Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

California discloses massive ID theft
IDG News Service ^ | October 20, 2004 | Paul Roberts

Posted on 10/21/2004 2:32:37 PM PDT by Paleo Conservative

The state of California has warned residents that their personal data may have been stolen from computers at the University of California, Berkeley, after a database used by researchers there was compromised by hackers.

The California Department of Social Services (CDSS) issued a media advisory on Tuesday, saying that the agency was working with the U.S. Federal Bureau of Investigation to investigate an intrusion on a computer at Berkeley that contained personal information on around 1.4 million recipients and providers of In Home Supportive Services (IHSS), which provides home-care services to low-income elderly and disabled Californians. Names, addresses, telephone and Social Security numbers, as well as the birth dates for IHSS participants, could have been stolen by the malicious hackers, according to Carlos Ramos, assistant secretary at CDSS.

The state agency gave Berkeley the IHSS data, which was stored on a machine at the university, for research on the CDSS program. If stolen, the information could be used to fake the identity of IHSS recipients.

The compromise occurred on Aug. 1 and was discovered on Aug. 30 by Berkeley IT staff using intrusion detection software, Ramos said.

According to Ramos, investigators know a malicious hacker exploited a vulnerability in "commercially available database software" and compromised the computer, but they don't know if the attack was targeted, speculating that malicious hackers possibly discovered the system by scanning for machines running vulnerable versions of the database software.

While evidence indicates that none of the database's information has been misused, IHSS recipients were encouraged to obtain a credit report and make sure that they were not identity theft victims, the CDSS said in a statement.

A database of personal information on elderly and infirm people would be an attractive target for identity thieves, who may lack the technical sophistication to defend themselves against identity theft, and may even be unaware the IHSS database stored their data, said Jonathan Bingham, president and founder at Intrusic Inc., a Waltham, Massachusetts, company that makes software for spotting suspicious activity on computer networks.

"You take somebody who's elderly and hasn't had experience with computer networks, they're not going to get it," Bingham said.

Without adequate forensic information, investigators face a daunting task in reconstructing the intrusion and determining whether the IHSS database was compromised, let alone finding the culprits, he said.

"The problem isn't that the system was attacked but that it wasn't discovered for a month," Bingham said.

In the meantime, the CDSS asked Berkeley to return the IHSS data and will investigate whether the researcher adhered to an agreement to protect the personal information in the database. The department will also review other researchers' work to make sure they are adhering to data protection guidelines, Ramos said.


TOPICS: Breaking News; Business/Economy; Crime/Corruption; US: California
KEYWORDS: computercrime; getamac; hackers; idtheft; lowqualitycrap; napalminthemorning; windows; wot
Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

1 posted on 10/21/2004 2:32:37 PM PDT by Paleo Conservative
[ Post Reply | Private Reply | View Replies]

To: Paleo Conservative

Democrats


2 posted on 10/21/2004 2:34:00 PM PDT by ServesURight (Tim Michels for U.S. Senate Wisconsin)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paleo Conservative
low-income elderly and disabled Californians. Names, addresses, telephone and Social Security numbers, as well as the birth dates for IHSS participants,

A particularly vulnerable group.

3 posted on 10/21/2004 2:35:06 PM PDT by BenLurkin (We have low inflation and and low unemployment.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paleo Conservative

I'm surprised why Berkley didn't use BSD. This sounds like a Winders box that was compromised. I get SNORT log entries on a daily basis for SQL exploits on my Linux machine.


4 posted on 10/21/2004 2:37:24 PM PDT by nascartex
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paleo Conservative; Lazamataz; HAL9000; Bush2000; Nick Danger

Man, this article went out of the way to not mention that this hack was through the Oracle software that was purchased via no-bid by Gray Davis prior to his recall...

5 posted on 10/21/2004 2:38:20 PM PDT by Southack (Media Bias means that Castro won't be punished for Cuban war crimes against Black Angolans in Africa)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ServesURight
Berkeley...

Liberal scum...

