Live data from Hacker News

Office of Personnel Management Says Hackers Got Data of Millions of Individuals

nytimes.com

11–20 of 86 posts

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#11

The worst of this is that I had just taken a government job when the 4.2 million person breach was claimed to have happened. I had very serious concerns about giving out so much (and it was an absolute ton, more than any other employer I've ever worked for) information. I had thought about not taking the job but like many Americans I really didn't have much of a choice. The choice was homelessness and perhaps even go…

> Why does the government need so much data on its employees; that's what should be asked!

I don't know if you had to get a clearance or not, and if you did, what kind. But assuming that you did get a clearance, they need all of this information because they need to build up a psychological, emotional, familial, and financial profile of you to determine how much of a risk you are. At least, that is what the government will tell you is the reason why they investigate you so much.

You can request a copy of the investigation the US government performs on you (whether you are a government employee or a contractor with a clearance) through a form you can find on the website of the Office of Personnel Management. Although, hilariously, they will censor some of the information about you that they find. That is a window into what their thinking is, because you see who they talk to, what questions they ask, and how people responded.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#12
When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me.

edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren't savvy enough to do it themselves, train notaries to do it.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#13

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

The goverment has known how to vet their systems since well before 1989, when I attended a class taught by a security consultant for the DoD.

For example, your aged grandfather used to run ethernet through pressurized conduit. If that pressure ever dropped some heavily armed men would turn up.

The IP packet header has fields for security classification as well as compartment. If I design warheads and you design rocket engines, our computers are in different compartments so the router between us will drop packets if you and I attempt to discuss our work. However I could invite you to lunch.

What Bradley Manning did was simply not possible. Or rather it would not have been without the Congressional COTS mandate: Common Off-The-Shelf Computers. Rather than design special hardware or write special software for military computing the avionics for the F-35 Joint Strike Fighter were purchased online from Alibaba.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#14
post #3

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

> This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

This is precisely how I feel about this kind of thing.

To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. The necessary degree of transparency would, of course, mean any such improvements would be available to anyone in other countries, but I think that situation is far superior to our current climate where we suspect (and not as wild conspiracy theory) that our vulnerabilities were as likely created by the NSA as not.

Many American individuals—and presumably companies—consider the NSA an adversary simply because these individuals value their privacy and the NSA has shown only hostility toward Americans concerning their privacy. In some alternate universe, my own opinion of the NSA could have been positive had they been an agency focused on decreasing the risk of individuals' privacy being compromised.

At the very least, that they are not (apparently) presently sufficiently charged with assisting other branches of the government maintain security is a misallocation of talent.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#16

When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me. edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren't savvy enough to do it themselves, train notaries to do it.

You may be interested to see Estonia's advancement in this direction: http://estonia.eu/about-estonia/economy-a-it/e-estonia.html

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#18
post #16

When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me. edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren't savvy enough to do it themselves, train notaries to do it.

You may be interested to see Estonia's advancement in this direction: http://estonia.eu/about-estonia/economy-a-it/e-estonia.html

I'm immensely jealous of Estonia's ability to rebuild their infrastructure from the ground up. I know we'll never have that chance in the US, but if we did, we could build something truly incredible, especially now that government is slowly starting to understand the benefits of the "lean startup" model (I say that loosely).

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#19

When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me. edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren't savvy enough to do it themselves, train notaries to do it.

The issue here is not that SSNs are used for identity (which is what they SHOULD be used for), but rather that they are used for authentication, which is retarded beyond belief. https://technet.microsoft.com/en-us/library/cc512578.aspx

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#20

The worst of this is that I had just taken a government job when the 4.2 million person breach was claimed to have happened. I had very serious concerns about giving out so much (and it was an absolute ton, more than any other employer I've ever worked for) information. I had thought about not taking the job but like many Americans I really didn't have much of a choice. The choice was homelessness and perhaps even go…

Yes, that's the worse part of this.
Post reply on HN