Google Search

Showing posts with label employee. Show all posts
Showing posts with label employee. Show all posts

Thursday, May 1, 2014

Tokyo airport employee loses handwritten passcodes ahead of Obama visit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tokyo Haneda Airport. Image courtesy of ShutterstockThe dangers associated with writing passwords down were expertly demonstrated by a Japanese airport worker over the weekend as the country prepared for the first visit by a US president in almost 20 years.

Rubbish bins and luggage lockers have been sealed and over 16,000 police officers have been mobilised in the capital city of Tokyo ahead of President Barack Obama's visit Wednesday night - but it may be the loss of several passcodes that has caused the biggest security headache so far.

Speaking on Tuesday, a transport ministry official said that an employee of Skymark Airlines at Tokyo's Haneda International Airport mislaid a printout containing key passcodes on Sunday.

The document was found just thirty minutes later on the floor of the departure lobby but the Japanese government were not prepared to take any chances.

Whilst there is no word on which areas of the airport would have been accessible with the lost codes, the ministry instructed the company that manages Haneda International to change them immediately in order to avoid even the slightest chance of a security breach.

The security faux pas comes at an awkward time for the airport, as it is just one month since the Metropolitan Police Department created a dedicated counter-terrorism unit tasked with securing the facility after the number of international flights was increased by almost fifty percent.

The same airport is also set to become a key destination when the Olympic games are hosted in the city in 2020.

It also comes at a time when airport security in general is under the spotlight following the news that a 16-year-old boy had survived a five-hour flight in an aircraft's wheel well. The lad had jumped a fence at San Jose airport and was able to gain access to the plane's undercarriage without alerting security.

But the Tokyo airport isn't alone in having a problem with remembering security codes or passwords without the need to write them down – other organisations have had a good go at embarrassing themselves recently too.

Two years ago a televised ESPN interview took place in front of a wall which proudly displayed two passwords, and in February a CBS Super Bowl report clearly displayed the TV station's WiFi username and password in the background.

Password. Image courtesy of ShutterstockYou may also remember the Polish television broadcast that featured a woman being interviewed in front of a whiteboard that displayed the company's login credentials and Prince William's RAF photos that showed off an incredibly lame password choice.

So how can you choose a password that is both strong and easy enough to remember without having to write it down?

This video from Sophos gives some great practical advice on doing just that.

As said in the video, it would be foolish to then reuse that same password across the entire web because, should it be compromised in any way, the bad guys will then have access to ALL of your accounts.

Therefore, it would be wise to also use a password manager, such as KeePass or LastPass, which will allow you to store many complex passwords whilst only needing to remember one - and, whatever you do, don't write it down!

Follow @Security_FAQs

Follow @NakedSecurity

Image of Tokyo Airport and password courtesy of Shutterstock.


View the original article here

Saturday, March 2, 2013

1 "terrific employee" + 1 thumb drive + 6,000 lost medical records = fired!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Lost USB stick, courtesy of ShutterstockA woman called a "terrific employee" by her boss was fired after downloading 6,000 medical records onto a USB drive that she then lost.

The Salt Lake Tribune reports that the woman - an account manager handling Medicaid data for residents of Utah, in the US - was shown the door after losing the portable drive earlier this month.

Jim Clair, the CEO of her now-former employer, Goold Data Systems, of Maine, said it was all pretty regrettable:

"She was a terrific employee who made a mistake, a pharmacist who oversees the entire Utah account... But [the data loss] is that serious to us."

Goold Data Systems manages pharmacy claims for several states' Medicaid programs.

Contrary to company policy, the woman had downloaded a file containing names, ages and prescription information for 6,000 Utah Medicaid recipients onto a USB memory stick.

Then, earlier this month, somewhere between Salt Lake City, Denver and Washington, D.C., the woman lost the device.

Of course, companies should take such matters seriously, but they should do more than write policies that employees might be completely oblivious about.

Here's the thing: the employee probably didn't even realize that putting a file onto a thumb drive was against company policy, as CEO Clair told the Salt Lake Tribune.

She had difficulty uploading a file ordered by the Utah Department of Health, so she just found it easier to pop it onto a thumb drive, he said.

Woman with USB, courtesy of ShutterstockSo is the incident really her fault?

There are readily available technologies that prevent copying of unencrypted sensitive files (or any files at all) onto USB drives.

Having a company policy against USB drive usage, or USB drives leaving the facilities, is insufficient - perhaps even a bit on the lax side, given that it's technologically feasible to stop these things.

Clair admits that the information on the drive may never wind up being compromised. It did not, in fact, contain Social Security numbers, which would have opened up the door much wider for identity theft.

"It could be sitting in the trash somewhere and eventually destroyed," Clair said. "But it should have never happened in the first place."

He's right. It should never have happened in the first place.

And if Goold, and other businesses, did a bit of work beyond writing policy, they could ensure it doesn't.

As Sophos's Paul Ducklin said back when police were fined over a stolen, unencrypted USB drive, encrypt everything, and you never have to worry about the stuff you didn't encrypt.

Follow @LisaVaas
Follow @NakedSecurity

Lost USB and woman with USB images courtesy of Shutterstock


View the original article here