Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

181–190 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#181
post #77

The only way to prevent hackers from getting access to databases that contain our names, picture, and license plate number - is to never create such a database.

Single points of failure via centralization, comparable to monoculture in farming

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#182

Earlier quoted context omitted.

You and a whole bunch of other people making the same extremely basic observation. It would be good if you would suggest some alternative strategies, since 'don't bother keeping that data' isn't a realistic option in this context.

sure it is! you don't need to keep a centralized photo db of every person who enters your country all in one place, even to build ML models on. This could have been federated in a variety of ways that would've reduced a breach risk. Or, we could avoid building a massive surveillance network that doesn't help make our world better.

I'm not arguing for centrality, but how do you see this actually working? People submit photographs when they make visa applications, so how are you going to store that?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#183
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

I'd expect at least huge fine and re-evaluation of the whole contract (it could be they are unique provider that can not be replaced, but more likely there are other options). Looks like causing private data of hundred thousands of people to be stolen is regarded as a minor thing not worthy of real punishments.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#184

Earlier quoted context omitted.

Part of my job is designing software that is resistant to amplification once the hacker is already in, so maybe I can help here. When you plan your security, step 1 is making it hard to get in, step 2 is making it hard to persist, i.e. plant a command and control process somewhere inside the perimeter, and to move laterally in the system, i.e. get from one service into a more important service. There's some basic stu…

One of my favorite Hacktober tricks was putting an alias around SSH on the developers machine, so the next time they used 2FA to get into a remote host I would drop a note into their MOTD (to prove persistence). That short-lived SSH token would be enough to install persistence. So obviously, your payment hosts should be very wary of things like port forwarding over SSH, and any unknown outbound traffic.

Yup, at some point it just becomes an arms race.

The fundamental imbalance in such an arms race is that the tech giant might have countermeasures that would prevent the SSH alias from working (my team does), but the level of paranoia required to get those countermeasures in place is beyond what a bank could effectively implement. This particular battle disproportionately favors the red team.

And that's not to say that my team has everything covered. The red team consistently manages to find forehead slapping holes in our defenses. There's just too much surface area to cover.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#185
post #35

Earlier quoted context omitted.

“In the private sector” covers a lot of ground and I have extreme skepticism about your faith in the process unfolding that way: ask yourself how many breaches you’ve been part of and whether anything more than a press release happened along with waiting for the news to die down. How many customers did Experian lose? (In the enterprise software world, I can tell you how epic failure to perform on an 8+ figure contrac…

> How many customers did Experian lose? Experian didn't lose any customer data, though. They only lost data on their products. Their actual customers had no reason to stop paying for their services.

Some of these https://krebsonsecurity.com/tag/experian-breach/ look like Experian is leaking like a sieve, or am I missing something?

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#186

Earlier quoted context omitted.

Correct me if I'm being overly cynical, but this is an oft-repeated truism that is as useless as "the only winning move is not to play." It's technically the truth, but what are we supposed to do, revert all information systems to non-electronic media? What is the intended takeaway from this statement? If anything, it absolves data security efforts of responsibility by pointing out that there's always a chance of dat…

1. Do not collect unnecessary information. 2. Delete information after use.

Reasonable GDPR

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#187

Earlier quoted context omitted.

Correct me if I'm being overly cynical, but this is an oft-repeated truism that is as useless as "the only winning move is not to play." It's technically the truth, but what are we supposed to do, revert all information systems to non-electronic media? What is the intended takeaway from this statement? If anything, it absolves data security efforts of responsibility by pointing out that there's always a chance of dat…

1. Do not collect unnecessary information. 2. Delete information after use.

This will only happen when information becomes a liability.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#188
post #77

The only way to prevent hackers from getting access to databases that contain our names, picture, and license plate number - is to never create such a database.

Correct me if I'm being overly cynical, but this is an oft-repeated truism that is as useless as "the only winning move is not to play." It's technically the truth, but what are we supposed to do, revert all information systems to non-electronic media? What is the intended takeaway from this statement? If anything, it absolves data security efforts of responsibility by pointing out that there's always a chance of dat…

The objective afaiu was to expedite entry into the country by creating a database of faces and personal identity information. And that's a great objective.

But often the risk of personal harm outweighs the benefits. And in the case of digital assets the question is when, not if this personal data will be exfiltrated. And when it is, that is often more inconvenient than any potential convenience benefits.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#189

Earlier quoted context omitted.

> How many customers did Experian lose? Experian didn't lose any customer data, though. They only lost data on their products. Their actual customers had no reason to stop paying for their services.

Some of these https://krebsonsecurity.com/tag/experian-breach/ look like Experian is leaking like a sieve, or am I missing something?

Experian makes its money selling credit checks to banks and other businesses. You're not their customer, you're their product.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#190
post #59

Earlier quoted context omitted.

Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP. I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with…

Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be p…

> If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be people that have very limited experience making executive decisions, and the usual explanations proffered by the "we hate management" crowd - of nepotism, insiderism, back-scratcher-ism - are more likely valid.

If we revert from "involved in a controversy" back to "has demonstrated extreme incompetence", your argument carries less weight. We can at least say that the inexperienced new guys haven't been tested and found wanting. The

Post reply on HN