LinuxWorld
Subscribe to this site with RSS

Laptop security: Do companies care?

Over the past few months there has been an unremitting drumbeat of news stories about vast amounts of data being lost when corporate laptops are stolen. In almost all these cases, the data on the laptop was not encrypted, but that is not the real problem.

Google gets 8.2 million hits for the search "laptop+stolen" and Google News gets 1,700. Some hits point to software or devices to protect laptops against theft or to track them when they're stolen. Too many, however, are about laptops being stolen; far too often those laptops contain confidential information on thousands of people.

The latest example comes from Ernst & Young, which had a laptop stuffed with information about more than 240,000 Hotels.com users stolen. Apparently, this happened awhile back, but Ernst & Young did not have the honesty to admit its stupidity publicly until The Register started nosing around.

This is not the only laptop Ernst & Young has let slip through its fingers this year. Earlier, four company laptops were stolen from a conference room while the auditors who were supposed to protect them were off at lunch.

That happened shortly after another employee managed to lose his laptop containing the Social Security numbers of some customers' employees. Ernst & Young refuses to say how many people were threatened by that loss.

Ernst & Young is hardly alone in its zeal to expose others' confidential information, then not fess up. There is the marvy case of the Department of Veterans Affairs employee who for years had been taking home disks full of Social Security numbers and other information on veterans (26 million, as it turned out). It took the department weeks to break the news when the data finally was stolen.

Other recent examples include a Fidelity laptop with Social Security numbers and other data for about 200,000 HP employees and a Wells Fargo laptop with information on "a relatively small percentage" of Wells Fargo's millions of customers. (Apparently, Wells Fargo, like Ernst & Young, thinks providing incomplete information is not the same thing as lying.)

React: Give us your thoughts on the issues here.
Use this form to start a public discussion with other Linux World users on this article.
Log In | Register for an account (Why you should)

Note: Register to have your user name appear; otherwise your comment will show up as "Anonymous."

*Anonymous comments will only appear once they are approved by the moderator.

Newsletter sign-up

Sign up for one of Network World's newsletters compliments of Linux World

Linux & Open Source News Alert
Web Applications Alert
Video & Podcast Alert
Security: Threat  Alert
Virtualization Alert

Email Address: