Slashdot Mirror


Whopping-Big Data Theft At U.C. Berkeley

aceta writes "An intruder penetrated a research computer at U.C. Berkeley in August and had access to names, social security numbers and other data for 1.4 million Californians participating in a state social program. CNET calls it the worst intrusion U.C. Berkeley has experienced. SecurityFocus additional details: the hacker used a known vulnerability, and state officials have yanked the university's research access to the data because of the breach. The victims were all receiving or providing at-home care under a state program to help the elderly and disabled. The FBI is investigating."

10 of 380 comments (clear)

  1. It's not theft by Anonymous Coward · · Score: 5, Funny

    It's "copyright infringement".

  2. Traffic Safety Center by 2.7182 · · Score: 5, Interesting

    Interesting. A few years ago there was a smaller such incident at the Berkeley Traffic Safety Center.

    1. Re:Traffic Safety Center by Sc00ter · · Score: 5, Funny
      So you drive around with your car under a big blanket or something?

  3. Fix by rguiu · · Score: 5, Funny

    Should be quite easy to fix, now give new name and social security name to everyone involved.

  4. Why did they need all of that data? by ericzundel · · Score: 5, Insightful

    It makes you wonder...

    Why does a research program need access to social security numbers, phone numbers, and the like?

    I think the real story is the State of California sharing too much personal information, regardless of how the hacker got access to it.

  5. Re:At Berkeley? by Indy+Media+Watch · · Score: 5, Funny

    Two things have come out of Berkeley, Unix and LSD. It is uncertain which caused the other.

    --

    Indy Media Watch-Proctologist of the Internet

  6. Re:Yeah by NardofDoom · · Score: 5, Insightful

    A wise man once said "A society is stable when some nut guns down a schoolyard and the laws *don't* change."

    --
    You have two hands and one brain, so always code twice as much as you think!
  7. SSN by sxmjmae · · Score: 5, Informative

    They should have cleaned the data and removed the SSN. When we pass information outside the company we remove any reference to the SSN and replace it with a zero padded sequence to the same length as the SSN. If they ever need to know who the individual is they can give us this sequence number and we can look them up. Our plans are to remove any possible reference to the SSN in the database and replace them with a good old fashion sequence number (IE Customer number). Only payroll will have a table that links the sequence number to the SSN (a must when filing taxes).

    --
    My Sig indicates the end of the comment I posted.
  8. I worked on this project... by bigbikkuri · · Score: 5, Informative

    I was working on this project, and I'll tell you I was extremeley disheartened to learn people would try and sabotage this project. It is for a really good cause (if you believe in unions that is, I don't, but it was still for a good cause) and I hope the project isn't jeapordized beyond repair because of this. For those who might have guessed, the system that was hacked was a Windows 2000 Pro box running SQL Server and a statistics program called STATA. The box was only up and running while retrieving data and was turned off the rest of the time while I was on the project. There were very strict rules about letting the box onto the network since it wasn't a Berkeley box, but then they took the box and put on their own security software which supposedly made the data safe. I can give you the name of the IT guy in charge if you want. Many of you are listing reasons for not having the SSN's on the database, and that they should have been kept at the state level and then the state give us unique identifier numbers. In actuality, the state does not provide that service, and only provides the data from several databases. We ourselves then created unique identifiers because we needed very specific samples from different populations of California. This identifier was made with a combination of people's relations, their ethnicity, and their social security number. You'd be surprised how many people in California have the same name. Also, although maybe not the best reason in some programmer's opinion - it was easier to separate people by their SSN because STATA didn't present a way to compare strings in a useful enough manner so as to use a combination of name and zipcode. And if you are wondering why we had names and addresses and phone numbers, it is because we called and mailed these people ourselves. Our first mailing - worked a 22 hour day, and tried about four different assembly lines! The state didn't help at all - and in the current time when we have idiot Republicans like Arnold (I can't spell his last name) who thinks fixing a state budget crisis involves cutting the budget of an already failing program and driving MORE people into poverty, I don't think you can expect them to help us tell them how and why they are wrong. I'm no longer on the project (got shipped overseas) but the people working on it are rock solid individuals, and personally, as a former IT guy myself, I blame the morons who worked IT at the division this project is taking place. I understand Berkeley is huge, but for a University that supposedly is "computers" - they have a lot of people with absolutely no clue.

  9. Re:Not Illegal by clausiam · · Score: 5, Insightful

    But that is completely insane. They're saying you can refuse to give it but that may mean you have to go without the service requesting it and then they mention a utility as an example and say "the choice is yours". So if you want to keep your SSN as private as possible you may have to live without electricity and water? It that what they call choice? /Claus