Bonum Certa Men Certa

Being Honest About Security Breaches

posted by Roy Schestowitz on Oct 08, 2023

Crochet Blanket In Progress

THE Web (or web) we weaved in nearly 37 years combined (adding the age of this site to its sister site's) is a very large web of nearly 300,000 page, which all reside on the same server now, served in static form without a visitor-accessible (as opposed to user-accessible) back end. Throughout these years there were no known security incidents and now we're extra secure because scripts are not reachable by visitors of the sites or their respective Gemini capsules.

The half dozen [1-6] or so stories below focus on security incidents (via DataBreaches), which are not only very very very costly [2] but involve elaborate cover-ups [1], implicating governments [3] and impacting companies profoundly [4]. They try to blame other nations [5] (not the holes) or downplay the issues [6] (blaming human error) though the net effect is the same.

During my (almost) 12 years at Sirius I witnessed several security breaches. As noted at the time in some videos and articles, those affected were not being notified. Even staff of Sirius was barely made aware at times. Sometimes clients were given a hint, but as far as I can tell, those further down the chain were left in the dark.

A culture of lousy managers in charge (liars without technical skills) is part of the problem. They only care how they're seen, not about people's safety or any sense of integrity.

Related/contextual items from the news:

  1. OrthoAlaska notifies 176,203 patients of breach. When was the breach?

    On October 12, 2022 — almost a full year ago — OrthoAlaska discovered unauthorized activity on their systems. On March 3, 2023, they learned that information on former employees was stored in the system. On April 3, 2023, they notified those affected.

    And that’s where things remained until September 22, 2023, when OrthoAlaska notified HHS that 176,203 patients were affected by a breach.

    Was this the same breach first discovered in October 2022? We do not know because there is no notice on OrthoAlaska’s website at this time.

  2. Data breach at MGM Resorts expected to cost casino giant $100 million

    The data breach last month that MGM Resorts is calling a cyberattack is expected to cost the casino giant more than $100 million, the Las Vegas-based company said.

    The incident, which was detected on Sept. 10, led to MGM shutting down some casino and hotel computer systems at properties across the U.S. in efforts to protect data.

  3. Citizen data leak: NID wing suspends access for suspected govt, pvt partner organisations

    The national identity registration wing of the Election Commission [of Bangladesh] has suspended data access to a number of its government and private partner organisations over suspicions of leaking citizens’ data online, while putting all of its 174 service recipient organisations under watch.

  4. Clorox Expects Double-Digit Sales Drop Following Cyberattack

    Household cleaning product giant Clorox said Wednesday that an August cyberattack had taken a big swipe out of the bleach maker’s sales and profits in the quarter that ended Sept. 30.

    The Oakland, California-based manufacturer maker expects organic sales to drop between 21% and 26% due to widespread disruption, order processing delays and product outages after the August cyberattack.

  5. North Korea Suspected in Massive Hack of DeFi Project Mixin (1)

    The massive breach of a decentralized finance project bears the hallmarks of a North Korean attack, according to a senior White House official.

    Mixin Network, which helps blockchains handle transactions more efficiently, said it had lost less than $150 million in a late-September attack. Originally the company estimated it lost $200 million but reduced it after a final inspection.

  6. NL Health Services Reveals Pediatrics Privacy Breach

    NL Health Services has another privacy breach on its hands.

    The news came quietly in a news release sent out just after 5:30 Friday evening.

    The breach is related to an email sent to the parents and guardians of 253 pediatric patients with diabetes.

    Officials say “the recipients of that email were inadvertently not blind copied,” allowing everyone on the list to see each other’s email addresses.

