Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

121–130 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#121

The sad truth is Congress is the biggest offender of poor network security practices. Every time they bring in Equifax, DHS, etc to explain why they didn't practice basic IT security due diligence or due care I am reminded of the time smart people were hired to implement basic network security for Congress. Once they realized Joe in IT (who was hired to keep hackers out) can see Congressman Bob has a foot fetish, fis…

Not far off from what it turns out (after investigation) really happened![1] [1] https://en.m.wikipedia.org/wiki/Imran_Awan

> Not far off from what it turns out (after investigation) really happened![1]

> [1] https://en.m.wikipedia.org/wiki/Imran_Awan

I don't see how that link supports your conclusion? From my reading of it, no data was stolen by Imran Awan?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#122

The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email. Anyone think they approved the security of that subcontractor before giving sensitive information to them? More importantantly, why is that type of data leaving CBP in the first place?

> Anyone think they approved the security of that subcontractor before giving sensitive information to them? They almost certainly did, actually. FIPS [1] and FISMA [2] are pretty strict requirement for every company contracting with a government agency. IMO it's one of the rare situations where, at least conceptually, the federal government has done something right in terms of security. Now whether FIPS/FISMA, and t…

If Fedramp is like other security certifications, written policies can be used in lieu of actual enforcement.

A policy could be something like:

"Vendor shall not move sensitive data out of CBP's secure network"

So it's pretty much on the honor system. And some new employee at the vendor may not even be aware of all of the policies they are supposed to be following. The vendor is still reponsible for that employees actions, but it can be discovered too late (as in this case, the breach was already made)

But instead of just a written policy (among dozens or hundreds of others) that people are expected to abide by, this could be enforced by limiting the vendor's access to the network. For example, by counting how many records they access, how many bytes of data they download over their connection to the secure network, or not giving them direct access at all and exposing only an API controlled be CBP that gives them access to only the data they require)..

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#123

Earlier quoted context omitted.

Given that the contractor violated the data handling rules in their contract, the only possible remedy is revocation of their facility security clearance, followed immediately by revocation of the personnel security clearances of everyone who claimed that these systems were operating in accordance with their SSPs. I'd like to believe that this will happen, but I've seen plenty of cause for FSCs to be revoked and almo…

And remunerations for all citizens that were affected in the form of cash payments.

Nah, Americans can be subject to their own laws, they were voted for. I'd go for remunerations for non-US citizens who had no choice in the matter (e.g. by being sent to the US for work.) Maybe see us as a bit more equal.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#124

I’ll just keep saying this, and getting dismissed by everyone I know - any data security discussion around a centralized data store that doesn’t begin with the recognition that that data store will be compromised, is a discussion that is just a joke.

You and a whole bunch of other people making the same extremely basic observation. It would be good if you would suggest some alternative strategies, since 'don't bother keeping that data' isn't a realistic option in this context.

I’m not sure why you’re being downvoted; I think it’s a fair comment. My response is that I’m honestly not sure what the best response is. But if we start with insecurity as a given, then I feel like we could at least be exploring better alternatives around... people storing data locally and always providing it for every interaction? Maybe.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#125
Just another reminder that there is no accountability left in America, and you reap what you sow. If you want a society that is accountable, you need to start with a culture that values honor and takes shame seriously. You can’t impose a sense of honor from the outside without building it slowly from within, any more than you can impose respect without earning it.

If you ignore these principles, you make room for people who lack self-worth, and those are the most destructive forces in a society because they have nothing to lose.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#126

You can outsource work, you can't outsource responsibility. It will likely be a long time before the various powers that be really get this.

Isn't monetary liability a form of "outsourced responsibility"? I'm not understanding why damages from lawsuits are not sufficiently motivating the industry to take data breaches seriously. Maybe they just aren't awarding enough damages to change behavior?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#127
post #117

Earlier quoted context omitted.

We don't necessarily have a functioning representative democracy, though - too much power is held by lobbyists, the fact that politicians can lie to the population, and the fact that our votes don't 1:1 elect officials due to gerrymandering and voter suppression.

Too much power is given to money and wealth. This has held true for thousands of years in Western civilisation (back in Ancient Greece, wealth was measured by output, the Pentekosiomedimnoi being the aristocrats). The whole setup seems more and more like a grand cash grab.

It's actually mostly just pure laziness.

https://history.house.gov/Historical-Highlights/1901-1950/Th...

The Permanent Apportionment Act of 1929 was enacted because it was "too hard" for Congress to rezone/redistribute House of Representative members. This measure, and ones like it both in law and in business, create large bureaucratic organizations that move slowly and are prized for their stability, which is another word for "zero accountability or disruption."

Very few people set out to have growing inequality of resources or to amass power for the sake of doing it, though of course the people in power now seek to keep it for the sole reason of not wanting to lose it (they frame it as "too big to fail," "stability is important," and so forth).

It's just pure inertia. We went away from smaller regional governments that reports up to a lightly-empowered federal one with a lot of individual liberty step by step, for convenience and for "safety" (any number of military or police actions, foreign and domestic), and we get what we deserve.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#128

The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email. Anyone think they approved the security of that subcontractor before giving sensitive information to them? More importantantly, why is that type of data leaving CBP in the first place?

> Anyone think they approved the security of that subcontractor before giving sensitive information to them? They almost certainly did, actually. FIPS [1] and FISMA [2] are pretty strict requirement for every company contracting with a government agency. IMO it's one of the rare situations where, at least conceptually, the federal government has done something right in terms of security. Now whether FIPS/FISMA, and t…

Most of these are so called "paper security", while some real technical vulnerabilities can effectively crash all these fictional barriers.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#129
Same story that is also trending on the HN homepage right now... My comment from that story which is from (https://www.buzzfeednews.com/article/daveyalba/the-us-govern...):

Quote from the article: “There should never have been the ability to download a database like this off of government servers.”

Sorry that I don't have a ton of links to support this claim, but "believe me" (as our Commander-in-chief would say) that the US Government would cease to function if it were not for subcontractors (read, private companies) performing tasks on behalf of the government. Personally, I don't agree with this way of our government doing business, but that is the way it is.

When I was in college, I worked for an archeology lab, and our lab was the subcontractor, of the subcontractor, of the contractor that had contracted to provide a service to the USACE (US Army Corps of Engineers). And every way along the way, money was skimmed off of the top. It's just "the American way" of doing business.

People lament regulation all the time. I have a feeling the executives of Ingersoll Rand love it every time a new regulation is put into place.

Follow the money.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#130

The government is never held accountable for mistakes they make. They are, in fact, too big to fail.

> The government is never held accountable for mistakes they make. In a functioning democracy "they" is "us".

> In a functioning democracy "they" is "us".

That notion is generally not in keeping with the western common-law tradition, which holds a more skeptical view of governments which have the moral authority to operate within any domain and with any powers so long as they can connect those powers to the consent of the governed.

Instead, the tradition of the United States, for example, is that government power is limited and enumerated and does not change no matter what "us" may say about it in the form of political elections.

I suggest that you read (just an example) Federalist 10 by James Madison and consider how thoroughly these guys thought through the argument you are making about democracy and how hard they tried to make something better.

And none of this is to amount to founder worship: we can all see now that there was tremendous hypocrisy in founding a nation which didn't categorically prohibit slavery from the get-go. And in fact, slavery continues to this day in the form of a prison system that "us" has occasionally been happy to endorse, the rights of the incarcerated be damned.

All I'm saying is: don't tout democracy in such simplistic terms without also considering the arguments of its critics.

Post reply on HN