Homeland Security Can't Even Configure Its Mailing List Software Correctly?

from the that-makes-me-comfortable dept

Just after the federal gov’t screwed up and shut off ca.gov, we find out that the Department of Homeland Security misconfigured its email list software causing a deluge of annoying emails to over seven thousand government employees. The list, normally used to broadcast news summaries of security news, apparently was set up so that any reply messages automatically were broadcast to all members. What happened next is familiar to lots of folks on mailing lists, where the “reply all” button is misused. The one difference, though, was that this wasn’t a misuse of the reply all button, but on the mailing list automatically sending out anyone’s message to everyone on the list. Many security experts on the list are apparently wondering what that says about Homeland Security’s ability to deal with cybersecurity issues. Perhaps it was just a little configuration error, but you would think that the folks at the DHS would be a bit more careful about those things.

Filed Under: ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Homeland Security Can't Even Configure Its Mailing List Software Correctly?”

Subscribe: RSS Leave a comment
15 Comments
Forest Johnson says:

Government Intelligence

Any good American knows the two words that never go together, Government and Intelligence. I am in a wonderful country, one of the best on this little blue marble we call home. But, some of the decisions made by our government, governmental policy makers and agents/agencies there, are less than admirable.

The best part of all this though… Elections!!!

Jiminy says:

Re: OUt of Office

If you had read the story NipseyRussell, you would realise that the problem with the system was the an ‘reply’ was being forwarded to everyone on the global address list. The Out of Office needn’t be configured to some ‘reply all’ status for everyone to get spammed by it. The out of office ‘reply’ (singular) could be duplicated and sent to everyone. That being said, out of office replies to not generate out of office replies. So the initial statement was just as stupid.

Clueby4 says:

Two words - Lotus Notes

According to Ars Technica’s article this was a Lotus Notes issue.

http://arstechnica.com/news.ars/post/20071005-dhs-flunks-e-mail-administration-101-causes-mini-ddos.html

Why in the hell are they using Lotus Notes, IBM doesn’t even use that piece of garbage. Great security BTW, grab a user.id file and your in. I know some Lotus fanboy will probably flap that tired diatribe “Notes is Groupware” which sounds good but it doesn’t excuse the EXTREMELY POOR DESIGN of the Notes platform.

The most damning design flaw in Notes is the Address book. “All your eggs in one basket”, hardly conveys the ignorance. More like “All your eggs, chickens, livestock, cash, children, hopes, dreams and then kitchen sick in one basket”

Beside the idiots at DHS should have a static reply to.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...