What Are You Doing With 25 Million Social Security Numbers On Your Laptop?
from the seemed-like-a-good-idea-at-the-time dept
In the never-ending barrage of stories about customer data leaks, one question is never answered: why are people carrying around laptops with so much personal information anyway? As you might expect, the answer's got more to do with laziness and stupidity than anything else. There's really no good reason for people to be carrying all this data on their laptops when it can be more securely held (in theory, anyway) in a central location, and accessed as needed over a network. Of course, all that requires a lot of effort, as does ensuring employees' computers are using encryption and other security techniques, and as long as companies have no incentive to protect customer data, there's little reason for them to go to the trouble, and cost, of actually securing data.






Reader Comments (rss)
(Flattened / Threaded)
Keeping data centralized
[ reply to this | link to this | view in thread ]
Annonomize the data
Much of this information is so easy to anonomize (e.g. Addresses, phone numbers, SSN, etc.). The structure of data is the important thing, not necessarily the content. Take a representative sample of the structure and then put in bogus data. As the OP stated, this is complete laziness and stupidity. It is NOT that hard.
[ reply to this | link to this | view in thread ]
The next big screw up
[ reply to this | link to this | view in thread ]
Fat, bloated and cumbersome
[ reply to this | link to this | view in thread ]
"Silly" status quo is hard to change
I can often get away with making one up. Until organizations change these "just because" default identifiers, I think we will experience more such breaches of information.
[ reply to this | link to this | view in thread ]
Re: Fat, bloated and cumbersome
[ reply to this | link to this | view in thread ]
Re: "Silly" status quo is hard to change
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Obvious
[ reply to this | link to this | view in thread ]
all i have to do is read the paper each day for the 'fuck up du jour", call that company's IT executive (or his new replacement), ask them how many millions of names they need at 1/10 cent per name, and profit...
[ reply to this | link to this | view in thread ]
Re: Re: Fat, bloated and cumbersome
[ reply to this | link to this | view in thread ]
Re: Keeping data centralized
Dealing in information is no different than physical inventory. An employer would fire anyone walking out of the building with selling inventory, no matter what it is. There's no plausible reason for it, unless movement of that inventory has been recorded with the appropriate paperwork. So why is data treated any differently? I can't take home a couple of carons of product to complete my work, why should a guy/gal with a laptop be able to move sensitive data?
Your employer was on top of things - mostly because they had to be. When other businesses have to be, under penalty of huge fines, this problem will be mitigated.
[ reply to this | link to this | view in thread ]
Novel idea... yes, I know.
[ reply to this | link to this | view in thread ]
Re: Re: Fat, bloated and cumbersome
[ reply to this | link to this | view in thread ]
It boggles the mind that the public sector can encrypt and send data on a daily basis that complies with or exceeds DOD standards, but the folks that are entrusted with our most sensitive personal information keep it in a completely insecure database on their laptop with no consideration of those that it will negatively effect.
Why not just put in an archive, encrypt it, and be done? It would be just as easy to access for the end user, but the common thugs that abscond with the laptop that was carelessly left in a vehicle wouldn't be able to access it with ease, due to lack of knowledge.
[ reply to this | link to this | view in thread ]
Not hard to get at all
[ reply to this | link to this | view in thread ]
Look in the mirror, sys admins
[ reply to this | link to this | view in thread ]
Re: "Silly" status quo is hard to change
[ reply to this | link to this | view in thread ]
Re: "Silly" status quo is hard to change
Nitpicking, but Utah doesn't demand you put in on. They can leave the field blank. As I did.
Back to the topic, I think we need a new social number, one that is for the federal government and a citizen only. That could be, you know, secure.
When my healthcare account number is my social security number, it proves we have lost focus of what a social security number is.
[ reply to this | link to this | view in thread ]
what am I doing?
No, really, it comes down to laziness. If I didn't fight and prove that the potential losses would close the business I work for we wouldn't have SafeBoot on our laptops right now. Everyone wants to have the security, but IT is supposed to take care of that. They don't understand it starts with the user being responsible.
Of course, enter the obligatory IT Staff are not responsible for your own stupid carrying of said laptop into areas that are potentially dangerous, such as pool areas, bars, hot tubs, saunas, roof tops, crashing planes, etc., though our users probably think that we are...
[ reply to this | link to this | view in thread ]
almost forgot
WTF? We're not your storage racks; we keep you working!
[ reply to this | link to this | view in thread ]
Re: anonymous coward
[ reply to this | link to this | view in thread ]
Re: Re: "Silly" status quo is hard to change
[ reply to this | link to this | view in thread ]
Shrugged Off
[ reply to this | link to this | view in thread ]
Re: "Silly" status quo is hard to change
Well, thats great, but while you managed to provide yourself a modicum of security, you did it while committing a felony.
Providing a FALSE Soc Sec Num is a felony. Do not do that. Simply refuse to provide it.
[ reply to this | link to this | view in thread ]
Re: Re: "Silly" status quo is hard to change
[ reply to this | link to this | view in thread ]
Add Your Comment