Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

51–60 of 131 posts

Re: The OPM Data Breach [pdf]

#51
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

>It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think th…

Exactly this. The US government thinks about computer security as a kind of war - cyberwar - and for better or for worse it has adapted the mindset that "security by demonstrated capability to drop scary bombs with brutal precision and efficiency" is more realistic than "security by making every building bomb proof."

Geopolitics these days isn't about impenetrable borders, it's about deterrence by ability to project force. They are looking at IT security the same way.

Re: The OPM Data Breach [pdf]

#53
One of the most frustrating things about this whole fiasco is that the OPM breach finally became public in the summer of 2015, but I and many other victims weren't officially notified (or offered our measly couple years of identity protection) until December or later. At the time, I shared some of my thoughts on the breach here (some of the info may be out of date in light of the new report; I was piecing stuff together as best as I could): https://forrestbrazeal.com/2015/12/08/welp-i-was-an-opm-hack...

I was also annoyed that so much of the political posturing around the breach centered on OPM systems' lack of encryption. I haven't read all of this report, but it's nice to see the summary focusing on the lack of 2FA, a security practice that would actually have helped stop an internal infiltrator.

Re: The OPM Data Breach [pdf]

#55
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

NIST sets the standards (FIPS).

Most programs for security guidelines seem to be descendants and ongoing implementations of HSPD-12.

I believe the Office of the Inspector General would be in charge of auditing in some cases, but it's usually up to each individual agency.

Re: The OPM Data Breach [pdf]

#57
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

>It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think th…

As other people touch on, a good offense is something the NSA can actually do themselves. They don't have the authority to be a good defense. They had - and have - no ability to compel OPM to get their shit together.

In terms of defense, they've got a severe case of Congress-induces toothlessness.

Re: The OPM Data Breach [pdf]

#58
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

In keeping with industry best practice, I require staff to sandpaper off their fingerprints and regrow them every 90 days.

For "security".

Re: The OPM Data Breach [pdf]

#59
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

241 pages and not one mention of NIST or FIPS.

There's actual several mentions of NIST, ATOs, and FISMA, all of which implicitly cover FIPS by reference.

#acronymheatdeath

Re: The OPM Data Breach [pdf]

#60

Earlier quoted context omitted.

Yes the minority members of a committee can issue their own reports, e.g. [0]. It probably won't happen in this case because the "other" party just wants this issue to go away. Arguing in public would only draw attention. [0] http://democrats-benghazi.house.gov/sites/democrats.benghazi...

> It probably won't happen in this case because the "other" party just wants this issue to go away. Arguing in public would only draw attention. From tptacek's comment, made ~5 minutes before yours: http://democrats.oversight.house.gov/news/press-releases/cum... Why would they want to avoid discussing this?

That looks like a different thing? I.e. a "memo" prepared by "staff"?

Nevertheless I'm sorry to have made a comment that seemed partisan. The Democrats and Republicans can both jump in a lake for all I care.

Post reply on HN