<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; Data Encryption</title>
	<atom:link href="http://www.endpoint-security.info/category/encryption/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:55:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Lost thumb drive leads to potential data breach</title>
		<link>http://www.endpoint-security.info/2010/07/29/lost-thumb-drive-security-breach/</link>
		<comments>http://www.endpoint-security.info/2010/07/29/lost-thumb-drive-security-breach/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 19:55:21 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[thumb drive]]></category>
		<category><![CDATA[USB]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=472</guid>
		<description><![CDATA[A thumb drive containing personal data of current and past graduate medical education residents and fellows at Cooper University Hospital has recently gone missing. Lost around July 8th, the incident has been reported to the proper authorites a few days later who are now looking into the potential security breach only two weeks later. According [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F07%2F29%2Flost-thumb-drive-security-breach%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F07%2F29%2Flost-thumb-drive-security-breach%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>A thumb drive containing personal data of current and past graduate medical education residents and fellows at Cooper University Hospital has recently gone missing. Lost around July 8th, the incident has been reported to the proper authorites a few days later who are now looking into the potential security breach only two weeks later.</p>
<p><a href="http://abclocal.go.com/wpvi/story?section=news/local&amp;id=7578794" target="_blank">According to hospital sources</a>, the lost data includes Social Security numbers, addresses, and phone numbers. As it always happens in such cases, the data was not in anyway encrypted or protected.</p>
<p>The University later released the following statement:</p>
<p><span id="more-472"></span><br />
<a href="http://www.endpointprotector.com/lp/endpoint_protector_general_EN.php"><img title="Endpoint Security and Device Control Solutions with low TCO and great ROI." src="/wp-content/uploads/banners/banner-galactic-red-epp.jpg" border="0" alt="Endpoint Security and Device Control Solutions with low TCO and great ROI." width="500" height="100" align="middle" /></a></p>
<blockquote><p>&#8220;Cooper University Hospital is investigating the circumstances surrounding a missing thumb drive. The thumb drive contained information with personal data about graduate medical education residents and fellows for the current and prior academic years. We have advised the residents and fellows who were advised to contact their local police. No other employee information was compromised. Further, No patient information or records were compromised. The incident was reported to the New Jersey State Police Cyber Crimes Unit on Friday, July 23 as per the state notification procedure. The hospital is conducting a thorough investigation and has initiated an aggressive plan to protect any personnel who could be affected by this potential security breach.&#8221;</p></blockquote>
<p>As of yet there are no information on the number of individuals affected by the breach.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/02/22/breached-server-puts-170000-at-risk/" rel="bookmark" class="crp_title">Breached server puts 170,000 at risk</a></li><li><a href="http://www.endpoint-security.info/2010/06/30/medical-diagnoses-of-130000-people-lost/" rel="bookmark" class="crp_title">Medical diagnoses of 130,000 people lost</a></li><li><a href="http://www.endpoint-security.info/2009/05/25/1-tb-of-data-on-the-clinton-administration-gone-missing/" rel="bookmark" class="crp_title">1 TB of data on the Clinton Administration gone missing</a></li><li><a href="http://www.endpoint-security.info/2008/06/05/the-army-investigates-breach-exposing-1000-to-identity-theft/" rel="bookmark" class="crp_title">The Army Investigates Breach Exposing 1,000 to Identity Theft</a></li><li><a href="http://www.endpoint-security.info/2008/09/29/playing-hide-and-seek-with-private-records/" rel="bookmark" class="crp_title">Playing Hide and Seek with Private Records</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2010/07/29/lost-thumb-drive-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK: Information Commissioner&#8217;s Office reports that the NHS has disclosed 305 security losses, as the amount of breaches tops 1,000</title>
		<link>http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/</link>
		<comments>http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/#comments</comments>
		<pubDate>Sat, 29 May 2010 09:40:14 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[security breaches]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=439</guid>
		<description><![CDATA[Over more than 1000 data losses for the NHS. This is a new record. Of which alone 307 were as a result of stolen data or hardware and 233 due to lost data or hardware. The Information Commissioner&#8217;s Office has warned organisations that they need to minimise the risk of mistakes, as the amount of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F05%2F29%2Fuk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F05%2F29%2Fuk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<blockquote><p>Over more than 1000 data losses for the NHS. This is a new record.<br />
Of which alone 307 were as a result of stolen data or hardware and 233 due to lost data or hardware.</p></blockquote>
<p>The Information Commissioner&#8217;s Office has warned organisations that they need to minimise the risk of mistakes, as the amount of losses reported tops 1,000.</p>
<p>The ICO claimed that staff need simple procedures on how to handle personal information with appropriate training to ensure the importance of securing it is fully understood. It also said that it is essential that the protection of people&#8217;s personal information is part of organisations&#8217; culture and DNA.</p>
<p>An ICO report revealed that 254 breaches were as a result of information being disclosed in error, 307 were as a result of stolen data or hardware and 233 due to lost data or hardware.</p>
<p>A further 83 were due to a technical or procedural failure and 59 were lost in transit. A breakdown of companies revealed 305 incidents were recorded by the NHS, 288 in the private sector and 132 by local government. Only 81 incidents were the result of central government.</p>
<p>David Smith, deputy commissioner at the ICO, said: “We all know that mistakes can happen but, the fact is that human error is behind a high proportion of security breaches that have been reported to us. Extra vigilance is required so that people&#8217;s personal information does not end up in the wrong hands.</p>
<p>“Organisations should have clear security and disclosure procedures that staff can understand, properly implement these and ensure that they are being followed by staff. Staff must be adequately trained not just in the value of personal information, but in how to protect it.</p>
<p>“We are keen to work with organisations to prevent breaches happening in the first place and to help ensure that things are put right when they do go wrong.”</p>
<p>Source and full article: <a href="http://www.scmagazineuk.com/ico-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/article/171205/">SC Magazine</a></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/02/25/uk-companies-pay-47-for-every-private-record-lost/" rel="bookmark" class="crp_title">UK Companies Pay £47 for Every Lost Private Record</a></li><li><a href="http://www.endpoint-security.info/2008/09/06/2008-sky-is-the-limit-for-us-data-breaches/" rel="bookmark" class="crp_title">2008: Sky is the Limit for US Data Breaches</a></li><li><a href="http://www.endpoint-security.info/2008/12/01/uk-governement-says-no-to-data-breach-notification-law/" rel="bookmark" class="crp_title">UK Governement says no to data breach notification law</a></li><li><a href="http://www.endpoint-security.info/2008/09/11/private-data-of-5000-lost-along-with-hard-drive/" rel="bookmark" class="crp_title">Private Data of 5,000 Lost along with Hard Drive</a></li><li><a href="http://www.endpoint-security.info/2008/11/13/self-encrypting-laptop-from-dell/" rel="bookmark" class="crp_title">Self-encrypting laptop from Dell</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Endpoint Security: Playing it smart</title>
		<link>http://www.endpoint-security.info/2010/02/02/endpoint-security-playing-it-smart/</link>
		<comments>http://www.endpoint-security.info/2010/02/02/endpoint-security-playing-it-smart/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 11:16:46 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security experts]]></category>
		<category><![CDATA[security goals]]></category>
		<category><![CDATA[security purpose]]></category>
		<category><![CDATA[smart security]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=373</guid>
		<description><![CDATA[There have been so many news lately about stolen hardware with important data, server hacks, security threats embedded in any new gadget that gets launched (like the iPad), that it could make anyone think all security companies and experts care about is pointing warning fingers towards anything cool someone would think of using. With all [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F02%2F02%2Fendpoint-security-playing-it-smart%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2010%2F02%2F02%2Fendpoint-security-playing-it-smart%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>There have been so many news lately about stolen hardware with important data, server hacks, security threats embedded in any new gadget that gets launched (like the iPad), that it could make anyone think all security companies and experts care about is pointing warning fingers towards anything cool someone would think of using. With all these stories, some of which we&#8217;ve shared on our Twitter stream, security becomes this two-headed monster that&#8217;s there to kill the fun in technology.</p>
