Coupons On Thier Way to Your Door in 24 Hours
Showing posts with label SAIC. Show all posts
Showing posts with label SAIC. Show all posts

Thursday, July 26, 2007

Worst Case Scenario

I have recently posted some articles about security failures as it relates to computers that can't be accounted for and sensitive digital information transmitted in an unsecured way. That's not to mention the laptop computer that was taken home by a Veterans Administration employee and was subsequently stolen compromising some 26.5 million records. And then we bring into play the complete charlie foxtrot that CITIGROUP has made of the processing of US Passports.

What gives?

I mean, we're talking about a complete lapse of security and accountability here. From one aspect, military personnel not only have to be deployed to war zones, but now they have to worry about their own and their family's identities? That's the kind of distraction that could get someone killed. Shame on you, SAIC.

Then there's the retired military personnel, the veterans, who may not have much in the way of economic stability in the first place, who have to worry about the same issue. Veterans information was exposed once, but TWICE this year. Proud men and women serve their country bravely and their repayment is exposure to potential bad guys. Shame on you, VA.

If all that weren't bad enough, US Passports are back-logged in proportions never before seen. It's one thing when your vacation plans are fouled because your US Passport was delayed until the 12th of Never. It's another thing when you finally get your US Passport, but there are errors like a wrong date of birth, incorrect birth location; but, my favorite is it having the wrong picture (I can't make this stuff up). The kicker is when your US passport application gets lost completely. Your photos, application, application fee, and your birth certificate or previous passport are just gone (POOF!). Shame on you, CITIGROUP.

"OK. All that sucks, but why are you birthing a calf over it?"

Aside from identity theft within the country, which has become a past time for some bad guys, what happens if Al-Qaeda gets their grubby little hands on this information or some of the missing passport applications? They've got their computer geeks too, you know.

Digital and domestic terrorism, that's what happens. This goes far beyond the scope of the Red Cross Scam that targeted the spouses of deployed service members. Who knows how that information got leaked.

Please allow me to present a plausible scenario to you.

The bad guys get the information because it is lost, stolen, or otherwise misplaced. They steal the identities of veterans, military personnel and their families and cause complete economic havoc by running up credit cards and transferring savings to off-shore accounts to fund further terrorist activities. Millions of people become poor and destitute while they wait for the government to "solve the problem". What an incredible horror to know that not only have you lost everything, but that what you lost went to finance terrorist activities.

The second wave comes when military families and other citizens start getting threatening phone calls or suspicious letters containing a "strange white powder". Can you imagine the terror that would be instilled? You get a spooky phone call at three in the morning or open a letter you think is junk mail only to have white powder fly all over you and you rush to the Emergency Room. Now that Federal and Local law enforcement have their hands more than full, the next step comes.

The bad guys get the passports applications that were "lost", replace the pictures and reapply using false ID, which isn't that hard to get. And in the cases where the fees were paid with a money order, the poor person whose application was lost in the first place has now paid for a bad guy to gain access to the country. It's an open back door that anyone can walk right through while authorities are tracking down who was responsible for the first two steps.

The insanity of this is that I just thought of it. Me. A simpleton, for all intents and purposes. If I could dream up a nightmare like this, so can the bad guys. Or maybe the can one up me.

The time has come for us as citizens to start demanding the protection we're entitled to and the protection we were promised. Write your Representatives and Senators. Inundate them with letters, e-mails and phone calls. If everyone gets involved and does this, maybe, just maybe, for one day, a committee of some sort, perhaps the entire House or Senate won't be able to conduct business because of concerned and angry correspondence and phone calls. Then they'll step back and really look. "Why can't we do business today?" could turn into "Who's responsible for the lack of security?" and that could lead to action.

This is our time. Do we wait for the bad guys to come to us? I mean, certain government agencies have all but invited them, right? Or do we kick somebody in the pants to motivate them for our own protection? We elected our government officials and we pay their salaries. It's time they started working.

Friday, July 20, 2007

More Military Medical Records Exposed

Not just military, but dependant too. I hope none of you all are caught up in this.

Data security lapse affects almost 900,000
By William H. McMichael - Staff writerPosted : Friday Jul 20, 2007 15:38:36 EDT

The coded personal health care records of nearly 900,000 troops, family members and other government employees stored on a private defense contractor’s nonsecure computer server were exposed to compromise, the company announced Friday.

SAIC said the information, maintained under several health care contracts with the government, included combinations of names, addresses, Social Security numbers, birth dates and/or “limited health information in the form of codes.” It was stored on a single, SAIC-owned, nonsecure server in Shalimar, Fla., and was in some cases transmitted over the Internet in an unencrypted form. The information was exposed while being processed, the company said.

SAIC said a forensic analysis by top computer security experts “has not yielded any information that any personal information was actually compromised,” but added that “the possibility cannot be ruled out.”

Although SAIC announced the data breach Friday, the company acknowledged it has known about the problem since May 29, when U.S. Air Forces Europe notified SAIC that it had “detected an unsecure transmission of this personal information,” said SAIC spokeswoman Connie Custer.

However, SAIC had concerns about a potential problem even earlier. Two weeks before USAFE contacted the contractor, SAIC shut down the server “based on general concerns regarding the security of transmissions,” SAIC spokeswoman Melissa Koskovich said. SAIC confirmed that personal information had in fact been transmitted in an unsecure manner and stored on an unsecured computer.

Koskovich said the server has been shut down ever since. Neither she nor Custer knew the length of time over which the security lapse occurred, or when the company first began storing data at the site. “We’re working that now,” Custer said.

Storage of the data on an unsecure server is a violation of both SAIC and Defense Department policy, Custer said. Asked why an unsecure server was used to store the data, she said, “We’re trying to find that out. We’re doing an investigation.”

The Pentagon immediately expressed concern.
“We take this very seriously, and we’re taking all the steps necessary to make sure this doesn’t happen again,” said Defense Department spokeswoman Cynthia Smith, who also confirmed the department’s requirement for secure storage of the data.

But Smith downplayed this particular instance, saying “the risk for compromise is low” and that “there’s been no evidence of compromise.”

SAIC Executive Vice President Arnold Punaro said the nearly two-month delay in announcing the problem was unavoidable.
“We regret that it took a little bit longer than we would have liked,” he said, but added the time was needed to make an “accurate assessment” of the extent of the problem.
“Our task force has been working literally around the clock,” he said. “It was a massive amount of data.”

Experts initially had to accurately assess exactly what data was on the server. Some, Punaro said, was no more than a piece of an individual’s record, such as an isolated medical appointment file. As such, all records had to be matched against government Defense Enrollment Eligibility Reporting System, or DEERS, records, to determine how, with government permission, to contact individuals, he said.

FBI, Secret Service and other top computer experts were brought in to help analyze the problem, Punaro said.

SAIC said it is notifying about 867,000 individual records were involved. That includes 173,939 soldiers; 151,315 airmen; 96,925 sailors; 26,171 Marines; 10,415 Coast Guardsmen; 2,164 members of the U.S. Public Health Service; and 104 members of the National Oceanic and Atmospheric Administration. The remaining 406,000 are family members of those personnel.

The company has taken full responsibility for the lapse.
“We deeply regret this security failure, and I want to extend our apologies to those affected by it,” said chairman and chief executive officer Ken Dahlberg. “We are concerned about the inconvenience and risk of potential compromise of personal information this may cause. The security failure is completely unacceptable and occurred as a result of clear violations of SAIC’s strong internal IT security policies. We let down our customers and the service members whom we support. For this, we are very sorry.”

SAIC said the company is working with the affected agencies to “mitigate any potential inconvenience or harm” the security lapse may have caused. It has retained Kroll Inc. to help out those whose records were exposed affected. Kroll will operate an Incident Response Center with extended hours, information resources and credit and identity restoration services for any victims of related identity theft.

Those potentially affected will be provided the contact information by mail, Punaro said. All assistance will be provided at no cost to the government or affected persons.
The company’s internal investigation is being conducted using outside counsel to determine how the security lapse occurred. It also has placed “a number” of employees on administrative leave pending the investigation’s outcome, it said.

For more information, go to http://www.saic.com/response.