Showing posts with label DATA BREACH. Show all posts
Showing posts with label DATA BREACH. Show all posts

Tuesday, March 19, 2013

The 15 worst data security breaches of the 21st Century - CSO Online - Security and Risk

February 15, 2012CSO

Data security breaches happen daily in too many places at once to keep count. But what constitutes a huge breach versus a small one? For some perspective, we take a look at 15 of the biggest incidents in recent memory. Helping us out are security practitioners from a variety of industries, including more than a dozen members of LinkedIn's Information Security Community, who provided nominations for the list.

See our photo gallery of the 15 worst data breaches in recent history

  • 1. Heartland Payment Systems
  • Date: March 2008
  • Impact: 134 million credit cards exposed through SQL injection to install spyware on Heartland's data systems.

A federal grand jury indicted Albert Gonzalez and two unnamed Russian accomplices in 2009. Gonzalez, a Cuban-American, was alleged to have masterminded the international operation that stole the credit and debit cards. In March 2010 he was sentenced to 20 years in federal prison. The vulnerability to SQL injection was well understood and security analysts had warned retailers about it for several years. Yet, the continuing vulnerability of many Web-facing applications made SQL injection the most common form of attack against Web sites at the time.

There are conflicting accounts about how this happened. One supposes that a group of hackers took advantage of a weak data encryption system and stole credit card data during a wireless transfer between two Marshall's stores in Miami, Fla. The other has them breaking into the TJX network through in-store kiosks that allowed people to apply for jobs electronically. According to KNOS Project cofounder and chief architect Kevin McAleavey, this was possible because TJX's network wasn't protected by any firewalls. Albert Gonzalez, hacking legend and ringleader of the Heartland breach, was convicted and sentenced to 40 years in prison, while 11 others were arrested.

  • 3. Epsilon
  • Date: March 2011
  • Impact: Exposed names and e-mails of millions of customers stored in more than 108 retail stores plus several huge financial firms like CitiGroup Inc. and the non-profit educational organization, College Board.

The source of the breach is still undetermined, but tech experts say it could lead to numerous phishing scams and countless identity theft claims. There are different views on how damaging the Epsilon breach was. Bruce Schneier, chief security technology officer at BT and a prolific author, wrote in a blog post at the time that, "Yes, millions of names and e-mail addresses (and) other customer information might have been stolen. Yes, this personal information could be used to create more personalized and better-targeted phishing attacks. So what? These sorts of breaches happen all the time, and even more personal information is stolen." Still, Kevin McAleavey of the KNOS Project says the breach is being estimated as a $4 billion dollar loss. Since Epsilon has a client list of more than 2,200 global brands and handles more than 40 billion e-mails annually, he says it could be, "the biggest, if not the most expensive, security breach of all-time."

  • 4. RSA Security
  • Date: March 2011
  • Impact: Possibly 40 million employee records stolen.

The impact of the cyber attack that stole information on the company's SecurID authentication tokens is still being debated. The company said two separate hacker groups worked in collaboration with a foreign government to launch a series of spear phishing attacks against RSA employees, posing as people the employees trusted, to penetrate the company's network. EMC reported last July that it had spent at least $66 million on remediation. But according to RSA executives, no customers' networks were breached. John Linkous, vice president, chief security and compliance officer of eIQnetworks, Inc. doesn't buy it. "RSA didn't help the matter by initially being vague about both the attack vector, and (more importantly) the data that was stolen," he says. "It was only a matter of time before subsequent attacks on Lockheed-Martin, L3, and others occurred, all of which are believed to be partially enabled by the RSA breach." Beyond that, Linkous says, is the psychological damage. "The breach of RSA was utterly massive not only from a potential tactical damage perspective, but also in terms of the abject fear that it drove into every CIO who lost the warm-and-fuzzy feeling that the integrity of his or her enterprise authentication model was intact. Among the lessons, he says, are that even good security companies like RSA are not immune to being hacked. Finally, "human beings are, indeed, the weakest link in the chain," Linkous says.

  • 5. Stuxnet
  • Date: Sometime in 2010, but origins date to 2007
  • Impact: Meant to attack Iran's nuclear power program, but will also serve as a template for real-world intrusion and service disruption of power grids, water supplies or public transportation systems.

The immediate effects of Stuxnet were minimal -- at least in this country -- but eIQnetworks' John Linkous ranks it among the top large-scale breaches because, "it was the first that bridged the virtual and real worlds. When a piece of code can have a tangible effect on a nation, city or person, then we've truly arrived in a strange, new world," he says. Linkous says Stuxnet is proof that nation-states, "are definitely actors -- both attackers and victims -- in the cyberwarfare game." He adds that the more that electro-mechanical industrial and energy systems migrate to larger networks -- particularly the Internet -- "the more we're going to see these real-world intrusions."

  • 6. Department of Veterans Affairs
  • Date: May 2006
  • Impact: An unencrypted national database with names, Social Security numbers, dates of births, and some disability ratings for 26.5 million veterans, active-duty military personnel and spouses was stolen.

The breach pointed once again to the human element being the weakest link in the security chain. The database was on a laptop and external hard drive that were both stolen in a burglary from a VA analyst's Maryland home. The analyst reported the May 3, 2006 theft to the police immediately, but Veterans Affairs Secretary R. James Nicholson was not told of it until May 16. Nicholson informed the FBI the next day, but the VA issued no public statement until May 22. An unknown person returned the stolen items June 29, 2006. The VA estimated it would cost $100 million to $500 million to prevent and cover possible losses from the theft.

  • 7. Sony's PlayStation Network
  • Date: April 20, 2011
  • Impact: 77 million PlayStation Network accounts hacked; Sony is said to have lost millions while the site was down for a month.

This is viewed as the worst gaming community data breach of all-time. Of more than 77 million accounts affected, 12 million had unencrypted credit card numbers. According to Sony it still has not found the source of the hack. Whoever they are gained access to full names, passwords, e-mails, home addresses, purchase history, credit card numbers, and PSN/Qriocity logins and passwords. "It's enough to make every good security person wonder, 'If this is what it's like at Sony, what's it like at every other multi-national company that's sitting on millions of user data records?'" says eIQnetworks' John Linkous. He says it should remind those in IT security to identify and apply security controls consistently across their organizations. For customers, "Be careful whom you give your data to. It may not be worth the price to get access to online games or other virtual assets."

