Category Archives: Security

Disks still not being properly cleaned

I feel like I read a story like this one every year. Someone buys or finds an old hard drive and tries to recover the data. They then manage to expose the fact that people still do not properly erase information on disks before discarding them to the wild:

The research – which was based on 317 computer hard drives obtained from the UK, North America, Germany and Australia – showed just how many people believe in the data fairy: though 41% of the disks were unreadable, 20% contained sufficient information to identify individuals, 5% of the disks held commercial information on organisations ranging in the UK from Man Trucks to Easington Council, and included records of a Children’s Day Care centre.

There was also illegal information with 5% of the disks holding “illicit data” and 1% of the disks bearing paedophile information. As a result, a criminal investigation has been launched in South Wales and another one in Australia.

[…]

Just how compromising and thorough the information stored on computers can be was demonstrated by data obtained from disks belonging to Port Weller Dry Dock, a Canadian ship building company.

On the drives was information that showed the company had details on a bid for the US Navy’s top secret DD21 destroyer programme, part of a US defence programme intended to equip the US navy for the 21st century.

This problem can either get better or worse with the new era of online archive and storage solutions. In other words, people can transfer the issue of handling stored data to a service-based system but can they trust that such a service will do any better job than the companies in this study?

Jon Godfrey, from Life Cycle Services, has a nice quote in the story:

“People get worried about losing data on computers but they don’t realise that erasure is as important as retention. The survey shows that the commercial sector is still chronically ignorant of the destruction and retention of data, and our experience is that the problem is actually worse than the study suggests.”

Actually, studies also show that people do not get worried about losing data. So it is perhaps more accurate to say that people simply do not always understand the risks and/or are unequipped and untrained to handle them.

Correlating AOL search IDs to real people

The NY Times has picked up the AOL fiasco story and brought it home:

A Face Is Exposed for AOL Searcher No. 4417749

Buried in a list of 20 million Web search queries collected by AOL and recently released on the Internet is user No. 4417749. The number was assigned by the company to protect the searcher’s anonymity, but it was not much of a shield.

No. 4417749 conducted hundreds of searches over a three-month period on topics ranging from “numb fingers� to “60 single men� to “dog that urinates on everything.�

And search by search, click by click, the identity of AOL user No. 4417749 became easier to discern. There are queries for “landscapers in Lilburn, Ga,� several people with the last name Arnold and “homes sold in shadow lake subdivision gwinnett county georgia.�

It did not take much investigating to follow that data trail to Thelma Arnold, a 62-year-old widow who lives in Lilburn, Ga., frequently researches her friends’ medical ailments and loves her three dogs. “Those are my searches,� she said, after a reporter read part of the list to her.

I can only assume that the woman who is the subject of this story, as well as the reporter, understand the significance of personalizing the issue.

I can honestly say I am glad I have not been using AOL, although I have nothing to hide. I suppose it is the same feeling as being glad I do not drive cars with exploding tires, even though I consider myself a safe driver.

One of the lessons for AOL will probably be to have a legal, privacy and security approval for any and all data transfers with external entities. I have to believe that their lawyers and security team had no idea that someone was going to post search data for public consumption, and this will probably become a good part of the discussion going forward (if not already).

Multi-hull safety at sea and risk perception

I was asked to represent my local A-Cat fleet this evening at a club race planning meeting, to help bring us into the fold with the other approved one-design classes. It was a surprise to find most of the questions about the A-Cat, and multi-hull racing in general, related to safety concerns.

I had to explain the various risk factors and the safety measures I thought were appropriate for a high-performance ultra-light racing platform. This would have been easier if others sailed the same or even similar type boats, but you might say the difference between an A-Cat and a typical club racer is akin to the difference between a Mosler MT900s and a Toyota Camry. We’ve been sailing enough in local events, fortunately, that the issues were discussed with some real-world examples and in the end the fleet was approved.

People on sailing forums sometimes ask about A-Cat security and here are my thoughts in a nutshell:

I say a good radio, whistle, strobe, water and spare set of goggles/glasses (prescription) are most critical…a wetsuit is also typical gear for us where thicker ones give a fair amount of buoyancy. The way I look at it these basic items significantly reduce personal risk and you could still need them even if you manage to stay with the boat after a spill (torn sail, dismast, etc.). It’s bulky but to keep it nice an tidy (and reduce windage) I always wear a giant rashguard over everything.

And that just takes me back to an old Outside article on how to calculate risks during recreation:

NO WONDER, THEN, that the optimal adventure experience for many enthusiasts is one in which the perceived risk is high but the actual risk is acceptably low. Running rapids is a good example. “People look at big whitewater, and their perception is that it’s very dangerous,” says Pamela Dillon, executive director of the American Canoe Association. “But the stats tell a different tale. In sheer numbers—including canoeists, kayakers, and rafters—the most common way someone dies boating is in a canoe, on flatwater, with no PFD [personal flotation device], drinking alcohol.

“Fifty percent of people who die in canoes and kayaks are out fishing,” Dillon continues. “They’re not tuned in to the skills and information they need to participate safely.”

If there’s just one thing you could say about A-Cat sailors, I think “tuned in” might be it. Here’s Glenn doing a nice fly-by for the race committee (note the flat water):

balance

Happy MS patch Tuesday

Well, twelve patches with nine rated as critical have been officially announced. The list of vulnerabilities is longer than the fixes, so I give MS credit for finding a way to reduce the numbers (ah, the cumulative update). Yet, at least one patch requires a reboot and several deal with exploit code in the wild, so the significance of the vulnerabilities should be reviewed:

Critical

* MS06-040 – Vulnerability in Server Service Could Allow Remote Code Execution
* MS06-041 – Vulnerability in DNS Resolution Could Allow Remote Code Execution
* MS06-042 – Cumulative Security Update for Internet Explorer
* MS06-043 – Vulnerability in Microsoft Windows Could Allow Remote Code Execution
* MS06-044 – Vulnerability in Microsoft Management Console Could Allow Remote Code Execution
* MS06-046 – Vulnerability in HTML Help Could Allow Remote Code Execution
* MS06-047 – Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution
* MS06-048 – Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
* MS06-051 – Vulnerability in Windows Kernel Coul d Result in Remote Code Execution

Moderate

* MS06-045 – Vulnerability in Windows Explorer Could Allow Remote Code Execution
* MS06-049 – Vulnerability in Windows Kernel Could Result in Elevation of Privilege
* MS06-050 – Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution