Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

101–110 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#102

The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email. Anyone think they approved the security of that subcontractor before giving sensitive information to them? More importantantly, why is that type of data leaving CBP in the first place?

Compliance with NIST SP 800-53 is mandatory per statute and DHS policy. That system has an identified ISSO, ISSM, ISSPM, DAO, and AO who are responsible for authority to operate being given. If the paperwork is in place, a government employee signed off on that network's operation. If not, it doesn't have ATO and there's a government employee (the AO or CIO) responsible for allowing a such a network to be connected to government systems and store government-controlled information.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#103

The government is never held accountable for mistakes they make. They are, in fact, too big to fail.

> The government is never held accountable for mistakes they make. In a functioning democracy "they" is "us".

In one that is not too large to fail, I'd agree. We have a monolithic government that has been going away from "they" since the state restricted the size of the House of Representatives and have shifted more and more responsibility and power to the federal branch.

It's no different than the same moral hazard large corporations face that we empower through cronyism and the effects are obvious, notably events leading up to the great financial crisis in the late 2000s.

Large institutions not held accountable get to take outsized risks knowing they'll always be bailed out and not held accountable. This article is one of many examples of such.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#104

This is yet another reminder that managing the security of your company's third party contractors is just as important as managing your own company's security. Security is a game of weakest links, and it wouldn't have mattered if CBP's internal security was the best in the world if they were allowing access to a third party that doesn't have good security. It is naturally very difficult to enforce security mandates o…

> requiring that everyone they do business with have a strong, independently certified security program

As a start how about requiring ISO 2700x security certification?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#105

The government is never held accountable for mistakes they make. They are, in fact, too big to fail.

> The government is never held accountable for mistakes they make. In a functioning democracy "they" is "us".

We don't necessarily have a functioning representative democracy, though - too much power is held by lobbyists, the fact that politicians can lie to the population, and the fact that our votes don't 1:1 elect officials due to gerrymandering and voter suppression.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#106

The photos were transferred to a subcontractor’s network and later stolen through a “malicious cyberattack,” a CBP spokesperson told TechCrunch in an email. Anyone think they approved the security of that subcontractor before giving sensitive information to them? More importantantly, why is that type of data leaving CBP in the first place?

> Anyone think they approved the security of that subcontractor before giving sensitive information to them?

They almost certainly did, actually. FIPS [1] and FISMA [2] are pretty strict requirement for every company contracting with a government agency. IMO it's one of the rare situations where, at least conceptually, the federal government has done something right in terms of security.

Now whether FIPS/FISMA, and the people enforcing it, actually have any teeth or effectiveness is a different topic entirely.

1: https://en.wikipedia.org/wiki/Federal_Information_Processing...

2: https://en.wikipedia.org/wiki/Federal_Information_Security_M...

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#108
post #60

According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…

Indeed. CBP made the choice to subcontract w/o proper controls. It is still CBP's fault.

> made the choice to subcontract w/o proper controls

seems to have worked out very well for the army, and their contractors.

So well in fact, that a senator is on a campaign to pass legislation to specifically address the military case (leaving cases like the CBP which should be as obvious as from the get go, to be dealt individually too). The system is so broken in its lack of accountability that even well intentioned people are driven to insanity as the norm.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#109
post #94
post #89

Earlier quoted context omitted.

Government agencies should never be seen as victims. That's a weird absolute, and that's before the side dish of theology and... Spiderman? You can be powerful or negligent or whatnot and still be a victim.

In this case, CBP is collecting this data without the direct consent of _the people_, so who in this case is accountable? It's not _the people_ who made the decision to collect this data.

You can bear responsibility for something and still be a victim. It's really bizarre to suggest this is somehow not the case and to try to support that point with deities, comics and a call for GDPR legislation (for US federal agencies?). This kind of comment is the Markov chain with which threads are anchored to the bottom of the Abyss of Meaninglessness.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#110

Earlier quoted context omitted.

Given that the contractor violated the data handling rules in their contract, the only possible remedy is revocation of their facility security clearance, followed immediately by revocation of the personnel security clearances of everyone who claimed that these systems were operating in accordance with their SSPs. I'd like to believe that this will happen, but I've seen plenty of cause for FSCs to be revoked and almo…

And remunerations for all citizens that were affected in the form of cash payments.

S/citizens/Anyone/
Post reply on HN