At SEC: Porn Surfing Down, Waste Up, Stunning Disregard For Basic Computer Security
from the 'password'-is-not-a-good-password dept
An internal investigative report of the SEC's Trading and Markets division has been recently been reviewed by Reuters. After reading its rundown of the misdeeds and abuses uncovered, I'm left with the urge to laugh maniacally in the manner of someone having just cleared the tipping point and now sliding irretrievably into insanity. The sheer irresponsibility on display here springs from the sort of irredeemable carelessness that comes with spending other people's money (taxes) and operating without any credible oversight or accountability (a large percentage of government entities).Bess Levin at Dealbreaker points out that while the SEC's internal investigation may have turned up several misdeeds, ranging from the merely stupid to the positively horrendous, it is quite a step up from the insatiable pornhounds that used to populate the Commission:
If you had asked us two years or two months or two days ago if we thought that there would be a time in the near future when Securities and Exchange employees would not be regularly reprimanded for watching porn on their work-issued computers for 98 percent of the workday, we would have said absolutely not. No judgment, but in our professional opinion, people do not go from, among other things:Truly a mind-boggling set of employees. One regional staff accountant ran into the "no-porn" wall 1,800 times in a two week period, yet remained undeterred. Those caught accessing porn with ridiculous frequency cited the "stress" of their jobs as the underlying reason for the nearly uninterrupted pornathons.
* Receiving “over 16,000 access denials for Internet websites classified by the Commission’s Internet filter as either “Sex” or “Pornography” in a one-month period”
* Accessing “Internet pornography and downloading pornographic images to his SEC computer during work hours so frequently that, on some days, he spent eight hours accessing Internet pornography…downloading so much pornography to his government computer that he exhausted the available space on the computer hard drive and downloaded pornography to CDs or DVDs that he accumulated in boxes in his office.”
…to living a porn-free existence at l’office.
But this porn-heavy chapter in the SEC's history is now behind them, according to an internal investigative report viewed by Reuters. Moving boldly forward, the SEC has apparently ushered in a new wave of semi-competence, the sort befitting an agency that is entrusted with keeping our financial systems free of corruption. So, how is the New, Improved SEC doing?
Several Securities and Exchange Commission staffers responsible for monitoring the markets and exchanges broadly misused computer equipment to download music and failed to properly safeguard sensitive information, a report has found.Well, that's one strike for infringement and one strike for not securing sensitive information. "Securing information" seems to be something the SEC's Trading and Markets division is particularly bad at. To say this is ironic would be a colossal understatement, considering the government's current obsession with all things "cyber."
The report also found that the staffers failed to protect their computers and devices from hackers, even as they were urging exchanges and clearing agencies to do just that.
Although no breaches occurred, the staffers left sensitive stock exchange data exposed to potential cyber attacks because they failed to encrypt the devices or even install basic virus protection programs.
The report says the staff may have brought the unprotected laptops to a Black Hat convention where hacking experts discuss the latest trends. They also used them to tap into public wireless networks and brought the devices along with them during exchange inspections.Considering the amount of sensitive information the SEC has access to, it's stunning that the barest minimum of precautionary measures were never taken. This protection-free era of SEC computing occurred during the same period the SEC was issuing guidelines for public companies to follow when reporting security breaches to investors.
In addition to this complete disregard for basic security, the SEC Tradings & Market Division was handed a blank check to purchase equipment, leading to some unsurprising abuse.
[T]he full report... details an even broader array of problems, from misleading the SEC about the office's need to buy Apple Inc products, to cases in which staffers took iPads and laptops home and used them primarily for pursuits such as personal banking, surfing the Web and downloading music and movies.As Levin points out, it's an upgrade from the staff's former pornaholic ways but this report gives off the impression that staffers have simply found new ways to screw up. Would that this report contained anything truly surprising, but it's more of the same. It's not that all government entities are shot through with bumbling fools and opportunists looking for some power to abuse. Individually, there are plenty of good, hardworking public servants. But as an aggregate, nearly every derogatory cliche of government work (and government employees) can be proven true.
Rymer found that the office did not have any planning or oversight into its purchases of computer equipment. From 2006 through 2010, the office got permission to spend $1.8 million on technology devices.
At the very least, I suppose we (the people and the taxpayers) can be grateful that someone is looking into this and, better yet, ushering it out of the darkened hallways of regrettable governance and into the harsh sunlight of public appraisal. But with progress so incremental it barely fits the definition, there's still a long, hard road ahead that will demand the full attention of those tasked with shepherding the (mostly) unwilling herd.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Reader Comments
Subscribe: RSS
View by: Time | Thread
[ link to this | view in chronology ]
New slogan for Apple?
[ link to this | view in chronology ]
also a couple people spending their whole day being totally unproductive at work is likely waaaaaaay cheaper than data being compromised. this isnt a step up its a step down.
[ link to this | view in chronology ]
[ link to this | view in chronology ]
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Government
[citation needed]
[ link to this | view in chronology ]
Of Course...
There is no market incentive to keep the data secure and do a good job.
This is just another of the miriad of examples of why laws against theft should be applied universally, no matter what organization you are a part of/what color clothes you wear/or what euphemism you use to rename theft ("taxation").
I prefer consensual relationships. Try Voluntaryism instead.
[ link to this | view in chronology ]
I could do that job!
I could even work from home. They obviously don't check on their employees, so that won't be a burden to them.
[ link to this | view in chronology ]
IT
> staffers left sensitive stock exchange
> data exposed to potential cyber attacks
> because they failed to encrypt the
> devices or even install basic virus
> protection programs.
Seems to me the problem isn't that these staffers failed to do these things, it's that the SEC apparently has no competent IT department. In my agency, the average employee is not responsible for encryption protocols or installing virus checkers. It's the IT people who do that, and a good thing, too, because some people are so cyber-ignorant that for them just booting up their machine in the morning is a Herculean task.
If the SEC is relying on its secretaries, file clerks, and admin personnel to implement the agency's IT security, they're even more fundamentally screwed than the article portrays.
[ link to this | view in chronology ]
So where is...
When its not a regular person, they can't bend over fast enough to take the Big Media Shaft and spit out all kinds of tolerance and understanding.
[ link to this | view in chronology ]
Incompetence
Yes, 8 hour pornathons can be incredibly stressful. Pro tip: you don't actually have to masturbate to every picture you see.
But the porn stats and the security problems are connected. These people were triggering their web filter thousands of times, but none of them thought to google for "web proxy" to circumvent the filter? They just kept running into the wall over and over?
People with that little amount of problem-solving ability cannot be expected to adhere to even the simplest of security protocols. If I were their managers, I would be reconsidering their employment on the grounds that they just don't appear smart enough for the job.
[ link to this | view in chronology ]
There, restated the problem in two words. I doubt if an individual in private industry would get much further than a tenth of that block total before he was asked to step into the boss's office. The problem with government jobs is they're all carrot, no stick.
[ link to this | view in chronology ]
Very concerning...
But my main reaction is OMG! This is obviously a bureau with some problems. Now, granted, we need to hire highly intelligent specialists for a job like this, not mindless worker drones, and make no mistakes their job is genuinely stressful, but still WTF!
Also, to those of you suggesting we should gut the agency because of their inefficiency, that would be a huge mistake. In fact we really need to increase their funding (along with the banking arms of the consumer protection agency, if such a thing exists). You see Reagan and his successors already gutted this agency, and we got unregulated derivatives trading, the financial crisis and the bailout as a result.
We need more people in the SEC, and we need them to do their jobs.
[ link to this | view in chronology ]
Re: Very concerning...
[ link to this | view in chronology ]
"We have no clue about even the most rudimentary security, but we can assure you nobody much more knowledgeable than us hasn't waltzed right in an helped themselves to our data."
I feel so comforted.
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Better to have 01-SSC-6087 for security purposes.
[ link to this | view in chronology ]
ah ha!
[ link to this | view in chronology ]