<p>But that&#8217;s far from being true! Effective security is about playing it smart: seeing what could happen and preventing it, while allowing people to still have their share of fun. We tend to forget that, but that is the purpose to security in general and endpoint and data security in particular. iPods, iPads, colorful USB sticks, netbooks, smartphones, cameras, you should use it all as long as they help you work better and make your life easier. You should use them at home, in the office, while commuting, the idea is to know what threats they pose and how to prevent them.</p>
<p style="text-align: center;"><a href="http://view.picapp.com/default.aspx?term=gadget&amp;iid=7292879" target="_blank"><img class="aligncenter" src="http://cdn.picapp.com/ftp/Images/6/8/6/3/High_angle_view_89a9.jpg?adImageId=9824631&amp;imageId=7292879" border="0" alt="High angle view of two businesswomen with two businessmen in a conference room" width="380" height="253" /></a><script src="http://cdn.pis.picapp.com/IamProd/PicAppPIS/JavaScript/PisV4.js" type="text/javascript"></script></p>
<p>Security experts to concentrate on everything bad that&#8217;s happening. The reason is simple, if companies and individuals don&#8217;t fear the consequences, they tend to ignore the risks. The all present mantra &#8220;It can&#8217;t happen to me&#8221; is their shield against all attacks and breaches. So there is a reason and a purpose behind showing off all the bad stuff, but that should never cast a shadow over the real goal of security: <strong>making your life safer and better</strong>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2009/11/25/protecting-a-companys-confidential-data-can-make-people-happier/" rel="bookmark" class="crp_title">Protecting a company&#8217;s confidential data can make people happier</a></li><li><a href="http://www.endpoint-security.info/2009/10/28/call-centers-breach-data-security/" rel="bookmark" class="crp_title">Don’t trust call centers with your private details!</a></li><li><a href="http://www.endpoint-security.info/2009/12/14/french-authorities-use-stolen-data/" rel="bookmark" class="crp_title">Everyone loves stolen data, even the French authorities!</a></li><li><a href="http://www.endpoint-security.info/2009/11/13/corporate-data-breaches-raise-the-risk-of-consumer-id-theft/" rel="bookmark" class="crp_title">Corporate data breaches raise the risk of consumer ID theft</a></li><li><a href="http://www.endpoint-security.info/2009/08/11/how-to-prevent-social-networking-threats-on-private-data/" rel="bookmark" class="crp_title">How to Prevent Social Networking Threats on Private Data?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2010/02/02/endpoint-security-playing-it-smart/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How to control device use the easiest way possible?</title>
		<link>http://www.endpoint-security.info/2009/07/10/how-to-control-device-use-the-easiest-way-possible/</link>
		<comments>http://www.endpoint-security.info/2009/07/10/how-to-control-device-use-the-easiest-way-possible/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 09:54:36 +0000</pubDate>
		<dc:creator>Robert</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Device Control]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[My Endpoint Protector]]></category>
		<category><![CDATA[MyEPP]]></category>
		<category><![CDATA[SaaS]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=237</guid>
		<description><![CDATA[Take it to the could. See how it works explaind in plain english. Device Control and DLP taken to the cloud to help you reduce cost and deploy much faster. LinkedTubeDevice Control and DLP can with My Endpoint Protector be deployed in minutes at a fraction of costs from other solutions. Related Posts:Data Leakage and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F07%2F10%2Fhow-to-control-device-use-the-easiest-way-possible%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F07%2F10%2Fhow-to-control-device-use-the-easiest-way-possible%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Take it to the could. See how it works explaind in plain english.<br />
Device Control and DLP taken to the cloud to help you reduce cost and deploy much faster. </p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" type="application/x-shockwave-flash" width="400px" height="325px"><param name="movie" value="http://www.linkedtube.com/static/flash/player.swf?sum=Control%20devices,%20stop%20data%20theft,%20loss&#038;btn=www.EndpointProtector.com&#038;txt=Try%20it%20today&#038;vis=always&#038;url=http%3A%2F%2Fwww.EndpointProtector.com&#038;vid=OG4stgirGTQ"/><param name="quality" value="high" /><param name="menu" value="false" /><embed src="http://www.linkedtube.com/static/flash/player.swf?sum=Control%20portable%20device%20use%20and%20stop%20data%20theft%20and%20data%20loss&#038;btn=www.EndpointProtector.com&#038;txt=Try%20My%20Endpoint%20Protector%20today&#038;vis=always&#038;url=http%3A%2F%2Fwww.EndpointProtector.com&#038;vid=OG4stgirGTQ" width="480px" height="325px" quality="high" menu="false" pluginspage="http://www.macromedia.com/go/getflashplayer" type="application/x-shockwave-flash"><noembed><a href="http://www.linkedtube.com/OG4stgirGTQac78a60c69af7575b9b51a553888ae15.htm">LinkedTube</a></noembed></embed><blockquote>Device Control and DLP can with My Endpoint Protector be deployed in minutes at a fraction of costs from other solutions.</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2009/06/26/data-leakage-and-endpoint-security-from-a-sexy-perspective/" rel="bookmark" class="crp_title">Data Leakage and Endpoint Security from a Sexy Perspective</a></li><li><a href="http://www.endpoint-security.info/2010/05/06/video-controlling-device-use-in-your-office-is-a-must-to-protect-your-data/" rel="bookmark" class="crp_title">Video: Controlling Device use in your office is a must to protect your data</a></li><li><a href="http://www.endpoint-security.info/2009/06/13/cososys-on-the-obama-speech-at-provision-security-days/" rel="bookmark" class="crp_title">CoSoSys on the Obama Speech at Provision Security Days</a></li><li><a href="http://www.endpoint-security.info/2010/03/18/license-to-hope-protect-your-data-and-help-marginalized-children/" rel="bookmark" class="crp_title">License to hope &#8211; Protect your data and help marginalized children</a></li><li><a href="http://www.endpoint-security.info/2009/10/15/device-control-solution-for-windows-7-and-snow-leopard/" rel="bookmark" class="crp_title">The first fully compatible Device Control solution for Windows 7 and Mac OS X Snow Leopard</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/07/10/how-to-control-device-use-the-easiest-way-possible/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Months later, consequensces knocking on breached door</title>
		<link>http://www.endpoint-security.info/2009/04/01/months-later-consequensced-knocking-on-breached-door/</link>
		<comments>http://www.endpoint-security.info/2009/04/01/months-later-consequensced-knocking-on-breached-door/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 10:13:39 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Protection Act]]></category>
		<category><![CDATA[data protection law]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[security breach consequences]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=195</guid>
		<description><![CDATA[One might think that if several months have passed since an embarrsing data breach and nothing has happened, it&#8217;s all cool. One can relax, mind their own business and forget all about security. That&#8217;s not the case if we&#8217;re talking UK health authority. Namely, London-based Camden Primary Care Trust. They thought, sometime last August, that [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F04%2F01%2Fmonths-later-consequensced-knocking-on-breached-door%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F04%2F01%2Fmonths-later-consequensced-knocking-on-breached-door%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>One might think that if several months have passed since an embarrsing data breach and nothing has happened, it&#8217;s all cool. One can relax, mind their own business and forget all about security.</p>
<p>That&#8217;s not the case if we&#8217;re talking UK health authority. Namely, London-based Camden Primary Care Trust. They thought, sometime last August, that dumping PCs containing 2,500 patients&#8217; names, addresses and medical histories beside a skip inside the grounds of St Pancras Hospital was a good idea. They might reconsider now, as the Information Commissioner&#8217;s Office <a title="official enforcement notice form ICO" href="http://www.ico.gov.uk/upload/documents/pressreleases/2009/camden_pct_enforcement_notice_230309.pdf" target="_blank">has given Camden Primary Care Trust until the end of the month to improve security</a>, consequence of its breaching the Data Protection Act.</p>
<p>According to <a title="Data Breach Notice for Health Authority" href="http://www.theregister.co.uk/2009/03/24/hospital_data_breach_notice/" target="_blank">the Register</a>, &#8220;data on the obsolete computers was left unencrypted. The machines were subsequently swiped without authorisation and never recovered&#8221;. Given such gross negligence and obvious proof of being completely irresponsible, I cannot help being extremely happy they are forced to do something about their security!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2009/08/24/ftc-issues-final-rules-on-health-care-breach-disclosure/" rel="bookmark" class="crp_title">FTC Issues Final Rules on Health Care Breach Disclosure</a></li><li><a href="http://www.endpoint-security.info/2010/06/30/medical-diagnoses-of-130000-people-lost/" rel="bookmark" class="crp_title">Medical diagnoses of 130,000 people lost</a></li><li><a href="http://www.endpoint-security.info/2008/06/30/stockbrokers-get-fine-for-poor-security/" rel="bookmark" class="crp_title">Stockbrokers Get Fine for Poor Security</a></li><li><a href="http://www.endpoint-security.info/2009/09/21/new-us-healthcare-rules-criticized-by-encryption-experts/" rel="bookmark" class="crp_title">New US healthcare rules criticized by encryption experts</a></li><li><a href="http://www.endpoint-security.info/2008/05/04/88000-patients-exposed-to-identity-theft/" rel="bookmark" class="crp_title">88,000 Patients Exposed to Identity Theft</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/04/01/months-later-consequensced-knocking-on-breached-door/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Air France tries out biometric boarding cards</title>
		<link>http://www.endpoint-security.info/2009/03/30/air-france-tries-out-biometric-boarding-cards/</link>
		<comments>http://www.endpoint-security.info/2009/03/30/air-france-tries-out-biometric-boarding-cards/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 05:06:56 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Air France]]></category>
		<category><![CDATA[biometric boarding cards]]></category>
		<category><![CDATA[biometric security]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[fingerprint]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=194</guid>
		<description><![CDATA[Biometric security is on the rise, as new possibilities to use it come into shape, from entrance access and USB card security to the lastest trick: biometric boarding cards, a new usage thought up by Air France. What are they testing? RFID-equipped smartcards which store passenger fingerprints to allow automated boarding, according to the Register. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F03%2F30%2Fair-france-tries-out-biometric-boarding-cards%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F03%2F30%2Fair-france-tries-out-biometric-boarding-cards%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Biometric security is on the rise, as new possibilities to use it come into shape, from entrance access and USB card security to the lastest trick: biometric boarding cards, a new usage thought up by Air France. What are they testing? RFID-equipped smartcards which store passenger fingerprints to allow automated boarding, according to <a title="Fingerprind Cards Trials at Air France" href="http://www.theregister.co.uk/2009/03/19/france_fingerprint_cards/" target="_blank">the Register</a>.</p>
<p>How does the card do the trick? It is said to contain an encrypted version of forefinger and thumb prints for each passenger. It would be used dedicated gate, which checks the card, compares it to the passenger&#8217;s finger or thumb print and if it matches, it opens the gate. No clerk, no time wasted, all simple and easy.</p>
<p>This little baby can be re-used up to 500 times. It also has a barcode inserted into it, containing all the information a traditional paper boarding pass. Said passenger can check in online, insert their card into a dedicated machine withing the airport, get the flight info and seat number printed onto the card. According to Air France, getting such a card takes only a couple of minutes.The also claim once the information is transmitted to the card, it isn&#8217;t stored elsewhere, so your data is safe.</p>
<p>If you&#8217;re as impressed as I am and want a similar gadget, you have until the end of the year to become and AF frequent flier to be eligible for one. For a first hand experience, you&#8217;ll have to fly between Paris and Amsterdam. I think I&#8217;ll wait until they extend the program though!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/05/08/californian-supermarket-shoppers-victims-of-identity-theft/" rel="bookmark" class="crp_title">Californian Supermarket Shoppers, Victims of Identity Theft</a></li><li><a href="http://www.endpoint-security.info/2008/09/26/tjx-effects-forever-21-payment-card-breach/" rel="bookmark" class="crp_title">TJX Effects: Forever 21 Payment Card Breach</a></li><li><a href="http://www.endpoint-security.info/2010/05/28/edmonton-credit-card-fraud/" rel="bookmark" class="crp_title">Edmonton travel agency investigated for credit card fraud</a></li><li><a href="http://www.endpoint-security.info/2008/06/24/sensitive-data-of-healthcare-and-airline-companies-found-in-argentina-and-malaysia/" rel="bookmark" class="crp_title">Sensitive Data of Healthcare and Airline Companies found in Argentina and Malaysia</a></li><li><a href="http://www.endpoint-security.info/2008/04/27/credit-cart-info-of-wisebuy-customers-stolen/" rel="bookmark" class="crp_title">Credit Card Info of WiseBuy Customers Stolen</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/03/30/air-france-tries-out-biometric-boarding-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US 2008 data breach growth blamed on insiders</title>
		<link>http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/</link>
		<comments>http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 07:48:52 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[ITRC]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=173</guid>
		<description><![CDATA[Apart from the economic downturn, the year 2008 brought another critical issue to US companies: a nearly 50% increase in data breaches, leading them to lose considerably more sensitive data. According to an Identity Theft Resources Center (ITRC) study quoted by the Register, last year 35 million data records were exposed in 656 admitted incidents, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F01%2F19%2Fus-2008-data-breach-growth-blamed-on-insiders%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F01%2F19%2Fus-2008-data-breach-growth-blamed-on-insiders%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Apart from the economic downturn, the year 2008 brought another critical issue to US companies: a nearly 50% increase in data breaches, leading them to lose considerably more sensitive data. According to an Identity Theft Resources Center (ITRC) study quoted <a title="US data breach survey" href="http://www.theregister.co.uk/2009/01/08/us_data_breach_survey/" target="_blank">by the Register</a>, last year 35 million data records were exposed in 656 admitted incidents, amounting to a 47% increase compared to the 446 data loss incidents reported in 2007.</p>
<p>ITRC also states that about 40% of security breaches are never reported,  thus the true number of exposed confidential records is most likely to be far greater than the study suggests.</p>
<blockquote><p>Computer malware, hacking, and insider theft accounted for 29.6 per cent of recorded breaches, where the root cause of the attack is known. One in six breaches (15.7 per cent) were blamed to insider theft, a figure that&#8217;s more then doubled between 2007 and 2008.</p></blockquote>
<p>The good news is that as education regarding data loss prevention reached more companies, the number of incidents caused by human errors has decreased. But that is a very small light in a highly untrained corporate world, where most reported data breaches  involved data unprotected by either encryption or the simplest password protection. Let&#8217;s hope for a better protected 2009!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/07/07/insider-attacks-double-in-the-first-half-of-2008/" rel="bookmark" class="crp_title">Insider Attacks Double in the First Half of 2008</a></li><li><a href="http://www.endpoint-security.info/2008/09/06/2008-sky-is-the-limit-for-us-data-breaches/" rel="bookmark" class="crp_title">2008: Sky is the Limit for US Data Breaches</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li><li><a href="http://www.endpoint-security.info/2008/04/28/expensive-security-keeps-breaches-away/" rel="bookmark" class="crp_title">Expensive Security Keeps Breaches Away</a></li><li><a href="http://www.endpoint-security.info/2009/02/09/us-data-breach-cost-up-response-cost-down/" rel="bookmark" class="crp_title">US Data Breach Cost Up, Response Cost Down</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Self-encrypting laptop from Dell</title>
		<link>http://www.endpoint-security.info/2008/11/13/self-encrypting-laptop-from-dell/</link>
		<comments>http://www.endpoint-security.info/2008/11/13/self-encrypting-laptop-from-dell/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 10:55:10 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[private data]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=170</guid>
		<description><![CDATA[One of the most common causes of security breaches is stolen hardware. And I&#8217;m sure you&#8217;ve all heard of the thousands and thousands of laptops stolen in airports, from parking lots and other public places. And as most companies fail to implement a comprehensive endpoint security solution, a stolen laptop means trouble. For the end [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F11%2F13%2Fself-encrypting-laptop-from-dell%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F11%2F13%2Fself-encrypting-laptop-from-dell%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>One of the most common causes of security breaches is <a title="Stolen Harware, common cause for data breaches" href="http://www.endpoint-security.info/2008/04/12/stolen-hardware-most-common-cause-for-data-breaches/" target="_blank">stolen hardware</a>. And I&#8217;m sure you&#8217;ve all heard of the thousands and thousands of laptops stolen in airports, from parking lots and other public places. And as most companies fail to implement a comprehensive endpoint security solution, a stolen laptop means trouble. For the end users, a laptop sometimes stores most of their documents, personal and business, memories from trips and other important events and everything that is private and dear to them. Picturing everything lost to a stranger&#8217;s hand is hard to cope it.</p>
<p>Dell states there&#8217;s a new way to prevent such bad things from happening: <a title="Dell Encrypted Laptop" href="http://www.theregister.co.uk/2008/11/10/dell_self_encrypting_laptop/" target="_blank">a self-encrypting laptop</a>. Your data is still lost, but at least no one can acess it. The drives with self-encryption features are produced by Seagate and embedded in the new Dell product. And apparently, the Seagate hardware will soon be shipped by IBM and LSI as well. Let&#8217;s hope no one breaks the encryption system!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/03/08/stolen-laptop-puts-12500-patients-data-at-risk/" rel="bookmark" class="crp_title">Stolen laptop puts 12,500 patients&#8217; data at risk</a></li><li><a href="http://www.endpoint-security.info/2008/02/24/laptop-with-patient-data-stolen-from-nhs-hospital/" rel="bookmark" class="crp_title">Laptop with Patient Data Stolen from NHS Hospital</a></li><li><a href="http://www.endpoint-security.info/2008/07/08/daily-mail-loses-laptop-with-staffs-private-info/" rel="bookmark" class="crp_title">Daily Mail Loses Laptop With Staff&#8217;s Private Info</a></li><li><a href="http://www.endpoint-security.info/2008/10/20/deloitte-lost-hundreds-of-thousands-of-pension-details/" rel="bookmark" class="crp_title">Deloitte Lost Hundreds of Thousands of Pension Details</a></li><li><a href="http://www.endpoint-security.info/2008/03/26/stolen-agilent-laptop-with-records-of-51000-employees/" rel="bookmark" class="crp_title">Stolen Agilent Laptop with Records of 51,000 Employees</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/11/13/self-encrypting-laptop-from-dell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Deloitte Lost Hundreds of Thousands of Pension Details</title>
		<link>http://www.endpoint-security.info/2008/10/20/deloitte-lost-hundreds-of-thousands-of-pension-details/</link>
		<comments>http://www.endpoint-security.info/2008/10/20/deloitte-lost-hundreds-of-thousands-of-pension-details/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 07:33:31 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[lost hardware]]></category>
		<category><![CDATA[private records]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=162</guid>
		<description><![CDATA[Deloitte has recently admitted it had lost a laptop containing pension details on hundreds of thousands of individuals. What is different though is that finally this laptop contained encrypted information, was password-protected and no misuse of the stored information has been discovered. While losing laptops is not something to take lightly, I am happy to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F10%2F20%2Fdeloitte-lost-hundreds-of-thousands-of-pension-details%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F10%2F20%2Fdeloitte-lost-hundreds-of-thousands-of-pension-details%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">Deloitte has recently admitted it had lost a laptop containing pension details on hundreds of thousands of individuals.  What is different though is that finally this laptop contained encrypted information, was password-protected and no misuse of the stored information has been discovered. While losing laptops is not something to take lightly, I am happy to report those having it won’t be able to easily access the stored information.</p>
<p style="text-align: justify;">So what did the laptop contain? <a title="Register Article" href="http://www.theregister.co.uk/2008/10/13/deloitte_data_loss_vodafone/" target="_blank">According to the Register</a>, 150,000 railway workers&#8217; details, details on all UK Vodafone staff with pensions and as well as records of other unnamed pension funds were stored on the said laptop. No addresses or bank information though. How it was stolen? From a handbag of a Deloitte employee. Vodafone Staffers, as well as the railway workers have received letters letting them know what has happened soon after the theft. We’re now looking forward to see where the “thorough investigation” takes Deloitte.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/07/31/laptop-with-anheuser-busch-employees-private-data-stolen/" rel="bookmark" class="crp_title">Laptop With Anheuser-Busch Employees&#8217; Private Data Stolen</a></li><li><a href="http://www.endpoint-security.info/2008/08/12/stolen-flash-drive-with-personal-info-on-2600-delphi-workers/" rel="bookmark" class="crp_title">Stolen Flash Drive with Personal Info on 2,600 Delphi Workers</a></li><li><a href="http://www.endpoint-security.info/2008/07/29/slim-risks-yet-hcc-still-warns-of-lost-data/" rel="bookmark" class="crp_title">Slim Risks, yet HCC Still Warns of Lost Data</a></li><li><a href="http://www.endpoint-security.info/2008/07/08/daily-mail-loses-laptop-with-staffs-private-info/" rel="bookmark" class="crp_title">Daily Mail Loses Laptop With Staff&#8217;s Private Info</a></li><li><a href="http://www.endpoint-security.info/2008/09/26/tjx-effects-forever-21-payment-card-breach/" rel="bookmark" class="crp_title">TJX Effects: Forever 21 Payment Card Breach</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/10/20/deloitte-lost-hundreds-of-thousands-of-pension-details/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Federal Agencies Welcome Data Theft</title>
		<link>http://www.endpoint-security.info/2008/07/30/us-federal-agencies-welcome-data-theft/</link>
		<comments>http://www.endpoint-security.info/2008/07/30/us-federal-agencies-welcome-data-theft/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 07:38:51 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Laws & Standards]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[federal agencies]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[US]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=140</guid>
		<description><![CDATA[After 15 months of investigation into 24 major US federal agencies, the Government Accountability Office (GAO) has release a report showing that key US Departments still don&#8217;t take data security seriously. Given the list of breaches we&#8217;ve been covering affecting everyone from colleges and hospitals to the US Army, I&#8217;d say it&#8217;s high time they [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F07%2F30%2Fus-federal-agencies-welcome-data-theft%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F07%2F30%2Fus-federal-agencies-welcome-data-theft%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">After 15 months of investigation into 24 major US federal agencies, the Government Accountability Office (GAO) has release a <a href="http://www.gao.gov/new.items/d08525.pdf">report</a> showing that key US Departments still don&#8217;t take data security seriously. Given the list of breaches we&#8217;ve been covering affecting everyone from colleges and hospitals to <a title="US Army Security Breach" href="http://www.endpoint-security.info/2008/07/21/brand-new-security-breach-reported-by-the-us-army/" target="_blank">the US Army</a>, I&#8217;d say it&#8217;s high time they started!</p>
<p style="text-align: justify;">According to the report quoted by <a title="Vnunet Article" href="http://www.vnunet.com/vnunet/news/2222786/government-failing-digital-encryption" target="_blank">Vnunet.com</a>, around 70 percent of laptops and handhelds used by agency failed to comply with Office of Management and Budget (OMB)  rules and didn’t use encryption making the data available to anyone intending to steal it. The OMB rules are not even close to being new, as they decided all federal laptops should be encrypted back in 2007.</p>
<blockquote style="text-align: justify;"><p>“We are recommending that OMB clarify governmentwide encryption policy to address agency efforts to plan for and implement encryption technologies,” said the report.</p>
<p>“We are also making recommendations to selected agencies to properly install and configure FIPS-compliant encryption technologies, to develop policies and procedures to manage encryption, and to provide encryption training to personnel.”</p></blockquote>
<p style="text-align: justify;">Other practices of extremely low levels of security (or should we say non-existent security) include Nasa  employees refusing to deploy encryption software on their laptops and members of the Department of Education who weren’t told encryption software was installed so they of course weren’t using it. From what I know if they&#8217;re using Windows, whenever a new program is installed, you have a quite nagging message in your Startup Menu. How patient must one be to simply ignore it over and over again <img src='http://www.endpoint-security.info/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/08/14/bbc-admits-loss-of-childrens-data-rejects-any-responsibility/" rel="bookmark" class="crp_title">BBC Admits Loss of Children&#8217;s Data, Rejects Any Responsibility</a></li><li><a href="http://www.endpoint-security.info/2008/02/24/laptop-with-patient-data-stolen-from-nhs-hospital/" rel="bookmark" class="crp_title">Laptop with Patient Data Stolen from NHS Hospital</a></li><li><a href="http://www.endpoint-security.info/2009/07/28/us-federal-agencies-flunk-the-security-standards-exam/" rel="bookmark" class="crp_title">US Federal Agencies Flunk the Security Standards Exam</a></li><li><a href="http://www.endpoint-security.info/2008/09/06/2008-sky-is-the-limit-for-us-data-breaches/" rel="bookmark" class="crp_title">2008: Sky is the Limit for US Data Breaches</a></li><li><a href="http://www.endpoint-security.info/2009/09/21/new-us-healthcare-rules-criticized-by-encryption-experts/" rel="bookmark" class="crp_title">New US healthcare rules criticized by encryption experts</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/07/30/us-federal-agencies-welcome-data-theft/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
