A Man Jumped a Fence

…surrounding the White House Friday night and was able to get all the way inside the White House before he was stopped. A little birdie has told me how the penetrator was able to get so far.

The Secret Service successfully detected the man as he was climbing the fence, and they responded to him promptly. They committed their initial effort at stopping him to remonstrating with him as he moved across the lawn: this is the sort of thing that was done in the 19th century; such things are unseemly in the 21st. The man was on the wrong side of history, and his effort was doomed to failure, anyway. And so on.

When that didn’t appear to slow the man’s progress, the Secret Service sought to form an interdepartmental task force to intercept him. They tried to enlist the Capital Police, the DC police, they even went as far afield as the Montgomery and Prince George’s County Sheriff’s Departments. By the time the Secret Service realized that that effort wasn’t bearing fruit, the man was entering the North Portico—the front door of the White House—and they were forced to act unilaterally to apprehend him.

This was a devastating episode for the Secret Service.

More Party-of-No Yeses

The House passed three more bills in this short period before the mid-term election campaign recess.

One bill makes it illegal for IRS workers to use personal email accounts to conduct official business.

It’s already illegal to do this in many circumstances, as all official business communications must be recorded and saved. It’s also already contrary to IRS policy; although the IRS has ignored this policy whenever that became convenient.

This is, at bottom, an obvious move, too: private enterprise has, for years, held the flip side—the use of company equipment to conduct personal business—to be a fire-able offense; although they allow some limited personal use.

Another bill guarantees groups that are denied tax-exempt status the right to appeal the decision to a separate IRS office.

Also an obvious move. No government decision should be appeal-proof at the outset.

The third bill addresses complaints from groups that have had their confidential taxpayer information improperly disclosed by IRS employees. The bill allows the IRS to tell victims about the status of investigations into the disclosures. Current law forbids the IRS from releasing such information.

Here, I disagree slightly: the bill should require the IRS to disclose status information, not merely permit it. Still, it’s a step in the right direction.

Watch these three obvious moves die in the Democratic Party-controlled Senate.

DoJ Doing a Racial Bias Study of Police Departments?

That’s rich.

[T]he Justice Department has enlisted a team of criminal justice researchers to study racial bias in law enforcement in five American cities and recommend strategies to address the problem national[.]

Notice that: not researchers, not social science researchers, not social science of conflict researchers, not social science of culture researchers, not urban social science researchers, not…. Criminal justice researchers specifically. AG Eric Holder already has made up his mind on this one.

This study will be overseen by a DoJ led by a man who insists that

in things racial we have always been and continue to be, in too many ways, essentially a nation of cowards.

This study will be overseen by a DoJ led by a man who

dismissed voter intimidation case against two members of New Black Panthers, whose victims were white, even after those two had conceded the case by refusing to answer it.

This study will be overseen by a DoJ that’s openly racist in its civil rights enforcement.

A DoJ with its mind already made up on race expects to be trusted with a study of racial bias in police forces around the nation. This is, indeed, (trigger alert) chutzpah.

Personal Health Information Security

We’ve had HIPAA—the Health Insurance Portability and Accountability Act—for nearly 20 years. This act requires, among other things, all handlers of our personal medical information (primarily, but not exclusively, our doctors, hospitals, and health coverage plan providers) to have our permission to pass that information along, even to other doctors, hospitals, and health coverage plan providers and to take adequate steps to safeguard that information when it’s in their hands or being passed along.

It seems that this administration doesn’t consider itself bound by that same law. The latest example of this evident lawlessness is ObamaMart. The GAO has completed its own assessment of ObamaMart’s security and security practices, and it’s unimpressed.

…weaknesses remained in the security and privacy protections applied to HealthCare.gov and its supporting systems.

This is a year after ObamaMart’s rollout and the discovery of its lack of security. This is four years after HHS, through its CDC, began developing ObamaMart and…testing…it. It boggles my pea brain that security problems of this magnitude could still exist.

In the report, the GAO makes six recommendations to the Department of Health and Human Services to implement security and privacy controls to protect sensitive material. The report also makes 22 recommendations to resolve technical weaknesses in security controls.

Problems with the site ranged from the agency not setting up an alternate processing site for HealthCare.gov systems to allow them to be recovered if the site was hacked or went down to the strength of passwords.

These are basic things that any Computer Science 101 freshman knows. But wait—there’s more.

In addition to these weaknesses, we also identified weaknesses in security controls related to boundary protection, identification and authentication, authorization and configuration management. Collectively, these weaknesses put HealthCare.gov systems and the information they contain at increased and unnecessary risk of unauthorized access, use, disclosure, modification, or loss.

These are more of those things any freshman learns. And these are more of the sorts of things that HIPAA was designed to protect.

The HHS has denied some of these problems exist.

HHS has agreed with three of the six recommendations and has agreed with all 22 technical recommendations.

This isn’t incompetence. These folks are extremely intelligent and talented. Nor is this laziness. These folks are among the hardest working in government. No, this shortfall was deliberate.

Among the issues that concerned the administration’s own technical experts at the time was that security testing could not be completed because the system was undergoing so many last-minute changes.

Because securing citizens’ personal information is only an afterthought to this administration. Because obeying the principles and spirit of HIPAA and related Federal laws, if not their letter, just doesn’t matter to this administration.

Rules, and Rules

In a northern California grade school, there’s a dress code. And there can be no exceptions to the rule.

A young girl was told by her school that she couldn’t wear a T-shirt to pay tribute to the lives lost on Sept 11, 2001.

School leaders say they have a good reason for banning the sixth-grader’s Sept 11 memorial T-shirt on Thursday. When her stepfather tried to get permission, school administrators say it violated their dress code.

District Senior Director for Community Relations Trent Allen said that students were only allowed to deviate from the uniform on free dress days, and 9/11 isn’t one of those days.

It’s very much an important part of the academic process, but need to enforce dress code policy. If you start making exceptions it is hard to draw the line.

Emphasis added to that last. Because there’s a hint there regarding the bureaucratic nature of rules.