Close
Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: ATF Data Breach

  1. #1
    Machine Gunner Hound's Avatar
    Join Date
    Jan 2013
    Location
    Aurora
    Posts
    1,764

    Default ATF Data Breach

    For right now it looks like only employees are affected but if they will do it to their own it does not give much reassurance for any of our information.

    http://www.scmagazine.com/official-a...NTYyMTU3Nzg5S0

    An executive at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) headquarters is under investigation by the Department of Justice (DOJ) for allegedly improperly accessing and downloading ATF employee data. Scott Sweetow, deputy assistant director for strategic intelligence and information, was accused of sending employees' personal information to his personal account from his work email.
    While the ATF doesn't discuss ongoing investigations, DOJ spokesperson Patrick Rodenbush told CNN in a statement, his department “has security solutions in place that detect the transmission of sensitive personally identifiable information outside the Department's computer network.” If a problem is detected, the agency at which the incident occurred is contacted for additional investigation and to take appropriate action.
    Sweetow told the news outlet, “It appears somebody is actively seeking to damage my reputation.” The number of people affec
    My life working is only preparation for my life as a hermit.

    Feedback https://www.ar-15.co/threads/99005-Hound

  2. #2
    Gong Shooter
    Join Date
    Jan 2010
    Location
    Colorado Springs
    Posts
    646

    Default

    This is my shocked face. This is turning into such a joke with .gov security.

  3. #3
    Rebuilt from Salvage TFOGGER's Avatar
    Join Date
    Dec 2008
    Location
    Aurora
    Posts
    7,789

    Default

    The problem they face is that it's a purely defensive battle, against a foe that is agile and innovative. A stationary target, no matter how well defended, is doomed. As long as a computer system is not air gapped and is connected to ANY outside network, it is vulnerable. The reason that the US nuclear arsenal is still controlled by computers that use 5.25 inch floppy disks has as much to do with security as it does with budgets and apathy.
    Light a fire for a man, and he'll be warm for a day, light a man on fire, and he'll be warm for the rest of his life...

    Discussion is an exchange of intelligence. Argument is an exchange of
    ignorance. Ever found a liberal that you can have a discussion with?

  4. #4
    Machine Gunner Hound's Avatar
    Join Date
    Jan 2013
    Location
    Aurora
    Posts
    1,764

    Default

    Generally I would agree.......but I have personnally looked at some of these government sites and know others who have done so more recently. This is the equivalent of not posting sentries at the gate. Ya, a siege against an equal opponent favors the agressor but that assumes both sides are trying. These guys (the Government in general) are missing the basics. There is no excuse. To be fair, the ATF looks like it is doing better than most. The fact that they have some type of DLP (Data Loss Prevention) is a miracle. The fact that somebody was monitoring and actually caught it is a wonder.

    BTW... With the password for all nuke forces being 0000.................. That is not apathy, that is willful stupidity.

    Quote Originally Posted by TFOGGER View Post
    The problem they face is that it's a purely defensive battle, against a foe that is agile and innovative. A stationary target, no matter how well defended, is doomed. As long as a computer system is not air gapped and is connected to ANY outside network, it is vulnerable. The reason that the US nuclear arsenal is still controlled by computers that use 5.25 inch floppy disks has as much to do with security as it does with budgets and apathy.
    Last edited by Hound; 06-30-2015 at 12:54.
    My life working is only preparation for my life as a hermit.

    Feedback https://www.ar-15.co/threads/99005-Hound

  5. #5
    Zombie Slayer Aloha_Shooter's Avatar
    Join Date
    Feb 2007
    Location
    Colorado Springs, CO
    Posts
    6,571

    Default

    Two possibilities:
    1) This was a case of a bad egg who got caught doing something that is clearly wrong and has nothing to do with an agile, innovative foe.
    2) Someone cracked the guy's home system then used that to penetrate ATF to get personnel records. If that's the case, as foxtrot said, the foe doesn't need to be particularly innovative or agile given the government's love affair with and dependence on Microsoft software. Unlike the OPM breach, I'm not sure what a bad guy hopes to get from ATF personnel records so I'm a bit skeptical of Mr. Sweetow's "explanation."

  6. #6
    Thinks Gravy Boats are SEXY ASF! izzy's Avatar
    Join Date
    Jun 2015
    Location
    Centennial
    Posts
    1,630

    Default

    Am I wrong to so straight to "hope this doesn't slow down the turn around on my applications"?

  7. #7
    Moderator "Doctor" Grey TheGrey's Avatar
    Join Date
    Jan 2013
    Location
    Lone Tree
    Posts
    5,750

    Default

    Quote Originally Posted by Hound View Post
    Generally I would agree.......but I have personnally looked at some of these government sites and know others who have done so more recently. This is the equivalent of not posting sentries at the gate. Ya, a siege against an equal opponent favors the agressor but that assumes both sides are trying. These guys (the Government in general) are missing the basics. There is no excuse. To be fair, the ATF looks like it is doing better than most. The fact that they have some type of DLP (Data Loss Prevention) is a miracle. The fact that somebody was monitoring and actually caught it is a wonder.

    BTW... With the password for all nuke forces being 0000.................. That is not apathy, that is willful stupidity.
    Tsk. They changed it up after the last .gov data breach. Now it's ABCD1234.
    "There is nothing in the world so permanent as a temporary emergency." - Robert A Heinlein The Moon is a Harsh Mistress

    Feedback for TheGrey

  8. #8
    Mr Yamaha brutal's Avatar
    Join Date
    Jul 2011
    Location
    Unincorporated Douglas County, CO
    Posts
    13,965

    Default

    There are two kinds of companies (incl gov). Those that have had a data breach, and those that haven't discovered it yet.

    Several studies vary slightly, but the average time an infiltrator spends inside your systems weaving their web of connections before being discovered is around 280 days. Data mined will then be used slowly over time or the lists sold outright to the highest bidder on the black market.
    My Feedback
    Credit TFOGGER : Liberals only want things to be "fair and just" if it benefits them.
    Credit Zundfolge: The left only supports two "rights"; Buggery and Infanticide.
    Credit roberth: List of things Government does best; 1. Steal your money 2. Steal your time 3. Waste the money they stole from you. 4. Waste your time making you ask permission for things you have a natural right to own. "Anyone that thinks the communists won't turn off your power for being on COAR15 is a fucking moron."

  9. #9
    Gong Shooter Rumline's Avatar
    Join Date
    Nov 2013
    Location
    Colorado Springs
    Posts
    430

    Default

    Quote Originally Posted by TFOGGER View Post
    As long as a computer system is not air gapped and is connected to ANY outside network, it is vulnerable.
    Air gaps are about as good as we can do, but you should see the (publicly published) proof of concept methods for remotely compromising air-gapped systems.

  10. #10
    Escaped From New York zteknik's Avatar
    Join Date
    Nov 2010
    Location
    Colorado Springs
    Posts
    6,269

    Default

    Quote Originally Posted by TheGrey View Post
    Tsk. They changed it up after the last .gov data breach. Now it's ABCD1234.
    FHUGETABOUDIT!!!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •