Earlier quoted context omitted.
I've been using fde since like 2005 or so and I'm not even a bank. Seems like they don't have much excuse?
That's at least two years before even the most forward thinking offices started using FDE on PCs. Bitlocker came out in 07.
Morgan Stanley didn't wipe their hard drives before giving them to a third party
31–38 of 38 posts
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#32Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#33> "Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.” $35 million fine for 15 million customer's PII. The 'clear message' is that a customer's PII is worth about $2. Meanwhile the customers are on the hook for fraud monitoring in perpetuity.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#34The real mistake in this trainwreck was that Morgan Stanley didn't encrypt their hard drives.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#35> "Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.” $35 million fine for 15 million customer's PII. The 'clear message' is that a customer's PII is worth about $2. Meanwhile the customers are on the hook for fraud monitoring in perpetuity.
Could you sell each customers PII for more than $2 on darkweb? I kinda doubt it, seems like fair fine to me.
If I cut open your £180k Aston Martin with an angle grinder to steal a pair of sunglasses that I sell in a pub for £10, should my fine be £11?
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#36> "Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.” $35 million fine for 15 million customer's PII. The 'clear message' is that a customer's PII is worth about $2. Meanwhile the customers are on the hook for fraud monitoring in perpetuity.
Could you sell each customers PII for more than $2 on darkweb? I kinda doubt it, seems like fair fine to me.
Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#37Re: Morgan Stanley didn't wipe their hard drives before giving them to a third party
#38Earlier quoted context omitted.
I didn't see any indication that the hard drives from the data center policy had anything to do with drone's laptops coming and going. To be clear in one building there were a few thousand people working. When I visited myself and maybe a dozen or two dozen other people in the building had access to the data center. Cameras everywhere, appointment verification, IDs, man traps and all. I'd visit and go up to the doors…
I personally rolled a few servers out of the Pentagon. We had a paper letter to take them to our office. Other than my personal concern about it, that was that.