Live data from Hacker News

Office of Personnel Management Says Hackers Got Data of Millions of Individuals

nytimes.com

31–40 of 86 posts

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#31

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

The goverment has known how to vet their systems since well before 1989, when I attended a class taught by a security consultant for the DoD. For example, your aged grandfather used to run ethernet through pressurized conduit. If that pressure ever dropped some heavily armed men would turn up. The IP packet header has fields for security classification as well as compartment. If I design warheads and you design rocke…

Then why does Lockheed have hundreds of people involved with writing and testing avionics software for this aircraft? Why does Northrop Grumman have hundreds of engineers working on avionics hardware? Why does Lockheed Martin have an entire B737 that it heavily customized to test all of this hardware and software? https://en.wikipedia.org/wiki/Lockheed_Martin_CATBird

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#32
What's problematic about this is clearance data usually involves investigators asking questions of references of the applicant: "Do you know anything that could be used to blackmail the applicant into revealing confidential information?" If that sort of info was saved (even for those rejected clearance because they DID find something) and stolen in this hack, that could be rough going for a lot of folks.

https://www.clearancejobs.com/security_clearance_faq.pdf

"What will I be asked during a security clearance interview? During a ESI, the investigator will cover every item on your clearance application and have you confirm the accuracy and completeness of the information. You will be asked about a few matters that are not on your application, such as the handling of protected information, susceptibility to blackmail, and sexual misconduct. You will be asked to provide details regarding any potential security/suitability issues. During a SPIN, the investigator will only cover the security/suitability issue(s) that triggered the SPIN. The purpose of the SPIN is to afford the applicant the opportunity to refute or to confirm and provide details regarding the issue(s)."

More:

http://www.navytimes.com/story/military/2015/06/17/sf-86-sec...

"They got everyone's SF-86," one Pentagon official familiar with the investigation told Military Times.

"The SF-86, a 127-page document, asks government employees to disclose information about family members, friends and past employment as well as details on alcohol and drug use, mental illness, credit ratings, bankruptcies, arrest records and court actions."

..

http://news.clearancejobs.com/2015/06/13/sf-86-stolen-opm-ha...

"The entirety of at least some SF-85 and SF-86 background investigations held on OPM servers were breached, meaning sensitive data including relatives, spouses, and sensitive information on everything from mental health counseling to sexual behavior is now in the hands of the Chinese government."

And if you're really bored:

https://www.opm.gov/Forms/pdf_fill/sf86.pdf

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#34
post #22

Before you start shitting on OPM and the like, is this any different than what would happen if a dedicated attacker came after the most valuable data in your company? Clearly, OPM should know, but omg is the state of security poor.

>is this any different than what would happen if a dedicated attacker came after the most valuable data in your company?

My company didn't compile detailed background information about my "sexual misconduct", or spend money trying to detail the ways in which I might be blackmailed.

So yeah, it's a little different.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#35
post #7
post #3

Earlier quoted context omitted.

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

Yes, there's a whole portion of the Amazon Cloud that's run entirely for government (a family member is a higher-up at AWS Gov), and I have to assume they're also running private clouds with physical security, but I have no idea.

IIRC, GovCloud is available for general purpose usage by private companies, it's just expensive and not as flexible.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#36

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

With a straight face. The cognitive dissonance is strong.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#37

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

US Gov isn't a monolith. Interesting to think about in light of all of the recent articles on HN about the challenges of building out microservices or SOA. Just with human action instead of 10gig fiber, eventual consistency takes a lot longer, if it ever happens.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#38
post #14

Earlier quoted context omitted.

> This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well. This is precisely how I feel about this kind of thing. To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. The…

> To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. Didn't NSA develop SELinux? Edit: Heh, lets all avoid the fact that NSA created something insanely useful for the entire world. Nobody likes to think about these things. Hating is so much easier.

[deleted]

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#39
post #29
post #3

Earlier quoted context omitted.

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

> information security, which is their job as well. Is that really their job? It seems there might be a dozen other agencies responsible, ones less interested in foreign computer networks. Is that DISA's bailiwick? Perhaps NIST? Homeland Security? et cetera

NSA name is National SECURITY Agency.

The agency that deals with intelligence (espionage) is the CIA, and the CIA do have their own cyber espionage systems, NSA not only is not doing their actual job, but they are being redundant.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#40
I would like to ask a question, but its real. How many of you yes and no, would be willing to go to war knowing that China is making a record of every single interesting person in the United States? Would you physically be willing to go to war over that fact? They are literally profiling us and it seems like the average US citizen gives 2 shits.
Post reply on HN