DocuCrunch.com » Phony Lady Gaga CD used to steal sensitive docs

Phony Lady Gaga CD used to steal sensitive docs

July 13, 2010 by Sam Narisi
Posted in: In this week's e-newsletter, Latest News & Views, Security

Many companies ban or regulate the use of external storage drives to prevent sensitive information from being taken out of the office. But a recent incident at the Pentagon offers a warning about another data theft method.

American soldier Bradley E. Manning was arrested in May after being accused of stealing more than 150,000 highly classified documents and files from government computers in Iraq, including classified video of a helicopter attack that Manning leaked online.

Pentagon investigations have discovered his method for taking the data: He copied them to a compact disc disguised as a music CD by Lady Gaga.

While Manning burned the data to the CD, he said he wore headphones and lip-synched lyrics to look like he was listening to music.

In 2008, the Defense Department banned the use of USB thumb drives to prevent this type of thing from happening. The USB ports on computers with access to sensitive docs had been disabled.

However, the government’s computers still had disc drives installed with CD burning capabilities enabled, the New York Times reports.

Companies take note: You may want to think about policies and controls regarding CD burning for employees who deal with especially sensitive information.

Businesses might also want to considering disabling USB ports for those computers, or requiring IT to scan and approve USB devices before users connect them.

Also, configure anti-virus software to scan USB devices — in addition to users who intentionally pilfer company data onto iPods and other seemingly harmless storage devices, viruses can also be spread from those drives to the network if the proper controls aren’t in place.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , , , ,


One Response to “Phony Lady Gaga CD used to steal sensitive docs”

  1. Bob Says:

    Minor corrections:
    - USB is a “port” not a “portal”

    - CDs, DVDs and BLuray discs are referred to as “optical drives” not “disc drives”.

    - CD burning capability is a funtion of the device. CD or DVD readers can be used, referred to as “CD drive” or “DVD drive” in place of writeable / rewriteable drives, referred to as “CDR”, “CDRW”, “DVD+R”, “DVD-R”, “DVD+RW”. The main reason to mention this is that the device in question is licensed for the appropriate technology and has a visible logo on the front of the optical drive itself, meaning READ ONLY versus WRITEABLE devices can be identified by visual inspection.

    - Further, “burning software” allows data to be written to an optical drive. Optical drives do not function as part of the operating system as with flash drives and magnetic drives, but require special software to work properly. In newer versions of Windows, this software is included with the operating system, but is still separate. You can’t “burn” (write) data to a writeable optical device without “burning software”

    - The article’s title implies that somehow, Lady Gaga’s music was involved, or perhaps the manufacturing or distribution process for Lady Gaga’s music was somehow compromised. That’s not, in fact, the case. The article’s title could be more appropriately expressed as “Theif used CD burner while pretending to listen to music”. Lady Gaga is an insignificant detail.

    Here is some analysis of your conclusions:
    1. Any corporate environment handling sensitive data should have technology controls in place to disable USB ports, burning capabilities of the operating system, as well as prevent 3rd-party software installation. All of these are simple and cheap or free to implement.

    2. The correct security posture is to have all of these capabilities disabled as the default, enabling specific capabilties only where required. This ensures that as hardware is replaced, the new hardware inherits the appropriate policy. It also helps ensure that if there is an error, the error is more likely to be more restrictive than less restrictive. This approach is basic security 101.

    3. Environments where highly-sensitive information is involved, such as military or trade secrets, optical devices should not even be installed. If needed, they an be installed after the fact. If they are routinely used, read-only optical devices should be used by default, allowing writeable optical devices ONLY by exception (see #2)

    4. Asking IT to scan USB devices is asking for trouble. People are not going to follow a written policy if they don’t understand the risk or simply opt for the convenience of NOT following the policy. And, obviously, someone with malicious intent is NOT going to follow the policy. This is what is known as a “voluntary” or “opt-in” control because it requires people to “volunteer” to follow the correct process. The alternative is to implement technology controls (“mandatory” controls), which need to be only as restrictive as required, and resilient enought to handle various scenarios, such as disabling the use of certain classes of devices unless specifically approved by exception.

    5. Addressing USB and optical devices won’t solve the problem. Any computer has a hard drive that can be removed, and other types of ports that can be used to access and potentially duplicate sensitive information. As an example, there are camera pens, that look like ball point pens, that could be used to take pictures or video of the data displayed on a computer’s screen in order to copy sensitive data. The best approach is to ensure that multiple controls exist in layers, which is referred to as “defense in depth”. You are more likely to catch a determined hacker or theif when they trip over something simple, rather than expecting the “vault” approach to keep them out.

    6. There has to be an appropriate balance between restrictive security controls versus the cost and productivity overhead. The biggest mistake made in most corporate environments is to “overprotect” data that is not valuable nor sensitve. For each type of information, an assessment should be performed, and security controls should be implemented by risk level.

    Sorry to shoot your paraphrased interpretation of someone else’s work full of holes. This article is proof that you can repeat something interesting in order to sound interesting.


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement