Live data from Hacker News

US Customs Database Of Traveler Photos Was Hacked And Stolen

buzzfeednews.com

81–90 of 207 posts

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#81

Can I play devils advocate here? This is, of course, a serious breach and there will and should of course be consequences for the negligent parties but I am struggling to see the threat model being faced here. biometric data is just a username. I flash my face around all day, and am careless as to where I leave my thumbprint. The loss of so many photos and names is unlikely to have national level consequences (Compar…

>I am struggling to see the threat model being faced here. We don't really know the full details of the breach, but if the facial recognition database contained names in a column associated with pictures, that data can absolutely be leveraged and cross-referenced against other "fullz" for fraud that even passes a lot of online verification procedures.

I agree that we don't know what was lost, and it could easily be waaay worse than I imagine

But this kind of comes back to my point - why do we have online verification systems that rely on things like knowing my address in the last three years - Equifax breach should have meant we gave up on using a credit risk scoring system as an identity provider.

But we don't.

We need to rethink what is identity (start with web of trust) and who owns data that links to that identity.

I mean this could be the start of a positive identity provider - grab that downloaded database and provide a system that says this is a picture of Paul Brian's face, and his passport, and on the 20th August last year a official of the US government compared them in real life and verified they matched (there may even be a hash of the digital images made at the time but I should not get my hopes up)

Now make that globally available. Is that useful and valuable - I think so. I would prefer if I had been able to upload my public key to that at the same time (I can always visit NYC again) but you get the idea. This leads to question like why does my passport not generate a key pair for me to use? Can I use facial recognition to match my gravatar / facebook / twitter ? Why is knowing a non-secret (mother's maiden name, passport or drivers license number, three digits on back of credit card) seen as security?

Why is it we use what we have to hand and not what is needed? Why don't american banks use chip and pin?

It's not bad that my online identity is clear and visible - as long as the legal and practical frameworks exist to support it - which they basically don't right now but we could make it happen

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#82
post #9

> On May 31, 2019, CBP learned that a subcontractor, in violation of CBP policies and without CBP’s authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor’s company network > CBP ... is closely monitoring all CBP work by the subcontractor What. In the private sector, they'd have been fired and probably legal action levelled against them. Th…

Ha. In the private sector, we discovered a vendor was using an actually health database with real users in it for testing their app. It was all covered up, with no monitoring, because we recently bought that vendor.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#83
post #76

Earlier quoted context omitted.

Playing devil's advocate (and this is likely to be downvoted by the "we hate all management" crowd on HN), but the reality is that there isn't exactly a very large pool of people who have experience running/directing multi-billion dollar companies. If you start blacklisting every single C-level that was ever involved in a controversy, the only choices you're going to have for your board of directors are going to be p…

This has come up a number of times and I semi-agree with you. It's definitely true that C-level positions do take a special kind of problem solving to navigate with a high emphasis on time management skills that other people (even upper management) can usually delegate up... That said, the only thing restricting new entrants into that market is the resistance of that market. The skills it takes to be a CEO of a multi…

I'm not sure I agree with your first paragraph. I mean no disrespect to you or your abilities, but being a C-level executive, especially in a large corporation, isn't something that someone can just "train up to". These types of positions really do require a specific personality, specific desires, often a specific ethic (work ethic and otherwise), specific connections, and more. These are the things, along with the fact that due to organizational hierarchy, there are naturally less CEOs in the world than there are entry level workers, that limit the pool.

I'm certainly not saying that all C-levels possess these necessary traits in a positive way, and there are definitely some C-levels that only got where they are because of nepotism or luck, but I also disagree that there is a significant 'stifling' of newcomers. Nearly every company I have worked at has had a specific "track" for its employees to pursue management (including C level) positions, but my experience is that most people just aren't cut out for it (either because they self-selected that they didn't want/enjoy it, or because they didn't have the necessary personality for it). More specific to the tech industry, I've often seen/heard of Silicon Valley companies having separate "Individual Contributor" versus "Management" tracks. Many engineers self-select the IC track because they don't enjoy management aspects.

And that's not necessarily a bad thing, either. Not everyone is destined to be a CEO, nor should that be everyone's goal, and there's definitely nothing wrong with not being a possessor of the negative-in-many-aspects cutthroat ethics that being a CEO often requires. It's not all too dissimilar to how not everyone is destined to be a programmer, and you can't take just anyone off the street, hand them a programming textbook, and turn them into Linus Torvalds, nor should you.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#86
I’ll just keep saying this, and getting dismissed by everyone I know - any data security discussion around a centralized data store that doesn’t begin with the recognition that that data store will be compromised, is a discussion that is just a joke.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#87
post #36

Earlier quoted context omitted.

Only politically connected companies, if you and I ran a business like that the outcome would have been different. The state has no problem going after small businesses.

The problem is that once you’re over a very low level all companies will be politically connected: those are jobs in someone’s district!

Yeah, no. If you only had to be a medium sized business owner to access that kind of corruption the world would be a much fairer place.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#88

If only someone could have seen this coming, you know, outside of the thousands of people that saw this coming. This is just one of many reasons why mass surveillance is a terrible.

Why is it terrible. Sure this has the potential to have negative consequences for the people who's data it was but as far as the government cares it's working fine.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#89
post #60

According to the report, CBP is passing the buck on this one. They created policies that could be ignored. That’s on them. They shouldn’t be able to use their position to avoid accountability or to scapegoat their contractors (that they likely hired without due diligence). Government agencies should never be seen as victims. They hold power and authority that nobody else can hope to enjoy. There is no higher power to…

Government agencies should never be seen as victims.

That's a weird absolute, and that's before the side dish of theology and... Spiderman? You can be powerful or negligent or whatnot and still be a victim.

Re: US Customs Database Of Traveler Photos Was Hacked And Stolen

#90
post #52
post #35

Earlier quoted context omitted.

“In the private sector” covers a lot of ground and I have extreme skepticism about your faith in the process unfolding that way: ask yourself how many breaches you’ve been part of and whether anything more than a press release happened along with waiting for the news to die down. How many customers did Experian lose? (In the enterprise software world, I can tell you how epic failure to perform on an 8+ figure contrac…

I don't have _much_ experience with this but when I worked for a UK based e-commerce SaaS provider (which was focused on image, so, ymmv) we completely buried a contractor for using sub-contractors which didn't follow our data security standards (which the contractor knew about). a breach wasn't found, but that contracting company eventually became bankrupt under the weight of our negative press and litigation. I kno…

There's pretty strong selection bias in information about data security standards. The companies that have strong ones will go out of their way to publicize that fact, but companies with weak or nonexistent ones will never admit that fact to the general public or news media, and the only thing you may hear about it is when disenchanted employees make anonymous posts on web forums.

If a company with weak data-protection standards wins out over a company with strong ones, it's never because of their lack of data-protection standards. Rather, it'll be because all the other features, pricing, marketing, etc. they can do that's the opportunity cost of decent security. So as far as the information available to laypeople is concerned, most companies do a decent job with security and it's just a few bad apples that happen to be gigantic like Equifax, Facebook, Target, Yahoo, Anthem, and the U.S. government that are screwing things up.

(FWIW, at Google we took security very seriously and implemented some truly heroic measures to keep your data safe.)

Post reply on HN