Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

91–100 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#91

> “Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract,” the statement read. Could this lead to criminal charges? Perhaps charging the contractor under CFAA for unauthorized access?

Only if the contractor was not meant to have access to this data. I would put money on them being contracted to "securely manage" the data CBP accrued without consent.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#93
post #60

According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…

> They cannot absolve themselves of liability when they are invading everybody’s privacy.

This is incorrect. They can absolve themselves of liability an act with impunity.

You and I might not like that, but it is fact.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#94
post #89
post #60

According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…

Government agencies should never be seen as victims. That's a weird absolute, and that's before the side dish of theology and... Spiderman? You can be powerful or negligent or whatnot and still be a victim.

In this case, CBP is collecting this data without the direct consent of _the people_, so who in this case is accountable?

It's not _the people_ who made the decision to collect this data.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#95

The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email. Anyone think they approved the security of that subcontractor before giving sensitive information to them? More importantantly, why is that type of data leaving CBP in the first place?

At best, ads. At worst, ...

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#96

I’ll just keep saying this, and getting dismissed by everyone I know - any data security discussion around a centralized data store that doesn’t begin with the recognition that that data store will be compromised, is a discussion that is just a joke.

You and a whole bunch of other people making the same extremely basic observation. It would be good if you would suggest some alternative strategies, since 'don't bother keeping that data' isn't a realistic option in this context.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#97
post #60

According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…

Indeed. CBP made the choice to subcontract w/o proper controls. It is still CBP's fault.

Given that the contractor violated the data handling rules in their contract, the only possible remedy is revocation of their facility security clearance, followed immediately by revocation of the personnel security clearances of everyone who claimed that these systems were operating in accordance with their SSPs.

I'd like to believe that this will happen, but I've seen plenty of cause for FSCs to be revoked and almost no FSC revocations.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#99

Earlier quoted context omitted.

Indeed. CBP made the choice to subcontract w/o proper controls. It is still CBP's fault.

Given that the contractor violated the data handling rules in their contract, the only possible remedy is revocation of their facility security clearance, followed immediately by revocation of the personnel security clearances of everyone who claimed that these systems were operating in accordance with their SSPs. I'd like to believe that this will happen, but I've seen plenty of cause for FSCs to be revoked and almo…

And remunerations for all citizens that were affected in the form of cash payments.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#100

I’ll just keep saying this, and getting dismissed by everyone I know - any data security discussion around a centralized data store that doesn’t begin with the recognition that that data store will be compromised, is a discussion that is just a joke.

Why does decentralization save you from compromise?
Post reply on HN