Slashdot Mirror


U.S. Service Personnel Data Stolen

BStrunk writes "I was reading the news this morning on Reuters, when I stumbled across this article: U.S. Service Personnel Personal Data Stolen In the article, an official violated policy by taking the detailed personal information of thousands of active and reserve troops to his personal home, storing it on a personal computer, that was later stolen. In an age where domestic phone calls are monitored, a government employee was allowed to walk out of a government installation with the data on thousands of American citizens to store on an insecure personal computer? Doesn't that seem strange to you? This is a real failure, in my opinion, in government protection of its citizens. Layers of encryption and protected access was successfully bypassed to make the theft of this information as simple as stealing a home pc. Now, not only do service personnel currently serving have to worry about IEDs and being fired upon, but they are now subject to possible identity theft. A real failure. After this, how could one have faith enough to serve an inept institution?"

51 of 343 comments (clear)

  1. Strange question by stupidfoo · · Score: 3, Insightful

    After this, how could one have faith enough to serve an inept institution?

    Why do we need all the editorializing in the blurb? And the troops don't serve an institution.

    1. Re:Strange question by thrillseeker · · Score: 4, Funny

      After this, how could one have faith enough to serve an inept institution?

      Why do we need all the editorializing in the blurb?


      You must be new here.

    2. Re:Strange question by Anonymous Coward · · Score: 5, Insightful

      I agree, rants and opinions belong in posts, informative summaries belong on the main page. I don't go to slashdot to get raved at by someone who doesn't understand the difference.

      That being said, I agree this was a failure, but not of the U.S. governemnt. This was a failure by the analyist who didn't feel it manditory to follow the rules. Every good sercurity measure begins and ends with trust. The Office of Veteran Affairs was betrayed just the same as everyone else in this instance.

    3. Re:Strange question by Herkum01 · · Score: 3, Insightful

      The Office of Veteran Affairs was betrayed just the same as everyone else in this instance

      I call BS, Veteran Affairs has consistently been given low grades in security. It goes back to a culture of "I don't give a damn". As long as the agency is not punished, publicly or privately, you can bet it will happen again.

    4. Re:Strange question by RingDev · · Score: 4, Insightful

      I call shenanigans on your BS. You can't pin this down on just the VA. As a former member of the military who worked in HQ MC and the Pentagon, I can assure you that given the proper motivation of any worker, this information could be leaked/stolen/sold.

      In this case the fault was negligence. The laptop should have had an encrypted hard drive. The consultant should not have taken the data home. But if the consultant shouldn't have taken the data home, why was he given a laptop? There were many mistakes made in this process, and those same mistakes are made throughout the government and private sector. The VA has no special claim on incompetence.

      -Rick

      --
      "Most people in the U.S. wouldn't know they live in a tyrannical state if it walked up and grabbed their junk." - MyFirs
    5. Re:Strange question by jeepmeister · · Score: 2, Insightful

      This was a failure by the analyist who didn't feel it manditory to follow the rules.

      As an IT security engineer for a very large health maintenance organization, trying to prevent our physicians, administrative people and business oriented wonks from committing gross acts of security stupidity turns out to be one of the biggest challenges. Organizations need to drive hard to make sure employees are aware that putting sensitive information in positions of vulnerability will invariably lead to compromise that is simply unacceptable. Without security as a mindset, these compromises are guaranteed to continue. I believe the analyst who compromised the data was fired, so it's obviously going to take more than just threatening the offender with termination to prevent future blunders.

      --

      I don't need no estinkin' .sig
      Jeepmeister
    6. Re:Strange question by Himring · · Score: 2, Insightful

      In response to the "rant" on the main page:

      1. These were military personnel right? Referring to them as "American Citizens" is a stretch. Don't get me wrong. Hats off to our enlisted troops, but once you join the military you give up massive rights that a normal citizen has.

