Oh wow. Except for those secrets.
More competent technical control means a random contractor doesn't have passwords from mid-2025 to copy to their home machine that even still work after 30 days, if not 5.
Or maybe that'd have been the sort of project and standard CISA would have formerly done before the Republicans gutted it last year I guess, and this is just another symptom of rot? But yeah to your point technology certainly can absolutely help with this sort of thing. It's not some inevitable act of nature.
The usage of "exhibit a pattern consistent with..." is just describing what it looks like the repository was used for. i.e. it's not a set of government sourcecode for an internal project, it's not something indicative of intentionally leaking large amounts of data, etc.
They clearly stated what pattern this usage is consistent with: using it as a sort of personal scratch pad.
You’re assigning more meaning to the statement than there is. They are simply stating an observation.
The nuance here: when I’ve slipped and committed secrets, it’s typically a relative nothing burger: most common case is API keys to some third-party service. I’ve worked across a bunch of regulated industries and, within those, not caused a breach—because being in that space you know to be more careful, and because the companies in those spaces (wisely!) tend to support good security practices, more so than the industry average.
You'd be rich if you got a dollar for every worldwide murder too, but that doesn't make murder a common workplace occurrence.
In 2020 Chris Krebs contradicted stolen election claims. In 2025, Trump sacked Krebs and revoked his clearance, leaving CISA without a director. https://en.wikipedia.org/wiki/Chris_Krebs
In March 2025, the cuts began. https://techcrunch.com/2025/03/11/doge-axes-cisa-red-team-st...
In 2026, it was still without a director and running on fumes. https://techcrunch.com/2026/02/25/us-cybersecurity-agency-ci...
This activity is consistent with intentionally weakening a country's defenses from within and sowing chaos.
Eventually, paths like that may lead to increased privatization through security contractors.
[1]https://www.padilla.senate.gov/newsroom/press-releases/padil...
This is the "who killed Hannibal" meme. If Padilla and Warner didn't know about this, then they're incompetent themselves. Especially because they reported on it last year:
https://www.padilla.senate.gov/newsroom/news-coverage/cnn-tr...
Why did you forget this happened, Padilla?
because behind any senator there is a propaganda team, not a brain