Tuesday, January 15, 2008

Employee anger almost causes problems for company

Before I jump into my story, I wanted to introduce myself. Michael McCoy honored me by asking if I could contribute to this blog. My name is Nate Evans and I am a PHD candidate at Iowa State University in computer engineering. My research expertise is in an area very close to identity theft, social engineering. In some ways you could classify identity theft as a small piece of social engineering, but I don’t want to step on anyones toes here! I currently am working on my dissertation and am employed part time for the Walt Disney Company and The Krell Institute.

So in short, expect stories from me involving people ripping other people off.

When people define social engineering and try to explain the problem about it, they normally start with something like this:

“You can spend millions of dollars building a super secure computer system, but if the system admin sells his pass for $1,000, your system is now worth $1,000.” What if the system admin does not sell the password but instead uses it against the company to destroy or sell company data? This brings me to my story.

Recently a 51 year old administrator, Andy Lin, was given 30 months in jail and fined $81,200 for trying to destroy a medical drug database in a company he was employed with.

Way back in 2003, Andy learned that his company, Medco, was going to lay people off and he wasn’t sure he would survive the layoffs. In a fit of anger, he decided he would make the company pay by writing a script to delete everything in the company’s database. The script was set to go into effect automatically on his birthday April 23, 2004.

Well a couple weeks rolled by and Andy did not get laid off. As such he attempted to edit the code to make it ineffective. He failed and on April 23, 2004, the code deployed anyway.

Luckily the code contained numerous bugs and his program just crashed. Andy, still the cautious type, fixed the bug and reset his doomsday timer to the April 23, 2005.

Fortunately for the company, another System Admin was looking into this odd crash and found Andy’s code. On January 2005, Andy was arrested and pleaded guilty to one count of transmitting computer code with the intent to cause damage in excess of $5,000, and he was sentenced last week.

Its amazing how much damage one employee could do to a company. If that database was deleted the company would be in massive trouble. Imagine if the employee, instead of destroying it, sold it to the competitors...

You could take one of two lessons from this: Either don’t trust people, or pay your system administrators more!

Nate Evans
ISEAGE PBS Leader
The Krell Institute

Labels: , , , , , , ,

Thursday, March 15, 2007

Industry of Ignorance or Greed?

I have stated in my book as well as my lectures and seminars that in my opinion identity theft “insurance” or a “monitoring service” that is proactive as well as reactive will be a must in everyone’s insurance portfolio within three to five years.

You do not have to like this, it is a matter of necessity.

Ask yourself, when is the last time you have made a claim under your auto insurance? What about your home owners insurance? Then why do most of you carry it? It is the same reason you will start to carry identity theft insurance.

The problem with insurance products on the market today is they are not robust enough. Until someone starts to listen to the masses and builds a product for the good of the people instead of for corporate greed the individual will continue to lose.

I am convinced the insurance industry is to lazy and greedy to do the research needed to build a product that will have some real teeth. I am also convinced that the congress is to lazy, greedy and worried about being re-elected to make any "real" changes to the law that, god forbid, is on the side of the public instead of "corporate america." I want to assure the insurance industry, if you get your head out of the sand and realize what opportunity you have in front of you there is a lot of money to be made, while truly fulfilling your client's needs.

In a meeting, roughly one year ago, I attended with a large company that provides an identity theft protection product, I voiced my concern with their product and the lack of “true” proactive coverage and the false sense of security the consumer was getting from it. The answer I received from their managers was flabbergasting. They said their product was … (Another Post for another Time) Even I was shocked.

This is not a local, state, regional, or national issue, this is a global issue that can and will cause financial destruction on a global scale. This global issue will soon become an epidemic if unchecked as the below article from South Africa demonstrates.

In an article written by Nabelah Adams on 15 March 2007 for BusinessOwner.Co.ZA, Nabelah quotes Caroline Buthelezi of the Credit Information Ombud’s Office of South Africa as stating, “Clearing one’s name involves a great deal of effort as many people only discover the consequences of not reporting their ID book stolen when the credit bureau has already handed the matter over to their lawyers.”

“The consequences of ID theft might be even more exacerbated by the fact that attempts to have matters resolved are complicated by having to deal with attorneys,” Buthelezi says. This is of course if you can afford to hire an attorney.

© 2007 Michael R. McCoy

Labels: , , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft