<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Loss of Privacy &#187; data breach</title>
	<atom:link href="http://www.lossofprivacy.com/index.php/tag/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lossofprivacy.com</link>
	<description>Keeping you informed on recent losses to privacy and civil rights worldwide.</description>
	<lastBuildDate>Sat, 04 Feb 2012 16:54:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Easy to crack passwords revealed in RockYou hack</title>
		<link>http://www.lossofprivacy.com/index.php/2010/01/easy-to-crack-passwords-revealed-in-rockyou-hack/</link>
		<comments>http://www.lossofprivacy.com/index.php/2010/01/easy-to-crack-passwords-revealed-in-rockyou-hack/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 15:05:44 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[RockYou]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=2076</guid>
		<description><![CDATA[The recent RockYou hack has revealed, once again, why it&#8217;s so easy to do such things. People used predictable passwords despite the vast amount of warnings not to. Sensitive login credentials &#8211; stored in plain text &#8211; were left exposed because of a SQL injection bug in RockYou&#8217;s website. RockYou admitted the breach, which applied [...]]]></description>
			<content:encoded><![CDATA[
<p>The recent RockYou hack has <a href="http://www.theregister.co.uk/2010/01/21/lame_passwords_exposed_by_rockyou_hack/" target="_blank">revealed</a>, once again, why it&#8217;s so easy to do such things.  People used predictable passwords despite the vast amount of warnings not to.</p>
<blockquote><p>Sensitive login credentials &#8211; stored in plain text &#8211; were left exposed because of a SQL injection bug in RockYou&#8217;s website. RockYou admitted the breach, which applied to user password and email addresses for widgits it developed, and pledged to improve security in order to safeguard against future problems.</p></blockquote>
<p>From over 32 million passwords, the results were, sadly, not surprising.  The top ten were:</p>
<blockquote>
<ol>
<li>123456</li>
<li>12345</li>
<li>123456789</li>
<li>Password</li>
<li>iloveyou</li>
<li>princess</li>
<li>rockyou</li>
<li>1234567</li>
<li>12345678</li>
<li>abc123</li>
</ol>
</blockquote>
<p>While the top ten shouldn&#8217;t surprise you, the fact that over fifty percent of the passwords used regular names, slang, and common dictionary words should.  Even worse, the admins stored the information in plain text, something that should never be done.  Hashing the passwords is not difficult, yet <a href="http://www.rockyou.com/" target="_blank">RockYou</a> failed to do such a basic task.  RockYou also didn&#8217;t have simple security protocols in places, such as minimum password length, and alphanumeric passwords.</p>
<p>Users should be looking to create more <a href="http://www.us-cert.gov/cas/tips/ST04-002.html" target="_blank">difficult</a> <a href="http://www.microsoft.com/protect/fraud/passwords/create.aspx" target="_blank">passwords</a> or suffer the consequences of further breaches.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2010%252F01%252Feasy-to-crack-passwords-revealed-in-rockyou-hack%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2010%2F01%2Feasy-to-crack-passwords-revealed-in-rockyou-hack%2F&amp;linkname=Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2010%2F01%2Feasy-to-crack-passwords-revealed-in-rockyou-hack%2F&amp;linkname=Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2010%2F01%2Feasy-to-crack-passwords-revealed-in-rockyou-hack%2F&amp;title=Easy%20to%20crack%20passwords%20revealed%20in%20RockYou%20hack" id="wpa2a_2"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2010/01/easy-to-crack-passwords-revealed-in-rockyou-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Medical breaches rarely make national headlines</title>
		<link>http://www.lossofprivacy.com/index.php/2009/12/medical-breaches-rarely-make-national-headlines/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/12/medical-breaches-rarely-make-national-headlines/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 02:32:17 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Daily Censored]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=1888</guid>
		<description><![CDATA[Medical breaches often get a mention in a local or state paper, but rarely do they make national headlines.  Over the past two months, there have been numerous breaches, barely getting a mention, but, when taken as a whole, reveal just how at risk our personal information really is. Read the rest of my lengthy [...]]]></description>
			<content:encoded><![CDATA[
<p>Medical breaches often get a mention in a local or state paper, but <a href="http://information-security-resources.com/2009/12/02/healthcare-data-breaches-slow-to-surface/" target="_blank">rarely</a> do they make national headlines.  Over the past two months, there have been numerous breaches, barely getting a mention, but, when taken as a whole, reveal just how at risk our personal information really is.</p>
<p><a href="http://dailycensored.com/2009/12/06/medical-breaches-rarely-make-national-headlines/" target="_blank">Read the rest</a> of my lengthy article at The Daily Censored.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F12%252Fmedical-breaches-rarely-make-national-headlines%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Medical%20breaches%20rarely%20make%20national%20headlines%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F12%2Fmedical-breaches-rarely-make-national-headlines%2F&amp;linkname=Medical%20breaches%20rarely%20make%20national%20headlines" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F12%2Fmedical-breaches-rarely-make-national-headlines%2F&amp;linkname=Medical%20breaches%20rarely%20make%20national%20headlines" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F12%2Fmedical-breaches-rarely-make-national-headlines%2F&amp;title=Medical%20breaches%20rarely%20make%20national%20headlines" id="wpa2a_4"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/12/medical-breaches-rarely-make-national-headlines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do a quick check to see if your personal data could be lost</title>
		<link>http://www.lossofprivacy.com/index.php/2009/09/do-a-quick-check-to-see-if-your-personal-data-could-be-lost/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/09/do-a-quick-check-to-see-if-your-personal-data-could-be-lost/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 10:46:54 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[UK Privacy]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[open rights group]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=1537</guid>
