• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

University of Texas haxored!

Originally posted by: Hammer
aaaargh. they better not have my crap. :|

I know how you feel, but they said they got 59,000 SSN, that's an awful lot. I'm going to be keeping a close eye on my personal information and make sure nothing fishy is going on.
 
We had the same problem about a year ago and over 75000 students and staff were exposed. However, it was never determined how much information was accessed by the hacker(s).
 
Originally posted by: weeber
Originally posted by: Hammer
aaaargh. they better not have my crap. :|

I know how you feel, but they said they got 59,000 SSN, that's an awful lot. I'm going to be keeping a close eye on my personal information and make sure nothing fishy is going on.

Yeah, me too. I'm gonna send off for a credit report today and see if there's anything. I'll check again in a few months.

 
when will people realise Windows is not secure, nor will it ever be. Think about it. When one hole is found and patched, another one is found, etc.. etc.. .etc..... If I had a business/school or whatever that holds personal info like SSN's CC's etc.... I would make it offline..... Not even connectedto a network (Stand alone) That is the only way to make sure hackers do not gain access through the network to the important info..
 
Yeah, this was discussed here earlier this AM (no, I'm NOT a member of the repost police).

I wonder how UTexas' $80K per year infosec manager is feeling right now?
 
Originally posted by: snooker
when will people realise Windows is not secure, nor will it ever be. Think about it. When one hole is found and patched, another one is found, etc.. etc.. .etc..... If I had a business/school or whatever that holds personal info like SSN's CC's etc.... I would make it offline..... Not even connectedto a network (Stand alone) That is the only way to make sure hackers do not gain access through the network to the important info..
How the hell would you manage that then? Many people need access to the files at all times to make adjustments such as scheduling, billing, address changes, etc. How do you expect them to do this work? (This coming from someone that works with the system.) It may be a feasible idea for a small school, but when you have 40,000+ students it is impossible to have one centralized, non-networked computer handle the entire database.

 
Originally posted by: minendo
Originally posted by: snooker
when will people realise Windows is not secure, nor will it ever be. Think about it. When one hole is found and patched, another one is found, etc.. etc.. .etc..... If I had a business/school or whatever that holds personal info like SSN's CC's etc.... I would make it offline..... Not even connectedto a network (Stand alone) That is the only way to make sure hackers do not gain access through the network to the important info..
How the hell would you manage that then? Many people need access to the files at all times to make adjustments such as scheduling, billing, address changes, etc. How do you expect them to do this work? (This coming from someone that works with the system.) It may be a feasible idea for a small school, but when you have 40,000+ students it is impossible to have one centralized, non-networked computer handle the entire database.

Yep.
 
"We flat out messed up on this one," said Dan Updegrove, the university's vice president for information technology. "Shame on us for leaving the door open, and shame on them for exploiting it. Our No. 1 goal is to get those data back before they get misused."
Kudos to Updegrove for actually being responsible for his department's actions!! In this day and age, that's a very rare thing.

Dan Updegrove...you're my hero!!!! 😀
 
good ole western IL...runs on linux and we dont use SSN for anything. Wonderful place it is.
 
Originally posted by: FallenHero
good ole western IL...runs on linux and we dont use SSN for anything. Wonderful place it is.
You may not use SSN for anything, but it is still in the system for student loans and official records.
 
what really sucks is UT has been trying to weed-out the use of SSNs in their databases.

i hope no one screws w/ me 🙁
 
We had the same problem about a year ago and over 75000 students and staff were exposed. However, it was never determined how much information was accessed by the hacker(s).

WTF school do you go to? 75,000 students? That's like adding UF and Duke into one school.
 
Originally posted by: brxndxn
We had the same problem about a year ago and over 75000 students and staff were exposed. However, it was never determined how much information was accessed by the hacker(s).

WTF school do you go to? 75,000 students? That's like adding UF and Duke into one school.
It was at Purdue University.


 
Originally posted by: snooker
when will people realise Windows is not secure, nor will it ever be. Think about it. When one hole is found and patched, another one is found, etc.. etc.. .etc..... If I had a business/school or whatever that holds personal info like SSN's CC's etc.... I would make it offline..... Not even connectedto a network (Stand alone) That is the only way to make sure hackers do not gain access through the network to the important info..


how do you know it's Windows? 😕
 
Originally posted by: snooker
when will people realise Windows is not secure, nor will it ever be. Think about it. When one hole is found and patched, another one is found, etc.. etc.. .etc..... If I had a business/school or whatever that holds personal info like SSN's CC's etc.... I would make it offline..... Not even connectedto a network (Stand alone) That is the only way to make sure hackers do not gain access through the network to the important info..

rolleye.gif
moron.
 
really, they should tell everyone if their number was in the 59,000 or not. i'm both a student and staff, this does not make for a good day.
 
Hmmm, or they could give each student a random number instead of using their SSN as their ID........ just a thought.
 
from the UT ITS department page:

On Sunday, March 2 at 7:20 p.m., computer systems personnel at UT Austin discovered a computer malfunction. The affected computer system was immediately shut down, and detailed analysis was begun.

What happened?
The malfunction was assessed to be the result of a deliberate attack from the Internet. Subsequent analysis revealed that a security weakness in an administrative data reporting system was exploited by writing a program to input millions of Social Security numbers. Those SSNs that matched selected individuals in a UT database were captured, together with e-mail address, title, department name, department address, department phone number, and names/dates of employee training programs attended. It is important to note that no student grade or academic records, or personal health or insurance information was disclosed.

Is there evidence that the stolen data have been misused or disseminated?
UT, in conjunction with the U.S. Attorney?s Office, the U.S. Secret Service, and other law enforcement agencies, has focused its efforts since Sunday evening on identifying the perpetrator(s) of the break-in and recapturing the stolen data. To date there is no evidence that the stolen data have been distributed beyond the computer(s) of the perpetrator(s).

What is UT doing about this?
UT?s highest priority has been to identify the source of the attack and to cooperate with law enforcement authorities to capture the perpetrator(s), and any associated computers and data. Our second priority will be to assess the extent of further data exposure ? if any ? and to establish a proactive communication program with affected individuals and the UT community.

How many individual records were exposed?
Approximately 55,200 individuals had some of the above data exposed. This group includes current and former students, current and former faculty and staff, and job applicants.

How will affected individuals be notified?
The University is currently developing a communication plan and will contact affected individuals as soon as possible. At this juncture, there is no evidence that the data have been further exposed or misused.

 
Originally posted by: CorporateRecreation
Hmmm, or they could give each student a random number instead of using their SSN as their ID........ just a thought.

students have been asking for that for years. only this year have they said you're no longer allowed to ask students to put their ID# on any papers.
 
Back
Top