NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
Non-Encrypted Hall of Shame
print the content item {PDF=create pdf file of the content item^plugin:content.54}
in General IT Security > Non-Encrypted Hall of Shame


September 29, 2006 - Asheville Citizen-Times
North Carolina Department of Transportation, Division of Motor Vehicles (DMV) – a computer containing personal information on 16,000 drivers license applicants was stolen from a Louisburg, NC DMV office earlier this month. The information on the computer contained Social Security numbers, birth dates and drivers license numbers. In an odd statement Louisburg police detective Jason Abbott said the thieves probably sought the computer to make counterfeit drivers licenses, rather than to commit financial fraud. Other than under-age drinking exactly what does the detective think the drivers licenses will be used for? With this type information thieves can easily obtain credit cards in their name and with a fake drivers license can setup bank accounts, cash checks, etc. One certainly doesn't hope the licenses will be used for under-age drinking but the alternatives are very bad as well. DMV spokeswoman Marge Howell claims the personal information is not easily accessible. Why do they always say that? Five minutes on certain IRC channels will find someone that would purchase the data and unless its encrypted I guarantee it would be easily accessible to them. btw; there is no indication that the data was encrypted.


September 26, 2006 – ComputerWorld
General Electric (GE) - a company laptop containing the names and Social Security numbers of 50,000 current and former employees was stolen in early September from a locked hotel room. No information as to why this data was on the laptop. GE did state that the employee who had the laptop stolen from them was not fired. Apparently the data on the laptop was not encrypted.

No Longer Supported


September 25, 2006 ColoradoDaily.com
Colorado University's Leeds School of Business - Two laptop computers containing the personal information and Social Security numbers of nearly 1,400 CU-Boulder students were lost or stolen. The two computers disappeared while the school was moving to a different campus building on August 28th. No data encryption mentioned therefore it is doubtful the student's data was protected.


September 22, 2006 – MSNBC.COM
United States Commerce Department – 1,137 laptops have been lost or stolen at the Commerce Department in the last 5 years. Of those at least 246 contained Personal Identity Information (PII) (new government buzz term for your private information). Most of these laptops belonged to the Census Bureau and were used for data collection in the field. Its actually quite understandable that some of the 30,000 laptops they use would disappear (though 1 out of 30 seems high). Commerce Secretary Carlos M. Gutierrez said in their press release that "All of the equipment that was lost or stolen contained protections to prevent a breach of personal information" and apparently some of the PII data was encrypted. We sent a message to their office (that was read) on September 22nd asking if all devices containing PII data were encrypted. But as of September 27th we have not received a reply. Therefore until we hear from them their name goes on the list. The Census Bureau says that they have been adding encryption to all new laptops since 2001 but they still report that 139 of the missing or stolen laptops "were either partially encrypted or had no encryption". We do applaud the Commerce Department, and the Census Bureau in particular, for their recent efforts to improve the situation by encrypting new portable computers.


September 16, 2006 – Law.com
Howard, Rice, Nemerovski, Canady, Falk & Rabkin – A laptop owned by an employee of the accounting firm Morris, Davis & Chan in Oakland was stolen from the auditor's locked car in a public parking lot. The laptop contained the names and social security numbers of as many as 500 current and former employees of Howard, Rice, Nemerovski, Canady, Falk & Rabkin. The information on the computer had not been encrypted but had been password protected. But as said here many times just using a operating system password is almost useless since it is child's play to circumvent. Good encryption is next to impossible to break. If a company turns over senstive data to a third party, even auditing companies, they should be requiring the use of data encryption to protect that data. Responsibility does not end at the front door. This is a law firm after all, they should be able to write up a simple contract clause. Auditing firms have been burned on this a number of times lately and still apparently have not gotten the message.


September 16, 2006 – Detroit Free Press
Michigan Department of Community Health (MDCH) – An unencrypted USB flash drive was stolen from MDCH that contained the personal information on more than 4,000 current and former Michigan residents participating in a medical research study. The USB drive contained the names, current addresses, telephone, Social Security numbers and birth dates of the people participating in the study. The information did not include any health information, medical records or laboratory information The study was tracking the long-term effects of exposure to high levels of polybrominated biphenyls, a flame retardant that got mixed into cattle feed in the 1970s and was ingested by Michiganders in beef and milk. Apparently the data was not encrypted.


