Slashdot Mirror


Sensitive Data Stolen Via Digital Cameras

Jack writes "ITO is running an interesting story on a new security threat connecting digital cameras and hackers." From the article: "Following a spate of reports about Bluetooth and iPods devices being used to steal sensitive data from organizations, businesses are now urging to be vigilant as hackers use digital cameras to sidestep security measures. 'Camsnuffling', the latest IT managers headache being used to computer attackers to extract and store data with the help of digital camera." We've previously discussed this problem.

56 of 318 comments (clear)

  1. Memmory Sticks next? by Ironsides · · Score: 5, Insightful

    Since the article seems to be more concerned about using cameras to store information, rather than taking pictures of sensitive documents, how long until USB Memmory sticks are targeted? Floppies? Geez, if they're that worried about security they need to be concerned about anything that stores info, not just what appears to be everyday items.

    --
    Fly me to the moon Let me sing among those stars Let me see what spring is like On jupiter and mars
    1. Re:Memmory Sticks next? by ergo98 · · Score: 4, Insightful

      Since the article seems to be more concerned about using cameras to store information, rather than taking pictures of sensitive documents, how long until USB Memmory sticks are targeted? Floppies? Geez, if they're that worried about security they need to be concerned about anything that stores info, not just what appears to be everyday items.

      Removable storage devices are the problem, and the invention of "camstuffing" seems like a lame gimmick to try to spin more news out of it. The article ridiculously claims that "many employees use digital cameras in their day to day work" - Maybe at a photojournalism shop, but in most real businesses you'd look pretty odd connecting your camera to the PC. It's vastly lower on the threat scale than PDAs, cell phones, burnable media, or flash cards/keys.

      While I think the whole hacker vs cracker thing is a lame debate, in this case they're talking about people simply stealing or misappropriating data that they rightfully have access to. There is nothing (h|cr)ackeresque about that.

    2. Re:Memmory Sticks next? by malraid · · Score: 5, Funny

      That why our IT department fills every hole in every computer with epoxy. It's bitch when we have to fix something, but then, a broken computer is not a security threat.

      --
      please excuse my apathy
    3. Re:Memmory Sticks next? by schon · · Score: 3, Informative

      The article ridiculously claims that "many employees use digital cameras in their day to day work" - Maybe at a photojournalism shop, but in most real businesses you'd look pretty odd connecting your camera to the PC.

      It's not as ridiculous as you think.

      Perhaps most keyboard jockeys may not use digital cameras, but most of the businesses I know of who have employees that leave the building outfit their employees with digital camera.

      Building inspectors use them for taking pictures of job sites. Insurance agents use them for making appraisals, insurance adjusters use them for taking pictures of accidents. Rig foremen use them to take pictures of their rigs. General contractors, cabling salesmen, and land surveyors use them to take pictures of job sites.. and this is just off the top of my head. I'm hard pressed to think of a company I deal with that doesn't have at least one digital camera for staff use.

    4. Re:Memmory Sticks next? by ergo98 · · Score: 2, Insightful

      Worrying about IPods and usb-drives just seems like this decade's nod to a B-movie scenario that was just as tired last decade.

      iPod 60GB - $460
      USB cable - $8
      Misappropriating the financial database because you're the DBA - Priceless

      Well, maybe not priceless. Billions of dollars in actual and capitalization damage, destroyed market image, thousands or tens of thousands who'll have issues for years.

      It isn't tired - it's a very, very real risk. Too much data is being treated sloppily, and while this is only one of many steps that need to be taken to secure data, it is a concern.

    5. Re:Memmory Sticks next? by size1one · · Score: 2, Funny
      "Geez, if they're that worried about security they need to be concerned about anything that stores info"

      I have a photographic memory so my employer forces me to work blindfolded.

    6. Re:Memmory Sticks next? by AndroidCat · · Score: 2, Funny

      Jeez, next they'll stop me from plugging in a 802.11g USB adapter and connecting with a friend in the parking lot. Talk about paranoid!

