Ron Wyden Wants Federal Government To Do More To Protect Personal Devices/Accounts Used By Senators And Staffers

from the small-fix-with-bigger-potential-repercussions dept

Ron Wyden is writing letters again. This time he wants to know why the federal government isn't protecting the personal devices and email accounts used by federal officials. Attacks by state-sponsored hackers are never going to go away, and Wyden feels this lack of protection will make personal devices easy targets. From Wyden's letter [PDF] to Senate majority leaders:

Press reports from January of this year indicate that Fancy Bear--the notorious Russian hacking group--targeted senior congressional staff in 2015 and 2016. My office has since discovered that Fancy Bear targeted personal email accounts, not official government accounts. And the Fancy Bear attacks may be the tip of a much larger iceberg. My office has also discovered that at least one major technology company has informed a number of Senators and Senate staff members that their personal email accounts were targeted by foreign government hackers.

Given the significance of this threat, I was alarmed to learn that SAA cybersecurity personnel apparently refused to help Senators and Senate staff after these attacks The SAA informed each Senator and staff member who asked for help that it may not offer cybersecurity assistance for personal accounts. The SAA confirmed to my office that it believes it may only use appropriated funds to protect official government devices and accounts.

This seems a little odd, but there's a good reason the SAA doesn't extend coverage to personal devices. As Pwn All The Things pointed out on Twitter, personal devices can be used for personal things, and we don't want our elected officials using tax dollars for personal reasons.

This is a good example of a rule constructed for laudable reasons -- the strong firewall to stop legislators using govt money for campaigning and personal things is there for a reason -- ending up with bad consequences on edge-cases like defending high-value accounts from hackers

To protect against hacking attempts, Wyden is introducing legislation that would eliminate the SAA silos. The bill would allow the SAA to "provide cybersecurity assistance" for personal devices on an opt-in basis. We'll have to see how this plays out when implemented. It may make it more difficult to discern if any federal funds were misused by Senators or their staff.

On the other hand, it will help secure devices some government employees mistakenly believe aren't prime targets for state-sponsored hacking. It takes a certain amount of obtuseness to reach this conclusion, considering how heavily some government officials rely on their personal devices for communications with other government officials. The old FOIA dodge is still a popular one, and the difficulty of separating official work from personal work -- especially during election years -- likely means personal devices are used far more frequently than their government-issued ones.

While it's good the government as a whole is continually working towards more robust security, the fact is the private sector offers plenty of options for government officials to better secure their personal devices. Personal responsibility is still underutilized at the federal level, which makes them no better (or worse) than much of the general public.


Reader Comments

Subscribe: RSS

View by: Time | Thread


  • identicon
    bob, 21 Sep 2018 @ 4:05am

    no need.

    I dont have a problem with the Senate putting together a training course for staffers and other members about how to personally protect their devices. Oh wait there already is one, it's the annual Cyber security awareness training.

    If people aren't securing their devices it's because they don't care or don't believe the threat reports, of which there are many publicly available ones not including the Senate specific ones they all have access to.

    If staffers and members get their info exposed, well welcome to the world the reat of us live in. We don't have funds from the government to assign an IT group to protecting ourselves. And if the Senate people's devices have government sensitive data on them, then the owners are breaking both policy and possibly laws and shouldn't be allowed to work in that environment any more.

    reply to this | link to this | view in chronology ]

  • identicon
    I.T. Guy, 21 Sep 2018 @ 4:42am

    "difficulty of separating official work from personal work"

    Whaaa? Why so hard? I've never sent and email expressing my love for my wive via work email, nor have I ever replied to a user using my personal email.

    Its a cut and dry situation. Your business people should never get the email you talk to friends and family with.

    Sorry but there needs to be a hard line drawn. Gov business needs to be performed on Gov equipment. Period.

    BYOD shouldn't even be an option.

    "personal devices are used far more frequently"
    MDM? I never hear of MDM mentioned.
    I've seen better MDM from orgs with 1/10 of the budget.

    "he wants to know why the federal government isn't protecting the personal devices and email accounts used by federal officials."

    He needs to be asking why federal officials are using personal devices in the first place.

    I like Ron but this will only handle issues once there is a problem and the user gets to the point where they finally reach out for help. Usually too late. They need to be proactive.

    reply to this | link to this | view in chronology ]

    • identicon
      Anonymous Coward, 21 Sep 2018 @ 6:24am

      Re: Ron again

      "Ron Wyden is writing letters again. This time he wants to know... "


      Ron's letters are so very effective in problem solving(?)
      Writing letters is why we elect Senators.
      Ron and his Congressional co-workers have masterfully solved all the big issues facing the Federal Government and nation -- so there's ample time now to deal with this trivia of "personal devices".

      reply to this | link to this | view in chronology ]

    • icon
      James Burkhardt (profile), 21 Sep 2018 @ 9:00am

      Re:

      I see you cut context from several statements here.

      During a campaign year, for instance, delineating between government business and personal business becomes harder because the campaign requires heavy management, and is properly not managed on government hardware. Most people will confuse the devices at times, or more likely, send instructions or information using whatever device is at hand.

      Having worked for both small and medium businesses, unless hounded by the CFO, or forced to pay fines by some agency, most business leaders will use whatever card comes out of their wallet when they reach the register, and I regularly have to go through and settle up. Even with that hounding, most will continue to use their personal credit/debit cards and have to be reimbursed by the company. Its easy. Similarly with devices. In fact, most of these congressmen come from business where this practice is common.

      Its not to say that Gov Business is done on Government hardware shouldn't be the standard. But to not be prepared for the human nature to use a personal device on hand to send a memo is stupid. A security system that assumes the user will always operate in accordance with best practices is not a good security system.

      Moreover, that personal device still represents a security risk even if no government data is handled on it due to the wealth of data that could be gathered.

      Mobile Device Management would be unlikely to resolve issues with the use of devices outside the MDM scheme (government work on personal devices), so I am unsure why you brought it up in this context.

      reply to this | link to this | view in chronology ]

      • identicon
        Will B., 21 Sep 2018 @ 1:15pm

        Re: Re:

        Sorry to be flippant, but the first three quarters of your post boil down to "people do wrong things, so we shouldn't try to stop them doing those wrog things because they're normal." Ubiquity is not a defense.

        That said, I do think you make a good point that even purely personal data can be of use to hackers targeting politicians!

        reply to this | link to this | view in chronology ]

      • identicon
        Lawrence D’Oliveiro, 21 Sep 2018 @ 10:46pm

        Re: delineating between government business and personal busines

        But ... but ... Hillary!

        reply to this | link to this | view in chronology ]

  • identicon
    Capt ICE Enforcer, 21 Sep 2018 @ 4:43am

    Solution

    Well. If we give the government a key to all our electronics. I am sure they would remember to lock the door after leaving.

    reply to this | link to this | view in chronology ]

  • icon
    tom (profile), 21 Sep 2018 @ 6:48am

    Fixing this: https://www.techdirt.com/articles/20180918/09232040665/congress-fails-to-include-single-consumer-adv ocate-upcoming-privacy-hearing.shtml
    would be a good start.

    Hard to get too concerned about security when the basic business model of far too many companies(campaign contributors) includes being able to monitor, track and data mine the personalized tracking devices most folks carry.

    reply to this | link to this | view in chronology ]

  • icon
    DannyB (profile), 21 Sep 2018 @ 7:52am

    How about protecting the rest of us?

    Everyone else has personal devices too!

    Our devices are subject to attack by state sponsored hackers.

    The US government needs to protect us from certain governments that want to take away our crypto and security by requiring back doors. (Oh, wait...)

    But maybe I'm paranoid. Maybe there is No Such Agency that would want to spy on US citizens.

    reply to this | link to this | view in chronology ]

  • icon
    Bamboo Harvester (profile), 21 Sep 2018 @ 9:03am

    Is there really any point to this? They're STILL going to use "passw0rd" as their password....

    reply to this | link to this | view in chronology ]

  • icon
    ECA (profile), 21 Sep 2018 @ 11:31am

    Be Afraid..

    Wonderful..
    OPEN up everyone else with Backdoor encryption, but Protect our HIGH RANKING Gov. employees...
    From having their emails raided and Displayed for everyone to see..
    shouldnt we be doing this anyway??

    reply to this | link to this | view in chronology ]

  • identicon
    Anonymous Coward, 24 Sep 2018 @ 3:52am

    It sounds like someone wants special treatment. It is almost like they are more important than others.

    All animals are equal, but some animals are more equal than others.

    reply to this | link to this | view in chronology ]


Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Use markdown for basic formatting. HTML is no longer supported.
  Save me a cookie
Follow Techdirt
Insider Shop - Show Your Support!

Advertisement
Report this ad  |  Hide Techdirt ads
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Chat
Advertisement
Report this ad  |  Hide Techdirt ads
Recent Stories
Advertisement
Report this ad  |  Hide Techdirt ads

Close

Email This

This feature is only available to registered users. Register or sign in to use it.