September 13, 2006 – WISCTV.COM
American Family Insurance – Computers containing personal information on 2,089 customers was stolen from an American Family Insurance office on July 10th. The company started mailing out notifications to customers on Sept. 8th, apparently after a 45 day notification deadline under state insurance law. One of the stolen computers contained customer Social Security numbers, driver's license numbers, and the customers address. American Family said that most of its agents keep personal customer information on laptop computers and that they are now looking in to technical means to protect that information. So in short all of the laptops currently in use by American Family Insurance Agents are not protected and the data is not encrypted. A privacy disaster waiting to happen.


September 11, 2006 – Pionner Press
University of Minnesota – Two computers were stolen from the University of Minnesota's Institute of Technology that contained personal information on over 13,000 students. Information included names, birth dates, addresses, phone numbers, the high school they attended, student identification numbers, grades and test scores, and academic probation. The computers also contained the social security numbers of 603 students. The computers were stolen in August from the desk of the program coordinator. University officials did not know why the data was stored on the computers' hard drives rather than on the physically secured servers. When the department director was contacted by the news media all she could say was 'it's just really been a bad day,' before hanging up. No sign of data encryption.


September 1, 2006 – Chicago Tribune
City of Chicago - Personal data for more than 38,000 city of Chicago employees and retirees was on a laptop computer that was stolen from a company that provides retirement savings program services to the city employees. The city of Chicago said a laptop computer was stolen in April 2005 from the home of an employee who works for Nationwide Retirement Solutions, a Columbus, Ohio-based company. The laptop contained names, addresses, phone numbers, birth dates and Social Security numbers. The city of Chicago was not notified of the theft until July of 2006, over a year after the theft. This obviously is unsatisfactory. The company also said there was little to worry about because "the laptop was protected by a complicated password". Using only the operating system password to protect individuals personal data is also unsatisfactory, it should have been protected with strong encryption.


article index
page 1 : March 2007 to Present
page 2 : February 2007
page 3 : January 2007
page 4 : December 2006
page 5 : November 2006
page 6 : October 2006
page 7 - current : September 2006
page 8 : August 2006
page 9 : July 2006
page 10 : Prior to July 2006
Translate to: {GOOGLETRANS}
Google Ads




Headlines

»CVE-2007-6761
drivers/media/video/videobuf-vmalloc.c in the Linux kernel before 2.6.24 does not initialize videobu ...
»CVE-2010-1776
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod t ...
»CVE-2010-5321
Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6 ...
»CVE-2010-5329
The video_usercopy function in drivers/media/video/v4l2-ioctl.c in the Linux kernel before 2.6.39 re ...
»CVE-2011-3428
Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary c ...
»CVE-2011-3438
WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash ...
»CVE-2013-7463
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and ...
»CVE-2014-9654
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014- ...
»CVE-2014-9680
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo fi ...
»CVE-2014-9907 (imagemagick)
coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS f ...
»CVE-2015-0104
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration ...
»CVE-2015-0107
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration ...
»CVE-2015-1521
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet ...
»CVE-2015-1522
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a pack ...
»CVE-2015-7245
Directory traversal vulnerability in DLink DVGN5402SP with firmware W1000CN00, W1000CN03, or W2000EN00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.


Date published: 2017-04-25T00:00:01Z
Details

»Drupal Releases Security Updates
Original release date: April 19, 2017 Drupal has released an advisory to address a vulnerabil ...
»Cisco Releases Security Updates
Original release date: April 19, 2017 Cisco has released updates to address several high-impa ...
»Mozilla Releases Security Updates
Original release date: April 19, 2017 Mozilla has released security updates to address a vuln ...
»Google Releases Security Updates for Chrome
Original release date: April 19, 2017 Google has released Chrome version 58.0.3029.81 for Win ...
»VMware Releases Security Updates
Original release date: April 18, 2017 VMware has released security updates to address vulnera ...
»Oracle Releases Security Bulletin
Original release date: April 18, 2017 Oracle has released its Critical Patch Update for April ...
»Microsoft Addresses Shadow Brokers Exploits
Original release date: April 15, 2017 | Last revised: April 17, 2017 The Microsoft Security R ...
»VMware Releases Security Updates
Original release date: April 14, 2017 VMware has released security updates to address a vulne ...
»ISC Releases Security Updates for BIND
Original release date: April 12, 2017 The Internet Systems Consortium (ISC) has released upda ...
»Apache Software Foundation Releases Security Updates
Original release date: April 12, 2017 | Last revised: April 18, 2017 The Apache Foundation ha ...


