Wednesday, May 25, 2005

LexisNexis Security. NOT!

A report in Wired indicates that it did not require much skill to steal 310,000 personal identity files from Lexis/Nexis.

"You start looking at an account that's been logged into 500 times and generated 9,000 reports, for example, that's a lot of information (to examine)," Sibley said. "I'm just saying it's not one group that's compromised LexisNexis. Their security is really bad. This isn't a situation where you're talking about needing an ├╝berhacker to compromise (the system). Their passwords weren't as secure as your average porn site. I think it didn't take a genius to break them. Although I think the way the hackers did it was creative. We'll give them style points."

