I see this time and again. All the data in a single database where one compromised access can get it all. Data should be compartmentalized, and rate limited.
I see this time and again. All the data in a single database where one compromised access can get it all. Data should be compartmentalized, and rate limited.
If I recall, some of those references also got notifications in the mail.
That said, the compromised database was from a civilian, non-intelligence agency. Of course, logically, CIA agents shouldn't have been in that database but it seems they were.
And the other thing is that you have CIA, NSA etc working hard to spy on everyone but none of them were willing and able to keep the larger Federal Government from having terrible security practices. Which comes from the intelligence agencies being more about catching people and learning secrets than about protecting the US as such.
Yet they had fingerprints, meaning they must have gotten the data from the government.
But it does lead to a larger question. Articles by cybersecurity people always seem to focus on preventing unauthorized access. I've never read one that talked about given the inevitability of unauthorized access, how to avoid losing everything?
After all, we have ships with watertight compartments. Even spy networks are organized into "cells" to limit the damage from compromised agents.
Why is security not talking about compartmentalization?
Well, this is one article and it's always possible this is one of those "write down official X's talking points" articles, and official X doesn't talk about compartmentalization because the impression they are aiming for is "look us, we're helpless, helpless against these threats, please give us unlimited money and power and might be able to fix things, if we're lucky."