Army National Guard announces data breach
nationalguard.mil
nationalguard.mil
I think it's laudable that the Army National Guard would do a breach notification when there's only the possibility of malicious data loss.
One key difference is that the U.S. is already testing the technology and process necessary to carry out such an operation---reference the drone strike.
Just input corporation, firm or department name.
Select multiselect dropdown "what you take very seriously".
Select number of "employees|customers|people" (pick one) that will get free credit monitoring.
Select for how long.
Press [Submit]
Input payment information.
Press release automatically issued.
(we( at )?|CORP_NAME) take your (data|privacy|security|information) very seriously
"OMG we're in!"
This more like a breach of standards. At least they know where the data went. The OPM breach is far worse.
Say we'd like to know if A exists. There's some evidence for A's existence, which we'll E. The absence of this evidence is ~E.
By Bayes' theorem:
P(A) = P(A intersect E) + P(A intersect ~E) = P(A|E)* P(E) + P(A|~E)*P(~E)
So the probability that A exists is a weighted average of the probability that A exists when there is and is not evidence.(Since P(E)+P(~E)=1) There is a kind of 'conservation of probability'.
If the idea that 'E is evidence of A' is to mean anything at all, then it means that P(A|E) > P(A). Hence P(A|~E) must be less than P(A). Another way to say it is that P(~A|~E) > P(~A). And absence of evidence is absence of evidence.
Negative evidence is not the same thing as the utter and complete non-existence of any evidence whatsoever—the absence of evidence. That's because negative evidence absolutely is evidence.
The saying goes, 'the absence of evidence is not evidence of absence' not 'the evidence of absence is not evidence of absence'. See the difference?
Watch the linked video when you have a moment.
I wasn't. ~E is a shorthand way to write that E is not found, not that the opposite of E is found. In the language of probability/set theory, ~E is E's complement - every event in the space of probabilities except for what's in E. It's the unique set such that ~E intersect E = empty set, and ~E union E is the whole space.
The point of the proof I gave is that there is no distinction between 'negative evidence' and 'absence of evidence'.
As I mentioned earlier, there is a kind of conservation of probability. The only way for a piece of evidence to give evidence for A is that the lack of that evidence reduces the probability of A. The probability mass has to come from somewhere.
You where. What you are describing is, 'we constructed a hypothetical experiment and arrived at a null result'; that is, in fact, evidence.
No one is saying, 'a null result is not evidence of absence'.
Please stop conflating the presence of something with the absence of something.
Yes, the statement is a tautological statement. We are repeating the same assertion twice using different phrasing. And as such, the proposition as stated is logically irrefutable.
'No evidence is no evidence', is a correct—but diminished—restatement.
Have you watched the video?
Let's go back to my original example and say we want to know if A is true. We have the choice to run an experiment whose positive result E would give support to A. The linked video would say that before we run any experiment, we have no additional evidence for A. Essentially that P(A) = P(A). This is true.
The way this should be used in the real world is: I look even the slightest bit for A and don't find it. As long as my search for A had the smallest positive chance of finding it were it to exist, then my lack of ability to find A gave me information about the world, and we get that P(~A | ~E) > P(~A).
Edit: To be precise the maxim should be something like: "Absence of evidence after looking for evidence is evidence of absence".
Again, what is being said is, 'no evidence is no evidence'. If you have the absence of evidence then you have no evidence of absence.
We are--kind of--using the word absence in two senses. First as a synonym for none, a number less than one, zero; the second as a synonym for non-presence, non-existence, the lack of an extant sample.
Having zero [absent] evidence is not evidence that there is no extant sample [absence]. I hope that helps.
Say I'm looking for alien civilization. I write a magical program to search one planet at a time, and stop when it finds an alien civilization. I argue that with every planet that fails the test, we should consider that as information toward the case that this program will never stop. I think these claims are testable if crafted into narrower versions.
A reframed version of the maxim would be: Absence of evidence is not information for evidence of absence. Another reiteration could be "absence of evidence does not provide predictive utility toward any claims on the evidence of absence". I claim the opposite.
I think the author of your link would say that in my rephrasing of things, the whole class of my examples are negative evidence, because he counts any information as negative or positive evidence, and in consistency he demands perfect ignorance. No peeking in the cat box. Unfortunately, me scanning for planets counts as peeking, or getting information, into portions of a very large cat box.
And so the tautological saying, 'the absence of evidence is not evidence of absence' still stands unassailed.
Things are getting better and the DoD has switched to a non-SSN identification number but the SSN is still frequently used.
They started issuing cards with an EDIPI on them relatively recently, which is a step in the right direction, but there's still a lot of work to do.
The DOD originally switched to the SSN from the previous service numbers, as in "name rank and serial number". It was a convenience measure, since the service number system was arcane.
Service numbers were also public record, and I've read documents indicating that social security numbers were not considered sensitive information (notwithstanding the fact that the DOD didn't have the concept of PII formalized back then).
Should the DOD have moved back to another serial number system sooner? Possibly. I'm amazed that they're moving at all.
You authenticate everywhere using a long number (PIN) (so long you have to write it down and store it). All the services you authenticate with will store this PIN unhashed.
You should keep your PIN safe, because it can be used to apply for bank accounts, loans, and commit tax fraud if it is stolen.
If you ever forget your PIN don't worry. We will print it on various letters and mail them to you. If you need it urgently, you will find it next to your name in various post-hack data dumps around the internet.
Which could be anything. For example, an AWS server somewhere. Or, how about a VPS hosted by GoDaddy? A lame attempt at humor. Yet, what do we really know?
> by a contract employee,
Which could be anybody, right?
> we do not believe the data will be used unlawfully
We don't guarantee...we do not "believe".
More detail would have been useful. If my data was with the Guard I would not know what any of the above meant other than my data was made available to a contractor who uploaded it to a random server somewhere and, at the moment, it could be floating in space for anyone to grab.
Brilliant.
1) This was an external press release. It's possible communication to the actual Guard had more detail. Or not; it's the military, and they'll tell you what you "need to know."
2) While they don't guarantee the data wasn't leaked, I read that as more in the sense that "The non-DoD-accredited datacenter is outside of our auditing trail" than in the sense that it's actually likely the data was leaked. If you take my state's drivers' license database and uploaded it to AWS, the state can't "guarantee" the data wasn't used unlawfully either, but you can be certain that Amazon has a lot to lose if some failure of their infrastructure gives China access to a list of passport-authorizing documents.
The irony that the data had been uploaded to a physically secured, encrypted datacenter network from 27 DVDs in the possession of someone who could do whatever they wanted to with the contents of those DVDs without audit was not lost on me.
I don't reference this to imply it was good and proper use of the data; merely to note the difference between policy security and actual security.
I feel like this phrase has become the mating call of organizations who aren't serious about security until they get hacked.
Edit: I just had a look and found AWS is actually DoD-certified http://aws.amazon.com/compliance/dod/. I wonder what the data centre in question could be.
This Inwill guess is the least awful of a series of breaches to be released, as everyone falls over themselves to check their seals.
The shear between the tools publicly available on private data networks for analyzing and slicing bulk data and the tools available on cloud networks is wide and growing. As it continues to widen, you can anticipate that more and more tech-savvy mid-level staff in government positions will look at the status quo and say "I could follow policy to the letter, or I could use the cheap-and-easy tools I'm familiar with to get some Goddamn work done and trust that data living in AWS is at least as secure as where it currently lives, in that tool-shed-looking building on the back of the base with the door that doensn't quite latch correctly."
http://www.troyhunt.com/2015/07/we-take-security-seriously-o...