Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

61–70 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#61

The sad truth is Congress is the biggest offender of poor network security practices. Every time they bring in Equifax, DHS, etc to explain why they didn't practice basic IT security due diligence or due care I am reminded of the time smart people were hired to implement basic network security for Congress. Once they realized Joe in IT (who was hired to keep hackers out) can see Congressman Bob has a foot fetish, fis…

Not far off from what it turns out (after investigation) really happened![1]

[1] https://en.m.wikipedia.org/wiki/Imran_Awan

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#62
post #60

According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…

Indeed. CBP made the choice to subcontract w/o proper controls. It is still CBP's fault.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#63
> “Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract,” the statement read.

Could this lead to criminal charges? Perhaps charging the contractor under CFAA for unauthorized access?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#64

This is yet another reminder that managing the security of your company's third party contractors is just as important as managing your own company's security. Security is a game of weakest links, and it wouldn't have mattered if CBP's internal security was the best in the world if they were allowing access to a third party that doesn't have good security. It is naturally very difficult to enforce security mandates o…

From the article: "The subcontractor's network was then hacked, though CBP said its own systems had not been compromised."

No, actually your system was compromised by allowing the subcontractor to copy the data to another, more insecure network.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#66
post #54

Earlier quoted context omitted.

I kind of think you've misunderstood something. This person said "You will be hacked". A guaranteed absolute. If that were the case then why bother protecting anything? His wording was misleading. Not his intentions. Nobody is in disagreement that security is very important.

I disagree, his wording was pretty spot on. Don't collect personal data - it will be hacked. At many of the businesses I've worked at I've made an effort to lower our PII data blob purely to reduce liability for when it was compromised. If you can see some information, a hacker eventually will. Granted, lowering liability is apparently something I shouldn't worry about since no one is ever held to account for breache…

If that is what he was going for then alright. My bad.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#67
post #59
post #56

Earlier quoted context omitted.

This is unless the corruption includes those who are managing the subcontractor identified. In which case, the subcontractor is blacklisted and the people responsible move onto another company (ie, Initrode vs. Initech).

Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP. I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with…

Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be people that have very limited experience making executive decisions.

IME, this is especially the case for security positions like CISOs, where the pool of people with such experience is excruciatingly limited to begin with (and no, a high level engineer/developer does not have the same skillset as a security professional).

There's also something to be said for allowing people to learn from their mistakes. It's obviously higher stakes for an executive, but it's along the same vein as how we don't blacklist-for-life the developers who write vulnerable code.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#68
post #5
post #4

Where did the license plate information come from?

Just a guess, but maybe the CBP takes pictures of the license plate at land border crossings?

CBP does more than that.

They have a joint venture with DEA to have fairly comprehensive coverage of interstates. Also, private companies offer LPR services and sharing, not sure if this company did or if that database was breached.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#69
post #17

Rule #1 about databases: It will be hacked. Rule #2: see rule #1

That would imply that security is irrelevant. Maybe you should re-work your rule the say that it will attempt to be hacked. Therefore you should always worry about security.

no, the goal is not to make it unhackable because its impossible but to make it really really costly/difficult to be hack.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#70
post #44
post #20

Earlier quoted context omitted.

seems very likely, wapo journo broke this and it's alluded to: https://wapo.st/2ItjHfW

The Register reported the Perceptics breach on May 23: https://www.theregister.co.uk/2019/05/23/perceptics_hacked_l...

Sorry I was unclear and linked to the wrong article, I meant that wapo journo poking around led to DHS & CBP responding on the record. It was one in the line of recent articles about facial recognition that travelers can opt-out of but nobody is sure how exactly you are supposed to do so. The wapo article I linked did attribute The Register info linking Perceptics. Both wapo articles are linked in this tweet: https://twitter.com/geoffreyfowler/status/113817627922244403...

> And on Monday, after I published this column online, Department of Homeland Security officials called me to disclose that photos of travelers were recently taken in a data breach, accessed through the network of one of its subcontractors.

Post reply on HN