3 ms·
Hard pass. You can go back to sending letters with your SSN for employment, taxes, etc and ideally that should mean that your information doesn’t go on the int
by sethherr 3y ago
Hard pass.
You can go back to sending letters with your SSN for employment, taxes, etc and ideally that should mean that your information doesn’t go on the internet.
But you’re in the minority in wanting that hassle.
- ethbr1 3y agoAir gapping doesn't preclude electronic communication, only that the data at rest isn't accessible from a system with network connectivity. 1. Email / web-submit forms 2. Someone saves requests onto a disc and swivel chairs to load them into the offline system for processing 3. Results are written back to disc, which is swivel chaired back to net-connected systems Congratulations. You've just made physical access (or a much more difficult poisoned data bug) a requirement for data leaks.
- jjulius 3y agoI don't really have a position one way or the other on this, but since you're a "hard pass" I figure I'll ask ya from a devil's advocate perspective. If you insist on keeping all of this data online, how do you propose preventing what happened with Maine from happening again? Surely you must be willing to acquiesce that there is an increased level of security with OP's proposal in this regard, in spite of a lack of convenience?
- thedougd 3y agoI've investigated a number of MoveIT incidents and they're all looking about the same now. At this point, we should consider hosting a file transfer site a bad practice. These sites are usually used to transmit files between two organizations. Tactically, what could have been done to minimize or prevent this particular incident, while continuing to use MoveIT software: - Encrypt the files before dropping them onto the file transfer site. Communicate the key out-of-band. This one simple step would have avoided catastrophe. Unfortunately, many MoveIT site operators would not allow their customers to encrypt files sent to them. - Limit MoveIT site access, by IP address. This is a fairly common practice for file transfer sites. - Use a frontend, such as a load balancer or reverse proxy, that enforces authentication in front of MoveIT. - Disable the web site and only allow use of the SFTP (SSH) site.