News: 1675668731

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

School laptop auction devolves into extortion allegation

(2023/02/06)


When a Texas school district sold some old laptops at auction last year, it probably didn't expect to end up in a public legal fight with a local computer repair shop – but a debate over what to do with district data found on the liquidated machines has led to precisely that.

The San Benito Consolidated Independent School District sold more than 3,500 devices at auction in July 2022, of which 700 were purchased by local computer repair and resale shop RDA Technologies.

RDA co-owner David Avila said he found 11 hard drives the district had failed to wipe, and which contained sensitive data on employees and students. Avila told local media that he [1]reported the presence of the data to the district in October, saying "legally, it's their job to wipe out or destroy hard drives."

[2]

It's here things start to get complicated.

[3]

[4]

The district [5]admitted to the exposure of the data as a result of the sale to RDA, but said Avila's company "has not agreed to our proposed solution." Avila disputed that characterization in a late January [6]interview , saying that the district wanted him to sign a nondisclosure agreement as part of a deal to buy back the 11 computers, and an additional 503 that hadn't been inspected.

Avila says he wants the district to be open about the errors in its process – particularly as he alleges some computers sold by the district went to foreign buyers – so is not willing to sign an NDA.

[7]

The district also claimed that it wasn't given the chance to inspect the machines to verify they contained the alleged data. Avila denied this too, claiming a representative from the district had visited his shop to inspect them in October. Local news media reported they had inspected a machine and verified the data was present.

The district fired back with a [8]statement on February 2, along with a [9]copy [PDF] of communications with RDA. Among those communications are accusations from the district's legal representatives that Avila is attempting to "extort" the district.

Conveniently absent from the trove of communications is Avila's initial message to San Benito. Also missing is anything that actually incriminates Avila in extortion, as San Benito's lawyers allege in the missives.

[10]

The district also called RDA out for a similar scheme at a different Texas school district in 2019. RDA had machines from Edcouch-Elsa CISD where similar information was found. Avila [11]said at the time he wanted Edcouch-Elsa to notify the public, as in this latest case.

Edcouch-Elsa said it also failed to reach an agreement with RDA.

According to San Benito CISD, the matter is now in the hands of the Texas AG, who isn't looking at its data wiping failures, but is investigating RDA. "The District is providing information to the Texas Attorney General to aid representatives from the Texas Attorney General's office in their future inspection of RDA Technologies," Superintendent Theresa Servellon said.

[12]Have we learnt nothing from SolarWinds supply chain attacks? Not yet it appears

[13]HeadCrab bots pinch 1,000+ Redis servers to mine coins

[14]Fast-evolving Prilex POS malware can block contactless payments

[15]Former Ubiquiti dev pleads guilty in data theft and extortion case

Patch now to avoid a Jira takeover

Several versions of Atlassian's Jira Service Management Server and Data Center contain an authentication vulnerability that could let an unauthenticated attacker impersonate users and gain remote access to affected systems.

"With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into," Atlassian [16]stated in its advisory.

The Australian outfit said the bug earns a CVSS score of 9.4.

Such tokens can be accessed when an attacker is included on a Jira issue or request with the target user, or when an attacker gains access to an email containing a view request link from one of those users. Atlassian said bot accounts are particularly vulnerable in this scenario, as they are often used to communicate with other user accounts, but rarely see a human login.

Versions 5.3.x, 5.4.x and 5.5.x are all affected, Atlassian admitted, and it recommends upgrading to the latest versions now.

For those that can't immediately deploy the patch, Atlassian also issued a JAR file that will update the servicedesk-variable-substitution-plugin , but said that's only a temporary fix.

TSA urges airlines to be careful with that no-fly list

The Transportation Security Administration has urged airlines to take a look at their systems to make sure nothing is amiss after a hacker spotted a 2019 copy of the no-fly list on an [17]unsecured public-facing server last month.

While it doesn't appear to have been published online, a TSA spokesperson told several news outlets that the Administration had issued a security directive to all domestic airlines. [18]Per a TSA spokesperson, the directive "reinforces existing requirements on handling sensitive security information and personally identifiable information."

We can hope those existing requirements were being grossly ignored at CommuteAir, which exposed the list by leaving a test server exposed to the internet. The server in question was taken down before news of the exposure was reported.

Nonetheless, Republicans on the Committee on Homeland Security aren't thrilled with the incident, telling TSA administrator David Pekoske in a letter that news of the no-fly list's discovery was alarming.

"The notion that such a consequential database be left unsecure is a matter concerning cybersecurity, aviation security, as well as civil rights and liberties," Representatives Mark Green and Dan Bishop wrote in their letter.

The representatives have given the TSA until February 8 to respond to their questions. ®

Get our [19]Tech Resources



[1] https://myrgv.com/local-news/2023/01/06/san-benito-cisd-disputes-buyers-claims-that-purchased-computers-contain-confidential-data/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y@Dd0dSaWBNKbllDKKKbaAAAAJg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@Dd0dSaWBNKbllDKKKbaAAAAJg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y@Dd0dSaWBNKbllDKKKbaAAAAJg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.sbcisd.net/apps/pages/index.jsp?uREC_ID=3521596&type=d&pREC_ID=2396486

[6] https://myrgv.com/local-news/2023/01/25/company-offers-to-sell-back-san-benito-computers/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y@Dd0dSaWBNKbllDKKKbaAAAAJg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.sbcisd.net/apps/pages/index.jsp?uREC_ID=3442719&type=d&pREC_ID=2387648

[9] https://4.files.edl.io/4941/01/20/23/223647-f5efb0a8-9429-4c3b-9846-29589aa1926f.pdf

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y@Dd0dSaWBNKbllDKKKbaAAAAJg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.krgv.com/news/students-information-mistakenly-sold-at-edcouch-elsa-isd-auction

[12] https://www.theregister.com/2023/02/05/supply_chain_security_efforts/

[13] https://www.theregister.com/2023/02/04/headcrab_botnet_aqua/

[14] https://www.theregister.com/2023/02/03/prilex_malware_contactless_payments/

[15] https://www.theregister.com/2023/02/03/ubiquiti_dev_guilty/

[16] https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-2023-02-01-1188786458.html

[17] https://www.theregister.com/2023/01/23/infosec_news_roundup/

[18] https://therecord.media/no-fly-list-breach-tsa-domestic-airlines-warning/

[19] https://whitepapers.theregister.com/



Silly school

chivo243

I did this exact thing for many years. Wiping all student and faculty computers destined for the broker. Checked, and double checked by a second techie. All units wiped had all data migrated to the users new laptop prior to wiping and putting a factory image for the broker.

These un-wiped machines were most likely from School Administrators who couldn't be bothered to bring the unit in when required, and they fell through the cracks, hence the "Sensitive" data being left behind.

It's all too familiar behavior from a school district.

Re: Silly school

JimboSmith

Will no one think of the children? Rather than just switching on the lawyers and getting them warmed up.

Re: Silly school

Halfmad

We wouldn't let a drive out without it being wiped regardless of how late it came in when I worked in Education IT.

Then again we didn't resell kit, it went to libraries for public use or was gifted to local charities.

Re: Silly school

Anonymous Coward

we wouldn't even let machines go to charities with a used hard disk in, hard disks were removed and crushed. Our social services team however (operational not IT) bought a large number of early word processors with built in memory which later turned up at car boot sales complete with the last half dozen letters.

When challenged they denied ever realising that the devices had any memory and claimed they were 'just typewriters)

Investigating RDA ?

Pascal Monett

From this article, it seems to me that RDA is doing its job. Found unwiped sensitive data on auctioned machines that had also been sold to public buyers. It is largely too late to bring in an NDA and, if the goal is to sweep the whole affair under the rug, well a certain Mrs Streisand who certainly like to have a word with that school.

Re: Investigating RDA ?

blackcat

I think this is standard operating procedure for anything governmental in the US. Don't fix the problem, just sue the people who pointed it out.

Re: Investigating RDA ?

Anonymous Coward

Only in some states!

Re: Investigating RDA ?

Anonymous Coward

However, right now, it's the company that's under investigation, not the school. And that "Streisand effect" might be invoked again and again, the fact is, do you even remember right now what happened with Barbra Streisand? I sure don't.

So it might be the focus of news for a while, then the interest will wane, while the investigation will continue to put pressure on the company for months or years (again, not the school, which at this point doesn't seem at all interested in fixing their internal issue).

Given a few more "COMPANY UNDER INVESTIGATION FOR EXTORTING SCHOOL" headlines, I'm not sure the public consciousness will bother with the more complicated technical details.

Re: Investigating RDA ?

JimboSmith

Yep I remember what Mrs Streisand made a big song and dance about. I remember because I looked at the picture of her house that she’d complained about and thought that it was a bit too close to the cliff edge for my liking.

"He's the kind of man for the times that need the kind of man he is ..."