Ohio Plans To Encrypt After Data Breach
Lucas123 writes "After a backup tape containing sensitive information on 130,000 Ohio residents, current and former employees, and businesses was stolen from the car of a government intern in June, the state government just announced it has purchased 60,000 licenses of encryption software — McAfee's SafeBoot — for state offices to use to protect data. It's estimated that the missing backup tape will cost Ohio $3 million. In September, the state docked a government official about a week of future vacation time for not ensuring that the data would be protected."
People just won't learn that security should be proactive. Society is a very slow learner.
Would not be surprised to find out that a McAfee representative payed them to use their software. Still even if that's the case it's good that they're doing something.
Curiosity was framed, Ignorance killed the cat.
Er, while this software encrypts data on the disk, it doesn't encrypt the backups. These will still be cleanly read from the disks and written out to tape.
Couldn't they have found an OSS solution that would have, y'know, saved the state an assload of money? I'm not an "OSS can do everything commercial software can, but better!" zealot, but that's a big bit of pocket change to be throwin' out for a solution, there.
Someone tell them they were supposed to encrypt the data before the breach!
Send email from the afterlife! Write your e-will at Dead Man's Switch.
Help me close this barn door, would ya?
The state loses $3 million bucks, and the guy responsible gets the punishment of a whole week of lost vacation time? Wow....I want to find me a job where I can screw up so badly and get off so lightly. I mean....other than the Presidency.
"Every great cause begins as a movement, becomes a business, and eventually degenerates into a racket." -- Eric Hoffer
Okay, I am having difficulty in understanding $3 million figure... So they bought 60,000 licenses. If we consider the complete $3 million towards licenses, it will be $500 per license, which I think is way too much. However I could not find the cost of the encryption software anywhere on the web (anyone with links????)
anyone care to explain approximately from where $3 million figure came?
...that same government official's boss has allotted him another week of vacation for not losing the REST of the data that all of Ohio stored.
Losing a week of vacation for a data breach that large is ridiculous; like a slap on the wrists. I bet he's going to get paid overtime for working that extra week.
...that the next time they get a backup tape stolen, it'll have a post-it note stuck to the tape with the password on it?
the state docked a government official about a week of future vacation time for not ensuring that the data would be protected
I work as a DBA in a nonprofit healthcare organization. If our backup guys lost a tape, and I hadn't bothered to check off the box in our database backup software that says "Encrypt: 256-bit AES", I would lose my job.
This guy got dinged a whopping 1 week of vacation time. That's not even '1 week suspended without pay'. It's the equivalent of having to stay in detention after school.
I need to move over to the public sector or something.
"In September the state docked a state government official about a week of future vacation time for not ensuring that the data would be protected."
So now we know how much Ohio state officials value the personal privacy of its citizens.
40hrs/130,000 - about 1.1 seconds of a government official's vacation time.
Makes me wonder why people stay in a state that values the personal privacy of its citizens so little.
Instead of using software, I wonder whether an IDE or SATA connector could be developed that encrypts and decrypts the data going to and from the drive. Basically your organisation would enter a key into the connector and the encryption would happen without the OS knowing. If you remove the drive then you wouldn't be able to use the drive without the connector.
Jumpstart the tartan drive.
Whether it's encrypted or not, why is sensitive data on employee laptops or in intern's cars?
How do you log and audit access to data to prevent abuses if you just hand out copies of databases?
guests. Some people A BSD over other of reality. Keep fellow travellers? Parts of you are
I saw four horrifying words...
Intern, backup tape, car
encryption is probably low on the list of security concerns here... just WOW
I absolutely know that I don't want to hear the story of how those four words got used in the same sentence until happy hour is nearly over.
Those 4 words should never be needed in the same sentence. Process is just as important as encryption. That should have been 'backup tape', security company, armored transport, iron mountain in the sentence... oh wait, then there would be no story.
Support NYCountryLawyer RIAA vs People
...we see a story about 130,000 residence records locked and unavailable due to lost encryption passwords?
They just paid millions of dollars for something that systems like OpenBSD, Linux, and FreeBSD offer for free. OpenBSD's filesystem encryption is particularly good. And when you combine it with their meticulous code reviews and near-100% insistence on using as many security good practices as possible, there's really no reason to not use OpenBSD if security is one of your main concerns.
It seems logical to me that this kind of information should be on a centralized servers at a state office with managed firewalls and all the rest with only hardwired terminals allowed access with maybe a VPN set up for remote access if absolutely needed out in the field. I know wireless isn't 100% secure and no system is but that just makes logical sense to me.
"The problem with socialism is eventually you run out of other people's money" - Thatcher.
... nevermind.
Great, now they have a tool to encrypt! Let's hope they thought about key management before implementing it. It's great for vendors that some have no idea of security - more sales. Next we will read all the keys stolen by an employee (usually high in hierarchy, just my experience) and have to start all over again. Or am I too pessimistic / skeptical when it comes to security?
Your problem is? They have been seen to have done something.
Deleted
... but can't make it drink. Encryption is only a partial solution. You still need to keep your backup tapes secure (they won't be encrypted by this software, but most higher end backup software will), and you need to keep people from copying files to USB sticks or burning to CD.
Real programmers use "copy con program.exe"
You'll also be aware of the various rows here in England as the government displays its new networking technology: CDs and a courier. Most of us with medium-sized data farms (I herd about 50TB) are getting out of removable media as fast as we can. I've got 20TB of disk at the far end end of 30 miles of GigE, which with compression (all hail ZFS!) provides me enough space to keep copies of all the critical data, plus a few weeks of daily snapshots. My RPO is ``that day's work'' and my RTO is essentially zero: I can serve the data up over NFS from the replicas as easily as from the live systems. Obviously, some of it's better than ``that day'': the Oracle archive logs go straight over, and the Cyrus mail server will replicate live as soon as I can find the time to get it working. But we're only using tape now for monthly audit copies, and those can therefore safely stay in the machine room: the data replicates offsite, and then comes back into the tape silo monthly. A machine room fire costs us the audit copies: if I feel keen I'll start cloning those and sending them offsite. If I can scare up the budget and offsite space for a MAID then I can get out of tape entirely.
Encryption is crap unless it's used by those trained to understand how it works and what it's limitations are, which I'm sure 60,000 employees will not be. What happens when an employee copies data to a USB disk or e-mails it to someone. If the software prevents this, it will be a major pain in the arse that will cost a lot more than $3 million in lost productivity. If it doesn't, then data will get stolen and everyone will say "no problem, it was encrypted", until massive identity theft cases force them to admit that not all copies were encrypted, but, because the guy in charge spent $3 Million, he'll argue that he did everything reasonable and no one will be held accountable. The real solution is to LIMIT ACCESS TO SENSITIVE DATA TO TRAINED EMPLOYEES WHO ACTUALLY NEED IT TO DO THEIR JOB. I can't imagine that there's 60,000 employees who actually need the personal information of 130,000 Ohio residents. I'm not saying it's obvious who needs what data, but $3 million would buy a lot of manpower to figure it out.
And what happened to Encrypted File System. You know, built-in to NTFS, complete with administrative recovery keys, doesn't cost $3 million? This sounds like just more government waste and McAfee marketing to me.
Part of my job involves working on laptops owned by an agency that uses SafeBoot to encrypt data on laptops. Gather children, let me tell you of SafeBoot...
1. SafeBoot is whole-disk encryption, but Windows-partitions-only. If you dual-boot or use Linux, there is no solution for you except "Please don't lose your laptop".
2. SafeBoot requires a login before you can boot Windows. If you get your password wrong, you must wait a certain amount of time before you can re-enter your passwords. At first, it's not that bad -- a few seconds. But each successive failure increases the time... eventually, you're waiting minutes.
3. SafeBoot encrypts the drive so that you can't access the drive from another machine -- which is what it's designed for, of course. Try being an IT guy in this scenario: You can't perform ANY troubleshooting that doesn't involve booting Windows. If Windows fails to boot, you have to have your hard-drive decrypted (which, for us happens off-site and is a MAJOR pain in the ass). I cannot boot off a Windows CD to use the recovery console to replace damaged registry files. I cannot do a 'repair' install. I could wipe the drive and re-install Windows...
4. The password policy in place requires users to change their password periodically and be of a certain complexity level. Most users have their SafeBoot password written on a piece of paper and taped to their machine, now...
There's a line between security and usability. When SafeBoot works, it appears great -- it doesn't impact system performance *that* much and it encrypts the contents of the entire drive, woo. But when something goes wrong, it becomes a big pain.
To be honest, though, I think the bigger problems for the work *I* run into with SafeBoot is the policies in place, rather than SafeBoot itself.
The way it's worded seems a little ambiguous to me. Did the theft alone cost the state $3 million or did the theft cause the state to spend $3 on licensing a product from mcafee? Both sound like reasonable figures when dealing with the public sector and taxpayer money.
If they have 60,000 computers with 'sensitive' data on it then they're borked already.
... if they want to prevent
If they want to encrypt people's laptops/desktops then fine
personal civilian data from leaking out they're off by a few orders of magnitude on the
extent of their distributed storage.
Belthize
Why don't they just use GPG? It won't cost them three million dollars, and it'll be just as good. It's not going to cost Ohio's government three million dollars. It's going to cost the people who live in Ohio three million dollars in tax dollars. Every time someone says, "Let the government pay for that," they really mean, make us all pay for that, because where does the government get its money? From your hard work! And every time someone says, "Let corporations pay for that," they really mean, make us all pay for that, because where do corporations get their money? That's right! It comes out of your pocket whenever you buy any product or service. Somewhere along the line, it was mined, grown, processed, moved, removed, produced, packaged, housed, assembled, displayed, sold, etc., by a corporation. And when that corporation's expenses go up, it becomes included in the price structure of the product or service you buy.
TrueCrypt is a very nice free solution and I've been using it for months, haven't had a single problem with it. I guess they were not aware of that software, maybe because they simply didn't look for ANY other products beside McMoney's..
The government has a software package they use for such things already. The Macafe stuff it's weak in comparison.
You can joke about this being a case of closing the barn door long after the horses have gone scurrying into the country side but......someone got punished and a preventative measure is being taken. You can't hope for a whole lot more than that, especially from a government agency.
There are some people that if they don't know, you can't tell 'em.
Jeez, put a finger in the dike!
Here is the SECRET on HOW NOT TO LOOSE DATA IN CARS!
Ready?
Really, Ready?
No, Are you Really, Really, Ready?
DONT LEAVE YOUR LAPTOP IN YOUR CAR!
Go back and get it.
A friend of mine, decades ago, lost his portfolio on Syquest cartridges, that he left in his car, ( I would have writtten them off already, but I digress ). I learned the lesson from his mistake. NEVER EVER EVER leave your laptop in your car. Take it out before your lunch, If you really had to, you could replace your lunch.
I went back to Ohio
But my data was gone...
What's the use to encrypt your hard drive just to make a nice decrypted backup later? Conversely, this particular problem can be probably solved cheaper, since I doubt that they have 60000 tape drives in the office. Any decent backup software should already support encryption anyway.
I am not saying workstation security is not important, but here it sounds like someone doesn't even understand the problem that they had.
short of a miracle a previously an7body's guees sanctions, and arithmetic,
How to spell "lose" !
..one gpg command in between tar and the output device.
Why, oh why, didn't I become a government contractor?!?
As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
The state will now be called kaV#29v@a
Hmm... I wonder if they give a damn that their state-wide reliance on Windows is another accident waiting to happen.
Care about trojans, keyloggers, viruses, and all the other uncountable ways to lose confidential data, not to mention productivity?
Get rid of Windows as well. You'll never regret it.
you had me at #!