      --
      One line blog. I hear that they're called Twitters now.
    7. Re:Memmory Sticks next? by gary73013 · · Score: 5, Interesting

      Don't laugh. The three letter Government Agency for which I work fills all the USB ports, etc., with epoxy. Wireless networking is NOT permitted and the buildings are shield to prevent RFI from leaving/entering the building. Additionally, security personnel "war-drive the perimeter of all buildings to ensure there is NO 802.11 traffic. Also,if I remember correctly (I'm at home now), the extra network port and parallel and serial ports on my PC have been filled with epoxy too! The infrared ports and such usually have a shield permanently glued over them too! LOL

    8. Re:Memmory Sticks next? by Anonymous Coward · · Score: 2, Interesting

      There is no question that memory sticks can be a problem. "My" computer is locked down by my employer to the point that it is an expensive browser with no other functionality. I can't install anything. I use my USB device to run unauthorized software. CMD.EXE was locked out, but for whatever reason, COMMAND.COM wasn't, so I open a command window and run what I want (as long as it doesn't mess with registry settings, which are blocked). I detest Internet Explorer, so I run Portable Firefox!

      Bios changes were also blocked, but reinstalling the bios via that command window has allowed me to allow CDROM boots, so I can also boot KNOPPIX if I want.

    9. Re:Memmory Sticks next? by ozric99 · · Score: 2, Funny

      Yeah, too right. Security is king in the Farm Service Agency. Gotta keep those tomato crops safe from daggum terrists.

  2. Why go to all that trouble... by greyfeld · · Score: 4, Insightful

    when you can just buy a thumb drive and plug it in to any machine and get almost whatever you want.

    1. Re:Why go to all that trouble... by jonnythan · · Score: 4, Informative

      Because lots of corporations and governmental bodies, particularly those dealing with sensitive data, have access to removeable media such as USB drives, CD-RW drives, and floppy drives, disabled by default.

    2. Re:Why go to all that trouble... by Carthag · · Score: 2, Informative

      But it appears that in this case the cameras are used as USB drives. Wouldn't they also already be disabled, then?

  3. Easy fix, remove access to the usb ports by psyon1 · · Score: 4, Insightful

    Like the computers in a cabinet, and only allow bonded techs to get in to install peripherals :)

    I know its not realistic, but alot of security problems can be fixed if we give up convenience.

  4. How serious are you about security? by winkydink · · Score: 4, Insightful

    If you or your company, is truly serious, then the steps to limit these sorts of things are pretty straightforward (no iPods/cameras in the workplace, locking the bios to prevent new usb, no admin rights on your machine, etc...).

    The problem starts when the copmpany talks the talke, but doesn't back it up with action, leaving IT staff with a mixed message.

    A clear, well-written security policy that has been bought off by and supported by exec mgmt is the only way to go. Sarbox is a great tool for scaring mgmt into line here. :)

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

  5. Let's start with the obvious... by c0dedude · · Score: 2, Insightful

    Sensitive data should not be in plain view. Camera phones, then, are not a problem.

    --
    Since when has this country used intellectual elite as a pejorative term?
    1. Re:Let's start with the obvious... by AndroidCat · · Score: 2, Funny

      Digital cameras are too much work and attract attention. I just bring in a crate of Silly Putty for copying documents.

      --
      One line blog. I hear that they're called Twitters now.
    2. Re:Let's start with the obvious... by harbichidian · · Score: 2, Insightful

      Military working facilities don't have janitors, they have people with less rank. ::withering smile::

  6. "Cameras" is a little misleading/shortsighted... by ScentCone · · Score: 4, Insightful

    Why not just repeat this article on a regular basis, updating a list of things with some sort of commonly used comm port/interface and simple file-system storage? Right now it's phones, PDAs, pens, music widgets, camerads, fobs... but next it will be eyeglasses, shoes, student ID cards, car keys, fake fingernails, or someday your pre-frontal cortex. This article is mostly about how you can't trust people you can't trust. Cameras don't have much to do with it, per se. If cameras provided a way around an established lack of trust, then we'd have an article to read.

    --
    Don't disappoint your bird dog. Go to the range.
  7. cannot be helped by middlemen · · Score: 4, Insightful

    Most of us must have read the story about a crow wanting to drink from a jug of water, but the water being too low, the crow could not drink it. So it dropped some pebbles/stones in it and then the water rose so that the crow could drink it. If a crow can be resourceful like this applying its brain (however small), so can humans. And "hackers" (why lord why! it is crackers) are resourceful and how much ever technology progresses, there will be people who will defeat the technology by sheer brainpower and kludges. So, such things are inevitable and in fact extremely necessary to spinoff the growth of new better technology.

  8. Big zoom cameras are something too. by baryon351 · · Score: 4, Interesting

    A friend of mine has one of the big zoom cameras, an 18x canon, and has often found the info revealed in one of them is insanely high. zooming in to take a photo of an aged guy on a park bench reading a newspaper brought out a picture that revealed every word on the front page of it. I found myself zoomed in and reading that article before realising how simple it was, and that we were more than a hundred feet from him.

    Anyone here run a business with a display visible from a window, even one half a city block from the next window?

    1. Re:Big zoom cameras are something too. by manifoldronin · · Score: 2, Insightful
      Anyone here run a business with a display visible from a window, even one half a city block from the next window?
      Yeah, especially considering the more senior an exec becomes the bigger/more windows his office gets to have...
      --
      Tyranny isn't the worst enemy of a democracy. Cynicism is.
    2. Re:Big zoom cameras are something too. by frostman · · Score: 3, Informative

      That's a great point, but isn't limited to digital cameras per se. You can do the same thing with film (and that's been the subject of a few movies).

      The digital angle mostly means it's much more convenient, and with Photoshop very convenient indeed. Plus the whole memory card angle, though in the kind of scenario under discussion here a film canister wouldn't be too hard to smuggle out of a sensitive location.

      I was recently walking by a ground-floor open-plan office - architects, I think - and the guy closest to the window had his back to the window. Presumably to avoid distractions. Which of course meant his ginormous LCD monitors were facing the window...

      --

      This Like That - fun with words!

    3. Re:Big zoom cameras are something too. by TedCheshireAcad · · Score: 2, Funny

      Could you, uh, point us to some, uh....evidence? I would like to review the legitimacy of the case...yeah...that's it.

  9. Re:You know... by winkydink · · Score: 2, Insightful

    Forget it. That ship sailed long ago. People were complaining about the misnomer since the Morris Worm (and probably before that too). The media has coopted the word hacker whether you want them to or not. While you can continue to use it "correctly" in certain small circles, the general public equates hacker with malice.

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

  10. May as well... by grumpyman · · Score: 3, Funny

    Disallow pen and paper, and blind-fold visitors until they are escorted to where they are supposed to go.

  11. Oh no by varmittang · · Score: 2, Insightful

    The Camera Phone, they must all be disallowed in the work place. That is going to be difficult, since most phones have a camera, and people are going to want them in case the kids get sick.

    --
    -----BEGIN PGP SIGNATURE-----
    12345
    -----END PGP SIGNATURE-----
  12. Camsnuffling by digitaldc · · Score: 3, Funny

    I thought 'camsnuffling' was breathing heavily through the nose while taking a picture?

    --
    He who knows best knows how little he knows. - Thomas Jefferson
  13. Re:iPods only for illegal use? by Kelson · · Score: 2, Insightful

    Not only that, but I imagine many of them are playing music they bought legally -- on their own time -- either in round plastic form or from iTMS, on their home computer.

  14. "Camsnuffling?" by quinby · · Score: 2

    Let's consult the Oracle:

    "Your search - camsnuffling - did not match any documents.

    Suggestions:

            * Make sure all words are spelled correctly.
            * Try different keywords.
            * Try more general keywords."

  15. Unless you lock the USB ports... by L0neW0lf · · Score: 3, Interesting

    Someone will get in, if they have access to your local intranet. It's that simple.

    I'd bet everyone here has seen a picture of the USB flash drive disguised as a PEZ(tm) dispenser. What about the new Swiss Army Knife that has one built in? Heck, you could mod a USB drive to look like a Zippo or a Bic lighter. As others have said, I can't even see why camera phones are such a hot deal other than for their ability to take pictures; storing documents can be done in a far less noticeable way when there's access to USB ports.

    --

    Never look down your nose at others. Someday, someone is bound to see your boogers.
  16. What the USA National Archives do... by ATeamMrT · · Score: 5, Interesting
    Since the article seems to be more concerned about using cameras to store information, rather than taking pictures of sensitive documents, how long until USB Memmory sticks are targeted? Floppies? Geez, if they're that worried about security they need to be concerned about anything that stores info, not just what appears to be everyday items.

    They check everyone who enters, no cameras are allowed. Everyone needs a special Id issued by them to eneter. No jackets are allowed. No loose sweaters are allowed. They have lockers where any banned item can be kept, outside the secure area. Once you make it to the guards station, they stamp every sheet of paper you take in. When you leave, you can only take out papers they stamped. They check EVERYTHING. And they have a ton of security cameras in the building, and employees that keep track of who comes and goes. I needed papers which were in a secure area. They made me wear an ID tied around my neck, and I was escorted by an employee.

    They also make it a crime to try and decieve them (for example, sneak a camera in). People can go to jail, and there are heavy penalties. They have multiple checks. The first one is a metal detector and a police officer who is more than willing to use the hand wand. The next step is the security officer who checks you in.

    If companies want security, it is not hard to ban everything, hire 20 or 30 police officers, make it a crime to violate their policy, and treat everyone as dishonest liars who are more likely to steal.

    A chain is only as strong as the weakest link. That is the mentality these institutions have, so they don't trust anyone, not even thier own guards.

    1. Re:What the USA National Archives do... by databyss · · Score: 2, Insightful

      The company I work at has much the same policy, except for the stamping of papers and clothing requirements (I think anyway, they don't bother employees as much as guests). All the employees here wear ID's around our necks, guests have the same thing. We don't feel like we're being treated as criminals. It makes us feel empowered.

      We understand that the work we do has a potential for security risks that need to be handled. You'd be a fool, in this industry, to have lax security. In the long run it's in the employees interest to have very strict security. My job depends on it.

      --
      Hmmm witty sig or funny sig? Maybe elitest techy sig!
  17. Re:Top-Secret Information Leaking by ergo98 · · Score: 4, Insightful

    But if you work for a company like mine, where the data is the company's life-blood I can completely understand why they'd want to keep your USB and other storage devices (like iPods) out of their space.

    Employees don't need to be treated like criminals, but they shouldn't have more access than they need. For instance USB storage devices should be disallowed as a matter of security policy (not as a lame "leave what you tell us about at the door", but as an actual OS enforced system policy). I care about this from a user and customer perspective, where random employees of banks, insurance companies, and other businesses have access to an enormous amount of my data: I've worked at a large bank and a large insurance company, and the controls aren't anything like most people imagine.

  18. Free Luna! by Thud457 · · Score: 2, Funny

    How am I supposed to smuggle jokes for Mike into the computer complex if you instate a policy like that?!!!

    --

    the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

  19. Julius Caesar by giorgiofr · · Score: 4, Funny

    Yo, there was this guy long time ago, you know, called C.J. Caesar MC, and he was, like, worried that the Man would steal his secretz, 'namean?, so he came up with this gimmick where he wrote something on a piece of dead skin, how gross is that?, man, but if you had read it it wouldn't have made no sense, but if you had known HOW to read it, then hell yeah, lotsa sense there... than his buddy later called this thingamajig ROT-13 or some such nerdy word, and then lotsa other guys did the same, but more powerful...

    I hope you liked this short intro to ENCRYPTION and understand how it can solve some of your problems. Thank you and goodnight.

    --
    Global warming is a cube.
  20. Human larynx as security risk by ewg · · Score: 5, Insightful

    The human larynx is the biggest security risk. It's a ubiquitous device that can broadcast via sound waves any proprietary information a knowledge-worker has been exposed to.

    Of course this description is (intended to be) humorous, but the serious point is one we've heard often enough: you can't solve a human problem with a technological solution.

    --
    org.slashdot.post.SignatureNotFoundException: ewg
  21. collateral damage by AxemRed · · Score: 4, Interesting

    This is becoming more of a problem for me too... I'm an amateur photographer. I have enjoyed photography for about 10 years, but over the last 3 years or so, businesses have become much more paranoid about cameras. Concert venues have cracked down, and many stores will kick you out for walking around with a camera, let alone taking pictures. Personally, I have always thought that (for the most part) you should be able to photograph anything that you are allowed to freely look at, but because of abuses, that isn't usually the case. It's sad really.

    1. Re:collateral damage by Ph33r+th3+g(O)at · · Score: 2, Insightful

      Cameras are potentially accountability, and thus potentially liability. They don't like anything taking pictures that could be evidence (except for their own cameras--with those, evidence could be "lost" or "inadvertently destroyed").

      --
      I too have felt the cold finger of injustice.
  22. Warning... by Pedrito · · Score: 4, Interesting

    Photocopiers can be used to copy sensitive data. Please dispose of all photocopiers in your company...

    Okay, I did RTFA, but I'm not entirely sure "how" a digital camera is a threat other than being used to take snapshots of sensitive data. Sure, you can plug it into a USB slot, but for a lot of cameras, they're little more than thumbdrives when they're connected via USB, so a thumbdrive would certainly be less conspicuous, but then you have to ask how this is much different from say, floppy disks, which until recently, were pretty ubiquitous.

    The article mistakenly states: "Hence, simply plugging it into a computer's USB can allow hackers to obtain sensitive data." How? Does plugging in a camera suddenyl disable all security in a computer? Suddenly all your encrypted data is decrypted? Suddenly the camera has access to everything? This is a completely unqualified statement that means nothing. It's a thumb drive and you have no more access to sensitive data than the person at the keyboard which is presumably the same person with the camera.

    Sorry, maybe I'm missing something, but this seems like a pretty stupid article.

  23. Re:"Guns" is a little misleading/shortsighted.. by Pantero+Blanco · · Score: 2, Insightful

    You missed the point. They only listed a single device capable of causing the problems they listed, when there are many more that would be more likely to. He wasn't saying that the employees were the only factor.

    To use your analogy, it would be like someone writing an article on why a pocket knife could be dangerous in a criminal's hands.

  24. My secret hiding place by Hoi+Polloi · · Score: 3, Funny

    "just slip one in your pocket."

    I could've been hiding it in my POCKET? Oh shit...

    --
    It is by the juice of the coffee bean that thoughts acquire speed, the teeth acquire stains. The stains become a warning
    1. Re:My secret hiding place by Kelson · · Score: 3, Funny

      Your USB drive doesn't happen to look like a gold watch, does it?

  25. Re:Top-Secret Information Leaking by Shakrai · · Score: 2, Insightful

    I've worked at a large bank and a large insurance company, and the controls aren't anything like most people imagine.

    No they are not. The stuff I that I saw go on in the insurance industry would scare the living daylights out of people.

    The biggest one I can think of would be the offsite tape backups at the agency I worked for. These were run every business day. How do you think they were offsite? Safe deposit box? Fire proof safe at the owners house? Nope! They gave the chief CSR the tapes and made her responsible for them. She took them home in her purse. More then once she lost a tape or forgot to bring it back in.

    Despite that glaring amount of stupidity they refused to give me (the in-house IT) administrative access to the network or servers. I was supposed to talk to my boss if I needed him to log in for me. They trusted nobody but they let this woman take the companies entire database and image archive home with her every night. They justified this because "Tape drives are expensive and nobody else is likely to have one or know what's on the tape if she loses it."

    I wonder how many of those tapes are floating around out there.

    --
    I want peace on earth and goodwill toward man.
    We are the United States Government! We don't do that sort of thing.
  26. This reminds me of the time . . . by ndansmith · · Score: 2, Interesting
    a local kid decided to steal software with his iPod. The kid walks into an Apple store, plugs in his iPod to one of the demo machines, and downloads all of the expensive software (ProTools, Photoshop, etc.). I guess he eventually got caught but there were no charges pressed (probably had something to do with the fact that he did not agree to a EULA, haha).

    That is to say that the conveniece of plug-n-play mass storage (whether it be usb stick, camera, iPod) can be a major security risk. Add that to unsecured systems running as administrator (or root, etc.) in the workplace or showroom, and you have a great potential for mischief.

  27. Information Classification by Ferment · · Score: 2, Insightful

    Classification of information and treating that information accordingly is at the heart of the issue. It is impracticle to have to protect all information. Organisations need to decide what needs to be protect and to what extent and then implement policies based on those decisions. If you have highly senstive information, clearly classify it so, limit who has acesses it and how they access it.

    When I did defense work, classisfied systems sat on seperate networks behind locked doors. Only those who knew the combinations to the locks and had electronic key cards with the right pins could access the rooms. There were no connections from the machines to the outside world and in fact many rooms were RF sheilded to prevent EM snooping. Cameras, IPods, Thumb-drives and USB watches were certainly not allowed in these rooms.

    I am not suggesting that all organisations need this kind of security but using seperate physical networks, limiting physical access, and disallowing the presence of certain devices around these machines is not beyond the pale.

    --
    A passion for apathy.
  28. Word for word copy of another post by jlowe · · Score: 2, Informative

    This guy simply cut and pasted several posts from this story: http://it.slashdot.org/article.pl?sid=04/07/06/125 0212&tid=172

  29. Defense Contractors, memory sticks, and cameras by SeanDuggan · · Score: 4, Interesting
    I work in a building with defense contractors. Cameras are banned, even non-digital ones, for fear that someone might take a picture, but they have no problems with USB sticks and digital music players. I once had a guard ask after the headphones I was wearing. When I explained they were to my digital music player, he waved me on, saying that he just wanted to be sure they weren't plugged into a cell phone. (Cell phones are required to be turned off while in the building ostensibly because the signals can disrupt some of the RF experiments. Camera cell phones are, of course, banned.)

    Oh, and when the news reports came out, they did also briefly ban Furbies (remember when they were marketed as being able to mimic language? Security feared they'd be used as recording devices) and Coke cans (Coke was running that contest where prize cans had a GPS transmitter in them to lead in the prize team. This is more of the signal interference than a security thing, but people weren't hot on a GPS transmitter inside secured locations either).

    --
    This sig has absolutely no significance and serves only to take up screen space and waste the time of the reader.
  30. roll your own by catalyst · · Score: 2, Interesting

    How arrogant of $INDUSTRY_GROUP to think that they can actually solve $SECURITY_HOLE by pushing this $TECHNICAL_FIX fix down our throats! All they'll ever catch with this are the really casual users, who aren't capable of anything worse than annnoyance; any *real* villain would get around $TECHNICAL_FIX in heartbeat by just $10_SEC_CIRCUMVENTION. Why does /. keep shilling 2-bit press releases from $INDUSTRY_GROUP, anyway?

    $INDUSTRY_GROUP="Icomm"
    $SECURITY_HOLE="data smuggling"
    $TECHNICAL_FIX="camera ban"
    $10_SEC_CIRCUMVENTION="SFTP'ing the whole damn corporate database to a home SSH server set up on port 80"

  31. Bluetooth != storage device by AeroIllini · · Score: 4, Insightful

    Wow. This is a terrible article.

    From all the grammar mistakes, to the pointless buzzwords ("camsnuffling", "podslurping"), to the mention of how USB devices instantly give anyone access to any data on a computer, to the fact that "hackers" and "computer attackers" are mentioned several times when the data being taken is clearly being taken by employees who have access to it in the first place.

