all of your points totally undermine the benefits of centralization and computerization. perhaps that is the point and that there are some things that should just not be digitized or made "easy to do," but security people also recognize that security is often not the end goal. creating a usable system where the reward outweighs the risk is the goal. if the reward, despite this risk/vulnerability, is still very high, then we'll probably keep doing it.
your points are what you would want to do if you wanted to make an ideally secure system, but nobody wants only an ideally secure system...
> … but nobody wants only an ideally secure system
Indeed! The ideally secure system would be one which doesn't exist/doesn't have ANY interface, much like the perfect computer which doesn't perform any IO with the rest of the world.
"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards... and even then I have my doubts."
100% agree! Typically you do not want to trade off usability for security, but there are situations in which you do. The question then becomes how much do you trade off and are there solutions that give you similar gains but don't involve trade offs?
I'm just proposing some tools which might be useful when security is significantly more important than other considerations.
I don't think that this is a case where you want to trade off security for usability, and I don't think that generally those cases exist. You always want more usability. The problems that OPM has are massive, their solutions need to scale. Solutions like what you propose make their solutions stop scaling.
Security people (and armchair security people especially) think that security is the end goal. Security is never the end goal. The mission is the end goal. Security is only useful in so much as it helps you achieve the mission. Sometimes security needs to get out of the way when the mission needs to get done. It is always a tradeoff. The personnel clearance system is already such a tradeoff, a background investigation system that needs to scale to millions of people. Good luck making it "ideally secure."
There were data hygiene and application/network security best practices that OPM should have followed. In hindsight, they would have been way cheaper than the response to a breach like this. Responding by taking all the systems offline would most likely be far more expensive to the system as a whole than a future breach.
> There were data hygiene and application/network security best practices that OPM should have followed
Like what? Can you reference anything?
Your comment criticizes security but, this is a HUGE leak. You can't just sweep this kinda data under the rug for the sake of usability. That's just laziness. The mission matters and is important, but if you can't protect the data that people give you, you shouldn't have it at all.
This was a government agency; there is NO REASON for any kind of security tradeoff.
A company with CC info? Ok, yeah that's a different story with different tradeoffs. But this is the kind of data breaches that can cause vast amounts of harm to individuals and the nation; people's lives are put in danger by this leak. You wanna tell me that it's OK to sacrifice security for the sake of usability in cases like that? Would you feel the same if it was your life that was now at risk?
They had a responsibility to protect the data they held AS WELL AS to serve the mission. not one or the other. both. it is irresponsible to take risks with data that is not yours.
You know that there is no perfect security, right? So do you imply that, since security is so important, government should stop function? Anything government does decreases security, even if so slightly.
With FISMA no one builds even remotely secure systems, nothing anyone here would even want their name associated with. And this is because under FISMA government executives can "except risk", and they don't have to justify why.
So when your agency needs an application to do X, and you will face consequences if it doesn't get spun up, and to do so requires you cut a lot of security corners, but you won't face any consequences for doing so, you're going to cut those corners. Especially if not cutting those concerns means delays in rolling out that system, or spending a ton of money to fix all those security problems. The state of information security in the government is atrocious for this reason. It's not that complicated. There is no real incentive to secure systems, and very real insentives to not do so. You just issue the ATO and accept the risk. It's up an running and everyone is happy. If it's not and running people are pissed. It gets owned, people shrug and say "well nothing is totally secure".
>Security people (and armchair security people especially) think that security is the end goal.
This only seems to be your mistaken perception of what security people think. I'm a security analyst and I've never met anyone in my industry that believes that security is a goal that can be achieved. Security is a process that will never end.
>I don't think that this is a case where you want to trade off security for usability, and I don't think that generally those cases exist. You always want more usability.
If you believe that security is always a tradeoff(which you stated) and you believe that there is never a situation where you would want to make such a tradeoff, you are basically saying that there is never a situation where you would want security, which is ridiculous. There is always a balance between usability and security. In most cases, the scales will tip towards usability by a large margin, but there are times where a significant hit to usability in the name of security is the right decision.
your points are what you would want to do if you wanted to make an ideally secure system, but nobody wants only an ideally secure system...