Slashdot Log In
When Data Goes Missing Will You Even Know?
Posted by
ScuttleMonkey
on Tue Jan 24, 2006 01:34 AM
from the average-joe-in-a-clean-room dept.
from the average-joe-in-a-clean-room dept.
Lam1969 writes "Jack Gold says IT shops may have a huge problem on their hands, and probably don't know even know about it. The problem is USB flash drives, which he predicts will probably reach 10 GB in capacity in three years, and the lack of policies to guide use of them by employees. From the article: 'With more and more employees using flash drives, smart phones with Secure Digital memory cards, portable hard drives, etc., the likelihood of companies actually knowing about all instances of data loss is declining rapidly. And as a result, the possibility of companies breaking laws, whether for data-loss disclosure or regulatory compliance, is growing dramatically.' Gold predicts 'at least one publicized major case of unencrypted data loss from a portable device' in the next year, which will result in many companies banning these kinds of devices."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
data has walked out the door before. (Score:5, Insightful)
From the slashdot post:
While there is truth to this, it is not a new truth and it is not the complete truth. It's one more mechanism for "losing" data but it's not the first and it won't be the last.It's an effective mechanism for moving large volumes of data, but it's not the only mechanism.
Corporate espionage and theft has and will continue to exist. USB drives are just one more aspect. While there may be some "exposure" and scandal soon about some USB drive falling into the wrong hands I doubt it will surpass any of the recent scandals (lost tapes and customer data).
Unfortunately, I'm guessing the article is correct in its prediction: "It is highly likely that within the next year, we will see at least one publicized major case of unencrypted data loss from a portable device. Afterward, a lot of companies will ban such devices". That would be a knee jerk reaction and counter productive but I'm already seeing it on so many other levels, e.g.,
among many others. I still think the greatest exposures are social engineering... and the paranoia around security policies don't address that. Sigh
(And, besides, isn't the RIAA is working on a solution to apply DRM to USB drives too? ) ;-)
Re:data has walked out the door before. (Score:3, Interesting)
We already hear about it (Score:5, Informative)
Will it be more prevalent? Maybe. But it already happens. Now, the question is, is there a program that can encrypt/decrypt an entire (relatively) small drive with some sort of key system or something? I think that will be the most logical step to protect small drives like these.
Parent
Re:We already hear about it (Score:5, Insightful)
-nB
Parent
Re:We already hear about it (Score:4, Insightful)
Parent
Re:data has walked out the door before. (Score:5, Informative)
No need for "afterward". Most companies that are extremely interested in protecting data (such as a large
It doesn't take a smart company to figure out that you don't want Billing.mdb on a floppy. USB is really no different.
Parent
Columnists Rehashing Old Scaremongering (Score:5, Insightful)
- Briefcases get lost all the time, and briefcases have been large enough to contain sensitive information for decades now. Keychains also get lost on occasion, and especially for small businesses that's often enough to get in the building at night or steal a company truck.
- Yellow Sticky Notes with your IP address and VPN password fit in your pocket just fine, and DSL means that people can suck up your data even faster than when we used to use Yellow Sticky Notes to carry modem phone numbers and dialup passwords.
- Documents that are actually important are usually 1-100 pages long. You can store them on mashed-up dead trees if you avoid spilling coffee on them. Them newfangled USB thingies hold a lot of data, but back when we carried 3.5" floppy disks 20 miles through the snow uphill both ways , Microsoft Office wasn't as bloated, so a zipfile of The Secret Plans still usually fit in your pocket. That's not the same as carrying out the whole blueprints for your next chip in your pocket, but mini-CDs do pretty well - they're certainly enough to carry the HR personnel database home.
- DVDs and CDROMs fit pretty neatly into briefcases, and most newer PCs have at least a CD burner, so you can still carry the chip blueprints home.
- Laptops are easy to carry, and go missing all the time. The San Francisco Police aren't very good at recovering them even when they've got them in their evidence room and the thief in custody; your mileage may vary
:-) And unlike keyrings and regular briefcases, laptops have obvious resale value so they're more attractive to thieves.
- RM-05 removable disk packs are a bit big to fit in your briefcase, but magtapes fit just fine, and before magtapes we had ASR-33 paper-tape, which works just fine for carrying the Numerical Control tape that tells the milling machine how to cut your submarine-propeller plans.
- Mainframes with Greenscreen 3270s are much less portable, but back when I worked for The Big Phone Company they were worried about people carrying computer printouts home, and they checked our briefcases on the way out the door of buildings that handled sensitive information.
