Census Bureau Loses Hundreds of Laptops
Billosaur writes "According to CNN, The U.S. Commerce Department has lost 1,137 laptop computers since 2001, most of them assigned to the Census Bureau. According to Commerce Secretary Carlos M. Gutierrez, 'All of the equipment that was lost or stolen contained protections to prevent a breach of personal information.' This comes after the fiasco involving the Veteran's Affairs Department's loss and eventual recovery of a laptop containing 26.5 million veteran and active-duty records." Given the scope of the operation, are these losses to be expected or is this an example of poor government security standards?
'All of the equipment that was lost or stolen contained protections to prevent a breach of personal information.'
I would like to know what kind of protection is being used. Is it just password protecting windows? encrypted hard drives? This kind of blanket statement doesn't really tell me much about how safe the census data really is.
Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
From TFA:
"All of the equipment that was lost or stolen contained protections to prevent a breach of personal information," said Commerce Secretary Carlos M. Gutierrez. "The amount of missing computers is high, but fortunately, the vulnerability for data misuse is low."
Ya, OK, I know I feel better. My bet is that they all had some kind of encryption software installed on them that very little to none of the users actually use.
Let me guess... they put on Windows login passwords.
Since 2001? Hmm, at that time there were still lots of Win98 machines floating around even in business. You could assign a password, or just bypass the login with IIRC, pressing ESC.
The scary thing is that government moves so slowly when it comes to technology. It wouldn't surprise me that they're using some ancient encryption - decent for its age -- but completely inadequate with today's tools.
Temps, on the other hand, are a different story. Some of them feel entitled to keep the laptop as a lovely parting gift. Others feel the need to test the ability of the employer to retrieve the computer. When push comes to shove, it's not easy to retrieve a computer from a temp who lives in some remote part of the country -- without spending more than the computer is worth. If you have to send someone to visit in person -- game over.
I think that a big part of the problem is that Federal employees can't really be punished, unless they're grossly negligent.
In terms of job security, it's just below being a pedophile priest; most of the time if you fuck up, you might get demoted or shuffled around ("I see there's a warehouse in Sioux Falls that needs a manager...") but probably not actually thrown out on your ass by Security.
IMO, this leads to all sort of laziness and a general lackadaisical attitude on the part of a great many USG employees -- not all of them, to be sure, but it seems like there are usually 4 bags of useless skin for every one person who's pulling the weight of 5 people. It's about the only place I've ever seen that could honestly look to gigantic multinational corporations for advice on how to be more efficient. Total sausage factory, in other words.
The laptop losses don't really surprise me, because I doubt these people get more than some sort of administrative demerit -- if that -- for losing one. I'm sure there's some sort of procedure that they go through, but I'm willing to bet that in the long run they just get a new machine issued and they go on, grinding their way towards retirement.
If you want to stop these losses, I have a plan: tell people that they get one laptop. If they lose it, they can try to do their job without one, and if they can't do it, then they can find a new job somewhere else. Like the private sector. Maybe McDonalds. Or if you can't tolerate being that extreme, just make any loss of a laptop come with an automatic demotion of one Government Service grade. There's nothing like the fear of demotion to strike fear into the hearts of bureaucrats.
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
Given that 1) they have a massive short-term workforce of census takers and 2) I doubt they were giving them 1999's highest-end hardware, I can't get too worked up about this. What would the government do with a slightly higher stack of Pentium 120s, build a bigger Beowulf cluster? As long as there was no privacy violation, this doesn't sound like such a bad loss rate for such a huge project.
What I'm listening to now on Pandora...
Let's assume that at any given time there were about 20,000 laptops in use at the Commerce Dept in the five years since 2001. (30K laptops were used in that period, but some would have been swapped out during that time.)
1,137 missing over this period is a bit over 200 per year, or about 1% attrition per year.
I'd say yes. We're talking mobile pieces of equipment, easily hidden in a suitcase or even in coat these days.
The level of data compromise, as opposed to physical asset loss, is another matter, but then the article doesn't quantify that.
a world in progress...
the worst part is, if it was them, those so called "security measures" will mean nothing since they will have the access codes anyway. let's just hope they decided to delete all of the census junk so they could have more room for the torrent porn and music.
I'm more concerned about the "nearly 250 from the Census Bureau containing such personal information as names, incomes and Social Security numbers". I heard a sound bite about it from the Commerce Dept. statement this morning, they said not to worry, the data is, and I quote, "password protected".
Yeah, that's real comforting.
[command INSERTWITTYQUIP failed: insufficient wit]
Not only do census takers ask questions to which they are not entitled answer--by any stretch of the Constitution--they store the information on laptops that any recently-fired hamburger flipper fucktard can walk around with and lose or trade for a couple rocks of crack.
slashdot broke my sig