If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
The OPM Data Breach [pdf]
41–50 of 131 posts
Re: The OPM Data Breach [pdf]
#42If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
FWIW: Someone I know whom worked for DIA as a sysadmin about 10-15 years ago recalled multiple instances of TS/SCI folks being fired for surfing for porn over monitored networks... career- & clearance-ending. Maybe that's the only culturally-unacceptable sin in that community, apart from making the org/folks look bad?
Re: The OPM Data Breach [pdf]
#43sure would be nice to have something better than a raster image of pages 2-231
Re: The OPM Data Breach [pdf]
#44Earlier quoted context omitted.
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
This kind of stupidity is why I think I can never take a gov't job. I don't think I'd last a week. Sorry you had to put up with it.
Re: The OPM Data Breach [pdf]
#45Earlier quoted context omitted.
After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!
This kind of stupidity is why I think I can never take a gov't job. I don't think I'd last a week. Sorry you had to put up with it.
Re: The OPM Data Breach [pdf]
#46If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…
Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think that the best defense is a good offense, and maybe they have good reasons for that but from the outside it seems like they're just overly affected with wanting to feel 'l33t'.
https://medium.com/@bruces/the-ecuadorian-library-a1ebd2b4a0...
Re: The OPM Data Breach [pdf]
#47Earlier quoted context omitted.
I disagree. If you're going to say "But the authors of this document had a job to do: portray administration appointees in the worst light possible." then you need to at least show some examples of that. You're not making an argument. You're trying to pass an opinion as a fact. You need to back up statements like that.
I simply disagree with you.
If you're disagreeing that you "need" to provide proof because your claim is substantiated intrinsically, then you're being pompous and lazy.
Re: The OPM Data Breach [pdf]
#48Earlier quoted context omitted.
This kind of stupidity is why I think I can never take a gov't job. I don't think I'd last a week. Sorry you had to put up with it.
What about things the US Digital Service or 18F? The image they present is that those teams are different and outside the standard government bureaucracy. I'm skeptical.
Re: The OPM Data Breach [pdf]
#49Re: The OPM Data Breach [pdf]
#50Earlier quoted context omitted.
In some places its typical for such legislative committees to also issue minority/dissenting reports - does that happen in the US?
Yes the minority members of a committee can issue their own reports, e.g. [0]. It probably won't happen in this case because the "other" party just wants this issue to go away. Arguing in public would only draw attention. [0] http://democrats-benghazi.house.gov/sites/democrats.benghazi...
From tptacek's comment, made ~5 minutes before yours:
http://democrats.oversight.house.gov/news/press-releases/cum...
Why would they want to avoid discussing this?