SSD missing from SAP datacenter turns up on eBay, sparking security investigation
- Reference: 1687347068
- News link: https://www.theregister.co.uk/2023/06/21/ssd_sap_datacenter/
- Source link:
According to sources close to the incident, four SSD disks went missing from SAP's Walldorf datacenters in Baden-Württemberg, southwest Germany, in November last year.
One of the disks later turned up on eBay and was bought by an SAP employee. They were able to identify that it belonged to SAP. The disk contained personal records of 100 or more SAP employees.
[1]
A subsequent investigation found that the disks had been stolen, although human error and process failure also contributed to their loss, The Register understands.
[2]
[3]
The investigation showed there were no physical checks on people leaving the datacenter, which was described as a secure location. The disks were moved to an unsecured building in the HQ complex and from there they were stolen. The whereabouts of the three remaining disks are unknown to SAP.
The Register understands it is the fifth incident of disks going missing from SAP's European datacenters in two years.
[4]SAP admits HANA Cloud makes for multicurrency messes
[5]SAP's cloud drive hits speed bumps with American users
[6]SAP gets cloudy with a chance of AI in bid to woo on-prem brigade
[7]SAP signs IBM Watson deal, ChatGPT showstopper waits in the wings
In response to questions raised by The Register , a SAP spokesperson said the disks contained no personally identifiable information (PII).
"SAP takes data security very seriously. Please understand that while we don't comment on internal investigations, we can confirm we currently have no evidence suggesting that confidential customer data or PII has been taken from the company via these disks or otherwise," they said.
[8]
The security breach will be an embarrassment to SAP as the company centered on enterprise resource planning (ERP) software strives to increase its [9]success in cloud computing and software as a service , both through its own cloud services and services hosted by third-party providers.
In 2019, Finnish data removal specialist Blancco found that of a sample of 159 random used drives on eBay in the US and Europe, 42 percent (or 67 devices) enabled anyone with basic IT literacy to access the data stored by their previous owners. A whopping 15 percent contained PII that could be used by cybercriminals, the company said. ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJMeoIRhCUOBrh1advy3ZAAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJMeoIRhCUOBrh1advy3ZAAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJMeoIRhCUOBrh1advy3ZAAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2023/06/20/sap_hana_cloud_multicurrency_mess/
[5] https://www.theregister.com/2023/05/23/sap_americas_user_review/
[6] https://www.theregister.com/2023/05/17/sap_seeks_boost_with_ai/
[7] https://www.theregister.com/2023/05/03/ibm_watson_chagtgpt/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJMeoIRhCUOBrh1advy3ZAAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/05/23/sap_americas_user_review/
[10] https://whitepapers.theregister.com/
Quite.
I'm intrigued how they were able to identify the drives as belonging to SAP otherwise... they must have been unencrypted or else they'd just look like a bunch of random data at best, or not even let you see the drive at all (if you have ATA-level encryption on).
I suppose in theory they could have connected them to a system and supplied SAP drive encryption credentials and then seen data that nobody without those credentials could have, but it doesn't sound that way. It sounds like plain-text to me.
"I'm intrigued how they were able to identify the drives as belonging to SAP otherwise... they must have been unencrypted or else they'd just look like a bunch of random data at best, or not even let you see the drive at all (if you have ATA-level encryption on)."
Hard to know exactly.
I'm assuming these were Enterprise high-capacity SSDs (so not the "common") made by a vendor that SAP used. It is possible the particular model/models of SSD were only sold to a limited number of enterprise customers and so them being sold on eBay would point to only a small number of enterprise orgs they could have come from.
Many enterprise/cloud providers shred HDDs/SSDs on-site when they come to the end of their operational life and so any such "unusual" models of drive would be unlikely to be resold anywhere.
Also OPAL drive encryption has in the past been broken/bypassed by security researchers, usually not due to flaws in OPAL in general but rather due to vendor implemention-specific flaws.
It is possible that the drives were not encrypted at all (on the assumption that they would be securely wiped when finished with and shredded if end-of-life).
Possibly, they scan the "serial numbers" of all of their drives into some sort of "inventory database" so they can also track their movements and confirm delivery to a secure shredder I hear data centers do stuff like that.
"a SAP spokesperson said the disks contained no personally identifiable information"
Given that the drive bought on eBay contained data on 100 SAP employees either SAP employees don't count as persons or the spokesperson is pushing things even further than the standard script for this situation.
"no personally identifiable information (PII)"
Wondering whether this is a literal quote from the SAP spokesperson (unlikely as it was not inside quotation marks) or written by TheReg's Lindsay.
As the SSDs were stolen in Germany (i.e. EU) then what matters is whether they contained any "Personal Data" which is what EU Data Protection Law (GDPR) is about. PII tends to be a USA term which has a narrower definition than "Personal Data" and is not relevant in the EU.
I'd expect Lindsay to know the difference between Personal Data and PII...
This is one of the big problems with the Americanisation of The Register, using an American term here makes things very unclear...
SAP takes data security very seriously.
Demonstrably they don't, Because this doesn't happen to people who do.
Re: SAP takes data security very seriously.
... at least, not five times in two years.
Re: SAP takes data security very seriously.
And SAP wonder why no one wants to "Rise" to their cloud...
Poor saps.
At least they didn't get root...
'SAP takes data security very seriously'
When we get caught, we take it seriously. Normally, we just assume everything is tickey-boo. Very relaxed about our data warehouse and its appalling physical security until it was discovered to be a weak point. Now it looks like we have a PR disaster on our hands so we need to show that we really do care, honest.
There, FIFY.
WTF
No encryption at rest?
The GDPR fine should be large.
Where I work
Is a lot smaller than SAP, but apparently we are far more secure.
1. All servers, NASes, etc., are inside locked racks. Yes, the racks aren’t anything special, and the locks are pretty flimsy, but it would be obvious if someone liberated a drive.
2. All racks are in locked rooms, using card and touchpad access. And with security cameras inside the rooms and outside, pointing at the doors. Only authorized people are allowed inside. And the cameras would spot some taking a drive.
3. Entrance, and exit, to the building are via security doors in a mantrap system, with lots of cameras.
4. The sysadmins would probably notice missing drives, not least when reviewing the backup logs.
5. The Morgue where we play with dead equipment is right next to the server rooms. And is locked and the door has security cameras.
6. Anyone who pulls any equipment from the server rooms has to sign for it. And sign it back in when done. We definitely do not allow drives to leave the building. Unless they are headed to Iron Mountain for storage or destruction.
7. As getting into the Morgue or the server rooms requires the key card, which is your ID card, you can't even access anything without it being clear whodunit.
8. Backup tapes are stored in fire-resistant cabinets in the Morgue until the guys from Iron Mountain show up to take them to secure storage. The cabinets are, of course, locked. (Yes, we still use tape. It works.)
There is no reason for a drive to be anywhere except the Morgue or a server room, or in transit between them. (Except for brand new drives arriving from outside, of course.) Any drive going out of service is reformatted seven times, if it still works, and destroyed by physically drilling holes through it. Really good recovery people might get some data from the drive, but it won't be easy. Destroyed drives are sent to Iron Mountain and run through their shredder. Now not even a really good recovery service is going to find much.
So how, exactly, did a major corporation manage to let drives get out into the wild, and not once but multiple times?
Re: Where I work
"2. All racks are in locked rooms, using card and touchpad access. And with security cameras inside the rooms and outside, pointing at the doors. Only authorized people are allowed inside. And the cameras would spot some taking a drive."
Really? If the cameras are pointing at the doors then presumably I can remove a drive from a server and have it in a pocket as I leave.
Now it should still be possible to say "this was when the drive disappeared, and there were only three people who accessed the room then", but drives are no longer large enough to need any skill to hide them.
Re: Where I work - Cistern Failure
Research Machines assembly plant had a flooded male lavatory, the cause was a jammed open valve.
One of the contractors had signed out a replacement HDD (Still in its shrink wrapped factory bag), then gone to the lavatory & hidden it in the cistern for later retrieval at the shift end but jammed the valve open.
He was traced from serial number on the HDD, the timestamp of signing for it & the security footage from that point & then going for his data dump.
Sorted!
It's the code for multi-currency they need in Singapore.
And in the Cloud
Cloud Computing:
Just someone's servers in someone else's building with unknown computer and physical security.
But this wasn't even Cloud. It was their own datacentre! Oops!
Don't be a sap
" SAP takes data security very seriously... "
So seriously that folks can leave a secure area with kit unchallenged. This reminds me of the famous wikileaks incident where the perp transported secrets out of a SIPRNET environment on writable CDs that he pretended were pop music he'd brought in to play on his phones. The investigation found that the stringent SIPRNET security protocols were not applied to guys they knew: " [1]Personal use was common, widespread and casually accepted – “Defense (Coombs): How was it enforced? Lim: No. You trusted people ”
[1] https://alexaobrien.com/archives/1735
I used to know a guy that would run a scam thusly:
1) pop out a drive on a raid array
2) reseat it
3) wait for the compaq (yes this was ages ago) engineer to turn up, replace the drive and leave the old one in the rack because of the disk retention policy.
4) swipe the 'faulty' drive
No idea if they got flogged on fleabay though
Thats ok because they use self encrypting drives right? So a person with the drive cant use the data on it correct?