Cloud

12/21/2017
12:23 PM
50%
50%

US Census Bureau: Data Exposed in Alteryx Leak Already Public

The US Census Bureau says no personally identifiable information it collected was compromised in this week's Alteryx leak.

Data analytics firm Alteryx made headlines this week when UpGuard discovered a misconfigured Amazon Web Services S3 storage bucket exposed sensitive information of 123 million households. The leak exposed information from Experian and the US Census Bureau.

The US Census Bureau today issued a statement following reports claiming Alteryx exposed personally identifiable information (PII) collected by the Bureau. The agency said Alteryx only had access to publicly available data from census.gov, including published data from the 2010 Census.

"The company implicated had no access to PII collected by the Census Bureau, nor did the reported data leak involve Census Bureau servers or Census Bureau data stored through cloud services," the Bureau said.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
12/31/2017 | 9:54:51 PM
Re: Incorrectly Configured S3 Bucket
@Ryan: Well, they already have, as we've started to see. Whether it's enough, however, remains to be seen.
Cadopac
50%
50%
Cadopac,
User Rank: Apprentice
12/27/2017 | 7:12:53 AM
Re: Incorrectly Configured S3 Bucket
Agreed !
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
12/26/2017 | 8:49:36 AM
Re: Incorrectly Configured S3 Bucket
@Dr T. "Secure VPC's"

My assumption is that amazon does this by default and then customers, unfortunately, reduce the security parameters. Based on earlier discussion on brand reputation I would be surprised if Amazon made customers pay more for a secure deployment.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
12/26/2017 | 8:46:23 AM
Re: Incorrectly Configured S3 Bucket
@Joe. That's a great point. Question is, what is the catalyst to start Amazon on the path of completely locking down their UI/UX from a hardening perspective? Is this exposure enough to facilitate a change?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/25/2017 | 7:15:21 PM
Re: Incorrectly Configured S3 Bucket
Anytime Amazon sees its name in the news articles about data breaches -- even if it's "not their fault" -- it's brand damaging. That is a good point and true. Nobody wants to be in the news because of breaches.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/25/2017 | 7:13:34 PM
Re: Incorrectly Configured S3 Bucket
Ultimately, the fault lies with the users/customers That would be the case, if system is breached because data is not encrypted at rest it, consumers and argue with that.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/25/2017 | 7:11:31 PM
Re: Incorrectly Configured S3 Bucket
Amazon, by default, should be deploying secure VPC's. I think Amazon already provides that, it may cost the consumer tough.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/25/2017 | 7:09:50 PM
Re: Incorrectly Configured S3 Bucket
Can someone elaborate as to if this was a fault of amazon or the company leveraging those services? That is the question in the cloud, it depends on the cloud service provider I guess
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
12/25/2017 | 7:08:16 PM
Public data
It can be public data but if protected and accessed by hackers that would still constitute a breach and should be avoided
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
12/23/2017 | 5:39:41 PM
Re: Incorrectly Configured S3 Bucket
@Ryan: Since an outbreak of high-profile breaches due to misconfigured S3 buckets, Amazon has made some efforts to make things easier to configure and more transparent/visible. Ultimately, the fault lies with the users/customers -- but Amazon does bear some responsibility from a UI/UX perspective, no doubt. Anytime Amazon sees its name in the news articles about data breaches -- even if it's "not their fault" -- it's brand damaging.
Page 1 / 2   >   >>
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
6 Reasons Why Employees Violate Security Policies
Ericka Chickowski, Contributing Writer, Dark Reading,  10/16/2018
Getting Up to Speed with "Always-On SSL"
Tim Callan, Senior Fellow, Comodo CA,  10/18/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Latest Comment: Too funny!
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.