But yes, within the next couple of years, somebody's going to have a USB keyring/wristwatch/Walkperson/iPod/Pseudopod/someParent
Watch the log files! (Score:5, Insightful)
The log files don't lie!
Of course if you can't find them, then it doesn't matter, does it? Does WinXX create a log file of USB insertion - damned if I know!
Might not want to admit that... (Score:5, Insightful)
Wouldn't this be accessing files that you were not granted access to? Isn't this a crime in several US states, and is it really a good idea to admit to it in a column with your picture and name at the top?
Just curious if the 'Good Samaritan' is putting himself at risk (and if it was curiosity or a desire to return the property that was the motivation).
dumb approach. (Score:5, Insightful)
Gold predicts 'at least one publicized major case of unencrypted data loss from a portable device' in the next year, which will result in many companies banning these kinds of devices."
Which will solve exactly nothing. What are you going to do, search everyone as they enter and leave the building? If you want to limit data theft, limit access to huge amount of data in the first place. That eliminates the risk to any new technology to get the data offsite.
A little epoxy will fix that right up. (Score:5, Interesting)
Re:A little epoxy will fix that right up. (Score:5, Insightful)
As a dev (and with tons of confidential and privlidged info on my computer) I am specifically instructed to take my notebook home every night. It is considered part of our business continuity plan. Not only that but this is a large multinational corp, not a mom and pop shop. That said, the drive is encrypted, and security policies are in place for communication back to the office when I'm away (2048 bit RSA VPN).
What it boils down to is this:
My employer knows that if I want to steal data I can do it. Even if it comes down to hand transcription of one memorized line of code per day. So they trust me and provide me a hardened notebook to do my work on. Even if it is lost the data will not be compromized till it's likely to be useless anyway.
-nB
Parent
Re:A little epoxy will fix that right up. (Score:4, Interesting)
There is logic in it, if you think about it from a "corporate IT putting out a blanket rule" perspective.
That rule that applies to you also applies to Sharon, a blonde hairdresser by trade who's just taken a second job in the bank to supplement her income.
Sharon has a laptop of her own, and wants to bring it on so she can get on the Internet in her lunch hour - after all, she's not allowed to use company computers for personal web surfing.
Unlike yourself, Sharon's never heard of virus scanning (well, she has, but she was checked by her doctor when she started seeing her new boyfriend, so that's all right). She thinks spyware is the name of the next James Bond film.
Now the bank has a number of business critical systems running Windows. Perhaps unsurprisingly, Auto Update is disabled. This is because, despite Microsoft's best efforts, such updates occasionally break things. Instead, updates are trialled on a test network and then, following a change control procedure, are applied. This procedure takes a while, so at any one time most of the critical Windows systems can be a good few weeks behind on patches. This rises when testing reveals problems, and it rises even further when the system in question was built and maintained by an outside company - their update, assuming they provide one in a reasonable timescale, is subject to the same test requirements and change control as a Microsoft update.
Meanwhile, Sharon's PC, which is swimming in spyware, trojans and viruses, is merrily scanning the network for vulnerabilities.
I don't think I need to spell out the rest...
Parent
Re:A little epoxy will fix that right up. (Score:4, Informative)
rm -rf /lib/modules/2.6.n/kernel/drivers/usb/storage should do it.
Oh, right. Windows.
Parent
Re:A little epoxy will fix that right up. (Score:5, Interesting)
And USB, I think, is only 4 wires... if the plug is epoxied, just open the case and hotwire your own outlet.
Somone else already mentioned installing a 2nd harddrive to copy data. And one could also install a $20 USB/Firewire card in one of the PCI slots.
That leaves filling the whole computer with epoxy. Great, you've turned your PC into a commodore 64. I hope you don't have to fix it!
People just have to accept that if a person has physical access to the machine, they can compromise it.
Parent
Uh, you can turn off USB drive access in Windows.. (Score:5, Informative)
What the article probably meant to say is that sloppy security practices, combined with increasing personal storage, increases the risk of unknown data loss.
You can lock down a Windows box just fine against casual and accidental leaks if you know what you're doing, and you have a corporate policy to enforce. You can even prevent deliberate attempts at data theft, if you really want to be a hardass.
not just USBs.. (Score:4, Informative)
auditing (Score:5, Interesting)
Minox Baby!!! (Score:5, Funny)
Since 3/4 of you aren't going to RTFA... (Score:4, Informative)
So to clue you all in:
The article is not about people stealing sensitive data from their workplace using their USB drives. The article is about people losing data, because they've lost the USB drive they had it stored on.
The real issue leading to confused reporters (Score:4, Interesting)
It all boils down to "Do you trust your employees"?
There are businesses that do, and there are those that don't.
Those that do work on the assumption an employee will not do anything to harm the business intentionally - take a file he is exposed to during work and transfer it somewhere outside the organization.
Hence, it will not take all measures required to prevent him from doing so.
A business that does worry about such things will - What you carry will be checked at the door. Your PC will be locked (the case, physically locked). No Floppy, CD-R, USB, no means to connect media you bring from home. Internet access will be so restricted you wouldn't even be able to encapsulate an SSH tunnel over DNS packets you kindly ask your DNS server/proxy to send for you. And so forth.
Pointing at a business where everyone has web access and a dell sitting on his desk with 2 USB ports looking at him and saying "Hey, this guy can copy a confidential word document on the USB key" is hardly news, doesn't bother anyone in the first type of organization, and usually a non-issue in the second (which would have taken excessive measures to prevent exactly this kind of thing).
Nothing to see here, move along.
To executives, concerned about this: guess what? (Score:5, Interesting)
Guess what the company can do about it? It can stop treating the employees as shit. Especially stop pretending that the company is some amorphous entity that makes its owners/shareholders entitled to profit, and can impose idiotic demands and shitty conditions and pitiful pay on everyone else in it. Employees do their work, this is why they have access to company's things. Nothing, ever, happened in a company without some employees making it happen, so if any of you wonder, why people can destroy your precious company, keep it in minds -- THIS IS BECAUSE THOSE PEOPLE ARE THE COMPANY.
There is nothing wrong with avoiding overbroad access where it isn't necessary for things to work, however there is no way to make any company "secure" from the very people whose only responsibility is to keep things running. Don't piss them off, and remember that you didn't become Presidents, CEOs and VPs by understanding how to operate anything that makes your company what it is. Every time you eat your lunch, think how many people you have abused today, and what will happen if any of them will press a few buttons.
So, disable the USB port (Score:4, Interesting)
* Disconnected the USB ports and,
* Disabled them in the OS and,
* Removed the USB flash device
* Padlocked the case shut.
It takes a few moments per machine and should be part of the standard build for any business that cares about their data.
Re:It's not the theft they're worried about (Score:5, Insightful)
It isn't the theft of data that TFA is really concerend about.
The real threat comes from actual LOST data. With portable storage media getting bigger and bigger, more and more data can be put on it. Including massive amounts of spread sheets and even databases. (I worked for one company that insisted on keeping a sensitive database on USB keys, to be sneaker-netted around to whoever needed it).
Top that off with more and more USB keys floating around the office. Sure, right now, not every employee has one. Or, at best, every employee has just one. But it is becoming more and more prevellant to have "unowned" keys. In other words, a company buys a crapload, and people just grab whichever key is available at the moment to use.
Soon, people will treat USB keys like they treat floppy disks; there'll be a big pile of them, and employees will just grab one as they need it.
Because of this causal attitude towards USB keys, it'll become near impossible to track all the data. Employee X copies Spread Sheet A onto a key, takes it home to work on it, brings it back, and tosses the key back in the pile. You now have an unaccounted for instance of that data. Each time an employee does that, you have more and more instances of data that are unaccounted for.
There's no guarentee that the employee will blank out the key. There's no way of tracking which data is on which key. So an employee might check out a key that has data on it that isn't theirs. There might be hundred of files on the key. Who knows. They don't. They won't care, either. They'll just copy thier files over, work on them, copy them back.
So, each key has tons of data on it. If someone were to ask the CFO "Show me all copies of Sensitive Spread Sheet 5", they couldn't.
Now, one employee checks out a key. They treat it just as casually as they would a floppy disk. They lose it somewhere. (Falls out of their pocket, gets left on the bus, etc). Now, a floppy disk might have just a tiny amount of information on it. A few documents. A couple spreadsheets. A USB key could have an entire database! Someone picks it up, and suddenly has the bank information for all the company's employees...
That's the big issue there. Not that employees will sneak data away on USB keys (though that is a concern, too), but that employees will be too casual with large amounts of data and quite literally LOSE it.
Parent
Re:It's not the theft they're worried about (Score:5, Funny)
Yep. It's in Genesis. Something about a bloody great boat.
What worries me is how far the lesson has been taken. What happens if Him Upstairs has full backups? What if he decides he doesn't like the direction things are going and rolls back to an earlier saved state? How would we ever know if he did?
Parent