"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!
I'd like to see YYYY-04-01 RFC on biometrics authenticator expiration protocols.
The OPM Data Breach [pdf]
61–70 of 131 posts
Re: The OPM Data Breach [pdf]
#62Earlier quoted context omitted.
>It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think th…
Exactly this. The US government thinks about computer security as a kind of war - cyberwar - and for better or for worse it has adapted the mindset that "security by demonstrated capability to drop scary bombs with brutal precision and efficiency" is more realistic than "security by making every building bomb proof." Geopolitics these days isn't about impenetrable borders, it's about deterrence by ability to project…
Re: The OPM Data Breach [pdf]
#63Earlier quoted context omitted.
What about things the US Digital Service or 18F? The image they present is that those teams are different and outside the standard government bureaucracy. I'm skeptical.
Employee of 18F here, speaking unofficially. We care a lot about security - both from the technical side and from the policy compliance side!
Re: The OPM Data Breach [pdf]
#64"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!
Re: The OPM Data Breach [pdf]
#65If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
> It seems NSA has spent all its budget on cool hacking tools and programs From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network. I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can p…
Maybe not directly. But the NSA could play a much more positive role in information security generally by moving out of the shadows and making more of its research public. The expertise that the NSA has acquired in securing information needs to be widely disseminated to work its way into engineering curricula and praxis, and that won't happen as long as the NSA communicates by whispering.
Re: The OPM Data Breach [pdf]
#66Interestingly enough, I haven't either seen either an emphasis on the main responsible directors being women; or claims that the agency was a "glass cliff".
Re: The OPM Data Breach [pdf]
#67If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
Not quite all of them. OPM doesn't seem to keep track of any paper SF-86s that were phased out in favor of the first web site iteration around 2001. Those earlier records may be safe. The image PDF isn't searchable so I couldn't confirm this.
Re: The OPM Data Breach [pdf]
#68If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
Re: The OPM Data Breach [pdf]
#69If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
Re: The OPM Data Breach [pdf]
#70> The Exfiltration of the Security Clearance Files Could Have Been Prevented. TL;DR, there were two intrusion actors that were acting in concert. After being notified by US-CERT of exfiltration activity from the OPM network, OPM monitored the first one, who conducted the initial breach (use of contractor login credentials) and then performed survey of their network. They attempted to flush out her malware but failed…
Does she still have that job? If so.. ugh.