http://data.danwin.com/pdfs/house-oversight-opm-breach-2016-...
(not sure why ABBYY blew its size up to 98MB...)
And here it is in plaintext via pdftotext:
http://data.danwin.com/pdfs/house-oversight-opm-breach-2016-...
31–40 of 131 posts
http://data.danwin.com/pdfs/house-oversight-opm-breach-2016-...
(not sure why ABBYY blew its size up to 98MB...)
And here it is in plaintext via pdftotext:
http://data.danwin.com/pdfs/house-oversight-opm-breach-2016-...
This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.
In some places its typical for such legislative committees to also issue minority/dissenting reports - does that happen in the US?
http://democrats.oversight.house.gov/news/press-releases/cum...
If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
Earlier quoted context omitted.
> It seems NSA has spent all its budget on cool hacking tools and programs From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network. I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can p…
> The NSA can't make another federal agency improve its computer security. Maybe it should have the power to intervene and stop it? This is still the federal government (it is not about walking into Facebook and shutting it down). I think it is the only agency with the brainpower to do it. It should be been trying to hack it and test the system periodically to identify flaws in it. Then mandate changes. > Do you want…
That's indeed the problem. There was a strong push for a while to put NSA in charge of civilian infosec infrastructure. But Congress didn't really want to put a combat support agency in that role. So DHS is technically in charge of that. But we still have the majority of federal agencies stuck fending for themselves when it comes to securing their networks. Without stronger action from Congress, this may never change.
Earlier quoted context omitted.
I don't know if "suddenly" is the most accurate word. This attack originated in May 2014 and was identified sometime in mid 2015. https://www.opm.gov/cybersecurity/cybersecurity-incidents/
That is light speed as far as the government is concerned. You couldn't get an FOIA answered in that time period.
Note: Sure, politicians move very quickly when politics are involved.
Earlier quoted context omitted.
> The NSA can't make another federal agency improve its computer security. Maybe it should have the power to intervene and stop it? This is still the federal government (it is not about walking into Facebook and shutting it down). I think it is the only agency with the brainpower to do it. It should be been trying to hack it and test the system periodically to identify flaws in it. Then mandate changes. > Do you want…
> Nobody seems to be in charge. That's indeed the problem. There was a strong push for a while to put NSA in charge of civilian infosec infrastructure. But Congress didn't really want to put a combat support agency in that role. So DHS is technically in charge of that. But we still have the majority of federal agencies stuck fending for themselves when it comes to securing their networks. Without stronger action from…
Earlier quoted context omitted.
> Nobody seems to be in charge. That's indeed the problem. There was a strong push for a while to put NSA in charge of civilian infosec infrastructure. But Congress didn't really want to put a combat support agency in that role. So DHS is technically in charge of that. But we still have the majority of federal agencies stuck fending for themselves when it comes to securing their networks. Without stronger action from…
Because when I think of technical sophistication, I think of DHS.
This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.
In some places its typical for such legislative committees to also issue minority/dissenting reports - does that happen in the US?
[0] http://democrats-benghazi.house.gov/sites/democrats.benghazi...
If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
Two distinct attacks, likely related, possibly coordinated took place. The first was observed in March 2014 and thought to be expelled in late May 2014.
Before that expulsion, a second attack began. While OPM thought it was in the clear, the 21.5M records were exfiltrated in July 2014. As late as August 2015, that same attack vector was used to steal fingerprint information as well.