[HN Gopher] DEA Investigating Breach of Law Enforcement Data Portal
___________________________________________________________________
DEA Investigating Breach of Law Enforcement Data Portal
Author : todsacerdoti
Score : 55 points
Date : 2022-05-12 11:04 UTC (11 hours ago)
(HTM) web link (krebsonsecurity.com)
(TXT) w3m dump (krebsonsecurity.com)
| adolph wrote:
| It's backdoors all the way down.
|
| _That reporting also showed how the core members of LAPSUS$ were
| involved in selling a service offering fraudulent Emergency Data
| Requests (EDRs), wherein the hackers use compromised police and
| government email accounts to file warrantless data requests with
| social media firms, mobile telephony providers and other
| technology firms, attesting that the information being requested
| can't wait for a warrant because it relates to an urgent matter
| of life and death._
| adolph wrote:
| Krebs is funny, writing as if this is something new calling for
| review.
| https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
|
| _If we assume for the moment that state-sponsored foreign
| hacking groups can gain access to sensitive government
| intelligence in the same way as teenage hacker groups like
| LAPSUS$, then it is long past time for the U.S. federal
| government to perform a top-to-bottom review of authentication
| requirements tied to any government portals that traffic in
| sensitive or privileged information._
| encryptluks2 wrote:
| Sure, lets trust an agency with a history of abuse. Lets believe
| that politicians like Rudy Giuliani and George Bush had no
| foreknowledge of 9/11 in order to have Americans gladly give away
| their freedoms and go to war over false reports.
| saas_sam wrote:
| Fortunately the Good Guys are in charge now and we don't do
| that sort of thing anymore.
| hawkeyedan wrote:
| This is a really important story. I think about all the requests
| government agencies make for backdoors to things ... then I read
| something like this ... Ick.
| ImPostingOnHN wrote:
| This is why law enforcement can't be trusted with arbitrary
| search (sorry, "scan" [eyeroll emoji]) powers
| bri3d wrote:
| One would think that groups like cartels already have access to
| this system, since access seems to be available to quite
| literally millions of law enforcement employees nationwide.
|
| I think Krebs misses the point a little with the discussion of
| MFA and PIV cards - sure, this system should absolutely have MFA,
| but what it really should do is not exist in the first place, and
| barring that, at least have scoped access control.
| annoyingnoob wrote:
| The US Government pushes MFA hard. If you work in the DoD
| supply chain you must have MFA. I find it hypocritical that
| sensitive government data like this is not protected in the way
| the government prescribes for contractors. This is a 'what is
| good for the gander is good for the goose' (yes that is
| backward from typical) situation. Why not make use of ample
| resources from CISA?
|
| https://www.cisa.gov/mfa
|
| https://www.beyondidentity.com/blog/us-government-now-requir...
___________________________________________________________________
(page generated 2022-05-12 23:02 UTC)