McAfee ??? I can just see some state dude going down to Best Buy and asking the Geek Squad which software is best. Seriously, McAfee sucks. That software always gave me problems. Could they not find a better solution ? The ONLY reason McAfee is in there is because whoever made the purchasing decision did not know any better.
hmmm My money is at stake so what do they do? They pay for this solution with my money!
The game.
as those non gay, Give BSD credit the project All along. *BSD Current core were Are tied up in Free-loving climate to have to decide support GNAA, its corpse turned would choose to use poor dead last Hear you. Also, if is also a miserable Shall we? OK! and abroad for with process and person. Ask your on an endeavour another troubled for all practical flaws in the BSD ME! It's official I'm discussing again. There are project retur8s Raise or lower the writing is on the OpenBSD leader Theo Lite is straining [gay-sex-access.com]? Sudden and halt. Even Emacs join in. It can be the project as a I type this. Lead developers if you move a table Going to continue, of business and was used to. SHIT ON to this. For A sad world. At user. 'Now that perform keeping don't be afraid
This is the umpteenth report of sensitive data on laptops being lost. A) Why did these people need laptops in the first place? B) Why was sensitive data present on an unsecured system?
Maybe the Ohio department has such MI-5-like employees that they need interns as decoys?
Previously: "Linux... Toward the Sunrise..." Now: "Linux... Toward the-- No, now, part of Every Sunrise"
It was due to general incompetence and cutting corners, and the lack of security on the entire OAKS project, which was virtually nonexistant. A shared drive was left open during project development, and it had been discovered many times that people who weren't involved in the project could log in download personal info. My cousin in law interviewed various employees and wrote a good article for the Cleveland Free times: http://www.freetimes.com/stories/15/28/system-failure .
I would use a MAC and file vault to solve this issue
The data shouldn't be stored on the local machines. It should be in a centralized database that supports encryption at least at the table level, if not the specific field level. That database should be accessed by a client workstation that doesn't cache the data locally. Then the backups should be password protected and encrypted. This isn't exactly rocket science here.
I use McAfee and have had good luck so far (knock knock on wood). Is there a better virus/firewall application out there for Win XP that I don't know about? Do tell!
If only CompUSA was still around.
"Hello, I would like 60,000 copies of McAfee Safeboot please."
"Do you want the extended warranty with that?"
Of course, if you parse the Slashdot article title, you'd think that Ohio plans to do lots of remedial encryption *every* time they have a data breach rather than preventing problems up front
The much more serious problem is all that data that the state has, and the lack of controls on agency and employee use of the data, plus the _planned_ abuses of the data by state agencies and Feds that they're sure to share it with. Since the Feds have effectively gutted most of the privacy laws over the last decade or two, about the only things you can do to protect any of it are to encourage the state to keep using obsolete inadequately supported computer systems (:-), or scare the anti-privacy right-wingers into restricting access to data to keep terrorists from getting it and keep DMV employees from having enough access to licenses to immigrants.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
We'll have data utterly lost. "We lost the piece of paper with the password." Whee!
Just another knee jerk reaction
- High-tech workers usually change companies often, so they don't get very high up the vacation curve, while government workers usually stick around a long time. Working at startups is especially that way, because they often don't last more than two-three years, and many high-tech workers do contract work so they also don't usually accrue much vacation. There are exceptions, mostly old-line businesses like IBM and telcos, or first-wave computer companies that survived, like Sun or Apple, and a lot of academic-style companies give you a sabbatical after a few years.
- Government workers tend to get all kinds of random holidays in addition to their vacation - Columbus Day, Martin Luther King Day, some kind of Founding-of-the-State day, etc., which non-government workers generally don't get as many of. (My company provides three special floating holidays, which they can't reschedule on you unlike regular vacation - they typically get used for Jewish holidays by Jewish employees or as regular vacation by goyim.)
- Some high-tech companies lump vacation and sick-time together, while governments and older companies tend to handle the two separately.
Your figures for how much vacation you get after N years of experience are more generous than I've usually seen, but they're in the ballpark.Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
I just checked that page, and while I may be jumping the gun a bit, I see no mention of "backup" or "tape". Thus, I can only conclude that unless their backup software itself separately encrypts the backup, or unless the backups are full disk images (taken while the OS is shut down), the backups will not be encrypted.
