Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security Privacy

Computer With UK Bank Customer Data Sold On eBay 184

Walpurgiss tips a BBC News story about a man in Oxford who paid $140 for a computer on eBay, and was shocked to find on it bank records of several million customers of the Royal Bank of Scotland, its subsidiary Natwest, and one other bank. "Mr. Chapman said anyone with a basic knowledge of computer software would have been able to find the data fairly simply. 'The information was in back-up CDs and in ISO files so it would have been possibly quite easy to find...,' he said."
This discussion has been archived. No new comments can be posted.

Computer With UK Bank Customer Data Sold On eBay

Comments Filter:
  • by jkinney3 ( 535278 ) on Tuesday August 26, 2008 @09:27PM (#24759165)
    I bought a pair of SGI Origin 200 machines that contained names, credit cards, and enough data to be a real problem for many thousands of people. The labels on the machines listed them as from @home which had closed their doors. I did the dd if=/dev/zero dance and reinstalled IRIX.
  • Hand it back? (Score:5, Interesting)

    by Mishotaki ( 957104 ) on Tuesday August 26, 2008 @09:46PM (#24759329)

    So in the article, they say that they expect him to hand "it" back.. does that means that the poor guy who paid 77£ to give back the computer for free?

    Personally i'd charge a hefty sum to make them get back that computer, just to make them remember that he paid and he was nice enough to tell them.

  • Re:Hand it back? (Score:4, Interesting)

    by timmarhy ( 659436 ) on Tuesday August 26, 2008 @10:08PM (#24759539)
    i'd charge the pricks a consulting fee for my time. a few grand should cover it. i certainly wouldn't be handing back what is entirely his property, since he purchased it fair and square they have no recourse.

    mind you in his day and age i wouldn't be suprised if he ends up in jail for his honesty, if it was me i wouldn't be saying anything. if i was a more desperate man i might even have sold those details online for a princely sum....

  • Goodwill (Score:5, Interesting)

    by gnu-sucks ( 561404 ) on Tuesday August 26, 2008 @10:09PM (#24759547) Journal

    I bought a sun box at goodwill once and besides an intact customer database for several large companies, it also had the admin's personal backup files, including his "My Documents" folder, his Palm cell phone, and 1200 dpi scans of his passport. Oh, and some file called "passwords.doc". No idea what is in there...

    More details here:
    http://lfnet.net/blog/?p=41 [lfnet.net]

    But yeah... wipe it before you get rid of it.

  • Re:Honesty (Score:5, Interesting)

    by Anonymous Coward on Tuesday August 26, 2008 @10:11PM (#24759561)

    "Always do good. It will gratify some and astonish the rest." ~Mark Twain

  • by PPH ( 736903 ) on Tuesday August 26, 2008 @10:52PM (#24759909)

    Its tough to sell a machine with no O/S on it. Most buyers will take one look at the retail price of XP (for example) and subtract that from their eBay bid. Most sellers are unwilling to risk a complete disk scrub and reinstall. Even if they are, its doubtful that they still have (or ever had) media to do an install on a clean system. The most that the non-tech savvy will attempt is to drag the contents of 'My Documents' to the trash can icon.

    This is an opportunity for a Linux distro. Include an easy-to-use boot/nuke/install mode and offer them to people who put systems up for sale on various web sites.

  • Re:Wait... what!? (Score:3, Interesting)

    by bernywork ( 57298 ) * <bstapleton&gmail,com> on Tuesday August 26, 2008 @11:20PM (#24760141) Journal

    If the machine came in contact with this data, why the drives were even sold is beyond me. The drives should have been removed and run through a shredder / grinder.

    Any machine that contained data or could have contained such as this should have been through a more... robust... decomissioning process.

  • Re:Hand it back? (Score:1, Interesting)

    by Anonymous Coward on Tuesday August 26, 2008 @11:56PM (#24760511)

    Extortion for what? He bought the system and all of the items with it legally. By most laws, that data is physically located on his property, and is legally his to do with what he wants. The inadvertent sale is not his fault; it's pretty much akin (I would think; IANAL) to being sold a house with $25,000 in the attic.

    Which oddly, friends of mine had happen... and they reported and turned it over to the police. If the money has no illegal connections attached to it, it's theirs.

  • by XanC ( 644172 ) on Wednesday August 27, 2008 @12:06AM (#24760619)

    Why would you encrypt when you could just write randomness?

    10 write zeros.
    20 write randomness.
    30 GOTO 10 (as many times as you like)

  • Re:Honesty (Score:1, Interesting)

    by Anonymous Coward on Wednesday August 27, 2008 @01:34AM (#24761237)
    I've a shared $webHosting on bluehost -- i found bunch of text files in /tmp directory with credit card details.
  • by larien ( 5608 ) on Wednesday August 27, 2008 @03:30AM (#24761863) Homepage Journal
    Except it wasn't them who lost the data, although what a 3rd party was doing with all those records I'm not sure.
  • Re:Honesty (Score:2, Interesting)

    by bit01 ( 644603 ) on Wednesday August 27, 2008 @04:15AM (#24762061)

    Kudos for him for speaking up rather than trying to abuse the situation.

    How do you know he didn't make a copy before speaking up? Get the cash and the kudos...

    ---

    Virus scanners don't detect M$ and US government trojans.

The hardest part of climbing the ladder of success is getting through the crowd at the bottom.

Working...