  • 8. ESTsoft
  • Date: July-August 2011
  • Impact: The personal information of 35 million South Koreans was exposed after hackers breached the security of a popular software provider.

It is called South Korea's biggest theft of information in history, affecting a majority of the population. South Korean news outlets reported that attackers with Chinese IP addresses uploaded malware to a server used to update ESTsoft's ALZip compression application. Attackers were able to steal the names, user IDs, hashed passwords, birthdates, genders, telephone numbers, and street and email addresses contained in a database connected to the same network. ESTsoft CEO Kim Jang-joon issued an apology and promised to, "strengthen the security system of our programs."

  • 9. Gawker Media
  • Date: December 2010
  • Impact: Compromised e-mail addresses and passwords of about 1.3 million commenters on popular blogs like Lifehacker, Gizmodo, and Jezebel, plus the theft of the source code for Gawker's custom-built content management system.

Online forums and blogs are among the most popular targets of hackers. A group calling itself Gnosis claimed responsibility for the attack, saying it had been launched because of Gawker's "outright arrogance" toward the hacker community. "They're rarely secured to the same level as large, commercial websites," says the KNOS Project's Kevin McAleavey, who adds that the main problem was that Gawker stored passwords in a format that was very easy for hackers to understand. "Some users used the same passwords for email and Twitter, and it was only a matter of hours before hackers had hijacked their accounts and begun using them to send spam," says McAleavey.

In an act of industrial espionage, the Chinese government launched a massive and unprecedented attack on Google, Yahoo, and dozens of other Silicon Valley companies. The Chinese hackers exploited a weakness in an old version of Internet Explorer to gain access to Google's internal network. It was first announced that China was trying to gather information on Chinese human rights activists. It's not known exactly what data was stolen from the American companies, but Google admitted that some of its intellectual property had been stolen and that it would soon cease operations in China. For users, the urgent message is that those who haven't recently updated their web browser should do so immediately.

  • 11. VeriSign
  • Date: Throughout 2010
  • Impact: Undisclosed information stolen

Security experts are unanimous in saying that the most troubling thing about the VeriSign breach, or breaches, in which hackers gained access to privileged systems and information, is the way the company handled it -- poorly. VeriSign never announced the attacks. The incidents did not become public until 2011, through a new SEC-mandated filing. "How many times were they breached?" asks eIQnetworks' John Linkous. "What attack vectors were used? The short answer is: we don't know. And the response to that is simply: we should." "Nearly everyone will be hacked eventually," says Jon Callas, CTO for Entrust, in a post earlier this month on Help Net Security. "The measure of a company is how they respond." VeriSign said no critical systems such as the DNS servers or the certificate servers were compromised, but did say that, "access was gained to information on a small portion of our computers and servers." It has yet to report what the information stolen was and what impact it could have on the company or its customers. Linkous says the company's "failure to disclose until legally required to do so is going to haunt VeriSign for some time."

  • 12. CardSystems Solutions
  • Date: June 2005
  • Impact: 40 million credit card accounts exposed. CSS, one of the top payment processors for Visa, MasterCard, American Express is ultimately forced into acquisition.

Hackers broke into CardSystems' database using an SQL Trojan attack, which inserted code into the database via the browser page every four days, placing data into a zip file and sending it back through an FTP. Since the company never encrypted users' personal information, hackers gained access to names, accounts numbers, and verification codes to more than 40 million card holders. Visa spokeswoman Rosetta Jones told Wired News at the time that CSS received an audit certification in June 2004 that it was compliant with data storage standards, but an assessment after the breach showed it was not compliant. "Had they been following the rules and requirements, they would not have been compromised," Jones said. The company was acquired by Pay-by-touch at the end of 2005.

  • 13. AOL
  • Date: August 6, 2006
  • Impact: Data on more than 20 million web inquiries, from more than 650,000 users, including shopping and banking data were posted publicly on a web site.

In January 2007, Business 2.0 Magazine ranked the release of the search data in among the "101 Dumbest Moments in Business." Michael Arrington, a lawyer and founder of the blog site TechCrunch, posted a comment on his blog saying, "The utter stupidity of this is staggering." AOL Research, headed by Dr. Abdur Chowdhury, released a compressed text file on one of its websites containing 20 million search keywords for more than 650,000 users over a three-month period. While it was intended for research purposes, it was mistakenly posted publicly. AOL pulled the file from public access by the next day, but not before it had been mirrored and distributed on the Internet. AOL itself did not identify users, but personally identifiable information was present in many of the queries, and as AOL attributed the queries to particular user accounts, identified numerically, an individual could be identified and matched to their account and search history by such information. The breach led to the resignation of AOL's CTO, Maureen Govern, on Aug. 21, 2006.

  • 14. Monster.com
  • Date: August 2007
  • Impact: Confidential information of 1.3 million job seekers stolen and used in a phishing scam.

Hackers broke into the U.S. online recruitment site's password-protected resume library using credentials that Monster Worldwide Inc. said were stolen from its clients. Reuters reported that the attack was launched using two servers at a Web-hosting company in Ukraine and a group of personal computers that the hackers controlled after infecting them with a malicious software program. The company said the information stolen was limited to names, addresses, phone numbers and e-mail addresses, and no other details, including bank account numbers, were uploaded. But one problem was that Monster learned of the breach on Aug. 17, but didn't go public with it for five days. Another, reported by Symantec, was that the hackers sent out scam e-mails seeking personal financial data, including bank account numbers. They also asked users to click on links that could infect their PCs with malicious software. Once that information was stolen, hackers e-mailed the victims claiming to have infected their computers with a virus and threatening to delete files unless the victims met payment demands.

  • 15. Fidelity National Information Services
  • Date: July 2007
  • Impact: An employee of FIS subsidiary Certegy Check Services stole 3.2 million customer records including credit card, banking and personal information.

