Risk Factor iconRisk Factor

Yes, Virginia: IT Security Does Seem to Be Getting Worse

USA Today reported this week that more than 162 million personal records have been reported lost or stolen in 2007, triple the 49.7 million that were reported missing in 2006.

The story notes that: "Volunteers at Attrition.org keep track of incidents, mostly in the USA, many of which are made public to meet new data-loss-disclosure laws. Of more than 300 cases tracked in 2007, 261 were reported in the USA, 16 in Great Britain, 15 in Canada, six in Japan, two in Australia, and one each in Denmark, Ireland, Sweden and Norway."

This is likely an undercount, since when the story was written, the latest cases in the Canada and the UK were not yet reported.

The story also noted that arrests or prosecutions have been reported in just 19 cases.

Okay, there is just a little under three weeks until 2008. Any guess for the final 2007 tally as provided by Attrition.org? I figure it will be around 170 million - I'm counting on the good folks in the UK government to help make the number.

Grab the Waders: UK Flood of Lost Personal Info

wading-boots-2.gif The Driver and Vehicle Agency in Coleraine, Co Derry has admitted Tuesday that two unencrypted computer discs containing the names and addresses of over 6 000 motorists in Northern Ireland have been lost in the post.

Separately, the HM Prison Service disclosed that confidential personal details of dozens of prisoners intended to be sent to Norfolk police were instead delivered to a private company. The letters gave names, criminal histories and addresses of more than 40 serious offenders that were being released - including pedophiles.

Similarly, the National Health Service (NHS) that Sefton Primary Care Trust has sent thousands of staff records to four private companies by mistake. The personal details included dates of birth, national insurance numbers, pensions and salary details.

Then yesterday, the NHS also confirmed that a computer disc containing the names, dates of birth and addresses of 160,000 children data was sent to St Leonard's Hospital in Hackney but failed to reach the right department - even though it was signed for by hospital staff. At least in this case, the data was encrypted using a 256 bit cipher.

UK Data Loss: No Harm, No Foul

CD_Object.gif UK Prime Minister Gordon Brown was asked MP Edward Leigh during a meeting with the Parliamentary IT body Pitcom about the IT security issues at HM Revenue and Customs (HMRC) and whether they represented a systemic failure. According to the Register, Brown said there was a difference between rules not being followed and failure of procedures and systems. (True, but irrelevant.)

Brown also added that no one had lost any money.

Right then, no harm, no foul. Play on!

Déjà vu - Sensitive Canadian Data Missing in Post

It is being reported by CTV.CA that private medical information on 140 British Columbia and 480 New Brunswick residents contained on four unencrypted magnetic tapes disappeared. Information on the tapes includes names, Medical Services Plan numbers, birth dates and possibly some description of services rendered and the costs of those services.

The information was "misplaced" on October 5, but New Brunswick medicare authorities were not made aware of the loss until Oct. 25. The province's director of medicare operations did not know about the vanished information until Nov. 29.

B.C. Information and Privacy Commissioner David Loukidelis who is investigating the loss said that he was "appalled that health information is being transmitted in such an insecure way."

Who Speaks For Humans?

alien-mask-3.gif In today's Wall Street Journal, there was a note regarding a story that is in Seed science magazine regarding the question:

"If aliens are out there, how should Earthlings go about getting in touch with them?"

"The question has provoked arcane but furious debate among scientists searching for extraterrestrials. Because scientists haven't picked up signs of alien life near Earth, the debate is essentially philosophical, revolving around such issues as who rightly speaks for humanity and whether humans want to draw the attention of possibly hostile life forms."

"A dispute erupted recently among scientists over an effort to draft a protocol for messages going from Earth into space, reports David Grinspoon in Seed, a science magazine. Several scientists who believe that governments and other scientists should be consulted prior to any space-bound communications resigned in protest from a prominent study group on extraterrestrial intelligence."

This got me to thinking about my earlier post on Microsoft's error reporting, and my joking reference about it possibility being a search for artificial intelligence. However, what happens if a computer does indeed become self aware? Who speaks for the human race, and does the first self-aware computer speak for ones that come after it?

UK Data Scandal Was Predicted Years Ago

CD_Object.gif Last week, Forbes reported that Prime Minister Gordon Brown disagreed with the acting chairman of the HM Revenue and Customs (HMRC) David Hartnett's portrayal that the numerous HMRC data breaches over the past few years "may well" indicate a systemic operational failure.

"I don't accept that that is what the chairman ...said," said Brown.

Okay, I guess he didn't say it.

Over the weekend, the Sunday Telegraph published a story that said senior HMRC officials were warned by auditors in March 2004 that, ".. letting junior staff have access to the entire system was a recipe for disaster." The auditors also said, "... mistakes would not be detected and that the system was open to fraud."

Hmm, again I am left to wonder what actually does constitute a systemic operational failure in the eyes of senior UK government officials?

Phishing for Cyberlove with Robo-Lovers

heart.gif According to the London Telegraph, "flirting robots" are invading Russian dating websites with the aim of gaining personal information from unsuspecting victims. CyberLover is one such robot that masquerades as a person seeking love on-line, according to the story. It interacts with a potential victim asking questions like, "When's your birthday? Where can I send you a Valentine's Day card?" and so on. The fear is that these robo-lovers could soon be invading popular social networks phishing for information.

I wonder what happens when one robo-lover encounters another on-line? Do they exchange code words so they know that the other is one of their own? Or do they just keep chatting one another up forever?

Microsoft Error Reporting: Really A Search for Artificial Life?

In historian Felipe Fernández-Armesto's survey book Ideas that Changed the World, there is a section entitled "Impossibilism." In it, he reviews some of the paradoxes that philosophers like William of Ockhamâ''s raised for contentious debate in the 14th century, such as â''God can order you to commit murderâ'' or â''God can reward good with evil.â''

If William of Ockham were alive today, he would probably coin something appropriate about Microsoftâ''s problem reporting.

As I noted a few weeks ago, Microsoft captures and analyzes those errors that unfortunately but not unexpectedly pop up every so often, which on some days provides Microsoft with 50 gigabytes worth of problem data.

I was recently sent a link to a screen shot of an error message that I have never encountered:

Windows Problem Reporting Has Stopped Working

A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.

As the comments at the link note, this error message poses some very interesting philosophical paradoxes and implications. For instance, how can a solution be sent if the problem reporting scheme is not working? How can a solution even be available if the problem is not reported? Or does it really indicate that Windows has developed HAL-like self-awareness? This could help explain Microsoft's Potty Mouth Santa.

All this made me wonder whether:

a) Microsoft has another error monitoring program to watch for when its Windowâ''s Problem Reporting code has an error, and whether there is another one to watch for that one to have an error, and so on: all this watch watching might explain why its operating systems are so large, and;

b) if (a) above is not true, does the Microsoft error analyst team have a category for this specific types of error, waiting in hopes of an error turning up some day indicating that in fact Windows is now self-aware, kind of like the SETI folks do in waiting for that special signal from space to appear?

SBInet Lives!

lemon-halves.gif If some convenient major news event isn't happening, then government officials like to use Friday afternoons to bury bad news or to make announcements that they don't want looked at too closely.

As I wrote on Friday, things were pretty quiet on the SBInet front, when, lo and behold, the Department of Homeland Security (DHS) announced Friday afternoon that it had conditionally accepted Boeing's border-surveillance system. DHS Secretary Michael Chertoff said that it was now going to run a 45-day operational system stress test before giving final acceptance.

However, I doubt that the stress test will result in failure, regardless of the real results. Along with this "conditional acceptance" Boeing was awarded a $64 million task order to design, develop and test an upgraded "common operating picture software system" for the Custom and Border Protection (CBP) command centers and agent vehicles to make the system more user friendly. Don't you think if there was any real doubt about accepting the system, the contract award would have been delayed for six weeks?

More likely, the system stress test is meant more to fend off Congressional criticism than as a means of generating information on which to make a final acceptance decision: i.e., dressing up the lemon.

As the Arizona Daily Star reported (subscription may be required), "After the 45 days, officials will put in orders for additional changes, Chertoff said. Full acceptance of the system depends on the results of the test run."

Furthermore, the paper said, that despite the lengthy delays and the doubling of costs in the launch of Boeing's pilot project, Chertoff said that DHS "isn't worried about Boeing designing and implementing similar systems along the rest of the border. 'We picked a particularly demanding area of the border, with a lot of ground clutter,' Chertoff said. 'So it should be a good kind of challenge,and some other parts of the border should be easy.' " I guess Chertoff nor the DHS have ever heard of software system scalability problems especially in using commercial-off-the-shelf (COTS) components.

Boeing was also quoted as saying that that the company "learned valuable lessons" during the work that will reduce future risk. Of course, the whole project was sold as being low risk from the beginning, but who keeps track of those promises, right?

LAUSD Payroll Repayments - A Little Slack for Employees

stop.gif The LA Times last week reported that Los Angeles Unified School District (LAUSD) has decided to extend its deadline to recoup most of the $53 million that it believes to have been overpaid to about 32,000 employees because of its faulty payroll system.

The Times writes that the LAUSD had originally "set a Nov. 26 deadline for workers to decide whether to repay the entire amount they had reportedly received, repay only the amount they believe they were overpaid, or refuse to pay anything. Employees were also warned that if repayments were not made by Dec. 10, they would also have to repay additional money withheld by the district for state and federal taxes."

The new dates for employees were the December 7th regarding how they wished to proceed, and now they have until Dec. 17 to make any repayments.

About 2,400 LAUSD employees have decided to contest the district's claims and are refusing to pay some or all of the amounts demanded, because they don't trust the figures the LAUSD has provided to them.

The LAUSD is putting none too subtle pressure on those 2,400 to accept the amount they are said to owe nevertheless.

As the Times reports, "those disagreements won't be discussed until next year, when district and union officials can set up a resolution process. But by then the district will have paid taxes on over-payments, and employees will be faced with the prospect of seeking refunds for themselves from tax agencies."

LAUSD officials believe that most of their payroll problems are behind them, but if a large number of its 2,400 employees who are contesting their alleged over-payments are shown to be indeed correct in their suspicions, the mess will have only just begun.


Risk Factor

IEEE Spectrum's risk analysis blog, featuring daily news, updates and analysis on computing and IT projects, software and systems failures, successes and innovations, security threats, and more.

Willie D. Jones
Load More