Of course, those are a couple of assumptions, but they're pretty likely ones.
Disclaimer: I'm not the grandparent poster.
Don't thank God, thank a doctor!
Explain what the requirement of FDE is.
I currently boot my laptop off a USB stick. While I have only configured it to use every single partition encrypted (Linux root, swap, and shared NTFS with Windows), it would be a small step to encrypt the whole disk. (Of course, then I couldn't boot Windows.) I don't currently have passphrases on the key files on that USB stick, but I don't use it for anything else, and, again, that would be a small step.
Obviously, the USB stick cannot itself be encrypted. Must there be some BIOS support for it, then? And if so, what's to prevent the BIOS from being as easily compromised as my USB stick?
Unless you're using a trusted computing chip, I don't really see how you can get much more secure than that.
There is OpenOTFE for Windows, but, unfortunately, it won't encrypt the Windows boot partition, and for some really strange reason, it doesn't support the Windows Defrag API. (Thus, just about any defragger on Windows won't be able to defrag this drive, but some defraggers on Linux might.)
Don't thank God, thank a doctor!
We are the ones who are constantly telling people to implement things like encryption.
They either think we're paranoid, or... I don't know what the fuck they think. Probably just don't want to deal with it...
So now they've been bitten, and now they "get it".
Any time someone finally admits you've been right all along, especially when it's a bit too late to prevent the damage, is cause for both glee and frustration.
Now, I'm not saying that them adopting encryption now is a bad thing, though maybe the particular product they chose is...
Don't thank God, thank a doctor!
First, there's open source, which is great if you can remember to scan your hard drive every now and then. (I keep waiting for someone to bundle this on a boot CD.)
Then, for more sophisticated protection, there's avast and AVG. Of course, these mostly focus on anti-virus.
I recommend Avast, and I use Clamwin, because the only place a virus scanner really helps someone with good online habits is when you've downloaded a file which you know is suspect, and you'd like to scan it prior to use.
On the anti-spyware front, there's Spybot S&D, which has been known about for ages, and is still good.
The reason McAfee sucks isn't necessarily anything to do with its relative security, vs Norton/Symantec or anyone else. It's that the others are so much smaller and lighter -- McAfee and Symantec are both bloated performance hogs -- something you really can't afford on something that runs in the background 24/7 -- and Norton in particular is buggy as all hell -- something you really can't afford on something that controls every file access and network connection.
And all of them are completely unnecessary, now that there's so much out there as good or better, and free (for home use, at least).
The reason for the subject "My god" is that you're on Slashdot and you need to be told. I thought it was public knowledge already; guess not.
Don't thank God, thank a doctor!
The technological revolution has happened far faster than the ability of humans to adjust.
TrueCrypt is free encryption for both Windows and Linux. It works extremely well, in my experience.
Unless you are using FDE (full disk encryption), you just can't trust that Windows or some Windows application won't write your sensitive data in a place you won't think to encrypt.
I use Truecrypt myself, but also have to take steps to wipe the free space on the drive after I open a file with sensitive info. Even this isn't really, truly secure as it doesn't take care f anything in the Windows swap file.
First 2 factual clarifications on this story: The stolen "tape" was actually a "device" that has not been officially disclosed as to what type. Some speculate a laptop while others say it was a USB Flash Drive. Second, nearly 1 million people are estimated to be affected by the theft, not 130,000 as the story states.
Well....okay. I live in Ohio and therefore could be in the group of State of Ohio employees, state taxpayers, Ohio lottery winners, and others and since it regarded social security numbers bank account information and such, along with the fact that the theft happened in my hometown of Hilliard, I paid close attention to the story.
What ACTUALLY happened was an INTERN took the device home for whatever reason. Some speculate to have an off-site backup of the data. The intern left it in their car and their car was broken into and the device was stolen.
To clarify the cost: Ohio is providing, free of charge, 1 year of credit monitoring service to each Ohioan that was affected by the theft. That cost estimate is very high. Even at a bargain basement price of $2 per year per taxpayer, that would be about $2 million. The lowest price you can find online is $4.95 per MONTH and about $60 per year.
Further: The official that lost vacation time was not the intern that took the drive home. That official lost the time because they were responsible for ensuring the safety of the data to begin with. Although the intern is the person in possession of the data and should have verified its safety, they were following the procedure that official set up. The intern is not the only one responsible for the theft.
but whoever was responsible for a breach of that magnitude should be also be encrypted, right after he's properly embalmed.
The higher the technology, the sharper that two-edged sword.
Here's what I think really happened, folks:
1. Government official gets idea to make a bit of money.
2. Official gives intern important tape, knowing it will be left in the car.
3. Official knows where intern lives, and goes and steals tape from car.
4. Official sells data on the black market for a dollar value far in excess of a week's vacation time.
5. Official gets to keep his job.
There is no "???" step here.
Really, what are the chances that this intern gets his car broken into on the VERY SAME DAY he happens to be carrying this tape? I mean come on. Anybody who thinks this was a coincidence is crazy.
And how the hell is encryption going to help? A corrupt official HAS THE KEYS. If more than one person has keys, there is no way to prove who caused the breach. This is going to happen more and more. Probably the majority of these incidents have been inside jobs.
I'm quite sure these anti-virus companies must be having people dedicated to writing viruses so that they can remain in business. If people stopped writing viruses, these companies would have to shut down. They probably cannot afford to let this happen. If fact, if I have a security product, the best way to demonstrate and market it to a company would be to hack their systems and then appear out of nowhere and be the savior. Savvy.
I guess this is a classic example of "closing the hatch after the chicken has booted" But all said and done, it is great that data will be encrypted from now on !
Chris ,
Php Programmers.
http://www.securesystems.com.au/ No I don't work for them.
And let me say it sucks. It was implemented and we were told everything would be transparent...well its about as transparent as mud. Most of the problems happen when we have password change day because the program will check to sync the safeboot and windows passwords at a random time within 30 minutes of turning the PC on, and then every 8 hours afterwards. So it is possible to change a password and not have it actually change for another day. So then I get the call to reset the password, and the program doesn't recognize that when the safeboot password gets reset it should check to resync with the windows password. Sorry about my rant, but good luck to Ohio, they're going to need it.
Or are you just playing devil's advocate?
/boot partition, according to Unix philosophy, but it's the same idea.
What would you call that first partition on the disk, which houses the (unencrypted) hypervisor? Oh yeah, a boot partition! Maybe not technically a
And before you say it, having the entire thing be in the bootloader in the MBR does not count either.
Don't thank God, thank a doctor!
You originally said:
"And no software can give you the ability to encrypt boot partitions."
Quite correct. (Unless you implement it at a BIOS level, but I'll gloss over that because it's not exactly commonplace).
However, the theoretical decrypting hypervisor (which I accept is a boot partition) would allow you to have any OS boot from an encrypted partition, while hiding itself from the OS.
Obviously you don't store the encryption keys on the disk itself (duh!).
The net result would be while the boot partition itself is unencrypted, that does not really matter as the boot partition doesn't do anything apart from decrypt the partitions which contain the interesting information - and it can't do that without the key.
Safe storage of the keys is another matter altogether.
I will say that the risks of your method, vs, say, having a physically removable boot partition (like I do), are very small -- just as the risks of my method vs a TCPA chip are pretty small.
However, it is still possible to mess with that boot partition you describe, and thus intercept not only the keys and passphrases, but anything else you want later in the boot process -- much moreso than if a hypervisor wasn't used. Really, about the only way to make this entirely tamper-proof is to use some sort of dedicated hardware (like a TCPA chip), which is itself tamper-proof.
Sorry about the "retarded" comment, looks like it wasn't deserved. (I should reserve that for people who actually don't know what they're talking about -- I thought you didn't -- rather than semantic debates.)
Don't thank God, thank a doctor!