Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Security Privacy

100 Million Victims of Data Theft 115

jcatcw writes "With the latest significant data breach — theft of a Boeing laptop with unencrypted personal information on 382,000 employees — the Privacy Rights Clearinghouse estimates that the total number of data breach victims has passed 100 million since they started tracking in February 2005. The director, Beth Givens, admits 'the number 100 million is largely a fictional number,' but it surely errs on the low side. Since California is still the only state with disclosure laws, incidents are difficult to analyze fully. However, Congress this week passed a bill requiring that the Department of Veterans Affairs report breaches."
This discussion has been archived. No new comments can be posted.

100 Million Victims of Data Theft

Comments Filter:
  • by BadAnalogyGuy ( 945258 ) <BadAnalogyGuy@gmail.com> on Monday December 18, 2006 @01:06AM (#17283246)
    How can you trust the article when they make the outlandish claim that Boeing makes laptops. They make airplanes, silly.
  • by rolfwind ( 528248 ) on Monday December 18, 2006 @01:16AM (#17283280)
    Right now, it's becoming clear to me that the problem is that the weak chain in the link is that the creditors/banks/etcetera consistently rely on a few lines of data to complete transactions and identify the parties involved, 95% of which is publicly available, the other 5% easily stolen.

    I don't know what to do to solve this, any suggestions?

    (Way back when, my friend who worked at a Sam Goody used to actually check credit cards when customers bought something on his first day on the job. After the manager caught wind that he denied someone using their friend's mom's credit card, supposedly with permission, he got yelled at and told not to do it again. I can't help but think that the laws are too lax in this area and the industry has little interest fixing it.)
    • by AoT ( 107216 ) on Monday December 18, 2006 @01:20AM (#17283300) Homepage Journal
      Yeah, there's that problem; and also the fact that it is 100M known victims of identity theft.

      On a side note, why is it that I get all these credit card offers from companies whom already have my SSN, I know you got it guys, and they tell me I'm "pre-approved" for credit, and yet I have to send all this info in?

      Come on big brother! If'n you're going to know everything about me please dont make me fill out all the damn forms in triplicate!
      • From TFA (Score:4, Insightful)

        by AlanS2002 ( 580378 ) <sanderal2@NoSpAm.hotmail.com> on Monday December 18, 2006 @01:37AM (#17283374) Homepage
        Yeah, there's that problem; and also the fact that it is 100M known victims of identity theft.

        From the article: "A stolen laptop at The Boeing Co. has pushed a widely watched tally of U.S. data breach victims past the 100 million mark". Saying that the 100M people are thought to have had data disclosed about them is not the same as saying that 100M people are known victims of identity theft.
        • I was counted twice! (Score:5, Interesting)

          by Aphoric ( 808093 ) <slashdot@jch u l l . com> on Monday December 18, 2006 @01:54AM (#17283422)
          I have been counted at least twice though. I am a veteran and got a letter from the VA with a previous theft, and that was just a few months after I got a letter from Boeing telling me that my info was stolen. Have not heard anything about this latest one, I do appreciate the free credit monitoring I get now, but I am not convinced it would do me any good if someone was really using my info. Plus it is only for one year, that is a relatively short period of time, the info has an unlimited life.
      • by Sycraft-fu ( 314770 ) on Monday December 18, 2006 @05:50AM (#17284284)
        The people who send you preapproved offers have very little info on you, pretty much just name and address. Basically they ask one of the credit reporting agencies for a list of people falling within a given set of criteria. They then send offers to those people. IF you want to take them up you have to give them more info and they get a full rundown of your credit and decide if they still want to give you credit, and if so on what terms (you can be turned down for preapproved cards).

        You can opt out of this if you want, you have to contact the credit bureaus and tell them to quit giving out your info for this and they will.
      • Come on big brother! If'n you're going to know everything about me please dont make me fill out all the damn forms in triplicate!
        many things in life acquire a logic explanation using this axiom: banks want your property, bureaucracy wants your time.
        • many things in life acquire a logic explanation using this axiom: banks want your property, bureaucracy wants your time.

          WTF does a bank want with my property? Don't let's be silly. Banks want your money, not your property. They are, in fact, willing to pay you for your money (this is called "interest" on your savings account or CD). They're also willing to sell you money, at a slight markup, so as to obtain more money; this is known as a "loan".

          But your property? If you've got a foreclosure on your mortgag

          • Federal reserve, BCE... all owned by a network of private banks. They print the money. Normal banks lend each other money, use fractional reserve, (from wikipedia: "Fractional-reserve banking refers to the common banking practice of issuing more money than the bank holds as reserves. Banks in modern economies typically loan their customers many times the sum of all deposits they hold.")

            And money is not backed by gold. Money is essentially paper which is trusted to have value, and those who print this paper
    • Re: (Score:3, Insightful)

      by Anonymous Coward
      I don't know what to do to solve this, any suggestions?

      Do it the same way that you make companies care about any other type of public safety issue. Make it very painful for them if they fail to protect the data. If they lose privacy data they should be completely liable for any damages that occur. A couple of major class action lawsuits and we can make it so that companies won't want to collect privacy data except when absolutely needed.
      • Companies really need to start learning about security. My date of birth is not a good way of identifying me, because it's on the electoral register next to my name, and is publicly available (Gillette did some good marketing with this, sending a free razor to every male as soon as they appeared on it). Similarly, asking my for my mother's maiden name is not secure. Anyone who knows my name and date of birth can get this quite easily.

        One of my banks has quite a sensible system; I select a password, bu

      • Yep, absolutely. This is the way forward, and it's long overdue. Awards of 100% of real damages plus statutory punitive damages of $100 per victim per incident if negligence is demonstrated would do the trick real quick, I'd imagine.

        • by radtea ( 464814 )
          Awards of 100% of real damages plus statutory punitive damages of $100 per victim per incident if negligence is demonstrated would do the trick real quick, I'd imagine.

          Unfortunately, your imagination does not conform to reality. Punitive measures rarely have a dramatic effect on human behaviour.

          This can easily be seen in actual data. Consider the death penalty.

          North Dakota has one of the lowest homocide rates in the U.S. [disastercenter.com] and has not had the death penatly since the 1930's [usask.ca]. The homocide rate in Texas is te [disastercenter.com]
          • For someone so keen on hard evidence, you're making a mighty big jump from what affects individuals who are screwed up enough to kill someone with a firearm and what affects a profit-making business. If you make something painful enough in financial terms, businesses will tend not to do it. Short of making the executives personally liable -- which would be no more constructive anyway by your own argument -- what better incentive would you suggest?

    • by Ajehals ( 947354 ) on Monday December 18, 2006 @01:36AM (#17283372) Journal
      This is an old problem - the banks / merchants etc... want to make it easy enough for you to spend your money or to get credit that you do it on a regular basis. If banks decided to make it harder - in order to increase their / your security / privacy then it means that they lose business, especially if they are the first to do it. Basically they don't mind losing a bit of money to make a lot of money.

      Of course as long as its easy to get hold of your cash or get credit, someone will want to exploit that to get hold of cash or credit in your name. So making it harder to commit fraud or identity theft is really only beneficial to the customer, which in turn means that the only path to making it harder to commit fraud or identity theft is to introduce legislation or regulation to make it happen. That of course is opposed by the banks and merchants (as they lose out) and opposed by the majority of customers as they don't see that there is a problem until it happens to them.

      So yeah, apart from not seeing an easy solution for the banks and merchants, I also don't really see a will to implement any solution which decreases the amount of spending or credit applications, or one that will cost money to roll out (after all most organisations are looking at short term profit not long term strategy's).
    • by bluefoxlucid ( 723572 ) on Monday December 18, 2006 @02:58AM (#17283656) Homepage Journal

      I solved this problem ages ago. Some guy, actually two of them, invented something called the Diffie-Hellman Public Key Encryption Algorithm. Since then we've had dozens of these show up and now have RSA and DSA/ElGamal out there. Pretty much, with huge (1024 byte!) challenges and hardware devices with your key in them, as well as transferable One Time Pads (so you can let someone else use your credit card once, twice, for $5, for $10...), you can make it so everyone along the way can verify your identity and nobody along the way can pretend to be you.

      The system drawn out isn't that complex. It's lazy distributed too; anyone can cache your public key, so anyone can independently verify you over and over again. This means that the store can verify your card isn't a spoofer and not pester the credit card company with it if it is; and if it's not, then the credit card company can also verify your card isn't a spoofer (and that the store isn't sliding in extra charges after you've signed for the price) and not pester the national PKI network with it.

      • The technical merits of public key cryptography are not in question, but rather the understanding of the public with regard to the proper use of these methods is and that is the real difficulty. If you cannot make the system completely workable without any knowledge or understanding on the part of the public then your efforts will fail because average people do not, will not, or cannot understand the basis for public key cryptography enough to be informed users of the system. I have personal experience with
        • you cannot make the system completely workable without any knowledge or understanding on the part of the public then your efforts will fail because average people do not, will not, or cannot understand the basis for public key cryptography enough to be informed users of the system.

          Lock the PubKey in a hardware device (a USB device, really). All transactions have to ping the device. The easiest way to do this would be to embed a small OS (Minix? You could do it in all of 12,000 lines of code probab

    • by Jessta ( 666101 )
      In Australia the shop is liable for credit card fraud. So it is in the shops best interest to make sure that the person making purchases on a credit card are who they say they are.

      The real problem is that the information that identifies you as you is the same information that you give to people to prove that you are you.
      Giving anyone you need to prove your identity to all the information they need to pretend to be you.
      What is needed is something on long the lines of public-private key cryptography.
    • Re: (Score:3, Insightful)

      by dbc001 ( 541033 )
      This is a great point - I get annoyed every time a credit card transaction goes through and I don't have to sign anything. Don't they realize that without a signature there's no way to prove whether the transaction was me or someone else?
      • Yes, they do realize that. The merchant has decided that the convenience of swipe and go will bring in more money than they will lose from reversed charges. For instance, I don't go to gas stations that don't accept credit cards at the pump. I don't want to wait in line to pay behind the idiot buying cigs and the idiot buying lottery tickets when I can go across the street, pay the same amount, and be out in much less time.

        -dave
      • They realise it, they just don't care.

        Typically, the vendor is responsible for the loss if they permit a card transaction and it gets challenged successfully by the card holder. If the vendor doesn't check the signature or PIN properly, it's not going to be the card company's loss.

        The only major exception is if the vendor has correctly followed procedures laid down by the card companies to verify ID (e.g., collecting a signature and checking it against the card, or using the Chip and PIN machine). In th

        • Mod parent up for a very insightful post on the cost and gains of security. too bad I don't have mod points right now.
    • by bl8n8r ( 649187 )
      > I don't know what to do to solve this, any suggestions?

      1) Address the ignorance factor first. Make sure people are aware of the issue of data security and the seriousness of it. Don't assume they automatically know. Explain it to them in a way that is informative and not condescending.

      2) Use a platform designed to keep users in userland.

      3) Setup laptops with encrypted filesystems [0] and encrypted connections [1]. Do not give users administrative access. Re-image [2] system partitions for extra fr
    • by garwain ( 688087 )
      My cards have no signature, but a clearly printed "Check Identification" on the back. I use my VISA almost everywhere, and estimate that I am asked for my licence maybe once a month at the most. A lot of people hang onto the card until I sign the slip, then pretend to look at both, then hand over the card. Then there is the occasional person who has neve heard of doing that. One guy told me that it was illegal to do that, and another refused to process the sale, until I called VISA on my cellphone, to ask i

  • I wish I was the copyright holder, and protected by the applicable laws, of my own personal information.

    • by JoshJ ( 1009085 )
      This actually seems like an interesting idea and potentially a real benefit that could come of the bullshit draconian copyright laws in existence right now. Any lawyers know what's up with this?

      That said I can see the downside, it "legitimizes" even more draconian copyright legislation- instead of relying on "Think of the artists!" they could rely on "Think of the identity thieves!"
    • Re: (Score:1, Troll)

      by IpSo_ ( 21711 )
      I actually have an uncle who copyrighted his name and also became his own "sovereign nation" (or something along those lines) which actually enabled him to skirt many laws in Canada at least. I can't remember the exact name of the "program" he got the information from, something like "In The Truth", but its pretty interesting stuff. The stories he tells are hilarious.

      Stories like fining judges large amounts of money for using his name without permission (it was copyrighted after all) and they ACTUALLY PAID,
      • Hi.

        This must sounds silly, but does your uncle have an email address? If so, could you email it to sollaa@vfemail.net? I would really like to ask him some questions. In particular, I would like more information about this, and intend to contact a Canadian lawyer regarding the legitimacy of such claims. If all this works out, I want to move to Canada.

        I could make a mint on my name, especially in a long, drawn out trial. :-)
      • I actually have an uncle who copyrighted his name and also became his own "sovereign nation"

        I've heard many stories about your uncle, he's the Baron Munchausen [imdb.com], right?

        By obtaining a drivers license you are agreeing to abide by the motor vehicle laws. If you don't have a drivers license and you know what you are doing, they can't touch you for breaking any of the laws

        Your story would go well as a light comedy movie script, but it doesn't stand the hard test of reality. That's not how democracy, or any othe

        • by IpSo_ ( 21711 )
          I figured it was all BS too... Until my uncle started actually doing it.

          Keep in mind I get this information 2nd/3rd hand usually... Take a look at this site explaining how it is done with regards to income tax in both US and Canada:

          http://www.detaxcanada.org/ [detaxcanada.org]

          I just heard another story of my uncle latest adventures... The last three times he has been in court (he defends a bunch of other people as well) he just takes a color laminated photocopy (intended as a copy) of his (or the defendants) birth certificat
    • by drsmithy ( 35869 )

      I wish I was the copyright holder, and protected by the applicable laws, of my own personal information.

      Copyright is fucked up enough already. I shudder to think how legislation trying to do this would make it worse.

      • This could be the way to bring it crashing down.

        Worth a shot, isn't it? What could possibly make it worse?

  • by anilg ( 961244 ) on Monday December 18, 2006 @01:27AM (#17283344)
    That according to http://attrition.org/dataloss/rant/100million.html [attrition.org]
    The Data Loss Database - Open Source has almost 510 events and over 143 MILLION compromised records as of this writing. 100 million? Dudes and dudettes, we had that over six months ago.
  • I have a feeling that more and more reporting on this subject is going to make thieves take a closer look at what they are stealing in future, thus making identity theft a greater possibility.
  • It would seem more logical to just sum up the known figures, and present them along with information about what areas they cover, making it clear they are minimum values. I'm pretty sure those totals would ring the alarm bells just as effectively for those who actually care about it.
  • How much of the information is redundant however? Is it 158 million American's, 158 Million people across the globe, or 30 Million people 5 times over?
  • the strangely named "Privacy Rights Clearinghouse" has just announced that they'll be showing up at one lucky person's house with a giant check with all 100 million pieces of personal data written on it in a really, really small font. I hope I win it!
    • Actually your joke gave me an idea. What they should do is to print out all 100 Million names (not the rest of the info of course ;-) on paper in 12 point type and present it to the new Congress in January. It's easy to quote these huge numbers - 100 Million or a Billion - nobody can really imagine how many that is. Print it out to get an idea how much potential damage we're looking at in the years to come.

      The way things are going, it's just a matter of time until the personal info of anyone connected to th
  • I wonder... (Score:2, Insightful)

    by e-scetic ( 1003976 )

    I never read of anyone having suffered consequences as a result of someone losing their data. Why is that?

    Doesn't it seem as if there would be a few major class action lawsuits, at the very least? You'd think every time data loss occurs on this large a scale, it would be followed by droves of people suffering from identity theft or fraud

    • Re: (Score:3, Interesting)

      by suv4x4 ( 956391 )

      I never read of anyone having suffered consequences as a result of someone losing their data. Why is that?

      Doesn't it seem as if there would be a few major class action lawsuits, at the very least? You'd think every time data loss occurs on this large a scale, it would be followed by droves of people suffering from identity theft or fraud


      You're correct: theft or loss of a machine doesn't automatically mean identity theft.

      First, the machine should be in a working state which is sometimes not the case.
      Then, th
    • Re: (Score:3, Insightful)

      by scdeimos ( 632778 )
      I never read of anyone having suffered consequences as a result of someone losing their data. Why is that?

      Because not many media outlets are interested in reporting on individuals who lose a few hundred dollars when they can throw around figures like 100,000+ victims in a single crime.

  • The director, Beth Givens, admits 'the number 100 million is largely a fictional number,
    I suppose that's better than just tossing out a large, fictional number.
    • by Nymz ( 905908 )
      IANAG (I am not a grammerian) but I think the point of the sentance isn't the size of the number, but it's value or state, and therefore the adverb form was used appropriately.
  • Protect yo'self (Score:3, Informative)

    by jomama717 ( 779243 ) <jomama717@gmail.com> on Monday December 18, 2006 @02:19AM (#17283522) Journal
    A buddy of mine was recently affected by the UCLA breach and was lamenting about all of the precautions and protections he was required to put into place now that his SS# was likely in some scumbag's hands, and it dawned on me that he may have actually gotten lucky. He was awakened to the reality of identity theft without having to experience any tangible loss, and is now motivated to take the proper precautions. It then occurred to me that to not assume that my information was in the wrong people's hands didn't make any sense and I have taken the same precautions my friend did:
    1. Access to my credit report/score
    2. Big 3 credit bureau monitoring - notification of any new accounts or loans in my name
    3. Personal case officer (through the bank) if something happens
    These services can be purchased for anywhere from $5 to $12 a month depending on the bank. I suppose I could still get burned but I can't imagine any of it could hurt, well worth the money at any rate in my mind.
    • by tgd ( 2822 )
      It doesn't feel to you like you're paying protection money to the mob buying those services from your bank? A bank that is part of the problem because like every bank, they'll gladly loan money in your name with little or no verification?

      If they wanted to protect your identity, they'd make it harder to steal. Companies losing personal information aren't the problem, companies who casually take action based on very little information that will impact you when that information is lost is the real problem.
  • First off, the term "identity theft" is completely ridiculous. No one is taking away who you are. Your friends and family won't suddenly forget who you are. A better term would be "credit fraud".

    This is the basic scenario: A criminal poses as you to borrow money (usually with a credit card), and then whoever lent that person the money asks you to repay it.

    Then there are generally 2 consequences for you: debt and reputation damage. The debt itself is usually the lesser of the two problems, since you're not legally obligated to repay money that someone else borrowed in your name. Reputation damage, on the other hand, is incredibly hard to repair. This usually takes the form of erroneous information on your credit report.

    Private agencies (Equifax [equifax.com], Experian [experiangroup.com] and TransUnion [truecredit.com] are the majors in the USA) maintain this information of your past financial transactions, and sell it to potential lenders in the form of a credit report. Lenders then use this information to decide how risky it would be to lend you money. These credit reporting agencies err on the side of over-reporting negative information, because a defaulted loan from an under-qualified borrower costs banks and lenders much more than a qualified applicant being turned away. Additional services (like providing reportees an easy way to correct errors) would cost credit reporting agencies much more than their client lenders would be willing to pay for the increased accuracy, so they don't bother implementing them.

    The short version is that banks and other lenders knowingly rely on imperfect information about potential borrowers, because it is the most economically sensible thing to do. It's not profitable for them to pay for more accurate information. If they decide not to lend you money, even based on erroneous information, it will likely be very hard to change their minds.
    • Yeah, every time this comes up, someone posts to object to the terminology. Face it, ID theft is what we call it even though it isn't literally true. They are, however, eroding your identity with various banks, so it's more accurate that you may think. Anyway, have fun tilting at windmills.
      • "ID theft" is even worse. It makes it sound like someone stole your drivers license so they could buy beer. At least "identity theft" vaguely relates to what's going on.
    • by rastos1 ( 601318 )

      First off, the term "identity theft" is completely ridiculous. No one is taking away who you are....

      If you are not the only one "Jonboy X" that can prove that he is "Jonboy X" than you don't have identity. You are left with plurality at best ;-) You had identity before and now you don't have it anymore. Sounds pretty much like theft to me. Of course it is not only about the name. If someone can succesfully pretend to be you - including your debt history, providing correct address, SSN, CC # and your /.

      • If you are not the only one "Jonboy X" that can prove that he is "Jonboy X" than you don't have identity. You are left with plurality at best ;-) You had identity before and now you don't have it anymore. Sounds pretty much like theft to me. Of course it is not only about the name. If someone can succesfully pretend to be you - including your debt history, providing correct address, SSN, CC # and your /. account ... - how do we know it is you? We don't. You lost your identification.

        It's not so much the "identity" part that strikes me as odd; it's the "theft" part. When someone steals your television, they have it and you don't. When someone "steals" your identity, you still have it because you're still you. It's just that now, someone else has some information that can be used to impersonate you to people who don't check too closely.

        Maybe everyone should periodically be able to buy a public/private cryptographic key pair that can be used to authenticate you. The higher your net w

        • When someone steals your television, they have it and you don't. When someone "steals" your identity, you still have it because you're still you. It's just that now, someone else has some information that can be used to impersonate you to people who don't check too closely.

          I would agree with you if it was about copying data such as software, music, films, etc. But if someone has all the data that identifies you, he can effectively take it away from you. He can change your address so that all your mail goes

        • When someone steals your television, they have it and you don't. When someone "steals" your identity, you still have it because you're still you.

          Except the damage they do de-values you being you. Say you had a great credit score and were about to buy a home. Oops, now you can't get approved for the home loan because of all the black marks on your credit score. Can you honestly say that doesn't make you less valuable?

          People have spent thousands of dollars and years trying to clean up after an identity

    • First off, the term "identity theft" is completely ridiculous.
      Yeah, it should be Identity Sharing.
      • by raynet ( 51803 )
        Or how about Identity Infringement? I googled for Copyright Infringement and got this:

        Copyright infringement occurs when a person copies someone else's copyrighted items without permission. This would also include public display of a copy of copyrighted work.

        After small modification it actually sounds quite ok to me:

        Identity infringement occurs when a person copies someone else's identity without permission. This would also include public display of a copy of identity.

        Ofcourse using that copied identity to
        • Or how about Identity Infringement?
          Or better, Identity Cloning, as in phone cloning. Identity Infringement could be an effect of Identity Cloning, but it isn't the act itself.

          Also the word "cloning" has that nicely sinister sound to it - crazy scientists and their two-headed cows, the word "Attack", etc.
    • by bky1701 ( 979071 )
      "A better term would be 'credit fraud'."

      I much perfer "some-moron-is-buying-stuff-with-my-money-and-i-am -going-to-get-blamed-all-because-some-stupid-compa ny-can't-use-blowfish-i-hate-this".
    • I agree that "identity theft" is an over-used term when "credit fraud" might be a better description in most situations. However, I've heard of "identity theft" that didn't involve credit fraud. During the immigration debate that was going on last summer, I read a story in the newspaper (sorry, don't have a link) about a woman on the east coast who applied for unemployment benefits, but was denied because records showed that she was currently employed somewhere in the midwest. Except, she wasn't working in
    • I work in the financial services industry and I totally agree with the parent post. Banks and credit reporting agencies are doing what is most financially efficient for themselves, which is not reducing errors to zero, but reducing them to a number they can absorb the risk on, while foisting some of that risk on to consumers as well.

      In reality though, 99% of that risk is still on the banks. Most credit card fraud isn't using your personal info to get a mortgage in another state, but simply making some
  • by artifex2004 ( 766107 ) on Monday December 18, 2006 @02:36AM (#17283584) Journal
    The university I graduated from reported someone had hacked in and gotten access to about 6K student and faculty records, including payroll info.
    Their idea of taking care of the problem? Wanting me to register online (!!) or over the phone to be told if I was one of the victims, and also to get a free credit report or get credit monitoring, though they don't seem to think they should pay for that or for any fees I might get if I have been victimized...

    Oh, and I only found out because it was in the local news.
    • Man they are really taking care of business. Is there no liability on their end for not taking the proper measures to at least inform all the victims of the problem?
  • Your User number 100,000,000 Claim your prize by sending in your credit card info as well as full name!!!! Be quick this is a limited time deal!!!!
  • estimated 347 million people are victims of made-up statistics.
  • "...was stolen from an employee's car earlier this month"

    Seriously, who carries around a Laptop with "Personal Information" of 382 Gazillion living, dead and zombie employees in a fscking Laptop and leaves it in a car unattended.

    You would think they would store this information in a so-called safe server somewhere and have policies on not taking them around in Laptops. Why would you need that information on a laptop anyway ? For fsck sake - We're talking about serious personal information!

    I say hire stewie
    • For what it's worth, the data wasn't supposed to be on the laptop and the guy was fired for going against company policy.
  • In this case, we should possess our own personal data, and unauthorized possession should be theft, just like someone broke into your house and stole your computer. I have about 300 GB of storage at home, and I'm quite sure that all the personal information that companies 'own' about me could easily be stored on MY premises.
  • Soon everyone will have been victimized, yes?
  • Stupidity (Score:3, Interesting)

    by Lavene ( 1025400 ) on Monday December 18, 2006 @03:14AM (#17283734)

    A laptop containing the personal information on 382,000 current and retired workers of Chicago-based Boeing Co. was stolen from an employee's car earlier this month, according to Boeing spokesman Tim Neale. He declined to say exactly where the laptop was stolen.
    That really sums it up. You will never ever have better security than what the stupidest person with access to sensitive data can muster. Leaving a laptop with such data unattended in a car??

    You can enforce encryption on every file, strong passwords etc but sooner or later some smuck will print it out and forget to schred the printout when done. So it ends up on some dump available to anyone crawling around looking for something usable.

    Designers of company security forget the most obvious and most dangerous threat: stupidity! My personal favorite quote used to illustrate exactly that is the following:

    When the infamous "ILOVEYOU" email virus hit, I saw TV news coverage that included an interview with some bubblebrained company secretary. At one point she said, "Oh, I saw we had dozens of these emails coming in, and of course I was suspicious, but I had to open just one of them because, you know, 'I Love You!' *giggle* I had to just see what it was about, you know?"
    You can't foolproof a system, you simply need to get rid of the idiots. Which sadly is easier said than done...
  • What are the fines in such situations? This is clearly they fault - the've taken personal data and haven't took enough care of it (in fact they were stupid enough to feed that data into laptop and get it stollen). What does US law says about it? In Poland (European Union) they would face severe consequences.
  • ...their identity stolen? This computer fear thing smacks of the whole terrorism scam. How many people here inside the US have been or know personally someone who has been the victim of terrorism? The media, for whatever reason, seems to want to amp up the fear quotient of this nation. I bet that stolen wallets/physical mail account for ten thousand times more id fraud than any computer activities, yet that doesn't get headlines. Nor does the fact you are more likely to die from an accident in your bat
    • I know several people who have had their credit card numbers stolen. Its actually fairly common and by far the most common form of identity fraud. Why do you think you see so many ads on TV about protection from having your credit card numbers stolen? Its because that shit happens all the time and smart people care a great deal about being protected from it.
      • by b.burl ( 1034274 )
        Seriously? By so called hackers? Or was their mail stolen? And where is the hard data on numbers of police investigations resulting from credit fraud vs numbers of police investigations resulting from credit fraud caused by computer malfeasance? As to why you see it on tv, you see a lot of terrorism stuff (only talking about the US here) and that is virtually unheard of. Paranoia is the life blood of our media.
        • Not hackers so much as Phishers. (I assume you are familiar with this) Huge amounts of money is lost every year by people who submitted their credit card info or paypal password to authentic looking websites. I (and prettymuch everyone I know) routinely get emails from "paypal administrators" or "bank of america customer service" asking for info.

          I have always tried to impress that paranoia you are looking down on onto people I know when it comes to stuff like this. Trusting these spam emails or giving any
  • by RulerOf ( 975607 ) on Monday December 18, 2006 @04:57AM (#17284112)
    Two words: Terminal Server.

    I know it has been asked before, but WHY in the name of GOD does this kind of information need to be on a fucking laptop?!

    My mother works at a VA hospitol and as such, has access to read and modify all the personal information necessary to commit identity theft on thousands of patients, and of course, she has a laptop computer issued by the hospitol so that she can work from afar. When she originally received it, it was nothing more than a Win2k box with VPN software, MS terminal services. All of the sensitive data was/is stored on the servers on their intranet. After a small "upgrade," the laptop was returned, only this time it came back with a full encryption setup. The interesting thing is that there is STILL no sensitive data stored on the laptop. It is, however, just as easily accessible. The point is, if someone stole that laptop, no sensitive data would be compromised, even if the encryption was broken (which probably wouldn't happen).

    I don't fucking understand, why when we have the technology READILY available to completely prevent this kind of crap, that it isn't used. A shout out to all the companies on this planet: Centralize your damned security. Laptops cost $500. This kind of shit publicity and potential lawsuits cost a hell of a lot more.
  • This case would make an excellent case-study for the Vista Bitlocker [wikipedia.org] facility. The cynic in me wonders whether Microsoft may play on this convenient timing.
  • The poster says, "Since California is still the only state with disclosure laws..."

