Slashdot Log In
"Clear" Laptop Found, In the Same Locked Office
Posted by
kdawson
on Wednesday August 06, @08:06AM
from the never-mind dept.
from the never-mind dept.
jafo alerts us to an SFGate story reporting that the lost "Clear" Program laptop has turned up in the same office from which it was reported missing, but not in its previous location. "A preliminary investigation shows that the information was not compromised... The computer held names, addresses and birthdates for people applying to the program, as well as driver's license, passport and green card information. But, she said, the computer contained no Social Security numbers, credit card numbers, fingerprints, facial images or other biometric information... The information was encrypted on the server, but not on the laptop, although it should have been... However, it was protected by two levels of passwords." Reader jafo adds, "Pardon me if I have little confidence that an organization that loses a sensitive laptop for 9 days is able to tell if it was compromised."
Related Stories
[+]
"Clear" Air-Travel Pass Data Stolen From SFO 376 comments
Kozar_The_Malignant writes "A laptop containing the unencrypted security data for 33,000 travelers using the Clear system was stolen at San Francisco International Airport on July 26, according to CBS5 Television. The Clear system allows travelers who register and pay a $100.00 annual fee to speed through airport security by using a smart card at special kiosks in some airports. TSA has suspended new registrations in the system, which is run by a private contractor, Verified Identity Pass, Inc., a subsidiary of GE. The laptop was apparently stolen from a locked office at SFO. The company has now decided that it might be a good idea to encrypt the data in their systems. They are in the process of notifying customers that all of their personal data, including name, address, SSi number, passport number, date of birth, etc. has been compromised."
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

Sorry (Score:5, Funny)
... I borrowed it for the weekend to play WoW.
Reply to This
Re:Sorry (Score:5, Funny)
I'm amazed...how did you get through the two levels of passwords? You must be one hell of a master hacker!
Reply to This
Parent
Re:Sorry (Score:5, Funny)
Oh, that's easy. You see, we tape the passwords to the bottom of the PC. Those of us who work there know this, but no outside hacker would ever think to look there.
Plus the first password is 12345 and the second is ABCDEFG. Half the time, I don't even have to look at the sticky note.
Reply to This
Parent
Re:Sorry (Score:5, Informative)
Reply to This
Parent
Re:Sorry (Score:5, Informative)
Your (mysterious) reply prompted me to go to the far corners of the internet to learn that the proper word is "defuse". Words spoken like a true zen master - you don't get a clue unless you are already enlightened.
Thank you.
Reply to This
Parent
Re:Sorry (Score:5, Funny)
Only if you roll less than a 20 on 2d10.
God, I can't believe I remember crap like that from 20 years ago. :)
Reply to This
Parent
Re:Sorry (Score:5, Funny)
Is "20 years ago" code for "last night in moms basement"?
Reply to This
Parent
Two Levels of Passwords? (Score:5, Funny)
Those are, like, needed to remove the hard drive, right?
Reply to This
Re:Two Levels of Passwords? (Score:5, Funny)
Yes, the screws on the bottom of the laptop will ask you the boot and Windows passwords before they'll open.
Reply to This
Parent
Re:Two Levels of Passwords? (Score:5, Informative)
You don't even have to remove the HD. If the data is not encrypted you can boot from a USB key or CD and just copy the files.
Reply to This
Parent
Re:Two Levels of Passwords? (Score:5, Interesting)
Reminds me of one time where my boss was in the field at a customer's factory. He had his "notebook" in which he writes everything down. (a paper notebook, old school, not a laptop)
He left it on a table in the break room for a couple hours and forgot about it. Later, when he remembered, it was gone.
A few hours LATER, it was back, pretty much where he left it.
Luckily it didn't have any pricing or other such things in it, but it still wasn't a good thing.
But Karma is interesting, this same customer a few months later set us an email which happened to have a high level very confidential spreadsheet attached, accidentally. It contained the companies strategic plan for the coming months - peoples salaries, names, locations, PLANT CLOSURE PLANS, savings from plant closures, all that stuff. "ummm, yes, there was a spreadsheet that you
My point is, and I have one, encryption is fine but it is no guarantee against mistakes and/or stupidity.
Reply to This
Parent
no excuses (Score:5, Insightful)
Reply to This
I lost all confidence in Clear yesterday (Score:5, Interesting)
Reply to This
Two Passwords? (Score:5, Insightful)
So... what does that actually mean? I know that TFA is a media fluffed version washed for the general masses, but they could've mentioned that part at least. If one was the NT login, were the admins smart enough to disable the LM Hash? Still, booting it with a *NIX CD and blanking the SAM password for administrator is trivial. What could the second be? A BIOS password? Open it and pull the battery. Big deal.
Is there something I'm missing about this? Are there a (whopping!) two password scheme that could actually make something more secure then just booting it with something else and pulling data off?
Reply to This
Re:Two Passwords? (Score:5, Insightful)
Hmm. Standard internal investigation procedure: Wait until suspected bad actor has gone home, go into his office, remove hard drive from computer, use Ghost to create reasonably accurate copy of existing drive on another drive, replace duplicate drive in computer. Take your original drive back to your forensics lab, use your forensics software to make a forensically sound image of the original drive, lock the original drive in your safe in case a judge ever wants to see it, drill down through your forensic image at your leisure.
If you weren't especially interested in creating chain of custody documents, you'd just make a forensic image of the original drive and replace the original drive in the box. Then, absent tool marks or other evidence that the box had been opened, even a qualified forensic technician could swear under oath that there was no evidence that anybody had accessed the data on the box. And it wouldn't matter how many passwords you had on the box if it weren't encrypted...
Reply to This
Parent
Re:Two Passwords? (Score:5, Informative)
It could be a big deal. We do warranty and service work for HP hardware and in the past laptops have come in with BIOS passwords and we were not able to remove them. The password is actually part of the ATA protocol and so the disk is unusable without it, even in another machine. I think the only operation you can do is an ERASE. If you remove the battery then the BIOS forgets not only the BIOS password, but the disk password too.
I'm sure there are backdoors for some drives, but the customer in question in this case certainly wasn't willing to pay for us to investigate it so the data was as good as lost.
TPM, if implemented correctly, provides fairly good protection too. As does Microsofts BitLocker.
Physical access reduces security by a whole heap, but if things are done right then it doesn't reduce it to zero.
Of course as others have mentioned, an organisation that loses laptops like that probably isn't 'doing things right'...
Reply to This
Parent
"Clear" Laptop Found, In the Same Locked Office (Score:5, Funny)
That is why I prefer opaque laptops.
Reply to This
How Hard Did They Look? (Score:5, Insightful)
Reply to This
Correct response (Score:5, Insightful)
Whichever it was, the only information they had was that it was unaccounted for. It was actually a good response to automatically assume the worst case scenario and deal with the situation as if that had happened. If the worst case scenario was the case then at least it was dealt with as best it could be. If not then the only harm done is to them and not their customers.
So while losing it was very inept, their response afterwards was actually fairly responsible of them.
Reply to This
Clear is bullshit (Score:5, Interesting)
This whole 'Clear' thing is bullshit. Its a bad solution to a problem that should not exist in the first place.
If you buy the story that all the airport security that results in thousands standing around waiting to get to their gates is both necessary and effective then you must question any program that claims to pre-screen anyone because that just opens a window of opportunity between the pre-screen and the actual boarding of the flight in which the pre-screened person can be compromised in any number of ways.
It all comes back to the problem that there is no such thing as "the evil bit" - and any system which tries to make up for that by using some other combination of 'bits' as a proxy for the non-existent 'evil bit' is just a house of cards built on a non-existent foundation.
Even if you take Bruce Schneier's view that Clear is a good thing - not for the pre-screen, but because of the open-market approach to airport security which lets people pay more in exchange for a guaranteed short processing time - its still bullshit. That's because the rich and the powerful - the idiots who make the laws that created the TSA and their time/money wasting policies will be able to avoid having to suffer the consequences of their own actions. They can just pay a few hundred dollars more and never suffer the crap that they dumped on all the plebes.
Congress already exempts itself from too many of the laws its passes (no social security, they have their own program, no anti-discrimination in hiring laws on the hill, etc) they should not be able to get another free pass on suffering the effects of creating the TSA.
Reply to This
Quote of the Day (Score:5, Funny)
"[data was not encrypted] However, it was protected by two levels of passwords."
Baby, I'm sorry I cheated on you. But I was thinking of you while we did it.
Reply to This
We'll just put it back (Score:5, Insightful)
So, what we have here is starting to sound like: employee 'borrows' office computer for home use, manager raises alarm, news media panics, employee waits until dust settles a little to slip 'borrowed' property back into office.
Either that, or the identity thieves who who masterminded the scheme to steal that data were really slow.
Reply to This
Ask Slashdot (Score:5, Funny)
Dear Slashdot,
I've borrowed a laptop from my office to download a little . . . well, nevermind. But, the thing is that my manager went apeshit and the laptop turns out to have a lot of valuable data sitting on it. What should I do?
The FBI is searching the homes of all the employees, so I can't keep it. If I give it to a friend, some one will eventually tell and I'll get busted.
If I dump it or destroy it, they'll assume espionage and the investigation will go on for months and I'm sure to slip up eventually.
If I return it to quiet things down, I might provide them with forensic evidence they can link to me, not to mention maybe getting caught doing it.
Please help. If I lose my security clearance, I'll never get another job.
Reply to This
My guess... (Score:5, Funny)
It was never actually missing. They just couldn't find it in their own office.
Reply to This
It wasn't (Score:5, Insightful)
The truth is, they have no idea if it was compromised or not. All you'd need is an Ubuntu boot CD and you could read the data straight off the drive.
Next time they should use THREE levels of passwords. ;)
Reply to This
Parent