Slashdot Log In
Data Theft Notifications - How Soon is Too Soon?
Posted by
Cliff
on Fri Sep 22, 2006 10:36 PM
from the sooner-than-later dept.
from the sooner-than-later dept.
bsdbigot asks: "I started getting a bunch of stock-tout spam in the last month or so. The other day, I happened to look and see it was coming in to an email address I had dedicated to my online trading account account. I've spoken to the online trading company, and I've given them the info on these spams. It turns out there is an 'ongoing investigation,' which includes 'outside agencies,' but they stop short of saying that there is any theft or breach. How soon should such a company let its customers know that their data has been compromised? Should they wait until they have all the details and have plugged the breach, or should they let customers know that there is a possible problem as soon as they recognize it?"
"Personally, I believe a security breach has occurred. So, I asked them how many people are affected by this; they feel certain that it's an isolated problem, because they haven't received a deluge of complaints. They don't know how these spammers got my reserved email address from my online broker (but they didn't sell it, they are quite clear on that), so how can they be so certain it's not their entire database, and how can they be so sure that things like my SSN and bank routing information wasn't also stolen?"
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Do more (Score:4, Insightful)
Re: (Score:3, Funny)
Re:Do more (Score:4, Insightful)
Parent
Re:Do more (Score:4, Insightful)
For companies and agencies that have to have highly sensitive information like SSN's on file, there should be an exceptionally small number of people who have access to that information. A small enough number that I can count them on one hand. And none of those people should ever be allowed to take any portion of that list out of the system in any way, not on a thumb drive, not on a laptop, nothing. The vast majority of the employees should only be able to access the last 4 numbers of any given person for varification purposes.
Parent
Re:Do more (Score:4, Insightful)
First start with the fact wether or not the company needs the SSN or not. When in doubt, the answer is no.
It is a Social Security Number, not a Person Verification Number. If you use it for anything else then for Social Security reasons, you do not need to get it in the first place.
The best way not to loose the data or be tempted to sell it is not to have it.
Parent
Re: (Score:2)
In this day and age, the answer is Yes. Names change - people get married, divorced, decide to use Chuck or Charly instead of Charles. People move. Matching things up on these two - name and address - works 99.9% of the time (with a little effort) - but isn't absolute. SSN (and SIN for those in the Maple Leaf state) allows a match for that final 0.1% percent. (Yes, SSN change occasionally too, but
Re: (Score:3, Informative)
Your bank reports capital gains on your accounts to the IRS. They need your SSN. If you don't give it to them, they probably won't give you an account.
Re: (Score:2)
Re: (Score:2)
Re: (Score:3, Interesting)
Employees and contractors coming in contact with money, financial data (of which SSN is one piece), and any other customer data should be bonded. That is not a perfect solution, but a good first step. Try working in a bank branch without being bonded -- probably not going to happen. Banks know there's a lot at risk (and the government probably req
Re: (Score:2)
Turns out someone misconfigured a mailserver and someone was able to havest the email acounts for all the domains configured on the server. The other problem was traced to some bullshit E-Greeting card that my girlfriend devided to open when she checked her mail. Several weeks after the problem started on that address, the same E-card she sent me was implicate
Safe/sorry (Score:5, Informative)
File complaints with the federal and your state Attorney Generals against the trading company immediately. Consider a 6-month paid monitoring service from a major credit reporting bureau. Both the feds and your state will have advisory hotlines. IANAL and slashdot is not the place you want to go for this kind of information. Basically, don't fsck around if you think anything has been compromised.
I've been there, and these steps cost me a few dollars but saved me tens of thousands. Overseas types are pretty damned creative with your numbers. paranoid != not out to get you.
Re: (Score:2)
Plug the hole first (Score:4, Interesting)
As soon as it becomes public knowledge that they've got a vulnerability somewhere, the number of people poking around their interface attempting to stumble upon that hole (or other ones) will skyrocket. Better to fix known problems before they essentially invite the community to look for chinks in their armor. That said, as soon as any known holes are patched, they should inform the affected users; or, if they can't determine whose information was nabbed, they should alert all of their customers.
Keep in mind that no matter how suspicious the circumstances, unless you use that email address solely for your brokerage account, there's really no way to prove a connection unless the company admits it. A friend of mine started playing online poker, used his email address to sign up for the site, and doesn't get any poker spam. A week or so later, his wife started getting a ton of poker-related spam at her email address. It's just a coincidence, though it's about impossible to convince her of that.
I've seen a huge uptick in stock spam lately, across the board (I have a number of email accounts and only one of them is tied to a brokerage). Maybe you're just on the same spam lists
D'oh! (Score:2)
How stupid is E*Trade? (Score:5, Interesting)
Like the article-poster I'm one of those guys who uses individualized addresses for each online entity they deal with, as in slashdot thinks my email is slashdot@mydomain.com, amazon thinks it is amazon@mydomain.com and etrade thinks it is etrade@mydomain.com - those examples are simplified for illustrative purposes.
A while back, before the bubble burst, I dabbled in some options trading in my etrade account. Therefore, Etrade's marketing department decided that would make my contact information something they could sell to the CBOE and I started getting bi-weekly spam from somebody on behalf of the CBOE trying to sell me all kinds of bullshit options information -- all sent to my etrade-only address.
After about a year of that crap, it finally stopped on its own. But then I started to get spam from the same mailing-list operator that the CBOE had used, but this time they were promoting other brokerages like TD Waterhouse, and most recently "TradeKing" which seems very questionable.
Whenever I get one these brokerage spams, I have to laugh. Etrade breached my privacy to make a buck or two and I'm sure they did the same thing to tens of thousands of other customers. But the end result is that their competition now has a confirmed mailing list of etrade customers, and the stupid greedy bastards GAVE it to them.
I've since opened an account with TD Waterhouse (aka Ameritrade) and make most of my trades through them, in part because of etrade's callous treatment of my privacy. I wonder how many others have done the same...
Re:How stupid is E*Trade? (Score:5, Informative)
Parent
Re: (Score:2)
The problem is that at least 1/2 of the services on the web will consider this an invalid address (despite it being perfectly valid). Very annoying.
Re: (Score:3, Insightful)
Re: (Score:2)
Re: (Score:2)
Down sides: creating a new address is more involved; if you don't control your own DNS servers, you have to wait for the zone to reload. I've scripted most of this so that I can set up a new one in under a minute.
Up side: when an address is abused, you just yank th
As stupid as Ameritrade (Score:2, Informative)
Ameritrade/TD-W also let its email addresses out, too. My specifically-for-Ameritrade email address got vanilla (same type as my other accounts; not investing at all) spam. So I changed it. Again.
DT
Re: (Score:3, Interesting)
I do the same thing. So, I'll get to the point quickly...
The email address that I use for my Hertz rental membership has been distributed to spammers, twice. The first time, I sent a complaint and after a while I got a patronizing response about how it couldn't be them, and was instead someone else to whom I had given the address. It must have been a form response, as I had alr
Maybe YOU were hacked (Score:3, Insightful)
Re: (Score:3, Informative)
Re: (Score:2)
Credit card info and passwords will be encrypted, if a user is taking any precautions at all.
However, most connections between MTAs (Message Transfer Agents like Sendmail, Postfix, etc.) are not encrypted. My Postfix server offers TLS to a
This has happened to me before... (Score:2)
I NEVER type these addresses anywhere, and they are not something a wide net spam sender would guess...
Over the last few years i have had about 4 situations where those very account specific addresses began receiving a LOT of spam.
The sites included Dell, and PCMall. The PCMall ones very primarily sexual in nature...
I have thought of every possible way they could have gotten that addre
Re: (Score:2)
Re: (Score:2)
You think that nobody has ever come up with this idea before, creating unique mailboxes for various relationships? I've been doing it for 6 or 7 years, and I've taught dozens others the same idea. I probably got the idea from someone else or an article I read online or in print. But regardless, it is a simple and logical scheme that some savvy spammers are bound to figure out on their own (more so now
Dictionary attacks? (Score:2)
Are we talking about Ameritrade? (Score:4, Informative)
"I started getting a bunch of stock-tout spam in the last month or so. The other day, I happened to look and see it was coming in to an email address I had dedicated to my online trading account account. I've spoken to the online trading company, and I've given them the info on these spams. It turns out there is an 'ongoing investigation,'
Is the trading company called Ameritrade by any chance? They got a leak problem, maybe an insider job. Look at this thread on spamgourmet (an anti-spam site that I help with): http://bbs.spamgourmet.com/viewtopic.php?t=81&star t=60 [spamgourmet.com]
Re: (Score:3, Funny)
Damn, I went there looking for recipes. Please stop using misleading domain names.
Immediate but reserved (Score:2)
certain laws may apply (Score:3, Informative)
Oops (Score:2)
How soon is too soon??? (Score:2)
Sometimes hard to tell (Score:2)
But if you believe that sensitive data was probably stolen, then you should have to alert the people you believe were probably affected immediately. The only problem with thi
Re: (Score:2)
It's a balancing game... (Score:2)
Let's take a stolen laptop, for example. If Company A's suffers a laptop theft, and the laptop (for whatever stupid reason) has the personal data of thousands of customers or employees on it, how should that company respond? This is obviously an example of poor security to begin with (no one should have that kind of information on a laptop taken off the premises), but how do you keep a bad situation from getting wor
Re: (Score:2)
I'm not sure there's always a best way to handle these things - sometimes it could be informing everyone, at other times it could just mean scrutinizing accounts more closely while keeping everything quiet. It's a hard thing to balance.
The same rule as always applies here-SECURITY THROUGH OBSCURITY DOES NOT WORK. You could be dealing with a couple of punk kids who randomly stole a laptop and are off at the first opportunity to pawn it-or you could be dealing with organized gangsters who know damn well w
Are they incorporated in California??? (Score:3, Interesting)
I understand that there have been several attempts to leverage that law on behalf of US citizens who can't afford to live in California (us poor, ol' east coast folks!) to require major corporations transacting any business in California to immediately disclose based on that law.
I'm sure there's jurisdictional issues, but there's at least some chance in hell that virtue jurisprudence will prevail.
Anyone with an actual Litt.D, SJD, or otherwise more qualified care to add fact to my hype and speculation?
Re: (Score:2)
Transfer your account to another broker. Now. (Score:2)
Get out of that broker now. Move all your assets to another broker. You don't want to have assets with a broker in trouble.
I've been through a broker bankruptcy, and it's a huge hassle. Yes, you eventually get the assets back, but you may be trapped in a position and unable to trade out of it.
priorities (Score:4, Funny)
that depends, how long does it take to finance a new ferrari and a yacht to ship it out of the country?
Notify Immediately (Score:3, Interesting)
Re: (Score:2)
Myself I'd run screaming from such an online store, and war
ANSI and BBB Standards (Score:3, Informative)
Whether or not this results in the answer to your question (how long notification should be given), at least this is a step in the right direction for some centralized thinking instead of everyone doing it on their own.
Why should they care? (Score:2)
True security only comes when it's in the best interests of the person for whom the security is a cost, particularly at a corporate level. I'm sure t
disposable addresses (Score:2)
Re: (Score:2)
I agree.
Change your address to your address. . .