Date published: not known
Details

»VB2016 paper: Debugging and monitoring malware network activities with Haka
In their VB2016 paper, Stormshield researchers Benoît Ancel and Meh ...
»VB2017: a wide ranging and international conference programme
We are proud to announce a very broad and very international progra ...
»John Graham-Cumming and Brian Honan to deliver keynote addresses at VB2017
Virus Bulletin is excited to announce John-Graham Cumming and Brian ...
»Virus Bulletin says a fond farewell to John Hawes
As VB's COO John Hawes moves on to new challenges, the team wish hi ...
»VB2016 paper: One-Click Fileless Infection
Symantec researchers Himanshu Anand and Chastine Menrige explain ho ...
»Mostly blocked, but still good enough: Necurs sending pump-and-dump spam
The Necurs botnet has started sending pump-and-dump spam. Almost al ...
»Why the SHA-1 collision means you should stop using the algorithm
Realistically speaking, if your software or system uses the SHA-1 h ...
»VB2017 Call for Papers: frequently asked questions
The call for papers for VB2017, which takes place 4 to 6 October i ...
»Throwback Thursday: Michelangelo - Graffiti Not Art
This week marked the 25th anniversary of the trigger date of the in ...


Date published: not known
Details
Main Menu
· Home
Current Security News
 
US-CERT Current Activity

» Drupal Releases Security Updates
[19 Apr 2017 06:17pm]

» Cisco Releases Security Updates
[19 Apr 2017 06:14pm]

» Mozilla Releases Security Updates
[19 Apr 2017 06:04pm]

» Google Releases Security Updates for Chrome
[19 Apr 2017 06:02pm]

» VMware Releases Security Updates
[18 Apr 2017 02:34pm]

» Oracle Releases Security Bulletin
[18 Apr 2017 02:30pm]

» Microsoft Addresses Shadow Brokers Exploits
[15 Apr 2017 07:09pm]

» VMware Releases Security Updates
[14 Apr 2017 04:13pm]

» ISC Releases Security Updates for BIND
[12 Apr 2017 08:19pm]

» Apache Software Foundation Releases Security Updates
[12 Apr 2017 12:11pm]

***
US-CERT Alerts

» TA17-075A: HTTPS Interception Weakens TLS Security
[16 Mar 2017 06:40am]

» TA16-336A: Avalanche (crimeware-as-a-service infrastructure)
[30 Nov 2016 10:00pm]

» TA16-288A: Heightened DDoS Threat Posed by Mirai and Other Botnets
[14 Oct 2016 05:59pm]

» TA16-250A: The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations
[06 Sep 2016 04:29pm]

» TA16-187A: Symantec and Norton Security Products Contain Critical Vulnerabilities
[05 Jul 2016 08:50am]

» TA16-144A: WPAD Name Collision Vulnerability
[23 May 2016 05:38am]

» TA16-132A: Exploitation of SAP Business Applications
[11 May 2016 05:31am]

» TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
[14 Apr 2016 01:48pm]

» TA16-091A: Ransomware and Recent Variants
[31 Mar 2016 04:00pm]

» TA15-337A: Dorkbot
[03 Dec 2015 04:40pm]

***
Computerworld Security

» Customers roast Microsoft over security bulletins' demise
[24 Apr 2017 12:49pm]

» Researchers remotely kill the engine of a moving car by hacking vulnerable car dongle
[24 Apr 2017 10:54am]

» Russian man receives longest-ever prison sentence in the U.S. for hacking
[24 Apr 2017 09:17am]

» FAQ: What is blockchain and how can it help business?
[24 Apr 2017 04:01am]

» There's now a tool to test for NSA spyware
[22 Apr 2017 05:43am]

» Hackers use old Stuxnet-related bug to carry out attacks
[20 Apr 2017 02:57pm]

» Developer lifts Windows 7's update blockade with unsanctioned patch
[20 Apr 2017 02:28pm]

