Privacy Incident Involving DHS OIG Case Management System
dhs.gov
dhs.gov
I've lost track now.. which one do you mean?
The OPM breach of the SF-86 database is still the worst and most catastrophic that I'm aware of. That was larger (millions), was the result of background checks (aka blackmail fodder), included full read/write access (tainted?), and likely every position that required a clearance outside the CIA.
This one seems especially terrible because it had information on people unrelated to the US government.
*I had a Secret 10+ years ago.
> “...unauthorized unauthorized transfer of data.”
Am I being dense or is this unintended?
FTFY.
It's actually a pretty good way to explain speculative execution. You know you might need to so something so you just do it using the slush fund and if it isn't useful you toss the result and if it is useful you keep doing it while papers are shuffled around and authorization happens. Certainly not ideal but not unheard of either.
Investigative Data: Individuals associated with DHS OIG
investigations from 2002 through 2014, which includes
subjects, witnesses and complainants who were both DHS
employees and non-DHS employees. The PII contained in this
database varies for each individual depending on the
documentation and evidence collected for a given case.
Information contained in this database could include names,
Social Security numbers, alien registration numbers, dates
of birth, email addresses, phone numbers, addresses, and
personal information provided in interviews with DHS OIG
investigative agents.
Most of that is business-as-usual for a DB leak, but there's something that catches my eye: personal information provided in interviews with DHS OIG
investigative agents.
Would this only be information provided by people about themselves, or does the inclusion of "subjects of investigations" mean that this is a colossal dump of life-ruining hearsay that could destroy anyone that DHS has ever touched?Speaking of which, this bit at the end disgusts me:
What is DHS doing to better secure employees’ PII?
Why does this read as anything other than "What is DHS doing to better secure american citizens' PII"? DHS employees aren't the only people affected by this. I'd expect "subjects, witnesses and complainants of DHS investigations" to number in the millions.OIG is internal affairs. The people they investigate are employees, not the public.
You don't lose the right to protection from someones incompetence just because you're employed by them.
https://www.gpo.gov/fdsys/pkg/FR-2015-07-27/html/2015-18385....
https://www.gpo.gov/fdsys/pkg/FR-2015-07-27/html/2015-18385....
The OIG investigates complaints against DHS (and child agencies) officials, employees, and policies brought by Congress, the public, and other agencies. It's similar to the stereotypical Internal Affairs department in every police movie.
> Last week, Eric Hysen announced that he’s leaving the White House’s U.S. Digital Service (USDS) to establish a similar team within DHS, as the agency’s digital service lead
According to his Twitter and LinkedIn info, Hysen has apparently left DHS and now works at the Chan Zuckerberg Initiative.
According to the 2016 USDS report to Congress [1], USCIS (Citizenship and Immigration), an agency within DHS, did collaborate with USDS and 18F to launch a modernization of its immigration requests system. Given the size of DHS, I seriously doubt that this effort alone would have significantly impacted or involved other agencies in DHS.
The USDS 2017 report [2] mentions DHS as one of 7 federal agencies at which they have "active teams", but no other details are given.
[0] https://fedtechmagazine.com/article/2015/10/dhs-creates-digi...