Home > Who Knows What Evil Lurks in the Cyber Heart?

Data Security

Who Knows What Evil Lurks in the Cyber Heart?

The Hackers Know. (Apologies to The Shadow.)

7/13/2007

Universities don't become headlines because a $2,000 computer is hacked or lost.  They become headlines when sensitive information such as Social Security numbers, credit card numbers, and medical information is stolen.  In terms of liability, the asset is not equipment; it is information.

There they were, big as life--a list of Social Security numbers buried in a long forgotten folder on my computer.  Back in the early 1990s I'd take a break from bits and bytes to teach an occasional physics course and would do what every university professor did back than---store grades by name and Social Security number.  As a computer jock, I stored them on my computer and made regular archival backups.  (It was also common practice to post a list of grades indexed by Social Security number on your office door.  Names were carefully omitted, however, to prevent student embarrassment.)  

Identity theft wasn't an unknown concept back then.  (The underground book "How to Create a New Identity" by "Anonymous" had been around for more than a decade.)  It just wasn't a big deal.  But times have changed.  Now it is a very big deal.  And one of the keys to identity theft is the Social Security number, or SSN.  Protecting personal information is now a legal requirement; losing it has been a source of embarrassment for many colleges, universities, and businesses.

But how can you protect sensitive data, if you don't know where it is?  Recently a large research university addressed this question by hiring one of the Big-4 accounting firms to do a risk assessment on departmentally managed computers. The computers were all scanned and color-coded red/yellow/green based on the amount of risk they presented the organization. To see whether the university could internally do the same job the Big-4 firm had been hired to do, a small group of computing center staff developed a program based on a computational biology algorithm used to search huge genome databases for specific patterns. To their horror they found that 50 percent of the computers that had been rated "green" (lowest risk) by the Big-4 firm actually had large amounts of sensitive information (including massive spreadsheets and/or fully relational databases with SSNs, contract info, etc.) in extremely insecure configurations. The homegrown scanning program also found "green" machines that had been compromised and contained Trojan horse "backdoors" or were infected with viruses.  The initial reaction was to pursue a course of litigation against the Big-4 firm, but, after assessing the situation, they found that 77 percent of the compromised computers were running up to date anti-virus software and that the firm had followed industry best practices!

Now the story gets even more interesting. Existing tools that scan for sensitive data generally require system administrator access and as are awkward to use for scanning faculty, departmental, and staff computers outside central IT's control.  The university, however, refined its home-grown tool so it could be run on distributed PCs without user intervention--and found copious lists of SSNs, credit card numbers, and other sensitive data that users were unaware were on their computers.  Since those early days, similar experiences at other organizations show an estimated 70 percent of the sensitive information data resides outside the Data Center!


Recommended Reading
  • College of Southern Nevada Implementing Angel To Run Online Courses

    The College of Southern Nevada (CSN), a community college in Las Vegas with 41,000 students, has adopted the Angel Learning Management Suite (LMS) to support its online course offerings. In Spring 2008 CSN began evaluating alternatives to WebCT, which it currently runs, and made the decision to adopt Angel in the fall. In January 2009, CSN's 865 sections of online enrollment will be delivered using the Angel LMS.

  • Toshiba Brings DisplayLink to Docking Station

    Toshiba has introduced a new USB docking station that incorporates DisplayLink--a technology that allows computers to connect to projectors and other types of displays through USB 2.0.

  • Mitsubishi Ships SXGA+ Projector with DICOM Simulation

    Mitsubishi has begun shipping a new LCD-based SXGA+ projector aimed at higher education, specifically medical schools. The new MH2850U, according to Mitsubishi, is "specially engineered for projecting DICOM simulation images for use in medical education and training."

  • First Look: Komodo IDE 5.0

    Last month, ActiveState released Komodo IDE 5.0, the company's latest integrated development environment (IDE). Komodo supports multiple programming and markup languages, including HTML, JavaScript, PHP, Perl, Java, Python, C++ and more. It does not support some .NET languages at present, such as ASP/ASP.NET, C# and VB.NET.

  • IBM Offers Cloud Computing Help

    IBM last week announced consulting services specifically designed to help organizations assess their options in using cloud computing technology. "Cloud computing" is a much argued term, but it typically refers to solutions delivered over the Internet, rather than via customer premises-installed software.

  • Hollins U Chooses Omnilert for Emergency Notification Ahead of VA Deadline

    Hollins University, among other higher ed institutions in Virginia, has implemented Omnilert's e2Campus emergency notification system (ENS) just ahead of a state-mandated deadline requiring them at every public institution of higher education by Jan. 1. Hollins itself isn't a public campus, but wished to implement an ENS before the end of the year, the school said in a company statement.