IRS Latest To Get Dinged Over Lost Computers

from the it's-tax-time dept

Just a couple days after learning that the National Nuclear Security Agency, which is tasked with that little job of keeping the government's nuclear secrets safe, is having a problem holding onto its computers, it's been revealed that the IRS is having the same problems. A new audit of the agency indicates that over the last few years, it has lost at least 490 computers, with many of them containing -- you guessed it -- unencrypted personal data. It's hard to know which is more disturbing, the losses at the National Nuclear Security Agency or the IRS. On the one hand, potentially losing nuclear secrets is pretty scary, but on the other hand, there's probably no federal agency that has more personal data on US citizens that could be used by identity fraudsters than the IRS. With the government so unable to hold onto its computers, it's a wonder that other governments even bother engaging in real espionage. All they need to do is wait for some of these laptops to find their way onto the black market. Meanwhile, if the IRS is wondering why my taxes are going to be filed late this year, it's because the computer they were being prepared on is, um, missing.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

Reader Comments

Subscribe: RSS

View by: Time | Thread

  • identicon
    Republican Gun, 5 Apr 2007 @ 1:37pm

    Nuclear Secrets or IRS

    Hmmmm more disturbing would be the IRS. Hope they understand when my backup fails 6 1/2 years from now in an audit. Or maybe I could just say I lost it. Somehow I think I would still be in big doo doo.

    reply to this | link to this | view in chronology ]

  • identicon
    Anonymous Coward, 5 Apr 2007 @ 4:13pm

    I heard the report on the radio this morning, which said that this wasn't a
    large-scale data breach. This site has some of these details.

    It's not a TJX or VA. But still worrysome even if you're not one of the
    taxpayers involved.

    They might smart enough(or lucky) to not put the entire database on one laptop
    that went missing, but not smart enough to always encrypt the data under their care.

    reply to this | link to this | view in chronology ]

  • identicon
    R. Kerns, 5 Apr 2007 @ 6:16pm

    Typically Blown Out of Proportion

    When I see news reporting on agencies "losing" computers I really don't get overly spun up. When it comes to assets such as laptops or even desktops it really is not uncommon for systems to be outwardly swiped to be reused for other things... The fact is that they typically aren't lost so much as just reutilized without notice. That being said I find it wholly poor practice for any organization large or small to not keep better track of systems by not just the serial number but also by MAC address. There are systems out there like ForeScout's NAC that you can put in a filter to specifically alert when a lost computer pops up somewhere else on the network via its hardware address. While 400+ misplaced computers is worrisome I am more concerned over a TJX type incident where there was a Breach with intent to steal information. There has also been a mandate from the White House for all federal organizations to utilize disk encryption for portable devices and I would imagine that there will be something coming around for the commercial/financial sector as well via regulations like PCI DSS... I think the average cost per record lost for a commercial entity is around $182 per recent studies so it is nothing but beneficial for a company to take fairly simple measures to address easily identifiable security problems.

    reply to this | link to this | view in chronology ]

  • icon
    rahrens (profile), 6 Apr 2007 @ 4:12am

    agree w/#3

    I work for a Federal Agency, and I've seen the same thing.

    Usually, when an Agency "loses" a piece of equipment, it means one of three things:

    1. It's been surplused, and somebody forgot to do, or lost, the paperwork.
    2. It's been reassigned, and somebody forgot to do, or lost, the paperwork.
    3. It's been mislaid in storage somewhere, and they really don't know where it is. (But it's probably still under lock & key - they just don't know where.

    Face it, most Federal Agencies are pretty big places, with many different physical locations where things can get lost. That doesn't mean that they really ARE lost, as in stolen, it just means they can't find it when it's time to do the inventory.

    That said, MY Agency has a policy that only the IT department can buy PCs or laptops. And when we do, ALL machines that are slated to leave the physical confines of an Agency location are encrypted. No exceptions, even the Commissioner has to have it done. Even desktops.

    Also, there is no need tor data to be stored on a physical drive on a laptop. We use a VPN solution that is about as secure as such things can get, especially so that our employees can easily get to their network resources. ALL data is encouraged to be stored online, so if someone loses a laptop, not only is the entire HD encrypted, but there shouldn't be any data there to lose anyway - we mostly encrypt the HDs to keep network information, such as server names, from getting distributed.

    These reports are based upon inventory records gathered by the Agencies themselves, and is what gets reported to Congress. The news media gets a hold of this, and it becomes "DATA LOSS". But in reality, most of us in the know realize what it really means. (And that is that they get raked over the coals by Congress, but nothing was ever really actually released to the public.)

    reply to this | link to this | view in chronology ]

Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here

Subscribe to the Techdirt Daily newsletter

Comment Options:

  • Use markdown. Use plain text.
  • Remember name/email/url (set a cookie)


Add A Reply

Have a Techdirt Account? Sign in now. Want one? Register here

Subscribe to the Techdirt Daily newsletter

Comment Options:

  • Use markdown. Use plain text.
  • Remember name/email/url (set a cookie)

Follow Techdirt
Special Affiliate Offer

Essential Reading
Techdirt Insider Chat
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it

Email This

This feature is only available to registered users. Register or sign in to use it.