Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

121–130 of 131 posts

Re: The OPM Data Breach [pdf]

#121
post #74

One of the most frustrating things about this whole fiasco is that the OPM breach finally became public in the summer of 2015, but I and many other victims weren't officially notified (or offered our measly couple years of identity protection) until December or later. At the time, I shared some of my thoughts on the breach here (some of the info may be out of date in light of the new report; I was piecing stuff toget…

I still never received any notice about it. Was employed by DoD in late 00's, so am fairly certain my info was in the batch.

You'd remember filling out an SF-86. But yes, I was definitely in the breach, yet I have not been notified.

Re: The OPM Data Breach [pdf]

#122
post #63

Earlier quoted context omitted.

Employee of 18F here, speaking unofficially. We care a lot about security - both from the technical side and from the policy compliance side!

How was recruitment?. Someone I know tried to get a got job there, got stuck in the queue forever. Was told to wait months. So eventually gave up and took another job.

Hiring in gov't is hard. We've had to pause and refactor our hiring process several times. Long delays are just as frustrating to us, trust me. It's getting better all the time though.

Re: The OPM Data Breach [pdf]

#123
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

The letter they sent me claimed that there is currently no way to create fake fingerprints, so there's nothing to be worried about, 2 years of identity theft monitoring is good enough.

That was a blatant lie tho.

Re: The OPM Data Breach [pdf]

#124
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

The letter they sent me claimed that there is currently no way to create fake fingerprints, so there's nothing to be worried about, 2 years of identity theft monitoring is good enough.

I wasn't sure if they were lying or merely incompetent when they said that. Mythbusters has an episode of them defeating fingerprint locks using a print lifted from a glass, and the technique they used was anything but sophisticated.

Re: The OPM Data Breach [pdf]

#125
post #65

Earlier quoted context omitted.

> It seems NSA has spent all its budget on cool hacking tools and programs From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network. I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can p…

> The NSA can't make another federal agency improve its computer security. Maybe not directly. But the NSA could play a much more positive role in information security generally by moving out of the shadows and making more of its research public. The expertise that the NSA has acquired in securing information needs to be widely disseminated to work its way into engineering curricula and praxis, and that won't happen…

Yes, maybe they should release a kernel security scheme for Linux that incorporates some lessons learned. Maybe they could call it SELinux.

Re: The OPM Data Breach [pdf]

#126
post #36

Earlier quoted context omitted.

Because when I think of technical sophistication, I think of DHS.

Exactly, they simply have never had the institutional knowledge required to secure government networks.

Their hostile attitude towards computer security pay incentives practically guarantees nobody will jump ship from IOC or TAO. This problem will likely only be resolved by a big media stink.

Re: The OPM Data Breach [pdf]

#127

Earlier quoted context omitted.

I believe Defense had their own, parallel system, so it may not be a given that you're in the leak.

Cleared employees are in the OPM data leak.

Not all of them. For example, the reported risk to CIA agents in US embassies in China was that they would suspiciously not be in the leaked data like actual State dept staff would be.

Apparently the Defense investigators (DSS) merged into OPM in 2004- https://en.wikipedia.org/wiki/Defense_Security_Service

Re: The OPM Data Breach [pdf]

#128
post #65

Earlier quoted context omitted.

> The NSA can't make another federal agency improve its computer security. Maybe not directly. But the NSA could play a much more positive role in information security generally by moving out of the shadows and making more of its research public. The expertise that the NSA has acquired in securing information needs to be widely disseminated to work its way into engineering curricula and praxis, and that won't happen…

Yes, maybe they should release a kernel security scheme for Linux that incorporates some lessons learned. Maybe they could call it SELinux.

I mentioned SELinux in a previous comment along the same vein.

Re: The OPM Data Breach [pdf]

#130

Earlier quoted context omitted.

> It probably won't happen in this case because the "other" party just wants this issue to go away. Arguing in public would only draw attention. From tptacek's comment, made ~5 minutes before yours: http://democrats.oversight.house.gov/news/press-releases/cum... Why would they want to avoid discussing this?

That looks like a different thing? I.e. a "memo" prepared by "staff"? Nevertheless I'm sorry to have made a comment that seemed partisan. The Democrats and Republicans can both jump in a lake for all I care.

> Nevertheless I'm sorry to have made a comment that seemed partisan.

I'm interested in figuring out what you mean by your remark. You're saying nobody wanted to talk about it, but it seems for opposite is the case. What prompted your original remark?

Post reply on HN