California Identity Theft Starter Kit for $6Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!  Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Our Partners
Downloads
Security Incidents : California Identity Theft Starter Kit for $6
Posted by Max on 2007/3/24 7:36:24 (1538 reads)
Security Incidents

A security breach in California set hundreds of thousands of Social Security Numbers online for 6 bucks a piece.
From what we know, these records have been available for sale on the World Wide Web since 2004, making this potentially the longest running government breach in California's history.

That old saw, "We're from the government, and we're here to help you," could be updated for the Internet age. How about this one: "We're from the government, and we're here to give your identity away -- no questions asked."


That was pretty close to how it was in California over the last three years, and who knows right now on how many local, state, county, and federal Web sites nationwide?

State Assemblyman Dave Jones, D-Sacramento, has accused the state of "selling an identity theft starter kit on the Internet" after he discovered the gaping security hole on the California secretary of state's Web site.

The site had been posting uniform commercial code filings, which are voluntarily provided by banks, with "enough information to open a credit card in someone else's name." He said the state was selling Social Security numbers for $6 each, an Internet connection, and a credit card. As a test, Jones bought 20 public records, 14 of which he said contained enough information to enable him to open credit cards in someone else's name, had he wanted to.

The filings are only supposed to be available to financial institutions and contain information about collateral used for loans, mostly from businesses, but some personal loans as well. The state has to accept the filings, but good lord, it doesn't have to make the information so easy to access online.

The state secretary of state, Debra Bowen, has said the 2 million files, which were available for at least three years, will be taken down until her office can figure out a way to hide all but the last four numbers of each person's Social Security number. She also says there have been no complaints of identity theft filed. But so what? As an ABC News report on the story notes, most people never find out where their data was stolen from.

But none of this really addresses why such personal data was widely accessible in the first place, and what will be done afterward to keep out prying eyes. In fact, along with the state of Indiana, officials might consider now a good time to review what information is being posted online. What information should be public? What changes should be made to documents so that they can go from being electronically filed to being posted safely on the Internet?

What do citizens think about state DMVs and census offices selling their personal data? Shouldn't the government just agree now that no Social Security number should ever be posted on any public document? Any insurer or bank or credit analyst who needs your SS number probably already has it (and probably because you gave provided it yourself).
Why should anyone else need it legitimately? Someone else's need to spam millions with credit or insurance offers isn't your problem.




Other articles
2010/3/18 8:07:31 - Panda Cloud Antivirus Receives ICSA Labs' First Cloud-Based Certification
2010/3/17 15:49:34 - Open-Source Email Security Taken To The Next Level at WebhostingDay
2010/3/17 15:18:40 - McAfee Warns ABout Scareware or Fake Antivirus Software
2010/3/2 5:22:13 - VeriSign and AVG Will Integrate VeriSign Trust(TM) Seal Within AVG LinkScanner(R)
2010/3/1 7:36:12 - New Stealth Software Protects P2P Users From Lawsuits by Copyright Holders
2010/2/24 13:55:16 - New State of The Art Firewall By Palo Alto Networks
2010/2/24 13:50:26 - Beware of Fake Antimalware Programs Like PCsProtector
2010/2/24 13:38:02 - New Registry Cleaner Guide Helps Your PC Perform Faster
2010/2/3 7:32:43 - PC Login Now (Full version) Available Now For Free.
2010/2/3 7:11:57 - Mitto Named One of 20 Top Web Applications

The comments are owned by the poster. We aren't responsible for their content.