domain="http://securityratty.com/tag/retirement fund">retirement fund</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/personal identification information">personal identification information</category>
      <category domain="http://securityratty.com/tag/active fund participants">active fund participants</category>
      <source url="http://breachblog.com/2007/12/11/ywcarf.aspx">YWCA Retirement Fund participants exposed in stolen computer</source>
    </item>
  </channel>
</rss>
