DOGE has enough real problems that we don't need to cry wolf about its hypothetical (although maybe "inevitable") future actions.
DOGE has enough real problems that we don't need to cry wolf about its hypothetical (although maybe "inevitable") future actions.
It is very much under dispute whether or not the data has been used/shared in a legal manner.
Imagine a new CEO arrives at <b2b platform tech company> and has stated their top goal is to cut costs and improve efficiency.
Then imagine this CEO brings in outside technical people and instructs the existing security team to grant full access to all customer data. They plan to analyze this data to assess how customer’s use of the platform impacts operating costs.
This would be insanely inappropriate and would likely breach customer contracts and break privacy laws. It is of little comfort that the “breach” is wholly “inside” the company.
In almost every large organization, there are numerous internal boundaries that large amounts of data should never cross for any reason. Framing this as “the government having access to government data” is problematic, for the same reason a tech company allowing unfettered access to customer data for some analysis project could not be described in good faith as “the company having access to company data”.
Exactly who it is within the organization that has access to the data and how that access aligns with existing laws/policies is extremely important.
Our company would sign a confidentiality agreement with McKinsey.
This would be perfectly valid.
There are restrictions that some clients put on consulting companies like everyone on the project has to go through background checks, be US citizens (some government contracts) or have security clearance. But those are some other rules that Musk and team are breaking.
In other words, any contract between businesses usually has a broad chain of confidentiality that goes down to subsidiaries and sub contractors.
Imagine working IT and having to train people that even when their jobs are directly threatened they are still supposed to withhold data, and then those same people are fired anyways for complying with security policy.
And people are gleeful that these people are losing their jobs.
This absurd oversimplification needs to be called out.
The 'government' is not a single individual, nor should 'government data' be treated without regards to specifics.
The exact entity doing the accessing, and the exact data that's being accessed, all need to be accounted for, and the appropriateness of the access will change depending on the context.
DOGE hasn't been transparent in any of this, which is my chief complaint at the moment.
Obviously we have an extensive framework for data security within the government that is built upon the idea that compartmentalization of data and limiting access is incredibly important.
Even in situations where it is unavoidable that someone have access to data as a function of their job requirements, we very frequently have strict logging and auditing of access to that data. You might not be able to reasonably prevent a DBA from having access to the information in a database and allow them to still perform their work, but plenty of places will log and audit every action they take and review them accessing that data.
We know there are people in DOGE that clearly would not pass security screenings for access to the data that they have - one of them was recently fired for leaking data from their previous employer!
Acting like the fact that they are nominally part of the government so it is OK for them to have basically unfettered access to all sots of sensitive information is bizarre to me.
One of the main points of privacy legislation is to functionally limit the government's ability to collect, use, disclose, and retain personal information in the first place. That's entirely contrary to the idea that government departments can share or access it pell-mell.
I feel like this is a bad episode of the Twilight Zone.
No, “vetting” basically means they checked to see if you ever got caught embezzling money, or in the case of clearances, if you lied about committing any crimes (committing them is ok). They are regular people and getting them to abide by sensible IT policies is a giant nightmare and compliance is poor.
Heck, have people already forgotten Trump’s tax returns were leaked by politically motivated “vetted” people working for the IRS? Not the first time that happened either. And they didn’t even find anything interesting!
I am so primed to parse emoticons eagerly that I thought that the philosophy was :《
However little is involved in vetting, it's something that has been done for regular government employees and hasn't been done for these employees. I'd rather have minimal safeguards than none.
It is entirely possible for an insider or internal data incident to be a "breach," regardless of whether the data leaked outside the org or they had the permission of the President. If someone came in to my office with an employee badge, said that they had been personally hired by the CEO, and demanded super admin access to all systems, I would laugh in their face. If anyone actually agreed to that person's demands, it would be a massive, all-hands-on-deck incident to figure out what they touched and how much we were going to get fined for the breach in security controls.
I wouldn't discount such reckless vulnerabilities happening here. Any decent IT department would faint imagining the overtime needed to fix such issues.
Yeah in theory they’re both parts of “the government” but “government” is a big umbrella that comprises a bunch of separate entities, each with varying degrees of independence from each other. We’re used to thinking of it all as one entity because we’re used to operating under political leadership that isn’t actively trying to destroy the government. But now that they are, the separation of duties matters a lot more. All of this stuff is happening either in violation of, or indifference to the actual law.