← Back to context

Comment by iAMkenough

2 hours ago

I find it interesting that the co-author of the OP violated long-standing security practices and copied a social security database into an insecure AWS instance without proper oversight.

Is it still commendable if in order to develop this, the taxpayer-funded developer themselves published our PII to a consumer, privately controlled third-party server without following federal data security protocols? Seems like an attempt to make up for the damage they caused.

Standing up your own AWS-equivalent internally is not much work, yet the PII data leaked to publicly available services due to this developer's personal choices and lack of oversight to prevent sensitive government data from being published externally.

Notably, this resulting work has not been published as public domain (CC0).