It's time to admit that computers connected to the internet can not be secured. Even if the entire operating system is vetted and locked down, and only vetted and audited apps are run on the system, there will always be zero day exploits. Science has come up with no possible way to provably secure network connected computers. So do not trust them any more. Please prove me wrong, but I doubt you can. The most trusted…
>It's time to admit that computers connected to the internet can not be secured. That ship sailed a long time ago. It was normal back in the 1990s for InfoSec folk to assume that "if it's connected to the Internet, eventually, it will be compromised." The goal (then, as now) is to implement layered (defense-in-depth) mechanisms to deter such activities -- at perimeters, network and systems infrastructure platforms an…
The reasons you list for a weak defense posture don't really apply to a government. Also the GAO has issued a constant stream of reports saying US government agencies have poor security. It was likely only a matter of time before something like this incident happened. Similarly it's probably only a matter of time until the IRS, Social Security, and other agencies are successfully attacked on a large scale.