I worked on a support team for a company that that had some major financal institutions as a customer.
We had remote access to their networks at times. My very first day I was amazed how much access I had at will.
One day it was announced that a customer had come to us and demanded everyone had to meet X requirements to be able to work on their networks.
Not long after another financal institution made a similar request.
Some folks inside the company were a bit riled up by the requirements (background checks, some other things). They felt the requirements were absurd.
Considering the access we had I thought they weren't strict enough. As just a lowly support dude hired during the dot com boom because the company needed warm bodies (who could do some independent thinking / troubleshooting) ... I had a lot of access.
I don't know if they were thinking about spying like this, but I'm always amazed how much access people have to data and etc just from a technical support perspective (forget developers...).
Later the company outsourced support to other countries... I'm not even sure you need spies in the US / would know anyone was spying under those circumstances.
Support teams are probabbly a hell of a lot cheaper / easier to infiltrate / they get little / poor management / oversight. I saw tons of strange choices by our outsourced technical support staff, every single time I raised concerns it was discarded by something to the effect of "yeah they suck".
And that doesn't account for all the financial institutions who outsourced their own direct ops teams to other countries ... I'd call them and if they ever were capable of following instructions 9x out of 10 they'd open up the wrong network / modems / etc.
This is a very common answer to these stories on hackernews but this one is from a humble point of view that truly brings home the point.
My side is that I worked for a bank on the brokerage side for ten years in different positions. What always struck me was that my access was very carefully controlled, I was a background checked employee and had to meet with compliance once a year, etc etc.
However when a law firm asked for anything or consultants said they needed more data they just sent massive data dumps to the network admin guy, no questions further asked. At least not at my pay grade.
As I've consulted I ask for only what I need to keep my own risk down but it is always a surprise to my clients I don't want PII I don't need and only the data that my model will help enhance.
It's a tale that plays out in many forms. In the early 80's I worked for a goverment entity and had tough physical security to enter the building - however, monthly fire drill would see this large building empty onto the open carpark that was easily accessible as no perimeter fence and with that and the aspect that when re entering the building after the fire-drill, there was always one fire door open to circumvent the bottleneck at reception and with that - no security checks then.
Though many instances of weak links in process due to human nature that get overlooked and only come to light once there is an incident.
Which is the crux, incidents cause things to change, yet if you see that potential flaw the gravatas you have in flagging that issues is often dismissed because it hasn't happened. That is sadly often a pattern we see play out time and time again in many forms.
Literally yesterday we had an issue with someone trying to piggyback into the office behind an employee who had badged in. Said person was intoxicated and removed his pants in the elevator, so it was immediately apparent there was a problem, but what happens when it's someone more nondescript?
About two years after my company was bought by a larger one, I was the first person at the office one morning, only to find someone waiting outside the doors. Before I could ask, he introduced himself as an employee from an out-of-town office, and produced a company ID, so I let him in with me.
We had been told to expect some visitors from that office, but I was almost hoping he was not legit, since most of us at my location still do not have a company ID, so I couldn't really say if his was real or not.
Working with some massive insurance companies to build a technologically interesting product for them to reduce fraud, I was given their entire claims data sets for the previous decade as an outside consultant with zero background checks involved. I even raised that as a scary issue but was told to pipe down haha
Seen the same working with hospital datasets. We only used them on site (office of third party provider, not the hospital) and anonymized them, but from what I now know about fingerprinting our anonymizations wasn't strong enough and it was also up to us to do, after we received the real data. We mostly did it because we had friends, family and possibly ourselves in some of the hospitals.
We were told it was ok and all the paperwork had been done (we had a somewhat legitimate need), but if that's the case the standards are far too loose and there are far too many copies of patient data around.
Worked as a hospital clerk at one of the top hospitals in my country. This was in the mid 2000s. I thus had access to the system and all the information contained in the same. One day, I got an opportunity to serve a certain female legislator who was/is married to someone from my small city. A nephew of the the legislator's husband is a good friend. Now, I actually needed help from the legislator and thought it was unethical of me to get her contact details from the hospital's system. I eventually got the contact details from my friend. But, while I was careful about this ethical issues, I knew of a colleague of who didn't. While I didn't get the help I wanted from the legislator, I sometimes ask myself whether getting in touch with her, regardless of how I got the contact, was ethical. This dilemma is as a result of the fact that I only met the legislator courtesy of the privilege accorded me by the hospital.
Oh gosh yes. I couldn't have done the project without it, to be honest, not in the time frames needed. Still makes me a little queasy though, although I was the only person given access to said data sets and met with executives from said companies prior to, so I suppose it's not quite as crazy as I made it sound...
