> There were data hygiene and application/network security best practices that OPM should have followed
Like what? Can you reference anything?
Your comment criticizes security but, this is a HUGE leak. You can't just sweep this kinda data under the rug for the sake of usability. That's just laziness. The mission matters and is important, but if you can't protect the data that people give you, you shouldn't have it at all.
This was a government agency; there is NO REASON for any kind of security tradeoff.
A company with CC info? Ok, yeah that's a different story with different tradeoffs. But this is the kind of data breaches that can cause vast amounts of harm to individuals and the nation; people's lives are put in danger by this leak. You wanna tell me that it's OK to sacrifice security for the sake of usability in cases like that? Would you feel the same if it was your life that was now at risk?
They had a responsibility to protect the data they held AS WELL AS to serve the mission. not one or the other. both. it is irresponsible to take risks with data that is not yours.
You know that there is no perfect security, right? So do you imply that, since security is so important, government should stop function? Anything government does decreases security, even if so slightly.
With FISMA no one builds even remotely secure systems, nothing anyone here would even want their name associated with. And this is because under FISMA government executives can "except risk", and they don't have to justify why.
So when your agency needs an application to do X, and you will face consequences if it doesn't get spun up, and to do so requires you cut a lot of security corners, but you won't face any consequences for doing so, you're going to cut those corners. Especially if not cutting those concerns means delays in rolling out that system, or spending a ton of money to fix all those security problems. The state of information security in the government is atrocious for this reason. It's not that complicated. There is no real incentive to secure systems, and very real insentives to not do so. You just issue the ATO and accept the risk. It's up an running and everyone is happy. If it's not and running people are pissed. It gets owned, people shrug and say "well nothing is totally secure".
Like what? Can you reference anything?
Your comment criticizes security but, this is a HUGE leak. You can't just sweep this kinda data under the rug for the sake of usability. That's just laziness. The mission matters and is important, but if you can't protect the data that people give you, you shouldn't have it at all.
This was a government agency; there is NO REASON for any kind of security tradeoff.
A company with CC info? Ok, yeah that's a different story with different tradeoffs. But this is the kind of data breaches that can cause vast amounts of harm to individuals and the nation; people's lives are put in danger by this leak. You wanna tell me that it's OK to sacrifice security for the sake of usability in cases like that? Would you feel the same if it was your life that was now at risk?
They had a responsibility to protect the data they held AS WELL AS to serve the mission. not one or the other. both. it is irresponsible to take risks with data that is not yours.