The North Korean hacks into several companies are an example of how bad it is now, add in some good deep fake technology and soon you will not be able to distinguish who is actually working for your company.
The North Korean hacks into several companies are an example of how bad it is now, add in some good deep fake technology and soon you will not be able to distinguish who is actually working for your company.
I think this is one of those things that sucks but may be necessary.
You need to trust the knowledge workers that make up your economy to not send your research to a hostile nation so they can take advantage of your R&D investments.
And you need to know that your critical infrastructure (beyond Internet and trains, think about electricity and running water) isn't vulnerable to being slowly pwned and then shut down all at once in a catastrophic event that coincides with a forcible military reunification of one Asian country with another.
Although the latter problem is less malice and more general incompetence in the cyber security realm. Can't solve that with a security clearance or RTO. Solar Winds anyone?
unfortunately among many circles, it is the opposite. More and more "zero trust" .. more logging and audit, more spot checks, more re-logins .. It is a culture clash, always-on networking has made it much worse, since security professionals have endless lists of problems they see.
Shades of HIPAA. It tries to tackle security and privacy of patient data but it winds up applying large corp requirements (inappropriately) to small practices. There seems to be little distinction of who the regs are being applied to.
One upshot is that small practices have to dedicate resources to understand/audit/report/comply with requirements that don't apply to them.
ex: Extensive audits of how a practice secures local patient data that doesn't exist - because it fully resides on remote provider platforms.
A few years ago everyone thought that would happen to Ukraine, that Russian hackers would shut down everything from water delivery to weapon systems. The hackers almost certainly tried, yet the lights remained on. Imho we overestimate the power of "nation-state hackers" and underestimate the resilience of our systems.
On the other hand, because of early mover advantage, a lot of utilities in the US computerized fairly early but the upfront cost of maintenance remained high.
You were instructed that anything you had in your vehicle when you got to the gate (in the middle of nowhere) might be confiscated. Show up with the rental car, keys, ID, and necessary equipment only. Nothing but you and your clothing would leave the site, yes it cost a laptop each visit (that we sent ahead). ID, car and keys stayed at the gate.
Blindfolded while onsite until you got to the equipment, someone would take you to the bathroom.
It was a lot, but I suspect some form of “all electronics dropped here” should be the SOP in a lot of places.
It kinda horrifies me when I hear about congressional members upset about not being able to take their phones to some meetings and so on.
Aren’t companies required to establish an employee’s origin by bureaucratic means? IDs, SSNs, notarized copies, work permit, etc? Why are North Korean guys even a problem, it feels like they shouldn’t be able to fake identification numbers and permits, unless something is fundamentally wrong with the country’s accounting.
The problem is that identity theft is so ridiculously easily in the US that it's trivial for bad actors to just steal someone's identity. The solution is to fix identity theft.
Not one thing to fix this was done. Anyone could buy my information and be me, NOTHING was done to fix this insanely huge problem.
In my experience, National Security tends to mean the security of (primarily) the US Gov and (secondarily) Gov contractors and major campaign donors. National Security applies to individuals when justification is needed to deploy systems that surveil Americans (not suspected of a crime).
> For a long time the U.S. military resisted the use of PALs. It feared the loss of its own independence, and it feared malfunction, which could put warheads out of action in a time of crisis.
I’m also heavily “leaked”, but nobody can do anything with my numbers without actual counterfeiting. I could share my ids here if not for pseudonymity. The fact that your identity can be legally hired into a company without your proven id hard copies, that’s the root of the problem, imo.
The US is plagued by stupid right wing people who think that ID is satanic, and stupid left wing people who think that ID by nature will marginalize poor people. Because we’ve allowed the federal government to outsource ID to the states, the US is stuck with inadequate identity framework for a long time.
Doesn't this result in more over the shoulder opportunities by insider threat actors (i.e. spies) in conventional open office settings? Unclear how this meshes with outsourcing also.