No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…
There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.
Office of Personnel Management Says Hackers Got Data of Millions of Individuals
21–30 of 86 posts
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#22Clearly, OPM should know, but omg is the state of security poor.
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#23Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#24No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…
The goverment has known how to vet their systems since well before 1989, when I attended a class taught by a security consultant for the DoD. For example, your aged grandfather used to run ethernet through pressurized conduit. If that pressure ever dropped some heavily armed men would turn up. The IP packet header has fields for security classification as well as compartment. If I design warheads and you design rocke…
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#25Before you start shitting on OPM and the like, is this any different than what would happen if a dedicated attacker came after the most valuable data in your company? Clearly, OPM should know, but omg is the state of security poor.
Well, most SF/HN startups data wouldn't get people killed if leaked to the wrong hands, whereas OPM had sensitive information on spies/foreign agents/etc where that is a serious possibility.
The question I'm curious about is what if a Silicon Valley style startup was going to start a company holding ID information for gov workers? Including potentially identities of people whose livelihood depends on secrecy. I'd imagine they would be investing quite heavily in security. But it is plausible even that wouldn't stop nation-state attackers...
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#26Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#27So did anyone get fired?
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#28When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me. edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren't savvy enough to do it themselves, train notaries to do it.
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#29No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…
There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.
Is that really their job? It seems there might be a dozen other agencies responsible, ones less interested in foreign computer networks. Is that DISA's bailiwick? Perhaps NIST? Homeland Security? et cetera
Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals
#30Earlier quoted context omitted.
There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.
> This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well. This is precisely how I feel about this kind of thing. To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. The…
Didn't NSA develop SELinux?
Edit: Heh, lets all avoid the fact that NSA created something insanely useful for the entire world. Nobody likes to think about these things. Hating is so much easier.