Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Networking Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Sensitive Data Leaking Onto P2P Networks

Government, businesses hit by inadvertent disclosures.

August 6, 2007 12:00 PM ET

Computerworld - Corporate and government documents containing confidential  and sometimes classified  data are increasingly getting exposed through the use of peer-to-peer networks on computers holding the sensitive information.

The problem of inadvertent exposure of sensitive data on P2P networks is a whole lot worse than many government and corporate IT managers believe, said Eric Johnson, professor of operations management at the Center for Digital Strategies at Dartmouth Colleges Tuck School of Business in Hanover, N.H.

Much of the problem, Johnson told the U.S. House Committee on Oversight and Government Reform late last month, is due to the installation of P2P software on computers used by telecommuting workers and contractors.

P2P file-sharing networks represent a significant and poorly understood threat to business, government and individuals, Johnson said. Every employee, contractor, customer or supplier is a potential weak link.

Retired U.S. Army Gen. Wesley Clark, a member of the board of directors at Tiversa Inc., a Cranberry Township, Pa.-based provider of P2P network monitoring services, told the House committee during a hearing that he was able to access more than 200 sensitive government documents from file-sharing networks in a matter of hours.

Clark said he found classified diagrams of the Pentagons backbone network infrastructure, complete with IP addresses and password change scripts; physical terrorism threat assessments for three major U.S. cities; and information on the U.S. Department of Defenses information security system audits on P2P networks. Theres all kind of data leaking out inadvertently, Clark told the committee.

The documents discovered during Clarks search were simply what we found when we put the straw in the water, he said. The American people would be outraged if they were aware of what is inadvertently being disclosed on P2P networks, said Clark.

The retired general said that the use of P2P software by a contract worker at the Pentagon likely caused much of the data to leak onto the P2P network. The breach was discovered in May.

Daniel Mintz, CIO at the U.S. Department of Transportation, told the committee that 93 DOT-related documents were inadvertently exposed on a P2P network in March.

He blamed the release of the documents on the installation of Lime Wire LLCs LimeWire P2P software on the computer of a DOT worker who was authorized to work at home. Mintz said the music- and video-sharing software was installed by the workers teenage daughter.

The DOT inspector general found that 30 of the approximately 93 DOT-related documents were publicly accessible at the time via LimeWire or other P2P software by virtue of residing in a shared folder, Mintz said.



Jump to comments

p2p

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

Tackling the Top Five Network Access Control Challenges
Computerworld and Juniper invite you to download this white paper.  

How to Secure and Accelerate Your Oracle Applications
Learn about the escalating application performance and security challenges facing corporations, today!  

Enterprise Application Delivery: No User Left Behind
Gain the ability to deliver applications to all users, using any device, across any network.  

Accelerate SSL Encrypted Applications
Gain complete visibility into SSL application sessions, making it easy to apply appropriate acceleration and security controls to all SSL traffic.  

The Commercialization of ITIL: Lessons Learned
Register for this event today!