SEC Workers Fail to Encrypt Computers with Sensitive Information
November 9, 2012 9:12 AM
comment(s) - last by
Sources say workers involved are being disciplined
With the myriad
high-profile hacks and attacks on government and corporate computer systems around the world
, it's easy to believe that the U.S. federal government and its many arms would do all they can to keep its networks secure. However, that is not always the case.
reports that workers at the U.S. Securities and Exchange Commission failed to encrypt some of their computers that contained highly sensitive information from stock exchanges. The failure to encrypt the information left data vulnerable to cyber attacks according to people familiar with the situation.
The computers left unencrypted reportedly belonged to a small number of employees in an office within the SEC Trading and Markets Division. That particular division is tasked with ensuring that various stock exchanges follow guidelines to protect the markets for potential cyber threats and system problems.
That makes it incredibly ironic that the employees tasked with ensuring systems are protected from cyber threats would leave their own computers unprotected.
Some of the staffers are known to have taken the unprotected computers to a
Black Hat convention
where computer hackers gather. There is no clear indication of why the staffers would have taken unencrypted and unprotected computers into the hackers den.
The SEC insists that no data was breached from the insecure computer systems. However, the SEC was forced to spend around $200,000 to hire a third-party firm to conduct a thorough analysis to come to that conclusion.
This article is over a month old, voting and posting comments is disabled
11/9/2012 1:55:24 PM
I agree. At the very least it should have been the local IT department's rule (although it should really have been a directive from the head person at the SEC) that all the computers in their care have encrypted HDD prior to use, which again points at the IT department for not having such a rule. I'm sure they wouldn't forget to load their favourite antivirus software, so how come they thought it was ok to not have an encrypted HDD? The only logical answer is because they have lots of HDD that aren't encrypted, which is stupid because PCs are often sold when they are deemed "out of date", and people have often resurrected data from "erased" HDDs in the past. If every computer did have an encrypted HDD, and one "escaped the net" and was sold without having the HDD securely erased ... Do I have to ask? Do they have a policy regarding this?
As an aside, I do wonder what indications the new computers would have given if they did or didn't have encrypted drives to their new owners. When I bought this computer it booted up to Windows 7 in just seconds (I removed it and loaded a Linux distribution), so how is a new owner supposed to know the HDD wasn't encrypted?
Is it possible for the LAN to be set up so that there is an immediate indication given that a computer doesn't have an encrypted HDD, e.g. no one can login on it?
I think these employees are just being made scapegoats for the failure of a whole department of "yes men".
"Folks that want porn can buy an Android phone." -- Steve Jobs
Did You Partake in "Black Friday/Thursday"?
Did You Partake in "Black Friday/Thursday"?
I skipped Thanksgiving to get the Black Thursday deals!
I spent Thanksgiving with friends/family, but I lined up at midnight for the deals!
Skip Thanksgiving? Wait in line? No way, but I'll go out today and see what's left.
I prefer Cyber Monday.
I don't do deal shopping... too much stress, it just isn't worth it.
Amid Recent Cyberattacks, Senate Poised to Revive Cybersecurity Bill
November 1, 2012, 2:37 PM
Apple to Break Its Vow of Silence on Security Issues at Black Hat
July 25, 2012, 7:37 AM
LinkNYC Terminals to Blanket New York City With Free WiFi, Free Calls, and Ads
November 17, 2014, 6:50 PM
Microsoft is Open-Sourcing Most of .NET, Adding OS X and Linux Support
November 12, 2014, 8:27 PM
Home Depot Lost 53 Million Emails, Blames Windows, Buys Execs New Macs
November 9, 2014, 5:00 PM
Former NSA Lawyer: If Google, Apple Encrypt User Data, They’ll Wither on the Vine Like Blackberry
November 6, 2014, 12:15 PM
Report: AT&T Eyeing $40B DirecTV Purchase
May 1, 2014, 8:00 AM
WebOS Class Action Settlement Costs HP $57 Million
April 1, 2014, 10:22 AM
Most Popular Articles
Hack of Sony Pictures Indicates Employees Were Pirating Blu-Rays
November 25, 2014, 4:00 PM
Google Caves to Microsoft and Apple's Pet "Patent Troll" Rockstar
November 24, 2014, 3:30 PM
Report: Samsung Galaxy S5 Sales Have Come in 40% Below Projections
November 24, 2014, 6:58 AM
Xiaomi Aims to be #1 Smartphone OEM Within 10 Years, Apple Urges Caution
November 21, 2014, 9:33 AM
Some High-End Luxury Watchmakers Crack Down Hard on Smartwatch Faces
November 26, 2014, 1:28 AM
Latest Blog Posts
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information