Network World reported that the theft was discovered in May 2007, and that a database administrator named William Sullivan, said to own a company called S&S Computer Services in Largo, Fla., had been fired. But the theft was not disclosed until July. Sullivan allegedly sold the data for an undisclosed amount to a data broker, who in turn sold it to various marketing firms. A class action lawsuit was filed against FIS and one of its subsidiaries, charging the companies with negligence in connection with the data breach. Sullivan agreed to plead guilty to federal fraud charges and was sentenced to four years and nine months in prison and ordered to pay a $3.2 million fine. On July 7, 2008, a class-action settlement entitled each person whose financial information was stolen to up to $20,000 for unreimbursed identity theft losses.

Read more about malware/cybercrime in CSOonline's Malware/Cybercrime section.

Other stories by Taylor Armerding

Posted from DailyDDoSe

Sunday, February 24, 2013

Forensic Samples of a Wordpress Hack

P372

I run a website that is used by around 10 people for private reasons. This server hosts no ads, sells nothing, and gets almost no pageviews. But it still is regularly probed by spammers and hackers to see if it is secure. How do I know this? I watch my server logs. This week, 9 out of the top 10 “page not found” (404) errors were for hackers attempting to find exploits. In fact, I wouldn’t be surprised if 90% of the site’s traffic is by those same hackers attempting to hack my little site. I saw access attempts to the following files: webdav/test phpMyAdmin/scripts/setup.php mysqladmin/scripts/setup.php websql/scripts/setup.php pma/scripts/setup.php etc...... All of these attempts were logged in my error log because none of those pages exist on my server, but if they did exist, they could have become a way for hackers to turn my website into a tool for their purposes. In this case, all but the first one were attempts to hack phpMyAdmin with the setup file, probably to do some form of SQL-injection on the site. The webdav/test was probably trying to do the same thing with a possible webdav server on my website. And as you can see from those error logs, the hackers don’t stop with the default name of the file they want to exploit. Don’t assume that just because you’ve renamed your phpMyAdmin directory to “pma” that the hackers won’t find it. Security through obscurity isn’t security, and your file names and directories can be figured out, especially by the determined hacker who uses a script to simply hit dozens or hundreds of possibilities. But Don’t Stop with Just the Error Logs It can be tedious, but it’s a very good idea to scan your access logs periodically to make sure that nothing strange is happening. If you start getting hundreds or thousands of hits to a page (especially a PHP or CGI page) that previously was almost invisible, you should check out that page to see what it is. If it has any type of form on it, you may have opened yourself up to attack without realizing it. I also like to keep tabs on the dates that files were edited. I don’t have all the file dates on my many websites memorized, but I know that I did or didn’t edit a file last week. If you notice a strange date on a file on your server (and you’re the only one who edits files there), check out that file. Make sure that it says what you want it to say, and not what some script kiddie changed it to say. Keep Your Scripts Up-to-Date If you use tools like phpMyAdmin or WordPress on your website, you should make sure that they are up-to-date. Scripts and tools from reputable companies have a vested interest in keeping their tools secure. And you are only going to be secure if you use the most up-to-date version. A hacker still might find an exploit, but you’re safer than with an older version. Be Vigilant Don’t think that you’re too secure to be hacked or too small or anything else. There are a lot of hackers out there with automated scripts that simply troll the internet looking for sites to exploit. If your site has a vulnerability, it might be next. The only way you can be secure is to be vigilant. watch your server logs for suspicious activity deal with exploits as soon as you find them keep your scripts and tools up-to-date put scripts and tools (like phpMyAdmin) behind server passwords make those passwords as secure as you can (12-20 or more characters long, with letters, numbers, and symbols, and no words via webdesign.about.com

Posted from DailyDDoSe

Monday, October 1, 2012

Mama I'm Coming Home || B'bye Karen CON

"Not Afraid"

[Chorus:]
I'm not afraid (I'm not afraid)
To take a stand (to take a stand)
Everybody (everybody)
Come take my hand (come take my hand)
We'll walk this road together, through the storm
Whatever weather, cold or warm
Just letting you know that, you're not alone
Holla if you feel like you've been down the same road (same road)

[Intro (during Chorus):]
Yeah, it's been a ride
I guess I had to, go to that place, to get to this one
Now some of you, might still be in that place
If you're trying to get out, just follow me
I'll get you there

You can try and read my lyrics off of this paper before I lay 'em
But you won't take the sting out these words before I say 'em
Cause ain't no way I'ma let you stop me from causing mayhem
When I say I'ma do something I do it,
I don't give a damn what you think,
I'm doing this for me, so fuck the world
Feed it beans, it's gassed up, if it thinks it's stopping me
I'ma be what I set out to be, without a doubt undoubtedly
And all those who look down on me I'm tearing down your balcony
No if ands or buts, don't try to ask him why or how can he
From "Infinite" down to the last "Relapse" album
He's still shitting, whether he's on salary paid hourly
Until he bows out or he shits his bowels out of him
Whichever comes first, for better or worse
He's married to the game, like a fuck you for Christmas
His gift is a curse, forget the Earth, he's got the urge
To pull his dick from the dirt, and fuck the whole universe

[Chorus]

Okay quit playing with the scissors and shit, and cut the crap
I shouldn't have to rhyme these words in the rhythm for you to know it's a rap
You said you was king, you lied through your teeth, for that
Fuck your feelings, instead of getting crowned you're getting capped
And to the fans, I'll never let you down again, I'm back
I promise to never go back on that promise, in fact
Let's be honest, that last "Relapse" CD was ehhh
Perhaps I ran them accents into the ground
Relax, I ain't going back to that now
All I'm trying to say is get back, click-clack, blow
Cause I ain't playing around
It's a game called circle and I don't know how, I'm way too up to back down
But I think I'm still trying to figure this crap out
Thought I had it mapped out but I guess I didn't, this fucking black cloud
Still follows, me around but it's time to exorcise these demons
These motherfuckers are doing jumping jacks now!

[Chorus]

And I just can't keep living this way
So starting today, I'm breaking out of this cage
I'm standing up, I'ma face my demons
I'm manning up, I'ma hold my ground
I've had enough, now I'm so fed up
Time to put my life back together right now! (now)

It was my decision to get clean, I did it for me
Admittedly, I probably did it subliminally
For you, so I could come back a brand new me you helped see me through
And don't even realize what you did, believe me you
I been through the ringer, but they could do little to the middle finger
I think I got a tear in my eye, I feel like the king of
My world, haters can make like bees with no stingers
And drop dead, no more beef flingers
No more drama from now on, I promise
To focus solely on handling my responsibilities as a father
So I solemnly swear to always treat this roof, like my daughters
And raise it, you couldn't lift a single shingle on it!
Cause the way I feel, I'm strong enough to go to the club
Or the corner pub, and lift the whole liquor counter up
Cause I'm raising the bar
I'd shoot for the moon but I'm too busy gazing at stars
I feel amazing and I'm

[Chorus]

Thanks to camila, Christopher Chiocca, Romi Ezzo, Kim, Katie Mueller for correcting these lyrics.

Posted from DailyDDoSe

Cleaning out my Closet || Dedicated to Karen #CON

"Cleanin Out My Closet" by Eminem

Where's my snare?
I have no snare in my headphones - there you go
Yeah... yo, yo

Have you ever been hated or discriminated against?
I have; I've been protested and demonstrated against
Picket signs for my wicked rhymes, look at the times
Sick as the mind of the motherfucking kid that's behind
All this commotion emotions run deep as ocean's exploding
Tempers flaring from parents just blow 'em off and keep going
Not taking nothing from no one give 'em hell long as I'm breathing
Keep kicking ass in the morning and taking names in the evening
Leave 'em with a taste as sour as vinegar in they mouth
See they can trigger me, but they'll never figure me out
Look at me now; I bet ya probably sick of me now ain't you momma?
I'm a make you look so ridiculous now

I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet (one more time)
I said I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet

Ha! I got some skeletons in my closet
And I don't know if no one knows it
So before they thrown me inside my coffin and close it
I'm a expose it; I'll take you back to '73
Before I ever had a multi-platinum selling CD
I was a baby, maybe I was just a couple of months
My faggot father must have had his panties up in a bunch
Cause he split, I wonder if he even kissed me goodbye
No I don't on second thought I just fucking wished he would die
I look at Hailie, and I couldn't picture leaving her side
Even if I hated Kim, I grit my teeth and I'd try
To make it work with her at least for Hailie's sake
I maybe made some mistakes
But I'm only human, but I'm man enough to face them today
What I did was stupid, no doubt it was dumb
But the smartest shit I did was take the bullets outta that gun
Cause I'da killed him; shit I would've shot Kim and him both
It's my life, I'd like to welcome y'all to "The Eminem Show"

I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet (one more time)
I said I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet

Now I would never diss my own momma just to get recognition
Take a second to listen for who you think this record is dissing
But put yourself in my position; just try to envision
Witnessing your momma popping prescription pills in the kitchen
Bitching that someone's always going through her purse and shit's missing
Going through public housing systems, victim of Munchhausen's Syndrome
My whole life I was made to believe I was sick when I wasn't
'Til I grew up, now I blew up, it makes you sick to ya stomach
Doesn't it? Wasn't it the reason you made that CD for me Ma?
So you could try to justify the way you treated me Ma?
But guess what? You're getting older now and it's cold when your lonely
And Nathan's growing up so quick he's gonna know that your phony
And Hailie's getting so big now; you should see her, she's beautiful
But you'll never see her - she won't even be at your funeral!
See what hurts me the most is you won't admit you was wrong
Bitch do your song - keep telling yourself that you was a mom!
But how dare you try to take what you didn't help me to get
You selfish bitch; I hope you fucking burn in hell for this shit
Remember when Ronnie died and you said you wished it was me?
Well guess what, I am dead - dead to you as can be!

I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet (one more time)
I said I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet

I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet (one more time)
I said I'm sorry momma!
I never meant to hurt you!
I never meant to make you cry; but tonight
I'm cleaning out my closet

Posted from DailyDDoSe

Wake Me Up When September Ends - BIG SMILES!!!

"Wake Me Up When September Ends" by Green Day

Summer has come and passed
The innocent can never last
wake me up when September ends

like my father's come to pass
seven years has gone so fast
wake me up when September ends

here comes the rain again
falling from the stars
drenched in my pain again
becoming who we are

as my memory rests
but never forgets what I lost
wake me up when September ends

summer has come and passed
the innocent can never last
wake me up when September ends

ring out the bells again
like we did when spring began
wake me up when September ends

here comes the rain again
falling from the stars
drenched in my pain again
becoming who we are

as my memory rests
but never forgets what I lost
wake me up when September ends

Summer has come and passed
The innocent can never last
wake me up when September ends

like my father's come to pass
twenty years has gone so fast
wake me up when September ends
wake me up when September ends
wake me up when September ends

Posted from DailyDDoSe

Thursday, August 23, 2012

Oversight of Government Privacy, Security Rules for Health Data Questioned | Center for Democracy & Technology

Oversight and accountability for following federal privacy and security rules is critical if the public is going to trust that the next generation of electronic health care providers, insurers, and billing services can protect the privacy of their medical information.  A recent report by the Government Accountability Office questions whether sufficient work is being done to build that public trust.

The GAO report says the Department of Health and Human Services has failed to issue new rules for protecting personal health information and lacks a long-term plan for ensuring that those new rules are being followed.  The HHS Office for Civil Rights (OCR), which is responsible for overseeing these efforts, acknowledged these concerns but noted that rules are winding their way through government channels and that they have "taken the necessary first steps towards establishing a sustainable" oversight program.   

The report's two main concerns are: (1) the urgent need for guidance on de-identification methods, and (2) lack of a long-term plan for auditing covered entities and business associates for compliance with federal privacy and security rules (specifically, HIPAA and HITECH).

De-Identification Guidance

De-identification is a tool that enables health data to be used for a broad range of purposes while minimizing the risks to individual privacy.  Under HIPAA, there are two methods that can be used to de-identify health data. The first is the safe harbor method, which merely requires the removal of 18 specific categories of identifiers, such as name, address, dates of birth or health care services, and other unique identifiers.  The second is the expert determination method that certifies that the data, in the hands of the intended recipient, raises a very small risk of re-identification. The safe harbor method is static and presumes that the removal of the 18 categories of identifiers translates into very low risk of re-identification in all circumstances.

