[HN Gopher] DEA Investigating Breach of Law Enforcement Data Portal
       ___________________________________________________________________
        
       DEA Investigating Breach of Law Enforcement Data Portal
        
       Author : todsacerdoti
       Score  : 55 points
       Date   : 2022-05-12 11:04 UTC (11 hours ago)
        
 (HTM) web link (krebsonsecurity.com)
 (TXT) w3m dump (krebsonsecurity.com)
        
       | adolph wrote:
       | It's backdoors all the way down.
       | 
       |  _That reporting also showed how the core members of LAPSUS$ were
       | involved in selling a service offering fraudulent Emergency Data
       | Requests (EDRs), wherein the hackers use compromised police and
       | government email accounts to file warrantless data requests with
       | social media firms, mobile telephony providers and other
       | technology firms, attesting that the information being requested
       | can't wait for a warrant because it relates to an urgent matter
       | of life and death._
        
       | adolph wrote:
       | Krebs is funny, writing as if this is something new calling for
       | review.
       | https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
       | 
       |  _If we assume for the moment that state-sponsored foreign
       | hacking groups can gain access to sensitive government
       | intelligence in the same way as teenage hacker groups like
       | LAPSUS$, then it is long past time for the U.S. federal
       | government to perform a top-to-bottom review of authentication
       | requirements tied to any government portals that traffic in
       | sensitive or privileged information._
        
       | encryptluks2 wrote:
       | Sure, lets trust an agency with a history of abuse. Lets believe
       | that politicians like Rudy Giuliani and George Bush had no
       | foreknowledge of 9/11 in order to have Americans gladly give away
       | their freedoms and go to war over false reports.
        
         | saas_sam wrote:
         | Fortunately the Good Guys are in charge now and we don't do
         | that sort of thing anymore.
        
       | hawkeyedan wrote:
       | This is a really important story. I think about all the requests
       | government agencies make for backdoors to things ... then I read
       | something like this ... Ick.
        
       | ImPostingOnHN wrote:
       | This is why law enforcement can't be trusted with arbitrary
       | search (sorry, "scan" [eyeroll emoji]) powers
        
       | bri3d wrote:
       | One would think that groups like cartels already have access to
       | this system, since access seems to be available to quite
       | literally millions of law enforcement employees nationwide.
       | 
       | I think Krebs misses the point a little with the discussion of
       | MFA and PIV cards - sure, this system should absolutely have MFA,
       | but what it really should do is not exist in the first place, and
       | barring that, at least have scoped access control.
        
         | annoyingnoob wrote:
         | The US Government pushes MFA hard. If you work in the DoD
         | supply chain you must have MFA. I find it hypocritical that
         | sensitive government data like this is not protected in the way
         | the government prescribes for contractors. This is a 'what is
         | good for the gander is good for the goose' (yes that is
         | backward from typical) situation. Why not make use of ample
         | resources from CISA?
         | 
         | https://www.cisa.gov/mfa
         | 
         | https://www.beyondidentity.com/blog/us-government-now-requir...
        
       ___________________________________________________________________
       (page generated 2022-05-12 23:02 UTC)