Showing posts with label ohio. Show all posts
Showing posts with label ohio. Show all posts

Saturday, June 23, 2007

Data compromise in Ohio reveals the need to be more proactive in protecting information

The practice of sending computer back-up tapes containing a lot of personal/financial information home with interns went on for 2-3 years at a government office in Ohio, according to an article in the Columbus Dispatch.

The Columbus Dispatch is reporting:

In fact, it appears that the former technical manager for the Ohio Administrative Knowledge System didn't use regular state employees -- only two or three interns besides himself -- to take the data home on a rotating basis for safekeeping, said Ron Sylvester, a spokesman for the Ohio Department of Administrative Services.

Apparently, this was part of a security policy, to safeguard the information from fire, or some sort of other disaster.

According to a state policy that officials said was last updated in April 2002, two backup copies were to be made each day of the data in the state's $158 million payroll and accounting system, known as OAKS. The current day's backup tape was to be maintained on site in the network administrator's office, and the previous day's backup tapes were to be taken to the network administrator's home in case of a fire or other disaster at the office.

My question is, can they account for all of these tapes, made daily?

If two tapes a day were made, this would equate to anywhere from 730 to 1095 tapes, at this one agency. If these tapes were routinely backed up and taken home, it wouldn't be hard to make extra copies and not return them.

Of course, someone with the proper knowledge and expertise probably wouldn't have a hard time copying them away from the office, either.

In response to this, the State of Ohio has hired a security firm to look into this matter.
The panel also earmarked up to $100,000 for Interhack Corp. of Columbus to assess the security of the new state accounting setup and to verify that state officials have identified all important data that have been stolen.

Curtin, the founder of Interhack, said it would take time, expertise and money for someone to read the tape. Because the state has notified those whose personal data may be affected, it would be difficult for a thief to use the information, he argued.

"So at this point now, if somebody tries to use the data, they're going to be found out pretty quickly," he said.

According to this report, the data wasn't encrypted, therefore (in theory) it might be not very hard to access it. If the data were encrypted, it would take expertise and money, but it still could be accomplished by someone with the necessary knowledge and ambition to do so.

Organized criminals, who deal in stolen information, have been reported to hire experts, who probably have this "knowledge and expertise."

Even scarier, Mr. Curtin also revealed that this probably wasn't the only agency sending information home:
Curtin said the practice of sending backup data home with employees is fairly common because of the cost involved in hiring a company to do it or using another facility.
Mr. Curtin is probably right that this particular information won't be used anytime in the near future. Criminals would rather use information, nobody knows has been breached. They make (steal) a lot more money that way.

I'd be more worried about information, which might have been easily compromised, that no one knows about yet.

We can all learn something from what happened in Ohio and the key is to start being proactive about how we secure valuable information.

Reacting costs a lot of money, and does little, to solve to overall problem.

Revealing article by the Columbus Dispatch, here.

My original post on the Ohio Data breach, here.

Here is a post about people with the necessary knowledge and expertise to access (hack) information being recruited by organized criminals making a lot of money with stolen information:

IT Students Aren't the Only Human Resources that Internet Criminals Desire

Saturday, June 16, 2007

Ohio data breach reveals how "not very secure" personal information is

I discovered a long time ago, it would be pretty hard to keep up with all the data-breaches. After all, they seem to happen with alarming frequency.

The most recent blunder, enabled by a State of Ohio security procedure, illustrates how not very secure a lot of personal information is.

Stephen Majors of the AP (courtesy of Forbes) is reporting:

A 22-year-old intern was given the responsibility of safeguarding the personal information of thousands of state employees, a security procedure that ended up backfiring.

The names and Social Security numbers of all 64,000 Ohio state employees were stolen last weekend from a state agency intern who left a backup data storage device in his car, Gov. Ted Strickland said Friday.

Interesting, a security procedure that backfired?

The AP story gives more details on this:

Under protocol in place since 2002, a first backup storage device is kept at a temporary work site for a state office along with the computer system that holds all the employee information, and a second backup device is given to employees on a rotating basis to take home for safekeeping, officials said
I guess this means that rotating employees have the ability to take this "storage device" home -- and if any of them happened to be dishonest -- it wouldn't be very hard to make a copy. Information is bought and sold by data-brokers, and criminals, alike. The reason for this is because it makes them a lot of money.

Of course, the official spin artists, aren't stating exactly what the device is. The Police report states that it's worth about $15, which isn't very expensive, and therefore probaby isn't very secure (my guess).

Governor Strickland was quoted in the article as saying:

"I don't mean to alarm people unnecessarily." "There's no reason to believe a breach of information has occurred."
Sadly enough, this might make sense -- when information is protected like this, it probably could have been copied long ago -- and no one would know any better. It wouldn't be necessary to go through all the trouble of breaking into a car to steal it.

With security like this, the information could have been compromised a long time ago.

Governor Strickland's site, which offers the "official spin" and free identity theft protection for the most recently "compromised," can be seen, here.

AP Story, here.

The Privacy Rights Clearinghouse and Attrition.org do have people, who have the time to keep up on all the data-breaches, in case anyone wants to take a detailed look at the problem.

This information is worth money, here is a post about how it is being sold right on the Internet:

Information Week exposes the Internet Underworld

Insider theft is nothing new, and should be a concern when protecting information. As long as information is worth a lot of money, insiders will probably be solicited for it. Here is a post, I wrote about this matter:

Why it's become TOO easy for restaurant workers to skim payment cards