Quantcast StorefrontBacktalk » Blog Archive » A Chilling Reminder Of The Internal Security Threat
advertisement
advertisement

A Chilling Reminder Of The Internal Security Threat

Written by Evan Schuman
December 1st, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

It’s one of the oldest pieces of security guidance: The biggest threats are always from a company’s employees, not from intruders. But popular perception has never supported this truth because outside intrusions are comparatively highly publicized while internal threats are generally dealt with secretly, with a termination and an offer to avoid prosecution if the thief remains silent.

But T-Mobile this month reminded us of how serious an internal threat can be. In what U.K. authorities are dubbing one of the biggest data breaches in that country’s history, a resourceful (although ethically challenged) T-Mobile employee is accused of taking millions of pieces of customer data and selling it to company rivals. This situation is the subject of StorefrontBacktalk’s security column this week on the new McAfee security blog.


advertisement

3 Comments | Read A Chilling Reminder Of The Internal Security Threat

  1. Steve Sommers Says:

    I have read reports that the annual costs for internal fraud far exceeds the costs for external fraud yet for some reason, internal fraud does not get much press. Go figure.

  2. Evan Schuman Says:

    No mystery there. No company wants to admit to an internal assault. If handled properly, it can remain secret. No jail time, no fines. Just a termination and maybe restitution.

  3. A reader Says:

    The old (very very old, like pre-computerized systems old) rule of thumb in retail used to divide shortage into thirds. One third of shortage was external theft, such as shoplifters or con artists. One third was internal theft. And the last third of shortage was due to procedural or other errors, spoilage, damage, etc.

    Clearly a systems-based internal theft these days could do a lot more than empty a few tills of their change funds. But how often is it really happening, and how will we ever know unless Loss Prevention departments start publishing their figures?

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

Kill All The Passwords

This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly. Read more...
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis. Read more...