Companies beware: The next big leak could be yours
December 2, 2010 By JORDAN ROBERTSON , AP Technology Writer
The Internet homepage of Wikileaks is shown in this photo taken in New York, Wednesday, Dec. 1, 2010. WikiLeaks' release of secret government communications should serve as a warning to the nation's biggest businesses: You're next. (AP Photo/Richard Drew)
(AP) -- WikiLeaks' release of secret government communications should serve as a warning to the world's biggest companies: You're next.
Computer experts have warned for years about the threat posed by disgruntled insiders and by poorly crafted security policies, which give too much access to confidential data. And there is nothing about WikiLeaks' release of U.S. diplomatic documents to suggest that the group can't - or won't - use the same methods to reveal the secrets of powerful corporations.
And as WikiLeaks claims it has incriminating documents from a major U.S. bank, possibly Bank of America, there's new urgency to addressing information security inside corporations and a reminder of its limits when confronted with a determined insider.
At risk are companies' innermost secrets - e-mails, documents, databases and internal websites that are thought locked to the outside world. Companies create records of every decision they make, whether it's rolling out new products, pursuing acquisitions, fighting legislation, foiling rivals or allowing executives to sell stock.
Although it's easy technologically to limit who in a company sees specific types of information, many companies leave access far too open. And despite the best of intentions, mistakes happen and settings can become inadvertently broad, especially as networks grow more complex with reorganizations and acquisitions.
And even when security technology is doing its job, it's a poor match if someone with legitimate access decides to go rogue.
With the right access, a cheap thumb drive and a vendetta are the only ingredients an insider needs to obtain and leak secrets. By contrast, outside attackers often have to compromise personal computers at the bottom of the food chain, then use their skills and guile in hopes of working their way up.
Employees go rogue all the time - for ego, to expose hypocrisy, to exact revenge or simply for greed.
A former analyst with mortgage lender Countrywide Financial Corp., now owned by Bank of America, is awaiting trial on charges he downloaded data on potentially 2 million customers over two years, charging $500 for each batch of 20,000 profiles. Prosecutors say the analyst worked secretly on Sundays, using an unsecured Countrywide computer that allowed downloads to personal thumb drives. Other home loan companies bought the customer profiles, including Social Security numbers, for new sales leads, according to authorities.
Also, an employee with Certegy Check Services Inc., a check authorization service, was accused of stealing information on more than 8 million people and selling it to telemarketers for a haul of $580,000. The worker was sentenced in 2008 to nearly five years in prison.
Despite the repeated warnings, many large companies lack clear policies on who should have access to certain data, said Christopher Glyer, a manager with the Mandiant Corp., an Alexandria, Va.-based security firm that investigates computer intrusions.
WikiLeaks argues that revealing details of companies and governments behaving badly, no matter how the information is obtained, is good for democracy.
Julian Assange, WikiLeaks' founder, told Forbes magazine that the number of leaks his site gets has been increasing "exponentially" as the site has gotten more publicity. He said it sometimes numbers in the thousands per day.
Assange told Forbes that half the unpublished material his organization has is about the private sector, including a "megaleak" involving a bank. He would not name the bank, but he said last year in an interview with Computerworld that he has several gigabytes of data from a Bank of America executive's hard drive.
Assange also told Forbes that Wikileaks has "lots" of information on BP PLC, the London-based oil company under fire for the massive Gulf of Mexico oil spill. Assange said his organization is trying to figure out if its information on BP is unique.
WikiLeaks previously published confidential documents from the Swiss bank Julius Baer and the Kaupthing Bank in Iceland. The site also published an operation manual for the U.S. prison in Guantanamo Bay, Cuba.
WikiLeaks' most recent leaks exposed frank and sometimes embarrassing communications from diplomats and world leaders. They included inflammatory assessments of their counterparts and international hot spots such as Iran and North Korea.
The prime suspect in the diplomatic leaks, Army Pfc. Bradley Manning, is being held in a maximum-security military brig at Quantico, Va., charged in connection with an earlier WikiLeaks release: video of a 2007 U.S. Apache helicopter attack in Baghdad that killed a Reuters news photographer and his driver.
Military investigators say Manning is a person of interest in the leak of nearly 77,000 Afghan war records WikiLeaks published online in July. Though Manning has not been charged in the latest release of internal U.S. government documents, WikiLeaks has hailed him as a hero.
Manning boasted to a hacker confidant that security was so flimsy he was able to bring a homemade music CD into work, delete its contents and fill it with secrets, according to a log of the exchange posted by Wired.com.
Experts said a key flaw in the military's security was that Manning may not have even had to look all that hard for the data, as it was apparently available for many people to see. The Defense Department says it has bolstered its computer security since the leaks.
Companies have many options technologically to protect themselves.
Alfred Huger, vice president of engineering for security firm Immunet Corp. in Palo Alto, said companies could simply configure their e-mail servers to restrict who certain people can send documents to.
Other measures include prohibiting certain people from copying and pasting from documents, blocking downloads to thumb drives and CD-ROMs, and deploying technologies that check if executives' e-mail messages are being checked too often - a sign that an automated program is copying the contents.
But the more companies control information, the more difficult it is for employees to access documents they are authorized to view. That lowers productivity and increases costs in the form of the additional help from technicians.
"You run the risk of creating an environment that's so rigid that people can't do their jobs," Huger said. "You have to find that balance. Unfortunately, there's no panacea against it."
©2010 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
-
From lemons to lemonade: Reaction uses carbon dioxide to make carbon-based semiconductor,
28 comments
-
Thioridazine kills cancer stem cells in human while avoiding toxic side-effects of conventional cancer treatments,
3 comments
-
SpaceX private rocket blasts off for space station (Update),
41 comments
-
Climate scientists say they have solved riddle of rising sea,
30 comments
-
Scotland passes turbine test to harness tidal power,
40 comments
-
length of wire in a coil of known dimensions?
13 hours ago
-
India Engineering Powerhouse
21 hours ago
-
electromagnet core dereference between hard and soft iron
22 hours ago
-
Measuring water pressure in an open tank
May 24, 2012
-
Question from a non-engineer: Pulley Systems
May 24, 2012
-
Formula to calculate psi required to deliver gpm through nozzel
May 23, 2012
- More from Physics Forums - General Engineering
More news stories
Yahoo kills 'Livestand' just 6 months after debut
(AP) -- Yahoo is killing a tablet magazine called Livestand just six months its debut on the iPad.
9 hours ago |
not rated yet |
1
Computers excel at identifying smiles of frustration (w/ Video)
(Phys.org) -- Researchers at the Massachusetts Institute of Technology (MIT) in the US have trained computers to recognize smiles, and they have turned out to be more adept at recognizing smiles of frustration ...
Yahoo! ditches digital newsstand for iPads
Yahoo! shuttered its fledgling digital newsstand for iPads on Friday in what it said was the start of a product purge intended to make the floundering Internet pioneer more nimble.
10 hours ago |
not rated yet |
0
Facebook IPO debacle raises investor dander
The spate of complaints and investigations over the Facebook stock offering suggests big institutions had an edge over small investors, raising questions about the process.
11 hours ago |
not rated yet |
0
Apple CEO Cook gives up $75M in stock dividends
(AP) -- Apple CEO Tim Cook is giving up $75 million in dividends on restricted stock that the company is awarding to all of its employees.
14 hours ago |
1.8 / 5 (4) |
2
Of mice and mental models: Neuroscientific implications of risk-optimized behavior in the mouse
(Medical Xpress) -- Regardless of an organism’s biological complexity, every encephalized animal continuously makes under-informed behavioral choices that can have serious consequences. Despite its ubiquity, ...
Dragon arrives at space station in historic 1st (Update 2)
The privately bankrolled Dragon capsule made a historic arrival at the International Space Station on Friday, triumphantly captured by astronauts wielding a giant robot arm.
Landmark calculation clears the way to answering how matter is formed
(Phys.org) -- An international collaboration of scientists, including Thomas Blum, associate professor of physics, is reporting in landmark detail the decay process of a subatomic particle called a kaon ...
High-speed method to aid search for solar energy storage catalysts
Eons ago, nature solved the problem of converting solar energy to fuels by inventing the process of photosynthesis.
It's in the genes: Research pinpoints how plants know when to flower
Scientists believe they've pinpointed the last crucial piece of the 80-year-old puzzle of how plants "know" when to flower.
Researchers solve structure of human protein critical for silencing genes
In a study published in the journal Cell on May 24, Cold Spring Harbor Laboratory (CSHL) scientists describe the three-dimensional atomic structure of a human protein bound to a piece of RNA that "guides" the pr ...
Dec 02, 2010
Rank: not rated yet
What's even worse is when politicians decide what appropriate infosec measures might be and then mandate compliance with them. Recently doing some work for a state agency here in the U.S. I encountered this problem. They were attempting to meet new compliance standards from the state capital that included 'eliminating the usb drive threat.' After the systems were installed productivity plummeted and no one could do even basic tasks without relearning how to do them. And they still got raped by a worm and joined a huge botnet because patch management bothered the employees too much and wasn't mandated by the state.
This is the same state/agency that had me stop the show during business hours because the ibm i-series needed anti-virus software installed 'urgently.'
Dec 02, 2010
Rank: not rated yet
Dec 03, 2010
Rank: not rated yet
No. The United States of America does.
Our politicians have recognised that China is effective at 1) controlling their large population 2) maintaining power through 1 party.
We're the Chinese Police State now, people. Right here in the U.S.A. The Republicans and Democrats have MERGED. There is only ONE parth and its modeled after the Communist Party of China.