> “Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract,” the statement read. Could this lead to criminal charges? Perhaps charging the contractor under CFAA for unauthorized access?
US Customs Database Of Traveler Photos Was Hacked And Stolen
91–100 of 207 posts
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#92Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#93According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…
This is incorrect. They can absolve themselves of liability an act with impunity.
You and I might not like that, but it is fact.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#94According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…
Government agencies should never be seen as victims. That's a weird absolute, and that's before the side dish of theology and... Spiderman? You can be powerful or negligent or whatnot and still be a victim.
It's not _the people_ who made the decision to collect this data.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#95The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email. Anyone think they approved the security of that subcontractor before giving sensitive information to them? More importantantly, why is that type of data leaving CBP in the first place?
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#96I’ll just keep saying this, and getting dismissed by everyone I know - any data security discussion around a centralized data store that doesn’t begin with the recognition that that data store will be compromised, is a discussion that is just a joke.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#97According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…
Indeed. CBP made the choice to subcontract w/o proper controls. It is still CBP's fault.
I'd like to believe that this will happen, but I've seen plenty of cause for FSCs to be revoked and almost no FSC revocations.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#98Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#99Earlier quoted context omitted.
Indeed. CBP made the choice to subcontract w/o proper controls. It is still CBP's fault.
Given that the contractor violated the data handling rules in their contract, the only possible remedy is revocation of their facility security clearance, followed immediately by revocation of the personnel security clearances of everyone who claimed that these systems were operating in accordance with their SSPs. I'd like to believe that this will happen, but I've seen plenty of cause for FSCs to be revoked and almo…
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#100I’ll just keep saying this, and getting dismissed by everyone I know - any data security discussion around a centralized data store that doesn’t begin with the recognition that that data store will be compromised, is a discussion that is just a joke.