Live data from Hacker News

CIA pulled officers from Beijing after breach of federal personnel records

washingtonpost.com

11–20 of 35 posts

Re: CIA pulled officers from Beijing after breach of federal personnel records

#11

"We, too, practice cyberespionage and . . . we’re not bad at it" - James Clapper Ironic, for the intelligence leader of a country that had their defensive systems completely penetrated (with the federal personnel records), and their offensive systems fully outed in the most humiliating way possible (by Snowden) It seems to me that yeah... you kind are bad at it. At the very least, a little less self-certainty might b…

Being bad at defense doesn't necessarily imply being bad at offense. Security is hard because you have to win 100% of the time. Being good at cyberespionage means getting a win now and then. I'm not saying the US is good at it, just that neither the OMB breach nor the Snowden incident bear on that. And a lot of the info released by Snowden indicate they were pretty good at it (at least targeting their own citizens) or those disclosures wouldn't be such a big deal.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#12
post #7

Earlier quoted context omitted.

That smells fishy, as it would be something exploited immediately by any anti-submarine vessel.

Anti-submarine vessels have to do one thing really well to have any chances; be quiet. Fishing vessels can happily plough the ocean wave pinging to their heart's content. An anti-submarine vessel that did that quickly becomes a target, or if the submarine is feeling generous, something to go around - thanks for telling us where you are. There's a time and a place for active sonar in finding and killing submarines, bu…

Plus you have to be right above the submarine. The ocean is vast.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#13
post #7

Earlier quoted context omitted.

That smells fishy, as it would be something exploited immediately by any anti-submarine vessel.

Anti-submarine vessels have to do one thing really well to have any chances; be quiet. Fishing vessels can happily plough the ocean wave pinging to their heart's content. An anti-submarine vessel that did that quickly becomes a target, or if the submarine is feeling generous, something to go around - thanks for telling us where you are. There's a time and a place for active sonar in finding and killing submarines, bu…

Sure, but I just don't think a sub would show up as a black, signal-free shape on a fishing boat's sonar, except under contrived conditions.

Though I may be judging it wrong based on only having used crappy sonar equipment.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#14
post #7

Earlier quoted context omitted.

That smells fishy, as it would be something exploited immediately by any anti-submarine vessel.

Anti-submarine vessels have to do one thing really well to have any chances; be quiet. Fishing vessels can happily plough the ocean wave pinging to their heart's content. An anti-submarine vessel that did that quickly becomes a target, or if the submarine is feeling generous, something to go around - thanks for telling us where you are. There's a time and a place for active sonar in finding and killing submarines, bu…

Then part of your navy is hacked fishing boat sonar kits and an uplink to the anti-submarine vessel. :)

Re: CIA pulled officers from Beijing after breach of federal personnel records

#15
When Chelsea Manning leaked the documents, noone was put in danger.

When Snowden leaked the documents, no one was endangered.

This breach, and lots of people are endangered.

But are you getting calls for criminal investigation? Are heads rolling (other than the head of OPM, who was hated anyways)?

Re: CIA pulled officers from Beijing after breach of federal personnel records

#16

Earlier quoted context omitted.

Anti-submarine vessels have to do one thing really well to have any chances; be quiet. Fishing vessels can happily plough the ocean wave pinging to their heart's content. An anti-submarine vessel that did that quickly becomes a target, or if the submarine is feeling generous, something to go around - thanks for telling us where you are. There's a time and a place for active sonar in finding and killing submarines, bu…

Then part of your navy is hacked fishing boat sonar kits and an uplink to the anti-submarine vessel. :)

The Soviets used to do that with their "fishing fleet". We would send submarines out the Strait of Juan De Fuca, it would drop down to 1,000 feet, and the "fishing boats" would lose it every time. It still didn't work. I don't know of any reliable way to find a submarine, even today.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#17

"We, too, practice cyberespionage and . . . we’re not bad at it" - James Clapper Ironic, for the intelligence leader of a country that had their defensive systems completely penetrated (with the federal personnel records), and their offensive systems fully outed in the most humiliating way possible (by Snowden) It seems to me that yeah... you kind are bad at it. At the very least, a little less self-certainty might b…

I imagine Clapper was more focusing on offensive capabilities here. Not to mention, Clapper's quote is taken out of context, he wasn't bragging, he was arguing against a tit-for-tat retaliation.

Defensive is interesting considering how many federal departments there are and how they're all pretty autonomous in regards to IT. Going after employment records was especially devious as they aren't classified, so whatever requirements OPM had to follow weren't very stringent.

The real issue here, and something that affects the private sector as well is why are we not treating all IT data as classified? Why all the half measures? I think we're still in the early stages of digitization and automation and have to learn security lessons the hard way.

Also in autocratic states where information is tightly controlled, hacks like this don't make the news. We have no idea what the NSA is actually doing in these countries outside of Snowden, whose data is mostly (all?) domestic programs. And the stuff we do know about like Stuxnet, only come out because certain people wanted to turn it into a political football.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#18
post #11

"We, too, practice cyberespionage and . . . we’re not bad at it" - James Clapper Ironic, for the intelligence leader of a country that had their defensive systems completely penetrated (with the federal personnel records), and their offensive systems fully outed in the most humiliating way possible (by Snowden) It seems to me that yeah... you kind are bad at it. At the very least, a little less self-certainty might b…

Being bad at defense doesn't necessarily imply being bad at offense. Security is hard because you have to win 100% of the time. Being good at cyberespionage means getting a win now and then. I'm not saying the US is good at it, just that neither the OMB breach nor the Snowden incident bear on that. And a lot of the info released by Snowden indicate they were pretty good at it (at least targeting their own citizens) o…

Being good at cyberespionage means "not getting caught"

Re: CIA pulled officers from Beijing after breach of federal personnel records

#19

"We, too, practice cyberespionage and . . . we’re not bad at it" - James Clapper Ironic, for the intelligence leader of a country that had their defensive systems completely penetrated (with the federal personnel records), and their offensive systems fully outed in the most humiliating way possible (by Snowden) It seems to me that yeah... you kind are bad at it. At the very least, a little less self-certainty might b…

Yesterday I was wondering why encryption is not the default. Government shmovernment, but I remember looking up how to password-protect directories in Windows 95 (sorry to everyone else on HN who got started on an Apple II). It wasn't until college that I figured out that you can easily navigate the directory structure in another machine by just plugging in hard drives to a machine running a different OS. I look at people's nude pics of themselves by PC/phone repair people, and I'm convinced that there is no good reason why data should be stored in plain text. But now search comes into the picture, and it's expected and we're probably stuck with it for my lifetime

Re: CIA pulled officers from Beijing after breach of federal personnel records

#20

When Chelsea Manning leaked the documents, noone was put in danger. When Snowden leaked the documents, no one was endangered. This breach, and lots of people are endangered. But are you getting calls for criminal investigation? Are heads rolling (other than the head of OPM, who was hated anyways)?

Isn't that what this article is about? We are pretty certain that this was an act of espionage by another nation state. Criminal investigations are not how you respond in those cases (unless we found the agent on our soil, which AFAIK we did not).

What is curious is that we aren't sure what the norms are for how to respond to cyber espionage, unlike with in person espionage which had a whole set of responses we could fall back on.

Post reply on HN