ISU Data Breach

AirWalke

Well-Known Member
Aug 7, 2006
6,769
1,240
113
Des Moines
We're lucky the scope is rather limited to just those departments. Sounds like if the hacker really wanted to, they could have accessed a number of other records, but it sounds like they just gained access to just a small collection of servers so they "lower their risk" of drawing attention to their bitcoin operation.
 

Cycsk

Year-round tailgater
SuperFanatic
SuperFanatic T2
Aug 17, 2009
27,141
15,190
113
How do you "create" bitcoins? And why do you need big servers for it? Aren't they just a form of digital currency?
 

ISUCyclones2015

Doesn't wipe standing up
SuperFanatic
SuperFanatic T2
Dec 19, 2010
13,980
9,501
113
Chicago, IL
bet it was 2015!

my thought exactly

Everyone knows that servers are the worst for generating bitcoins efficiently. One decent graphics card can out compute a server for bitcoins (Graphics cards are 100x better for the bitcoin algorithm)

So no... it wasn't me.

How do you "create" bitcoins? And why do you need big servers for it? Aren't they just a form of digital currency?

Basically bitcoins get created whenever a certain number of bitcoin transactions get verified by other computers. To verify a transaction, it takes A LOT of computing power. Now times that by like a million and that's how many transactions you need to verify before bitcoins get released to you. (It is mainly team oriented now but I don't wanna get into that). But basically the more computing power you have, the more bitcoins you can get created for you or your team. Though servers are incredibly inefficient.

It is a little more complicated than that but I don't want to get too technical here.

But my main concern is with ISU's security regarding classes and departments just straight up having social security numbers. This means that literally every department you've ever had a class in has your SS# and name attached to it. First off that is an incredibly wasteful database practice, let alone huge security concern. All a department should need is a Student ID #. I hope this triggers a massive overhaul of that system.

I honestly don't believe the "hacker" was looking for social security numbers though. If they know that this person was doing bitcoin stuff then he/she left a major trail and was very careless. He/she probably didn't even know that data was on there.

Lastly, ISU is giving you a year of data protection just like Target did. I would suggest waiting as long as possible until the final date you can sign up. If the "hacker" was trying to find out the social security numbers then they will wait until everyone's year is up. So if it is just a coupon, honestly wait 6-9 months before even making an account.
 

greatshu

Well-Known Member
SuperFanatic
SuperFanatic T2
Dec 4, 2007
2,366
218
63
KS
If it wasn't required, it was the easiest 4 credit online class you could take.
So, I'm sure a lot of people took it required or not.

(I think it was 4 credits? I could be wrong as it was a decade ago)


Do they still require Library 160?
 

im4cyclones

Well-Known Member
Jun 14, 2010
3,850
532
113
Ames, IA
Dang. The only Computer Science class I took was in the spring of 1996.

Of course, this was shortly after they stopped posting our grades by using our SSN. Yes, they used to post a list of SSNs in the hallway with class grades.

Crazy that we weren't worried too much about it back then. But we are worried about it now.
 

ISUCyclones2015

Doesn't wipe standing up
SuperFanatic
SuperFanatic T2
Dec 19, 2010
13,980
9,501
113
Chicago, IL
Also they still have that crappy comp sci class that's required but basically none of the engineer majors require it.
 

CycloneErik

Well-Known Member
Jan 31, 2008
105,885
49,812
113
Jamerica
rememberingdoria.wordpress.com
But my main concern is with ISU's security regarding classes and departments just straight up having social security numbers. This means that literally every department you've ever had a class in has your SS# and name attached to it. First off that is an incredibly wasteful database practice, let alone huge security concern. All a department should need is a Student ID #. I hope this triggers a massive overhaul of that system.


All we have are Student ID#s. I've yet to have access to an SSN unless a student writes it down on something, and I'm adamant that nobody should be giving me that.
Faculty/department access to that personal info is pretty limited.