California Identity Theft Starter Kit for $6Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    Fix Network Security Flaws on Your Biz Network - Trial | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Security Incidents : California Identity Theft Starter Kit for $6
Posted by Max on 2007/3/24 7:36:24 (1016 reads)
Security Incidents

A security breach in California set hundreds of thousands of Social Security Numbers online for 6 bucks a piece.
From what we know, these records have been available for sale on the World Wide Web since 2004, making this potentially the longest running government breach in California's history.

That old saw, "We're from the government, and we're here to help you," could be updated for the Internet age. How about this one: "We're from the government, and we're here to give your identity away -- no questions asked."


That was pretty close to how it was in California over the last three years, and who knows right now on how many local, state, county, and federal Web sites nationwide?

State Assemblyman Dave Jones, D-Sacramento, has accused the state of "selling an identity theft starter kit on the Internet" after he discovered the gaping security hole on the California secretary of state's Web site.

The site had been posting uniform commercial code filings, which are voluntarily provided by banks, with "enough information to open a credit card in someone else's name." He said the state was selling Social Security numbers for $6 each, an Internet connection, and a credit card. As a test, Jones bought 20 public records, 14 of which he said contained enough information to enable him to open credit cards in someone else's name, had he wanted to.

The filings are only supposed to be available to financial institutions and contain information about collateral used for loans, mostly from businesses, but some personal loans as well. The state has to accept the filings, but good lord, it doesn't have to make the information so easy to access online.

The state secretary of state, Debra Bowen, has said the 2 million files, which were available for at least three years, will be taken down until her office can figure out a way to hide all but the last four numbers of each person's Social Security number. She also says there have been no complaints of identity theft filed. But so what? As an ABC News report on the story notes, most people never find out where their data was stolen from.

But none of this really addresses why such personal data was widely accessible in the first place, and what will be done afterward to keep out prying eyes. In fact, along with the state of Indiana, officials might consider now a good time to review what information is being posted online. What information should be public? What changes should be made to documents so that they can go from being electronically filed to being posted safely on the Internet?

What do citizens think about state DMVs and census offices selling their personal data? Shouldn't the government just agree now that no Social Security number should ever be posted on any public document? Any insurer or bank or credit analyst who needs your SS number probably already has it (and probably because you gave provided it yourself).
Why should anyone else need it legitimately? Someone else's need to spam millions with credit or insurance offers isn't your problem.




Other articles
2008/10/9 14:10:42 - Google Trends Used to Promote Fake Anti-Virus Software
2008/10/9 13:50:47 - Spam, Child Porn, Illegal Pharmaceuticals, and Stolen Data Make The Web Axis of Evil
2008/10/8 12:22:22 - New Anti-Phishing Service by BluePrint On National Cyber Security Awareness Month
2008/10/7 16:17:07 - Adware Released As Fake Antivirus Increases
2008/10/2 15:30:28 - Agnitum's Outpost Security Suite Pro Gains Another VB100% (on Windows Server 2008)
2008/10/2 15:21:49 - New FREE Security Tools From Verizon
2008/9/30 17:45:27 - SkyRecon Adds Anti-Virus Protection (AVP) to Its StormShield Security Suite
2008/9/30 17:32:11 - IdentitySecure, The New Identity Theft Protection Program from Affinion
2008/9/30 17:13:08 - Web Application Security Mythbusters by Cenzic Inc.
2008/9/30 17:03:58 - Disk Doctors Announces Support For The Hurricane IKE and Gustav victims

The comments are owned by the poster. We aren't responsible for their content.