Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

81–90 of 131 posts

Re: The OPM Data Breach [pdf]

#81
post #78

Earlier quoted context omitted.

NSA and USCC is a distinction without a difference. They've even got the same head honcho.

Both organizations focus on similar concepts (after all exploitation and attack are two sides of the same coin). But there is a legal distinction which is important. NSA legally cannot do all that CYBERCOM can do.

You're absolutely correct, it's legally a massive difference. In practice, they're more or less the same people groups of the same people.

So I tend to view the distinction between the two as something of a legal fiction.

Re: The OPM Data Breach [pdf]

#82

One of the most frustrating things about this whole fiasco is that the OPM breach finally became public in the summer of 2015, but I and many other victims weren't officially notified (or offered our measly couple years of identity protection) until December or later. At the time, I shared some of my thoughts on the breach here (some of the info may be out of date in light of the new report; I was piecing stuff toget…

as a foreign citizen, previously living and working for the DoT through a contractor, i was never notified as well. pretty sure my data got leaked as well.

Re: The OPM Data Breach [pdf]

#83
post #19

Earlier quoted context omitted.

I don't know. That's not a hurdle my argument needs to clear.

I disagree. If you're going to say "But the authors of this document had a job to do: portray administration appointees in the worst light possible." then you need to at least show some examples of that. You're not making an argument. You're trying to pass an opinion as a fact. You need to back up statements like that.

The document is a "Majority Staff Report". And the only listed authors are from one party. By definition it is a partisan document. That doesn't mean that it's 100% false (or 100% true), but that's the context for the report.

Regardless of whether or not anything was exaggerated, it's still a partisan, political document. The contents don't change that. This would still be the case if it was a "Minority Staff Report" too...

Re: The OPM Data Breach [pdf]

#84
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

The letter they sent me claimed that there is currently no way to create fake fingerprints, so there's nothing to be worried about, 2 years of identity theft monitoring is good enough.

I'm sure you're very comforted by that addition of the qualifier "currently."

Correlated letter from 2011: "Dear streptomycin, your fingerprint data is currently not stolen!"

Re: The OPM Data Breach [pdf]

#85
post #6

Ah yes, when they themselves are affected, suddenly there is a 230 page report. Meanwhile you sure as hell can't, you know, get an actual post mortem when they bomb an Afghani hospital.

I don't know if "suddenly" is the most accurate word. This attack originated in May 2014 and was identified sometime in mid 2015. https://www.opm.gov/cybersecurity/cybersecurity-incidents/

The crazy thing to me was that the 2015 discovery was reportedly [1] due to a "product demo".

Of course, I expect that the company was entirely legitimate, but running an intrusion detection company would apparently be great cover for gaining free vulnerability scans of potential targets.

[1] http://arstechnica.com/security/2015/06/report-hack-of-gover...

Re: The OPM Data Breach [pdf]

#86
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

> Yet the all SF-86 forms Not quite all of them. OPM doesn't seem to keep track of any paper SF-86s that were phased out in favor of the first web site iteration around 2001. Those earlier records may be safe. The image PDF isn't searchable so I couldn't confirm this.

Yap, 2000 or sounds about right.

Re: The OPM Data Breach [pdf]

#87
post #6

Earlier quoted context omitted.

I don't know if "suddenly" is the most accurate word. This attack originated in May 2014 and was identified sometime in mid 2015. https://www.opm.gov/cybersecurity/cybersecurity-incidents/

That is light speed as far as the government is concerned. You couldn't get an FOIA answered in that time period.

FOIA aren't exactly something the government cares about, don't think that's an apt comparison

Re: The OPM Data Breach [pdf]

#88
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!

Seriously? I don't think I've ever seen a security policy where it was not written that you cannot share passwords!

Re: The OPM Data Breach [pdf]

#89
OPM's e-QIP site was vulnerable to heartbleed for at least a week after public disclosure (2014).

They still claim that they were never exploited. The arrest records, addresses, and other sensitive info I was able to view say otherwise.

I expected the EINSTEIN program would have helped to quickly defend against heartbleed after disclosure, but apparently not. US Gov just sucks at cybersecurity defense.

Post reply on HN