Home > Security News > Schneier: Data breach at UCLA barely newsworthy
Security News:
EMAIL THIS
COLUMN

Schneier: Data breach at UCLA barely newsworthy

By Bill Brenner
15 Dec 2006 | SearchSecurity.com


Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Security bloggers are focusing on another big security breach this week. But some are starting to wonder if it's really worth paying attention to anymore.

UCLA is among the latest in a long list of organizations forced to acknowledge a data security breach affecting those who do business with them.

In this case, a hacker cracked a university database containing the personal information of former students, faculty and staff, exposing 800,000 people to potential identity fraud. The intrusions apparently went on for more than a year before UCLA security staff discovered it last month.

Reaction in the blogosphere ranges from disgust that the hacks were allowed to go on for so long to amusement that the latest victim is an organization that helped create the Internet.
About Security Blog Log:
Senior News Writer Bill Brenner peruses security blogs each day to see what's got the information security community buzzing. In this column he lists the weekly highlights. If you'd like to comment on the column or bring new security blogs to his attention, contact him at bbrenner@techtarget.com.

Recent columns:

Zero-Day Tracker a hit, but IT shops need better strategy

Oracle answers its security critics

Zango defying FTC agreement, researchers say

Then there's the virtual yawn coming from the blog of security luminary Bruce Schneier. With security breaches becoming such a routine occurrence, he suggested that there's no longer a reason to make big headlines out of each new case.

"This is barely worth writing about: yet another database attack exposing personal information," Schneier wrote. "My guess is that everyone in the U.S. has been the victim of at least one of these already."

Though it may not be worthy of the coverage it's getting, he did point to one thing about the UCLA case he found troubling.

Jim Davis, UCLA's associate vice chancellor for information technology, told media outlets that the attack was sophisticated and used a program that exploited a flaw in a single software application among the many hundreds used throughout the Westwood campus.

"An attacker found one small vulnerability and was able to exploit it, and then cover their tracks," Davis told The Los Angeles Times.

To that, Schneier said, "It worries me that the associate vice chancellor for information technology doesn't understand that all attacks work like that."

BoingBoing is among the many blogs making mention of the UCLA breach. One of its readers wrote in to describe the email he received from the university. Illustrating how the breach affected more than students and faculty, the reader noted that he has never attended UCLA.

"I applied to their law school three years ago," he said.

Meanwhile, a CISO who frequently contributes to the Emergent Chaos blog under the name Arthur wrote that the breach showed a lack of security controls on UCLA's part.

"It's a real shame they didn't have more effective security controls and monitoring systems in place," he wrote. "Maybe then this incident wouldn't have happened or been detected and stopped much earlier."

The Independent Sources blog noted the irony of the situation, given that UCLA played a big role in the creation of the Internet.

"Think of it as Frankenstein turning on its maker," the blog said. "Years ago, UCLA played an active role in creating the Internet. Then several years later, it is used to steal personal information on 800,000 current and former UCLA students and faculty."

UCLA may be proud of their computer science department, the blog said, but "it'd be nice if the folks running the main computer system did a little better job locking down the database."

Microsoft's massive patch tally
Elsewhere, Microsoft released its December patch load Tuesday, fixing zero-day flaws in Visual Studio and Windows Media Player as well as other glitches in Internet Explorer and Windows.

Unless the software giant rushes an out-of-cycle patch into circulation before the year is out, the company will have addressed 133 critical and important vulnerabilities in 2006, according to a tally kept by McAfee in its Avert Labs blog.

The blog includes two graphics showing the number of critical and important flaw fixed this year compared to 2004 and 2005.

Tags: Identity Theft and Data Security BreachesDatabase Security ManagementIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Identity Theft and Data Security Breaches
How to prevent and build protection against online identity theft
Heartland breach highlights PCI limitations
FBI investigates coordinated ATM scam
Encrypt now to meet new Mass. data protection law
Recovery plans essential for preventing data loss disasters
Internal auditors and CISOs mitigate similar risks
Cybersecurity expert sees PCI DSS problems ahead for retailers
PCI is about eliminating data, not securing it, former QSA says
Data breach discovery, disclosure outpaces 2007
PCI groups to focus on wireless, pre-authorization changes
Identity Theft and Data Security Breaches Research

Database Security Management
Oracle to buy Sun Microsystems for $7.4 billion
Oracle issues 43 updates, fixes serious database flaws
Information security book excerpts and reviews
Kaspersky website hacked multiple times, expert says
Kaspersky website hacked, customer activation codes exposed
SQL injection attacks targeting Flash, JavaScript errors
Fuzzing tool helps Oracle DBAs defend against SQL injection
Oracle extends Audit Vault third-party database compatibility
When should a database application be placed in a DMZ?
Oracle patches dangerous WebLogic, Secure Backup vulnerabilities
Database Security Management Research

Identity Theft and Data Security Breaches
TJX to pay $9.75 million for data breach investigations
Man pleads guilty in online banking hacking scam
White House cybersecurity czar faces major hurdles
Heartland breach cost $12.6 million, CEO says
An inside look at security log management forensics investigations
LexisNexis investigates breach, notifies thousands
Senators hear call for federal cybersecurity restructuring
Former Federal Reserve Bank employee arrested
Attackers cash in on fundamental data handling mistakes, Verizon finds
Courts turn aside data breach suits

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data encryption/decryption IC  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
link encryption  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts