{"id":1013,"date":"2008-10-01T18:13:28","date_gmt":"2008-10-02T02:13:28","guid":{"rendered":"\/?p=1013"},"modified":"2008-10-03T19:53:06","modified_gmt":"2008-10-04T03:53:06","slug":"are-countrywides-systems-designed-around-need-to-know","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=1013","title":{"rendered":"Are Countrywide&#39;s systems designed around need to know?"},"content":{"rendered":"<p><img loading=\"lazy\" src=\"\/wp-content\/images\/2008\/10\/mad_as_hell.jpg\" alt=\"I&#39;m mad as hell and I&#39;m not taking it any more\" width=\"418\" height=\"480\" align=\"right\" \/><\/p>\n<p>It was inevitable, given how sloppy many companies are when handling\u00a0the identity of their customers,\u00a0that someone\u00a0would eventually steal all my personal information.\u00a0 But no matter how much science you have in your back pocket, it hurts when you get slapped in the face.<\/p>\n<p>The theory is clear:\u00a0 systems must be built to withstand being breached.\u00a0 But they often aren&#39;t.<\/p>\n<p>One thing for sure:\u00a0the\u00a0system used\u00a0at Countrywide Mortgage was so leaky that when I phoned my bank to ask how I should handle the theft,\u00a0my advisor said, &#8220;I don&#39;t know.\u00a0 I&#39;m trying to figure that out, since my information was stolen too.&#8221;\u00a0 We commiserated.\u00a0 It&#39;s not a good feeling.<\/p>\n<p>And then we talked about the letter.<\/p>\n<p>What a letter.\u00a0\u00a0It is actually demented.\u00a0 It&#39;s\u00a0as though\u00a0Countrywide&#39;s information systems\u00a0didn&#39;t exist, and weren&#39;t a factor in any insider misbehavior.\u00a0<\/p>\n<p>I agree there was a bad employee.\u00a0 But is he the only guilty party?\u00a0 Was the system set up so\u00a0employees could only get at my personal information\u00a0when there was<strong> a need to know<\/strong>?\u00a0<\/p>\n<p>Was the need to know documented?\u00a0 Was there a separation of duties?\u00a0 Was there minimization of data?\u00a0 Can I see the audit trails?\u00a0 What was going on here?\u00a0 I want to know.<\/p>\n<p>My\u00a0checks\u00a0rolled in\u00a0to Countrywide with\u00a0scientific precision.\u00a0 No one needed to contact me through emergency channels.\u00a0\u00a0Why would anyone get access to\u00a0my personal information?\u00a0 Just on a whim?\u00a0\u00a0<\/p>\n<p>How many of us were affected?\u00a0 We haven&#39;t been told.\u00a0 I want to know.\u00a0 Iit bears on <strong>need to know<\/strong> and storage technologies.<\/p>\n<p>But I&#39;m ahead of myself.\u00a0 I&#39;ll share the letter, sent by Sheila Zuckerman on behalf of &#8220;the President&#8221; (&#8220;President&#8221; who??).<\/p>\n<p style=\"padding-left: 30px;\">We are writing to inform you that we recently became aware-that a Countrywide employee (now former) may have sold unauthorized personal information about you to a third party. Based on a joint investigation conducted by Countrywide and law enforcement authorities, it was determined that the customer information involved in this incident included your name, address, Social Security number, mortgage loan number, and various other loan and application information.<\/p>\n<p style=\"padding-left: 30px;\">We deeply regret this incident and apologize for any inconvenience or concern it may cause you. We take our responsibility to safeguard your information very seriously and will not tolerate any actions that compromise the privacy or security of our customers&#8217; information. We have terminated the individual&#39;s access to customer information and he is no longer employed by Countrywide. Countrywide will continue to work with law enforcement authorities to pursue further actions as appropriate.<\/p>\n<p>I don&#39;t want to hear this kind of pap.\u00a0 I want an audit\u00a0of your systems and how they protected or did not protect me from insider attack.<\/p>\n<p style=\"padding-left: 30px;\">If you are a current Countrywide mortgage holder, we will take necessary precautions to monitor your mortgage account and will notify you if we detect any suspicious or unauthorized activity related to this incident. We will also work with you to resolve unauthorized transactions on your Countrywide mortgage account related to this incident if reported to us\u00a0in a timely manner.<\/p>\n<p>I find this paragraph\u00a0especially arrogant.\u00a0 I&#39;m the one who needs to do things in a timely manner although they didn&#39;t take the precautions necessary to protect me.