Earlier quoted context omitted.
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
Seriously? I don't think I've ever seen a security policy where it was not written that you cannot share passwords!
The OPM Data Breach [pdf]
91–100 of 131 posts
Re: The OPM Data Breach [pdf]
#92Earlier quoted context omitted.
I simply disagree with you.
If you're disagreeing that you "need" to provide proof as a duty, then you're correct. If you're disagreeing that you "need" to provide proof because your claim is substantiated intrinsically, then you're being pompous and lazy.
Re: The OPM Data Breach [pdf]
#93If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
Firstly, why do you insist in letting OPM off the hook?
Secondly, even if we stipulate that OPM isn't at fault and that someone should have stopped this, you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us
Re: The OPM Data Breach [pdf]
#94Earlier quoted context omitted.
> The NSA can't make another federal agency improve its computer security. Maybe it should have the power to intervene and stop it? This is still the federal government (it is not about walking into Facebook and shutting it down). I think it is the only agency with the brainpower to do it. It should be been trying to hack it and test the system periodically to identify flaws in it. Then mandate changes. > Do you want…
> Nobody seems to be in charge. That's indeed the problem. There was a strong push for a while to put NSA in charge of civilian infosec infrastructure. But Congress didn't really want to put a combat support agency in that role. So DHS is technically in charge of that. But we still have the majority of federal agencies stuck fending for themselves when it comes to securing their networks. Without stronger action from…
You should go read the cybersecurity act passed in December of 2015, and realize that DHS is now authorized to force agencies to use it's security and offerings.
Re: The OPM Data Breach [pdf]
#95Earlier quoted context omitted.
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
Sucks. Consider writing a book / get in touch with theintercept on a new machine from public wifi. https://theintercept.com/securedrop/ FWIW: Someone I know whom worked for DIA as a sysadmin about 10-15 years ago recalled multiple instances of TS/SCI folks being fired for surfing for porn over monitored networks... career- & clearance-ending. Maybe that's the only culturally-unacceptable sin in that community, apart…
Re: The OPM Data Breach [pdf]
#96Earlier quoted context omitted.
What about things the US Digital Service or 18F? The image they present is that those teams are different and outside the standard government bureaucracy. I'm skeptical.
Employee of 18F here, speaking unofficially. We care a lot about security - both from the technical side and from the policy compliance side!
Which is doubtless why you ignore the TIC guidelines, etc
Re: The OPM Data Breach [pdf]
#97Interestingly enough, I haven't either seen either an emphasis on the main responsible directors being women; or claims that the agency was a "glass cliff".
Re: The OPM Data Breach [pdf]
#98Re: The OPM Data Breach [pdf]
#99"The OPM Data Breach: How the Government Jeopardized Our National Security for More than a Generation"
Re: The OPM Data Breach [pdf]
#100Earlier quoted context omitted.
It is not a technical document. It is a document that contains technical details. For instance: it contains a formal set of "findings", as in the "findings" of law and fact in a trial. Here's one of the first findings: FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities. That's not technical language. It's not even formal language. O…
I won't argue with you the difference between a technical document and a document with technical details. You're welcome to that definitional win. There are interesting technical details in this document about the exact methods, vectors, files, timelines, etc used in both offense and defense of this incident. They would be of interest and value to many in this community regardless of the partisan agenda of the commit…
This document walks up the abstraction chain several notches and attacks the org chart and security policy of the MS Word variety, not the way things were written or configured (except insofar as bad config stemmed from not enough teams of paper not enforced well enough). It is pitched at the kind of CIO/CTO who could just as easily be any other CxO, not at engineers.