Live data from Hacker News

Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

nytimes.com

21–30 of 84 posts

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#21

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

I contract for many large state and federal agencies.

For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations.

Contractors are also able to legally bypass red tape and bureaucracy required of federal employees. For instance if I was directly employed by one of my clients i would be severely limited in the toolchain that I use and I wouldn't even be allowed admin access on my development machine (despite having it on multiple servers which are orders of magnitude more sensitive). If I was their employee, every time I needed to install a java update I'd have to call up IT sit on hold and explain to them exactly why I need to install this update etc.. I've had it literally take a week of futzing around with bizarre errors (from the crazy policy settings and restrictions on the laptop) on hold with some poor schmuck at a national level helpdesk four time zones away who has zero experience with programming trying to get a dev-enviornment set up on a government laptop which would have taken literally an hour on a computer I have local admin access on. I would rather be waterboarded than do that again. Contracting and having our own rules saves literally unending amounts of pointless bullshit. Many things would probably never get completed internally because of situations like this. Of course those contractor advantages cut both ways when considering security.

In OP's situation I'm not sure him being a contractor makes any difference. Either kind of employee can take a usb stick home and transfer stuff to a compromised PC. A contractor or employee may have gotten their clearance a long time ago and unless they have some kind of regular unannounced random inspection of their home you'd never know if they were a hoarder. And if they never caused or were involved in a security incident in the past there would probably be very little desire to bother shaking them down. I'd say problems in this category may be worse internally. I've met many husks of people in government positions who have been there for decades and are completely unemployable. What's worse is they can't be fired easily like a contractor so as long as they show up sober 9-5 they never leave.

Not saying it's a good situation. The contractor knowingly and clearly broke laws, policies, and rules. I annually have to take record keeping and security courses and quizzes to maintain access to the network. I am sure the contractor implicated here had much more stringent requirements than I have due to his clearance level. Thus this guy's screwed, his company is screwed too. legally too. Lord knows this guy can't pull strings at the DoJ to save his ass like some people from recent memory.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#22
The advantage gained by welding advanced technologies is driven by exponential sales cycles. If we allow the government to continue their "back room" rationalizations, there will be a point our demand for more faster will come back and haunt us from a cost standpoint. With exponential advances in technology come several orders of magnitude more oversight capacity by a government who continues to make serious errors in calculations when doing things in secret.

The government isn't currently bad because people in it are bad. It's bad because our government has some bad ideas on what it means to govern successfully externally, in an age that is accelerating internal change in individuals. We want it better faster, too.

If we're going to continue to have government, the government needs to immediately become 90% more transparent and start setting the vision for us to do what we need to do to manage these changes.

And then I look at our current election and just shrug my shoulders.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#23

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

The government has all sorts of pay guidelines on what people can make, which makes it near impossible for them to retain talent. Most of the NSA guys I know put in 18 or so months, then go to Booz Allen and get contracted right back to the department they left at 4x the pay (one guy even got his same desk back).

Every time someone points out the "why'd they give a clearance to X person" argument, I point out that there are close to a million people with security clearances. No screening system is perfect, but for something being ran by the government it is pretty damn good.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#24
post #7

Earlier quoted context omitted.

What is interesting to me is that even super security gurus at NSA can't contain their most sensitive data (well, maybe tools aren't highest level?). At some point I think we need a better security strategy than trying to stop data from leaving, and more about how to make sure data is useless outside of its domain. edit: I say that now in retrospect that security and freedoms of data seem always at odds. DRM being a…

DRM is about neither security nor freedom.

But the more secure we make our devices, the more opportunities we create for them to be locked down. One person's security update is another's anti-jailbreak patch. Trusted computing can be used to protect against malware and to block users from saving Netflix streams.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#25
post #14

Earlier quoted context omitted.

What would those damages consist of? The only material impact I can think of is the apparently U.S.-developed Stuxnet program.

Look at how US prosecutors pile on the cost estimates in hacking cases.

Indeed. "We had no idea security was a thing until you broke in, so now we're counting the cost of giving a shit going forward as damage you inflicted."

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#26
post #7

Earlier quoted context omitted.

What is interesting to me is that even super security gurus at NSA can't contain their most sensitive data (well, maybe tools aren't highest level?). At some point I think we need a better security strategy than trying to stop data from leaving, and more about how to make sure data is useless outside of its domain. edit: I say that now in retrospect that security and freedoms of data seem always at odds. DRM being a…

DRM is about neither security nor freedom.

DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#27
post #12

Earlier quoted context omitted.

What is the point of this comment? It provides nothing to the conversation. Try to be constructive in the future. For instance elaboration on why you like this idea, etc would at least give people something to discuss.

This comment provides even less to the conversation.

[deleted]

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#28
post #10

So, basically, it looks like there's a reasonable probability that this guy isn't the leaker. I know that if I wanted to actually blow the whistle on somebody like the NSA, I would make sure to plant the evidence on somebody else to give them a juicy target to latch onto.

How principled of you to ruin someone's career and let them spend the rest of their life in prison.

I turned down working for the NSA so I wouldn't even be in the position to have to worry about things like that, thanks.

We should be talking about the fact whistleblowers need legal protection. The current treatment of whistleblowers leaves those who wish to defend the principles of the country no good options.

We should also be talking about how easy it is to frame someone and have them found guilty. The fact that we both have zero problem believing that it's that easy to set someone up should be terrifying.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#30

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

As an outsider looking in, it seems like there have been a lot of DLEs due to contractors though. Theres the obvious example of Snowden, but also the QinetiQ breach (https://www.bloomberg.com/news/articles/2013-05-01/china-cyb...). Moonlit Maze might be a counterexample.
Post reply on HN