Earlier quoted context omitted.
Many devices that a business might throw away in 2015 may not have been devices that supported full disk encryption out of the box.
I've been using fde since like 2005 or so and I'm not even a bank. Seems like they don't have much excuse?
Morgan Stanley didn't wipe their hard drives before giving them to a third party
11–20 of 38 posts
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#12I used to visit the data centers of some very large financial institutions. The SoP at those places was that hard drives from the data center NEVER left the building except through a device that destroyed them…. Their security guards were really into checking for them and etc. It was a pretty common rule across those banks and etc at that time, and that was quite a while ago.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#13The real mistake in this trainwreck was that Morgan Stanley didn't encrypt their hard drives.
Many devices that a business might throw away in 2015 may not have been devices that supported full disk encryption out of the box.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#14Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#15The real mistake in this trainwreck was that Morgan Stanley didn't encrypt their hard drives.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#16Earlier quoted context omitted.
I've been using fde since like 2005 or so and I'm not even a bank. Seems like they don't have much excuse?
That's at least two years before even the most forward thinking offices started using FDE on PCs. Bitlocker came out in 07.
I wasn't working in IT so I have no idea what corporate policy was like at the time, but it was highly recommended in hacker circles. It can't have been that hard.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#17Earlier quoted context omitted.
I've been using fde since like 2005 or so and I'm not even a bank. Seems like they don't have much excuse?
Are you running an EMC CLARiiON array with the export encryption option licensed? What works on your desktop isn't really comparable to what Morgan Stanley had on the datacenter floor 10 years ago.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#18Earlier quoted context omitted.
That's at least two years before even the most forward thinking offices started using FDE on PCs. Bitlocker came out in 07.
Yeah, MS was ultra behind. Scramdisk came out in 1998 or 99 as I recall. I wasn't working in IT so I have no idea what corporate policy was like at the time, but it was highly recommended in hacker circles. It can't have been that hard.
In the early 2000's, any sort of encryption was a non-trivial burden on already slow (by today's standards) systems. Plus the whole export encryption fiasco and more.
I'd say FDE didn't really take off until your mobile devices started to offer it by default, and make it easy enough that regular users don't ever need to think about it. Now pretty much all operating systems support FDE "out of the box".
Saying folks should have been running FDE back in the early 2000's is just absurd, really.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#19> "Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.” $35 million fine for 15 million customer's PII. The 'clear message' is that a customer's PII is worth about $2. Meanwhile the customers are on the hook for fraud monitoring in perpetuity.
Until living, breathing, actual people face real consequences for this kind of thing, any enforcement actions are just theater.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#20I used to visit the data centers of some very large financial institutions. The SoP at those places was that hard drives from the data center NEVER left the building except through a device that destroyed them…. Their security guards were really into checking for them and etc. It was a pretty common rule across those banks and etc at that time, and that was quite a while ago.
At the same time I heard several stories of people copying the files onto their desktop hard drives and leaving the building with them when lehman went bust.
To be clear in one building there were a few thousand people working. When I visited myself and maybe a dozen or two dozen other people in the building had access to the data center. Cameras everywhere, appointment verification, IDs, man traps and all.
I'd visit and go up to the doors and passers by would stop to watch "he's going inside..."
Whatever a random drone was doing with their laptop, that's a whole other issue / policy.
It was even more fun at military sites. NOTHING non essential ever left. You, your ID (they held it), your clothing, glasses... that was all that came out, your laptop and any spare parts were left behind every time. If you went to the very special sites... you also made sure nothing was in your car that you didn't want to lose.