The only way to prevent hackers from getting access to databases that contain our names, picture, and license plate number - is to never create such a database.
US Customs Database Of Traveler Photos Was Hacked And Stolen
181–190 of 207 posts
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#182Earlier quoted context omitted.
You and a whole bunch of other people making the same extremely basic observation. It would be good if you would suggest some alternative strategies, since 'don't bother keeping that data' isn't a realistic option in this context.
sure it is! you don't need to keep a centralized photo db of every person who enters your country all in one place, even to build ML models on. This could have been federated in a variety of ways that would've reduced a breach risk. Or, we could avoid building a massive surveillance network that doesn't help make our world better.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#183> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#184Earlier quoted context omitted.
Part of my job is designing software that is resistant to amplification once the hacker is already in, so maybe I can help here. When you plan your security, step 1 is making it hard to get in, step 2 is making it hard to persist, i.e. plant a command and control process somewhere inside the perimeter, and to move laterally in the system, i.e. get from one service into a more important service. There's some basic stu…
One of my favorite Hacktober tricks was putting an alias around SSH on the developers machine, so the next time they used 2FA to get into a remote host I would drop a note into their MOTD (to prove persistence). That short-lived SSH token would be enough to install persistence. So obviously, your payment hosts should be very wary of things like port forwarding over SSH, and any unknown outbound traffic.
The fundamental imbalance in such an arms race is that the tech giant might have countermeasures that would prevent the SSH alias from working (my team does), but the level of paranoia required to get those countermeasures in place is beyond what a bank could effectively implement. This particular battle disproportionately favors the red team.
And that's not to say that my team has everything covered. The red team consistently manages to find forehead slapping holes in our defenses. There's just too much surface area to cover.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#185Earlier quoted context omitted.
“In the private sector” covers a lot of ground and I have extreme skepticism about your faith in the process unfolding that way: ask yourself how many breaches you’ve been part of and whether anything more than a press release happened along with waiting for the news to die down. How many customers did Experian lose? (In the enterprise software world, I can tell you how epic failure to perform on an 8+ figure contrac…
> How many customers did Experian lose? Experian didn't lose any customer data, though. They only lost data on their products. Their actual customers had no reason to stop paying for their services.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#186Earlier quoted context omitted.
Correct me if I'm being overly cynical, but this is an oft-repeated truism that is as useless as "the only winning move is not to play." It's technically the truth, but what are we supposed to do, revert all information systems to non-electronic media? What is the intended takeaway from this statement? If anything, it absolves data security efforts of responsibility by pointing out that there's always a chance of dat…
1. Do not collect unnecessary information. 2. Delete information after use.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#187Earlier quoted context omitted.
Correct me if I'm being overly cynical, but this is an oft-repeated truism that is as useless as "the only winning move is not to play." It's technically the truth, but what are we supposed to do, revert all information systems to non-electronic media? What is the intended takeaway from this statement? If anything, it absolves data security efforts of responsibility by pointing out that there's always a chance of dat…
1. Do not collect unnecessary information. 2. Delete information after use.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#188The only way to prevent hackers from getting access to databases that contain our names, picture, and license plate number - is to never create such a database.
Correct me if I'm being overly cynical, but this is an oft-repeated truism that is as useless as "the only winning move is not to play." It's technically the truth, but what are we supposed to do, revert all information systems to non-electronic media? What is the intended takeaway from this statement? If anything, it absolves data security efforts of responsibility by pointing out that there's always a chance of dat…
But often the risk of personal harm outweighs the benefits. And in the case of digital assets the question is when, not if this personal data will be exfiltrated. And when it is, that is often more inconvenient than any potential convenience benefits.
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#189Earlier quoted context omitted.
> How many customers did Experian lose? Experian didn't lose any customer data, though. They only lost data on their products. Their actual customers had no reason to stop paying for their services.
Some of these https://krebsonsecurity.com/tag/experian-breach/ look like Experian is leaking like a sieve, or am I missing something?
Re: US Customs Database Of Traveler Photos Was Hacked And Stolen
#190Earlier quoted context omitted.
Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP. I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with…
Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be p…
If we revert from "involved in a controversy" back to "has demonstrated extreme incompetence", your argument carries less weight. We can at least say that the inexperienced new guys haven't been tested and found wanting. The