Comments

merkelcellcancer May 28, 2007 9:26 AM

In the past the FBI has been scrutinize for lack of infrastructure and networking that would ensure direct and accurate communication for all its field offices and computer networks. I am not surprised that the lack of standardization of its computers and networks has contributed to this security problem.

A single disgruntled agent or IT expert could bring the system to its knees.

Anonymous May 28, 2007 12:28 PM

I rely on the FBI’s continued lack of competence as the best way to protect the US national security.

Nathan May 28, 2007 3:18 PM

There’s a piece in the latest Wired magazine about an employee at Sandia National Labs cyber stalking the lead singer of Linkin Park.

The lab had bad security, auditing, and oversight (the employee spent all day every day just stalking the singer). Of course when outside investigators closed in they had to figure out how to do their job without triggering the lab’s bureaucratic self defense mechanisms.

You can read about it here: http://www.wired.com/entertainment/music/news/2007/05/ff_linkinpark

Hyper Cynic May 28, 2007 5:08 PM

@Bruce

The GAO report is quite interesting and depressing. You note the importance of auditing. I cannot help wondering how the staff responsible for IT security would have the capability to effectively audit access to resources if they did not have the skills/tools/resources/mindset to secure the network in the first place.

Speaking from personal experience, I also have a few questions about Trilogy:

  1. If Trilogy is so Uber sensitive, did the acountants budget accordingly?
  2. Are the users ready and willing to buy into the security versus convenience tradeoff?
  3. Did the Trilogy network architect highlight the security risks?

I am cynical. It’s far too easy for upper management to issue instructions of the “make it so” variety without understanding the real implications of their decisions. Complex IT security and human nature rarely mix well.

meta cynic May 28, 2007 6:44 PM

“Complex IT security and human nature rarely mix well.”

(cough) Complex ANYTHING and human nature rarely mix well. It’s just that few things outside of IT let you create such recursive castles of air. The non-physicality of IT is its weakness and its strength.

sooth_sayer May 28, 2007 9:28 PM

generally speaking GAO reports are meant to address toilet paper shortage in washington .. One should NEVER make a story of their pronouncements.

This one is no exception

Leave a comment

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.