Welp, now any company that does business with the government has to share data with them... Guess the only privacy-focused companies left will be the ones who refuse to work with the government.
Not quite sure what you are referring to here - do you mean after-the-fact when there has been a breach? (This is what is mentioned in [0]).It seems like there needs to be some NTSB-like entity given the breadth and depth of people this effects. What would be a better way of doing these types of post-hoc security audits?
No, they are requiring any company that does business with the government to share information with them basically regarding any potential security risks. Essentially, using the word encryption in your email could be considered a potential security risk.
> Essentially, using the word encryption in your email could be considered a potential security risk.
How? This seems a bit of a stretch. Is using the word "lock" in an email a potential security risk? Are SPF, DKIM, and DMARC headers potential security risks?
Regardless, I don't necessarily like the idea, because gathering a bunch of audit and pentest reports into a single location seems like a very appealing target. Here's hoping there's not an OPM-style breach.
4 comments
[ 3.7 ms ] story [ 23.6 ms ] thread[0] https://www.npr.org/2021/04/29/991333036/biden-order-to-requ...
How? This seems a bit of a stretch. Is using the word "lock" in an email a potential security risk? Are SPF, DKIM, and DMARC headers potential security risks?
Regardless, I don't necessarily like the idea, because gathering a bunch of audit and pentest reports into a single location seems like a very appealing target. Here's hoping there's not an OPM-style breach.