Sie sind auf Seite 1von 2

CASE STUDY: INDIANA UNIVERSITY Act of 1974 “forbids such agencies (as IU) from even

asking for
COMPUTER NETWORK
Social Security numbers in other than specifically
enumerated situations. That the SSN is included in any
such faculty internet research database is out rage us,”
On Wednesday, March 11, 2015, over 2,000 Indiana
Roberts wrote on his Web conversation with Bruhn.
University (IU) faculties received the following e-mail
“Even if the files are not meant to be available to the
message: “Are you aware that Indiana University put
public, the wholesale collection of such information in
your privacy at risk? Have they contacted you about it?”
an ‘Internet data base’ demonstrates a clear failure to
The sender of this message was Glen Roberts of Oil City,
understand even the most basic precepts of personal
Pennsylvania, who describes himself on his web
privacy.”
homepage as a talk show host, privacy advocate, and
Internet entrepreneur. Searching the Internet, Roberts
located an IU file containing the names of 2,760 IU
faculty, along with their Social Security numbers, Roberts’ Justification Roberts was described by people
addresses, and phone numbers, which Roberts had at two Pennsylvania newspapers as “an interesting
downloaded and posted on his Web Site. The file had fellow and a computer whiz-bang.” According to the Erie
been created by the University Graduate School to Times, which did a profile on Roberts several months
provide information on the research interests of the prior to this incident, he came to Oil City from the
faculty members so that they could be notified of Chicago area, where he published a paper that dealt
funding opportunities that might be of interest to them. with privacy issues. He has done a short-wave radio
All IU information on the Web is supposed to be program and now does a radio program on the internet.
protected by a “safeword card.” According to Norma Also, he has been a network television consultant and
Holland, director of university computing services: “We appeared on local talk shows. Roberts also publishes
have what is called a ‘firewall, ‘an internet term that several Web pages and works as a computer consultant.
essentially prevents access to data which are not public. Roberts said he came across the IU file during a check of
The safeword card allows only authorized and his own domain. By typing “SSN” into the Infoseek
authenticated users to get to those data.” But this search engine, Roberts said, he called up a list of entries
sensitive file apparently was not protected. According to that showed a name and Social Security number. By
Jeffrey Albert, associate dean, this was an obsolete file opening that file, he found the IU research database.
that escaped unnoticed when the system was being Roberts said he has been involved in publicizing privacy
upgraded to make it more secure. The university issues for about 15 years. His interest began, he said, by
immediately removed the file and disabled the old using the Freedom of Information Act and obtaining
gateway service. The situation was called “an eye- copies of government documents. He said he was
opener” by IU Vice President for Public Affairs surprised at the amount of information available of
Christopher Simpson: “it was fortunate that more which people are not usually aware. He has been
sensitive data was not compromised. Although we are particularly interested in the seemingly wide spread
very sensitive to the release of information like this, this availability of individuals’ Social Security numbers,
is vastly different from having individual access to the which are pathways to other information and whose
university’s most sensitive proprietary information. This disclosure raises the potential of unauthorized use a
is good wake-up call. That is exactly how we are viewing person’s identity. Roberts states that the issue is this:
it.” But Roberts posed a question of other potential “Should the university be collecting this information and
security problems. “You must remember that even putting it in data bases, with maybe not the intent to
though my page may have brought this to your pass it out all over the world but with intent that a fair
attention in an unpleasant manner, the real danger lies number of people may be accessing that information?”
in those who may have silently obtained the Roberts said he published the IU list because the privacy
information from your site with no one the wiser,” he issue does not usually become tangible to people until
wrote in a Web page dialogue with Mark S. Bruhn, IU they experience an invasion themselves. “The bottom
information security officer. Roberts claims the Privacy line is privacy is an extremely important issue but it is
only important when you see it affect yourself
firsthand,” he said. “That’s what I have done with other
Web pages. People can experience it firsthand, and with from Germany? What are the chances this is not related
that experience can be more public debate and action to the World Wide Web issue?” Boone said.
on the issues.”
Boone’s wife said the issue is an settling. “It feels like
Faculty Reaction Many of the faculty members on the such a violation,” she said. “You feel like someone
published list disagree with Roberts’ tactics. They were knows you but you don’t know them. That is very
primarily concerned that their Social Security numbers uncomfortable.” The situations has been frustrating to
were made easily available for the obvious reasons and Ackerman, who said the credit card companies told him
over a hundred faculty e-mailed protests to Roberts. “I they could not put a block on his Social Security
go to Roberts and say ‘I like people who are watchdogs, Number. He was told he could contact three credit
but do you need to post this information in a convenient agencies, which many banks use to check a person’s
location to make your point?” said Kurt Zorn, of the IU credit, and they could put a hold on his records.
School of Public and Environmental Affairs. “I think he Ackerman also contacted the office of IU’s legal counsel,
might have done more damage by doing this than the which was unable to offer much assistance. “At this
university did in its oversight. There might have been point, we don’t even know if his experience relates in
more effective ways of calling attention to the any way to Roberts’ Web page,” said Michael Klein,
problem.” Law professor Ed Greenebaum added that he associate university counsel. “There are some timing
believes Roberts made a judgment about the university coincidences, but you just don’t know.” However, the
without any information, which is unfair. “The impact is university is exploring whether there is any legal liability
to expose us to a danger he says he is trying to prevent, Roberts might incur if faculty members are damaged,
and it’s much more than it otherwise would have been,” financially or otherwise. Klein added that the university
Greenebaum said. “My concern is not with the is reviewing the issue of using Social Security numbers
university’s intent but why this individual feels the need, in its course of running the school. “As an institution, we
inconsistently in my view, to facilitate the distribution of are taking a look inward to determine if there are some
our Social Security numbers.” With IU threatening to alternatives,” he said.
take legal action and the heavy volume of protests from
IU faculty, Roberts removed the IU file from his Web
page and said he has no intention of posting the names Berdasarkan ilustrasi kasus yang terjadi pada Indiana
and Social Security numbers again. University Computer Network, anda diminta:

The Consequences On March 27, religious studies 1. Mengidentifikasi 3 (tiga) isu utama dalam kasus
professor James Ackerman said he recently has been tersebut!
billed for phone lines, Internet access, and credit card 2. Jelaskan gambaran tentang sistem keamanan
accounts that are not his own. Although it has not been jaringan komputer yang dijalankan oleh Indiana
verified, he believes someone picked up his name and University dan Bagaimana penilaian anda terhadap
Social Security number from Roberts’ Web page. Within kualitas sistem keamanan jaringan tersebut?
two weeks of the posting, Ackerman received a bill for a
month’s Internet time, had a call from AT&T saying it 3. “Roberts claims that the Privacy Act of 1974 forbids
was ready with a conference call he did not order, got the university from even asking for Social Security
an inquiry from Ameritech asking if he made a call from Numbers (SSN)” Mengapa SSN digunakan oleh
Germany to Portland, Oregon, and discovered there Indiana University untuk manajemen database-nya?
were calling card accounts opened in his name. William Adakah alternatif selain SSN yg dapat digunakan
Boone, an education professor, said his wife received an dalam database Indiana University? Jelaskan!
inquiry from MCI’s frauds department about calls 4. Apakah anda setuju jika Roberts diperlakukan
originating from Germany using the Boones’ calling card sebagai seorang Hacker? Jelaskan argumentasi
number. Although there has been no proof that anda?
Roberts’s Web page was the source of the information
5. Siapa yang seharusnya bertanggung atas kasus yang
used in the fraud, Boone and others believe the
menimpa Prof.James Ackerman dan William Boone?
incidents are more than a coincidence. “What are the
Apa tanggung jawab Indiana University atas kasus
chances two IU professor are getting unauthorized calls
tersebut?

Das könnte Ihnen auch gefallen