    Been in a cave for the last few years? See http://infosec.uga.edu/policymanagement/breachnoti ficationlaws.php [uga.edu] for information on 34 state breach notification/disclosure laws.
  • The article pertaining directly to Boeing stated the following:

    Although the laptop was turned off and was password protected, Neale said the data on it was not encrypted.

    My point is that how many people know how to access this information, or better yet, know to even look for this type of data on a stolen computer? I can see some kid trying to get into the laptop for a couple of days, and subsequently reformatting the hard drive. I don't want to imply that this information can't easily be compromi

  • number of data breach victims has passed 100 million

    Yes, but, how many are dupes?

  • As of last July, 34 states [pirg.org] had laws requiring consumer notification. Some are triggered directly immediately upon the loss, others only if the data is considered "at-risk". It's hard to take TFA seriously when it can't even get basic facts correct that can be found in less time than it took to write this comment ...

  • by martyb ( 196687 ) on Monday December 18, 2006 @01:19PM (#17289248)

    THE PROBLEM: It is currently financially worthwhile for some companies to play loose with personal information. The perceived costs of the consequences of poor protection are not sufficient to warrant a change in their way of doing business.

    Many merchants / agencies / whatever don't seem to want to provide us additional protections. All it would take is for a few companies who already take security very seriously to sign up for the best star rating listed below, chalk it up to advertising expense, and put the pressure on the other merchants who do not sign up. "Hey! *WE* take your security seriously, and we put our money where our mouth is. If *WE* mess up, we clean it up and pay *YOU* for your inconvenience. Why would you want to deal with anyone else?"

    There is a financial opportunity for an enterprising group to make a fortune here. Existing insurance companies provided graduated coverages and fees depending on certain items. I can select how much liability insurance I want for my car. I can pay the insurance company a larger premium for a greater amount of coverage. Alternatively, if I have certain protective measures in place, then my premiums can be reduced. I choose the level of coverage that works for me.

    whenever there is a security breach, make a payment to each CONSUMER! Get the consumer to be your best ally in getting merchants to sign up for the protection. So, if a merchant compromises the security of MY information, then the insurance company sends ME a check. I'll leave it as an exercise for the reader on how this could be extended to cover other organizations that have access to personal info such as hospitals or government agencies.)

    Also, and VERY important: advertise this feature like crazy - get the consumers to push the merchants to get the coverage along with an easy-to-remember grading scale for consumers to use to assess the degree of protection they are provided by a merchant. It took a few years, but now US car companies are advertising the NHTSA crash test ratings. [dot.gov] I expect the same could work for credit protection.

    NOTE: All dollar amounts are pulled out of a hat. I'm just trying to put something concrete out there to use as a starting point for discussion. Obviously, the size of the covered merchant would affect the premiums and payouts, and I have NOT worked those into these numbers. Please offer improvements! The examples listed here might be appropriate for a moderate to large merchant.

    Have a graduated scale of costs and coverages that depended on what level of security measures were in place at the time of the loss / theft.

    • PROTECTION LEVEL: ONE STAR:
      If a merchant takes no security precautions then the insurance company would:
      • charge high premiums: $10M per year, plus $10 per covered client.
      • require high deductible: $5M deductible (in escrow).
      • provide low payment to each consumer: $100.00 to each consumer.
      • provide limited credit monitoring protection: 6 months of credit reporting agency monitoring.

      The consumer gets some benefits, even if the merchant makes no great effort to protect the user. It's still better than anything that the consumer is now getting. After a few payouts, word-of-mouth will boost interest by consumers in seeking out at lest this minimal coverage. CEOs and CIOs will start to take notice.

    • PROTECTION LEVEL: TWO STAR:
      If a merchant takes certain, documented, security precautions ( encrypted DBMSs, firewalls) then the insurance company would:
      • charge moderate premiums: $5M per year, plus $10 per covered client.
      • require moderate deductible: $1M deductible (in escrow).
      • provide better payment to each consumer: $500.00 to each consumer.
      • provide better credit monitoring protection: 1 year of credit reporting age

Think of it! With VLSI we can pack 100 ENIACs in 1 sq. cm.!

Working...