\u00a0<\/p>\n<p style=\"padding-left: 30px;\">As an additional measure of protection, Countrywide has arranged for complimentary credit monitoring services provided by a Countrywide vendor at no cost to you over the next two years. We have engaged ConsumerInfo.com, Inc., an Experian\u00ae Company, to provide to you at your option, a two-year membership in Triple Advantage Credit Monitoring.\u00a0 You will not be billed for this service. Triple Advantage includes daily monitoring of your credit reports from the three national credit reporting companies (Experian, Equifax and TransUnion\u00ae) and email monitoring alerts of key changes to your credit reports.<\/p>\n<p>Why are they doing this?\u00a0 Out of the goodness of their hearts?\u00a0 Or because they&#39;ve allowed my information to be spewed all over the world through incompetent systems?<\/p>\n<p style=\"padding-left: 30px;\">To learn more about and enroll in Triple Advantage, log on to <a href=\"http:\/\/www.consumerinfo.com\/countrywide\">www.consumerinfo.com\/countrywide<\/a> and complete the secure online form. You will need to enter the activation code provided below on page two of the online form to complete enrollment. If you do not have Internet access, please, call the number below for assistance with enrollment.\u00a0\u00a0 You will have-90 days from the-date of-this letter-to-use the code to activate the credit monitoring product.<\/p>\n<p style=\"padding-left: 30px;\">Borrower Activation Code: XXXXXXXXX<\/p>\n<p>And now the best part.\u00a0 I&#39;m going to need to hire a personal assistant to do everything required by Countrywide and still remain employed:<\/p>\n<p style=\"padding-left: 30px;\">In light of the sensitive nature of the information, we urge you to read the enclosed brochure outlining precautionary measures you may want to take. The brochure will guide you through steps to:<\/p>\n<ul>\n<li>\n<div style=\"padding-left: 30px;\">Contact the major credit bureaus and place a fraud alert on your credit reports;<\/div>\n<\/li>\n<li>\n<div style=\"padding-left: 30px;\">Review your recent account activity for unauthorized charges or accounts;<\/div>\n<\/li>\n<li>\n<div style=\"padding-left: 30px;\">Be vigilant and carefully review your monthly credit card and other account statements over the next twelve to twenty-four months for any unauthorized charges; anTake action should any unauthorized activity appear on your credit report.<\/div>\n<\/li>\n<\/ul>\n<p>I need more information on why I only need to be vigilant for twelve to twenty-four months, when, thanks to Countrywide, my personal information has spilled out and I have no way to get it back!<\/p>\n<p style=\"padding-left: 30px;\">We apologize again that this incident has occurred and for any inconvenience or worry it may have caused.\u00a0 If you have questions, please call our special services hotline at 1-866-451-5895, and a specially trained representative will be ready to assist you.<\/p>\n<p style=\"padding-left: 30px;\">Sincerely,<\/p>\n<p style=\"padding-left: 30px;\">Sheila Zuckerman<br \/>\nCountrywide Office of the President<br \/>\nEnclosure<\/p>\n<p>O.K.\u00a0 This is going to be a long process.\u00a0 It drives home the need for data minimization.\u00a0 It\u00a0underlines the need for stronger authentication.\u00a0\u00a0But\u00a0EVERY case like this should make us deeply question the way our systems are structured, and ask why there are no professional standards that must be met in protecting private information.<\/p>\n<p>When a bridge collapses, people look into the why of it all.<\/p>\n<p>We need to do that with these identity breaches too.\u00a0\u00a0 As far as I&#39;m concerned, Countrywide has a lot of explaining to do.\u00a0 And as a profession we need clear engineering standards and ways of documenting how our systems are protected through &#8220;need to know&#8221; and the other relevant technologies.<\/p>\n<p>Finally, we all need to start making insider attacks\u00a0a top priority, since all research points to insiders and our number one threat.<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Was my identity stolen because there was a thief, or because Countrywide didn&#39;t have systems that limit access based on &#8220;need to know&#8221;.<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[63,62,40,11],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1013"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1013"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1013\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}