California State Jobs Site Riddled With Security Holes

by on 10-23-2009 09:35 AM

Imagine this common scenario: you’ve been laid off and you need to register with the state to receive unemployment benefits. Part of the requirement today in California is to post your résumé to a state-run CalJobs website. An investigation into the security of that website has uncovered numerous security risks that could easily lead to identity theft for the hundreds of thousands of users.

Tom Diederich was just such a user of the CalJobs site. As part of his requirements to apply for state benefits, he dutifully posted his résumé to the CalJobs site. Then, he saved the page using his browser’s bookmarking feature. The next day, he revisited the page, only to see the résumé of a complete stranger. Further investigations by security experts have found that not only is it simple to pull up the resumes of strangers by tweaking the url address, but you can even edit the information on your screen. Imagine the opportunity not only for a cybercrook to steal your identity and reputation but also for malicious visitors to create havoc among legitimate job seekers by changing important information on their forms.

According to the news report, over 750,000 California residents have posted their résumés to the site. When you consider the rich treasure found in the average résumé (name, address, telephone numbers) and the volume of user data on the site, it is a highly attractive target for cybercriminals who prefer working off of massive databases of stolen information. The security holes have been brought to the attention of the California state officials who manage the site but it’s unclear whether or not users of the site have suffered losses as a result of the situation.

 

Comments
by on 10-23-2009 09:42 AM
Just proves that it doesn't just have to be a lack of security on your home PC that can lead to ID theft.
by Dieds on 10-23-2009 10:13 AM
Thanks for blogging on this story, Marian. I'm very concerned about my info being stolen, as it is on the EDD website. My advice for my fellow unemployed in California (who knows, other states might also be at risk) is to post only minimal info to meet the requirements -- nothing more.
by Yaso_Kuuhl Rootkit Eradicator on 10-24-2009 01:36 AM
Very disheartening to read about such security holes :-(
About the Author
  • Norton's Internet Safety Advocate. I write and speak about issues impacting the online security and safety of kids and families.
Announcements
Please read our Participation Guidelines and Terms of Service before using the community.