Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts

July 1, 2008

British Health Records Stolen

This is really beginning to get to me. With the proliferation of laptops in our society, you would think that knowledge of security would begin to rapidly spread as well. However, this is the second story in less than a week of a laptop being stolen from a car. Now, if this was an office of some sort, with semi-inconsequential data it would be understandable. But it seems that more and more, Healthcare IT staff are carrying around patient data on their personal laptops. These are people who are carrying around credit card info, banking numbers, social security numbers, Names, dates of birth. And i still wouldn't have a problem with it if they would take some sort of rudimentary precautions to ensure the protection of the data. However, there have been cases of IT staff storing full system backup tapes, laptops, USB Crypto keys, and entire servers in the back of their cars. They are then completely amazed when these top-level security measures are thwarted by a crook with a crowbar. This latest incident occured after a British IT worker for the NHS trust left his laptop unsecured in his car, along with 21,000 patients details. To make things worse, none of the information was encrypted. So the thief now has complete access to any and all patient data. The NHS trust reinforced the now common perception that they were completely technologically incompetent by stating (trying to make the situation better) "the data will almost certainly by wiped by the thief"

What steps should you take in order to secure a system from theft?
A. Set a Bios Level Password
B. Set at least a 14 digit password.
C. Require some sort of Biometric Authorization for Access
D. Always keep your data in an encrypted folder
E. If practical, Hide private data inside of another file
F. Keep any backups in humidity controlled, insulated environment.
G. Rule of Thumb: If your system can be seen, its public data.
H. Thumb of Rule: If your system is in your car, it deserves to be stolen.

May 23, 2008

Vulnerabilities in the Tennesse Valley Authority Power Grid

Recently, in a disclosure by the US Government Accountability office- the UAO makes the following statement.

"Until the TVA fully implements these security program activities, it risks disruption of its operations as the result of a cyber incident, which could impact its customers," the GAO says. TVA delivers electricity to an area that includes most of Tennessee and parts of Alabama, Georgia, Kentucky, Mississippi, North Carolina and Virginia -- an area with a population of 8.7 million people.

The Authority Power grid is essentially not separate from its corporate network. The latter is ripe with vulnerabilities, including faulty hardware, Anti-virus free machines, poorly patched control systems and a myriad of other issues. The network has "Limited intrusion Detection" and ineffective management. Basically, if you happened upon a Wireless Access Point, with WEPCrack- Your have access to the world's largest public power grid.

I find this to be disgusting, and an absolute slap in the face for the IT community. How hard is it, admins, to set a 14 digit pass code, configure a router, or even mass install a freaking Anti-Virus? Remember, people depend on you for their livelihoods- take the responsibility seriously.

January 14, 2008

Hacker Safe?


Please, don't be lulled into a sense of false security just because a website has the hacker-safe logo on it. "Why not?" You ask me, BECAUSE- *DURRRRR* NOTHING IS HACKER SAFE. But why specifically? The hacker safe certification is a subscription program through various Companies, and although your favorite "Adult" website may be hacker safe when you register. This doesn't mean it will be two weeks down the road. What they companies do is they test each registered website every day using a automatic program, and if they find problems they will tell the website. Thats it, they dont fix it, force the website to take down the certification, nothing- they just say "Hey theres a problem." Dont Believe me?
Geeks.com is a $150 million company specializing in the sale of excess inventory and manufacturers' closeouts. Its Web site says that it is tested on a daily basis by ScanAlert Inc., which offers a service that constantly monitors sites for vulnerabilities.
But ScanAlert spokesman Nigel Ravenhill said via e-mail last week that the vendor, which is being acquired by McAfee Inc., had withdrawn its Hacker Safe certification from Geeks.com "several times" last year after finding vulnerabilities in the retailer's systems. Geeks.com fell out of compliance last June and again in December, he said.
The compromised information included names, addresses, telephone numbers and Visa credit card numbers, according to a copy of the letter posted on The Consumerist blog.
Now, What are the implications of this break in? Am I telling you that you should be a paranoid schizo when doing business on the internet? DUH. A wise man once told me "Putting your credit card on the Internet is like putting your naughty parts in a wood grinder." Although its not the most glamorous quote in the world, its true. Listen to the man, dont stick your wah-wah in the wood grinder.

January 10, 2008

Password Security

As well as having commentary and occasional How-to's from the dark side of security as well as white-hats, I am going to use this as somewhat of a Venting forum for personal observations of idiocy. Okay, first let me say- Passwords are not that hard to remember- unless you have 8+ Numbers, Letters, and symbols in your password, it can very easily be shoulder surfed. Shoulder surfing is an act of seeming to be interested in one's meaningless conversation, in order to see them type their password. For businesses- this can be especially nasty- while that young kid who seems to be so interested in your business plan is watching you login to your systems- you are handing him the foothold to your bottom line. Solution? For 10 dollar's you can prevent all would be surfers: Monitor Mirror