It’s an old (ish) story, but I couldn’t resist linking to The Register and one of its prime candidates for headline of the year, “Smut-swapping sailors leak secret missile specs“. The Reg’s story is safe to read at work, but is a lesson on what happens when classified missile data gets mixed up with indecent images. I, of course, hope that none of you reading this have inadvertently sent out the wrong information with indecent images, but there is probably a fair percentage of you who have just plain sent the wrong information to the wrong person by mistake.
This blog talks about 3BView the company, the technology, what's going on in our markets of metadata removal, data leak prevention and document transformation.
Wednesday, 1 August 2007
Insert naval pun here
Friday, 27 July 2007
Too much exposure in images - more on EXIF
Following the Harry Potter story, EXIF stores even more personal information than I first thought in images – as you’d expect Wikipedia has all the details. The camera serial number is the obvious personal information you might want to remove, but date and time are stored which could be tricky. And cameras with GPS capability can store the location the photo was taken as well. Scary!
One of the least obvious but perhaps potentially most embarrassing aspects, though, is that if you edit a photo, the EXIF data may still contain a thumbnail of the original photo. Can you guess where this is leading? Yes, a certain Cat Schwartz (who’s apparently a minor celebrity in some circles) posted cropped photos of herself on her blog, and the EXIF data contained thumbnails of the original, uncropped photos that showed her posing topless. Full story here (but the links to Schwartz’s blog and the photos are now dead).
Tuesday, 24 July 2007
Harry Potter and the hidden metadata
Wouldn’t that be a great book title?
Sadly not yet written, but there’s an interesting story doing the round about how metadata could catch the culprit who leaked ‘Harry Potter and the Deathly Hallows’ on the internet.
The leaked copy was actually painstakingly-taken images of each page of the book, and the hidden EXIF metadata in the images contains the camera’s serial number. It’s a Canon Rebel 350D, apparently, and the company is trying to find out if the camera was registered and therefore they can use the serial number to track down the errant photographer.
It certainly puts me off registering the products I buy.
Thursday, 19 July 2007
UK threatens prison for information misuse
Is it just me, or does it feel like some companies don’t take data security seriously? Well, the
The Information Commissioner, Richard Thomas, told the BBC, “Frankly these [security breaches] are inexcusable. None of this is really rocket science - security is fundamental.” Couldn’t agree more. He also said, “The roll call of banks, retailers, government departments, public bodies and other organisations which have admitted serious security lapses is frankly horrifying."
The press release on the report is here, which includes a link to the full report.
Wednesday, 11 July 2007
Monday, 9 July 2007
When does open mean shut?
Interesting story on the BBC on Tuesday about Microsoft working with the UK National Archives to ensure documents can be read in the future. I’ve posted on this problem before, but Microsoft’s move to promote its Open XML file format is really getting some attention.
Friday, 6 July 2007
The psychology of security
I missed posting a link to this when it came out, but Infosecurity Today has got a great interview with Bruce Schneier of BT Counterpane in its May/June issue and on its site. They also link through to a longer essay on this topic that Schneier has posted on his website here.
It’s pretty much essential reading. He also talks about the insider risk that I’ve previously mentioned, and says “I think companies underestimate the severity of insider threat”, as well as proposing why.