Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

71–80 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#71
Can I play devils advocate here?

This is, of course, a serious breach and there will and should of course be consequences for the negligent parties

but

I am struggling to see the threat model being faced here.

biometric data is just a username. I flash my face around all day, and am careless as to where I leave my thumbprint.

The loss of so many photos and names is unlikely to have national level consequences (Compare this to say the Office Of Personnel management breach from some years back - that has horrible implications for US National security for decades) and the personal level consequences are ... hard to see

What this does underline is that we are outrageously careless as an industry with our data (comparable to early industrial "pollution" as Schneier points out). And it is not going to get better without a) career and business ending consequences b) new ways to store / secure data c) a new way of thinking about who owns and what is personal data

Personally I think we need a new form of intellectual property (just as we are trying to work out what kind of company FAANG are (not telcos, not newspapers, what is a platform?) we need to ask what is personal data

This comment is presumed under law to be my property, my copyright. I might license that property away (dunno never read HN T&Cs) but it is mine. But google and apple and others will track that I sat down at a certain time and place to write it, my ISP will see when I sent to which servers.

All of that data is also created by my conscious actions - should that data not also be my property. And if need be licensed - and compensated for its use?

And when (if) my data is held - then we should presume that it can be accessed by my agents for my benefit (from spending patterns to heart data). I would argue that Sometimes surveillance can be good for us - but only in ways similar to doctors knowing more about me can be good for me - the entire industry of medicine has individual interests at its heart and took a long time to get there.

We are heading in that direction (perhaps) but till we get there, carelessness will be the cheapest option, surveillance always bent agansit is (by state or other actors). We should rail against this stupid dumb breach, but punishing the "bad guys" is not even the first step on the road.

If I can make a bad analogy - It's not one incident that people got sick from one chef badly cooking chicken - it's we need to look at factory farming and meat consumption and healthy eating and marketing bias as a whole.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#73
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

They probably are doing some sort of critical service that can't be immediately stopped. That doesn't mean they will get contracts in the future or won't get legal action taken, but it takes time to review all that with the DOJ and decide how to proceed.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#74
post #17

Rule #1 about databases: It will be hacked. Rule #2: see rule #1

That would imply that security is irrelevant. Maybe you should re-work your rule the say that it will attempt to be hacked. Therefore you should always worry about security.

At a minimum, if something is secure by design, there's way less to worry about.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#75

Can I play devils advocate here? This is, of course, a serious breach and there will and should of course be consequences for the negligent parties but I am struggling to see the threat model being faced here. biometric data is just a username. I flash my face around all day, and am careless as to where I leave my thumbprint. The loss of so many photos and names is unlikely to have national level consequences (Compar…

>I am struggling to see the threat model being faced here.

We don't really know the full details of the breach, but if the facial recognition database contained names in a column associated with pictures, that data can absolutely be leveraged and cross-referenced against other "fullz" for fraud that even passes a lot of online verification procedures.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#76
post #59

Earlier quoted context omitted.

Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP. I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with…

Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be p…

This has come up a number of times and I semi-agree with you. It's definitely true that C-level positions do take a special kind of problem solving to navigate with a high emphasis on time management skills that other people (even upper management) can usually delegate up... That said, the only thing restricting new entrants into that market is the resistance of that market. The skills it takes to be a CEO of a multi-billion dollar company are certainly beyond me currently, but it's a skill I could train up to if I tried - especially if I had chosen to do so earlier in life. And these positions do come with a high amount of responsibility, buuut... they don't produce value for the company at all in line with their salaries and they're certainly not irreplaceable.

I don't hate management, I've worked for some great middle managers that have made my life easy - and for some terrible ones that constantly over-promised and pushed the weight down on us in the trenches. For upper management I've worked for three main veins of persons, the ones that micromanage and attempt to constantly invest themselves in every problem - leading to an inability to make good high level decisions... the sort that are removed from business by such an extent that they are unable to reason about direction decisions and fail to support a company's natural growth.. and those that are approachable but limited, who will voluntarily back out of any low level decision discussion but coordinate what decisions are being discussed and what those decisions mean for other portions of the company.

So mainly I'm rejecting your assumption that the pool is limited to begin with - people do come from famous families and waltz into the field with no prior experience, and those who try to work their way up tend to be stifled due to their lack of experience.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#78
post #59

Earlier quoted context omitted.

Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP. I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with…

Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be p…

I feel that your thesis is broken by definition: if there is such a small pool of people with this level of experience - so small that they are worth the money and are super difficult to replace - shouldn’t they have already made all their mistakes? Isn’t the board, by definition, paying for people who have a very high chance of making good decisions?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#79

Earlier quoted context omitted.

Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be p…

I feel that your thesis is broken by definition: if there is such a small pool of people with this level of experience - so small that they are worth the money and are super difficult to replace - shouldn’t they have already made all their mistakes? Isn’t the board, by definition, paying for people who have a very high chance of making good decisions?

> shouldn’t they have already made all their mistakes?

Is there some finite limit of mistakes that humans make over their lifetimes? In fact, it would be the opposite - those who are making more decisions are by definition likely to make more wrong decisions, as compared to someone who doesn't make as many decisions.

> Isn’t the board, by definition, paying for people who have a very high chance of making good decisions?

Yes, which is why the salaries for such positions are often so high.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#80
The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email.

Anyone think they approved the security of that subcontractor before giving sensitive information to them?

More importantantly, why is that type of data leaving CBP in the first place?

Post reply on HN