6 posted on 10/21/2004 2:39:51 PM PDT by 69ConvertibleFirebird (Never argue with an idiot. They drag you down to their level, then beat you with experience.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Paleo Conservative

Paging John Edwards, class action law suit alert.

If anything happens to anyone on the list. Sorry for the citizens of California but confidentiality has been broken. I used to make homevists to people who used supportive services. They are the truly vunerable. Sloppy records security.


7 posted on 10/21/2004 2:40:39 PM PDT by MKM1960
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascartex

So now exploited Oracle Databases are Microsoft's fault too, now?


8 posted on 10/21/2004 2:42:25 PM PDT by Chad Fairbanks ("I don't worry about Muggers. My biggest fear is Poachers." - Elizabeth Edwards)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Paleo Conservative

Voter fraud....


9 posted on 10/21/2004 2:42:50 PM PDT by StrictTime ("They might be fake/ they might be lies/ they might be big, big, fake, fake lies" TMBG)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paleo Conservative

How much would you like to bet every one of these elderly and disabled people who's ID was in the database votes a straight Democratic ticket come election day?


10 posted on 10/21/2004 2:43:12 PM PDT by tacticalogic ("Oh bother!" said Pooh, as he chambered his last round.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Chad Fairbanks

Where does it say Oracle database in the article?


11 posted on 10/21/2004 2:43:18 PM PDT by nascartex
[ Post Reply | Private Reply | To 8 | View Replies]

To: tacticalogic

In alphabetical order.


12 posted on 10/21/2004 2:45:55 PM PDT by Paleo Conservative (Hey! Hey! Ho! Ho! Dan Rather's got to go!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Paleo Conservative

this doesn't happen. computers are completely safe. national medical database? completely safe.


13 posted on 10/21/2004 2:45:59 PM PDT by the invisib1e hand (do not remove this tag under penalty of law.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Chad Fairbanks; nascartex
So now exploited Oracle Databases are Microsoft's fault too, now?

That sounds like an opportunity for massive finger pointing.

14 posted on 10/21/2004 2:47:10 PM PDT by Paleo Conservative (Hey! Hey! Ho! Ho! Dan Rather's got to go!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: StrictTime
Ding ding ding. Betcha all the "recipients" who die between August 1 and November 2 still manage to vote for Kerry.
15 posted on 10/21/2004 2:47:51 PM PDT by JasonC
[ Post Reply | Private Reply | To 9 | View Replies]

To: Paleo Conservative

That would be about as smart as stealing a homeless man's house keys.


16 posted on 10/21/2004 2:49:16 PM PDT by Old Professer (Fear is the fountain of hostility.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: nascartex

Oracle is the Database System of choice among California state agencies, thanks to Former governor Davis... It would be a safe bet that the college was using the same database, but it is currently just a guess on my part.


17 posted on 10/21/2004 2:49:19 PM PDT by Chad Fairbanks ("I don't worry about Muggers. My biggest fear is Poachers." - Elizabeth Edwards)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Chad Fairbanks

OH. I did not know that. I wasn't aware of any exploits for Oracle newer than 9i. Now ifs its 7 or 8, then yeah, there are BIG holes in those revisions.


18 posted on 10/21/2004 2:52:47 PM PDT by nascartex
[ Post Reply | Private Reply | To 17 | View Replies]

To: nascartex

Oracle warns of exploits for latest DB flaws
Malicious code that can exploit unpatched vulnerabilities in its software



By Paul Roberts, IDG News Service October 15, 2004



Oracle (Profile, Products, Articles) Corp. is warning customers to apply software patches it released in August, citing the availability of malicious code that can exploit unpatched vulnerabilities in its software.


19 posted on 10/21/2004 2:55:19 PM PDT by Southack (Media Bias means that Castro won't be punished for Cuban war crimes against Black Angolans in Africa)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Paleo Conservative
The compromise occurred on Aug. 1 and was discovered on Aug. 30

*snicker*

20 posted on 10/21/2004 2:56:02 PM PDT by Lurking in Kansas (I'm just a guy sitting in my living room in my pajamas...)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson