Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

51–60 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#51

Earlier quoted context omitted.

That would imply that security is irrelevant. Maybe you should re-work your rule the say that it will attempt to be hacked. Therefore you should always worry about security.

I'm with OP here. You just shouldn't have unencrypted, sensitive data in a database.

I kind of think you've misunderstood something. This person said "You will be hacked". A guaranteed absolute. If that were the case then why bother protecting anything?

His wording was misleading. Not his intentions. Nobody is in disagreement that security is very important.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#52
post #35
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

“In the private sector” covers a lot of ground and I have extreme skepticism about your faith in the process unfolding that way: ask yourself how many breaches you’ve been part of and whether anything more than a press release happened along with waiting for the news to die down. How many customers did Experian lose? (In the enterprise software world, I can tell you how epic failure to perform on an 8+ figure contrac…

I don't have _much_ experience with this but when I worked for a UK based e-commerce SaaS provider (which was focused on image, so, ymmv) we completely buried a contractor for using sub-contractors which didn't follow our data security standards (which the contractor knew about).

a breach wasn't found, but that contracting company eventually became bankrupt under the weight of our negative press and litigation. I know that this is essentially bullying but it was used as an example to other contractors who might try something like that.

Incidentally the SaaS provider no longer exists, gobbled up by netsuite (which was, itself, acquired by Oracle).

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#53
post #37
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

> In the private sector, they'd have been fired and probably legal action levelled against them Tell me again one meaningful action against a data leak in the private sector. I'll wait.

Don't you remember how Equifax was hacked into and their stock price briefly dropped? Then they were burdened with all those email addresses people entered to check their credit... And they had to pay the ultimate price by spamming those addresses constantly with advertisements, and that's not cheap!

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#54

Earlier quoted context omitted.

I'm with OP here. You just shouldn't have unencrypted, sensitive data in a database.

I kind of think you've misunderstood something. This person said "You will be hacked". A guaranteed absolute. If that were the case then why bother protecting anything? His wording was misleading. Not his intentions. Nobody is in disagreement that security is very important.

I disagree, his wording was pretty spot on. Don't collect personal data - it will be hacked. At many of the businesses I've worked at I've made an effort to lower our PII data blob purely to reduce liability for when it was compromised. If you can see some information, a hacker eventually will.

Granted, lowering liability is apparently something I shouldn't worry about since no one is ever held to account for breaches these days.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#55
post #37
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

> In the private sector, they'd have been fired and probably legal action levelled against them Tell me again one meaningful action against a data leak in the private sector. I'll wait.

The issue in question isn't so much the breach, but the misuse of data by the subcontractor. I've personally witnessed people be fired for this, and know of lawsuits that exist for this specifically, and that's just at the company I work for...

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#56
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

Sounds like pretty standard PR legalese to me. I guarantee that the same is going to happen to the subcontractor (after a lengthy investigation, to be sure), but it's bad practice to go throwing around public legal threats, especially for the government which likely has a multi-hundred page contract with these people, and especially at such an early point in any investigations going on.

This is unless the corruption includes those who are managing the subcontractor identified. In which case, the subcontractor is blacklisted and the people responsible move onto another company (ie, Initrode vs. Initech).

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#57
post #17

Rule #1 about databases: It will be hacked. Rule #2: see rule #1

That would imply that security is irrelevant. Maybe you should re-work your rule the say that it will attempt to be hacked. Therefore you should always worry about security.

That's absurd. This statement is exactly why we use algorithms like bcrypt to store passwords. If we could be confident that our database wouldn't be hacked, we could just store passwords in plain text and save a whole lot of CPU cycles.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#58
post #53
post #37

Earlier quoted context omitted.

> In the private sector, they'd have been fired and probably legal action levelled against them Tell me again one meaningful action against a data leak in the private sector. I'll wait.

Don't you remember how Equifax was hacked into and their stock price briefly dropped? Then they were burdened with all those email addresses people entered to check their credit... And they had to pay the ultimate price by spamming those addresses constantly with advertisements, and that's not cheap!

And as a free service, I can now have them email me whenever my credit score changes, so I can log in and see that I fluctuate up and down 2 points routinely for "algorithm changes". Take that, Experian!

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#59
post #56

Earlier quoted context omitted.

Sounds like pretty standard PR legalese to me. I guarantee that the same is going to happen to the subcontractor (after a lengthy investigation, to be sure), but it's bad practice to go throwing around public legal threats, especially for the government which likely has a multi-hundred page contract with these people, and especially at such an early point in any investigations going on.

This is unless the corruption includes those who are managing the subcontractor identified. In which case, the subcontractor is blacklisted and the people responsible move onto another company (ie, Initrode vs. Initech).

Yea, that's one of the more disturbing modern trends - especially at the C-level, once someone is in that cloud they tend to just rotate jobs consequence free... and maybe occasionally run for president after doing their best to bankrupt HP.

I agree that an individual unfairly blamed by a company for their failure should be able to move on with their life but... we've seen plenty of clearly guilty people get out with a golden parachute and turn to serving on the board of directors of companies for the ridiculous sum that tends to net you.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#60
According to the report, CBP is passing the buck on this one.

They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence).

Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to hold them to account because the electorate had already been subverted to maintain their position. So they should not be protected from fucking up. In this context, God or the Lord is not a higher power, it is also a scapegoat.

With great power comes everybody else’s responsibility... said only by people in this century.

Edit: to follow this up, CBP is also the agency that sucks up all the data on your phone and laptop. They have treasure troves of license plates, passport photos, and titty and dick pics.

They cannot absolve themselves of liability when they are invading everybody’s privacy. If they say they don’t use the data, and they are acting out of ignorance, then that’s a solid case for not collecting it in the first place.

As it stands, the US needs a GDPR.

Post reply on HN