The sad truth is Congress is the biggest offender of poor network security practices. Every time they bring in Equifax, DHS, etc to explain why they didn't practice basic IT security due diligence or due care I am reminded of the time smart people were hired to implement basic network security for Congress. Once they realized Joe in IT (who was hired to keep hackers out) can see Congressman Bob has a foot fetish, fis…
US Customs Database Of Traveler Photos Was Hacked And Stolen
61–70 of 207 posts
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#62According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#63Could this lead to criminal charges? Perhaps charging the contractor under CFAA for unauthorized access?
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#64This is yet another reminder that managing the security of your company's third party contractors is just as important as managing your own company's security. Security is a game of weakest links, and it wouldn't have mattered if CBP's internal security was the best in the world if they were allowing access to a third party that doesn't have good security. It is naturally very difficult to enforce security mandates o…
No, actually your system was compromised by allowing the subcontractor to copy the data to another, more insecure network.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#65Rule #1 about databases: It will be hacked. Rule #2: see rule #1
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#66Earlier quoted context omitted.
I kind of think you've misunderstood something. This person said "You will be hacked". A guaranteed absolute. If that were the case then why bother protecting anything? His wording was misleading. Not his intentions. Nobody is in disagreement that security is very important.
I disagree, his wording was pretty spot on. Don't collect personal data - it will be hacked. At many of the businesses I've worked at I've made an effort to lower our PII data blob purely to reduce liability for when it was compromised. If you can see some information, a hacker eventually will. Granted, lowering liability is apparently something I shouldn't worry about since no one is ever held to account for breache…
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#67Earlier quoted context omitted.
This is unless the corruption includes those who are managing the subcontractor identified. In which case, the subcontractor is blacklisted and the people responsible move onto another company (ie, Initrode vs. Initech).
Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP. I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with…
IME, this is especially the case for security positions like CISOs, where the pool of people with such experience is excruciatingly limited to begin with (and no, a high level engineer/developer does not have the same skillset as a security professional).
There's also something to be said for allowing people to learn from their mistakes. It's obviously higher stakes for an executive, but it's along the same vein as how we don't blacklist-for-life the developers who write vulnerable code.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#68Where did the license plate information come from?
Just a guess, but maybe the CBP takes pictures of the license plate at land border crossings?
They have a joint venture with DEA to have fairly comprehensive coverage of interstates. Also, private companies offer LPR services and sharing, not sure if this company did or if that database was breached.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#69Rule #1 about databases: It will be hacked. Rule #2: see rule #1
That would imply that security is irrelevant. Maybe you should re-work your rule the say that it will attempt to be hacked. Therefore you should always worry about security.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#70Earlier quoted context omitted.
seems very likely, wapo journo broke this and it's alluded to: https://wapo.st/2ItjHfW
The Register reported the Perceptics breach on May 23: https://www.theregister.co.uk/2019/05/23/perceptics_hacked_l...
> And on Monday, after I published this column online, Department of Homeland Security officials called me to disclose that photos of travelers were recently taken in a data breach, accessed through the network of one of its subcontractors.