      2. My dad served in the army, and from my understanding, it is anything but "intelligent." "Army Intelligence" was referred to as an oxymoron....

      --
      "All great things are simple & expressed in a single word: freedom, justice, honor, duty, mercy, hope." --Churchill
  2. Conspiracy? by neonprimetime · · Score: 2, Interesting

    The burglary from the employee's home in Aspen Hill, Maryland, involved a laptop computer with an external disk drive, officials have said.

    2 things...
    1.) Wouldn't stuff this sensitive be encrypted if it's sitting on an external disk drive?
    2.) Is there some sort of conspiracy going on? With the terrorist arrests in California and Canada? Perhaps somebody is planning something big ... and it starts by gathering all the personally identifiable information they can get on us citizens? (first the vets data was stolen, now this) ... Maybe the US terrorist threat level should be raised to red!

  3. Re:IED? by RingDev · · Score: 2, Informative

    Improvised Explosive Devise.

    Basically a bunch of artillery shells wired to a trigger or remote. When a US convoy drives past the IED hiding spot, a watcher triggers the explosive and the huge crater is formed right where the convoy used to be.

    -Rick

    --
    "Most people in the U.S. wouldn't know they live in a tyrannical state if it walked up and grabbed their junk." - MyFirs
  4. Re:IED? by dk-software-engineer · · Score: 2, Informative

    Improvised Explosive Device - http://en.wikipedia.org/wiki/Ied

  5. Since you are reposting 3 week old news by hsmith · · Score: 4, Informative

    You could at least post the update that the Vet's are now suing the VA.

    1. Re:Since you are reposting 3 week old news by Billosaur · · Score: 2, Insightful

      The original event, the 26.5 million veteran records, may be old news, but now that has widened to encompass 2.2 million active members of the military, so this is hardly 3-week-old news. What it points to is a systemic problem -- why can't people keep sensitive data safe? The discussions here on Slashdot have gone on and on, with the consensus being that it seems stupid not to encrypt data, given the widespread availability of decent encryption software.

      If anything, this is going to prove a blow to the idea of telecommuting and/or working from home. Not to get too far off topic, but companies may now become very leery of sensitive data making it out past their firewalls, especially when it seems their employees can't handle it properly or keep it safe.

      --
      GetOuttaMySpace - The Anti-Social Network
  6. More Than Identity Theft by foo+fighter · · Score: 3, Insightful

    There's a real fear that this includes classified disability info.

    If that info gets on the web, an employer googling a potential employee's name may see that candidate has, for instance, post-traumatic stress disorder (PTSD) and decide not to hire them. It's currently illegal to discriminate like that, but there's no way anyone will ever know in this hypothetical situation.

    --
    obviously no deficiencies vs. no obvious deficiencies
    1. Re:More Than Identity Theft by MrSquirrel · · Score: 2, Insightful

      New, from the makers of HIPPA -- Unsecured Information Fun! It's absurd to think that a "Veterans Affairs data analyst who had violated official procedures by taking the data home" caused millions of people to be at risk for ID theft or worse. It's 2006 -- he is an alleged data analyst, meaning he should know the risk of unsecured data. 1) he broke office procedure by taking the data home, 2) he left the data completely unsecured on a computer in his home. If this happened at a health-insurance-industry related company, under HIPPA the employee AND the company would both be held accountable and severely reprimanded... but because it's the government, "oh, everything's peachy, we're looking in to it" -- I haven't even heard of the employee being fired. What's worse is that there were originally "only" 50,000 people at risk from this data, now - a week later - it's been released that the number is in the millions... Go-go gadget government uh-oh.
      (I've been following this story for a while, note a very timely /.)

      --
      A computer once beat me at chess, but it was no match for me at kick boxing.
  7. From the "Fine Tooth Comb" department by SomeoneGotMyNick · · Score: 3, Informative

    This is in addition to the identifying data of millions of Veterans stolen in the same event. They originally reported only Veteran data. Now it seems it contains active duty soldier info as well.

  8. Ever vigilant by Rob+T+Firefly · · Score: 2, Insightful

    TFA: Bryan Whitman, a Pentagon spokesman, said, "We want to encourage service members to be vigilant and carefully monitor their personal information and any statements related to recent financial transactions."

    Great, as if they didn't have enough to deal with. I can just picture some soldier under mortar fire in Iraq, trying to load a rifle with one hand while juggling a cellphone on hold with American Express in the other hand..

  9. Not a dupe! by GundamFan · · Score: 2, Interesting

    It's not a Dupe... this is a diffrent theft, the origonal data stolen was from the V.A. database.

    It just happened exactly the same way...

    I guess Slashdot can't help if the news is repetative.

    --
    I don't give a damn for a man that can only spell a word one way.
    Mark Twain
    1. Re:Not a dupe! by SomeoneGotMyNick · · Score: 3, Informative

      Not quite....

      The Active Duty info is a subset of the same data stolen weeks ago.

  10. And in other news by porkchop_d_clown · · Score: 3, Insightful
  11. Official Use Only Information by goombah99 · · Score: 5, Informative

    The information is not classified, it's Official Use Only, which is a form of protected information. Personell records are usually, in part, execmt from freedom of information act requests, so they may enjoy a slightly higher level of protection than ordinary OUO.

    However, nearly every govenrment computer in existence includiung laptops has gobs of OUO information on it. It's not encrypted because it's not that sort of information. It's just controlled dissemination. That does not mean it might be harmless to release it but it's way below classified.

    It is not alarming the people occasionally accdentally disseminate or lose control of OUO. Employees are simply expcted not to do so wilfully or wantonly or carelessly. Its even permissible to share OUO with people outside the governemnt if the employee thinks it would be useful to do so. The fact that OUO was taken home is not a big deal.

    In this case the only big distinctions are the massive quantity of the information, and the fact that it's personell records which do have higher levels of protection. Apparently it was also policy not to take these home.

    --
    Some drink at the fountain of knowledge. Others just gargle.
    1. Re:Official Use Only Information by truthsearch · · Score: 2

      The information is not classified, it's Official Use Only, which is a form of protected information.

      Apparently not. :/

    2. Re:Official Use Only Information by cyclone96 · · Score: 2, Interesting

      Government control of this sort of information can often be very poor, because there are not business or contractual ramifications.

      I work for the federal government, and I often travel overseas with a government owned laptop. That laptop usually has export controlled (but unclassified) information on it.

      Whenever I do this I have to fill out many forms documenting exactly what is on that laptop. When I asked why, it was "so we know what was on it if you loose it - that would technically be an export, and we need to document it".

      OK - so I point out that we ought to encrypt the data (which is quite easy) so we don't even have to bother with that and not worry about it being exported.

      Blank stare, and then a "Please just fill out the forms". I could mail the laptop to China and they probably wouldn't care, as long as the SF8574 is on file at the export control office.

      Now, on the other hand I know for a fact that if one of our contractors would lose that same data, there would be hell to pay - not from the government directly, but his own company which has been penalized heavily on other contracts for mishandling information. They have built a culture of sensitivity to information that should be protected. In the government, I really only detect that when dealing with classified data (which can have big time personal ramifications if mishandled).

      --
      Worst...sig...ever!
  12. Re:IED? by Foofoobar · · Score: 4, Funny

    Its a device used to keep from getting pregnant. In the late 80's, there was an IED for OIL program that the UN started with limited success. Since then, the country has had a glut of birth control so much so that inventive terrorists have discovered a way to turn them into cheap and effective weaponry. This is why the military has upped its recruiting of pre-teen girls to combat this menace.