Senior managers don't need to control the servants' access because they won't take your job, they're lesser beings in the caste system. The control is there for those who might take your job or customers because they are caste equivalents.
At no stage are customers' concerns so much as considered. Control is not of the data, it's the vital control of peers and rivals. If you're not a rival, who cares?
I worked at a charter school for a while, and had access to the test scores and demographic data (including dob and ssn) not just for our students, but for every public school student in Texas, past and present.
The knowledge level on those staff's is often near 0, they operate with wonky budgets (here is a gazillion dollars for ipads... no money to maintain them or the rest fo the systems), and are just making do the best they can.
The IT staff at one complained to me the librarian at one elementary school kept changing things on them. In reality she had a clue and they couldn't even operate rudimentary role based access type system to stop her.
This is a function of how schools are funded in the US. This is the system you asked for through voting and tax policy (maybe not you, but you being the broad citizen).
Living inside the beast for my entire career - We have just enough funding to keep the doors open, and remain staffed at a minimal level. Additional funding, above what we can raise through local taxes, ALWAYS comes with an asterisk.
So we can get access to $50,000 supplemental funding this year, awesome. But we have to buy I-pads. Nevermind that literally every other piece of technology in the building is windows based. Oh, and we cannot spend that on infrastructure upgrades to the wi-fi system to support the extra capacity. And it has to be spent in six months or you lose it.
It's the way we're funded in the US. It isn't necessarily a function of the schools or the staff therein. Those people are generally trying to do their best.
It's the shit system and it needs to be burnt to the ground.
This is a function of how schools are funded in the US.
Not just schools. A lot of government-related sectors.
Transit is a big one. Back when I used to follow this sort fo thing, I would see a lot of municipalities turning down federal grants because the money could only be spent on buses, trains, an related infrastructure; and the towns and cities didn't have the money to pay for the people involved.
Maybe when self-driving vehicles become common, this won't be so much of a problem anymore.
Several years ago, one of our competitors implemented a public-facing web-based form for a local ISD. When the form loaded, the user was prompted with two pieces of info: a student's last 4 digits of SSN and their birthdate. The form then performed an AJAX request to the server, which did a DB lookup and pulled in ALL the transcript data of the matching student record to send back to the front-end.
Said competitor then presented this "solution" at a vendor conference and bragged about how amazing and easy to use it was and how the parents loved it because they no longer had to call the school to request transcripts yadda yadda. When casually asked about security/privacy concerns, their engineer basically said "well, how likely is it that an unauthorized party will know both a student's birthdate and the last 4 digits of SSN? Probably not very."
It's not a U.S. thing. It's a state thing. Not every state funds its schools through real estate taxes.
Nevada, for example, is funded by sales taxes, ad valorem property taxes ("property" as in things, not houses and land), gambling taxes, federal money, estate taxes, and mining taxes.
Currently reading snowden book, "Permanent record". At one point he says that private companies do a huge amount of work for the NSA & Co, and have ridiculous level of access to vast arrays of personal data, which they proceed to give to their employees or subcontractors for processing.
Not being a smart ass but how do background checks work for foreign persons? Say for a former student that came to USA 5 years ago and is 23 years old? Odds are that he will look clean in every way. Even if he's a spy all traces are covered.
My other comment was sent to oblivion because it is politically incorrect, but the reality is that a lot students have loyalties to the old country. Also when you add the family back there and corruption being a normal way of getting things done, these things are bound to happen. I don't suggest to freeze them out, just don't be surprised.
Not being a smart ass but how do background checks work for foreign persons?
Note that there are many different types of background checks, varying from things like "working with children" checks, to financial status checks, to security checks of different kinds.
You are correct - it's very hard for a foreign person to pass some types of these. In some cases that means it's very difficult for them to get one of these jobs.
Your other comment says different things though. I think it's a fair question "how do background checks work for foreign persons" vs "IMO, it's wayyy much easier to corrupt people from second or even third world countries, there corruption is the norm".
It is wayyyyyyy much easier, I'll repeat. To get things done corruption is used and the government can make or break, virtually everything in your life. Or your families'.
A lot of things are broken in USA but it's light years away in that department compared to a lot of countries.
I mean, you're not wrong that corruption is a bigger problem in many countries than it is in the USA (which I guess you see similar to how I've heard many Chinese see the CCP). But saying all "second or third world countries" (whatever would even fit that definition) is quite a generalisation. Even within your definition of first world countries where there isn't (much/any) corruption, why should an Austrian be loyal to Sweden and pass any background checks?
Companies who offshore also run across this dilemma. This is how companies can lose IP to competitors.
Let’s say an IC designer offshores some work, that company has other clients as well and the off shore company has access to a lot of the R&D of the client company. Lots of things can happen in that situation and does happen.
My very first day I was amazed how much access I had at will.
Another branch where you might expect security awareness is anti virus companies. I'm a pentester and in smallish companies everyone knows everyone, but nobody knows me, yet most days I can tailgate into the office without question. This morning a lady asked suspiciously "are you looking for someone?" and I just replied that I know where to go, thanks. I walked on and she didn't pursue. Free rein.
I don't have to mention any specific company, this happens everywhere. Helpful, trusting that everything will be alright, clicking links... Vulnerabilities help but they are optional.
I wish I could tell people that having that much access raises legal issues for me.
It's not enough to have them sign a contract limiting liability because as a business they have far more lawyers than I do.
When I work on a contract I want to be able to say in court that I couldn't possibly be in any way related to the event of a bug, security breach or data loss because I simply do not have access.
It is genuinely worrying on my part to carry around credentials with that much data.
What if my laptop is hacked or stolen?
I do not want to be sued (again it doesn't matter if they have a valid case or not, I don't want to deal with legal fees or anything.)
A few months ago in Quebec we got a big cooperative bank "hacked" that way by an employee that got offered money by some insurance reseller.. He was able to export the data of 4.5 millions persons out and sell it to them. We recently found out that they were offering 40k$ to get it. Sure you could infiltrate them, but seems like even buying the data is quite accessible too.
BMO and another org in 2018. BMO's security was atrocious, for a while they had you use your 4-digit pin to log into online banking. One of the reasons I ended up switching to Tangerine...
Years ago, the key code to one of the back doors of a very large and well known financial institution in SF was extremely simple and consequetive and 4 digit sequence that everyone including contractors knew. I wonder if they ever fixed it?
Comments
I worked on a support team for a company that that had some major financal institutions as a customer.
We had remote access to their networks at times. My very first day I was amazed how much access I had at will.
One day it was announced that a customer had come to us and demanded everyone had to meet X requirements to be able to work on their networks.
Not long after another financal institution made a similar request.
Some folks inside the company were a bit riled up by the requirements (background checks, some other things). They felt the requirements were absurd.
Considering the access we had I thought they weren't strict enough. As just a lowly support dude hired during the dot com boom because the company needed warm bodies (who could do some independent thinking / troubleshooting) ... I had a lot of access.
I don't know if they were thinking about spying like this, but I'm always amazed how much access people have to data and etc just from a technical support perspective (forget developers...).
Later the company outsourced support to other countries... I'm not even sure you need spies in the US / would know anyone was spying under those circumstances.
Support teams are probabbly a hell of a lot cheaper / easier to infiltrate / they get little / poor management / oversight. I saw tons of strange choices by our outsourced technical support staff, every single time I raised concerns it was discarded by something to the effect of "yeah they suck".
And that doesn't account for all the financial institutions who outsourced their own direct ops teams to other countries ... I'd call them and if they ever were capable of following instructions 9x out of 10 they'd open up the wrong network / modems / etc.
This is a very common answer to these stories on hackernews but this one is from a humble point of view that truly brings home the point.
My side is that I worked for a bank on the brokerage side for ten years in different positions. What always struck me was that my access was very carefully controlled, I was a background checked employee and had to meet with compliance once a year, etc etc.
However when a law firm asked for anything or consultants said they needed more data they just sent massive data dumps to the network admin guy, no questions further asked. At least not at my pay grade.
As I've consulted I ask for only what I need to keep my own risk down but it is always a surprise to my clients I don't want PII I don't need and only the data that my model will help enhance.
Yeah I had a similar experience in terms of security being strong in one place. .. and non existant (as I describe) elsewhere.
Some of our customers did have pretty strong proesses in some places... but then zero when a process changes or something like that.
Lots of: "Oh no we can't do that because <security>".
Ok makes sense. It's a hassle but it is a good policy.
"But you can..."
All sense out the window, everything is undone.
It's a tale that plays out in many forms. In the early 80's I worked for a goverment entity and had tough physical security to enter the building - however, monthly fire drill would see this large building empty onto the open carpark that was easily accessible as no perimeter fence and with that and the aspect that when re entering the building after the fire-drill, there was always one fire door open to circumvent the bottleneck at reception and with that - no security checks then.
Though many instances of weak links in process due to human nature that get overlooked and only come to light once there is an incident.
Which is the crux, incidents cause things to change, yet if you see that potential flaw the gravatas you have in flagging that issues is often dismissed because it hasn't happened. That is sadly often a pattern we see play out time and time again in many forms.
Literally yesterday we had an issue with someone trying to piggyback into the office behind an employee who had badged in. Said person was intoxicated and removed his pants in the elevator, so it was immediately apparent there was a problem, but what happens when it's someone more nondescript?
About two years after my company was bought by a larger one, I was the first person at the office one morning, only to find someone waiting outside the doors. Before I could ask, he introduced himself as an employee from an out-of-town office, and produced a company ID, so I let him in with me.
We had been told to expect some visitors from that office, but I was almost hoping he was not legit, since most of us at my location still do not have a company ID, so I couldn't really say if his was real or not.
Working with some massive insurance companies to build a technologically interesting product for them to reduce fraud, I was given their entire claims data sets for the previous decade as an outside consultant with zero background checks involved. I even raised that as a scary issue but was told to pipe down haha
Seen the same working with hospital datasets. We only used them on site (office of third party provider, not the hospital) and anonymized them, but from what I now know about fingerprinting our anonymizations wasn't strong enough and it was also up to us to do, after we received the real data. We mostly did it because we had friends, family and possibly ourselves in some of the hospitals.
We were told it was ok and all the paperwork had been done (we had a somewhat legitimate need), but if that's the case the standards are far too loose and there are far too many copies of patient data around.
It was great for development though.
Worked as a hospital clerk at one of the top hospitals in my country. This was in the mid 2000s. I thus had access to the system and all the information contained in the same. One day, I got an opportunity to serve a certain female legislator who was/is married to someone from my small city. A nephew of the the legislator's husband is a good friend. Now, I actually needed help from the legislator and thought it was unethical of me to get her contact details from the hospital's system. I eventually got the contact details from my friend. But, while I was careful about this ethical issues, I knew of a colleague of who didn't. While I didn't get the help I wanted from the legislator, I sometimes ask myself whether getting in touch with her, regardless of how I got the contact, was ethical. This dilemma is as a result of the fact that I only met the legislator courtesy of the privilege accorded me by the hospital.
Oh gosh yes. I couldn't have done the project without it, to be honest, not in the time frames needed. Still makes me a little queasy though, although I was the only person given access to said data sets and met with executives from said companies prior to, so I suppose it's not quite as crazy as I made it sound...
That doesn't protect you from accessing and leaking data.
Note the difference:
Senior managers don't need to control the servants' access because they won't take your job, they're lesser beings in the caste system. The control is there for those who might take your job or customers because they are caste equivalents.
At no stage are customers' concerns so much as considered. Control is not of the data, it's the vital control of peers and rivals. If you're not a rival, who cares?
I worked at a charter school for a while, and had access to the test scores and demographic data (including dob and ssn) not just for our students, but for every public school student in Texas, past and present.
Data security is a myth.
School's in particular are horrible.
The knowledge level on those staff's is often near 0, they operate with wonky budgets (here is a gazillion dollars for ipads... no money to maintain them or the rest fo the systems), and are just making do the best they can.
The IT staff at one complained to me the librarian at one elementary school kept changing things on them. In reality she had a clue and they couldn't even operate rudimentary role based access type system to stop her.
This is a function of how schools are funded in the US. This is the system you asked for through voting and tax policy (maybe not you, but you being the broad citizen).
Living inside the beast for my entire career - We have just enough funding to keep the doors open, and remain staffed at a minimal level. Additional funding, above what we can raise through local taxes, ALWAYS comes with an asterisk.
So we can get access to $50,000 supplemental funding this year, awesome. But we have to buy I-pads. Nevermind that literally every other piece of technology in the building is windows based. Oh, and we cannot spend that on infrastructure upgrades to the wi-fi system to support the extra capacity. And it has to be spent in six months or you lose it.
It's the way we're funded in the US. It isn't necessarily a function of the schools or the staff therein. Those people are generally trying to do their best.
It's the shit system and it needs to be burnt to the ground.
This is a function of how schools are funded in the US.
Not just schools. A lot of government-related sectors.
Transit is a big one. Back when I used to follow this sort fo thing, I would see a lot of municipalities turning down federal grants because the money could only be spent on buses, trains, an related infrastructure; and the towns and cities didn't have the money to pay for the people involved.
Maybe when self-driving vehicles become common, this won't be so much of a problem anymore.
Don't forget contractors.
Several years ago, one of our competitors implemented a public-facing web-based form for a local ISD. When the form loaded, the user was prompted with two pieces of info: a student's last 4 digits of SSN and their birthdate. The form then performed an AJAX request to the server, which did a DB lookup and pulled in ALL the transcript data of the matching student record to send back to the front-end.
