Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

21–30 of 131 posts

Re: The OPM Data Breach [pdf]

#21
post #17
post #12

Earlier quoted context omitted.

Let's be fair: while the source may well be partisan, it is also a technical document. Referring to it simply as a partisan political document doesn't acknowledge its full contents or its value to a technical community.

It is not a technical document. It is a document that contains technical details. For instance: it contains a formal set of "findings", as in the "findings" of law and fact in a trial. Here's one of the first findings: FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities. That's not technical language. It's not even formal language. O…

I won't argue with you the difference between a technical document and a document with technical details. You're welcome to that definitional win.

There are interesting technical details in this document about the exact methods, vectors, files, timelines, etc used in both offense and defense of this incident. They would be of interest and value to many in this community regardless of the partisan agenda of the committee.

Re: The OPM Data Breach [pdf]

#22
post #21
post #17

Earlier quoted context omitted.

It is not a technical document. It is a document that contains technical details. For instance: it contains a formal set of "findings", as in the "findings" of law and fact in a trial. Here's one of the first findings: FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities. That's not technical language. It's not even formal language. O…

I won't argue with you the difference between a technical document and a document with technical details. You're welcome to that definitional win. There are interesting technical details in this document about the exact methods, vectors, files, timelines, etc used in both offense and defense of this incident. They would be of interest and value to many in this community regardless of the partisan agenda of the commit…

It is not my argument that this is an uninteresting or uninformative document.

Re: The OPM Data Breach [pdf]

#23
post #19

Earlier quoted context omitted.

Is there something in this document that you can point to as being inaccurate or obviously exaggerated?

I don't know. That's not a hurdle my argument needs to clear.

I disagree. If you're going to say "But the authors of this document had a job to do: portray administration appointees in the worst light possible." then you need to at least show some examples of that.

You're not making an argument. You're trying to pass an opinion as a fact. You need to back up statements like that.

Re: The OPM Data Breach [pdf]

#24
post #10

This isn't the "official postmortem". It's the official report of the GOP-led House Oversight and Government Reform Committee. It's a partisan political document. A better title: Republican House Oversight Report On OPM Data Breach.

In some places its typical for such legislative committees to also issue minority/dissenting reports - does that happen in the US?

Re: The OPM Data Breach [pdf]

#25
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

> It seems NSA has spent all its budget on cool hacking tools and programs

From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network.

I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can perform audits: which it appears to have done; OPM had the lowest security posture of any agency.

Should the NSA have prevented the exfiltration? How would that work? Do you want the NSA to have the authority to cut network connections occurring in the U.S. internet? Should the NSA have authority over civilian government agencies? What about hacking and wiping the intruders' endpoints? Sounds like an act of war to me, if those endpoints are on Chinese soil.

I doubt the vast majority of HN'ers want an increase in NSA's authority or scope.

Re: The OPM Data Breach [pdf]

#26
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

One of NSA's primary missions is information assurance. I'm sure they have blue teams. But their mandate is pretty limited in regards to what they can do with civilian infrastructure.

Technically DHS should do it. I don't see DHS having the expertise and brainpower for it.

Re: The OPM Data Breach [pdf]

#27
post #19

Earlier quoted context omitted.

I don't know. That's not a hurdle my argument needs to clear.

I disagree. If you're going to say "But the authors of this document had a job to do: portray administration appointees in the worst light possible." then you need to at least show some examples of that. You're not making an argument. You're trying to pass an opinion as a fact. You need to back up statements like that.

I simply disagree with you.

Re: The OPM Data Breach [pdf]

#29
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

[deleted]

Re: The OPM Data Breach [pdf]

#30
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

> It seems NSA has spent all its budget on cool hacking tools and programs From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network. I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can p…

> The NSA can't make another federal agency improve its computer security.

Maybe it should have the power to intervene and stop it? This is still the federal government (it is not about walking into Facebook and shutting it down). I think it is the only agency with the brainpower to do it. It should be been trying to hack it and test the system periodically to identify flaws in it. Then mandate changes.

> Do you want the NSA to have the authority to cut network connections occurring in the U.S. internet?

To the federal agencies. Cyber defence doesn't work with current bloated beaurocracy. Nobody seems to be in charge.

> I doubt the vast majority of HN'ers want an increase in NSA's authority or scope.

I don't know. I would rather them spend more time defending, wouldn't mind expanding their power and diverting more budget towards that.

Post reply on HN