Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

101–110 of 131 posts

Re: The OPM Data Breach [pdf]

#101
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

> If only we had an agency in charge of protecting and securing these kinds of systems. Firstly, why do you insist in letting OPM off the hook? Secondly, even if we stipulate that OPM isn't at fault and that someone should have stopped this, you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us

> why do you insist in letting OPM off the hook?

I am not. It failed massively. Letting it do what it kept doing before is not going to work. We have hard evidence of its failure. There is no point mentioning it, it is obvious.

> , you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us

So where was US-CERT all this time? It was active since 2003. It had more than a decade to ramp up and get up to speed.

Why where all the electronic SF-86 forms stolen? You'd think out of all the places, they would protect, that would be close to the top.

> before blindly blaming NSA

Because they are probably the only ones that have the smarts to do it? Also isn't that their mission as well. https://www.nsa.gov/what-we-do/ . Second line is "Defends vital networks". OPM files with detailed and personal details on millions of current and past government workers who have clearance is pretty vital one would think.

Re: The OPM Data Breach [pdf]

#102
post #19

Earlier quoted context omitted.

I don't know. That's not a hurdle my argument needs to clear.

I disagree. If you're going to say "But the authors of this document had a job to do: portray administration appointees in the worst light possible." then you need to at least show some examples of that. You're not making an argument. You're trying to pass an opinion as a fact. You need to back up statements like that.

The past 8, if not the past 24 years, of highly partisan, political, and acrimonious relations between political parties in the U.S. is sufficient context for the observation that this is a single party's view of the incident to be salient.

That of the two major parties, the report is authored by the one with a far more adversarial relationship wwith the truth is also worth mentioning.

Not that the report mightn't contain elements of reality. But this is also likely to be as critical of the opposing part and politically beneficial to the authoring party as possible .

The fact is that this isn't a bipartisan and balanced (possibly, yes, to the point of compromise) report. That is not an opinion.

Tptacek hasn't argued the contents are specifically flawed. But the impartiality of the authors is certainly suspect on well-founded grounds.

Re: The OPM Data Breach [pdf]

#103

One of the most frustrating things about this whole fiasco is that the OPM breach finally became public in the summer of 2015, but I and many other victims weren't officially notified (or offered our measly couple years of identity protection) until December or later. At the time, I shared some of my thoughts on the breach here (some of the info may be out of date in light of the new report; I was piecing stuff toget…

I just got my postcard informing me I was affected last month. I tossed the offer of credit protection because I'm already stacking multiple "we're sorry" credit protections from other breaches. The thing that burns me though, is that the credit protection is for a limited time. The severity of this breach and they can't give us a lifetime of protection?!?

What is "credit protection"?

Re: The OPM Data Breach [pdf]

#104
post #10

This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.

It's a political document in other words based on limited information and perspective?

Re: The OPM Data Breach [pdf]

#105
post #19

Earlier quoted context omitted.

Is there something in this document that you can point to as being inaccurate or obviously exaggerated?

I don't know. That's not a hurdle my argument needs to clear.

Yes, agreed, a partisan document out of a Congressional Committee is inherently biased. I don't think anyone would dispute this as a general principle so there's no reason to think this a special case.

Re: The OPM Data Breach [pdf]

#106
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

The letter they sent me claimed that there is currently no way to create fake fingerprints, so there's nothing to be worried about, 2 years of identity theft monitoring is good enough.

In what world are they living, where there is "no way to create fake fingerprints"? Of course that is possible. Here is one example: http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren.en

It is easily possible to create fake fingerprints that can fool any known finger print scanner. If you know one, that supposedly can't be tricked, please let me know.

Re: The OPM Data Breach [pdf]

#107
post #63

Earlier quoted context omitted.

Employee of 18F here, speaking unofficially. We care a lot about security - both from the technical side and from the policy compliance side!

How was recruitment?. Someone I know tried to get a got job there, got stuck in the queue forever. Was told to wait months. So eventually gave up and took another job.

Sometimes it's a matter of being in the right place at the right time. I applied (and was rejected) for at least 50 federal positions before I was hired. My organization needed someone fast to replace a 20-year fed who was retiring. They compiled a list of all the candidates who made the cert, and in the end, a veteran was selected. Except she wasn't a veteran, not even close. She had lied on her application, and assumed that no one would follow through - and she was almost right, because OPM clearly didn't do anything. But one of my bosses is an Air Force reservist, and he caught it right away. They went back to the original list, and to make a long story short, I was hired even though I'm a non-veteran with only private sector experience. To anyone who is really determined to make it happen, I've heard Kathryn Troutman's books recommended by coworkers.

Re: The OPM Data Breach [pdf]

#108

> The Exfiltration of the Security Clearance Files Could Have Been Prevented. TL;DR, there were two intrusion actors that were acting in concert. After being notified by US-CERT of exfiltration activity from the OPM network, OPM monitored the first one, who conducted the initial breach (use of contractor login credentials) and then performed survey of their network. They attempted to flush out her malware but failed…

" and still ignored/tabled by the CIO, Donna Seymour. " Does she still have that job? If so.. ugh.

She retired [1]

[1] https://oversight.house.gov/release/chaffetz-responds-to-ret...

Re: The OPM Data Breach [pdf]

#109
post #103

Earlier quoted context omitted.

I just got my postcard informing me I was affected last month. I tossed the offer of credit protection because I'm already stacking multiple "we're sorry" credit protections from other breaches. The thing that burns me though, is that the credit protection is for a limited time. The severity of this breach and they can't give us a lifetime of protection?!?

What is "credit protection"?

In the US, most things are based on credit and not on actual money you have. If your credit is bad you can't do basic things like get a car, a house or a loan. If your identity is stolen someone else can do things in your name, and for example not pay back a loan. This causes your credit rating to sink, on top of the other problems (like people coming to your house because you didn't pay them).

If you check out http://money.visualcapitalist.com/all-of-the-worlds-money-an... you can see the derivatives and debt are a huge chunk of the not-actual-money part of the economy, which one way or the other is based on credit, credit ratings or ratings in general.

While this probably doesn't scale back to 1 person's identity, it does show that having someone mess with your credit is a whole lot worse than someone just stealing some money.

Re: The OPM Data Breach [pdf]

#110
post #103

Earlier quoted context omitted.

What is "credit protection"?

In the US, most things are based on credit and not on actual money you have. If your credit is bad you can't do basic things like get a car, a house or a loan. If your identity is stolen someone else can do things in your name, and for example not pay back a loan. This causes your credit rating to sink, on top of the other problems (like people coming to your house because you didn't pay them). If you check out http:…

I get that credit scores are important. They are also in Germany. But what does credit protection do? Pay all the debts? Fix my score with all rating agencies?
Post reply on HN