Said competitor then presented this "solution" at a vendor conference and bragged about how amazing and easy to use it was and how the parents loved it because they no longer had to call the school to request transcripts yadda yadda. When casually asked about security/privacy concerns, their engineer basically said "well, how likely is it that an unauthorized party will know both a student's birthdate and the last 4 digits of SSN? Probably not very."
...yeah.
That thing where US schools are paid for by property taxes is so gross. Talk about a policy designed to maintain inequality.
It's not a U.S. thing. It's a state thing. Not every state funds its schools through real estate taxes.
Nevada, for example, is funded by sales taxes, ad valorem property taxes ("property" as in things, not houses and land), gambling taxes, federal money, estate taxes, and mining taxes.
http://ftp.ccsd.net/directory/budget-finance/pdf/Funding_K-1...
...and don't forget Erate dollars. Can't fund redundant systems, etc. https://www.fcc.gov/consumers/guides/universal-service-progr...
But it doesn't have to be.
Currently reading snowden book, "Permanent record". At one point he says that private companies do a huge amount of work for the NSA & Co, and have ridiculous level of access to vast arrays of personal data, which they proceed to give to their employees or subcontractors for processing.
I expect FAANGS to do the same.
Not being a smart ass but how do background checks work for foreign persons? Say for a former student that came to USA 5 years ago and is 23 years old? Odds are that he will look clean in every way. Even if he's a spy all traces are covered.
My other comment was sent to oblivion because it is politically incorrect, but the reality is that a lot students have loyalties to the old country. Also when you add the family back there and corruption being a normal way of getting things done, these things are bound to happen. I don't suggest to freeze them out, just don't be surprised.
Not being a smart ass but how do background checks work for foreign persons?
Note that there are many different types of background checks, varying from things like "working with children" checks, to financial status checks, to security checks of different kinds.
You are correct - it's very hard for a foreign person to pass some types of these. In some cases that means it's very difficult for them to get one of these jobs.
Your other comment says different things though. I think it's a fair question "how do background checks work for foreign persons" vs "IMO, it's wayyy much easier to corrupt people from second or even third world countries, there corruption is the norm".
It is wayyyyyyy much easier, I'll repeat. To get things done corruption is used and the government can make or break, virtually everything in your life. Or your families'.
A lot of things are broken in USA but it's light years away in that department compared to a lot of countries.
I mean, you're not wrong that corruption is a bigger problem in many countries than it is in the USA (which I guess you see similar to how I've heard many Chinese see the CCP). But saying all "second or third world countries" (whatever would even fit that definition) is quite a generalisation. Even within your definition of first world countries where there isn't (much/any) corruption, why should an Austrian be loyal to Sweden and pass any background checks?
Companies who offshore also run across this dilemma. This is how companies can lose IP to competitors.
Let’s say an IC designer offshores some work, that company has other clients as well and the off shore company has access to a lot of the R&D of the client company. Lots of things can happen in that situation and does happen.
Another branch where you might expect security awareness is anti virus companies. I'm a pentester and in smallish companies everyone knows everyone, but nobody knows me, yet most days I can tailgate into the office without question. This morning a lady asked suspiciously "are you looking for someone?" and I just replied that I know where to go, thanks. I walked on and she didn't pursue. Free rein.
I don't have to mention any specific company, this happens everywhere. Helpful, trusting that everything will be alright, clicking links... Vulnerabilities help but they are optional.
I kinda worry about this.
I wish I could tell people that having that much access raises legal issues for me.
It's not enough to have them sign a contract limiting liability because as a business they have far more lawyers than I do.
When I work on a contract I want to be able to say in court that I couldn't possibly be in any way related to the event of a bug, security breach or data loss because I simply do not have access.
It is genuinely worrying on my part to carry around credentials with that much data. What if my laptop is hacked or stolen? I do not want to be sued (again it doesn't matter if they have a valid case or not, I don't want to deal with legal fees or anything.)
This is what I wish.
Obviously things are far from that.
A few months ago in Quebec we got a big cooperative bank "hacked" that way by an employee that got offered money by some insurance reseller.. He was able to export the data of 4.5 millions persons out and sell it to them. We recently found out that they were offering 40k$ to get it. Sure you could infiltrate them, but seems like even buying the data is quite accessible too.
Is that Desjardins? They got hit November 2019.
BMO and another org in 2018. BMO's security was atrocious, for a while they had you use your 4-digit pin to log into online banking. One of the reasons I ended up switching to Tangerine...
Years ago, the key code to one of the back doors of a very large and well known financial institution in SF was extremely simple and consequetive and 4 digit sequence that everyone including contractors knew. I wonder if they ever fixed it?
After growing up reading BOFH, I believe the admin always controls everything