Feeds

Security cert body gives lesson in insecurity

(ISC)2 contact database left wide open

  • alert
  • submit to reddit

Providing a secure and efficient Helpdesk

Security certification and training body (ISC)2 has apologised for a serious security breach which saw the personal details of thousands of respondents to a survey posted onto an insecure server.

Phone numbers, email and contact addresses for many of the estimated 20,000 respondents to (ISC)2 Constituent Survey were easily available on the site because of lax security for a short time towards the end of last week. The data was unencrypted and left open to harvesting through simple URL manipulation despite a promise from (ISC)2 to survey participants that "your answers and feedback will be kept strictly confidential and will not be associated with you, your organization, or your employer". It was also possible to modify the information filled in, according to a Register reader, who sent us a sample of data (home and work addresses and phone numbers) to back up his concerns.

Upon hearing about the problem, (ISC)2 responded quickly by closing the survey site. The survey was re-opened on Tuesday after coders closed up the gapping security loophole. It’s unclear whether any sensitive data got into the wrong hands as a result of the cock-up.

(ISC)2 has issued a statement explaining its handling of the problem: "In the few hours after (ISC)2's annual Constituent Survey 2004 was distributed by its survey vendor last Thursday, several constituents alerted (ISC)2 that the survey had a potential vulnerability which, under the right circumstances, could reveal a respondent's name and survey answers. The survey was shut down immediately and all survey data was locked down. The issue has been resolved and the survey was re-opened on Tuesday."

"This is an internal survey of (ISC)2 constituents who are certified information security professionals bound by the (ISC)2 Code of Ethics. (ISC)2 is investigating the matter with its survey vendor. We apologize to our constituents for any inconvenience," it added. ®

Related stories

NCSP drafts secure code guidelines
Human error blamed for most security breaches
F-inSecure mailing list spreads Netsky-B virus
Kaspersky mailing list hijacked!
How secure is CA's security mailing list?

Choosing a cloud hosting partner with confidence

More from The Register

next story
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.