Monday, October 12, 2015

Indiana University- Week Seven

Since I started this blog as part of an assignment for my Master's in Cybersecurity, I wanted to take a look at a data breach involving a University.  These aren't that prevalent, which is a good thing, but it leaves me curious why more colleges aren't hacked.  You have a large number of college students, most of them somewhere between frazzled and partying, and they've handed over an enormous amount of personal information to the University.  I hope that it's because in academic settings, more educated people are paying better attention to the data security, but I don't know if that's accurate or not.  Whatever the reason, it's a good thing more University hacks and breaches haven't occurred.

In 2014, about 146,000 students at Indiana University had their information, including social security numbers, exposed.  This wasn't a hack, but it was a data breach.  Here's the difference: a hack is someone trying to access information that's specifically been made unavailable to them.  It's the online equivalent of breaking and entering.  A data breach can certainly be a hack, but it's larger than that.  It includes accidental releases of info.  Here, the data was exposed because it was stored on an unencrypted area.  Search engines gathered the information (because that's what search engines do), and gained access to 146,000 student's records.  This info should have been encrypted and it's pretty easy to lay the blame on the university for not encrypting an area that should have been encrypted.

When I said above that a hack was the online equivalent of breaking and entering, this data breach was more like a person walking through a public area of a government building, picking up brochures.  Only, someone made a mistake and put confidential info into the brochure racks.  The person who got the information wasn't necessarily acting nefariously- they collected random info that they were told was available for them to collect.  But that info shouldn't have been in that rack for them to collect.

References:
 Wang, Stephanie. "Data Breach at Indiana U May Have Exposed Student SSNs." USA Today. Gannett, 26 Feb. 2014. Web. 12 Oct. 2015. <http://www.usatoday.com/story/news/nation/2014/02/26/indiana-university-data-breach/5830685/>. 

No comments:

Post a Comment