* View
* Track
Mon, 21/07/2008 - 13:55 — Vavai
Your rating:
0
Bagi rekan-rekan yang ingin selalu mengetahui berita terbaru tentang dunia seputar Linux di Indonesia, silakan meluncur ke Planet Linux Indonesia
Planet Linux Indonesia berisi artikel dan posting dari berbagai KPLI dan komunitas berbasis distro. Artikel yang masuk meliputi berita terbaru, tips-trick Linux, pengumuman dll.
Jika anda memiliki komunitas Linux namun belum tercantum dalam list, silakan hubungi maintainer Planet Linux Indonesia melalui alamat email vavai at vavai.com.
Semoga Planet Linux Indonesia ini akan semakin melengkapi Linux.or.id dalam membantu para pengguna Linux di seluruh Indonesia.
Jika ada rekan-rekan yang ingin membantu mempercantik tampilan Planet Linux Indonesia, silakan email kepada alamat email diatas.
Showing posts with label computer. Show all posts
Showing posts with label computer. Show all posts
Can Data Breaches Be Expected From Bankrupt Mortgage Lenders?
10:44 AM | computer, internet, technology : elekronika, tips with 0 komentar »by: Tim Maliyil
The stock market is in a tumult. Actually, it has been for about a year, ever since the subprime fiasco (anyone take a look at Moody's performance over the past year?) Now that that particular issue has been beaten to death, other mortgage related issues are cropping up. Most of the stuff covered in the media is financial in nature, but some of those mortgage related issues do concern information security.
It's no secret that there are plenty of companies in the US that discard sensitive documents by dumping them unceremoniously: leave it by the curb, drive it to a dumpster, heave it over the walls of abandoned property, and other assorted mind boggling insecure practices. In fact, MSNBC has an article on this issue, and names numerous bankrupt mortgage companies whose borrowers' records were found in dumpsters and recycling centers. The information on those documents include credit card numbers and SSNs, as well as addresses, names, and other information needed to secure a mortgage.
Since the companies have filed for bankruptcy and are no more, the potential victims involved have no legal recourse, and are left to fend for themselves. In a way, it makes sense that companies that have filed for bankruptcy are behaving this way. (Not that I'm saying this is proper procedure.) For starters, if a company does wrong, one goes after the company; however, the company has filed for bankruptcy, it is no more, so there's no one to "go after." In light of the company status, this means that the actual person remaining behind to dispose of things, be they desks or credit applications, can opt to do whatever he feels like. He could shred the applications. He could dump them nearby. He could walk away and let the building's owner take care of them. What does he care? It's not as if he's gonna get fired.
Also, proper disposal requires either time, money, or both. A bankrupt company doesn't have money. It may have time, assuming people are going to stick around, but chances are their shredder has been seized by creditors. People are not going to stick around to shred things by hand, literally.
Aren't there any laws regulating this? Apparently, such issues are covered by FACTA, the Fair and Accurate Credit Transactions Act, and although its guidelines require that "businesses to dispose of sensitive financial documents in a way that protects against 'unauthorized access to or use of the information'" [msnbc.com], it stops short of requiring the physical destruction of data. I'm not a lawyer, but perhaps there's enough leeway in the language for one to go around dropping sensitive documents in dumpsters?
Like I mentioned before, inappropriate disposal of sensitive documents has been going on forever; I'm pretty sure this has been a problem since the very first mortgage was issued. My personal belief is that most companies would act responsibly and try to properly dispose of such information. But, this may prove to be a point of concern as well because of widespread misconceptions of what it means to protect data against unauthorized access.
What happens if a company that files for bankruptcy decides to sell their company computers to pay off creditors? Most people would delete the information found in the computer, and that's that-end of story. Except, it's not. When files are deleted, the actual data still resides in the hard disks; it's just that the computer's operating system doesn't have a way to find the information anymore. Indeed, this is how retail data restoration applications such as Norton are able to recover accidentally deleted files.
Some may be aware of this and decide to format the entire computer before sending it off to the new owners. The problem with this approach is the same as deleting files: data recovery is a cinch with the right software. Some of them retail for $30 or less-as in free. So, the sensitive data that's supposed to be deleted can be recovered, if not easily, at least cheaply-perhaps by people with criminal interests.