In HITECH, Congress directed HHS to complete a study of the HIPAA de-identification standard by February 2010.  Though covered entities rely more on the safe harbor method because it is easier to understand and more accessible, OCR aimed to produce guidance that would "clarify guidelines for conducting the expert determination method of de-identification to reduce entities reliance on the Safe Harbor method," according to the report.  Two years later and notwithstanding its good intentions, OCR has not released this guidance.  

CDT has met with industry and consumer stakeholders about how to improve federal policy regarding de-identified health data since 2009. CDT also recently published an article in JAMIA proposing a number of policies to strengthen HIPAA de-identification standards and ensure accountability for unauthorized re-identification.  

The OCR should issue the required guidance on de-identification without further delay and continue seeking public feedback on how to build trust in uses of de-identified data.  Foot dragging on this issue risks impeding progress on the ability to monitor the public's health in ways that go far beyond mere notification and routine reporting of symptoms, diagnoses, etc.  With these new capabilities in place, public health officials can move beyond traditional detection and response to outbreaks, enabling earlier disease detection, allowing public health officials to take a more active role monitoring health issues from cancer screening to adult immunizations to HIV.

Ensuring Compliance

Routine audits help ensure that covered entities and business associates comply with HIPAA and HITECH regulations.  Audits also provide OCR with important information about how entities covered by HIPAA and HITECH are implementing critically important privacy and security protections, and potentially surface issues needing further regulatory guidance and helping OCR better determine when penalties for noncompliance are warranted.  

HITECH directed HHS to audit entities covered by HIPAA for compliance with HIPAA and new HITECH requirements; OCR officials began those audits earlier this year. The report states that OCR has no plan to sustain these audits beyond 2012; the report also notes that HHS does not have a defined plan for including HIPAA business associates in its audits. HHS responded that OCR plans to review the pilot audit program at the end of this year and move forward with an audit program after that step is complete.

If the public is to trust that the privacy of their health information is well protected, it must know where that information is going and how it's being used. The report highlights the importance of audits as an effective mechanism for accountability. CDT is encouraged by the progress OCR has made to date in its pilot audit program, and we are pleased to see HHS commit to learning from the pilots to developing and implementing a sustained plan for auditing compliance with federal privacy and security regulations. 

For updates, follow us on Twitter at @CenDemTech.

https://www.cdt.org/blogs/suchismita-pahi/1607oversight-government-privacy-se...

Posted from DailyDDoSe

Monday, July 2, 2012

National Bloggers Club Unmasked: Link from Breitbart Unmasked - MAY CONTAIN SBU INFORMATION

A number of right wing bloggers who claim they are the National Bloggers Club have recently been attacking Brett Kimberlin in mass accusing him of every dirty deed in the book. So, because of that, we here at BU decided to check into this National Bloggers Club to see who was behind it, and what their mission is, and also who funded who, or where the money came from to run this loose knit operation of right wing bloggers who use the internet to raise money for causes they create, and or basically wreck havoc with anyone considered an enemy of their little group.

 

First up is Ali A. Akbar.

Ali and his childhood friends are directors of the National Bloggers Club. However they don’t all live at this address above. I find it strange they all do not live or even work at this address, yet file corporate forms with the State and IRS that claim that they all live or reside or work at this address. The issue here is that most of these people running this company are just young kids in their early 20′s who have scant to zero business experience and seem to not know the landscape of the business world or how to operate in it. But that is just my opinion.

Then there is the affable John Dennis Pedrie as one of the Directors of The National Bloggers Club. His claim to fame was that he worked until 2010 at the Onyx Ice Arena as an Ice Rink Maintenance Man. So he went from Ice Maintenance worker to Vice President of Technology and Development at Vice & Victory, which is another Ali Akbar creation, to one of the Directors of The National Bloggers Club. Wow, sounds like he has some real corporate experience behind him.

 

Then we go to Devon Wills, who’s claim to fame was that he was a personal shopper at J Crew before he became the CEO at Wills Group LLC, and then later a Director of The National Bloggers Club.

Right now he is going to the all christian stud Liberty University which was founded by the Reverend Jerry Falwell, and which claims in its mission statement that it trains Champions for Christ.

There are a number of others who are in the process of signing up for a National Bloggers Club board seat; such as Michele Malkin who has also been a front runner in leading the charge against Brett Kimberlin in the media. Of course we will post more data on this organization as the crow flies here at BU. The one interesting connection was who was the money man that seeded the National Bloggers Club? Well, that just so happens to be Foster Friess. Foster is another right wing corporate billionaire who has given money to the Koch Brothers, and also claims he also helps out American Crossroads which is run by Karl Rove.

 

Friess has been an active patron of religious and conservative causes. He has been instrumental in keeping the political campaign of the 2012 presidential hopeful Rick Santorum alive by financing a super PAC, the Red, White and Blue Fund, which runs television advertisements on behalf of Santorum, who was unable to run a television campaign with his own funds. According to campaign filings with the Federal Election Commission, Friess’s contributions to the Red, White and Blue Fund amount to more than 40% of its total assets – or, $331,000 as of 31 December 2011.[5][6]He had donated $250,000 to Santorum’s re-election campaign in 2006, and at least that amount to the Republican Governors’ Association.[7] In the wake of the New Hampshire Republican primary, 2012, and before the South Carolina primary, Friess told Politico that he was “putting together a challenge grant to encourage other wealthy donors to give to the Red, White and Blue Fund, … he said [the fund] received a $1 million check” the day after the New Hampshire vote.[8] The Million-dollar donation was conveyed in four checks between November, 2011 and January, 2012.[6]

In addition to Santorum’s faith, pro-life stance, and hawkish foreign policy leanings, the possibility of defeating incumbent President Barack Obama was a major component of Friess’s decision to back Santorum’s campaign.[9] Friess is reportedly considering major contributions to American Crossroads in hopes to influence key 2012 senate races.[10]

Friess has also donated $100,000 to Wisconsin Governor Scott Walker to help defeat the Democrats’ recall effort in 2011. In addition, he has reportedly donated more than $3 million to the conservative commentator Tucker Carlson‘s The Daily Caller website.[7] At one of the semi-annual, private seminars held by the Koch brothers in June 2011, Friess was recognized for his donation exceeding $1 million to the Kochs’ political activities.[11]

The other interesting connection was this Yahoo News article on the private invite only meeting that started the National Bloggers Club.

