News
3/24/2008
09:00 PM
Terry Sweeney
Terry Sweeney
Commentary
50%
50%

Real Tossers

How long do you hang on to decommissioned hard drives and storage devices? Do you at least wait to make sure your new drives or backup applications are functioning properly? If you answered yes to that last question, there might be a job at the White House for you.

How long do you hang on to decommissioned hard drives and storage devices? Do you at least wait to make sure your new drives or backup applications are functioning properly?

If you answered yes to that last question, there might be a job at the White House for you.The latest wrinkle in the missing White House e-mail saga is that the drives are gone. Tossed out. Destroyed, even.

"When workstations are at the end of their life cycle and retired... the hard drives are generally sent off-site to another government entity for physical destruction," the White House told a federal judge last week.

Normally, a reasonably sensible storage professional makes sure all necessary data was properly copied. And, normally, new applications -- whether it's an e-mail server or the backup system for it -- are tested and re-tested before anything gets destroyed. But this situation isn't normal, and the story behind the story keeps changing, or getting added to, like one of those serial chain letters that clutter your in-box.

Earlier on, I was willing to give the White House and CIO Theresa Payton the benefit of the doubt about this mess. My suspension of disbelief about this is officially suspended. The way they've disclosed details about the chronology and methods behind their actions now sounds improvised -- very lately improvised.

I have no idea if the judge in the case, John Facciola, is technically astute where the ins and outs of IT are concerned. But I'm betting he's started to sense that something's a bit off. This has now gotten to the point where it officially insults the intelligence. We'll see just how insulted the judge is in the next chapter -- his response won't be any kind of throwaway.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-1793
Published: 2014-12-25
rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."

CVE-2011-1794
Published: 2014-12-25
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...

CVE-2011-1795
Published: 2014-12-25
Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document con...

CVE-2011-1796
Published: 2014-12-25
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaS...

CVE-2011-1798
Published: 2014-12-25
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown othe...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.