Hacker Detection Firm… Hacked

from the data-compromised dept

You would think, if you’re in the “unauthorized computer break-in prevention” business, that you better make damn sure that your systems are pretty well protected — because you are absolutely going to be a target. However, on top of that, you should probably make sure that your customer records are encrypted and you don’t keep information you’re not supposed to — like credit card CVV numbers. Unfortunately, it appears that Guidance Software did none of those things, and is now informing customers that their info had been stolen by hackers. In fact, Guidance didn’t even notice the hack until two weeks after it happened, which doesn’t bode well for its sales pitch on its new security tools targeted at law enforcement officials.

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Hacker Detection Firm… Hacked”

Subscribe: RSS Leave a comment
Paul Vogel says:

Prevention Vs. analysis

It would be even more ironic if they were actually in the hacker prevention business.

But Guidance is in the computer forensic analysis software business. Their software either runs inside the network you want to protect (the enterprise version) or on a freestanding workstation that requires the physical hard drive from the suspect’s machine. No, I don’t work for Encase. In fact, my agency pays Encase a lot of money to purchase/license their programs.

It’s almost as good to say “Forensic software company hacked”.

Thomas says:

Re: Prevention Vs. analysis

Well…your right about them being a computer forensic company, but they also state the following on their website:

Most companies have sophisticated intrusion detection systems, but without a reasonable plan to address security breaches, the number of alerts is overwhelming. We don’t think you should have to pick and choose which issues to address; we think every significant event demands attention. That’s why we built EnCase? Enterprise software to provide a complete and automated incident response capability, able to fully integrate with your alerting systems, automating response, data analysis and remediation across your entire enterprise. And better still, EnCase Enterprise can do it live, while the network is up and running. Now you’re covering more ground, quickly, with little or no disruption to your organization.

So it would seem they did not use their own products at all or they just don’t work.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...