James O’Keefe attending the opening bash of the National Bloggers Club and claiming Fuck the media? Well James I think you have that wrong, it’s not fuck the media, it’s the media fucks you. But that is just how I look at it.

So what do we have here? We have Foster Friess starting the National Bloggers Club with James O’Keefe attending, with connections to the Koch Brothers and Karl Rove. We also have media personalities such as Michele Malkin who is also connected to Robert Stacy McCain. We also have Ali Akbar who is connected to the rest of the right wing bloggers, and who have all been attacking in mass one guy by the name of Brett Kimberlin, who I might add has been on a many years long crusade to expose the corruption behind Karl Rove and the Koch Brothers and James O’Keefe. I would call these connections very interesting indeed. What I also find even more interesting is that they have recently been raising money for a few bloggers who they claim are under the threat of some future lawsuit, yet, they have a billionaire funding them. So my question is why do they need to raise funds for some future legal challenges when they have such heavy guns seeding them with huge resources of money? Why not just call up Foster Friess and ask him for the money to support Robert Stacy McCain and Mandy Nagy and the millionaire John Patrick Frey? Those are very interesting questions which we will probe into in the days ahead.

Stay Tuned..

 

 

 

god know they did it to me...

posted my address, my parents address and phone numbers. medical and financial records that were illegally obtained, ALTERED, and placed in a public folder on at least 6 servers.

that's bullshit!

Posted from DailyDDoSe

Saturday, June 30, 2012

Manage My Account - TwitterGate paper trail - "Catch me if you can?" Exhibit B - Flickr

Failed
@earthspeakorg, 12/29/10 4:16 PM Retweet
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@srbijadanas, 12/29/10 3:00 PM me thinks ...
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@HeyJude408, 12/29/10 2:50 PM we saw too
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@rockingjude, 12/28/10 6:44 PM
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
Conversation hiding the evidence ?
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago
Failed
@JasonBWhitman, 12/28/10 5:47 PM
Reason: Unknown Error. Please try to delete and re-add this autopost destination if this issue persists.
5 months ago

Posted from DailyDDoSe

Police Tried to Erase Evidence Lulz does it for them

I didn't do it! But I have a pretty good idea who is. SO on the eve of the day you Pwned my site and stole my identity, I hope you die! Thanks again, Jaded, Anthony, Niels, Lance, Niels, and of course, Joe Black. I hole you all know how much you fucked up my life. I hole you all get exact what you deserve. Some awful virus that makes your balks turn green and fall off! Thanks for the Lulz. And the T-shirts. I hope you die!

Photo

אל

Posted from DailyDDoSe

Wednesday, May 23, 2012

Dear Metro: Next time, bring a warrant. @ELyssaD™ [Invoking privilege]

Police Investigate @ELyssaD™ -- warrantless wiretap of Twitter account

Metro Nashville Police Investigating @ELyssaD on Twitter

I was trying to de-escalate the situation with the local Police Department since I realize how much danger this city is in given recent laws to persecute Muslims and people who were not born in the United States 287(g)






















Seeking justice in the digital age... who do we hate more? Wikileaks for exposing the truth? Or the people who go to great lengths to cover it up? I want justice. I can handle the truth. I want to be freE.













 However, after watching the violence erupting around me, knowing that I am the primary target [thanks to COINTELPRO agent provocateurs] and being questioned by the police about my twitter stream, I really don't give a fuck.
RELEVANT HISTORY  Uploaded by on Nov 17, 2011
Metro Nashville Police Department continue to cover up crimes by failing to follow established code of conduct in lower income neighborhoods.
Some power hungry police officer demands to search my iPhone after he notices I am video taping the MNPD who took three hours to respond to multiple neighbors call 911 after witnessing multiple violent assaults against two women and one man on Monday evening.
I called 911 after two people approached my window threatening my life for being a "cracker Jew bitch" and threw a brick through my window where I was working on two projects about Cointelpro as a driving force behind the Occupy movement that is being funded by The American Nazi Party and the Lucis Trust.
I was interviewing someone who had been involved with Nazi medical experiments and how it effected his four children who suffer with a variety of neurological and psychological problems that are typical of victims of Mengele's subjects.
I had just received notification from the copyright office (USTPO) in Virginia that my submission was approved and was thrilled to learn that my publications would be protected under trademark and copyright laws since I received several take down notices that my publications were being removed due to the sensitive nature (and my vast knowledge) about the true purpose of organized, controlled opposition as a driving force to escalate domestic unrest designed to incite violence justifying a Police State ushering in the New World Order.

Refuses to take witness statements; refuses to reveal name or badge number and another violent criminal continues to terrorize and assault three individuals within minutes of being released.

No evidence? Check the fucking surveillance cams just above the the scene of the crime.


These people have no idea how they are being manipulated by disinformation agents, toxic living conditions and a system that is far more corrupt than even I imagined.
 The "monitor" Vernon Sims, claims to be TBI yet refused to show identification when he was "on patrol" aka STALKING, THREATENING, INTIMIDATIING, AND IMPERSONATING AN OFFICER!
My stalker, Vernon, clearly has some special deal with Metro because despite all the violence that broke out, he finds the time to threaten, harass and stalk me ignoring the fact that several residents threatened me after spooks came in and told people to stay away from me or they will "get in trouble"



WHAT THE FUCK?

I have no history of violence and have never even been in a fight.

