OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Dataloss] UK: Lost data disk exposes 2000 staff details

From: Jeffrey Walton (noloadergmail.com)
Date: Sun Jan 25 2009 - 12:29:30 CST


> personal details of around 2,000
> members of British Council staff has been lost.
In a perverted way, this is probably one of the few beneficial losses.
Perhaps stronger legislation will be presented which benefits all
British.

> the missing disk was securely encrypted to keep its contents safe if it
> falls into the wrong hands....
Perhaps it was encrypted with a proprietary algorithm also [see
below]. Even better, it might be using one of TSD's (of sci.crypt
fame) ciphers. In either case, it is interesting that the spokesman
was not cited as using the term 'encrypted'.

> "The data on the disk was compressed using a proprietary algorithm;
> furthermore it is not an ordinary CD-ROM or DVD, but an optical disk
> that can only be read by a particular type of reader with a specific
> version of specialist software. This software is no longer
> manufactured and cannot be purchased.
I suspect this is an attempt to comfort the victims.

> "These precautions ensure that the data is extremely secure in the
> unlikely event that the disk should fall into the wrong hands.
The spokesman should probably stay away from commenting on
Cryptography. It also seems that the 'unlikely event' has occured.

On 1/25/09, kirniki <kirnikigmail.com> wrote:
> http://www.channel4.com/news/articles/science_technology/encrypted+staff+data+disc+lost/2910732
>
> A computer data disk containing personal details of around 2,000
> members of British Council staff has been lost.
>
> [ SNIP ]
>
> "The data on the disk was compressed using a proprietary algorithm;
> furthermore it is not an ordinary CD-ROM or DVD, but an optical disk
> that can only be read by a particular type of reader with a specific
> version of specialist software. This software is no longer
> manufactured and cannot be purchased.
>
> "These precautions ensure that the data is extremely secure in the
> unlikely event that the disk should fall into the wrong hands. The
> system for transferring data is being reviewed and in the meantime the
> data is not being sent."
>
> {..}
>
_______________________________________________
Dataloss Mailing List (datalossdatalossdb.org)

Tenable Network Security offers data leakage and compliance monitoring
solutions for large and small networks. Scan your network and monitor your
traffic to find the data needing protection before it leaks out!
http://www.tenablesecurity.com/products/compliance.shtml