		<description><![CDATA[If you live in the UK, The Open Rights Group (UK EFF) has a series of 28 questions for you to answer and find out how likely it is the government has lost your private data. Given the recent revelations, it&#8217;s likely you have some data that is now missing.]]></description>
			<content:encoded><![CDATA[
<p>If you live in the UK, The Open Rights Group (UK EFF) has a series of <a href="http://www.openrightsgroup.org/dataloss/" target="_blank">28 questions for you to answer</a> and find out how likely it is the government has lost your private data.</p>
<p>Given the recent <a href="http://www.computerweekly.com/Articles/2009/08/27/237469/home-office-lost-377000-names-on-memory-stick.htm" target="_blank">revelations</a>, it&#8217;s likely you have some data that is now missing.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F09%252Fdo-a-quick-check-to-see-if-your-personal-data-could-be-lost%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Do%20a%20quick%20check%20to%20see%20if%20your%20personal%20data%20could%20be%20lost%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F09%2Fdo-a-quick-check-to-see-if-your-personal-data-could-be-lost%2F&amp;linkname=Do%20a%20quick%20check%20to%20see%20if%20your%20personal%20data%20could%20be%20lost" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F09%2Fdo-a-quick-check-to-see-if-your-personal-data-could-be-lost%2F&amp;linkname=Do%20a%20quick%20check%20to%20see%20if%20your%20personal%20data%20could%20be%20lost" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F09%2Fdo-a-quick-check-to-see-if-your-personal-data-could-be-lost%2F&amp;title=Do%20a%20quick%20check%20to%20see%20if%20your%20personal%20data%20could%20be%20lost" id="wpa2a_6"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/09/do-a-quick-check-to-see-if-your-personal-data-could-be-lost/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massive data breach at Network Solutions</title>
		<link>http://www.lossofprivacy.com/index.php/2009/07/massive-data-breach-at-network-solutions/</link>
		<comments>http://www.lossofprivacy.com/index.php/2009/07/massive-data-breach-at-network-solutions/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 14:15:13 +0000</pubDate>
		<dc:creator>Irene</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[Network Solutions]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.lossofprivacy.com/?p=1349</guid>
		<description><![CDATA[A massive data breach at Network Solutions lasted three months, but its customers were just informed yesterday, after the close of business. Susan Wade, Director of Public Relations for Network Solutions, spoke to The Tech Herald and explained some of the finer points to the DSA issued on Friday. Currently there is an investigation underway, [...]]]></description>
			<content:encoded><![CDATA[
<p>A <a href="http://voices.washingtonpost.com/securityfix/2009/07/network_solutions_hack_comprom.html" target="_blank">massive</a> <a href="http://www.thetechherald.com/article.php/200930/4128/Network-Solutions-573-928-possibly-compromised-in-attack" target="_blank">data breach</a> at Network Solutions lasted <a href="http://blogs.channelinsider.com/secure_channel/content/network_security/network_solutions_suffers_large_data_breach.html" target="_blank">three months</a>, but its customers were just <a href="http://www.careandprotect.com/feedback/e-commerce-data-security-alert%E2%80%93-some-merchants-were-affected-but-problem-is-fixed/" target="_blank">informed</a> yesterday, after the close of business.</p>
<blockquote><p>Susan Wade, Director of Public Relations for Network Solutions, spoke to The Tech Herald and explained some of the finer points to the DSA issued on Friday. Currently there is an investigation underway, and notices are going out to the 4,343 customers via email and postal notifications.</p>
<p>Wade explained that the malicious code was discovered during routine operations on a subset of servers that house the E-Commerce platform offered to Network Solutions customers.</p>
<p>E-Commerce customers are on a set of servers that are segmented from the Network Solutions infrastructure. The subset of servers where the malicious code was discovered hosted the 4,343 merchant sites that were attacked. Another point of interest is that the malicious code was discovered on only a fraction of the sites hosted for E-Commerce operations, where there are more than 10,000 sites overall.</p>
<p>The code may have captured transaction data from 573,928 cardholders during its run this spring. Network Solutions said that the merchants’ customers were exposed from March 12, 2009 until June 8, 2009. The level of exposure could vary depending on transaction volume, but transactions made after June 8, 2009 were not exposed to attack, as the hijacked sites were cleaned by then.</p>
<p>There is no information on how the code was planted on the sites. While examination of the code shows that it had the ability to ship data off to a third party, and Network Solutions believes that it did just that, the exact code is not available for public review. There is also no public information as to where the data believed to be stolen was sent.</p></blockquote>
<p>So, three months on and they still have no clue how the breach occurred, if the information has been used for malicious purposes or who is responsible.  Considering the fact that Network Solutions retains a large amount of personal account details for many online businesses, one would think that they would have better security measures in place.  Apparently, they don&#8217;t.</p>
<div class="topsy_widget_data topsy_theme_silver" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.lossofprivacy.com%252Findex.php%252F2009%252F07%252Fmassive-data-breach-at-network-solutions%252F%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Massive%20data%20breach%20at%20Network%20Solutions%22%20%7D);"></div>

<p><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F07%2Fmassive-data-breach-at-network-solutions%2F&amp;linkname=Massive%20data%20breach%20at%20Network%20Solutions" title="Twitter" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F07%2Fmassive-data-breach-at-network-solutions%2F&amp;linkname=Massive%20data%20breach%20at%20Network%20Solutions" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lossofprivacy.com%2Findex.php%2F2009%2F07%2Fmassive-data-breach-at-network-solutions%2F&amp;title=Massive%20data%20breach%20at%20Network%20Solutions" id="wpa2a_8"><img src="http://www.lossofprivacy.com/wp-content/plugins/add-to-any/share_16_16.png" width="16" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.lossofprivacy.com/index.php/2009/07/massive-data-breach-at-network-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

