Showing posts with label Data Breach. Show all posts
Showing posts with label Data Breach. Show all posts

Sunday, July 28, 2013

Cost of a Data Breach and Information collected about you on the Internet.

While we wait, talk and complain about our governments intrusion into our private lives we do very little about the professional criminal who is breaking into our web sites stealing our data. Curious isn't it?



The Real Cost of a Data Breach

Ok, now about all that data that we make freely available so we don't have to pay for services like google, youtube, hotmail, etc. Remember when your mom and dad said there was no such thing like a free lunch? They weren't wrong.


  1. Google Street View has collected over 5,000,000 miles of images 
  2. 58% of people are unaware of how data is gathered and shared online by advertisers 
  3. Facebook collects over 500 terabytes of data from its users each day 
  4. 50% of iOS apps track your location 
  5. Free apps are more than 4x as likely to access contact lists 
  6.  87% of US adults can be tracked via their mobile device

  7. Internet Privacy: How Much Data Does the Net Hold on You?

Sunday, March 25, 2012

Highlights from 2011 Verizon Data Breach Investigations Report


I have some of the key findings posted below from Verizons 2011 Data Breach Report. Nothing to surprising in the report; data breaches are occurring for two major reasons,  hacktivism and criminal intent. 

In 2010, the Secret Service arrested more than 1,200 suspects for cybercrime violations. These investigations involved over $500 million in actual fraud loss.

Because the increase in arrests criminals are opting to “play it safe” and are moving away from large-scale Financial Services firms and moving to hotels, restaurants, and retailers.

Verizon did write the story on data breaches is not changing every year. The story is the same each year. Some unstoppable attacker or some previous unknown method did not overpower the victims instead the victims knew how to stop the attacker with good proven best practices in infrastructure and software development.

Who were behind data breaches in 2011?
  • 92% stemmed from external agents (hackers).
  • 17% implicated insiders.


What commonalities exist in report data breaches?
  • 96% of breaches were avoidable through simple or intermediate controls.
  • 92% of attacks were not highly difficult.
  • 86% where discovered by a third party.
  • 83% of victims were targets of opportunity.


How did the breaches occur?
  • 50% utilized some for of hacking.
  • 49% incorporated malware 


Conclusions and Recommendations
  • Access Control
    • Change default credentials
    • User account review.
    • Restrict and monitor privileged users.          
  • Network Management
    • Secure remote access services
    • Monitor and filter egress network traffic
  • Secure Development
    • Application testing and code review
    • SQL injection
    • Cross-site scripting
    • Authentication bypass
    • Exploitation of session variables

  • Log Management and Analysis
    • Enable application and network witness logs and monitor them.
    • Define “suspicious” and “anomalous” (then look for whatever “it” is)

                                               





Saturday, March 24, 2012

Legislation in Congress Pursuing Data Breach Disclosure Measures


Last couple of posts I talked about current laws and how they relate to the fourth amendment.  In this post I will talk about three bills that are working it’s way though congress. These bills are in response to the Sony/Citigroup massive data breach.  As with any legislation it is unclear if these bills will make it to the floor to be voted on and if so what their final content will be. According to govtrack.us all three bills has an 8% chance of passing.

The first bill is S. 1408: Data Breach Notification Act of 2011. (http://www.govtrack.us/congress/bills/112/s1408) This bill will require federal agencies and business that “engage in interstate commerce “ and process data containing PII to disclose any breaches. Key point of this bill is…
  • A written notice of a security breach to individuals by mail, telephone, and e-mail.
  • Notice to major media outlets if a security breach involves more than 5,000 individuals.
  • A description of the categories of sensitive personally identifiable information acquired by an unauthorized person.
  • A toll-free telephone number for contacting an agency or business entity to ascertain the types of personal information maintained by such agency or entity.
  • The toll-free telephone numbers and addresses for the major credit reporting agencies. Authorizes a state to require that a notification also include information about victim protection assistance provided by that state.


The next bill is S. 1535: Personal Data Protection and Breach Accountability Act of 2011 (http://www.govtrack.us/congress/bills/112/s1535). A bill to protect consumers by mitigating the vulnerability of personally identifiable information (PII) to theft through a security breach, providing notice and remedies to consumers in the wake of such a breach, holding companies accountable for preventable breaches, facilitating the sharing of post-breach technical information between companies, and enhancing criminal and civil penalties and other protections against the unauthorized collection or use of PII.
Key points of this bill are…
  • Fine businesses that willfully concealing a security breach involving sensitive personally identifiable information.
  • Business must be interstate business that collects, accesses, transmits, uses, stores, or disposes of sensitive PII on 10,000 or more U.S.


The last bill is The Personal Data Privacy and Security Act of 2011 (http://www.govtrack.us/congress/bills/112/s1151). This bill tries preventing and mitigating identity theft, to ensure privacy, to provide notice of security breaches, and to enhance criminal penalties, law enforcement assistance, and other protections against security breaches, fraudulent access, and misuse of personally identifiable information. This bill defines PII as…
  • Specified combinations of data elements in electronic or digital form, such as an individual's first and last name or first initial and last name in combination with home address or telephone number, mother's maiden name, and date of birth.
  • A non-truncated social security number, driver's license number, passport number, or government-issued unique identification number.
  • Unique biometric data, such as a fingerprint, voice print, retina or iris image, or other unique physical representation.
  • A unique account identifier.
  • Any security code, access code, password, or secure code that could be used to generate such codes or passwords.