Live data from Hacker News

CIA pulled officers from Beijing after breach of federal personnel records

washingtonpost.com

31–35 of 35 posts

Re: CIA pulled officers from Beijing after breach of federal personnel records

#31
post #26

Earlier quoted context omitted.

Criminal negligence? Certainly, negligence that should incur public disgrace. Also arguably demonstrating one of the points made by the whistleblowers: You can't trust the government to properly manage all the information they collecting.

This isn't negligence. Instead of trying to protect data and networks the US government has made "cyber crime" a military issue. They've been doing it deliberately and publicly, for over a decade. Domestically they followed the same plan: companies get protection (financial, legal, image,) discouraging them from taking security seriously, and individuals get the CFAA which has a similar effect. They want data and net…

Purposeful negligence?

It should be prosecuted, in the court of public opinion if no one will bring it to a judicial court.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#32
post #10

"We, too, practice cyberespionage and . . . we’re not bad at it" - James Clapper Ironic, for the intelligence leader of a country that had their defensive systems completely penetrated (with the federal personnel records), and their offensive systems fully outed in the most humiliating way possible (by Snowden) It seems to me that yeah... you kind are bad at it. At the very least, a little less self-certainty might b…

For what it's worth, the CIA is the only federal agency that keeps their own employee records. Everyone else goes through OPM. They (rightfully) assumed that OPM couldn't keep secrets and that's where we find ourselves today. It's probable that these records are printed, locked in a vault. James Clapper, the DNI, heads 16 intelligence agencies under him, one of which (CIA) didn't have their records stolen. Though the…

I don't think it's possible to conclude that the CIA employee records were not hacked in separate attempts - only that there is no public record of a hack. But that's poor proof, if there were CIA records were separately stolen, I assume there would be a strong justification made to hide that outcome.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#33
post #11

Earlier quoted context omitted.

Being bad at defense doesn't necessarily imply being bad at offense. Security is hard because you have to win 100% of the time. Being good at cyberespionage means getting a win now and then. I'm not saying the US is good at it, just that neither the OMB breach nor the Snowden incident bear on that. And a lot of the info released by Snowden indicate they were pretty good at it (at least targeting their own citizens) o…

Being good at cyberespionage means "not getting caught"

I've never been caught. Does that make me good at cyberespionage? I think there's more to it than that. You might argue necessary but not sufficient, but I'd even disagree with that. The fact that the NSA was outed by Snowden has not made everything they're doing ineffective or we wouldn't be so worried about it.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#34
post #33

Earlier quoted context omitted.

Being good at cyberespionage means "not getting caught"

I've never been caught. Does that make me good at cyberespionage? I think there's more to it than that. You might argue necessary but not sufficient, but I'd even disagree with that. The fact that the NSA was outed by Snowden has not made everything they're doing ineffective or we wouldn't be so worried about it.

II agree but was highlighting the fact that being to blatant ala the OPM hack can backfire.

Re: CIA pulled officers from Beijing after breach of federal personnel records

#35

Earlier quoted context omitted.

Then part of your navy is hacked fishing boat sonar kits and an uplink to the anti-submarine vessel. :)

Which, if the word of it ever got out, would paint fishing boats as a valid target in combat operations.

On an interesting related note, during the recent Russian occupation of parts of Ukraine, a helpful app was created and released by "Russia" [1] that would allow pro-Russian civilians in the region to act as reconnaissance for the Russian and pro-Russian forces. Very simple; if you see some Ukrainian military, push the matching picture on the app. Your location and chosen picture are uploaded, and whoever is sitting at the other end sees all the results.

Bingo; you've turned the civil population into military reconnaissance. Are they now a valid target? They certainly don't seem to be just plain civilians anymore, but they're not lawful combatants either.

As it turned out, I am led to believe that the app wasn't a great success, but it's still a disturbing trend.

[1] I say "Russia" because I can't dig out more detail right now. Obviously company X working with agency Y or some other such.

Post reply on HN