Coupons On Thier Way to Your Door in 24 Hours
Showing posts with label VA. Show all posts
Showing posts with label VA. Show all posts

Thursday, July 26, 2007

Worst Case Scenario

I have recently posted some articles about security failures as it relates to computers that can't be accounted for and sensitive digital information transmitted in an unsecured way. That's not to mention the laptop computer that was taken home by a Veterans Administration employee and was subsequently stolen compromising some 26.5 million records. And then we bring into play the complete charlie foxtrot that CITIGROUP has made of the processing of US Passports.

What gives?

I mean, we're talking about a complete lapse of security and accountability here. From one aspect, military personnel not only have to be deployed to war zones, but now they have to worry about their own and their family's identities? That's the kind of distraction that could get someone killed. Shame on you, SAIC.

Then there's the retired military personnel, the veterans, who may not have much in the way of economic stability in the first place, who have to worry about the same issue. Veterans information was exposed once, but TWICE this year. Proud men and women serve their country bravely and their repayment is exposure to potential bad guys. Shame on you, VA.

If all that weren't bad enough, US Passports are back-logged in proportions never before seen. It's one thing when your vacation plans are fouled because your US Passport was delayed until the 12th of Never. It's another thing when you finally get your US Passport, but there are errors like a wrong date of birth, incorrect birth location; but, my favorite is it having the wrong picture (I can't make this stuff up). The kicker is when your US passport application gets lost completely. Your photos, application, application fee, and your birth certificate or previous passport are just gone (POOF!). Shame on you, CITIGROUP.

"OK. All that sucks, but why are you birthing a calf over it?"

Aside from identity theft within the country, which has become a past time for some bad guys, what happens if Al-Qaeda gets their grubby little hands on this information or some of the missing passport applications? They've got their computer geeks too, you know.

Digital and domestic terrorism, that's what happens. This goes far beyond the scope of the Red Cross Scam that targeted the spouses of deployed service members. Who knows how that information got leaked.

Please allow me to present a plausible scenario to you.

The bad guys get the information because it is lost, stolen, or otherwise misplaced. They steal the identities of veterans, military personnel and their families and cause complete economic havoc by running up credit cards and transferring savings to off-shore accounts to fund further terrorist activities. Millions of people become poor and destitute while they wait for the government to "solve the problem". What an incredible horror to know that not only have you lost everything, but that what you lost went to finance terrorist activities.

The second wave comes when military families and other citizens start getting threatening phone calls or suspicious letters containing a "strange white powder". Can you imagine the terror that would be instilled? You get a spooky phone call at three in the morning or open a letter you think is junk mail only to have white powder fly all over you and you rush to the Emergency Room. Now that Federal and Local law enforcement have their hands more than full, the next step comes.

The bad guys get the passports applications that were "lost", replace the pictures and reapply using false ID, which isn't that hard to get. And in the cases where the fees were paid with a money order, the poor person whose application was lost in the first place has now paid for a bad guy to gain access to the country. It's an open back door that anyone can walk right through while authorities are tracking down who was responsible for the first two steps.

The insanity of this is that I just thought of it. Me. A simpleton, for all intents and purposes. If I could dream up a nightmare like this, so can the bad guys. Or maybe the can one up me.

The time has come for us as citizens to start demanding the protection we're entitled to and the protection we were promised. Write your Representatives and Senators. Inundate them with letters, e-mails and phone calls. If everyone gets involved and does this, maybe, just maybe, for one day, a committee of some sort, perhaps the entire House or Senate won't be able to conduct business because of concerned and angry correspondence and phone calls. Then they'll step back and really look. "Why can't we do business today?" could turn into "Who's responsible for the lack of security?" and that could lead to action.

This is our time. Do we wait for the bad guys to come to us? I mean, certain government agencies have all but invited them, right? Or do we kick somebody in the pants to motivate them for our own protection? We elected our government officials and we pay their salaries. It's time they started working.

VA Lost 53 Computers, Auditors Say

Oh, for the love of God. What's this, the third time this year? Somebody needs to pull their head out and make sure accountability is happening.



VA lost 53 computers, auditors say

Amy Doolittle - Staff writer
Posted : Wednesday Jul 25, 2007 10:59:08 EDT


The Veterans Affairs Department has lost 53 computers that could include veterans’ sensitive, personal information, a new Government Accountability Office report said.


The computers are missing from four locations across the country. McCoy Williams, director of financial management and assurance at GAO, said veterans’ information possibly could be stolen as a result of the losses.


Williams said VA does not know who was using the computers before they went missing or what information was stored on them.


“We’re not sure ... we basically looked at the environment from a standpoint of ‘could it happen,’ and based on what we saw, the possibility exists” for information to be stolen, he said. “In a situation like this, you only need one case for messing up a whole lot of people.”


VA officials cautioned that missing laptops do not necessarily equal stolen information but nevertheless said the chance for a security breach still exists.


“I would say there’s a slim chance of it being stolen,” said Robert Howard, assistant secretary for information and technology at VA. “With all of the problems we’ve had, I have not encountered any case to my knowledge of identity theft as a result of these instances. Will information be exposed to the wrong people? Yes, we do have knowledge of that.”


The GAO audited three VA medical facilities and VA headquarters as part of their investigation. They found that as of March, officials at the Washington, D.C., VA medical center did not know the location of 28 percent of their information technology inventory. Six percent of the IT inventory was missing from the Indianapolis medical center, 10 percent from the San Diego center and 11 percent from D.C. headquarters.


“The four locations we audited put IT equipment at risk of theft, loss and misappropriation and pose continuing security vulnerability to our nation’s veterans with regard to sensitive data maintained on the equipment,” Williams said Tuesday at a hearing of the House Veterans Affairs oversight and investigations subcommittee.


The GAO also found that used hard drives waiting to be cleared were stored in unsecured bins at the facilities, even though many of them contained sensitive data. Rooms where potentially sensitive data was stored also lacked required security, auditors said.


“When you leave those hard drives, there’s always a possibility that someone will come in and take it,” Williams said at the hearing.


In addition to the items that are currently missing, the audited VA locations reported a total of 2,400 missing IT items valued at $6.4 million over 2005 and 2006, GAO found.


VA officials said they are working to put in place better safeguards to keep tabs on where equipment goes and who has it. They said they have put together a handbook for tracking equipment and will soon put in place new tracking software.


Officials said that since the investigation was concluded, 1,457 of the 1,900 items missing from headquarters have been recovered. That leaves 443 items that are simply lost and likely will never be recovered, they said.


Last year, the personal information of over 26 million veterans and active-duty personnel was lost when a VA laptop was stolen from the Maryland home of a VA analyst. That computer was recovered several months later.


Rep. Tim Walz, D-Minn., an Iraq veteran, said the effects of data insecurity extend beyond potential loss. He said the carelessness of VA is demoralizing to veterans.


“It has a very corrosive effect in trusting the VA in general,” Walz said. “Each of the [committee] members are sensing the frustration among constituents and veterans that this is one of the issues we speak of often and see very little movement on.”