Am I being paranoid? I don't think so. I've been tracking fraud for years now, and I can't help but conclude that the criminal underworld has plenty of people looking to be niche operators, not to mention that there are infinitesimal ways of defrauding people (look up "salad oil" and "American Express," for an example). An identification theft ring looking to collect sensitive information from bankrupt mortgage dealers wouldn't surprise me, especially in an environment where such companies are dropping left and right.
The economics behind it make sense as well. A used computer will retail anywhere from $100 to $500. The information in it, if not wiped correctly, will average many times more even if you factor in the purchase of data recovery software. Criminals have different ways of capitalizing on personal data, ranging from selling the information outright to engaging in something with better returns.
Is there a better way to protect oneself? Whole disk encryption is a way to ensure that such problems do not occur: One can just reformat the encrypted drive itself to install a new OS; the original data remains encrypted, so there's no way to extract the data. Plus, the added benefit is that the data is protected in the event that a computer gets lost or stolen. However, commonsense dictates that encryption is something ongoing concerns sign up for, not businesses about to go bankrupt. My guess is that sooner or later we'll find instances of data breaches originating from equipment being traced back to bankrupt mortgage dealers.
The stock market is in a tumult. Actually, it has been for about a year, ever since the subprime fiasco (anyone take a look at Moody's performance over the past year?) Now that that particular issue has been beaten to death, other mortgagerelated issues are cropping up. Most of the stuff covered in the media is financial in nature, but some of those mortgagerelated issues do concern information security.
It's no secret that there are plenty of companies in the US that discard sensitive documents by dumping them unceremoniously: leave it by the curb, drive it to a dumpster, heave it over the walls of abandoned property, and other assorted mindboggling insecure practices. In fact, MSNBC has an article on this issue, and names numerous bankrupt mortgage companies whose borrowers' records were found in dumpsters and recycling centers. The information on those documents include credit card numbers and SSNs, as well as addresses, names, and other information needed to secure a mortgage.
Since the companies have filed for bankruptcy and are no more, the potential victims involved have no legal recourse, and are left to fend for themselves. In a way, it makes sense that companies that have filed for bankruptcy are behaving this way. (Not that I'm saying this is proper procedure.) For starters, if a company does wrong, one goes after the company; however, the company has filed for bankruptcy, it is no more, so there's no one to "go after." In light of the company status, this means that the actual person remaining behind to dispose of things, be they desks or credit applications, can opt to do whatever he feels like. He could shred the applications. He could dump them nearby. He could walk away and let the building's owner take care of them. What does he care? It's not as if he's gonna get fired.
Also, proper disposal requires either time, money, or both. A bankrupt company doesn't have money. It may have time, assuming people are going to stick around, but chances are their shredder has been seized by creditors. People are not going to stick around to shred things by hand, literally.
Aren't there any laws regulating this? Apparently, such issues are covered by FACTA, the Fair and Accurate Credit Transactions Act, and although its guidelines require that "businesses to dispose of sensitive financial documents in a way that protects against 'unauthorized access to or use of the information'" [msnbc.com], it stops short of requiring the physical destruction of data. I'm not a lawyer, but perhaps there's enough leeway in the language for one to go around dropping sensitive documents in dumpsters?
Like I mentioned before, inappropriate disposal of sensitive documents has been going on forever; I'm pretty sure this has been a problem since the very first mortgage was issued. My personal belief is that most companies would act responsibly and try to properly dispose of such information. But, this may prove to be a point of concern as well because of widespread misconceptions of what it means to protect data against unauthorized access.
What happens if a company that files for bankruptcy decides to sell their company computers to pay off creditors? Most people would delete the information found in the computer, and that's that-end of story. Except, it's not. When files are deleted, the actual data still resides in the hard disks; it's just that the computer's operating system doesn't have a way to find the information anymore. Indeed, this is how retail data restoration applications such as Norton are able to recover accidentally deleted files.
Some may be aware of this and decide to format the entire computer before sending it off to the new owners. The problem with this approach is the same as deleting files: data recovery is a cinch with the right software. Some of them retail for $30 or less-as in free. So, the sensitive data that's supposed to be deleted can be recovered, if not easily, at least cheaply-perhaps by people with criminal interests.
Am I being paranoid? I don't think so. I've been tracking fraud for years now, and I can't help but conclude that the criminal underworld has plenty of people looking to be niche operators, not to mention that there are infinitesimal ways of defrauding people (look up "salad oil" and "American Express," for an example). An identification theft ring looking to collect sensitive information from bankrupt mortgage dealers wouldn't surprise me, especially in an environment where such companies are dropping left and right.
The economics behind it make sense as well. A used computer will retail anywhere from $100 to $500. The information in it, if not wiped correctly, will average many times more even if you factor in the purchase of data recovery software. Criminals have different ways of capitalizing on personal data, ranging from selling the information outright to engaging in something with better returns.
Is there a better way to protect oneself? Whole disk encryption is a way to ensure that such problems do not occur: One can just reformat the encrypted drive itself to install a new OS; the original data remains encrypted, so there's no way to extract the data. Plus, the added benefit is that the data is protected in the event that a computer gets lost or stolen. However, commonsense dictates that encryption is something ongoing concerns sign up for, not businesses about to go bankrupt. My guess is that sooner or later we'll find instances of data breaches originating from equipment being traced back to bankrupt mortgage dealers.
Windows And Software Installation Automation In An Enterprise
10:26 AM | computer, news info, tech: software, windows with 0 komentar »by: Ivan Abramovskiy
| |
IT department automation in an enterprise.
Recommended: for the heads of enterprises, IT departments, system administrators
This article will tell you:
How to quickly install Windows on all computers of an enterprise.
How to quickly upgrade software on all enterprise computers without losing any data.
How to automate all kinds of routine processes in an enterprise.
How to increase the productivity of system administrators in an enterprise.
Any company faces the problem of timely software update on all computers as well as the problem of the quick recovery and configuration of an employee's working environment. To solve this problem we offer our product: Almeza MultiSet.
A company before using MultiSet:
The software is installed/configured manually with the employee working with this computer being idle at this time.
Databases are updated, computers are configured, software is set up - all that is also done manually and requires the administrator to be present at every computer.
Every remote office requires system administrators to be employed
The IT staff has to be arranged to be on duty 24 hours a day.
Expenses on business trips made by technical specialists are necessary.
You get the following benefits after you deploy MultiSet in your company:
You will need only 1 administrator at any point on the network to update any amount of software on any number of computers. Note that the time needed to update software on all computers will be approximately equal to the time needed for one computer!
It is possible to quickly change the configuration on multiple or separate computers throughout the entire network. Note that the administrator has to be physically present at one computer only.
It is possible to quickly and safely reinstall WindowsXP without losing any current data!
It is possible to create a master disk for the standard automatic installation of a set of software on any number of computers.
It is possible to automatically install Windows together with drivers, service packs, any types of tools and applications.
It is possible to quickly update databases, configuration files on client computers.
Using MultiSet dramatically increases the effectiveness of using the office hours of the IT administration department.
Why particularly MultiSet?
Reliability. MultiSet reliably runs on any type of Windows operating system.
Quickness. Due to its innovational algorithm, MultiSet performs its functions fast, exactly and, which is most important, reliably.
Trustworthiness.. Among our clients there are banks, government organizations, customer support services, large corporations, which proves the actual usefulness of MultiSet in practice.
Flexible pricing policy. We offer a very flexible pricing policy that allows you to cover a large number of computers at minimum cost.
Low system requirements. MultiSet has minimum system requirement for its work. MultiSet supports the following operating systems: Windows Vista/XP/2003/2000 (32-bit) and Windows Vista/XP/2003 (64-bit).
SOLUTIONS FOR SMALL BUSINESS
Small organizations often do not have enough funds to employ an administrator and it often happens that regular employees have to update and configure software.
MultiSet will allow you to reduce expenses on calling administrators for every client computer, save a lot of time for everyone and therefore provide more time for employees to spend on their direct duties.
Download Free 30-day Trial:
http://www.almeza.com/download/multiset.exe
Web:
http://www.almeza.com
Subscribe to:
Posts (Atom)












