Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [ISN] Blood bank fears laptop heist ID theft |
|---|---|
| Date: | Thu, 23 Dec 2004 03:13:07 -0600 (CST) |
Forwarded from: Eric Hacker <myself@erichacker.com> One has to wonder how much more valuable that laptop is on the black market now that it is known to contain names and SSNs. We have ID counts and valuable configuration information being distributed in the news. Even is this was stolen by an addict, his fence probably keeps up with the news. On Wed, 22 Dec 2004 01:35:08 -0600 (CST), InfoSec News wrote:
http://news.com.com/Blood+bank+fears+laptop+heist+ID+theft/2100-1029_3-5500114.html
[...]
Delta's director of human resources, John O'Neill, said two layers of security could still protect the personal information despite the computer's theft. The first is Microsoft's standard Windows password required to launch the operating system, and the second is the series of steps required to launch what O'Neill described as an "esoteric, unique" database, created by a software provider he declined to name.
Now this spells out exactly what one needs to know in order to extract the information. Certainly makes putting a value on the laptop that much easier for someone who thinks they can get at the information inside. Now, I am not saying that this is a bad law. I think it has a lot of benefits for the consumer. What I am saying is that there are consequences to this law, especially the disclosure of details to the press by stressed out executives, that do not help protect the confidentiality of the stolen information. Obviously, one needs to have a personal information disclosure incident response plan in place before a disclosure occurs to prevent this issue. Obviously, an organization that well organized would probably be doing a better job of protecting the data in the first place.... Peace, Eric Hacker _________________________________________ Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - http://www.osvdb.org/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] REVIEW: "Malicious Cryptography", Adam L. Young/Moti Yung, InfoSec News |
|---|---|
| Next by Date: | [ISN] Linux lasting longer against Net attacks, InfoSec News |
| Previous by Thread: | [ISN] Blood bank fears laptop heist ID theft, InfoSec News |
| Next by Thread: | [ISN] Record $39M Robbed From N. Ireland Bank, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |