Security Incidents mailing list archives

Re: Biggest Incident This Week: Missing Hard Drives at Los Alamos


From: nazgul () SOMEWHERE COM (Kee Hinckley)
Date: Wed, 14 Jun 2000 19:45:21 -0400


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At 5:00 PM -0400 6/13/00, Dante Mercurio wrote:
Ok, everyone knows about the missing hard drives at Los Alamos. My question
to the security community is this:

If the data on the drives was so sensitive, why weren't the drives
encrypted?

Quick, we've got to disarm this nuclear bomb.
Damn, who's got the password to the disk?

But seriously, the thought occurred to me as well.  However I find
their lack of a an access log more egregious.  Tons of security, but
no one keeping track of who actually took the disks.  And access to
the room required a password too, so it seems likely that whoever had
that would also have the disk password.
- --

Kee Hinckley - Somewhere Consulting Group - Cyberspace Architects(rm)

I'm not sure which upsets me more: that people are so unwilling to accept
responsibility for their own actions, or that they are so eager to regulate
everyone else's.

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>

iQA/AwUBOUgZIiZsPfdw+r2CEQIzQgCffTIYVph2q6sFZtoEtv9ravx1DhEAnjeY
B7owmNVPISo0u2MJmYocoE+O
=d01Q
-----END PGP SIGNATURE-----


Current thread: