Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

11–20 of 131 posts

Re: The OPM Data Breach [pdf]

#11
If only we had an agency in charge of protecting and securing these kinds of systems.

It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team.

Stolen stuff includes millions of fingerprints. Those are obviously not hashed, so that's just the raw data I imagine. They'll learn lesson to not rely on fingerprints as much. Maybe that's one good thing coming out of it.

[+] CIA could still be affected, if for example some people there started at other agencies, or in the military (CIA likes to hire ex-Marines for example).

Re: The OPM Data Breach [pdf]

#12
post #10

This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.

Let's be fair: while the source may well be partisan, it is also a technical document. Referring to it simply as a partisan political document doesn't acknowledge its full contents or its value to a technical community.

Re: The OPM Data Breach [pdf]

#13
post #10

This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.

Perhaps https://www.opm.gov/cybersecurity/cybersecurity-incidents/op... is more informative technically, but this "post-mortem" is a fascinating read for me. It's like The Cuckoo's Egg for modern times, as writ by government subcommittee.

Re: The OPM Data Breach [pdf]

#14
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

[deleted]

Re: The OPM Data Breach [pdf]

#15
> The Exfiltration of the Security Clearance Files Could Have Been Prevented.

TL;DR, there were two intrusion actors that were acting in concert. After being notified by US-CERT of exfiltration activity from the OPM network, OPM monitored the first one, who conducted the initial breach (use of contractor login credentials) and then performed survey of their network. They attempted to flush out her malware but failed to account for a second actor that had managed to leave an alternate access point into the network.

> "Notably, OPM Director of IT Security Operations, Jeff Wagner, recommended deploying ... preventative technology"

So the problem was identified and brought up to committee and still ignored/tabled by the CIO, Donna Seymour. Preventive measures were only undertaken after the exfiltration of security clearance data was complete.

Re: The OPM Data Breach [pdf]

#16
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

One of NSA's primary missions is information assurance. I'm sure they have blue teams. But their mandate is pretty limited in regards to what they can do with civilian infrastructure.

Re: The OPM Data Breach [pdf]

#17
post #12
post #10

This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.

Let's be fair: while the source may well be partisan, it is also a technical document. Referring to it simply as a partisan political document doesn't acknowledge its full contents or its value to a technical community.

It is not a technical document. It is a document that contains technical details. For instance: it contains a formal set of "findings", as in the "findings" of law and fact in a trial. Here's one of the first findings:

FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities.

That's not technical language. It's not even formal language.

OPM was/is a clusterfuck. I'm not disputing that. But the authors of this document had a job to do: portray administration appointees in the worst light possible.

Re: The OPM Data Breach [pdf]

#18
post #17
post #12

Earlier quoted context omitted.

Let's be fair: while the source may well be partisan, it is also a technical document. Referring to it simply as a partisan political document doesn't acknowledge its full contents or its value to a technical community.

It is not a technical document. It is a document that contains technical details. For instance: it contains a formal set of "findings", as in the "findings" of law and fact in a trial. Here's one of the first findings: FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities. That's not technical language. It's not even formal language. O…

Is there something in this document that you can point to as being inaccurate or obviously exaggerated?

Re: The OPM Data Breach [pdf]

#19
post #17

Earlier quoted context omitted.

It is not a technical document. It is a document that contains technical details. For instance: it contains a formal set of "findings", as in the "findings" of law and fact in a trial. Here's one of the first findings: FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities. That's not technical language. It's not even formal language. O…

Is there something in this document that you can point to as being inaccurate or obviously exaggerated?

I don't know. That's not a hurdle my argument needs to clear.

Re: The OPM Data Breach [pdf]

#20
Interesting to see the steps they took to expel the APT (physically verifying the identity of account holders on account resets, taking services offline, resetting networking equipment).

Even more interesting is that had confidence they'd actually expelled the APT. Of course, they hadn't totally eliminated a related APT already in place.

This wasn't a "provision a clean box and run a build" reset... it's a massive, heterogeneous system. I can't even imagine how many vectors a nation-state APT could use to maintain a foothold.

Post reply on HN