If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
> If only we had an agency in charge of protecting and securing these kinds of systems. Firstly, why do you insist in letting OPM off the hook? Secondly, even if we stipulate that OPM isn't at fault and that someone should have stopped this, you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us
I am not. It failed massively. Letting it do what it kept doing before is not going to work. We have hard evidence of its failure. There is no point mentioning it, it is obvious.
> , you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us
So where was US-CERT all this time? It was active since 2003. It had more than a decade to ramp up and get up to speed.
Why where all the electronic SF-86 forms stolen? You'd think out of all the places, they would protect, that would be close to the top.
> before blindly blaming NSA
Because they are probably the only ones that have the smarts to do it? Also isn't that their mission as well. https://www.nsa.gov/what-we-do/ . Second line is "Defends vital networks". OPM files with detailed and personal details on millions of current and past government workers who have clearance is pretty vital one would think.