Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

71–80 of 131 posts

Re: The OPM Data Breach [pdf]

#71
post #66

Interestingly enough, I haven't either seen either an emphasis on the main responsible directors being women; or claims that the agency was a "glass cliff".

What on earth would either of those have to do with this?

I think that was a thinly veiled attempt at saying they were "diverse-hires" (a promotion or hire based on gender politics) instead of having a qualified individual in the position.

I'm unaware of the qualifications of either director, so who knows.

Re: The OPM Data Breach [pdf]

#72
post #63

Earlier quoted context omitted.

Employee of 18F here, speaking unofficially. We care a lot about security - both from the technical side and from the policy compliance side!

How was recruitment?. Someone I know tried to get a got job there, got stuck in the queue forever. Was told to wait months. So eventually gave up and took another job.

USAJobs is badly in need of an 18F overhaul.

Re: The OPM Data Breach [pdf]

#73

Earlier quoted context omitted.

After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!

Sounds like one of those situations where you're damned if you do and damned if you don't. Even the most eloquent bitchslap directed at such users, even if you disguise it as user education, can still cause strife. :/

> you're damned if you do and damned if you don't

Most of my military experience followed this maxim. For example: You witness your squadmates doing something against the rules. Do you do the Official thing and report that to your unit commander, as you required to by guidelines and the definition of "good soldier"? Because if you do, now your entire squad will ostracize you, make your life complete shit, and possibly leave you to die on the battlefield. If you don't, you had better hope they don't get caught, because if it comes out that you knew about it and didn't say anything, now you are in just as much trouble.

This happened literally every day.

Re: The OPM Data Breach [pdf]

#74

One of the most frustrating things about this whole fiasco is that the OPM breach finally became public in the summer of 2015, but I and many other victims weren't officially notified (or offered our measly couple years of identity protection) until December or later. At the time, I shared some of my thoughts on the breach here (some of the info may be out of date in light of the new report; I was piecing stuff toget…

I still never received any notice about it. Was employed by DoD in late 00's, so am fairly certain my info was in the batch.

Re: The OPM Data Breach [pdf]

#75

One of the most frustrating things about this whole fiasco is that the OPM breach finally became public in the summer of 2015, but I and many other victims weren't officially notified (or offered our measly couple years of identity protection) until December or later. At the time, I shared some of my thoughts on the breach here (some of the info may be out of date in light of the new report; I was piecing stuff toget…

I just got my postcard informing me I was affected last month. I tossed the offer of credit protection because I'm already stacking multiple "we're sorry" credit protections from other breaches.

The thing that burns me though, is that the credit protection is for a limited time. The severity of this breach and they can't give us a lifetime of protection?!?

Re: The OPM Data Breach [pdf]

#76
post #57

Earlier quoted context omitted.

>It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think th…

As other people touch on, a good offense is something the NSA can actually do themselves. They don't have the authority to be a good defense. They had - and have - no ability to compel OPM to get their shit together. In terms of defense, they've got a severe case of Congress-induces toothlessness.

Here's the kicker, technically NSA can't even do offense (attack). That's what US Cybercom is for. The NSA primary missions are SIGNIT and IA as a combat support agency. So they can gather information on foreign adversaries (and defend DoD networks), but they don't have the mandate to actually perform cyberwarfare. Or for that matter defend civilian networks against attack.

Re: The OPM Data Breach [pdf]

#77
post #58
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

In keeping with industry best practice, I require staff to sandpaper off their fingerprints and regrow them every 90 days. For "security".

A bit extreme isn't that? I just have my staff paint their fingerprints with women's ruby red fingernail paint. It dries to a smooth glass-like finish.

For "security"

Re: The OPM Data Breach [pdf]

#78
post #57

Earlier quoted context omitted.

As other people touch on, a good offense is something the NSA can actually do themselves. They don't have the authority to be a good defense. They had - and have - no ability to compel OPM to get their shit together. In terms of defense, they've got a severe case of Congress-induces toothlessness.

Here's the kicker, technically NSA can't even do offense (attack). That's what US Cybercom is for. The NSA primary missions are SIGNIT and IA as a combat support agency. So they can gather information on foreign adversaries (and defend DoD networks), but they don't have the mandate to actually perform cyberwarfare. Or for that matter defend civilian networks against attack.

NSA and USCC is a distinction without a difference. They've even got the same head honcho.

Re: The OPM Data Breach [pdf]

#79
post #78

Earlier quoted context omitted.

Here's the kicker, technically NSA can't even do offense (attack). That's what US Cybercom is for. The NSA primary missions are SIGNIT and IA as a combat support agency. So they can gather information on foreign adversaries (and defend DoD networks), but they don't have the mandate to actually perform cyberwarfare. Or for that matter defend civilian networks against attack.

NSA and USCC is a distinction without a difference. They've even got the same head honcho.

Both organizations focus on similar concepts (after all exploitation and attack are two sides of the same coin). But there is a legal distinction which is important. NSA legally cannot do all that CYBERCOM can do.

Re: The OPM Data Breach [pdf]

#80
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

At least you can change your password. Good luck getting new fingerprints.
Post reply on HN