funsec mailing list archives

Re: Breach of Obama's Passport Information Leads to Firings at U.S. State Dept.


From: Gadi Evron <ge () linuxbox org>
Date: Thu, 20 Mar 2008 21:21:10 -0500 (CDT)

On Fri, 21 Mar 2008, Paul Ferguson wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Via MSNBC.com.

[snip]

Two contract employees of the State Department were fired and a third
person was disciplined for accessing passport records of Sen. Barack Obama
"without a need to do so," State Department officials confirmed to NBC
News.

The three people who had access to Obama's passport records were contract
employees of the department's Bureau of Consular Affairs, NBC News has
learned. The unauthorized activity concerning Obama's passport information
occurred in January.

"A monitoring system was tripped when an employee accessed the records of a
high-profile individual,” a department official told NBC News. "When the
monitoring system is tripped, we immediately seek an explanation for the
records access. If the explanation is not satisfactory, the supervisor is
notified."

[snip]

More:
http://www.msnbc.msn.com/id/23736254/

When I first got drafted, I stayed for a short while with the recruitment office in Jerusalem. I remember that if you tried to look up some known model's details on your acount, you'd get into trouble.

I was too nice, it didn't even occur to me to search. Little did I know of what I will be able to search and won't in future positions, with different types of acounts.

Where people are involved my experience tells me they will abuse their power, especially when it's as easy as one click away. At one position I felt stupid for being the only one who doesn't--doesn't means INTENTIONALLY.

You can't control everything, but you can be smart about what you do control or monitor. Even the best people will see stuff they are not supposed to.

        Gadi.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Current thread: