Computer With UK Bank Customer Data Sold On eBay
Walpurgiss tips a BBC News story about a man in Oxford who paid $140 for a computer on eBay, and was shocked to find on it bank records of several million customers of the Royal Bank of Scotland, its subsidiary Natwest, and one other bank. "Mr. Chapman said anyone with a basic knowledge of computer software would have been able to find the data fairly simply. 'The information was in back-up CDs and in ISO files so it would have been possibly quite easy to find...,' he said."
Kudos for him for speaking up rather than trying to abuse the situation.
http://blindscribblings.com - Tasty pop-culture in conceptual fashion.
Dummy says dummy...
They made an ISO, made 3 CDs of each ISO (one for the filing cabinet, one for off site back up, one for the on site safe), then didn't both deleting the ISOs...
It's dumb, but not as dumb as your ideas.
M0571y H@rml355.
How many days do you think it will be before the government tries to charge him with something or the bank in question tries to sue him? I'd be pleasantly surprised if neither happened.
Also, the summary leaves out something that might affect those of us on the other side of the pond:
Bold mine. I know they have different branches for countries and such, but I wonder if any of this data crossed international bounds.
i'd charge the pricks a consulting fee for my time. a few grand should cover it. i certainly wouldn't be handing back what is entirely his property, since he purchased it fair and square they have no recourse.
Do that and you go straight to jail, don't pass go, don't collect $200. Your consulting fee will be seen as extortion.
http://michaelsmith.id.au
You might not have seen the video clip with the article [I don't know if it's visible outside the UK] but the guy said he bought two servers, one booted and had been wiped, the other didn't boot. It didn't boot because it was missing it's ram (or the chip was unseated), so anyway, he sorted that out, booted it up and found the data.
Soooo... one wonders if the machine didn't get wiped simply because the various techs could boot it and decided it was too much effort to move the drives to another machine?
now if i went to them and said "pay me or i'll tell the media what retards your IT security guys are" that's extortion. but since it's already all over the news sites it's not possible to call it extortion.
it's also pretty damn cheeky (and just the thing i'd expect from a bank) to expect him to just hand back his purchase.
this would in fact be an interesting case to test in court as to who owns data when you purchase a pc. no doubt IP lawyers would be foaming at the mouth saying your buying hardware not software (that might shoot some of their, but then this isn't software but plain data which they didn't license so he'd have a reasonable expectation that it came with the sale.
If you mod me down, I will become more powerful than you can imagine....