<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Fight Club &#187; Data Theft</title>
	<atom:link href="http://www.securityfightclub.com/tag/data-theft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityfightclub.com</link>
	<description>Brought to you by Awareness Technologies</description>
	<lastBuildDate>Sat, 05 Jun 2010 04:08:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security by obscurity is not security at all</title>
		<link>http://www.securityfightclub.com/security-by-obscurity-is-not-security-at-all/</link>
		<comments>http://www.securityfightclub.com/security-by-obscurity-is-not-security-at-all/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 21:00:40 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Data Theft]]></category>
		<category><![CDATA[Employee Theft]]></category>

		<guid isPermaLink="false">http://www.securityfightclub.com/?p=39</guid>
		<description><![CDATA[Probably about the worst security plan you can ever use is security by obscurity.In case you aren&#8217;t familiar with the term, security by obscurity is when you plan on someone not knowing they have access to something keeping them from accessing it.
This is fairly common on file servers, and internal applications such as CRM software.  [...]]]></description>
			<content:encoded><![CDATA[<p>Probably about the worst security plan you can ever use is security by obscurity.<span id="more-39"></span>In case you aren&#8217;t familiar with the term, security by obscurity is when you plan on someone not knowing they have access to something keeping them from accessing it.</p>
<p>This is fairly common on file servers, and internal applications such as CRM software.  All to often the domain groups Everyone or Authenticated Users will be used to grant access to network resources that only a subset of users need access to.  Often this is done because &#8220;eventually more people will need access to the network resource, so well just open it to everyone now&#8221;.  But even if others need access to the network resource later this isn&#8217;t a very good reason for granting everyone access to the resource.</p>
<p>The group that requested the resource may assume that the resource is not open to everyone (how would they know otherwise) and put data in that folder or application which others within the company shouldn&#8217;t have access to.  Now all of a sudden you&#8217;ve got a security breach just waiting to happen.  The employees that aren&#8217;t supose to have access find out that they have access to it, and start looking around and there&#8217;s all this data that they shouldn&#8217;t be able to see.  It could be company financials, it could be HR data, it could be the executives vacation photos, or the crown jewel of data your customers personally identifiable information.</p>
<p>Assume that it&#8217;s customer data, that hasn&#8217;t been masked for one reason or another, and a less than scrupulous employee comes across the data.  Being the less than scrupulous employee that they are they take the data and find a buyer for it, and not all of a sudden your customers all have identity theft issues.  All because someone didn&#8217;t set the rights to some network resource correctly.  Talk about something that should have been easy to avoid but is going to cause a lot of pain.</p>
<p>Considering that anywhere from <a href="http://redtape.msnbc.com/2007/10/study-id-thieve.html" target="_blank">34%</a> to <a href="http://www.continuitycentral.com/news04572.html" target="_blank">70%</a> of data theft is by employees (depending on what report you read)<a href="http://consumerist.com/313952/36-of-identity-thieves-are-women" target="_blank"> </a>security by obscurity just seams like it isn&#8217;t the way to go.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityfightclub.com/security-by-obscurity-is-not-security-at-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
