Massive TJX encrypted (or not) data theft

The BBC does not give much detail in its story, but it does at least mention that the data in question may have been encrypted:

In its filing to the Securities and Exchange Commission (SEC) the group said it believed “the intruder had access to the decryption tool for the encryption software utilized by TJX”.

Interesting. I’ve seen several people miss this fact in their analysis of the incident. Key management is often mentioned as a vague concept in the emerging regulations. Will we see sudden interest in tightening up the audit requirements for this crucial aspect of encryption? We’re working hard to refine and publish EKMI audit guidelines. The BBC continues…

It also admitted it did not know who, or how many people, were behind the attack, or whether there had been one breach or many.

The papers also said that a further 455,000 customers who returned merchandise without receipts had personal data stolen – including driver’s license numbers.

[…]

Hackers managed to access information from its TJ Maxx, Marshalls and HomeGoods shops in the US and Puerto Rico; Bob’s Stores in the US; as well as Winners and HomeSense shops in Canada.

It’s all so vague, but at least they’re trying to warn people/companies who might be affected. One might gather that times really have changed when they read a SF Gate article that (over?) emphasizes how little is apparently known about the incident:

“It’s not clear when information was deleted, it’s not clear who had access to what, and it’s not clear whether the data kept in all these files was encrypted, so it’s very hard to know how big this was,” said Deepak Taneja, chief executive of Aveska, a Waltham, Mass.-based firm that advises companies on information security.

Funny quote, eh? Maybe it is just not clear to Deepak? Wonder what he considers “easy to know” in investigations.

TJX also remains uncertain of the theft’s size because it deleted much of the transaction data in the normal course of business between the time of the breach and the time TJX detected it.

“There is a lot of information we don’t know, and may never be able to know, which is why this investigation has been so laborious,” TJX spokeswoman Sherry Lang said.

Ooops. I always wonder what people are thinking when I come across data retention practices that keep sensitive consumer identity/card around data longer than necessary but that delete transaction and log data.

The PCI DSS has helped me significantly in the face of VPs and C-level folks who insist that they absolutely need to keep consumer data around for “convenience” or some other arguably lopsided (is it really in the consumer’s interest?) value proposition. I can’t reveal names/places but I’ve certainly had some heated confrontations where I get to try and convince a highly-successful and profitable business person that their practices have generated a “weaponized” data repository that could blow up and things must change immediately.

Andranik Margaryan dead at 55

Maybe it’s just me but I can’t help but notice that the Armenian prime minister is suddenly found dead a few weeks after announcing that his country would start using a new gas pipeline from Iran by 2008 to lessen its dependence on Russia for power-generating facilities.

It seems the first section was reported to be open just last week.

The Armenia Diaspora complete story does not suggest any kind of foul play is suspected at all, although they do provide this rather awkward quote:

The U.S. charge d’affaires in Yerevan, Anthony Godfrey, issued a statement on the occasion, describing Markarian as a “valuable partner of the United States.”

Apparently he was expected to step down by mid-May, yet his influence over the upcoming elections probably was still considerable. A EurasiaNet writer in Yerevan posted some interesting analysis of the security dynamics of the region.

Analysts in Yerevan have long suggested that Tehran’s main motive for maintaining close links with its sole Christian neighbor is to limit the spread of Turkish influence in the region.

And likewise we probably can assume that US influence in “western-oriented” Armenia is to help limit the spread of Iranian influence, or perhaps facilitate intervention against nuclear proliferation.

Slavery abolition poems

The BBC has posted a special section regarding the 200th anniversary of Britain’s abolition of the slave trade, to be commemorated this Sunday, March 25th:

Nigerian poet Tolu Ogunlesi has written a poem for the BBC’s Weekend Network Africa programme to commemorate the passing of the Abolition of the Slave Trade Act.

They are taking poetry submissions here.

A selection of them will be posted below and broadcast on BBC Network Africa.

I thought the one by Bill Taunton was pretty clever.