Rep. Rogers Explodes: Americans’ Personal Data at Risk with Unsecured Website

‘You accepted a risk on behalf of every user of this computer that put their personal financial information at risk’

ROGERS: "And so let me tell you what you did. You allowed the system to go forward with no encryption on back-up systems. They had no encryption on certain boundary crossings. You accepted a risk on behalf of every user of this computer that put their personal financial information at risk because you did not even have the most basic end-to-end test on security of this system. Amazon would never do this. ProFlowers would never do this. Kayak would never do this. This is completely an unacceptable level of security, and here's the scary part, we found out after the contractors last week that an end-to-end test hadn't been conducted on security, not functionality, because if it's not functioning, you know it's not secure. Your on going hot patches without end-to-end tests. The private contractors told us it would take a very thorough two months just for an integrated end-to-end security test, which hasn't happened, because you're constantly adding new code every night to protect the functionality of the system. You have exposed millions of Americans because you all, according to your memo, believed it was an acceptable risk. Don't you think you had the obligation to tell the American people that we're going to put you in this system, but beware, your information is likely to be vulnerable? Would you commit today, secretary, to shut down the system and do an end-to-end security test so that these Americans can have their information--"
SEBELIUS: "No sir, if you read the memo,  --"

Video files
Full
Compact
Audio files
Full
Compact