Live data from Hacker News

Office of Personnel Management Says Hackers Got Data of Millions of Individuals

nytimes.com

71–80 of 86 posts

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#71
post #34
post #22

Before you start shitting on OPM and the like, is this any different than what would happen if a dedicated attacker came after the most valuable data in your company? Clearly, OPM should know, but omg is the state of security poor.

>is this any different than what would happen if a dedicated attacker came after the most valuable data in your company? My company didn't compile detailed background information about my "sexual misconduct", or spend money trying to detail the ways in which I might be blackmailed. So yeah, it's a little different.

And not only your information - that 21.5 million figure given for the clearance database is 1 in 15 people in the entire United States population.

What I'd like to know is how this information failed to warrant even the level of protection mandated for medical records - according to at least one major news source, the data wasn't even encrypted. The standard criteria in the US for "top secret" classification is described as material having the potential to cause "exceptionally grave damage" to the national security of the nation. A database of information pertaining to a process designed to collect all information potentially usable for coercion (blackmail, social ties, etc) of all the individuals in the most sensitive positions of the government, should have been classified and protected at the Top Secret level.

Frankly, the outrage I've seen so far is not nearly enough for the scale of the irresponsibility here. I firmly believe the director and CIO of the OPM should not only be removed from office, they should be subject to criminal charges for mishandling information that clearly _should_ have been classified.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#72

Earlier quoted context omitted.

I admit I was a little saddened to be insulted by someone whose work I admire. Your friend definitely has a point. People are dying because of software bugs. And process bugs. And outdated hardware. I agree with you that we have lost our expertise. I think the defense industry in general has a demographics problem. There's a lot of old guys who are about to retire. A lot of young, inexperienced people. And not enough…

I offer my heartfelt and humble apology for insulting you. That was not my intention though I do understand why you took it that way. I intended to insult the United States Congress.

A well-met insult. The government is putting itself into a corner with their current policies on hiring criteria. If you have an idea on how to change that, I'd support you however I could. If it matters, I really admire your apology, not many people have the "balls/vagina/both/neither" to admit, at the very least, a mis-interpretation of a comment.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#73

The worst of this is that I had just taken a government job when the 4.2 million person breach was claimed to have happened. I had very serious concerns about giving out so much (and it was an absolute ton, more than any other employer I've ever worked for) information. I had thought about not taking the job but like many Americans I really didn't have much of a choice. The choice was homelessness and perhaps even go…

> Why does the government need so much data on its employees; that's what should be asked! I don't know if you had to get a clearance or not, and if you did, what kind. But assuming that you did get a clearance, they need all of this information because they need to build up a psychological, emotional, familial, and financial profile of you to determine how much of a risk you are. At least, that is what the governmen…

[deleted]

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#74

Earlier quoted context omitted.

I admit I was a little saddened to be insulted by someone whose work I admire. Your friend definitely has a point. People are dying because of software bugs. And process bugs. And outdated hardware. I agree with you that we have lost our expertise. I think the defense industry in general has a demographics problem. There's a lot of old guys who are about to retire. A lot of young, inexperienced people. And not enough…

I offer my heartfelt and humble apology for insulting you. That was not my intention though I do understand why you took it that way. I intended to insult the United States Congress.

Thank you for your apology. I see how I misunderstood.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#75

Earlier quoted context omitted.

I admit I was a little saddened to be insulted by someone whose work I admire. Your friend definitely has a point. People are dying because of software bugs. And process bugs. And outdated hardware. I agree with you that we have lost our expertise. I think the defense industry in general has a demographics problem. There's a lot of old guys who are about to retire. A lot of young, inexperienced people. And not enough…

Is there some way I could do military computing without a clearance? I applied to the US Air Force Cyber Command as well as all manner of military computer security jobs. I received but one response, that my application to be an encryption machine trainer was declined. http://www.warplife.com/mdc/resume/

I am not an absolute authority on this. But my decade of experience in the defense industry tells me "probably not".

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#76

Earlier quoted context omitted.

I offer my heartfelt and humble apology for insulting you. That was not my intention though I do understand why you took it that way. I intended to insult the United States Congress.

A well-met insult. The government is putting itself into a corner with their current policies on hiring criteria. If you have an idea on how to change that, I'd support you however I could. If it matters, I really admire your apology, not many people have the "balls/vagina/both/neither" to admit, at the very least, a mis-interpretation of a comment.

Their hiring criteria are ridiculous. Every job I have ever applied for through USAJobs and other government systems (NASA STARS, US Navy CHART, and several others I cannot remember the names of at the moment) has resulted in a rejected application.

NASA's system told me that I was not qualified to work on rocket telemetry systems, even though I was then working as a telemetry engineer for the prime contractor on the NSROC II sounding rocket contract.

The Navy's system told me that I was not qualified to work on aircraft instrumentation and telemetry systems for NAVAIR, even though one of my past jobs was as an aircraft instrumentation and telemetry systems engineer for NAVAIR.

My wife has similar anecdotal experiences. She applied for a job with the federal government requiring experience as a K-12 biology teacher. She was rejected even though she worked as a high school biology teacher for almost a decade and won several national awards and two educational fellowships.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#77
post #14

Earlier quoted context omitted.

> This is more an indication of the NSA focusing too strongly on offensive/monitoring operations and not on information security, which is their job as well. This is precisely how I feel about this kind of thing. To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. The…

> To my mind, the NSA should be working to make the security technologies used by American individuals, American companies, and the American government as strong and as free of vulnerabilities as possible. Didn't NSA develop SELinux? Edit: Heh, lets all avoid the fact that NSA created something insanely useful for the entire world. Nobody likes to think about these things. Hating is so much easier.

Yes, and for a time that was great. That and more is what they should be doing!

Instead, they have thrown away any trust and respect they had earned. Now they are feared.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#78

And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.

US Gov isn't a monolith. Interesting to think about in light of all of the recent articles on HN about the challenges of building out microservices or SOA. Just with human action instead of 10gig fiber, eventual consistency takes a lot longer, if it ever happens.

Security is a hard thing for large organizations. Much of the time they simply don't have the expertise they need to know what their vulnerabilities are.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#79

Earlier quoted context omitted.

Is there some way I could do military computing without a clearance? I applied to the US Air Force Cyber Command as well as all manner of military computer security jobs. I received but one response, that my application to be an encryption machine trainer was declined. http://www.warplife.com/mdc/resume/

I am not an absolute authority on this. But my decade of experience in the defense industry tells me "probably not".

Then I expect the best contribution I could make is to continue writing.

I was an unclassified subcontractor once. The primary contractor selected me for my expertise with "the part".

What he should have done was to ask me to select the vendor. The part I was asked to write code for had quite a serious design flaw.

Re: Office of Personnel Management Says Hackers Got Data of Millions of Individuals

#80
post #52

Earlier quoted context omitted.

A loyal employee that made a mistake is still a valuable employee. We should focus on prevention and obviation (you can't steal what isn't there) over severe punishments.

This wasn't just a single employee that made a single mistake. The Navy is happy to fire commanding officers for calling out sailors who show up late for physical training because it's embarrassing to the sailor, and yet it seems like we can't get anything close to that kind of accountability elsewhere. It's not so much that Archuleta 'let this happen' (since I guarantee they would be hacked anyways), but the defensi…

Archuleta is a party hack who got what was supposed to be a patronage position. There are thousands of them the parties use to reward, you know, county canvassers after a successful campaign.

She should definitely be fired, not so much for what she allowed to happen per se, but because she doesn't have anything like the background she needs to do the job with which she's been entrusted.

Post reply on HN