Live data from Hacker News

Office of Personnel Management Says Hackers Got Data of Millions of Individuals

nytimes.com

41–50 of 86 posts

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#41

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

I was listening to the Senate hearing on Wednesday where they were asking the FBI director questions about this issue. They were talking about how they need to include the tech community in the conversation about how to best solve the problem of making sure the govt can access encrypted messages, etc. when they're conducting an investigation.

Senator McCain started asking questions about how it was possible to maintain citizens' privacy, but at the same time be able to access private data. Then he made it clear what his feelings were on the subject. Basically, his argument boiled down to "But, ISIS!".

"Is ISIS trying to kill Americans?", he asked the FBI director. The director said "yes". Then he said that b/c of ISIS, the govt has to be able to access keys so they can read encrypted data.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#42

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

US Gov isn't a monolith. Interesting to think about in light of all of the recent articles on HN about the challenges of building out microservices or SOA. Just with human action instead of 10gig fiber, eventual consistency takes a lot longer, if it ever happens.

You're right, it's not. More attack surface area.

Sure, you could in theory have a highly distributed system with multiple keys, but then you can't use it day to day for monitoring communications, which is the whole purpose of the backdoor.

The government may be able to keep the nuclear codes safe in such a fashion, but it wouldn't if ten different government agencies wanted to use them on a daily basis.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#43

Earlier quoted context omitted.

The goverment has known how to vet their systems since well before 1989, when I attended a class taught by a security consultant for the DoD. For example, your aged grandfather used to run ethernet through pressurized conduit. If that pressure ever dropped some heavily armed men would turn up. The IP packet header has fields for security classification as well as compartment. If I design warheads and you design rocke…

Then why does Lockheed have hundreds of people involved with writing and testing avionics software for this aircraft? Why does Northrop Grumman have hundreds of engineers working on avionics hardware? Why does Lockheed Martin have an entire B737 that it heavily customized to test all of this hardware and software? https://en.wikipedia.org/wiki/Lockheed_Martin_CATBird

You have a wooden head.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#44

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

I was listening to the Senate hearing on Wednesday where they were asking the FBI director questions about this issue. They were talking about how they need to include the tech community in the conversation about how to best solve the problem of making sure the govt can access encrypted messages, etc. when they're conducting an investigation. Senator McCain started asking questions about how it was possible to mainta…

Well, "But, ISIS!" is not a real argument, that should be clear.

Backdoors make the situation worse, not better. We'll still have ISIS, we'll be even less secure, and we'll have lost whatever is left of our right to privacy.

Pretty much a lose-lose for everyone involved (except maybe ISIS).

The answer to "But, ISIS!" is not backdoors, it's foreign policy.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#45

I would like to ask a question, but its real. How many of you yes and no, would be willing to go to war knowing that China is making a record of every single interesting person in the United States? Would you physically be willing to go to war over that fact? They are literally profiling us and it seems like the average US citizen gives 2 shits.

Ha, I guess they can join the team of the tech companies and other government agencies around the world doing the same. All of which is going to be increasingly available to the public.

The naked babies uploaded by their parents and parents friends today will be very familiar with the way the world will be, for it will all they would have known on some personal level beyond the grandparents of that time ranting on how good things used to be and wanting to allocate resources for destruction of others for such banal causes, despite the hypocrisies as their robot aids wipe the slobber from their mouths…

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#46

Earlier quoted context omitted.

Then why does Lockheed have hundreds of people involved with writing and testing avionics software for this aircraft? Why does Northrop Grumman have hundreds of engineers working on avionics hardware? Why does Lockheed Martin have an entire B737 that it heavily customized to test all of this hardware and software? https://en.wikipedia.org/wiki/Lockheed_Martin_CATBird

You have a wooden head.

...No need to be insulting and condescending. I understand that you were making a joke. But the fact is, your joke example was poorly chosen.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#47

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

Have the secret backdoor keys for Dual EC DRBG leaked yet? Nuclear launch codes and authenticators?

Analogies are useful but don't get carried away, especially when talking about something as broad as "the government" (as if it were one singular thing). The fact that a BLM federal officer lost his firearm doesn't instantly mean that all of our Tomahawk cruise missiles are next to be stolen.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#48
post #3

No surprises there. I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can't take advantage of this or that cloud service because the service's security isn't vetted. Clearly, the security in the backing systems owned by the government isn't sufficiently vetted either, so they're sacrificing velocity for non-security. I know, it's a flippant attitude.…

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

Network security is not NSA's job. Nor is information security. Communications security is, but only for "national security information" (i.e. classified) and military communications.

Defense against "cyber attack" isn't even NSA's job, and where NSA participates in such endeavors that's on .mil, not .gov

DHS does have responsibility for cyber security on .gov however. But what is DHS supposed to do if OPM decides to throw open the keys to the kingdom to any random "authenticated" contractor handling background checks?

P.S. NSA might somehow have caught this despite everything I mentioned if they were engaged in better "monitoring operations" on other government networks and international communications relays... is that really what you want?

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#49
post #39
post #29

Earlier quoted context omitted.

> information security, which is their job as well. Is that really their job? It seems there might be a dozen other agencies responsible, ones less interested in foreign computer networks. Is that DISA's bailiwick? Perhaps NIST? Homeland Security? et cetera

NSA name is National SECURITY Agency. The agency that deals with intelligence (espionage) is the CIA, and the CIA do have their own cyber espionage systems, NSA not only is not doing their actual job, but they are being redundant.

You have no understanding of how work is dispersed within the U.S. intelligence community.

Which is fine, of course, but why are you trying to speak as if you have authoritative knowledge?

You say that NSA is responsible for cybersecurity within an HR agency because their name has "SECURITY" in it, and as far as I can tell this is meant completely seriously. So should NSA also be responsible for the military defense of the nation since their name has "SECURITY" in it? Should they regulate financial markets because their name has "SECURITY" in it?

In case you wish to know, NSA is responsible for (among other things) 'SIGINT' and 'ELINT'. CIA is responsible for 'HUMINT', 'OSINT', and many other fun things.

Both the NSA and CIA are foreign intelligence agencies, mostly due to historical accident. And of course there's an entirely separate DIA, which also exists mostly due to historical accident, but focuses mainly on military intelligence matters.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#50
post #48
post #3

Earlier quoted context omitted.

There's quite a bit of u.s. government on amazon cloud. Using a cloud service doesn't magically give you better security. This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well.

Network security is not NSA's job. Nor is information security. Communications security is, but only for "national security information" (i.e. classified) and military communications. Defense against "cyber attack" isn't even NSA's job, and where NSA participates in such endeavors that's on .mil, not .gov DHS does have responsibility for cyber security on .gov however. But what is DHS supposed to do if OPM decides to…

> NSA might somehow have caught this despite everything I mentioned if they were engaged in better "monitoring operations" on other government networks and international communications relays... is that really what you want?

I can think of a few million people who might have, yeah.

Post reply on HN