BreachExchange mailing list archives

Re: time to name names (was Re: MORE BNY (Mellon Corp) Tapeslost)


From: "DAIL, WILLARD A" <ADAIL () sunocoinc com>
Date: Fri, 6 Jun 2008 19:30:56 -0400


Aside from the privacy issue, couriered tapes  are also a concern due to the "Crash Restart" method of system attack. 

Basically, a hacker colludes with your courier to drop off your tapes in the morning.  The courier then picks up the 
altered tapes that afternoon.  A couple of really nasty things happened to your tapes that day. 



________________________________

From: dataloss-bounces () attrition org on behalf of security curmudgeon
Sent: Fri 6/6/2008 3:24 PM
To: dataloss () attrition org
Subject: [Dataloss] time to name names (was Re: MORE BNY (Mellon Corp) Tapeslost)





: http://www.pittsburghlive.com/x/pittsburghtrib/business/s_570347.html
:
: "The tape was being carried by a commercial carrier ... and was lost in
: transit," said Ron Sommer, at the bank's Downtown offices. "It was
: ground transportation delivery, and it didn't reach its destination."

The amount of data loss incidents due to backup media being lost in
transit is disgusting. While everyone looks to the oragnizations like BNY
for these incidents, they need to disclose which commercial carriers are
losing the data like this.

I want to see the data and determine if a specific carrier or service is
primarily at fault here if that is where the blame lies.
_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss

Tenable Network Security offers data leakage and compliance monitoring
solutions for large and small networks. Scan your network and monitor your
traffic to find the data needing protection before it leaks out!
http://www.tenablesecurity.com/products/compliance.shtml



This message and any files transmitted with it is intended solely for the designated recipient and may contain 
privileged, proprietary or otherwise private information. Unauthorized use, copying or distribution of this e-mail, in 
whole or in part, is strictly prohibited. If you have received it in error, please notify the sender immediately and 
delete the original and any attachments.
_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss

Tenable Network Security offers data leakage and compliance monitoring
solutions for large and small networks. Scan your network and monitor your
traffic to find the data needing protection before it leaks out!
http://www.tenablesecurity.com/products/compliance.shtml


Current thread: