Even smart people make mistakes


Anybody want to know Trend Micro’s top secret internal strategic plans for our upcoming projects? How about our financial returns for the next quarter?

Well sorry, obviously we are not going to give that sort of information out publically – we’d need to be crazy to do something like that.

… On the other hand if you want a heads up on Microsoft’s upcoming Windows 8 and Windows 9 operating systems (128 bit apparently) just wander over to the LinkedIn social networking site.

PC Pro have published a short piece on how a certain key Microsoft employee’s LinkedIn profile described his job description as:

Working in high security department for research and development involving strategic planning for medium and longterm projects. Research & Development projects including 128bit architecture compatibility with the Windows 8 kernel and Windows 9 project plan. Forming relationships with major partners: Intel, AMD, HP and IBM.

Ouch.

This is yet another example of very sensitive company data being accidently posted to a social networking site, an all too common occurence. Social Networking sites are also invaluable as sources of reconnaissance for hackers targeting a specific company, whether it’s an IT admin on LinkedIn mentioning “managing Checkpoint Firewalls” in his job description, or an employee tweeting that they are going on their way to a “merger meeting with company X” – employees are quite often unaware of the sensitive information they are publically disclosing.

Don’t get me wrong, I like Social Networks. I even have a LinkedIn profile of my own, but I don’t put any data there that people would not already know.

If you are worried about this sort of data leakage occuring in your own company, I’d fully recommend reading my colleague David Sancho’s paper “A Security Guide to Social Networks“.

Perhaps Microsoft might like to print out a copy for all of their own employees.

Post from: TrendLabs | Malware Blog - by Trend Micro

Even smart people make mistakes

Author:...

Read Full Article

GSO
Written on Friday, 09 October 2009 03:21 by GSO

Viewed 13 times so far.
Like this? Tweet it to your followers!

Rate this article

Latest articles from GSO

Latest 'tweets' from GovernmentSecurity

  • News Update: Cyber war is coming, the impact could be huge: CBS News reports that cyber.. http://bit.ly/1tx1kr | #Security Link Monday, 09 November 2009 07:35
  • News Update: Tenable Network #Security Podcast - Episode 11: Welcome to the Tenable Netw.. http://bit.ly/2Iqd6G | Security Link Monday, 09 November 2009 07:35
  • News Update: Consent will be required for cookies in Europe: EDITORIAL: A law that dema.. http://bit.ly/3JYgip | #Security Link Monday, 09 November 2009 07:35
  • News Update: CBS 60 Minutes tackles cyber-terrorism: Could hackers get into the compute.. http://bit.ly/2d5Y21 | #Security Link Monday, 09 November 2009 07:35
  • Blog Update: We have launched the new GovernmentSecurity.org: We decided to launch th.. http://bit.ly/2G1SSF | #Security Link Saturday, 07 November 2009 17:38
blog comments powered by Disqus

Site Search

Disqus Tools