Oct 23, 2009 11:38 pm US/Pacific
CBS 5 Investigation Shuts Down State Jobs Website
SAN FRANCISCO (CBS 5) ―
-
-
The CalJOBS website has been shut down, after a massive security hole was discovered.
CBS
CBS 5 Investigates first uncovered the story Thursday night: A huge security breach in the state's online jobsite, CalJOBS. On Friday, the website was shut down.
CBS 5 notified the Employment Development Department, which runs theĀ
CalJOBS site, about the problems earlier this week and they said they would look into those security lapses.
Now they've closed the site down altogether. When you go to the website, it is now saying "System down: The CalJOBS site is temporarily unavailable". And that's the message job seekers in California will get if they log on to view their resume and check for available jobs.
This move comes less than 24 hours after CBS 5 Investigates reported security flaws in the website that potentially put more than three quarters of a million users at risk of identity theft.
Users such as Tom Diederich of Pacifica, who first emailed CBS 5 about a "glitch" he noticed.
After bookmarking his resume, he went back the next day and found other people's information.
"There was probably 6 or 7 times thatIi have seen it," he said.
That glitch was all it took for UC Berkeley computer science Professor Doug Tygar to discover other gaping security holes. "CalJOBS at this moment has very serious security vulnerabilities with their website," he said.
Within seconds he was able to crack into several job seekers' resumes, and could even manipulate them. "I believe that what happened was that they set up the system in a way that they thought would make it secure, but they left a giant hole in it," he said.
People receiving unemployment benefits are normally required to register on the site. But they're now being told the registration requirement is suspended until the system is available, in other words, until it's fully scrutinized.
(© MMIX, CBS Broadcasting Inc. All Rights Reserved.)
Comments