sigalrm’s Techdirt Comments

Latest Comments (305) comment rss

  • On the post: Second OPM Hack Revealed: Even Worse Than The First

    icon
    sigalrm (profile), 15 Jun 2015 @ 8:16am

    Re: Another thought

    "I wonder if he knew about the operational insecurity of the OPM? "

    Maybe. Doesn't really matter.

    "You have to admit that it would have saved an awful lot of hot mess if he had warned the government about it before it happened."

    Unlikely. History shows - repeatedly - that such warnings - at best - would have been ignored and at worst would have been received with great hostility.

    "In that case, he would have been awarded a medal for it and given a better job."

    No. Having embarrassed the Authorizing Official (required under FISMA, look it up) for whichever system it was, he'd have been lucky to have gotten the equivalent of an "atta boy, good job, go back to work" and subsequently having the report shelved, not be be looked at again until some reporter filed a FOIA request for it.
  • On the post: Second OPM Hack Revealed: Even Worse Than The First

    icon
    sigalrm (profile), 15 Jun 2015 @ 8:05am

    This is exactly what happens...

    When you give up privacy for security.

    I mean, don't get me wrong - there's no question that this is really bad. But if we, as a country, continue to centralize information on everybody in the name of security, then before too many years have elapsed, we're going look back on this particular breach as being small scale and, dare I say it, quaint.
  • On the post: Amendment Blocking Backdoor Searches, Backdooring Encryption To Be Added To Defense Funding Bill

    icon
    sigalrm (profile), 11 Jun 2015 @ 12:08pm

    Re: That'll teach 'em to mess with JQ Public... NOT

    And the other portion of the internal dialog...

    "Well, crap, congress says we can't use these dollars for surveillance. Guess we better tack another $500mm onto the black budget..."
  • On the post: FBI Successfully Stonewalls Inspector General Into Irrelevance By Withholding Timely Section 215 Documents

    icon
    sigalrm (profile), 10 Jun 2015 @ 2:49pm

    Re: Re: OIG without Power

    There's a saying I heard years ago (I don't know who to attribute it to, or I would):

    If you're given responsibility, but no authority, then your job is to take the blame when things go wrong.
  • On the post: US CIO Orders All .Gov Websites To Require Encrypted Connections, Amazon Enters The Secure Cert Space

    icon
    sigalrm (profile), 10 Jun 2015 @ 12:29pm

    Re: Re: Refreshing honesty

    A new usa.gov root cert installed and trusted by default in every major browser and OS?

    Seems legit.
  • On the post: US CIO Orders All .Gov Websites To Require Encrypted Connections, Amazon Enters The Secure Cert Space

    icon
    sigalrm (profile), 10 Jun 2015 @ 12:20pm

    Re: Re:

    Yes, but do they have a root certificate openly tied to the US Government pre-installed in every major browser and operating system? https://www.irs.gov's ssl cert is issued by Akamai and fails to validate due to a hostname mismatch. https://www.whitehouse.gov is signed by Verizon/Akamai. https://www.cia.gov is signed by Symantec.

    The US Government is big, and if they're going to successfully implement this mandate, they're going to need their own public root certificate authority to cost effectively sign all those new SSL Keys, and for the sake of simplicity, that root CA cert will need to be installed everywhere by default. Otherwise Grandpa is going to get a browser cert error when he goes to www.irs.gov, and we can't have that.

    Of course, once a root is installed, it can be used to sign certs for any web site.
  • Next >>


    This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it