Data Breach Notices Show Tip of the Iceberg
d2d writes "The Data Loss Database has released a new feature: The Primary Sources Archive, a collection of breach notification letters gathered from various state governments as a result of data breach notification legislation. The documents include breaches that were largely unreported in the media, many of which are significant incidents of data loss. This lends credence to the iceberg theory of data-loss reporting, where many incidents never break the surface. Now, thanks to the Open Security Foundation, we can 'dive' for them."
Some of my favorite highlights from recent incidents (I know, I shouldn't RTFM):
Names and Social Security numbers of at least 250,000 found through search engine
Date: 2008-12-02
Organizations: Florida Agency for Workforce Innovation
I guess there are many different ways you an innovate...
Social Security numbers of 341 posted on web
Date: 2008-12-04
Organizations: Economic Research Institute
If it's for research, then it's ok to post on the web...
Stolen laptop contains names and Social Security numbers of "several thousand " employees
Date: 2008-12-11
Organizations: Hewlett-Packard
If you thought only small time loser organizations like the first two on my list where subject to embarrassing data loss, that one would set you straight.
--
http://fairsoftware.net/ -- Software Bill Of Rights
I buy my saline kits from Chase Union Ltd in Movi, Michigan. The cost of a 1000 cc bag of sterile saline, drip tubing, sterile wipes (to wipe down your sac and all around) and catheter needle is with shipping around $25.
You can call them at +01 (248) 348-8191 and ask for item "MF 100" a scrotal inflation kit.
To do the saline, take the bag of saline and put in a microwave for about 5.5 minutes at low heat to warm to a bit above body temperature;about 100 degrees or so. Unwrap the outer plastic packaging and put the saline bag aside. Unwrap the drip tubing which comes with the kit and move the clamping system down toward the end opposite the vial type thing and CLOSE IT SHUT. Take the larger end of the drip tubing and uncap the protective cap........open the warmed bag of saline and remove the clear cap. Insert the drip tubing nozzle into the saline bag opening. Find a curtain rod, pot rack (which i have and use in the kitchen) shower rod or something elevated above you. Hang the bag of saline with the tubing attached and shut off. THEN VERY IMPORTANT. SQUEEZE SOME OF THE SALINE INTO THE VIAL ABOUT HALF WAY -THEN OPEN THE CLAMPING DEVICE AND BLEED ALL AIR OUT OF THE TUBING. YEAH YOU LOOSE A LITTLE BIT OF SALINE BUT THIS IS A MUST. YOU DON'T WANT ANY AIR OR AIR BUBBLES IN THE DRIP TUBING! REPLACE THE CAP ON THE WORKING END OF THE TUBING.
Before hand, while the bag of saline is warming either take a hot shower, or fill a basin or kitchen sink with very warm water sit in it for 4-7 minutes. The idea is to warm your ballsac skin up and let it get loose and hang.
When you have finished warming your sac, and you have the bag of saline (BLED FROM AIR), you are ready to grow.
With your sac still very warm use the wipes provided with the kit to wipe down your cock and ballsac. By the way, you will want an adjustable leather cock ring , nylon rope, or other type of removable cock/ball ring to wrap around cock and ballsac after inserting the catheter needle.
With you sac still warm and wiped down with antiseptics, sit in a chair with a towel underneath. Open the catheter needle don't get pansy here but with one hand, take the catheter needle and the teflon sheath that covers it and WITH THE OTHER HAND TAKE YOUR BALLSAC MOVING YOUR COCK OUT OF THE WAY AND DECIDE ON THE LOCATION OF THE INTENDED CATHETER NEEDLE. YOU NEED TO FOCUS ON THE AREA EITHER TO THE LEFT OR RIGHT SIDE OF YOUR BALLSAC AND UP CLOSE TO WHERE THE COCK CONNECTS. YOU PLACE THE CATHETER NEEDLE RIGHT BELOW THE COCK OR A LITTLE LOWER BUT TO ONE SIDE OR THE OTHER OF THE DARKER SKIN DIVIDING SKIN WHICH IS IN THE MIDDLE OF YOUR SAC.
DON'T GET SQUEEMISH BECAUSE THIS DOES NOT HURT. BUT INSERT THE CATHETER STRAIGHT DOWN CAUTIOUSLY INTO YOUR SAC. MOVE YOUR TESTICLE ASIDE YOU ARE GOING TO GO INTO THE BALLSAC CAVITY NOT THE TESTICLE.
YOU WILL EXPERIENCE A PRICK SENSATION,THEN A POP SENSATION AS THE CATHETER NEEDLE PIERCES THE MUSCLE TISSUE OF THE SCROTUM.
KEEP PUSHING THE CATHETER NEEDLE IN. IF IT GOES IN AND YOU FEEL FROM THE OTHER/OPPOSITE SIDE OF YOUR BALLSAC THAT THE NEEDLE IS THERE, THEN STOP.
Pull out the needle itself leaving the teflon sheath inserted into you sac. Tie yourself (cock and balls) off with some sort of removable cock ring or rope or robe tie or whatever.
Sit down, don' t plan to move around too much for the next 30 minutes - hour. Have your beers/soft drinks or whatever already out of the fridge. You will want to stay idle and focused while you do this.
While sitting, and close to the hanging bag of saline and the drip tubing, remove the protective cover of the end of the drip tubing, connect the drip tubing to the catheter sheath in you sac. THEN START ADJUSTING THE CLAMPING DEVICE OPEN TO ALLOW SALINE DRIPPING TO APPEAR IN THE VIAL UP BY THE BAG OF SALINE. ADJUST FOR AN EVEN DRIP DRIP DRIP FLOW AND NOT A STEADY STREAM OF SALINE.
If the saline doesn't drip at first, try pulling the catheter sheath out a bit until you at first experience a small burning sensation;it goes awa
A while ago, I was browsing around the downtrodden librarian, when I had to "walk the dog".
I've always wondered if the organisations that 'lose' data such as SS#s are diligent in warning potential victims of identity theft etc.
Totally ignorent in this area - perhaps someone here could clarify. What, if any, are the obligations of an organisation that holds sensitive data about you to inform you of it's potential or real loss?
Seems that this is a start, but it's still 'passive'. Some kind of active warning system would be better... After all, if someone's stolen my bank details and passwords, I'd really like to know, fast.
Sorry to reply to my own post, but hold your fire, grammer nazis - of course it should be "its".
We just need to somehow convince people that data is like a young blonde, attractive, girl. I'll even give you a sample police report:
Yesterday evening at 5:04pm, a young and attractive blonde female database was pushed into a UDP connection, which fled the scene shortly after...
#fuckbeta #iamslashdot #dicemustdie
Forget diving for it individually. Let OSF collect and collate, and task someone at /. with gathering and posting a weekly summary. It'd certainly serve a better purpose than "Ignore Mail". It'd bolster OSF's effort because, get serious now, which is going to be read more?
"I may be synthetic, but I'm not stupid." -- Bishop 341-B
Perhaps, to make it easier for the effected, we should just post the actual data that was lost. Then I could setup a google alert for my SSN/bank account number, and get an email when it's been found.
"Sunlight is the best disinfectant"?
Data breach notices have a scalability problem. As the number of notices soars, we need to better define what is a serious breach and what is not. Otherwise, the public drowns in breach notices, many of which are insignificant. --Ben http://hack-igations.blogspot.com/2007/12/does-lost-tape-equate-to-lost-data.html
Benjamin Wright, Dallas, Texas, benjaminwright.us
Despair saw it coming first
Considering that I've received notices of data nreaches at three current or former employers and from two government agencies all of which "may" have involved personal information including my date of birth, social security number, etc. Meanwhile, there's undoubtedly some organizations which have also lost data yet failed to report that fact, plus the likelihood that others have had breaches yet do not have my current contact information. It seems safe to assume that probably every bit of personal identity information for me is now in the public domain.
While I haven't yet become an identity theft victim, it seems like it's only a matter of time. Some agencies have offered 1-year enrollment in a credit monitoring service, others simply recommend that I should make sure to check my credit reports regularly. Gee thanks!
As infuriating as all of that is, what really gets my goat is all of the advice tossed out by many of these same agencies to be sure to shred bank statements before discarding them. While I agree that one shouldn't be careless with their own financial information: 1) it seems more likely that my personal information will be stolen from the very organizations that give me this advice than some neighborhood dumpster diver, and 2) if these agencies were even half as cautious with my information, these incidents would be a rarity.
Javascript, cookies, flash, and ActiveX must be enabled in order to view this sig.
"At the Data Loss Database."
"LOL"
be forgotten in a To place a paper the reaper In a Fueling internal to St1ck something had at lunchtime
The fundamental problem here isn't the data loss (other than a possible loss of privacy), but one of what someone other than the authorized owner of that information can do with it. Credit reporting agencies, property title offices, passport offices, and a whole host of other people need a much stronger form of authentication. These fools have ignored this problem for years, and impose costs not only on the victims but on everyone else due to prosecution, police investigation, etc..
From a practical security perspective, security on data use is really limited to the "something you have" aspect (i.e. your name/SSN/DoB/address), less on the "something you know" and rarely the "something you are" categories. Both government and private industry needs to wake up and start making it much more difficult for people to have anything bad done to them simply because someone uses their data ON TOP of mandating cryptography and security for information (which I deem to be separate concepts).
An idea - digitally sign the hash of a person's fingerprint, retina, signature and a non-obvious PIN (i.e. pictures, phrases, numbers, questions), put the root certificate authority in a government-controlled secure bunker or military base with FIPS 140 secured HSMs and multiple independent layered checks and balances, and use the signature/verification chain for both government and commercial uses.
our Ability 7o