<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Loss of Privacy &#187; breach</title>
	<atom:link href="http://www.lossofprivacy.com/index.php/tag/breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lossofprivacy.com</link>
	<description>Keeping you informed on recent losses to privacy and civil rights worldwide.</description>
	<lastBuildDate>Tue, 07 Feb 2012 13:21:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Over 25,000 security breaches since November 2001 at America&#8217;s airports</title>
		<link>http://www.lossofprivacy.com/index.php/2011/07/over-25000-security-breaches-since-november-2001-at-americas-airports/</link>
		<comments>http://www.lossofprivacy.com/index.php/2011/07/over-25000-security-breaches-since-november-2001-at-americas-airports/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 02:27:36 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security Theater]]></category>
		<category><![CDATA[airports]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=4402</guid>
		<description><![CDATA[The DHS and TSA like to tell us that what they are doing is making America safer, but a new report by the House Oversight and Government Reform subcommittee shows that little to nothing has changed in security to prevent breaches from occurring. The breaches &#8212; amounting to about seven a day, or about five [...]]]></description>
			<content:encoded><![CDATA[
<p>The DHS and TSA like to tell us that what they are doing is making America safer, but a new report by the House Oversight and Government Reform <a href="http://www.lossofprivacy.com/index.php/2011/07/jason-chaffetz-airport-perimeter-security/">subcommittee</a> shows that little to nothing has changed in security to <a href="http://motherjones.com/mojo/2011/07/tsa-blasted-congress-gao-security-breaches">prevent</a> <a href="http://edition.cnn.com/2011/US/07/13/airport.security/">breaches</a> from occurring.</p>
<blockquote><p>The breaches &#8212; amounting to about seven a day, or about five per year at every airport &#8212; include everything from people who accidentally leave a bag on a checkpoint conveyor belt to those who purposefully evade security and get onto airplanes without proper screening.</p>
<p>A TSA spokesman did not contest the figure, but questioned its significance, saying all breaches are investigated and resolved. The agency said it did not have a breakdown of breaches by severity.</p></blockquote>
<p>This is the spin that the TSA puts on a real problem.  They dismiss it by saying that it&#8217;s not significant because they&#8217;ve been investigated and resolved.  It doesn&#8217;t address the original problem of preventing security breaches to begin with.  These breaches occur in places where they should never happen in the first place.</p>
<blockquote><p>&#8211; 14,322 breaches into secure entries, passages or other means of access to the secure side of the airport.</p>
<p>&#8211; Approximately 6,000 breaches involving a TSA screener failing to screen a passenger or a passenger&#8217;s carry-on property, or doing either improperly.</p>
<p>&#8211; 2,616 instances involving an individual getting past the checkpoint or exit lane without submitting to all screening and inspections. Some 1,388 of these have occurred at the perimeter areas of airports.</p></blockquote>
<p>None of these breaches should even be possible if the people the TSA hired actually did their job.  There is no excuse.  For the TSA to simply say that they <a href="http://www.msnbc.msn.com/id/43738969/ns/us_news-security/">don&#8217;t matter</a> because they&#8217;ve been investigated and resolved confirms to many people that the TSA is incompetent and should no longer exist as a force to protect airport security.</p>
<blockquote><p>TSA spokesman Nicholas Kimball said the figures represent a &#8220;tiny fraction of 1% percent of the more than 5.5 billion travelers at the more than 450 airports nationwide that we have screened effectively since 9/11.&#8221;</p></blockquote>
<p>It doesn&#8217;t matter if it is a tiny fraction.  The TSA is often quick to point out that new procedures that have included taking off your shoes and full body scanners, are put into place precisely to catch that tiny 1% that might do something wrong.  You cannot use that 1% to defend intrusions of privacy and then dismiss them as trivial and still expect to be taken seriously.  Either that 1% is important or it is not.</p>
<p>25,000 security breaches.  0 terrorist attacks prevented.  Those two facts illuminate just how ineffective and unnecessary the TSA really is.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2011%252F07%252Fover-25000-security-breaches-since-november-2001-at-americas-airports%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Over%2025%2C000%20security%20breaches%20since%20November%202001%20at%20America%27s%20airports%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2011%2F07%2Fover-25000-security-breaches-since-november-2001-at-americas-airports%2F&amp;linkname=Over%2025%2C000%20security%20breaches%20since%20November%202001%20at%20America%26%238217%3Bs%20airports" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2011%2F07%2Fover-25000-security-breaches-since-november-2001-at-americas-airports%2F&amp;linkname=Over%2025%2C000%20security%20breaches%20since%20November%202001%20at%20America%26%238217%3Bs%20airports" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2011%2F07%2Fover-25000-security-breaches-since-november-2001-at-americas-airports%2F&amp;title=Over%2025%2C000%20security%20breaches%20since%20November%202001%20at%20America%26%238217%3Bs%20airports" id="wpa2a_2"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2011/07/over-25000-security-breaches-since-november-2001-at-americas-airports/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Possible breach at SFO, but security finds out two hours later</title>
		<link>http://www.lossofprivacy.com/index.php/2011/02/possible-breach-at-sfo-but-security-finds-out-two-hours-later/</link>
		<comments>http://www.lossofprivacy.com/index.php/2011/02/possible-breach-at-sfo-but-security-finds-out-two-hours-later/#comments</comments>
		<pubDate>Sat, 12 Feb 2011 22:09:00 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Travel]]></category>
		<category><![CDATA[airports]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[Security Theater]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=3712</guid>
		<description><![CDATA[I work at an airport, and sometimes, while working on computers near a security point, a TSA person will come and chat to me. Yesterday, a TSO told me that last week, a person from the street (not even a passenger! Just a deranged guy who walked into the airport) had slipped through a security [...]]]></description>
			<content:encoded><![CDATA[
<blockquote><p>I work at an airport, and sometimes, while working on computers near a security point, a TSA person will come and chat to me. Yesterday, a TSO told me that last week, a person from the street (not even a passenger! Just a deranged guy who walked into the airport) had slipped through a security checkpoint by basically just walking between the wall and the checkpoint, ducking under or going around those black retractable belt things they use to make lines.</p>
<p>The kicker is, it took TSA 2 hours to figure it out, and it wasn&#8217;t anything to do with their amazing skills, either. The crazy guy was making trouble in the gate area and an airline employee called the police. The guy didn&#8217;t have a boarding pass or anything like that. Good job, TSA! Way to justify that budget.</p></blockquote>
<p>If true, and there&#8217;s no reason not to believe otherwise, it just <a href="http://www.reddit.com/r/OperationGrabAss/comments/fiqvw/while_talking_to_tsa_at_work_he_informs_me_that/">highlights how useless security is at the airport</a>.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2011%252F02%252Fpossible-breach-at-sfo-but-security-finds-out-two-hours-later%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Possible%20breach%20at%20SFO%2C%20but%20security%20finds%20out%20two%20hours%20later%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2011%2F02%2Fpossible-breach-at-sfo-but-security-finds-out-two-hours-later%2F&amp;linkname=Possible%20breach%20at%20SFO%2C%20but%20security%20finds%20out%20two%20hours%20later" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2011%2F02%2Fpossible-breach-at-sfo-but-security-finds-out-two-hours-later%2F&amp;linkname=Possible%20breach%20at%20SFO%2C%20but%20security%20finds%20out%20two%20hours%20later" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2011%2F02%2Fpossible-breach-at-sfo-but-security-finds-out-two-hours-later%2F&amp;title=Possible%20breach%20at%20SFO%2C%20but%20security%20finds%20out%20two%20hours%20later" id="wpa2a_4"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2011/02/possible-breach-at-sfo-but-security-finds-out-two-hours-later/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Easy to crack passwords revealed in RockYou hack</title>
		<link>http://www.lossofprivacy.com/index.php/2010/01/easy-to-crack-passwords-revealed-in-rockyou-hack/</link>
		<comments>http://www.lossofprivacy.com/index.php/2010/01/easy-to-crack-passwords-revealed-in-rockyou-hack/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 15:05:44 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[RockYou]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=2076</guid>
		<description><![CDATA[The recent RockYou hack has revealed, once again, why it&#8217;s so easy to do such things. People used predictable passwords despite the vast amount of warnings not to. Sensitive login credentials &#8211; stored in plain text &#8211; were left exposed because of a SQL injection bug in RockYou&#8217;s website. RockYou admitted the breach, which applied [...]]]></description>
			<content:encoded><![CDATA[
<p>The recent RockYou hack has <a href="http://www.theregister.co.uk/2010/01/21/lame_passwords_exposed_by_rockyou_hack/" target="_blank">revealed</a>, once again, why it&#8217;s so easy to do such things.  People used predictable passwords despite the vast amount of warnings not to.</p>
<blockquote><p>Sensitive login credentials &#8211; stored in plain text &#8211; were left exposed because of a SQL injection bug in RockYou&#8217;s website. RockYou admitted the breach, which applied to user password and email addresses for widgits it developed, and pledged to improve security in order to safeguard against future problems.</p></blockquote>
<p>From over 32 million passwords, the results were, sadly, not surprising.  The top ten were:</p>
<blockquote>
<ol>
<li>123456</li>
<li>12345</li>
<li>123456789</li>
<li>Password</li>
<li>iloveyou</li>
<li>princess</li>
<li>rockyou</li>
<li>1234567</li>
<li>12345678</li>
<li>abc123</li>
</ol>
</blockquote>
<p>While the top ten shouldn&#8217;t surprise you, the fact that over fifty percent of the passwords used regular names, slang, and common dictionary words should.  Even worse, the admins stored the information in plain text, something that should never be done.  Hashing the passwords is not difficult, yet <a href="http://www.rockyou.com/" target="_blank">RockYou</a> failed to do such a basic task.  RockYou also didn&#8217;t have simple security protocols in places, such as minimum password length, and alphanumeric passwords.</p>
<p>Users should be looking to create more <a href="http://www.us-cert.gov/cas/tips/ST04-002.html" target="_blank">difficult</a> <a href="http://www.microsoft.com/protect/fraud/passwords/create.aspx" target="_blank">passwords</a> or suffer the consequences of further breaches.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2010%252F01%252Feasy-to-crack-passwords-revealed-in-rockyou-hack%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2010%2F01%2Feasy-to-crack-passwords-revealed-in-rockyou-hack%2F&amp;linkname=Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2010%2F01%2Feasy-to-crack-passwords-revealed-in-rockyou-hack%2F&amp;linkname=Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2010%2F01%2Feasy-to-crack-passwords-revealed-in-rockyou-hack%2F&amp;title=Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack" id="wpa2a_6"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2010/01/easy-to-crack-passwords-revealed-in-rockyou-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virginia Health Records Hacked Into</title>
		<link>http://www.lossofprivacy.com/index.php/2009/05/virginia-health-records-hacked-into/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/05/virginia-health-records-hacked-into/#comments</comments>
		<pubDate>Mon, 11 May 2009 02:25:22 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[wikileaks]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=1133</guid>
		<description><![CDATA[With President Obama pushing for more electronic medical records, Americans need to look closely at just how well guarded their personal, medical information really is.  Wikileaks reports that the Virginia Prescription Monitoring Program was hacked into and over 8 million medical records are being held for a $10 million ransom in an encrypted database. &#8220;I [...]]]></description>
			<content:encoded><![CDATA[
<p>With President Obama pushing for more electronic medical records, Americans need to <a href="http://www.securityfocus.com/brief/957" target="_blank">look closely</a> at just how well <a href="http://voices.washingtonpost.com/securityfix/2009/05/hackers_break_into_virginia_he.html" target="_blank">guarded</a> their personal, medical <a href="http://www.schneier.com/blog/archives/2009/05/virginia_data_r.html#c369744" target="_blank">information</a> really is.  <a href="http://wikileaks.org/wiki/Over_8M_Virginian_patient_records_held_to_ransom,_30_Apr_2009" target="_blank">Wikileaks</a> reports that the <a href="http://www.pmp.dhp.virginia.gov/" target="_blank">Virginia Prescription Monitoring Program</a> was hacked into and over 8 million medical records are being held for a $10 million ransom in an encrypted database.</p>
<blockquote><p>&#8220;I have your [expletive] In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh <img src='http://www.lossofprivacy.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> For $10 million, I will gladly send along the password.&#8221;</p></blockquote>
<p>Virginia now has a <a href="http://www.dhp.virginia.gov/Statement050609.pdf" target="_blank">statement</a> [pdf] clarifying that the backups are fine and <a href="http://www.dhp.virginia.gov/PMPQA050609.pdf" target="_blank">details</a> [pdf] on what was stored on the files.</p>
<p>In October 2008, a <a href="http://voices.washingtonpost.com/securityfix/2008/11/extortionists_target_major_pha.html" target="_blank">similar</a> event occurred.  Though smaller in nature, these types of breaches will become commonplace if everyone&#8217;s medical information is digitized.  It&#8217;s just too easy for criminals to access.  There&#8217;s so much information in medical files that it&#8217;s a goldmine just waiting to be dug through.  Sometimes, low tech, i.e. paper, is still the best way to go.</p>
<p>Here&#8217;s something to think about.  Identity theft.  Hacking people&#8217;s medical records.  Getting hit by a car and sent, barely conscious, to the hospital.  Do you trust electronic medical records now?</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F05%252Fvirginia-health-records-hacked-into%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Virginia%20Health%20Records%20Hacked%20Into%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F05%2Fvirginia-health-records-hacked-into%2F&amp;linkname=Virginia%20Health%20Records%20Hacked%20Into" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F05%2Fvirginia-health-records-hacked-into%2F&amp;linkname=Virginia%20Health%20Records%20Hacked%20Into" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F05%2Fvirginia-health-records-hacked-into%2F&amp;title=Virginia%20Health%20Records%20Hacked%20Into" id="wpa2a_8"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/05/virginia-health-records-hacked-into/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Uncle Sam&#8217;s Travel Website Closed After Breach</title>
		<link>http://www.lossofprivacy.com/index.php/2009/02/uncle-sams-travel-website-closed-after-breach/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/02/uncle-sams-travel-website-closed-after-breach/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 00:43:03 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=946</guid>
		<description><![CDATA[Govtrip.com is the website that many federal employees are required to use when booking work related travel.  The site was shut down after it was infected with a virus. Sometime on Feb. 11, hackers changed the Govtrip.com Web site to redirect visitors to a site that installed malicious software&#8230;..Govtrip.com also is used to reimburse workers [...]]]></description>
			<content:encoded><![CDATA[
<p>Govtrip.com is the website that many federal employees are required to use when booking work related travel.  The site was <a href="http://voices.washingtonpost.com/securityfix/2009/02/travel-booking_site_for_federa.html" target="_blank">shut down</a> after it was infected with a virus.</p>
<blockquote><p>Sometime on Feb. 11, hackers changed the Govtrip.com Web site to redirect visitors to a site that installed malicious software&#8230;..Govtrip.com also is used to reimburse workers via direct deposit, which means that many federal employees&#8217; checking account information is stored there as well.</p></blockquote>
<p>Fortunately, as soon as the problem was noticed, the site was shut down.  On February 12th, many employees were being told how to manually book trips until the problem was solved.</p>
<blockquote><p>According to an analysis shared with Washingtonpost.com, the compromise of govtrip.com came from multiple sources and was fairly extensive.</p></blockquote>
<p>The government hopes to have the site fully restored by Monday, February 23rd.  Until then, Northrop Grumman, the company that had run the site, has had its authority revoked.  It seems that Northrop Grumman isn&#8217;t the best company for this sort of <a href="http://www.timesdispatch.com/rtd/news/state_regional/state_regional_govtpolitics/article/VITA14_20081213-212918/150464/" target="_blank">situation</a>, yet, they keep being awarded contracts to do so.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F02%252Funcle-sams-travel-website-closed-after-breach%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Uncle%20Sam%27s%20Travel%20Website%20Closed%20After%20Breach%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F02%2Funcle-sams-travel-website-closed-after-breach%2F&amp;linkname=Uncle%20Sam%26%238217%3Bs%20Travel%20Website%20Closed%20After%20Breach" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F02%2Funcle-sams-travel-website-closed-after-breach%2F&amp;linkname=Uncle%20Sam%26%238217%3Bs%20Travel%20Website%20Closed%20After%20Breach" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F02%2Funcle-sams-travel-website-closed-after-breach%2F&amp;title=Uncle%20Sam%26%238217%3Bs%20Travel%20Website%20Closed%20After%20Breach" id="wpa2a_10"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/02/uncle-sams-travel-website-closed-after-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monster.com Breached Again</title>
		<link>http://www.lossofprivacy.com/index.php/2009/01/monstercom-breached-again/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/01/monstercom-breached-again/#comments</comments>
		<pubDate>Sun, 25 Jan 2009 14:10:08 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[monster.com]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=861</guid>
		<description><![CDATA[Monster.com was attacked again and their database breached.  A similar incident occurred in 2007.  Back then, the company said they would make the site more secure and they would take security much more seriously.  Their new and improved security was breached a few months later, proving that security appears to be just lip service at [...]]]></description>
			<content:encoded><![CDATA[
<p>Monster.com was attacked <a href="http://news.bbc.co.uk/2/hi/technology/6956349.stm" target="_blank">again</a> and their <a href="http://www.pcworld.com/businesscenter/article/158270/monstercom_reports_theft_of_user_data.html" target="_blank">database</a> <a href="http://www.theregister.co.uk/2009/01/24/latest_monster_security_breach/" target="_blank">breached</a>.  A <a href="http://news.bbc.co.uk/1/hi/technology/6956349.stm" target="_blank">similar incident</a> occurred in 2007.  Back then, the company said they would make the site more secure and they would take security much more <a href="http://www.theregister.co.uk/2007/09/03/monster_warns_victims/" target="_blank">seriously</a>.  Their new and improved security was breached a few months later, proving that security appears to be just lip service at Monster.com.</p>
<blockquote><p>&#8220;This remote server held over 1.6 million entries with personal information belonging to several hundred thousands of candidates, mainly based in the US, who had posted their resumes to the Monster.com website,&#8221; reported Symantec.</p>
<p>Symantec said it had seen reports of phishing e-mails sent out to Monster.com users which were &#8220;very realistic&#8221; and contained &#8220;personal information of the victims&#8221;.</p>
<p>The e-mail encouraged users to download a Monster Job Seeker Tool, which was in fact a program that encrypted files in their computer and left a ransom note demanding money for their decryption.</p>
<p>The program used to access Monster.com user data was a Trojan, which are commonly used to gain access to bank details, usernames and passwords.</p></blockquote>
<p>Monster.com will also not be sending out emails to users to know of the breach, despite the fact that this is <a href="http://privacylaw.proskauer.com/2007/08/articles/security-breach-notification-l/massachusetts-is-39th-state-to-mandate-breach-notification/" target="_blank">illegal</a> in most states.  Instead, there is a small security update on the site&#8217;s main page.  It&#8217;s also easy to miss.</p>
<p>Though the company is offering <a href="http://help.monster.com/besafe/jobseeker/index.asp" target="_blank">help</a>, there&#8217;s little to be done by users who don&#8217;t keep their software up to date and IT administrators who haven&#8217;t kept up with the latest reports of attacks or tried to actually make the site more secure.</p>
<p>One major way they could have made the site more secure is by using simple password security.  If you happen to use the account on a public terminal and forget to log out, anyone can go back into your account and change your password to a new one.  There is no prompt for you to type in your old password before creating a new one.  Passwords are also not encrypted.  These are the basics of security and Monster.com continues to fail at them miserably.</p>
<p>My advice is to go and log into your account, if you have one.  Delete your resume and cover letter.  Then, change your password to some random alpha-numeric string.  Then, cancel your account and explain to Monster.com that three breaches of security in less than two years is completely unacceptable.  Also explain that not notifying its customers of the breach, not taking responsibility, and, in general, the overall decline in usability are the reasons they have lost you as a customer.  Incompetence and a lack of integrity are what got Monster.com into this mess.  It&#8217;s the reason why you should be leaving Monster.com as well.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F01%252Fmonstercom-breached-again%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Monster.com%20Breached%20Again%20%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F01%2Fmonstercom-breached-again%2F&amp;linkname=Monster.com%20Breached%20Again" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F01%2Fmonstercom-breached-again%2F&amp;linkname=Monster.com%20Breached%20Again" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F01%2Fmonstercom-breached-again%2F&amp;title=Monster.com%20Breached%20Again" id="wpa2a_12"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/01/monstercom-breached-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Prisoners&#8217; Health Records Go Missing</title>