    --
    This is my sig. There are many like it but this one is mine.
  13. Apples and oranges by operagost · · Score: 2, Informative
    In an age where domestic phone calls are monitored, a government employee was allowed to walk out of a government installation with the data on thousands of American citizens to store on an insecure personal computer?
    Those are two separate issues. The proverbial apples and oranges come to mind. It's something like saying, "In an age where crackers are trading warez across P2P networks, people are allowed to have CD-RW drives in their computers?"

    Besides, domestic calls are not monitored without a warrant. Do you have a problem with that? Perhaps you are thinking of international* calls to known members of terrorist organizations.

    Doesn't that seem strange to you.
    Is that a question?

    * According to my phone bill, a call made from my house to another country is an international call.

    --

    Gamingmuseum.com: Give your 3D accelerator a rest.
    1. Re:Apples and oranges by Red+Flayer · · Score: 2, Insightful

      "Besides, domestic calls are not monitored without a warrant."

      Depends on what you mean by 'monitored'. Are records of domestic calls being kept and stored in a database for potential future use? You betcha. Is this monitoring? Maybe. I think so.

      And the point that was being made in the editsummary is, AFAICT, that the US government is capable of monitoring domestic phone calls, and willing to brute force the issue with the telcos, but not capable of of preventing this kind of stupid human error.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    2. Re:Apples and oranges by fortunato · · Score: 2, Insightful

      This is all well and good but the fact that they have been doing this for a long time neither makes it right nor does it mean it works. It certainly didn't seem to help them find the terrorists on 9/11. If it took 30 years for this to become a public enough issue that people are up in arms then, in my opinion, it was 30 years too long. But I'm glad to see people are starting to notice all the little infringements on our rights and to realize that you don't need very many little ones to end up with big ones.

      As regarding your second paragraph, everyone I've heard who have made statements like that seem to assume that the people who have access and control over all this collected information are robotic superheroes fighting for truth, justice, and the American Way, who would never ever ever ever ever mistakenly or purposefully use and/or abuse that information. Unless you haven't been keeping up on current events lately, there are all kinds of fraud, bribery, outing of secret agents, and other exciting criminal behavior going on with all of our government officials across all party lines. I'd have to say you like to live on the edge if you trust these people to do the right thing with your information.

    3. Re:Apples and oranges by Red+Flayer · · Score: 2, Insightful

      I have a service contract with the phone company relating to those specific calls. I do not have a service contract with the government relating to those specific calls. Due to the history of telephone monopoly in the US, neither I nor anyone else has the ability to demand confidentiality as part of our telephone service contract. The problem is that the government regulates a monopoly where it is in the direct interest of some parts of government to not regulate always in the favor of the citizen.

      As to the 4th amendment (which was not metioned in the OP or my response), note that every time the Supreme Court has ruled that the 4th amendment does not apply, the government has requested access to phone records in relation to the investigation of a specific crime. Data mining (which definitely falls under the umbrella of 'monitoring') is a whole different story, because law enforcement is now looking for evidence of behavior that does not necessarily have anything to do with ANY crime. This, my friend, is specifically forbidden by laws governing the operation of domestic surveillance -- and makes the US a police state.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
  14. Do you want trusted computing? by file-exists-p · · Score: 2, Insightful

    The only way to prevent most of that kind of leak is the infamous trusted computing. How can you prevent somebody to walk out of the building with critical files on his USB key without "secure hardware" ?

  15. As a vet, I can say... by blueZ3 · · Score: 4, Informative

    that most folks who go in the military don't do it to "serve an inept institution" or to serve an insitiution of any kind. Those who are serving for ideological reasons (even if "patriotism" only plays a small part in the decision) believe they're serving the country as a whole and the ideals it stands for. That's why we say "serving our country" not "serving the military."

    Everyone who has been in the service knows that there are always a few idiots up in the higher levels of the chain of command. Also that the civilian employees of the DoD aren't always interested in looking out for the interests of the military personnel that they are supposed to be serving. Dealing with the civilian DoD folks was a constant frustration during my time at Fort Bragg. Not that those folks are all bad, but the service they gave me when I was in the 82nd was second only to the service I get from the DMV -- surly and uncooperative.

    --
    Interested in a Flash-based MAME front end? Visit mame.danzbb.com
    1. Re:As a vet, I can say... by drinkypoo · · Score: 2, Insightful

      Those who are serving for ideological reasons (even if "patriotism" only plays a small part in the decision) believe they're serving the country as a whole and the ideals it stands for. That's why we say "serving our country" not "serving the military."

      I understand the reasoning of people going in for ideological reasons, but they're wrong. You are NOT serving your country. Anyone who believes that working for the military is serving their country is only fooling themselves. Over $400B on this bullshit war for oil. Whoop de shit. Even the reasons we sent troops there turned out to be bullshit.

      Or of course, go back a little further into history... remember all those weapons that we sold to third world countries? And now we have a terrorism problem.

      Make no mistake, working for the government in any capacity is working for the institution. The dirt of the country doesn't have a bank account, and doesn't write you a paycheck. The government does. Who do you think you're working for, really? (Or well, who you were working for...)

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  16. Don't Worry... by dcollins · · Score: 2, Funny

    Don't worry, this is all fixed now, and can't possibly happen again. We recommend that you not dwell on past history, and move forward into the future. Your private information is completely safe with the government, we've learned our lesson.

    And that goes double for next time, too.

    --
    We know where leadership by an anti-intellectual "strongman" who scapegoats minorities and likes boisterous rallies goes
  17. Quis custodiet ipsos custodes? by Medievalist · · Score: 2, Insightful



    "Who shall watch the watchers?" --Decimus Iunius Iuvenalis

  18. What is this, a Theme Summer? by Doctor+Memory · · Score: 3, Informative

    This follows on to the theft of several laptops worth of corporate employee data. Almost makes me want to open up a consumer credit protection business...

    Ernst & Young lose data on a quarter-million Hotels.com customers

    Ernst & Young (hey, there is a theme here!) lose information on Sun employees (including then-CEO Scott McNealy). Also included were employee records for IBM, Nokia and Cisco.

    Wells Fargo proves it can play the game too.

    And not to be left out, let's not forget Fidelity's loss of 200,000 HP employee records.

    What's scary is that both Fidelity and E&Y audit other companies for security and regulatory compliance (including HIPAA and Sarbanes-Oxley)...

    --
    Just junk food for thought...
  19. Re:Overtime... free or otherwise by drinkypoo · · Score: 4, Insightful

    This is a case of "no good deed goes unpunished."

    Not keeping records of servicemen's personal data secure is a good deed?

    The guy was working on a project at home "unauthorized", his laptop and usb hdd get stolen, officals grandstand, and he gets fired at age 60 (perhaps without a pension).

    Fuck, I sure hope so. I hope he got fired twice somehow in a bizarre star-trek-ian causality loop. Anyone who would keep confidential data on a computer in a physically insecure location without encrypting it is a fucking moron. Fuck him in his working-at-home ear.

    Perhaps you didn't notice, but the entire federal government got failing grades on their infosec security report card. Are you really okay with that? By making excuses for idiots who cannot see their way to actually protecting confidential data, you are part of the problem.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  20. Re:Once again. . . by jsnipy · · Score: 2, Interesting

    (most)Army civ employees are crap ... they make all contractors feel like cinderella (or cindarellus) for doing all of the work they [can't]/[won't]/[incapable of doing] while they rot on the vine. Tons of tax $$$$ could be saved by cutting these leechy turds loose.

    --
    -- if you mod me down, I will become more powerful than you can possibly imagine
  21. False sense of security by mabu · · Score: 2, Insightful

    People are focusing on the transgression of the guy putting this data on his laptop and taking it out of the building. In reality, you can bet the systems he was working on were networked and he could have accessed the data from his home directly. I'm not sure if there is a simple solution to this other than constantly making sure all data is encrypted wherever it is stored.

  22. Actual this is great by portwojc · · Score: 4, Insightful

    Actually this is the best thing that could have happened. A complete failure in a system, potential for identity theft, and involving current/past service men/women. I am one of those by the way.

    Why is this the best thing? Cause when troops are involved national pride actually works and things get done. People will flip out over this and they will finally fix it. Think of the children is first followed quickly by think of the troops. Now maybe they'll put the responsibility where it belongs. Squarely on the shoulders of those companies that deal with credit. Then I'll stop getting those calls for the new service that protects my credit and it only costs $14.95 a month. Make that free and actually go after these thieves instead of what they do now.

  23. Service to an inept institution. by GodInHell · · Score: 3, Insightful
    After this, how could one have faith enough to serve an inept institution?"

    This is a common misstatement made by those who think joining the armed services is about service to the army, or the navy, or the president. Joining one of the U.S.A.'s armed services is about serving your country, not the individuals in control of it. It's about protecting your homeland from invaders. It's about getting a shot at the brass ring of U.S. citizenship through sacrifice. It's about putting yourself on the line for your brother, your friend, your mother, your future, etc.

    When I apply for a job in the states, I do so based on my ability to trust my employer to treat me responsibly. I would refuse a job that didn't pay well, or one where my employment would be degrading or unduly dangerous. Joining any military is a distinctly different sort of employment. It's an inherently dangerous job, one in which you can expect abuse from your employer, rigorous and painful training, and eventual combat duty.

    So, in short, while this article is certainly a sign that our government is abusing our troops, one should honor those who do so despite the obvious risks inherent in service. Rather than wondering who would serve, we should wonder who would treat so poorly those who give so much. We ought (as in a moral ought) to respect and honor those who risk their lives to defend our way of life. We ought (again, moral ought) to hold in deepest revulsion those who abuse them, or send out the troops over petty personal desires and greed.

    -GiH

  24. No need for confusion. by dwalsh · · Score: 2, Insightful

    "In an age where domestic phone calls are monitored, a government employee was allowed to walk out of a government installation with the data on thousands of American citizens to store on an insecure personal computer? Doesn't that seem strange to you."

    No contradiction here, both are consistent with each other. Either way, it is because you have no privacy in the eyes of the state.

    --
    ${YEAR+1} is going to be the year of Linux on the desktop!
  25. Theft like this is stupid and unnecessary by Quila · · Score: 2, Insightful

    I've done work like this, writing software that works with various sensitive data, millions of records, maybe even one of you, and I've done it from home.

    However, my set of data was real data that was obfuscated, random names, SSNs, etc., generated, replacing the ones in the database. No real data was ever allowed to be exported off the database server, period. Only an SA could steal it.

    That this wasn't done is just gross negligence on the part of the organization.

  26. I Served - and the OP is wrong in one respect by EQ · · Score: 4, Insightful

    "how could one have faith enough to serve an inept institution?"

    I didnt serve the Army - I served *IN* the Army.

    What I served was the American People, through their elected Commander in Chief, and the primary focus of the Oath I and others swear is:

    to Uphold and Defend the Constitution of the United States

    Second error bythe OP is the "institution" that lost the data was not the military per-se but the Veterans Administration, a cabinet level office that is seperate fromthe Army, Navy, Airforce, marines and Coast Guard,m etc.

    When will ./ editors have enough of the spin and editorializing - especially when its egregiously wrong as it is in this case. How about getting an editor with some military background instad of the usual suspects? A little bit if diversity might help ./ avoid posters like the originator who completely misses the point of the article and instead tries to spin it politically (point is veterans records were taken via a moron breaking security at the VA, not some anti-military screed that the OP tries to spin it into).

    There Plenty of libertarian geek veterns out there who post here regularly - Rob, grab one and add some diversity to the editorial clique.

    --
    Buffalo buffalo Buffalo buffalo buffalo buffalo Buffalo buffalo! http://goo.gl/J9bkO
  27. Publish the SSNs ! by GlobalEcho · · Score: 2, Interesting

    I know that in this case more than social security numbers were taken. But this is a good spot to say that I would like the US government to publish, for free download, a list of all issued SSNs and their associated names. Then the banks, insurance companies, universities and so on will have to stop pretending the damn things are secret.

  28. Re:Once again. . . by Foobar+of+Borg · · Score: 2, Insightful
    Contractors without even crappy VA benefits and not subject to Geneva conventions. ;)

    Of course! Privatizing government functions lets the government get around that annoying thing called the "Constitution" (aka "just a goddamn piece of paper").

  29. Re:Once again. . . by Oculus+Habent · · Score: 2, Insightful

    I doubt "The Man" specifically engineered this failure. "...was allowed to walk out?" What kind of crap statement is that? He had a laptop and an external hard drive. I didn't see any mention of "His supervisor instructed him to copy sensitive data onto a personal computer..." Should everyone leave an hour early so the door guards can perform an extensive scan on their laptop? If they run across encrypted files, shoudl they require the keys, to ensure no secure data is being taken? If they have to check those files, then don't the door guards need very high-level security clearances?

    Unless you want the government to perform a full cavity search on every employee capable of interacting with anyone who has access to secure files every time they leave the building, this sort of thing can happen.

    All the procedure in the world won't make up for an unthinking -- or worse, uncaring -- employee worried about meeting a deadline.

    --
    That what was all this school was for... to teach us how to solve our own problems. -- janeowit
  30. It's An Old Problem. by ackthpt · · Score: 2, Insightful
    a government employee was allowed to walk out of a government installation with the data on thousands of American citizens to store on an insecure personal computer? Doesn't that seem strange to you. This is a real failure, in my opinion, in government protection of its citizens. Layers of encryption and protected access was successfully bypassed to make the theft of this information as simple as stealing a home pc.
    This happens all the time unfortunately. People's stupidity can circumvent and electronic security measures.

    Here's how it happens:

    • A study is made of security.
    • Recommendations are put forward and implemented.
    • Personnel in their mission to get work done find following secure procedures impedes their efficiency.
    • Personnel devise ways to short cut, wink and a nod, as long as it's me and you know, it's OK, etc.
    • Less restrictive, security is still viewed as a barrier to getting things done quicker, leads to more shortcutting and circumvention of procedures.
    • Someone suddenly loses a computer hard drive, CDs a laptop, a networked computer is breached, etc.
    • Everyone is shocked and amazed.
    • To those who enabled the shortcuts and circumvention are curiously mum, but people know who they are and they eventually get cleaned out or taken out of the security loop.

    The big problem is management, the people who make the big money to take responsibility, react more than proact. Security means vigilance, but it also means giving people the proper time to do their work within the procedures of security. In my life I've only met a few people who took day to day security seriously and made a point of not giving in when someone asked for a short cut, "just this one time."

    Management as much as ever seems to attract people to the wages and not the actual responsibilities. Peter principal of some strip I suppose.

    --

    A feeling of having made the same mistake before: Deja Foobar
  31. The news worse then the incident by Momoru · · Score: 2, Interesting

    Someone stole a laptop. It would be wiped and sold on the street. 99% chance no one would be the wiser, the thief didn't know what he had. Now news comes out that there could be a laptop with tons of valuable info...thiefs all now look to see if they have the golden laptop! Another case where the news of the incident makes the problem worse. Lets make a big deal of this when someone actually knows they have this data and uses it for ill intent.

  32. This makes me suspicious it was an inside job by spun · · Score: 2, Interesting

    This was different data, on the same damn laptop. I think the guy was in on it. Nothing else was stolen, just his laptop, which, oopsie! had not one but two sets of valuable data which were not supposed to be on it. Here's what I think went down:

    Dude had some bad debts to some bad men. Said bad men approached him with a way he could pay them off. Just get data for ID theft on his laptop then leave it in his house and they would make it look like a burglary. Dude does so, and reports laptop stolen, but not the data on it. Later, after other Bad Dudes are off his back, dude has a change of heart and admits the data was on the laptop.

    I know, never ascribe to malice or greed what can adequately be ascribed to incompetence, but I think the facts in this case are pretty damn fishy.

    --
    - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
  33. Re:Once again. . . by lowvato · · Score: 2, Informative

    I generally agree but have to add that when I worked on a Naval base, we had a very good set of govies, mostly software engineers (some with PhDs) who operated at a very sophisticated level of computing and were not just sitting around and rotting in their chairs. Even the management was good. In this case it was often the contractors that were mediocre -- we had the full range of really good contractors and some who were only good for dragging tax dollars out of the millitary. I think the difference here was that the job was interesting (meteorological and oceanic weather modelling products). Most people will sit around and rot when they are restricted by small minded bureaucracies. Everything was fine at this place until you had to request office supplies.

  34. Re:Are these thefts really just random events? by ScentCone · · Score: 2, Insightful

    First, how would someone know that this computer contained all this information?

    If you're following the story, every indication is that it was a routine suburban residential burglary. I live in the same county as the home that was robbed, and this is exactly like every other B&E we always see: laptops, game consoles, digital cameras, jewelry, cash. Rinse, repeat.

    If you live in the DC area as an info-worker, the odds of you handling sensitive payroll or similar data, especially related to government/military employees, is certainly higher than anywhere else in the country. But the odds of such a theft happening at all pretty much demand that crap like this is going to happen. The idiot probably would have lost his laptop in the same burglary regardless, but his inappropriate use of that data on his local drive, away from the office, turned something you otherwise would never have heard about into a real pain in the ass. Of course, the person who stole the hardware probably has no idea what's on it, or what to do with it.

    Am I being paranoid?

    If so, only about the wrong things. This is a workplace culture issue, not some nefarious plot. Too many people have casual access to all sorts of stuff (I know I do) without all of the interested parties really communicating about the risks and trust involved.

    --
    Don't disappoint your bird dog. Go to the range.
  35. Excuse me? by vivin · · Score: 5, Informative

    Now, not only do service personnel currently serving have to worry about IEDs and being fired upon, but they are now subject to possible identity theft. A real failure. After this, how could one have faith enough to serve an inept institution?"

    I'm in Iraq right now. Yes, we have to deal with IED's and being fired upon. And yes, having to worry about this isn't all that great either. But that has absolutely nothing to do with "serving an inept institution" as you call it. We don't serve an institution. We serve in the Armed Forces of the United States. I serve in the Army, and I don't think that the Army is inept. This isn't a failure of the US Army as a whole, but it was due to the indiscretionary act of one person. He violated OPSEC (Operational Security) and he had no business taking sensitive information into his personal computer. This is HIS fault, and I hope he gets prosecuted to the fullest possible extent under the UCMJ. So please, like the parent said, no editioralization is necessary. We serve because we took an oath. We serve because we are professionals. We serve because words like Loyalty, Honor, Duty and Courage mean something to us. It doesn't mean that it means nothing to a civilian. But I hate it when people assume we are nothing but mindless drones. I, personally, try to keep politics away from the military. Which is why I don't endorse any side of political debate, when speaking as a soldier. I'm here to do a job, and I'm here as a professional.

    Sorry for going so far off-topic.

    --
    Vivin Suresh Paliath
    http://vivin.net

    I like
    1. Re:Excuse me? by The+Good+Reverend · · Score: 2, Interesting

      This isn't a failure of the US Army as a whole, but it was due to the indiscretionary act of one person.

      If one person can do this kind of damage, then the problem is with the system, not just that person.