<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Stolen V.A. Laptop Recovered &#8211; No Identity Thefts Reported</title>
	<atom:link href="http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/</link>
	<description>Online Journal of Politics and Foreign Affairs</description>
	<lastBuildDate>Wed, 25 Nov 2009 07:15:57 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bithead</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88305</link>
		<dc:creator>Bithead</dc:creator>
		<pubDate>Thu, 29 Jun 2006 19:19:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88305</guid>
		<description>First...
As to how they knew the stuff hadn&#039;t been accessed; Everything past about nt3.51 (Assuming NTFS) contains a record of last file access and last file modified among other things.

Secondly...

And does the government being involved in the more celebrated laptop theft, constitute a larger security breach, than say a private concern? I don&#039;t think so, though it certainly does make a handy lever, if you don&#039;t happen to like the current administration. 

Think I&#039;m kidding? Consider the following story from the &lt;a href=&quot;http://www.theregister.co.uk/2006/06/28/medical_excess_loss/&quot; rel=&quot;nofollow&quot;&gt;Register&lt;/a&gt;:

&lt;blockquote&gt;Health insurance firm Medical Excess one-upped the laptop loss crowd by forking over an entire server with personal information on close to 1m people.

Medical Excess - an AIG company - began notifying customers this month that a break in at one of its offices has resulted in the the theft of a camera, two laptops and a file server. That server happened to contain the names, birth dates and social security numbers of 970,000 people. Even worse, some individuals have had their medical and disability information compromised by the theft.

&quot;The investigation following the theft of the server was quite complicated because data that was equal to one hundred million typewritten pages was stored on the server, much of which had to be manually reviewed,&quot; Medical Excess wrote to customers, in a letter obtained by The Register.&lt;/blockquote&gt;

Wouldn&#039;t you think that this kinda of theft that The Register is writing about here would get equal billing in the media, to the screaming over the VA a few months ago? That the volume of screaming is far from equal for the data thefts of private information not involving the federal government, should give a clue.</description>
		<content:encoded><![CDATA[<p>First...<br />
As to how they knew the stuff hadn't been accessed; Everything past about nt3.51 (Assuming NTFS) contains a record of last file access and last file modified among other things.</p>
<p>Secondly...</p>
<p>And does the government being involved in the more celebrated laptop theft, constitute a larger security breach, than say a private concern? I don't think so, though it certainly does make a handy lever, if you don't happen to like the current administration. </p>
<p>Think I'm kidding? Consider the following story from the <a href="http://www.theregister.co.uk/2006/06/28/medical_excess_loss/" rel="nofollow">Register</a>:</p>
<blockquote><p>Health insurance firm Medical Excess one-upped the laptop loss crowd by forking over an entire server with personal information on close to 1m people.</p>
<p>Medical Excess - an AIG company - began notifying customers this month that a break in at one of its offices has resulted in the the theft of a camera, two laptops and a file server. That server happened to contain the names, birth dates and social security numbers of 970,000 people. Even worse, some individuals have had their medical and disability information compromised by the theft.</p>
<p>"The investigation following the theft of the server was quite complicated because data that was equal to one hundred million typewritten pages was stored on the server, much of which had to be manually reviewed," Medical Excess wrote to customers, in a letter obtained by The Register.</p></blockquote>
<p>Wouldn't you think that this kinda of theft that The Register is writing about here would get equal billing in the media, to the screaming over the VA a few months ago? That the volume of screaming is far from equal for the data thefts of private information not involving the federal government, should give a clue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ICallMasICM</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88286</link>
		<dc:creator>ICallMasICM</dc:creator>
		<pubDate>Thu, 29 Jun 2006 17:13:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88286</guid>
		<description>&#039;but there was supposedly enough data in each record to facilitate ID theft, so itâ??s gotta have at least full name, DOB, SSN, and probably a few other things as well&#039;

Right - and I maybe wrong but I was under the impression that the 26.5 m records relates to individual personnel and other beneficiary records so add in whatever the associated transaction records and reference tables there are for the rdbms. Unless the disk was swapped in from another machine for some unknown reason - and if it was theft just take the disk - I&#039;m very skeptical about the whole situation.</description>
		<content:encoded><![CDATA[<p>'but there was supposedly enough data in each record to facilitate ID theft, so itâ??s gotta have at least full name, DOB, SSN, and probably a few other things as well'</p>
<p>Right - and I maybe wrong but I was under the impression that the 26.5 m records relates to individual personnel and other beneficiary records so add in whatever the associated transaction records and reference tables there are for the rdbms. Unless the disk was swapped in from another machine for some unknown reason - and if it was theft just take the disk - I'm very skeptical about the whole situation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unpartisan.com Political News and Blog Aggregator</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88284</link>
		<dc:creator>Unpartisan.com Political News and Blog Aggregator</dc:creator>
		<pubDate>Thu, 29 Jun 2006 17:10:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88284</guid>
		<description>&lt;strong&gt;Feds recover stolen computer with sensitive data on vets, military personnel...&lt;/strong&gt;

The government has recovered the stolen laptop computer containing sensitive data for up to 26.5 mil...</description>
		<content:encoded><![CDATA[<p><strong>Feds recover stolen computer with sensitive data on vets, military personnel...</strong></p>
<p>The government has recovered the stolen laptop computer containing sensitive data for up to 26.5 mil...</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Florida Masochist</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88280</link>
		<dc:creator>The Florida Masochist</dc:creator>
		<pubDate>Thu, 29 Jun 2006 16:38:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88280</guid>
		<description>&lt;strong&gt;Doing the happy dance...&lt;/strong&gt;

That&#039;s great news for all veterans(myself included). I&#039;m not questioning the FBI&#039;s conclusions, but would it be possible for someone to have copied what was on this laptop and still leave no trace? Or even make a duplicate harddrive? Or perhaps hack...</description>
		<content:encoded><![CDATA[<p><strong>Doing the happy dance...</strong></p>
<p>That's great news for all veterans(myself included). I'm not questioning the FBI's conclusions, but would it be possible for someone to have copied what was on this laptop and still leave no trace? Or even make a duplicate harddrive? Or perhaps hack...</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: legion</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88279</link>
		<dc:creator>legion</dc:creator>
		<pubDate>Thu, 29 Jun 2006 16:35:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88279</guid>
		<description>Michael,
Yes, it it&#039;s bare-bones info in raw text, but there was supposedly enough data in each record to facilitate ID theft, so it&#039;s gotta have at least full name, DOB, SSN, and probably a few other things as well... What the heck was the purpose of the original DB, anyway? Was it for billing? or medical history? Has that ever been discussed in the press?</description>
		<content:encoded><![CDATA[<p>Michael,<br />
Yes, it it's bare-bones info in raw text, but there was supposedly enough data in each record to facilitate ID theft, so it's gotta have at least full name, DOB, SSN, and probably a few other things as well... What the heck was the purpose of the original DB, anyway? Was it for billing? or medical history? Has that ever been discussed in the press?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: legion</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88278</link>
		<dc:creator>legion</dc:creator>
		<pubDate>Thu, 29 Jun 2006 16:33:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88278</guid>
		<description>Absolutely, ICallM. No way can an ordinary laptop manipulate (or possibly even load) a database with that many records...

Has anyone seen any news on the investigation of the guy who &quot;lost&quot; the info in the first place?</description>
		<content:encoded><![CDATA[<p>Absolutely, ICallM. No way can an ordinary laptop manipulate (or possibly even load) a database with that many records...</p>
<p>Has anyone seen any news on the investigation of the guy who "lost" the info in the first place?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88275</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Thu, 29 Jun 2006 16:32:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88275</guid>
		<description>&lt;blockquote&gt;If there was some sort of db containing 26.5 million records on it youâ��re probably talking multiple terabytes of data in a password protected database.&lt;/blockquote&gt;

Not so, all that can be stored in as little as a couple GB depending on the amount of data per record.</description>
		<content:encoded><![CDATA[<blockquote><p>If there was some sort of db containing 26.5 million records on it youâ��re probably talking multiple terabytes of data in a password protected database.</p></blockquote>
<p>Not so, all that can be stored in as little as a couple GB depending on the amount of data per record.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ICallMasICM</title>
		<link>http://www.outsidethebeltway.com/archives/stolen_va_laptop_recovered_-_no_identity_thefts_reported/comment-page-1/#comment-88265</link>
		<dc:creator>ICallMasICM</dc:creator>
		<pubDate>Thu, 29 Jun 2006 15:44:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.outsidethebeltway.com/archives/2006/06/stolen_va_laptop_recovered_-_no_identity_thefts_reported/#comment-88265</guid>
		<description>You know there&#039;s quite a bit that&#039;s odd about this story from the outset. If there was some sort of db containing 26.5 million records on it you&#039;re probably talking multiple terabytes of data in a password protected database. Why this would be on a laptop loaded up with server sized disk space is unclear unless it wasn&#039;t really a theft. I don&#039;t know how the VA operates its data storage but there are a lot of things that are very odd about this story.</description>
		<content:encoded><![CDATA[<p>You know there's quite a bit that's odd about this story from the outset. If there was some sort of db containing 26.5 million records on it you're probably talking multiple terabytes of data in a password protected database. Why this would be on a laptop loaded up with server sized disk space is unclear unless it wasn't really a theft. I don't know how the VA operates its data storage but there are a lot of things that are very odd about this story.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
