Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Database

    Database Breach at Computer Forensics Company Shocks Security Community

    Written by

    Lisa Vaas
    Published December 23, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security and law enforcement professionals are appalled that their personal information has been leaked by Guidance Software Inc., a security software and training company they say should have known better than to leave an unencrypted database exposed on the Internet.

      “I was shocked that a company like Guidance would be this sloppy,” said Peter Garza, CEO of EvidentData, a computer forensics and network security firm that counts itself among Guidances customer base.

      “My first response was that I was shocked they would have an unencrypted database that was accessible via the Internet,” Garza said. “I would think any vendor that has a system connected to the Internet would be more responsible, but as a security company, [Id think] theyd be even more adept.”

      Guidance last week sent a letter to its customers advising them that on Dec. 7 it had discovered a security breach on its customer records database. This wasnt your typical breach—this was a crime that Guidance customers described as being of national security proportions. The database contained credit card numbers of some 3,800 people, including investigative professionals from the NSA, FBI and CIA, as well as heads of law enforcement worldwide.

      “In terms of homeland security, the individuals participating in Guidance training are tasked with ensuring the safety of the U.S. and its infrastructure,” an EvidentData spokesperson said in an e-mail exchange. “Because of this, the breach can easily be correlated to break-in of national security proportions.”

      Guidance said in its letter that it believed that the compromised database contained names, addresses, credit card numbers and expiration dates. Most troublesome of all was the exposure of credit card verification numbers, given that it is illegal to retain that data in the first place.

      Guidance has been working with the U.S. Secret Service as it investigates the crime. It has deleted all of its customers credit card information from its database, Guidance said in the letter, and is “confident” that the intrusion has been contained.

      /zimages/1/28571.gifDatabase security breaches have been coming fast and furious as the year draws to a close. Click here to read what is being done about them.

      “While this event is extremely troubling, we are confident, based on an immediate forensic analysis, that the intrusion has now been effectively terminated and our network has been secured,” Guidance CEO John Colbert said in the letter. “In addition, we are reviewing our operations and redoubling our efforts to ensure that customer information is secure.”

      But that assurance didnt keep the thieves from racking up some $20,000 in unauthorized purchases of pay-per-click Google advertising on the American Express bill of one customer. According to the Washington Post, computer forensics investigative firm Kessler International received the Guidance letter at the same time it also received an American Express bill containing the unauthorized charges.

      Some customers are grumbling that, given the sensitive nature of the customer base, they would have preferred immediate notification, as opposed to getting a snail-mail notification a week after the breach was discovered.

      “Many three-letter agencies, state and local professionals like myself that are in computer forensics in the civil practice” have had their information exposed, Garza said. “They have a database of whos who on investigating computer crime, and that was compromised. Their response to the community should have been immediate, not two weeks later or a week later.”

      Next Page: Cutting Guidance some slack.

      Page 2

      But other customers were willing to cut Guidance some slack, given the nature of a network breach. Mitch Dembin, an assistant U.S. attorney and cybercrime coordinator for the Southern District of California, as well as a one-time customer of Guidance, said that he could understand the snail-mail notification approach, given that a company in Guidances position might not even be sure that its systems would be secure enough to send e-mail without further compromise of sensitive data.

      “Recognizing your system has been compromised, are you comfortable using e-mail to contact customers?” he said. “With mail, youre avoiding the possibility of electronic compromise. Although its recognized as significantly more expensive for companies to use the mail, to do so, I think, is to ensure the customer gets the notice, which you cant ensure through e-mail. Particularly since your system has suffered at least one known compromise.”

      The lessons the breach teaches are already well-known, Dembin said, given that in this day and age, everybody knows the value of encrypting the database. That doesnt make encryption a straight-forward choice, however. “There are some difficulties, including cost, in encrypting database information, particularly when its a live database,” he said. “Its not so simple as saying, Encrypt it. If you need the data quickly, if the data is active, theres going to be a performance hit. Its just not so easy. If it was so easy to do, yes, by now everyone would have a solution in place and be doing it.”

      Retention of credit card data is another problem entirely, Dembin said—one thats arisen after credit card systems had already come online.

      /zimages/1/28571.gifFor advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis Internets Security IT Hub.

      “When we first started taking credit card information online, I dont think these concerns existed,” he said. “These concerns have become far more significant now, and card companies have combined to require that vendors only keep certain information a certain amount of time. But again, thats an adjustment [you have to make] to the software. It seems to me the kind of thing that if it was easy, everybody would do it. It might require tweaks, updates or changes that companies are planning for but they hope to get to before [disaster strikes].”

      In the meantime, users like Garza arent planning to stop using Guidance software, which he called “probably the most widely used computer forensic software in the Windows environment.”

      Hell just be more careful next time he goes back for training or software, he said. “Ill pay with check, not by credit card,” he said.

      /zimages/1/28571.gifCheck out eWEEK.coms for the latest database news, reviews and analysis.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×