This is really beginning to get to me. With the proliferation of laptops in our society, you would think that knowledge of security would begin to rapidly spread as well. However, this is the second story in less than a week of a laptop being stolen from a car. Now, if this was an office of some sort, with semi-inconsequential data it would be understandable. But it seems that more and more, Healthcare IT staff are carrying around patient data on their personal laptops. These are people who are carrying around credit card info, banking numbers, social security numbers, Names, dates of birth. And i still wouldn't have a problem with it if they would take some sort of rudimentary precautions to ensure the protection of the data. However, there have been cases of IT staff storing full system backup tapes, laptops, USB Crypto keys, and entire servers in the back of their cars. They are then completely amazed when these top-level security measures are thwarted by a crook with a crowbar. This latest incident occured after a British IT worker for the NHS trust left his laptop unsecured in his car, along with 21,000 patients details. To make things worse, none of the information was encrypted. So the thief now has complete access to any and all patient data. The NHS trust reinforced the now common perception that they were completely technologically incompetent by stating (trying to make the situation better) "the data will almost certainly by wiped by the thief"
What steps should you take in order to secure a system from theft?
A. Set a Bios Level Password
B. Set at least a 14 digit password.
C. Require some sort of Biometric Authorization for Access
D. Always keep your data in an encrypted folder
E. If practical, Hide private data inside of another file
F. Keep any backups in humidity controlled, insulated environment.
G. Rule of Thumb: If your system can be seen, its public data.
H. Thumb of Rule: If your system is in your car, it deserves to be stolen.
My New Blog
July 1, 2008
British Health Records Stolen
Posted by
Gillis57
at
5:08 PM
0
comments
Labels: backdoor, backups, Biometric, Bios, Britain, data, doctor, Gillis Jones, Hack Stole, Healthcare, hospital, IT, Laptop, Leo Laporte, NHS Trust, Password, patients, Security, Stolen, theft
May 23, 2008
Vulnerabilities in the Tennesse Valley Authority Power Grid
Recently, in a disclosure by the US Government Accountability office- the UAO makes the following statement.
"Until the TVA fully implements these security program activities, it risks disruption of its operations as the result of a cyber incident, which could impact its customers," the GAO says. TVA delivers electricity to an area that includes most of Tennessee and parts of Alabama, Georgia, Kentucky, Mississippi, North Carolina and Virginia -- an area with a population of 8.7 million people.
The Authority Power grid is essentially not separate from its corporate network. The latter is ripe with vulnerabilities, including faulty hardware, Anti-virus free machines, poorly patched control systems and a myriad of other issues. The network has "Limited intrusion Detection" and ineffective management. Basically, if you happened upon a Wireless Access Point, with WEPCrack- Your have access to the world's largest public power grid.
I find this to be disgusting, and an absolute slap in the face for the IT community. How hard is it, admins, to set a 14 digit pass code, configure a router, or even mass install a freaking Anti-Virus? Remember, people depend on you for their livelihoods- take the responsibility seriously.
January 14, 2008
Hacker Safe?
Posted by
Gillis57
at
4:44 PM
0
comments
Labels: Anti-Virus, Bot, Digital Armaments, Hacker, Hacking, Hijack, Password, Security, Sql, SQL Injections, Tor, Trojan, Virus, Vulnerability, Windows
January 10, 2008
Password Security
As well as having commentary and occasional How-to's from the dark side of security as well as white-hats, I am going to use this as somewhat of a Venting forum for personal observations of idiocy. Okay, first let me say- Passwords are not that hard to remember- unless you have 8+ Numbers, Letters, and symbols in your password, it can very easily be shoulder surfed. Shoulder surfing is an act of seeming to be interested in one's meaningless conversation, in order to see them type their password. For businesses- this can be especially nasty- while that young kid who seems to be so interested in your business plan is watching you login to your systems- you are handing him the foothold to your bottom line. Solution? For 10 dollar's you can prevent all would be surfers: Monitor Mirror