> Worse… access to ALL of this information was given to certain foreign contractors, some of whom were in China.
Pretty sure this is unproven and, regardless, had nothing to do with the hack.
Pretty sure this is unproven and, regardless, had nothing to do with the hack.
I think this whole "foreign contractors" angle is sourced to a single anonymous ex-contractor speaking to Ars. Even if true, I don't think there's any evidence it has anything to do with this hack.
I still feel like I'm a little lost in the essay, though. It's easy to say that all data requires senior people to sign off before data can be decrypted. But that sounds really hard to implement and even harder to legislate. What specifically are you asking for? What am I supposed to be asking my representative to do?