Hacker Detection Firm... Hacked

from the data-compromised dept

You would think, if you're in the "unauthorized computer break-in prevention" business, that you better make damn sure that your systems are pretty well protected -- because you are absolutely going to be a target. However, on top of that, you should probably make sure that your customer records are encrypted and you don't keep information you're not supposed to -- like credit card CVV numbers. Unfortunately, it appears that Guidance Software did none of those things, and is now informing customers that their info had been stolen by hackers. In fact, Guidance didn't even notice the hack until two weeks after it happened, which doesn't bode well for its sales pitch on its new security tools targeted at law enforcement officials.

Reader Comments

Subscribe: RSS

View by: Time | Thread

  1. identicon
    Jared Anderson, 19 Dec 2005 @ 6:01pm

    No Subject Given

    Clearly this company is going to be in business for a long time to come...

    reply to this | link to this | view in thread ]

  2. identicon
    Paul Vogel, 19 Dec 2005 @ 6:20pm

    Prevention Vs. analysis

    It would be even more ironic if they were actually in the hacker prevention business.

    But Guidance is in the computer forensic analysis software business. Their software either runs inside the network you want to protect (the enterprise version) or on a freestanding workstation that requires the physical hard drive from the suspect's machine. No, I don't work for Encase. In fact, my agency pays Encase a lot of money to purchase/license their programs.

    It's almost as good to say "Forensic software company hacked".

    reply to this | link to this | view in thread ]

  3. identicon
    Tim, 19 Dec 2005 @ 8:09pm

    Re: Hacker Detection Firm... Hacked

    That's hilarious...and sad. Add to this the fact that most of their customers knew as much or more than they did about network security and computer crimes...lol.

    reply to this | link to this | view in thread ]

  4. identicon
    Tom Cameron, 19 Dec 2005 @ 8:23pm

    Re: Prevention Vs. analysis

    ...a special thanks goes to Paul and his company for funding this year's christmas, and my summer-of-'06 trip to Italy. Grazie!

    reply to this | link to this | view in thread ]

  5. identicon
    Ryan, 19 Dec 2005 @ 8:30pm

    No Subject Given

    Yeah, I just saw a commercial for (I think it was) AOL. It was like "we protect you from hackers." I was all, "shyah right! Some happy little company like AOL is going to keep my safe from determined and clever hackers. Right." This story proves my case.
    I think it's hilarous.

    reply to this | link to this | view in thread ]

  6. identicon
    Andrew Strasser, 19 Dec 2005 @ 9:03pm

    Every move like chess

    A hacker has you mated before you start.

    reply to this | link to this | view in thread ]

  7. identicon
    s, 20 Dec 2005 @ 2:33am

    No Subject Given

    Doesn't bode well at all... hehe

    reply to this | link to this | view in thread ]

  8. identicon
    Thomas, 20 Dec 2005 @ 8:33am

    Re: Prevention Vs. analysis

    Well...your right about them being a computer forensic company, but they also state the following on their website:

    Most companies have sophisticated intrusion detection systems, but without a reasonable plan to address security breaches, the number of alerts is overwhelming. We don't think you should have to pick and choose which issues to address; we think every significant event demands attention. That's why we built EnCase® Enterprise software to provide a complete and automated incident response capability, able to fully integrate with your alerting systems, automating response, data analysis and remediation across your entire enterprise. And better still, EnCase Enterprise can do it live, while the network is up and running. Now you're covering more ground, quickly, with little or no disruption to your organization.

    So it would seem they did not use their own products at all or they just don't work.

    reply to this | link to this | view in thread ]

  9. identicon
    Fred, 20 Dec 2005 @ 3:13pm

    Re: Prevention Vs. analysis

    Maybe the IDS did not go off? That statemnent says it integrates with the alerting systems. They are not an alerting system.

    reply to this | link to this | view in thread ]

Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Use markdown for basic formatting. HTML is no longer supported.
  Save me a cookie
Follow Techdirt
Techdirt Gear
Show Now: Takedown
Report this ad  |  Hide Techdirt ads
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Chat
Report this ad  |  Hide Techdirt ads
Recent Stories
Report this ad  |  Hide Techdirt ads


Email This

This feature is only available to registered users. Register or sign in to use it.