Encryption “would not have helped” at OPM, says DHS official
arstechnica.com
arstechnica.com
It's not surprising that corporations and governments don't take steps to avoid these problems when an 18-month membership in some identity theft insurance program is considered equitable compensation for losing 10-years' worth of personal information.
Few people have direct experience with that, remember that many of these systems are essentially the "second" generation of automation that has gone on in government. Systems built in the 90's were not even imagining the kinds of drive by side-load sandbox hopping attacks that are routine today. I expect it to get worse before it gets better but the new Digital Service has some interesting ideas there. I fear such things will lead to nationalizing the Internet as well and that bothers me, I still believe (perhaps naively) that it is possible to secure large networks from even persistent threats given the tools at our disposal.
"It would be incorrect to say that these older systems (especially the COBOL code) couldn't be updated to support encryption, however. There are numerous software libraries that can be used to integrate encryption schemes into older applications, including libraries from PKWare. Other government agencies and financial institutions already utilize such software, according to Matt Little, VP of Product Development at PKWare. The problem is that, as DHS Assistant Secretary for Cybersecurity Andy Ozment noted during his testimony, OPM didn't have the kind of authentication infrastructure in place for its major applications to take advantage of encryption in the first place. Encryption, he said, would "not have helped in this case."