Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Our Governments Are Making Us More Vulnerable
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
2/23/2015 | 11:06:20 AM
Re: presumption of privilege
" ... it's up to all of us as individuals & citizens to make sure that our private and public leaders are up to the task -- and held to the fire when they are not ..."

In my opinion, the entire problem is laid bare in that statement. The biggest issue is that those so-called leaders are not really up to the task. Elected officials tend to grant important positions to political allies, or to those with whom they have had long associations. Very little consideration is given to the person's ability to actually perform the task given to them. In a political environment, politics rule decision making processes and that, in and of itself, almost rules out selection of the best qualified individual. In many instances, those leaders aspire to expand their empire and sphere of influence much more than to actually perform their assigned tasks. As far as the "held to the fire" part, that is usually an even worse scenario. I'm reminded of the old saying "if a person screws up, promote them". Political environments tend to glaze over mistakes with regularity, and with little consequence. We need only look at the various scandals and security issues in the federal government for examples, and it gets even worse as you start looking at state and local levels where those events get very little press. I hate to sound so cynical about this whole thing; I would love to hear what other people think about this.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/23/2015 | 10:12:00 AM
Re: presumption of privilege
..necessary to place all government under the rule of law and to enforce same by means of education, freedom of the press, and the jury box and the ballot box.
@macker490, this covers our Constitutional checks and balances, but it's up to all of us as individuals & citizens to make sure that our private and public leaders are up to the task -- and held to the fire when they are not.
macker490
50%
50%
macker490,
User Rank: Ninja
2/23/2015 | 8:57:18 AM
presumption of privilege
people in governemnt acquire the belief that they are responsible for regulating the behavior of the people in their jurisdiction. from this they arogate to themselves a presumption of privilege -- to do whatever is necessary to carry out their obligation

these these run the gamut from the blundering bloke to the conspiring crook, and the occasional superlative leader. given the risks involved in government then it is necessary to place all government under the rule of law and to enforce same by means of education, freedom of the press, and the jury box and the ballot box.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/22/2015 | 10:23:26 AM
Re: Insecurity always
I agree. The only ways governments can justify surveillance on their citizens are around "bad guys will get you otherwise".
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/22/2015 | 10:21:13 AM
Re: Insecurity always
Not only that but also holes in harddisks firmware. Would would be worse, we all use those harddisks, we are all vulnerable basically.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/22/2015 | 10:18:31 AM
Re: Insecurity always
I agree, Thomas. It is part of "being in control" instead of "being secure". They do not get ultimate goal right at this point.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/22/2015 | 10:15:31 AM
Backdoors
As we all know it very well, any backdoor for government is potential opportunity for hackers. Governments should be enforcing rules and regulations in ways that systems are designed in secure manners, not with backdoors.
pporter531
50%
50%
pporter531,
User Rank: Apprentice
2/21/2015 | 9:25:34 PM
2 additional ways our government (USA) is making us more vulnerable
1. Creatng websites like Healthcare.gov

2. Not properly securing citizens PII at the IRS
CNACHREINER981
50%
50%
CNACHREINER981,
User Rank: Author
2/20/2015 | 6:21:39 PM
Re: Insecurity always
I gotta tell ya, Thursday's news of NSA and GCHQ stealing SIM keys from a private company, given them the power for blanket surveillance, just adds wood to the fire of this article.
CNACHREINER981
50%
50%
CNACHREINER981,
User Rank: Author
2/20/2015 | 6:20:08 PM
Re: Insecurity always
Yes. As much as I think Infosec is an important topic, and I want governments to consider it... I feel like they might be using it like "weapons of mass destruction" to get more money and relevance.
Page 1 / 2   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Mobile App Fraud Jumped in Q1 as Attackers Pivot from Browsers
Jai Vijayan, Contributing Writer,  7/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...