Personal Info of 3.5 Million Texans Was Publicly Accessible
SpaceGhost writes "The Houston Chronicle reports, 'Personal information of about 3.5 million Texans — including names, mailing addresses and Social Security numbers — was posted on a publicly accessible server at the state comptroller's office, much of it for more than a year.' Many of the records were for retired teachers and the unemployed, and they sometimes included DOB and drivers license numbers."
All your base are belong to us!
FRIST!
Fortunately the unemployed are less desirable than average for identity theft, so that will limit the losses a little bit.
I were in Texas, then I would have an easy claim to having my identity stolen for a good long time.
Pity.
I'm sure those 3.5 million Texans believe God will protect their data from misuse. Except from Satanists.
Names and addresses I can get from a phone book. SSNs are "not to be used for identification purposes." Thus, BFD.
Place blame squarely where it belongs: lending providers and others who use the SSN as some sort of magic key to an individual's identity. All it takes is a simple law and this shit could stop next week.
....even their screw ups.
How could that mistake have gone on for a year without somebody seeing it?
Better duck and cover. Typical person from Texas shoot first then ask questions later.
I'm Texan, and I was worried for a second that my data would be compromised. Then I saw who was affected and said "Phew! This is only the unproductive people!"
And before you flame me, if a Mr. Khan is even capable of making that much improvement to elementary+ education, when all the PhD educators in the US couldn't, yes, that means you were unproductive and students were generally excelling in spite of you, not because of you.
Information theory is life. The rest is just the KL divergence.
for propane and propane accessories. Maybe this will help the USPS.
=+300 million of us unchosens, not including the genuine native americans who are not inclined to expose themselves, having sovereignty in this territory.
what with searching for more terror, religious initiations, love etc..., do we really need clothes, or so-called 'private parts''? open society?
BFD? Then by all means, let's see your name, address, and SSN. ;)
I8-D
even private information disclosure :-)
Can I sue the state of Tex-ASS for damages?
As they say, things are always bigger in Texas, including STUPIDITY
( from using MICROCRAP )
Yours In Ashgabat,
Kilgore Trout
to get the info for illegal immigration.
"If any question why we died, Tell them because our fathers lied."
many people would object to giving up their "private parts".
Are you a grown up? I'm just asking because you don't represent yourself as one.
That is just what we need.
Joe Public: What do you mean I have to pay verisign a $100 a year just to file my taxes?
IRS Operative: You have to have your signature signed to prove who you are to us.
JP: You don't know who I am? Can you tax me if you can't identify me?
IRS: We can not tax you but you will be charged with tax evasion.
JP: How can you charge me if you don't know who I am?
IRS: Well first you will have to have your signature signed by verisign.
JP: Where did you get such a messed up idea like this?
IRS: From a slashdot poster.
seriously man this is a terrible idea.
"For I desired mercy, and not sacrifice" -- God
A few years ago, I found a publicly accessible server that belonged to the local K-12 school system in a medium sized city. By using the username "test," and password "test", any one could access all of the Individualized Education Plans (IEPs) that the school system kept for each and every one of its special education students. Probably, most of these documents were for "Gifted and Talented" children, and were standardized forms that had contact information. However, some of them almost certainly contained details about the learning disabilities that various children had.
Can't you read my question: Can I sue the state of Tex-ASS for damages?
Thanks for you (il)literacy.
What if Social Security Numbers + the Person's name were a Copyrighted Work? That would be the legal protection that would scare snarks!
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
... nothing to hide, nothing to worry? 1 2 3 That's how long it takes to be modded flamebait!
Perhaps I'm trolling, perhaps I'm not.
Dang. They *are* running the government like a business down there.
Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
Names, home addresses, email addresses, and home telephone numbers are posted by default for all UCLA students (including minors) on a publicly-accessible "directory" at http://directory.ucla.edu./ There are only 60,000 people associated with the university, but apparently it generates 3mm searches/mo... not surprising because it doesn't require a username or password and has only limited protection against scraping. One student was involved in the a mistaken identity case with the Rose Bowl stabbing and received (misplaced) death-threats from gang-bangers. Another student posted a racist video online and also received death threats and harassment (her actions were stupid but she didn't deserve what she got either). Neither knew that their information was out there. The school's response? We're subject to the CA Information Practices Act but don't consider this personally-identifiable information. "UCLA cannot change the default settings on URSA because that would violate UCLA’s policy, according to university registrar Anita Cotter." (http://www.dailybruin.com/index.php/article/2011/01/uclas_online_campus_directory_undermines_student_privacy) I'm pretty sure it was Hitler's policy to exterminate millions of Jews but that doesn't make it ethical, legal, or immutable, right? If you know anyone who is a disgruntled student at UCLA and feels like making a little cash with the help of a trial attorney, now's your chance.
Retired teachers and the unemployed, what do they have worth taking?
"I deeply regret the exposure of the personal information that occurred and am angry that it happened," [State Comptroller] Combs said in a statement.
[Translation] Let me put out this public statement saying absolutely nothing, but serving to CMA.
"I want to reassure people that the information was sealed off from any public access immediately after the mistake was discovered and was then moved to a secure location."
[Translation] I soiled myself, and berated my minions.
"We take information security very seriously"
[Translation] Oh *f+ck*! How am I going to spin this?
"...and this type of exposure will not happen again."
[Translation] With the grace of God, this'll all be forgotten by November, and I'll get reelected.
Some days it's just not worth
chewing through my restraints.
As the AG and the FBI are looking into matters: "Combs has endorsed legislation enhancing information security, including a proposal that each agency designate a chief privacy officer and another to create a state Information Security Council."
Gee Susan, I think the horse has left this burning barn...unless you're looking for ways to spread the blame the next time this happens?
Some days it's just not worth
chewing through my restraints.
Also, on a semi-related note, your name looks familiar and I've been meaning to ask you if you used to hang out at a right wing American politics site (I stopped being a regular there in early 2009). If you're the same Kilgore Trout, I think I know you from somewhere.
The press release regarding this incident says that those responsible for the breach were fired. Sadly, that doesn't mean the Chief Technology Officer is accepting responsibility for enabling an infrastructure to exist where this could happen. He's still there:
http://www.txdirectory.com/online/person/?id=21676&staff=2476
He's a political appointee who has followed Susan Combs from job-to-job. After this fiasco and the Texas State Budget overrun of $27 billion, this could very well be Combs' last campaign win for some time.
Sadly, some lower-level scapegoats will be looking for jobs sooner rather than later.
Especially the fuckups!
I've abandoned my search for truth; now I'm just looking for some useful delusions.
It's okay, I'm not using mine anyway...
I've abandoned my search for truth; now I'm just looking for some useful delusions.
Inquiring minds want to know....
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
The "not for identification" on the Social Security Card didn't mean "You may not use the Social Security Number for Identification" - it wasn't a pro-privacy imperative.
It was simply a disclaimer that the Social Security Administration was making no promises that the card they'd handed out was of any use for identifying the person now holding it. It was a card providing information, not identification.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
WHO CARES?!?!
Only if you hunt them all down, and remove their over sized *sses?
Only in Texas! a XXXXXL tee-shirt that you can use as a car cover.
Only criminals have something to hide by demanding privacy!
In Sweden all this information is public for all citizens. Private organizations do however need a permit to keep a registry with personal information.
Erik Dalén
And the entire database is now online in one zip file shared over the usual clandestine networks for your viewing pleasure.
Never attribute to malice that which is adequately explained by stupidity.
Never go to sea with two chronometers; take one or three.
Names and addresses I can get from a phone book. SSNs are "not to be used for identification purposes." Thus, BFD.
Place blame squarely where it belongs: lending providers and others who use the SSN as some sort of magic key to an individual's identity. All it takes is a simple law and this shit could stop next week.
The world is perfect. People obey the laws, and nobody takes unfair advantage of anyone else. Thus, BFD.
PPlace blame squarely where it belongs: criminals and malcontent who try to get things dishonestly. All you have to do is get rid of the bad people and it's puppies and rainbows forever.
Yeah, when looking for a name for your kid, write a poem and use that as the name. And if anyone uses the name without permission, invoke the DMCA.
The Tao of math: The numbers you can count are not the real numbers.
There are any number of publicly accessible (or for-fee) search sites where all manner of personal information is available. The US Government is not particularly careful about how, where, and what they store about citizens. True, the SSN was not "meant" to be used as a means of identification, but it IS used as such (hence identity theft). Like the fire team getting to the bar-be-que says, "Where's the fire"?
Having names, addresses, driver's license, voting, DOB, marriage, titles, deeds, etc ad nauseum is nothing new. Creating "new" legislation in response to such events is equally pointless as the previous "law" left unenforced.