Other Recent Techrights' Posts

They're Very Jealous of Richard Stallman and His Freedom (or Simple Lifestyle)
Jealousy is toxic because it can cause rational people to act irrationally and even severely harm themselves
Akira Urushibata on GNU coreutils
new message
There's Nothing Funny About Lawbreaking
There's plenty of room in society for humour, but "hacking" the state by breaking laws isn't cool or hip
Gemini Links 26/05/2025: Intangible Stuff and Slop Issues
Links for the day
 
Microsofters Have, in Effect, Attempted Extrajudicial Action Against Us
Courts and Judges (or Masters) don't exist to facilitate this kind of "bro" culture
UK High Court Masters Are Not Your Jesters, Microsoft
Judges aren't there for "funny" spectacles, they're there to act as arbiters in critical cases, not SLAPPs
Links 27/05/2025: Mass Layoffs at Volvo and More Evidence of 'AI' (Slop) Being a Passing Fad
Links for the day
The Code of Conduct (CoC) Gaslighting Phenomenon
There are still many people and projects foolish enough to outsource their labour to Microsoft via GitHub
Anouk Rozestraten (Deputy Director) Appears to Have Left the Free Software Foundation
Let's hope Rozestraten is still using and promoting Free software
More Mass Layoffs Coming Soon to Microsoft, Just a Question of When and How Many
Numbers from Washington were close to 5% and judging by prior rumours, it would be 5% + 5% (total 10%) at a later month
Links 27/05/2025: Bikes, Ideal Computers, and BYO
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 26, 2025
IRC logs for Monday, May 26, 2025
Richard Stallman's Milan Talk (Public Presentation) Was Packed, Video Available Soon
Looks like they even ran out of seats
The Openwashing Shills Initiative (OSI) - Part I: Complaints to IRS or USDOJ Needed
If enough people do it, this will be more effective, more so if people who are based in the US do it
Open Source Initiative (OSI) Lobbying and the OSI's Status at Stake
At the end we plan to summarise all the issues in one very long article
Breaking Into Other People's Devices Without Authorisation Isn't "Funny" or "Research"
“Chaos was the law of nature; order was the dream of man.”
The Issue Isn't the Internet, the Issue is How People Are Taught to Use or Misuse It
The Web is circling down the drain. The Internet is not.
A Healed Reputation of a Movement's Leader and His Robust Message
The more aggressively you push against resistors, the more credibility they will gain
Links 26/05/2025: Deletions from Microsoft's GitHub, Telegram Blocked in Vietnam
Links for the day
Linux Released Last Night and There's Already LLM Slop With Slop Images
BetaNoise does not seem to mind this anymore
Links 26/05/2025: Walmart Layoffs and DRM Dumpster Fire ('Old' Fire TV Devices Lose Netflix Access)
Links for the day
Gemini Links 26/05/2025: USB Camera Viewer and Fantasy Life
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 25, 2025
IRC logs for Sunday, May 25, 2025
Links 25/05/2025: 15 Years of UK Legal Aid Applicant Data Grabbed and 2 Billion Discord Messages Leaked Online
Links for the day
Gemini Links 25/05/2025: Farming and OpenBSD 7.7 on Acer Aspire ES 15
Links for the day
Fighting for Freedom is Much Better Than Fighting for Money
If life is about accumulation of money, then people will be "busy making money" till they die prematurely (with nothing to do with this money)
The Microsoft SLAPP Dossiers
A rather likely outcome is, they'll lose their licence to operate
Links 25/05/2025: Harvard’s Troubles and New Openwashing Examples
Links for the day
Gemini Links 25/05/2025: Whales and Battery Replacement
Links for the day
Links 25/05/2025: Climate Action Ridiculed and "Tesla Executive Admits That Self-Driving Is Going Nowhere Fast"
Links for the day
The Next Two Phases of Our Open Source Initiative (OSI) Series
Whatever people used to think about the OSI is no longer applicable and its current acronym is a misleading misnomer
Richard Stallman Has Barely Changed
Collecting "estate" "assets"? That's not "success" in the eyes of Dr. Stallman
Public Talk by Richard Stallman (RMS) Tomorrow
Still advertised
Gemini Links 25/05/2025: Konsole Layout Changes and Capitulation to Surveillance World
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 24, 2025
IRC logs for Saturday, May 24, 2025