Security cert body gives lesson in insecurity
By John Leyden, The Register Jun 3 2004 7:54AM
Security certification and training body (ISC)2 has apologised for a serious security breach which saw the personal details of thousands of respondents to a survey posted onto an insecure server.
Phone numbers, email and contact addresses for many of the estimated 20,000 respondents to (ISC)2 Constituent Survey were easily available on the site because of lax security for a short time towards the end of last week. The data was unencrypted and left open to harvesting through simple URL manipulation despite a promise from (ISC)2 to survey participants that "your answers and feedback will be kept strictly confidential and will not be associated with you, your organization, or your employer". It was also possible to modify the information filled in, according to a Register reader, who sent us a sample of data (home and work addresses and phone numbers) to back up his concerns.