Live data from Hacker News

Office of Personnel Management Says Hackers Got Data of Millions of Individuals

nytimes.com

21–30 of 86 posts

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#21
post #3

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

I submitted this a couple days ago... government slowing moving. http://www.logicworks.net/blog/2015/06/government-cloud-publ...

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#23
AWS Govcloud has a very small subset of AWS public features. Enough to get the job done though. Most importantly, it complies to all the FedRAMP, ITAR standards. The Government is just inherently slow in adopting and leveraging AWS's awesome infrastructure.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#24

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

The goverment has known how to vet their systems since well before 1989, when I attended a class taught by a security consultant for the DoD. For example, your aged grandfather used to run ethernet through pressurized conduit. If that pressure ever dropped some heavily armed men would turn up. The IP packet header has fields for security classification as well as compartment. If I design warheads and you design rocke…

[deleted]

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#25
post #22

Before you start shitting on OPM and the like, is this any different than what would happen if a dedicated attacker came after the most valuable data in your company? Clearly, OPM should know, but omg is the state of security poor.

> is this any different than what would happen if a dedicated attacker came after the most valuable data in your company?

Well, most SF/HN startups data wouldn't get people killed if leaked to the wrong hands, whereas OPM had sensitive information on spies/foreign agents/etc where that is a serious possibility.

The question I'm curious about is what if a Silicon Valley style startup was going to start a company holding ID information for gov workers? Including potentially identities of people whose livelihood depends on secrecy. I'd imagine they would be investing quite heavily in security. But it is plausible even that wouldn't stop nation-state attackers...

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#27

So did anyone get fired?

A loyal employee that made a mistake is still a valuable employee. We should focus on prevention and obviation (you can't steal what isn't there) over severe punishments.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#28

When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me. edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren't savvy enough to do it themselves, train notaries to do it.

Presumably, the Chinese and some random hackers now have every piece of relevant data on my life that could ever be used for at least the initial validation of my identity - up to and including my fingerprints. For repeat authentication it's not an issue but parts of this go way beyond SSNs.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#29
post #3

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

> information security, which is their job as well.

Is that really their job? It seems there might be a dozen other agencies responsible, ones less interested in foreign computer networks. Is that DISA's bailiwick? Perhaps NIST? Homeland Security? et cetera

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#30
post #14
post #3

Earlier quoted context omitted.

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

> This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well. This is precisely how I feel about this kind of thing. To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. The…

> To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible.

Didn't NSA develop SELinux?

Edit: Heh, lets all avoid the fact that NSA created something insanely useful for the entire world. Nobody likes to think about these things. Hating is so much easier.

Post reply on HN