» DHS's ICS-CERT warns of BrickerBot: IoT malware that will brick vulnerable devices
[19 Apr 2017 09:21am]

» Experts contend Microsoft canceled Feb. updates to patch NSA exploits
[18 Apr 2017 02:06pm]

» How one personal cyber insurance policy stacks up
[18 Apr 2017 05:00am]

» IDG Contributor Network: Most of the Windows zero-day exploits have already been patched
[17 Apr 2017 01:46pm]

» Microsoft confirms it's patched most of the NSA's Windows exploits
[17 Apr 2017 01:05pm]

» 1,175 hotels listed in payment card breach of Holiday Inn parent company
[17 Apr 2017 11:11am]

» Profiling 10 types of hackers
[17 Apr 2017 05:00am]

» An introduction to six types of VPN software
[15 Apr 2017 04:44pm]

***
Microsoft Security Advisories

» 3123479 - SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[14 Mar 2017 11:00am]

» 4010983 - Vulnerability in ASP.NET Core MVC 1.1.0 Could Allow Denial of Service - Version: 1.0
[27 Jan 2017 11:00am]

» 3214296 - Vulnerabilities in Identity Model Extensions Token Signing Verification Could Allow Elevation of Privilege - Version: 1.0
[10 Jan 2017 11:00am]

» 3181759 - Vulnerabilities in ASP.NET Core View Components Could Allow Elevation of Privilege - Version: 1.0
[13 Sep 2016 11:00am]

» 3174644 - Updated Support for Diffie-Hellman Key Exchange - Version: 1.0
[13 Sep 2016 11:00am]

» 3179528 - Update for Kernel Mode Blacklist - Version: 1.0
[09 Aug 2016 11:00am]

» 2880823 - Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate Program - Version: 2.0
[18 May 2016 11:00am]

» 3155527 - Update to Cipher Suites for FalseStart - Version: 1.0
[10 May 2016 11:00am]

» 3152550 - Update to Improve Wireless Mouse Input Filtering - Version: 1.1
[22 Apr 2016 11:00am]

» 3137909 - Vulnerabilities in ASP.NET Templates Could Allow Tampering - Version: 1.1
[10 Feb 2016 11:00am]

» 2871997 - Update to Improve Credentials Protection and Management - Version: 5.0
[09 Feb 2016 11:00am]

» 3118753 - Updates for ActiveX Kill Bits 3118753 - Version: 1.0
[12 Jan 2016 11:00am]

» 3109853 - Update to Improve TLS Session Resumption Interoperability - Version: 1.0
[12 Jan 2016 11:00am]

» 2755801 - Update for Vulnerabilities in Adobe Flash Player in Internet Explorer and Microsoft Edge - Version: 53.0
[05 Jan 2016 11:00am]

» 3057154 - Update to Harden Use of DES Encryption - Version: 1.1
[08 Dec 2015 11:00am]

***


***
Network World Security

» Customers roast Microsoft over security bulletins' demise
[24 Apr 2017 03:57pm]

» 7 patch management practices guaranteed to help protect your data
[24 Apr 2017 02:59pm]

» More Windows PCs infected with NSA backdoor DoublePulsar
[24 Apr 2017 08:50am]

» Bring Your Own Authentication is upending online security practices
[24 Apr 2017 08:37am]

» Fight firewall sprawl with AlgoSec, Tufin, Skybox suites
[10 Apr 2017 04:32am]

» Review: Canary Flex security camera lives up to its name
[24 Mar 2017 07:01am]

» Smackdown: Office 365 vs. G Suite management
[16 Mar 2017 07:01am]

» Zix wins 5-vendor email encryption shootout
[13 Mar 2017 04:00am]

» Review: vArmour flips security on its head
[06 Mar 2017 03:50am]

» 5 open source security tools too good to ignore
[21 Feb 2017 07:12am]

» Review: Samsung SmartCam PT network camera
[15 Feb 2017 07:00am]

» Review: Arlo Pro cameras offer true flexibility for home security
[09 Feb 2017 07:01am]

» Face-off: Oracle vs. CA for identity management
[26 Jan 2017 10:30am]

» 7 patch management practices guaranteed to help protect your data
[24 Apr 2017 02:59pm]

» More Windows PCs infected with NSA backdoor DoublePulsar
[24 Apr 2017 08:50am]

***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}