		<link>http://www.lossofprivacy.com/index.php/2009/01/uk-prisoners-health-records-go-missing/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/01/uk-prisoners-health-records-go-missing/#comments</comments>
		<pubDate>Thu, 15 Jan 2009 01:06:35 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[UK Privacy]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[prisoners]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[usb]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=827</guid>
		<description><![CDATA[While everyone agrees that USB drives should be encrypted, you&#8217;d be hard-pressed to find anyone who thinks attaching the password to the USB drive is a good idea; until now. If you are, or were, a patient at Preston Prison in Lancashire, there&#8217;s a good chance that your medical records are out in the open.  [...]]]></description>
			<content:encoded><![CDATA[
<p>While everyone agrees that USB drives should be <a href="http://www.schneier.com/essay-199.html" target="_blank">encrypted</a>, you&#8217;d be hard-pressed to find anyone who thinks attaching the password to the USB drive is a good idea; <a href="http://www.lep.co.uk/news/Apology-after-prisoners39-health-info.4862265.jp" target="_blank">until now</a>.</p>
<p>If you are, or were, a patient at Preston Prison in Lancashire, there&#8217;s a good chance that your medical records are out in the open.  The USB drive went missing on 30 December 2008 and has yet to be found.</p>
<blockquote><p>The stick may have contained information of up to 6,360 patients. However, in some cases, individual patients had more than one entry.</p>
<p>The information included prisoners&#8217; surnames, prison number, cell location, age range, prison clinic appointment times and references to medical conditions such as asthma, diabetes, mental health and even sexual health references.</p>
<p>Health chiefs have apologised for the breach and have taken urgent action to prevent it happening again.</p>
<p>&#8220;Even though there is no risk to anyone&#8217;s ongoing treatment or care, we have plans in place to contact those affected to inform them of the breach and apologise.&#8221;</p></blockquote>
<p>Uh, this happened two weeks ago and you still haven&#8217;t contacted those who may be affected?</p>
<blockquote><p>Anyone with concerns should contact the PCT&#8217;s confidential information line on: 0845 609 9866. It is open 9am to 5pm seven day&#8217;s a week until January 23, 2009.</p></blockquote>
<p>Because after the 23rd, the police will go back to not caring about this problem anymore.</p>
<p>You might be thinking, “Who cares, they&#8217;re just prisoners and the information was lost somewhere in the prison,” but what you aren&#8217;t thinking about is that this isn&#8217;t the first time something like this has happened.  The British government seems to have a habit of <a href="http://www.lossofprivacy.com/index.php/2008/09/02/count-on-the-british-government-to-keep-losing-your-data/" target="_blank">losing the private data</a> on all of its citizens, from baby to adult, law-abiding to prisoner.  The USB drive was also lost in a place full of criminals.  Do you really think that anyone, prisoner or guard, isn&#8217;t going to be tempted to take this information and sell it?  How likely is it that it&#8217;s going to turn up anytime soon?  I believe that it would have already happened if an honest person had found it.</p>
<p>This is a huge problem that the British government doesn&#8217;t seem to care to fix.  Because it happened to prisoners, they seem to care even less.  Just remember, your private, personal information is only as secure as the idiot carrying it.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F01%252Fuk-prisoners-health-records-go-missing%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22UK%20Prisoners%27%20Health%20Records%20Go%20Missing%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F01%2Fuk-prisoners-health-records-go-missing%2F&amp;linkname=UK%20Prisoners%26%238217%3B%20Health%20Records%20Go%20Missing" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F01%2Fuk-prisoners-health-records-go-missing%2F&amp;linkname=UK%20Prisoners%26%238217%3B%20Health%20Records%20Go%20Missing" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F01%2Fuk-prisoners-health-records-go-missing%2F&amp;title=UK%20Prisoners%26%238217%3B%20Health%20Records%20Go%20Missing" id="wpa2a_14"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/01/uk-prisoners-health-records-go-missing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

