This article has a very provocative title, but there is really nothing remarkable about it.
The story is that a Windows XP PC broke, so its hard drive was removed and connected to a new PC running Vista, whereupon the data could be read easily, to the author’s surprise.
Of course it could. The author says:
The broken PC had fingerprint-authentication hardware. The manufacturer and OS were also different (Windows XP), so reading the data from the old, broken PC seemed extremely difficult.
(中略)
Until now, I had felt reasonably secure because the PC had fingerprint authentication, believing that this would help prevent data theft, but I learned firsthand that it was completely meaningless.
Even with fingerprint authentication, it is merely a substitute for a Windows password. It is not a measure against extracting data. A different manufacturer makes no difference at all, and in this case a different OS would make no difference either.
To prevent information from being extracted from a disk, the hard drive must be encrypted.
That is precisely why products such as PointSec sell well.
Seen in this light, adding a fingerprint-authentication device has both advantages and disadvantages. If it creates a misunderstanding that leads people to lower their guard, it can actually be dangerous.
Incidentally, when I first saw the headline, I was startled because I thought someone had succeeded in extracting data from Vista + TPM. Of course, nothing of the sort had happened.
What a needlessly alarming article.
Some other comments:
The risk of information leakage is increasing. This incident made me realize that thin clients, which leave no data on the HDD, are extremely effective.
As with fingerprint authentication, unless thin clients are understood and operated correctly, they could actually make matters more dangerous.
Moreover, extracting information is not limited to physical means. Viewed that way, thin clients are not actually a fundamental solution.
As another aside, memory sticks are at even greater risk of being lost than PCs, and because there is a high risk of information leaking without the company noticing, managing them is extremely important. Fingerprint authentication and data encryption should probably be essential.
That is exactly right. Ideally, though, I think each file should be encrypted… (because the destination to which it is copied must also be managed.)
Related posts

Thoughts on the Benesse Personal Data Breach
It appears that children's and other personal data—up to 20.7 million records—was leaked[1] from Benesse. This is a thought-provoking incident in many respects. Let us consider…

Considering the Risks of Twitter’s 230 million-Person Data Leak
In 2023, during the early hours of January 6, Bloomberg’s report “Twitter May Have Leaked Information on More Than 230 million People” came across my feed,…
