Missing Hard Drive Spurs Data-Theft Fears In Canada
DevNull writes "A government of Saskatchewan (Canada) hard drive has gone missing, and it contains significant personal data - in fact, the government won't even detail what all is contained in it. Read about it from the CBC. So much for people who think the internet is the cause of all their security fears! Identity theft is the major concern at the moment."
B5_geek links to this
report on Bloomberg.com which says that "'[t]he information includes names, addresses, beneficiaries, social insurance numbers, pension values, pre-authorized checking information and mothers' maiden names," according to Co-operators Chief Executive Kathy Bardswick
REGINA - Thousands of Canadians across the country are being cautioned that a computer hard drive missing for two weeks from a Regina office contains their personal data. Saskatchewan government officials fear the data could be misused.
And people give de Raadt a hard time for encrypting the swap file...
Security, security, security, people. It's my (and your) information we're dealing with here. I'd sooner it not be put in the hands of the lowest bidder, Thankyouverymuch.
BD Phone Home!
Shameless plug. Like you weren't expecting it.
I've seen countless things in the news lately, and am really getting the feeling that at some point we are going to *have* to have a global, secure ID. A lot like the SSN's of today for america, but with two parts, one part that is on the internet, and one part on a random number generator of some sort that we keep on our person. That way, the internet information is useless.
Like it or not, at some point it seems like EVERONE's data gets stolen. I'm uber-paranoid about giving my info to anyone, but I KNOW that there is info floating around the internet about me that someone could use to steal my identity. Is anyone working on a two part identity sytem like this that isn't proprietary?
Shawn
Just ask the CIA/FBI/Lawrence livermore cats who couldn't seem to hang onto a laptop from 1996-2000. It's all fine and good if your system is cracker proof, but do try to keep an eye on it.
Software security means squat diddly if someone can just pop the HDD in as a slave.
"Inattention makes clowns of us all" -Bean
The Regina Leader-Post has more info about the hard drives than the Bloomberg article.
Co-operator's is recommending that those affected people monitor their credit report. However this is a new-identity goldmine. Birth Certificates, credit cards, passports, everything. Security experts recommend that people affected change all their bank accounts and credit cards and send letters to government offices, credit card companies and other companies as well.
The drive contained a list of members, the information above and credit card numbers of members of the Co-Operators Life insurance company.
Check out this article (Regina Leader Post).
(OT: Have you noticed that there are more and more threads on Slashdot that has less then 10 comments? Hmmm...)
This is a case where the work has been farmed out to ISM, which is a subsidiary of IBM. It's not the government's fault, but ISM/IBM who are to blame here.
The amount and detail of data makes this a SCARY situation.
It was encrypted, right?
/Applications/Utilities/Disk Copy, clicks File | New | Blank Image and chooses a name for the file, the desktop for its location, and AES 128 for encryption (recommended).
I mean, these days any schmo with an iBook goes
Then just unmount the drive image (drag it in the finder from your desktop to the trash -- which will turn into an eject button) before you leave your computer for the day, or whenever somebody's using it who shouldn't have access to the contents of that drive -- even if they're using your account, cuz' you're letting them sit at your computer.
Double-clicking the drive image prompts for a password (don't check 'save to keyring') before mounting it and once more you're good to go.
You don't even ever have to turn your computer off.
Um, yeah. (Eyes dart around the room looking for a way not to receive a bunch of off-topic downmods. Um....)
Wait! Got it!
"You know, this wouldn't happen if hard-drives were encrypted by default, and the OS needed a password from the HARDWARE (or a hash) such that on bootup if your configuration is different radically from what it was before, your valuable information becomes unreachable.
Oh wait, XP does this already.."
We all know that the real threat is those 31337 skr1p7 k1ddiez and no other threat
At least that is what *they* keep telling us. You do believe them, right?
heh heh
What level of data protection was specified in the contract? It's easy to blame ISM/IBM but I've worked on too many government contracts where the staffing and funding was totally inadequate to do everything the right way.
Mea navis aericumbens anguillis abundat
A large contributing factor to identity theft in the US is the ubiquity of the SSN. Basically, with that and an address, all sorts of bad problems start happening.
/cough)
Seems like a global ID would just be that much worse: a new target that is even better than the SSN in the hands of thieves.
So, I agree with the parent that
Not relying on one single id system is, imho, an important part of protecting your id, because that makes you less vulnerable to id theft.
Yeah, it makes things more complex for govenrments (and even for us poor slobs with more things to remember), but a single target is just too tempting to criminals.
(cough... windows viruses...
Some interesting things have been reported in the media around here. Some have said the data was encrypted, and that it was unlikely that anyone could get the data. If it was encrypted with anything recent, it would be near impossible to get the information off of it. If I were talking to the media and new it was encrypted
It was also mentioned that information was in a database, and the tables couldn't be linked very easily... but who really knows.
Investor's Group has issued this press release stating that Investor's Group client information was also contained on the stolen hard disk. After talking to my local IG representative, I was told the information was used to print monthly statements and included names, addresses, and investment details but did not include Social Insurance Numbers. Sort of scary to hear that information from a variety of different financial institutions was all contained on one hard disk.
Since information on this issue seems to be a bit lacking, I will try and fill in some of the details.
(As was mentioned) the drive was in a secure area of ISM Canada, a division of IBM which provides data services for commercial clients.
Amongs those clients was the Government of Saskatchewan, and a number of provincial agencies.
The province was very forthcoming as to the agencies affected, and which kinds of information was on that particular drive, how many people are affected by each type of informaton, and has made public disclosure very quickly. Most of the government information was encrypted, but not all. For example, the names and addresses, and the electical consumption of customers from the November 2002 bill of an electric utility are there.
Coop Life and Investor's Group are the only two private firms who have admitted to being affected. ISM indicates an undisclosed number of private firms had information on the drive, but none of them have been willing to admit a thing. Investor's group has a bunch of files regarding mutual fund accounts on the drive.
The Government has called on all affected companies to make a public statement and indicate the nature of the infomation on the drive, but has no means to compel them to do so. Thus, they haven't.
Police indicate that based on the information they have from ISM, they do not believe the data can be easily accessed. Obviously, many Slashdotters could pull it off, given a bit of luck. This does imply, though, that we're not talking about Excel spreadsheets here.
An arrest is pending, and the drive has been recovered. Police state there is no indication the person had the means to access the drive's information.
Although time will tell, from the above and other information it appears the drive was taken by an employee or contractor who wanted to pop the "free" HD into his Windows box at home. ISM was in the midst of a hardware upgrade, and the drive was supposed to remain in secure until IT could secure-wipe and dispose of the drive.
The Province has indicated it is talking to it's legal advisers, and is exploring the option of a lawsuit against ISM.