Cfrln’s Blog: Incidents

6000 Harvard applicants’ personal data on Bittorrent

Harvard just learned security investigation 101 the hard way.
Harvard admitted yesterday that a web server was hacked a month ago that contained financial application data for over 10,000 applicants. They knew about the incident on February 15 and took down the server till February 21 in order to investigate and implement stronger security controls. Their [...]

Facebook, privacy and IT data

Facebook is getting a lot of flak in the press (latest in the Register) about reports on a gossip blog about some pretty serious privacy holes:
1. anyone that works there can look at anyone’s private profile
2. anyone who works there can look at logs of what other profiles any user has seen.
If Facebook wants to [...]

Complexity and failures in the NYT

I’ve been posting occasionally when there’s some huge meltdown of a big service like the two recent Blackberry outages. My point is usually that the systems are too complex so the failure mode is usually unpredictable and hard to track down - hence the sputtering of PR people days after big outages while sysadmins are [...]

The logs behind the Fox Fark hack

Valleywag (the Silicon Valley Gossip site recently upgraded by means of well-known tech business reporter Owen Thomas becoming the valleywag), posted a detailed log event by log event account of the investigation by Drew Curtis, Fark’s founder, who figured out that a would-be hacker was a Fox news reporter.
The basic correlation technique is one I [...]

$1 billion market cap loss due to service problems. Ouch.

This one’s even worse than taking Ebay’s market cap down $1 billion yesterday.
Why do outages last this long? Because it’s too hard to find out where the problem happened.
Skype finally posted that the issue was a problem in their networking code at 10 p.m. last night, about a full day after the problem started, while [...]

Wireless meltdowns Thursday - shoulda Splunked it!

Nearly everyone at Splunk fell victim to a series of wireless meltdowns yesterday evening - across three different carriers. Cingular was down for 4 hours in the San Francisco Bay Area due to a “software glitch.” Verizon and T-Mobile Blackberries were delivering email 6-12 hours late.
(The local CBS station picked up on Cingular’s outage. [...]