<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Florida &amp;quot;state&amp;quot; password in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41786#M5202</link>
    <description>I see you're one of "those" people. I'm not going to dignify you're idiotic and incorrect comparison with a response that you a.) will never understand, and b.) won't listen to anyway.</description>
    <pubDate>Fri, 18 Dec 2020 20:35:23 GMT</pubDate>
    <dc:creator>Startzc</dc:creator>
    <dc:date>2020-12-18T20:35:23Z</dc:date>
    <item>
      <title>Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41603#M5159</link>
      <description>&lt;P&gt;OK, simply by mentioning that this &lt;STRONG&gt;would&lt;/STRONG&gt; come out of Florida I'm already at risk of being banned for making a political post, so I won't go too deeply into the background of this story (which is messy in the extreme).&amp;nbsp; Suffice it to say that a state employee has been arrested because she sent a message on a system which implied that she had to be misusing an account and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it turns out that there is, in fact, only one login and password, it is used by 1700 users ... and it's also &lt;A href="https://arstechnica.com/tech-policy/2020/12/florida-posted-the-password-to-a-key-disaster-system-on-its-website/" target="_blank" rel="noopener"&gt;posted online for anyone&lt;/A&gt; to find and use ...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:43:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41603#M5159</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T09:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41616#M5161</link>
      <description>&lt;P&gt;Don't think it's a political post.&amp;nbsp; It simply highlights some very BAD security practices that all of us have had to content with and have sometimes lost the battle (which may be the case here).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This really deserves an award.&amp;nbsp; Let's call it the "Oh Come On Now" award.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;keep smiling&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 08:34:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41616#M5161</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-12-13T08:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41620#M5162</link>
      <description>&lt;P&gt;This is just a mess on so many different levels. On the state side, I would say it's just lazy to share one password and for it to be public, no words. As for the woman, just because I forget to lock my front door does not give you the right to enter my house. I think the message that she sent was just adding to problems that were being had at the time and did not help matters any. Besides from the legal issues here I think it's also an ethical issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 16:35:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41620#M5162</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-12-13T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41781#M5198</link>
      <description>&lt;P&gt;Sounds to me like a case even the least experienced public defender could win against the state. They obviously wont be able to prove they did anything to protect the system in question and have no mechanism for nonrepudiation if everyone used the same account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Makes me wonder what information was used to justify the search warrant in the first place. Or maybe they just made sure to bring the request to a completely IT illiterate judge. I will definitely be watching to see how this one plays out. Whether she did it or not, the outcome could have far reaching implications for state and local IT professionals and employees in general.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 19:19:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41781#M5198</guid>
      <dc:creator>Startzc</dc:creator>
      <dc:date>2020-12-18T19:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41785#M5201</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1650808605"&gt;@Startzc&lt;/a&gt;&amp;nbsp;So if you leave your door wide open and I go in and take something you are saying this would be your fault for not securing your door and not mine for going where I clearly knew I should not be going?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lack of security does not give anyone permission!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 20:26:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41785#M5201</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-12-18T20:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41786#M5202</link>
      <description>I see you're one of "those" people. I'm not going to dignify you're idiotic and incorrect comparison with a response that you a.) will never understand, and b.) won't listen to anyway.</description>
      <pubDate>Fri, 18 Dec 2020 20:35:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41786#M5202</guid>
      <dc:creator>Startzc</dc:creator>
      <dc:date>2020-12-18T20:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41787#M5203</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1650808605"&gt;@Startzc&lt;/a&gt;&amp;nbsp;Please do! If you have a valid reason why it is a bad comparison I am all ears, hearing other people's ideas are how we learn. If you simply have nothing to say then please don't make comments you will not explain. And if I will not understand your response consider giving it some thought and finding a way to state it so anyone can understand it. Communication skills are very important.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John-&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 20:55:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41787#M5203</guid>
      <dc:creator>JKWiniger</dc:creator>
      <dc:date>2020-12-18T20:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41788#M5204</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1650808605"&gt;@Startzc&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Makes me wonder what information was used to justify the search warrant in the first place.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;They traced the IPV6 address to her house. Whether good intentioned or not, she accessed the State Emergency-Responder system and sent an unauthorized message. And don't come on here calling people idiots just because you disagree with their opinion. Eloquently state your objection and move on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 21:02:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41788#M5204</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2020-12-18T21:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41789#M5205</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P class="1608325576890"&gt;&lt;SPAN style="font-family: inherit;"&gt;&amp;nbsp;And don't come on here calling people idiots just because you disagree with their opinion. Eloquently state your objection and move on.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;Per posted Community usage guidelines please keep conversation respectful - see rule #4.&amp;nbsp;&lt;A href="https://community.isc2.org/t5/Welcome/ISC-Community-Usage-Policy-Guidelines-Updated-October-2020/m-p/38340" target="_blank"&gt;https://community.isc2.org/t5/Welcome/ISC-Community-Usage-Policy-Guidelines-Updated-October-2020/m-p/38340&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 21:10:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41789#M5205</guid>
      <dc:creator>AndreaMoore</dc:creator>
      <dc:date>2020-12-18T21:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41791#M5207</link>
      <description>&lt;P&gt;First, I didn't call anyone anything. Second, why should I be required to eloquently reply to a comment that made a lot of assumptions and was completely unsubstantiated by any opinions or facts?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 00:20:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41791#M5207</guid>
      <dc:creator>Startzc</dc:creator>
      <dc:date>2020-12-19T00:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41793#M5208</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1650808605"&gt;@Startzc&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;... why should I be required to eloquently reply...?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;It is not required to be eloquent. What is required is to be respectful.&amp;nbsp; To participate on this community, one is required to follow the rules set forth by is owners and to which&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1086253963"&gt;@AndreaMoore&lt;/a&gt;&amp;nbsp; (thier official representative) earlier provided a link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the topic at hand, no need to wonder about the justification.&amp;nbsp; The &lt;A href="https://arstechnica.com/tech-policy/2020/12/florida-posted-the-password-to-a-key-disaster-system-on-its-website/" target="_blank" rel="noopener"&gt;article&lt;/A&gt;&amp;nbsp;Rob &lt;A href="https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41603/highlight/true#M5159" target="_blank" rel="noopener"&gt;provided&lt;/A&gt; contains a link to &lt;A href="https://cdn.arstechnica.net/wp-content/uploads/2020/12/FDLE-search-warrant-affidavit-1.pdf" target="_blank" rel="noopener"&gt;the affidavit for the search warrant&lt;/A&gt; which enumerates the probable cause resulting in the warrant's issuance.&amp;nbsp; It also makes clear the Affiant's intent to search her computing devices to develop the requisite evidence (or in your vernacular, "non-repudiation").&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AFAIK, no charges have been issued, so I am not yet able to speculate how easily either party may prevail.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 07:08:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41793#M5208</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2020-12-19T07:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41798#M5210</link>
      <description>I'm *SO* glad that my initial post has engendered such thoughtful discourse and&lt;BR /&gt;high quality debate.&lt;BR /&gt;&lt;BR /&gt;(I *told* you the story was a mess. Somehow it seems to create additional messes&lt;BR /&gt;...)&lt;BR /&gt;&lt;BR /&gt;======================&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;"If you do buy a computer, don't turn it on." - Richards' 2nd Law&lt;BR /&gt;"Robert Slade's Guide to Computer Viruses" 0-387-94663-2&lt;BR /&gt;"Viruses Revealed" 0-07-213090-3&lt;BR /&gt;"Software Forensics" 0-07-142804-6&lt;BR /&gt;"Dictionary of Information Security" Syngress 1-59749-115-2&lt;BR /&gt;"Cybersecurity Lessons from CoVID-19" CRC Press 978-0-367-68269-9&lt;BR /&gt;============= for back issues:&lt;BR /&gt;[Base URL] site &lt;A href="http://victoria.tc.ca/techrev/" target="_blank"&gt;http://victoria.tc.ca/techrev/&lt;/A&gt;&lt;BR /&gt;CISSP refs: [Base URL]mnbksccd.htm&lt;BR /&gt;PC Security: [Base URL]mnvrrvsc.htm&lt;BR /&gt;Security Dict.: [Base URL]secgloss.htm&lt;BR /&gt;Security Educ.: [Base URL]comseced.htm&lt;BR /&gt;Book reviews: [Base URL]mnbk.htm&lt;BR /&gt;[Base URL]review.htm&lt;BR /&gt;Partial/recent: &lt;A href="http://groups.yahoo.com/group/techbooks/" target="_blank"&gt;http://groups.yahoo.com/group/techbooks/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Robert_Slade" target="_blank"&gt;http://en.wikipedia.org/wiki/Robert_Slade&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt; &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;</description>
      <pubDate>Sat, 19 Dec 2020 17:56:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41798#M5210</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-12-19T17:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Florida "state" password</title>
      <link>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41860#M5213</link>
      <description>&lt;P&gt;I'm just glad the argument flared and died.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what're the three legs of this broken-leg stool?&amp;nbsp; The system must be&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Secure&lt;/LI&gt;&lt;LI&gt;Easily Accessible&lt;/LI&gt;&lt;LI&gt;Always available&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Insert the obligatory "you can only pick two", and the password is&amp;nbsp;&lt;EM&gt;solarwinds123&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 18:29:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Florida-quot-state-quot-password/m-p/41860#M5213</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2020-12-21T18:29:25Z</dc:date>
    </item>
  </channel>
</rss>

