Bonum Certa Men Certa

Being Honest About Security Breaches

posted by Roy Schestowitz on Oct 08, 2023

Crochet Blanket In Progress

THE Web (or web) we weaved in nearly 37 years combined (adding the age of this site to its sister site's) is a very large web of nearly 300,000 page, which all reside on the same server now, served in static form without a visitor-accessible (as opposed to user-accessible) back end. Throughout these years there were no known security incidents and now we're extra secure because scripts are not reachable by visitors of the sites or their respective Gemini capsules.

The half dozen [1-6] or so stories below focus on security incidents (via DataBreaches), which are not only very very very costly [2] but involve elaborate cover-ups [1], implicating governments [3] and impacting companies profoundly [4]. They try to blame other nations [5] (not the holes) or downplay the issues [6] (blaming human error) though the net effect is the same.

During my (almost) 12 years at Sirius I witnessed several security breaches. As noted at the time in some videos and articles, those affected were not being notified. Even staff of Sirius was barely made aware at times. Sometimes clients were given a hint, but as far as I can tell, those further down the chain were left in the dark.

A culture of lousy managers in charge (liars without technical skills) is part of the problem. They only care how they're seen, not about people's safety or any sense of integrity.

Related/contextual items from the news:

  1. OrthoAlaska notifies 176,203 patients of breach. When was the breach?

    On October 12, 2022 — almost a full year ago — OrthoAlaska discovered unauthorized activity on their systems. On March 3, 2023, they learned that information on former employees was stored in the system. On April 3, 2023, they notified those affected.

    And that’s where things remained until September 22, 2023, when OrthoAlaska notified HHS that 176,203 patients were affected by a breach.

    Was this the same breach first discovered in October 2022? We do not know because there is no notice on OrthoAlaska’s website at this time.

  2. Data breach at MGM Resorts expected to cost casino giant $100 million

    The data breach last month that MGM Resorts is calling a cyberattack is expected to cost the casino giant more than $100 million, the Las Vegas-based company said.

    The incident, which was detected on Sept. 10, led to MGM shutting down some casino and hotel computer systems at properties across the U.S. in efforts to protect data.

  3. Citizen data leak: NID wing suspends access for suspected govt, pvt partner organisations

    The national identity registration wing of the Election Commission [of Bangladesh] has suspended data access to a number of its government and private partner organisations over suspicions of leaking citizens’ data online, while putting all of its 174 service recipient organisations under watch.

  4. Clorox Expects Double-Digit Sales Drop Following Cyberattack

    Household cleaning product giant Clorox said Wednesday that an August cyberattack had taken a big swipe out of the bleach maker’s sales and profits in the quarter that ended Sept. 30.

    The Oakland, California-based manufacturer maker expects organic sales to drop between 21% and 26% due to widespread disruption, order processing delays and product outages after the August cyberattack.

  5. North Korea Suspected in Massive Hack of DeFi Project Mixin (1)

    The massive breach of a decentralized finance project bears the hallmarks of a North Korean attack, according to a senior White House official.

    Mixin Network, which helps blockchains handle transactions more efficiently, said it had lost less than $150 million in a late-September attack. Originally the company estimated it lost $200 million but reduced it after a final inspection.

  6. NL Health Services Reveals Pediatrics Privacy Breach

    NL Health Services has another privacy breach on its hands.

    The news came quietly in a news release sent out just after 5:30 Friday evening.

    The breach is related to an email sent to the parents and guardians of 253 pediatric patients with diabetes.

    Officials say “the recipients of that email were inadvertently not blind copied,” allowing everyone on the list to see each other’s email addresses.

