nCircle.com >> nCircle Blog >> Sync

« On Death of Defense in Depth and Life To Digital Maoism | Main | What’s old is old again – vulnerabilities in Office 2007 »

Please crack into my online 401k account

No, please don’t try. I’m not extending an open invitation to anyone, but my 401k company is putting us at risk. We recently changed 401k vendors and yesterday in the mail I received my welcome letter and access PIN.
clip_and_save.jpg
What you see here is at the bottom of the letter, an invitation to write down my social security number along with my PIN, then clip it out and save it. Anyone at work reading this? Well good, here is my advice:

  • DON”T write down your SSN
  • DO shred the letter and
  • DO change your PIN
The content of the welcome letter is fine and good, but I take serious issue with two items.

Note: even though the image above says “nCircle Network Security”, we didn’t send out the letters. They were sent by the 401k company. So don’t think for a moment this is some common practice to nCircle. Whats more, I bet every person from many organizations using this large, nationwide company have all been put at risk.


TrackBack

TrackBack URL for this entry:
http://blog.ncircle.com/cgi-bin/mt-tb.cgi/156

Comments (2)

Adam:

Andrew,

Are you asking your HR people to complain, and ensure that the 401k company does better in the future?

Yes, sorry, should have included the positive as well as the negative.

I've already engaged with HR to send an email with my suggestions to all our participants as well as follow up with the 401k company. The good news is I apparently wasn't the only one who had concerns. I received a number of emails from employees making similar complaints. Its good to know that the people I work with are conscious to this as well.

--S

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Verification (needed to reduce spam):

Bio

Blog: Sync
Author: Andrew Storms

As nCircle's Director of Security Operations, Andrew Storms is responsible for setting and enforcing the company's security compliance programs as well as overseeing day-to-day operations for the Information Technology department. He is a Certified Information Systems Security Professional (CISSP).

About

This page contains a single entry from the blog posted on February 23, 2007 8:39 PM.

The previous post in this blog was On Death of Defense in Depth and Life To Digital Maoism.

The next post in this blog is What’s old is old again – vulnerabilities in Office 2007.

Many more can be found on the main index page or by looking through the archives.