I weigh 124 pounds and all these people are afraid of me?
Do I "look dangerous" because I am quite certain it won't be long before someone makes another attempt on my life. 
Much like Treyvon Martin, I was told police were on there way after a man threw a brick through my window and then chased me down the street. 
I was on the phone with 911 the whole time screaming "HELP, HELP, HELP" yet the police claim they did not want to waste radio space to update status of my call to a Code 3. 
Are you fucking kidding me?
911 told me to return to the scene of the crime where I was assaulted a second time, and the cops didn't even bother to arrest him or take witness statements. In fact, the officer would not even step out of the car to speak with me because he did not like the way I was dressed.
Because no action was taken against the man that assaulted me and vowed to kill and my father (who just happens to be a former Fed) I constantly carry my iPhone because the cops claim they did not have enough evidence to arrest this man.
They never bothered to check the surveillance camera and did not take statements from additional witnesses. 
They did, however take issue with the fact that I placed a video on YouTube and were even more upset that I contacted a former colleague in the Mayor's Office who then requested an investigation. 
 The Commander from the Chief's Office sent two Lieutenants to my home; one was aggressive and disrespectful and was more interested in what book I was reading and my website than the facts of the case.
I was told that they would follow up with the other witnesses who would corroborate my story, and that a Special Operations Unit and Gang Unit would be contacted regarding the racial comments that became commonplace every time I left the apartment.


One man hung up Nazi flags, another started praying in Muslim and all hell broke loose in the neighborhood. 









I became a target because I was white in a Black neighborhood, and apparently that alone was enough to incite hatred among the other tenants and 


I feared for life each time I left my apartment, so the police told me NOT to leave my home.

THAT IS OUTRAGEOUS!
The other tenants became more and more abusive and violent since they now had a new sense of entitlement because they knew the police would not take action.
It is worth noting that even after I left, the violence continued to escalate and one women was stabbed and several other injured in fights that broke out in the hallway. The cops still did not arrest the people who continue to live in the neighborhood, and some of them have shown up here at my new apartment to harass me and spread rumors.
The neighbors here have suddenly became abusive and overly concerned with my religion and it seems the writing is on the wall. They think my healthy paranoia is "suspicious" and I think their behavior is outrageous.




They constantly stand outside my window and scream at me and the "monitor" called the police on me after he threatened me and told me I was not allowed to go near a "white car."
There were SIX white cars, two of which have no tags, so how am I to know which white car is the one who stopped me at the mailbox and told me that two men were knocking at my door and were here to beat me up?

I may very well be the next Treyvon Martin and if so, so be it. I am old enough and experienced enough to know that these people do not see the bigger picture~ that they are being used to as examples to bring down the police state and usher in the New World Order. 

I leave these notes because I do not know if I will get shot at today, tomorrow or next week, and I think it is important to let people know that I have spent my entire life studying gang violence, and have fought hard against police corruption and discrimination so regardless of what happens to me, I do not want my work (or experience) to be in vain.
A cop came running after me, demanded to see my cell phone and after running my license to check for warrants (which seemed extreme) and finding none, he wrote up an incident report for "suspicious behavior" for video taping a crime scene, then releases the suspect claiming there is not enough evidence???

http://twitvid.com/TAZ47
I am one of the good guys, and if you can't see that by now... then take some time to look through some of my publications which are systematically being removed from the internet by groups like Anonymous, Lulz, and AntiSec.


This breaks my heart, but I am fighting a losing battle. 

I am starting to question my commitment and given the communities response~ I am not sure if they are worth the sacrifice.



THEY WANT ME TO DISAPPEAR WITHOUT A TRACE.














 Just being honest.
 I Spent the last year of my life trying ti to de-hack my life. And, here I am, frozen in time in a loopback cycle 127.0.0.1 with no fucking clean feed!
Uploaded by on Dec 15, 2011
Metro Nashville Police and Housing Authority accept NAACP membership card in lieu of State Identification and arrest one of two people with the same last name. Ronald Roan and Timothy Roan both reside on the same property hiding their true Identity in effort to evade police charges for Felony Assault and Grand Theft Auto.
Like Arizona, TN law requires State, Federal or Military Issued ID to help identify Mexican residents under 287(g)
As the victim, I resent being called to testify against another victim for procedural error resulting in multiple arrests and warrants that do not include charges for attempted murder and death threats.
Apparently the NAACP has changed since I last attended their monthly meetings.
Nazi propaganda may be illegal in France, but is "decoration" in my hometown.
"Cracker Jew Bitch" is onamove...
 You can't play the race card to justify death threats for being a Jew.
Elyssa Durant, Ed.M.

[Former Assistant to the Governors Office for Minority Affairs & Recipient of Journalism Award on freelance series covering TN Lawsuit filed by the NAACP against Metro Nashville Public Schools for violating zoning laws (desegregation)]
 Crack-her Jew bitch doesn't raise eyebrows in Nashville, TN?
Send in the Clowns? Fuck that. Send in the Feds and the ADL!

The Cops are Still Clowns.
My Worst Nightmare © 2009.

Category:

Tags:

If I do happen to disappear, please know it was not by choice. Please remember me. I did this for you...
That's all for today. This is the Daily Dose for today.
Just me,
e
@ELyssaD™













   ELyssa Durant © 2012 || All Rights Reserved || DailyDDoSe™ @ELyssaD™

Wednesday, April 25, 2012

Faux Security: BlackBerg Security and Shades of Project Viglio by @Krypti3ia @infosecisland

Faux Security: @JosephKBlack, @ElyssaD, BlackBerg Security, and Shades of Project Viglio

BlackBerg & ElyssaD:

A while back, I ran across ElyssaD and her whacky site which was scraping my content from Infosec Island. I later read Jaded Security’s post filling in the gaps that I had given up on in my searches on her digital rats warren of sites and chalked it up to idiots at play.

However, since then, she has failed to remove my content from her sites, her ersatz ‘employer’ Joe Black, has called me out as a supporter of Anonymous and LulzSec, and still, my content is on her frantically moronic sites.

image

So, the gloves come off.

I began to look around at her sites again to see what was being taken and scraped when I  began to not only see more of her erratic behaviour, but a pattern of baiting for attention not only on her part, but that of Joe Black.

So much so in fact, that I have to really wonder if Elyssa is not just an identity scrape of a real person as opposed to actually being online herself and posting all this claptrap.

After all, what was it that LIGATT and Aaron Barr were trying to do but create many sock puppet identities to control and use to sway opinion in PSYOPS fashion. So the questions for me now are these:

  • Is Joe Black just an insanely inept buffoon with some alleged connections to the defence base?
  • Is ElyssaD just a cutout for Joe to weave his insanity online for... Well whatever purposes he has in mind?
  • Is all of this just the personal lulz machine for whoever Joe may really be and is having a laugh?
  • Are they both just insane and useless wankers?

After picking through their digital trails, I still cannot say for sure what their goal is or just how real they both are. I am told that Joe is a real person and that some in my circle know of him.

Personally, I had never heard of him until he started tweeting craziness on Twitter and came up with his craptastic site. Over time though, he just progressively got crazier and crazier with comments and challenges to the likes of LulzSec, who then allegedly hacked him and showed just how poor his site security was.

Of course now there are allegations that Lulz did nothing that that he (Joe) had hacked/defaced his page himself to garner attention (as seen below):

image

After his site went down this last weekend, we all thought perhaps he had been hit by another Anon attack of some sort, but then he popped up again yesterday, claiming fantastically, that he is the new Nietzsche of information security!

Which is ironic, because Nietzsche went insane at the end of his life due to Tertiary Syphilis, which I think Joe has a head start on now. Then again, if you really know who Nietzsche was, and did, perhaps this is another nod to irony and a play on the ideas of putting crazy out to the world to see what happens.

Frankly though, from his tweets and writings, I think it is the former and not the latter. Joe is just an attention seeking fool and Elyssa, well, if Elyssa is truly the one posting on the Internet, hon, you need some mental health dollars spent on you STAT!

So, on to the LIGATT worthy baloney shall we? I will present it in short montages, somewhat like the montage scene in Team America. Mostly because I am listening to the soundtrack now and YOU are, well, you are a farce just like the film.

Joe.. Joe Black… CIA…:

image

Seriously Joe... If YOU are a NOC, then I am the King of Prussia. What the Hell are you saying? I mean, this right here just screams that you are either out of your head or just a clown.

If you are at all serious about this alleged business of yours and its ties to the military and government, then they, if they are indeed connected with you at all, should quickly pull out.

Then there’s this little ditty:

image

Holy WTF? Really? C’mon man! Who is going to buy this stuff other than Elyssa? (to the tune of Freedom Ain’t Free.. It costs a BUCK OH FIVE!)

And then there is this other missive:

image

Huh? Wha? Elyssa, take your MEDS! With employees like this, Joe is gonna have to have one HELL of a insurance plan! Elyssa, I am sure the Feds took you up on your offer and will give you FULL immunity *snort* (to the tune of North Korean Melody.. So Ronery)

AND then there is my favorite!

image

SO! That’s how it works within the intelligence and hacking communities! I had NO IDEA! Really, Elyssa, if indeed you are real and this tweet wasn’t just some elaborate insane joke.

YOU are not a hacker and it does not happen by “association” you morons. No more so than any of your degree’s (if real) make you an INTEL analyst or a Black OP specialist. (to the tune of Team America March.. just because it came on.. Can you smell the gravitas?)

Speaking of gravitas, if indeed Joe and Co. are real, that is what they are trying, and failing to convey to the would be clients that the site alleges to want. Therein, you have LIGATT-ed quite well Joey.

Board of Advisors:

Now, in another more interesting vein, Joe has added a board of directors to his site. Of course I had to look once Praetorian had pointed it out asking; “Who the hell are these people?”

So, I put on the waders and got the gloves on to go looking. What I found kinda makes me wonder what the hell is going on yet again. So, lets have a look at these people shall we?

Fernando Patzan:

image

Alright, so Fernando was pretty easy to find. I mean how many Fernando’s are there in infosec who have government ties? Yeah, so Fernando, my first question is this; “Do you really represent in any way Joe Black and his particular brand of crazy?”

Because if you don’t then this guy is dragging your reputation down with his easy use of your name as an advisor. Honestly, if half the stuff that Joe has done and said was on your advice, well, I should think that your current employers might want to re-think your job status.

Of course I have yet to speak with anyone who really knows you... So you too could be another cutout. However, I have found ancillary data through Google that you do really exist and you did work at GD. So, tell me my man, are you huffing the same glue from the same paper bag under that local underpass with Joe?

Oh, and if you don’t know him... Well dude, you better get on the horn with your lawyer…

Patricia Ellington:

image

Oh Patty, Patty, Patty, your creds are kinda... Well ‘meh’ aren’t they? You also have connections to me like Fernando now that the LinkedIn is working right. So, why have I never heard of you?

Well, I suppose that that is a bad question. So I will go back to the credibility issue and your connection to Joey here. Do you know Joe? Is Joe taking YOUR advice too in posting his whack ass diatribes about being in the CIA and allegedly outing Team Poison?

You too might want to call your lawyer…

John Berry:

John... Well... John is a blank slate to me. Of course his name is pretty common and bland, but I could locate no one with that name within the infosec community nor by using the super special word “CYBER” that all of the morons are using as a catch phrase today.

So he is a ghost... OOOOH maybe he is a super spy like Jason Bourne! I bet Joe knows you through his adventures in Thailand chasing heroin smugglers!

Not.

Justin Johnson:

image

Justin.. Well Justin was a bit of a puzzle. The only one who came up with network cred was this one. Are you an advisor to Joey? Once again, I say you should get a lawyer if you don’t already have one because this guy may be trading on your good name and credibility (VERY Ligattworthy!).

Justin, if you do in fact know Joey and you are working with him let me know... I have more questions like; HUH? Why?

Kevin G. Coleman:

image

Lastly, and most interestingly, we have Kevin. Oh Kevin, I liminally have heard of you before and I cannot believe that you would have anything to do with Joey, but, then again, maybe you like the glue huff now and again? Do you really advise Joe to do the crazy stuff he has been up to? Do you really approve of, or even know about this Elyssa character?

Dude, you are the most credible of the group and now you have this stink upon you!

If you know him and are working with him, best sever those ties now sir… EVEN if you are SEMI retired! This Joey character is only going to lead you down the path to smelling like a dog after a skunk attack while standing in the crap factory while it exploded due to a SCADA hack.

Please.. Someone tell these people their names are on this fool’s site!

Ugh…

Ok, so in the end, as “I’m So Ronery” plays on the headphones I end this psychic barf of a post. Joe, Elyssa... Time for your meds! And as always “Remember to fade away in a montage”...

K.

Cross-posted from Krypt3ia

SO FUCKING ILLEGAL!

to be continued...

Ssa_leslie_marc

 

Posted via email from DailyDDoSe