|
Glen L. Roberts Privacy Bulletin Board Net Caller-ID: 38.103.63.16 |
|
|
• "Genealogy Detective" • Shopping • Office Supplies • | |
|
Your SSN from Pension Provider to Privacy Penetrator 04/23/96 - 4:00 PM Date: Thu, 23 Apr 1998 15:53:30 -0400 From: "Jim Tobin" 04/22/98 - 7:30 PM Yesterday, the Associated Press and Lansing State Journal called about this matter. Both ran stories. The Detroit News and Detroit Free Press ran versions of the AP Story (online, at least). The State claimed in the articles that they fixed the problem and it was also reported that they would pay a hacker $20,000 to verify the fix! Here is a $20,000 tip: When I sign in as an eomplyer, and search for Job Seekers -- I should note that this is as an UNVERIFIED employer -- and view the HTML source code in Netscape, select "View" and the "Document Source," I find the following... (much deleted inbetween): !-- And here's another tag telling web_eval to display the results - table border=0 !-- ID = MI-384XX2443 -- !-- ID = MI-338XX0441 -- !-- ID = MI-382XX3942 -- The X's I added. Tell me these are not Social Security Numbers! Now, let me repeat myself from below, my commentary of April 9, 1998: Now, let's stop for a moment. I don't know what information is given to "verified" employers. However, just because someone is an employer, doesn't mean they should get your SSN or other personal information! Though, as an unverified empoloyer, examining the source of the html code (select View Source, under file on Netscape), it appears to give out some SSNs. Before, the State of Michigan pays a hacker $20,000 maybe they should learn to read english and use two mouse clicks in Netscape to see hwo they are destroying any concept of privacy for Job Seekers in Michigan! 04/09/98 - 11:30 AM I emailed the MESC webmaster and State Auditor yesterday, asking about the lack of a Privacy Act statement where they ask for Job Seekers SSNs on the web. No reply as of creating this web page. It started with an article in the Detroit News. A rebuttal, complaining about the Michigan Jobs Comission. Most of the article was the normal political bickering you might expect on governmental agencies. One paragaph jumped out though: Rebuttal: Employment service hurts state workers The Detroit News Tue, Apr 07 1998 Let's talk about the unemployed. They now go to the unemployment agency and file for benefits. If they are lucky, the Michigan Works agency is located in the same building. If not, they have to go where it is located and put their resume on the Internet. Don't know how to use the computer? Too bad. Sit there until you learn, because if you're not on the Internet, you receive no benefits. Meanwhile, your Social Security number, name, address and phone number are all over the Internet for everyone to see and use. It was interesting to see this on the same say, an article appears on the wire services about an IRS Audit. Wed, April 8, 1998 -- Chicago Sun Times Audit Finds IRS security lax "Under current procedures, an impostor who knows a taxpayer's name, address and Social Security number can find out tax and income information from the Internal Revenue Service with a simple phone call," according to an internal IRS audit of agency practices. I thought, it couldn't be! They aren't making these people post their resumes with SSN to the web? No way! So, I went looking just to make sure. I couldn't find them. Not at first anyhow. I signed in as an employer. Filled out my name and address. Specified N/A as my employer ID. Went to browse the resumes. Nothing, wouldn't give me even names without being a verified employer. Now, let's stop for a moment. I don't know what information is given to "verified" employers. However, just because someone is an employer, doesn't mean they should get your SSN or other personal information! Though, as an unverified empoloyer, examining the source of the html code (select View Source, under file on Netscape), it appears to give out some SSNs. Ok, let's stop being an employer and see what it's like to be a job seeker now. Gotta put in your name and address. Next, it asks for a identifier. For some reason, they encourage you to USE YOUR SOCIAL SECURITY NUMBER. This web page is on the Michigan Employment Security Commission web server, so I can only presume that it is a State Agency request for the SSN and requires a Privacy Act notice. Of course there is none. To make you feel better they have a grand explanation about the security of all this information and how it will remain private. (Compare that to the View Source option in Netscape while viewing the resumes by unverified employers). This is their assurance: To see the assurance yourself, you must follow this link and tell it you want to submit a resume and then fill in your name and address. The following message appears from the url: The real shock came when I did a bit more surfing around the public web pages of the Michigan Employment Security Commission (MESC). Most every web server keeps a log file of all activity on that server. The MESC does. The MESC goes a step beyond and offers the log files to the public: http://atb.mesc.state.mi.us/logs/ A review of the "access" (this was 50 megabytes) log file shows clearly that whoever made that statement on the privacy of the SSN has no clue about the big picture. Everytime a Job Seeker logs into the system, it records their ID (SSN) and PIN code in the access log file. Everytime an Employer logs into the system it also records their ID (a generic number, not an SSN -- why don't they give Job Seekers the same respect as the Employers?) I don't see the passwords for employers in the log files! Here are some select log file lines. X's added by me. 208.224.11.164 - - [06/Apr/1998:08:49:45 -0400] "GET /atb/seeker/login.ind?as_UserName=544XX8982&as_Password=XX89& IsRegistration=N&as_SubmitType=Submit HTTP/1.0" 302 221 38.156.109.3 - 364XX4157 [06/Apr/1998:08:51:25 -0400] "POST /cgi-bin/seeker/atb_js_oes0 HTTP/1.0" 200 5659 Not only are thousands of Social Security Numbers (SSN) disclosed to the public, the information needed for anyone to be a Job Seeker is available. Miscreants could easily go into the system and "update" other people's resumes'. Another file, "access.meta" seems to be almost a summary of SSNs from the access log file. 9 0 62568 26946 366XX6095 14 0 108154 27104 374XX7039 9 0 64315 26953 375XX0323 It is clear that the MESC must immedediately close their "Michigan Talnet Bank," revamp the system so that Job Seekers SSNs are not a part of it and apply other measures to ensure the integrity of the data and the system. At minimum the Job Seekers are due the same respect as employers in the protection of their personal information and the integrity of it! You are Visitor # |