Live data from Hacker News

Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

nytimes.com

31–40 of 84 posts

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#31

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

Don't they have random searches? when I went to HMGCC for an interview (at Hanslope Park) a couple of years back there was a sign up saying that you could be searched on entry and exit.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#32
post #26

Earlier quoted context omitted.

DRM is about neither security nor freedom.

DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).

It's funny. People get all excited about homomorphic encryption, which is basically DRM with a mathematical proof.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#33

Earlier quoted context omitted.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

Don't they have random searches? when I went to HMGCC for an interview (at Hanslope Park) a couple of years back there was a sign up saying that you could be searched on entry and exit.

He must've hidden it in his Rubix cube.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#34

Earlier quoted context omitted.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

As an outsider looking in, it seems like there have been a lot of DLEs due to contractors though. Theres the obvious example of Snowden, but also the QinetiQ breach ( https://www.bloomberg.com/news/articles/2013-05-01/china-cyb... ). Moonlit Maze might be a counterexample.

I think that's because most of the people doing the work are contractors. Not because of some notion of contractors being less secure/loyal/honest/organized than gov employees.

For one federal organization I work for literally everyone I work with and talk to at all levels seems to be a contractor except for a couple people. the ratio is at least 20:1 contractors to federal employees. As for why this is, it's mostly related to the reasons I mentioned in my wall of text

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#35

Earlier quoted context omitted.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

Don't they have random searches? when I went to HMGCC for an interview (at Hanslope Park) a couple of years back there was a sign up saying that you could be searched on entry and exit.

not where I work. Also, random could mean once every 10 years. I use a laptop and take it home every night. Unless they banned users from taking everything with them (phones keychains etc) there's not much a random search would accomplish.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#36

> He always thought of himself like a James Bond-type person, wanting to save the world from computer evil Maybe the NSA needs less James Bond characters and more engineers.

So? your not really making sense here "engineers" may well think that working for the good of the state is more ethical than working on an improved algo for google/facebook to monetize peoples private data.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#37

Earlier quoted context omitted.

Don't they have random searches? when I went to HMGCC for an interview (at Hanslope Park) a couple of years back there was a sign up saying that you could be searched on entry and exit.

not where I work. Also, random could mean once every 10 years. I use a laptop and take it home every night. Unless they banned users from taking everything with them (phones keychains etc) there's not much a random search would accomplish.

I know people who worked at places where taking a phone into work with a camera in was verboten.

And for high security places why on earth would they allow people to work on laptops that are taken home every night an obvious security risk.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#38
post #26

Earlier quoted context omitted.

DRM is about neither security nor freedom.

DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).

DRM is more about who has the keys, than security itself.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#39

Earlier quoted context omitted.

not where I work. Also, random could mean once every 10 years. I use a laptop and take it home every night. Unless they banned users from taking everything with them (phones keychains etc) there's not much a random search would accomplish.

I know people who worked at places where taking a phone into work with a camera in was verboten. And for high security places why on earth would they allow people to work on laptops that are taken home every night an obvious security risk.

well we don't even work onsite. I write my code on my company laptop. Test against a sanitized database on my companies network and whatnot. Then commit to my companies source control. Then I pickup my government issued locked down laptop, vpn in, remote desktop to the server across the US and svn-update.

I am not dealing with TS stuff here. There are files on the government network which are confidential and having access does require a clearance, but I don't actually work with confidential data directly.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#40

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

What I find astonishing is that these machines have working USB ports at all. And even if there are some external media connections like DVD burner or USB, wouldn't it make sense to at least hardwire them to some tamper-resistant logging device that protocols who used them at which time?
Post reply on HN