Other Recent Techrights' Posts

Freedom, Not Fame, is His Goal
pursuit of money can be not only tiring but also involve abandoning one's freedom
Getting Better After 20 Years
Exactly two months from now this site is turning 20
 
Further Transparency Problems at the EPO
The EPO was never meant to be profitable
Gemini Links 08/09/2026: "Everything Must Go", Announcing Perigee, and Presentations in a Browser
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 07, 2026
IRC logs for Monday, September 07, 2026
Alleged Manager at IBM Says "[t]here are likely to be a lot (and I meant, A LOT) of RAs before December."
"We’re getting pressure from above to put some team members on PIPs."
Links 07/09/2026: Amazon Cargo Plane Crash, .org/.net/.com Domains Considered Risky
Links for the day
Gemini Links 07/09/2026: Cheese, Text-based Life, and Icons in Swaybar
Links for the day
Links 07/09/2026: Slop Trashes Memory of Parton, Flock Surveillance Infuriates Everyone
Links for the day
EPO Hiding Cocainegate and Abandoning Transparency (Even Access to Very Basic Information is Denied)
The EPO isn't just becoming like a private for-profit corporation. It's also becoming more secretive.
Richard Stallman Has Resurrected Lost Updates
We didn't ask about it
SLAPP Censorship - Part 174 Out of 200: Cascading Scandals and a Path Towards Much-Needed, Long-Awaited Reform
Reform the UK's law, not "Reform UK"
EPO's Gema Requena Sempere (PD People) Contacted Regarding Children With Disabilities
In the coming week we may be in fruitful contact with some media regarding EPO scandals
Over at Tux Machines...
GNU/Linux news for the past day
Gemini Links 07/09/2026: Music Composition, Free Stuff, and Self-hosting Git Repos
Links for the day
IRC Proceedings: Sunday, September 06, 2026
IRC logs for Sunday, September 06, 2026
People Who Enforce the GPL Banned From Linux Foundation Board (After Bribes From Prolific GPL Violators), Now They're Banned From Giving Talks at Events
about the "LF" ('Linux' Foundation)
Gemini Links 06/09/2026: The Slop Plagiarism 'Holy War' (Hype, Scam, Scheme), Burning CD-Rs, and Hardcopy Mono
Links for the day
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part IV - Insufficient Resources in the Face of Distributed Denial of Service (DDoS) by Lawyers
it's about 120KG
OpenStreetMap is the Future, Dictatorship is the Past
OpenStreetMap helped us check maps for transport, various overlays with addresses, and there was 0% reliance on GAFAM or "Google" anything
Silent Layoffs, Cool-down, and Cool-off: How GAFAM and IBM Operate (the Law Doesn't Apply to Them)
Laws? What laws?
How Strikes at the European Patent Office Are Seen by Striking Staff in Berlin, Germany
We have some more EPO scandals to cover later this year and next year
Association for Computing Machinery Cites Techrights in Relation to GemText and Gemini Protocol
published yesterday, Open Access
Links 06/09/2026: More XBox Trouble (Microsoft Unrest, Many Silent Layoffs This Month), John Duffy as Next USPTO General Counsel
Links for the day
Gemini Links 06/09/2026: Avoiding 'Smart' 'Phones' and Setting up Gemini for the First Time
Links for the day
Links 06/09/2026: Sabotage by Slop and "What Happens If 'Open' 'AI' Dies?"
Links for the day
How Back Doors Became the 'Normal' or 'Norm'
"We also allowed a lethal monoculture to fester"
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part III - The SRA is Vastly Worse Than Brits Realise, We Have a "Wild West" in London
In the next part we'll begin looking at correspondence with the SRA
SRA and Manslaughter: How the SRA Contributed to Agony in Proprietary Software Scandals With Clear Misuse of "Without Prejudice"
Trying to prevent the public from finding out the criminal stuff that went on, resulting in many deaths
Canonical (or Ubuntu) Rejecting IRC Isn't the Widespread Trend
Internet Relay Chat (IRC) adoption still growing by some yardsticks
SLAPP Censorship - Part 173 Out of 200: Two Years
It was exactly 2 years ago that we filed lawsuits against Garrett
Linux of America
We could not help but notice GNU/Linux in North America yesterday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 05, 2026
IRC logs for Saturday, September 05, 2026
Gemini Links 06/09/2026: Internet Limiting (Limited Time Allotted) and Solar MiniServer
Links for the day
Eight Months of Strikes in EPO, Organised by the Staff Union (SUEPO) Also in Berlin
In Berlin, only one member of staff voted against the action plan