WiFi Exposes Sensitive Student Data
cfarivar writes "'Like leaving a vault open, the Palo Alto Unified School District failed to place a number of highly sensitive computer files containing student information in a locked location on its network. Using a laptop with a wireless card outside the district's main office, the Palo Alto Weekly gained access to such data as grades, home phone numbers and addresses, emergency medical information complete with full-color photos of students and a psychological evaluation."
It's time to introduce some level of legal accountibility for institutions which allow sensative data to be stolen.
The simple truth here is that pointy-hairs and beaurocrats understand one thing: Money. If you threaten to kick them in their budget, they'll respond; otherwise, you'll just keep seeing these articles.
I mean, this is *negligence* or the sort that could easily result in at least a major violation of privacy, or at worst a stolen identity or blackmail. These institutions with faulty IT -- and it's not as if this was some complex cracking job, this is just carelessness -- need to be taught a serious lesson.
(shakes head) It kills me that a college can lose piles of cash for buying shoes for one of their basketball players and a business can get fined for having workers like a box that's 5 lbs. too heavy, but when they expose the private, valuable data of their students/customers, there's no sanction whatsoever....
Every year during my review, I just pray the words "slashdot.org" aren't mentioned.
Well, given that it's a newspaper that found this, I can't see that there'll be a big problem as far as non-disclosure on this one. Not to mention the fact that it's been posted to slashdot of course :-)
On a side note, could the newspaper be held liable for this, given that they were intruding on the network without permission? If the newspaper gets screwed over this, it could generate some much-needed publicity and the following public backlash over this BIG problem in the current internet legal scene (namely that if someone finds an insecure network, they usually can't disclose it without getting whacked. Sometimes even if they only tell the company concerned, the company fixes it and then whacks them).
This just goes to show we have a lot more to learn about wirless technology. To a lot of people it may seem like simple common sense to use WEP or some other serious form of protection for sensitive records like that. But getting wiresless is becoming just as easy as getting a cable modem hooked up so more people are doing it at a faster rate and not researching the risks that come with it.
I read an interesting (all be in short) article not too long ago about the risks that does a nice job of explaining things.
Of course, they might just be declared enemy combatants and all this silly due-process thing could be avoided...
Every year during my review, I just pray the words "slashdot.org" aren't mentioned.
From the article, it almost sounds as though it was a wide open access point (no WEP encryption or MAC filtering). If this is the case, there should be no demonizing WiFi - just a sloppy sysadmin.
...that they can "crack" into a school district computer and no one blinks an eye. But the moment a student would try the same thing, he would be expelled.
Jason Lotito
Check out what the person in charge at the school said:
"I don't see this as such a huge news story," Superintendent Mary Frances Callan said the day after the district office abruptly shut down its wireless network and student information program. The real news, she added, was the great progress the district has made to its network plans, thanks to new software purchases, planned employee training sessions and the technology-use policy.
She has absolutely no sense of responsibility of the damage she could have/has caused. Money is the only thing that will get them to take notice.
The same information was also accessible to individuals using district computers within school sites.
This case shows who or what department that was incharge had concrete policy with regards to information and IT security.
Security was fundamentally flawed, little or no security mechanisms in place, even lan connections had access to the files! Wireless connection only exacerbated the situation.
The newspapers never admitted to stealing the Watergate documents. They at least claimed that the documents were stolen by an anonymous informant. This case is different, because the paper admits to committing the felony itself, not through an anonymous informant.
I see no reason to hold this paper to any different of a standard than Kevin Mitnick. Personally I'd like to see all hackers pardoned, but until then the law is the law.
This is a general network security issue.
Confidential data needs to have strictly managed flows and storage. It'd worrying enough that this information could be accessed anywhere on campus even without the wireless threat.
When it comes to something like a psych evaluation I cant see why that information isn't kept 'offline' or on a small secured network. There is *no* justification even for allowing all staff members direct access to this sort of thing - it's ripe for abuse. I also cant see any reason why you'd need access to such a report instantly.
This is probably offtopic, but how did he get caught? Did they track him down via his MAC? Was he doing something mischievous?
Things like this bother me. Its getting to the point where if you have a laptop and you're outside or if you're on a cablemodem doing something other than web surfing, you're going to get arrested. The media isnt helping the witch hunt. Uninformed press always make things seem worse than they are just to boost sales and preserve position.
This takes the cake: "I don't see this as such a huge news story," Superintendent Mary Frances Callan said ...
'nough said.
I'm a district over from Palo Alto, and it's not surprising to me that the wifi was open. That SasiXP and server shares were open is frightening. But this is what happens when parents are allowed to come in and run roughshod over the plans of the admins. Or when random parents are your admins. Palo Alto has tech people, they should get in trouble for leaving things unsecure, but the parent group that came in and blew a big hole in the existing security needs a solid slap on the knuckles too.
The tech staff that school have are usually underpaid and overworked, or contractors who are juggling the detail of 10-15 districts. I'm still cleaning up from the last time parents got involved, getting everyone connected to the internet.
To every tech minded parent out there: don't give us your used crap, don't come in and 'help,' just stay out of the way. We have a clue (well a lot of us do), but we spend 98% of our time cleaning up the messes left by helpful parents, clueless teachers, and malicious kids. We're trying to get the teachers up to speed, and we're working on making it hard for the kids to purposefully or accidentally fsck things up. But parents are totally deaf to the idea that the help they're offering is really hindering things.
How do you tell someone who wants to help, no. Or better yet, what's a good project to let parents feel good about helping without damaging my network, or my systems?
CIA Industries - Running the world for fun and profit
DAs know better than to wreck perfectly good laws they can use for selective prosecution by going after popular prey.
With pictures and family contact information, e.g., the names of the parents or relatives authorized to pick up the child at school, identity theft is nothing compared to the other abuses that are possible.
E.g., a pedophile could go "shopping" for a victim, then use the information in the file to convince the kid that a trusted adult sent them to pick them up.
Or they could be even more aggressive and add an alias to the list of people authorized to pick up the kid at school. Then they show up and breeze past security that would normally extend from classroom to doorstep.
For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken
"Andrew Hannah, a network administrator for the district, admitted security was an afterthought when the first open wireless networks were installed at the Jordan and Jane Lathrop Stanford middle schools and the district office between 2000 and 2002."
This is the problem with DeVry's, et al, ginning millions of Win32-morons out into the world of computer administration. You get a bunch of clownpunchers who know how to press shiny buttons but who don't have a clue about the underlying principles (and responsibilities) of the computer networks they are in charge of administering.
Mod me troll, but I'm tired of the polluted job market, and absolutely sick to death of cleaning up the puke left behind at countless small companies by these nimrods.
I have something in common with Stephen Hawking...
In all honesty, we shouldn't have legislation for data leaks and the such. Let's say Joe sysadmin sets up a WiFi network. Joe sysadmin locks down said network, board has difficult time accessing network and "orders" John netadmin to reduce the security and make it more "ease of use-ish." Now in the normal IT world there positions aren't filled with morons. In the educational system where tech jobs are filled @ $5.15 an hour, you have the soccer coach, or the part-time janitor doing IT work. Holes open up, since the net/sysadmin knows nothing of what they're doing, they get by.
The question is, would the hole have been discovered? Generally the answer is no, people don't always go looking for security exploits. Hehe, if I had WiFi when I was in HS, I'd be happier about that than anything. It makes me ponder if the news didn't try and get in, would someone have?
I've also worked for the school IT department at my university but quickly quit when I realized the average intelligence around is no higher than a walnut. The one thing I know however, is we don't want the government responsible for private information. Next thing we know is the government pushing DRM and all that other crap.
Hmmm, IANAL, but in most areas, isn't doesn't this fall somewhere under electronic tresspass, or electronic wiretap. Like, accessing a computer system that isn't yours and that you weren't authorized to access? Sounds like not only an admission of guilt, but them bragging about it..
Of course, press like this is rarely very good. It's enough to scare lots of people away from new technologies.. I'd be surprised if someone doesn't make a push to bring them back down to paper files for everything.
Serious? Seriousness is well above my pay grade.
Breach of security in regards to medical and psychological data under the schools care, which was known about but not acted on for 9 months? Sounds like some parents are going to get rich quick. Bring on the law suits.
The attitude of the schools staff appalls me; sounds like the poor admin can't even do his job as everything needs to be rubber stamped before it can go in effect. And since when do they think that by securing the perimeter of the network does it make the files any more secure.
GPLv2: I want my rights, I want my phone call! DRM: What use is a phone call, if you are unable to speak?
From reading the article, it looks like they didn't even bother using WEP
Aside from the fact that WEP is breakable and thus useless, if they had used WEP (and it wasn't broken) the data still would have been accessible to the legitimate wifi users (unless this was a special AP for people who need to see this data). They said the data was accessible to unauthorized users inside the network, too. And they fixed it by turning off the AP?
I salute the newspaper for taking the initive (and, perhaps, the risk) of accessing the data themselves. But I wish they would have spun it more as a "piss poor security" issue than a "wireless security" issue. As far as I can tell, this has hardly anything to do with wireless at all. It's certainly not a reason for schools to not run open networks. They just need to secure their wired networks just like they should have before wireless!
___
The way to see by faith is to shut the eye of reason. --Ben Franklin
I grow tired of seeing WiFi get the blame because someone didn't flip a simple switch on a cheap wireless hub that would had prevented 99.99% of the reporters of the world out there from doing this.
WEP exists to stop people like this, it won't stop someone determined, but it will stop the sensationalistic 'news at 11' types
As a rock-in-roll Physicist once said, No matter where you go, there you are.
Would you like a positive response this time?
If there's a liability exposure, institutions will buy liability insurance, and the insurance companies will be a well-funded central source of motivation and knowledge to improve security.
Steam boilers used to blow up and kill people. Insurance companies started demanding boiler inspections. After that, fewer boilers exploded.
The "U" in the UL tag on electrical equipment stands for "Underwriters".
In this age of identify theft, I think Universities should be held to a high standard of privacy. I know when i attended college, I had a real problem with the University using my social security number as my "Student ID" number. I complained to the Dean of Student Affairs, and was told that it was University policy and there was nothing that could be done about it.
I remember strolling by empty offices of professors seeing the green printouts of class rosters at the beginning of each semster, and thinking that all it would take is somebody to duck into one of these rooms, lift that list, and poof, you've got hundreds of names and valid social security numbers.
I realize that many schools are moving away from using the social security number as a form of student identification, but I wonder if this coincides with a shift in the fundamental philosophies of these estabilishments, or if it is simply a method of saving face. I sincerely hope it is the former rather than the latter.
RFC2119
I disagree. Companies should be held liable for their own insecurities. If they left their accounting books on the floor behind the toilet at the local gas station, and a competitor read them all, the competitor could not be sued for accessing that information. The same is true of the internet, or computer networks of any form. That network was being broadcasted over public airwaves, and therefore is public property. If it were secured in any way, then it would be illegal to circumvent the security devices. Unfortunately for the school, it was not.
"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
"WiFi Exposes Sensitive Student Data"
The technology isn't the problem, it's the people. Oh sorry, I guess "People Still Stupid, Film at 11:00" doesn't make a juicy headline, now does it?