Total lapse of “Layer 8 security”… Why things in the IT industry need to change soon!
I got this story mailed to me and I thought “good god!”. Where I live we are not quite as affected as other countries by the war on terror and especially not about the terrorist threat (well not much and who knows where Scandinavia is anyway!).
So maybe I am totally off by saying: WTF! The USA is spending tons of money on the war on terror and on homeland security but a normal office clerk can walk out of the Los Alamos with highly classified NUCLEAR documents? Who needs all this high tech anti terror stuff if all they need is a contractor filing clerk? And before you say: They can’t get nuclear material that easily! Well we have this big ex-communist country next to us and they are wiling to sell
Plus there is now Iran and all the other countries that are starting their nuclear testing “for energy purposes only”.
This whole story brought that cute old song: Underwear Goes Inside The Pants by LAZYBOY back into my head. Especially the part : Who´s the mastermind here, you or me…?
I mean, come on, this is total failure of any security or surveillance grade. And since this is not a recent issue I am more and more inclined to say this is a “Layer 8 ” failure (OSI Layer model…Layer 8 is the “user” :)). User education should have been done. And who qualifies anyone with half a semester of college as a “nuclear knowledgeable person”? That is like putting a “Helldesk” (yes, I have worked there too in my humble beginnings
), 1st level support person as a mission critical database administrator.<- YOU DON'T DO THAT!
The trend I see more and more with all this outsourcing is that everyone wants a big chunk of the contract cash so they go for the cheapest common denominator: anyone that can use a mouse and a keyboard, and sell them as specialists and experts. I cannot tell you how many times I had to laugh over these specialists that get paid more then most of us regularly employed people but don't know their bits from their bytes much less the stuff they are supposed to be specialized in. And corporations and governments put up with it. WHY? Why only in the IT industry? Hospitals ship their entire patients medical records to India to be indexed or managed because its cheaper. Yes, its also extremely high risk but I guess those damagers (managers) want to keep costs low and their fat bonus checks up. so budget cuts and savings it is.
I think in the last few years we have had more data theft and “data misplacement” then in the whole last century. But hey, we need to send 31 (or 36) pieces of information about our travel itinerary to the USA before the planes are allowed to land. What for? So it can be shipped to India for indexing or so that a low-level clerk can walk out the front door with all the data and sell it to the identity thieves around the corner?
Welcome to the world of absolutely NO privacy. Don’t even bother to try to keep it. This is the world where us Security people try to make amends with what we get AFTER the budget cuts so that we can provide the other people at least SOME sort of security and privacy. But I can see in the distant future this will all be obsolete, You will all have a RFID tag embedded and anyone can scan you and get your data. After all its for all out best since we need to fight the war on terror! Whoopdidoo.
No TagsPopularity: 4% [?]
Where *nix and security meet the general public
[…] nowadays? How can it be that we are shipping our personel files to OTHER COUNTRIES? Bye bye privacy!http://blog.2blocksaway.com/2006/12/12/total-lapse-of-layer-8-security-why-things-in-the-it-industry…Find Jobs - Environmental, Health, Safety, & Secutiry Manager Jobs …May 12, 2008 … […]