    And "Bluetooth" is apparently a USB storage device. Way to go.

    But in all seriousness, companies do have security issues regarding sensitive data leaving their computers in the hand of employees. How can these companies be sure that their data is secure while still maintaining access for the people who need it and not treating their employees like criminals?

    If I were Dell, or some other prebuilt Windows box company, I would offer a desktop computer with no external ports at all. No USB, no serial port, no floppy disk, no CD writer, no nothing. Just a hard drive and a network connection, and a DVD/CD-ROM drive. That way, companies can make all their data available over the internal network (c'mon, is setting up shared server space really *that* difficult?) and it's much harder to get the data out of the company. If the company is truly paranoid about people taking hard drives out of their desktops to take home with them, set up the computer with an encrypted file system which asks the main server for the passphrase every time the computer boots. If you're worried about people sending themselves things as attachments, then don't allow emails with attachments from your servers. If outside companies need access to sensitive data in order to do business with you, then set up a secure server for data exchange. No sweat.

    Precautions can be taken on the server side that make it very difficult for employees to steal sensitive data, but that still allow for efficient data flow within the company. And, of course, none of these ways will prevent anyone who is truly determined to get your data, but it will stop the casual stealers, and your chances of sensitive data getting out are much lower.

    --
    For security, the MD5 hash of this message and sig is 09f911029d74e35bd84156c5635688c0.
  32. Back to Dumb Terminals by xoip · · Score: 2, Insightful

    If companies are so concerned about data theft from the desktop access points go back to client/server and give people nothing more than a keyboard and monitor.

  33. Re:Top-Secret Information Leaking by Shakrai · · Score: 4, Interesting

    My employer has insurance companies as clients, too. Almost universally they're penny wise and pound foolish.

    And paranoid too. I wanted to replace the whole tape scheme with some sort of offsite service like LiveVault. He was completely convinced that they would steal our data and sell it to our competitors -- even though they dealt with banks and other companies hundreds of times our size. When he wouldn't go for that I suggested a server at his house backing up in real time across an encrypted VPN -- he didn't trust that either because somebody could "break" the encryption and sell it to our competitors.

    The sad thing is that it would have solved a lot of problems. We could have stopped buying bigger tape drives every few years (they scanned everything that came into that office and retained the images forever) when our existing one was too small. It would have been about a million times more secure then the "send a tape home with the CSR method".

    The funny thing is that I could never quite get it through to him that if our competitors were that smart/knowledgeable we'd already be out of business. Or that a CSR paid $7.00/hr is much more likely to betray you then a private company that you have a business agreement with.

    Yeah, it was PHB hell.

    --
    I want peace on earth and goodwill toward man.
    We are the United States Government! We don't do that sort of thing.
  34. Re:"Cameras" is a little misleading/shortsighted.. by Anonymous Coward · · Score: 2, Interesting

    "but next it will be eyeglasses, shoes, student ID cards, car keys, fake fingernails, or someday your pre-frontal cortex" Why use fake fingernails when you can use the real things. http://3quarksdaily.blogs.com/3quarksdaily/2005/08 /fingernails_sto.html

  35. PostIt now! by mlush · · Score: 5, Insightful
    From TFA
    "Firstly, regularly change system passwords that employ both letters and numerals."

    ...resulting in a new security breach know as PostIt snatching

  36. Enough with the Neologisms Already! by Millard+Fillmore · · Score: 2, Insightful

    Anybody else agree that they're tired of flavor-of-the-moment words coined to describe this kind of thing. From the article, we get "camsnuffling" and my favorite: "podslurping." The recent "splogs" also comes to mind.

    1. Re:Enough with the Neologisms Already! by Bloke+down+the+pub · · Score: 3, Funny

      If only someone could coin a catchy, pithy word for the phenomenon of coining pithy, catchy words for things.

      --
      It's true I tell you, feller at work's next door neighbour read it in the paper.