11 ms·
This is the EDGAR system that was breached: https://www.edgarfiling.sec.gov/Welcome/EDGARLogin.htm https://www.edgarfiling.sec.gov/Welcome/EDGARLogin.htm Up un
by sullivanmatt 9y ago
This is the EDGAR system that was breached: https://www.edgarfiling.sec.gov/Welcome/EDGARLogin.htm https://www.edgarfiling.sec.gov/Welcome/EDGARLogin.htm
Up until two years ago, that page used to recommend a minimum browser of either IE 5 or Netscape Navigator 3. If you look at the source and use of 'htm' extension, all signals point towards it being created using an extremely old version of Microsoft FrontPage (2000?). And that's not particularly uncommon on the government systems for unsexy tasks like filing regulatory reports. Limited IT staff and budget, paired with an unimaginable amount of red tape, lead to this type of breach. Also good InfoSec talent usually doesn't stay at the Federal space long. Anyone with strong skills within 50mi of the beltway can make $25k+ more per year by going private sector. Finally, let's not forget a much more limited talent pool is available because, in many situations, these jobs require you to be a U.S. citizen.
I would argue that the SEC breach is only a symptom of a much more systemic problem with IT at the Federal level. To fix it will be extremely costly and painful. To do nothing will be extremely costly and painful.
- thephyber 9y ago> To fix it will be extremely costly and painful. The last few years of the Obama administration, the White House proposed budget included an interesting and useful (IMHO) line item to address this. The gist of it was that any department could draw up a plan to take a loan against their future budgets to pay down IT efficiency projects (including streamlining of processes and improvements to cybersecurity posture). I doubt a Republican Congress would go for larger federal spending now for future savings, but I hope that all "government should be small and efficient" advocates would give this kind of proposal serious thought.