Showing posts with label Security Breaches. Show all posts
Showing posts with label Security Breaches. Show all posts

Thursday, September 19, 2019

Data Security and Facebook

An online report published by CNET on September 4, 2019 identified that at least 419 million records  of phone numbers tied with Facebook accounts appeared in databases online. The report was based on the revelation by TechCrunch

The exposure identified 133 million users from US alone and another 18 million and 50 million records from UK and Vietnam respectively.  The flaw as highlighted is Lack of Password protection on the server by Facebook. Records were identified with Demographic details also.

Now the big question, does this impact my privacy and security of my data online (read facebook data too)? Answer to this is pretty simple - if your demographic data and phone number is available example - sex, country and phone number (along with Facebook's Unique User ID) it is pretty much a compromise of your personal information leaving you vulnerable to certain cyber attacks. The data can also be misused to forge your identity with the modern mechanics of hacking.

This certainly is a big mess here by the team at Facebook to have left a critical server without password, the first baseline defense mechanism to check against unauthorized access. Though the very next day or so Facebook reverted with a statement that the data has been scrapped and is no more exposed to the open web. But from the time that server would have been put in place to the time the data was reported to be exposed and the steps by Facebook to scrap the data, do you think that the data would not have been compromised?  In all probabilities it would have been.

Though this is not the first time that such exposure or compromise has been reported. We keep on hearing such cases almost every other day.  The corporates accumulate our data for their business benefits and then miss out on the aspects of security to be deployed.  As per Facebook, this server probably served the purpose of searching a person on Facebook using the Phone Number of that person. My question here is why should the Phone Number search for Facebook user be activated in the first place? That itself is a breach of privacy and compromise of data that has been provided to a service provider as a security feature for secondary authentication.  

Facebook may state that they have this feature of find by phone to be controlled by the user and if user doesn't want to have this feature on, they can restrict it. Based on this aspect, I had a few discussions with a few facebook users and majority of them (close to 65%) didn't have an idea that they can control this feature of Search by Phone.  

So, the question still looms - "Should Corporates be allowed to Introduce Features that may pose Security and Privacy threats to the users?"

Thursday, October 7, 2010

CardSystems Solutions Hack 2005 - Legal Suit Targetting Auditor

The topic sounds to be shocking, but if you read the article "In Legal First, Data-Breach Suit Targets Auditor" you would be surprised to know the proceedings that led to the Legal Suit. 

It will be really interesting to note the developments from here on as the Auditor may contest that the report was good for "As on Date" of Report and they are not liable for any subsequent breach as they are not keeping an eye on how the organization dealt with the information post the Audit Completion.


But does the role of Auditor end with the submission of report, specifically when the identified organization fails a previous Audit for storing sensitive data in an unprotected manner or in a manner that is not as per the specifications?  

Should not the Auditor go back at the records of previous Audit and identify the reasons that might have led to the failure in complying to the requirement?


Isn't the Auditor supposed to maintain the integrity of Audit Process and NOT overlook serious issue that were being reported for a period of 5 years preceding the Audit?


There are lot of questions that create a eye of suspicion on the role of Auditors.  Many a times the Auditors tend to turn a blind eye towards certain issues that are present due to organizational work culture.  They don't tend to highlight the issues for the reason that they feel they are not responsible for that.


We had earlier seen a law emanating out from the hi-profile case of Enron and Arthur Anderson, where both the companies disappeared from the Market.  As if that was not enough a lesson to be learnt by the Auditors that we often get to know of similar cases, though not of that profile.


Would that mean we will soon see another law stemming out, something that would Regulate and Govern the Audit Scenario?  Should not the Auditors tighten their belts to ensure that the Audits and the Audit Reports are fair and square, resulting in what they are actually supposed to result in, rather than twisting the results one way or other?

It is quite interesting that the Noble Profession of Auditors is fast becoming Commercialized, and at this pace, i would not be surprised to see a License Regime enforced for the Auditors on same line as the Lawyers and Formation of a Regulatory Body Like Auditor's Council to Govern Auditors'.