This story is just another example of careless people that oversee our day to day lives. An iron mountain "secure" facility that backs up our personal data that has been collected by retailers such as Sears, J.C. Penney and even G.E. have "lost" a SCSI tape that contained hundreds of thousands of credit card transactions and also social security numbers for employees of different companies. The spokesperson said "The tape was never checked out, its just missing." I guess that they work under the honor system at this place. I find it very easy to believe that someone that wanted to steal data from one of these facilities would not sign it out and just take it. This is Social Engineering at it's best if I had to guess. They are going to look at the obvious people that have easy access to the equipment but I think that the blame is going to lie somewhere else. The data has been encrypted on the tape but it depends on the level of encryption that they decided to use. Judging by the level of security around the "protected" data at this facility, the person who took it should not have a hard time breaking the code. Maybe they should try 12345 for the key.
http://feeds.computerworld.com/~r/Computerworld/News/~3/219705350/article.do
Sunday, January 20, 2008
Whoops. Has someone seen my tape?
Posted by Sean Wilkerson at Sunday, January 20, 2008
Labels: credit card number, mistake, security, social security number
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment