The OPM Data Breach [pdf]
oversight.house.gov
oversight.house.gov
I was also annoyed that so much of the political posturing around the breach centered on OPM systems' lack of encryption. I haven't read all of this report, but it's nice to see the summary focusing on the lack of 2FA, a security practice that would actually have helped stop an internal infiltrator.
The thing that burns me though, is that the credit protection is for a limited time. The severity of this breach and they can't give us a lifetime of protection?!?
If you check out http://money.visualcapitalist.com/all-of-the-worlds-money-an... you can see the derivatives and debt are a huge chunk of the not-actual-money part of the economy, which one way or the other is based on credit, credit ratings or ratings in general.
While this probably doesn't scale back to 1 person's identity, it does show that having someone mess with your credit is a whole lot worse than someone just stealing some money.
Apparently the Defense investigators (DSS) merged into OPM in 2004- https://en.wikipedia.org/wiki/Defense_Security_Service
http://data.danwin.com/pdfs/house-oversight-opm-breach-2016-...
(not sure why ABBYY blew its size up to 98MB...)
And here it is in plaintext via pdftotext:
http://data.danwin.com/pdfs/house-oversight-opm-breach-2016-...
A better title:
Republican House Oversight Report On OPM Data Breach.
FINDING: Slow implementation of critical security requirements such as dual factor authentication is a true case of misplaced priorities.
That's not technical language. It's not even formal language.
OPM was/is a clusterfuck. I'm not disputing that. But the authors of this document had a job to do: portray administration appointees in the worst light possible.
There are interesting technical details in this document about the exact methods, vectors, files, timelines, etc used in both offense and defense of this incident. They would be of interest and value to many in this community regardless of the partisan agenda of the committee.
This document walks up the abstraction chain several notches and attacks the org chart and security policy of the MS Word variety, not the way things were written or configured (except insofar as bad config stemmed from not enough teams of paper not enforced well enough). It is pitched at the kind of CIO/CTO who could just as easily be any other CxO, not at engineers.
You're not making an argument. You're trying to pass an opinion as a fact. You need to back up statements like that.
Regardless of whether or not anything was exaggerated, it's still a partisan, political document. The contents don't change that. This would still be the case if it was a "Minority Staff Report" too...
That of the two major parties, the report is authored by the one with a far more adversarial relationship wwith the truth is also worth mentioning.
Not that the report mightn't contain elements of reality. But this is also likely to be as critical of the opposing part and politically beneficial to the authoring party as possible .
The fact is that this isn't a bipartisan and balanced (possibly, yes, to the point of compromise) report. That is not an opinion.
Tptacek hasn't argued the contents are specifically flawed. But the impartiality of the authors is certainly suspect on well-founded grounds.
If even that, which most of the intelligence and law enforcement officials have said is a catastrophe that won't be fixed for a generation, shouldn't be portrayed in the "worst light possible", then what should?
Enough with the partisan crap. This happened on those people's watch. Regardless of which party named them as the leaders of the OPM, they should be heavily criticized for it.
In fact, I'm actually quite angry myself at the fact that the Obama administration tried to downplay this for as long as possible last year. You actually didn't see much about it in mainstream media, and only some of it in tech media. All because Obama may have not wanted to be remembered as the president on whose watch the OPM breach happened.
So what I get from this is that you're the partisan one, not the OPM report.
http://democrats.oversight.house.gov/news/press-releases/cum...
[0] http://democrats-benghazi.house.gov/sites/democrats.benghazi...
From tptacek's comment, made ~5 minutes before yours:
http://democrats.oversight.house.gov/news/press-releases/cum...
Why would they want to avoid discussing this?
Nevertheless I'm sorry to have made a comment that seemed partisan. The Democrats and Republicans can both jump in a lake for all I care.
I'm interested in figuring out what you mean by your remark. You're saying nobody wanted to talk about it, but it seems for opposite is the case. What prompted your original remark?
They'll need to change their fingerprints immediately!
It is easily possible to create fake fingerprints that can fool any known finger print scanner. If you know one, that supposedly can't be tricked, please let me know.
Correlated letter from 2011: "Dear streptomycin, your fingerprint data is currently not stolen!"
For "security".
For "security"
TL;DR, there were two intrusion actors that were acting in concert. After being notified by US-CERT of exfiltration activity from the OPM network, OPM monitored the first one, who conducted the initial breach (use of contractor login credentials) and then performed survey of their network. They attempted to flush out her malware but failed to account for a second actor that had managed to leave an alternate access point into the network.
> "Notably, OPM Director of IT Security Operations, Jeff Wagner, recommended deploying ... preventative technology"
So the problem was identified and brought up to committee and still ignored/tabled by the CIO, Donna Seymour. Preventive measures were only undertaken after the exfiltration of security clearance data was complete.
Does she still have that job? If so.. ugh.
[1] https://oversight.house.gov/release/chaffetz-responds-to-ret...
Even more interesting is that had confidence they'd actually expelled the APT. Of course, they hadn't totally eliminated a related APT already in place.
This wasn't a "provision a clean box and run a build" reset... it's a massive, heterogeneous system. I can't even imagine how many vectors a nation-state APT could use to maintain a foothold.
It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team.
Stolen stuff includes millions of fingerprints. Those are obviously not hashed, so that's just the raw data I imagine. They'll learn lesson to not rely on fingerprints as much. Maybe that's one good thing coming out of it.
[+] CIA could still be affected, if for example some people there started at other agencies, or in the military (CIA likes to hire ex-Marines for example).
From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network.
I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can perform audits: which it appears to have done; OPM had the lowest security posture of any agency.
Should the NSA have prevented the exfiltration? How would that work? Do you want the NSA to have the authority to cut network connections occurring in the U.S. internet? Should the NSA have authority over civilian government agencies? What about hacking and wiping the intruders' endpoints? Sounds like an act of war to me, if those endpoints are on Chinese soil.
I doubt the vast majority of HN'ers want an increase in NSA's authority or scope.
Maybe it should have the power to intervene and stop it? This is still the federal government (it is not about walking into Facebook and shutting it down). I think it is the only agency with the brainpower to do it. It should be been trying to hack it and test the system periodically to identify flaws in it. Then mandate changes.
> Do you want the NSA to have the authority to cut network connections occurring in the U.S. internet?
To the federal agencies. Cyber defence doesn't work with current bloated beaurocracy. Nobody seems to be in charge.
> I doubt the vast majority of HN'ers want an increase in NSA's authority or scope.
I don't know. I would rather them spend more time defending, wouldn't mind expanding their power and diverting more budget towards that.
That's indeed the problem. There was a strong push for a while to put NSA in charge of civilian infosec infrastructure. But Congress didn't really want to put a combat support agency in that role. So DHS is technically in charge of that. But we still have the majority of federal agencies stuck fending for themselves when it comes to securing their networks. Without stronger action from Congress, this may never change.
You should go read the cybersecurity act passed in December of 2015, and realize that DHS is now authorized to force agencies to use it's security and offerings.
Maybe not directly. But the NSA could play a much more positive role in information security generally by moving out of the shadows and making more of its research public. The expertise that the NSA has acquired in securing information needs to be widely disseminated to work its way into engineering curricula and praxis, and that won't happen as long as the NSA communicates by whispering.
Which is doubtless why you ignore the TIC guidelines, etc
Most of my military experience followed this maxim. For example: You witness your squadmates doing something against the rules. Do you do the Official thing and report that to your unit commander, as you required to by guidelines and the definition of "good soldier"? Because if you do, now your entire squad will ostracize you, make your life complete shit, and possibly leave you to die on the battlefield. If you don't, you had better hope they don't get caught, because if it comes out that you knew about it and didn't say anything, now you are in just as much trouble.
This happened literally every day.
FWIW: Someone I know whom worked for DIA as a sysadmin about 10-15 years ago recalled multiple instances of TS/SCI folks being fired for surfing for porn over monitored networks... career- & clearance-ending. Maybe that's the only culturally-unacceptable sin in that community, apart from making the org/folks look bad?
Not quite all of them. OPM doesn't seem to keep track of any paper SF-86s that were phased out in favor of the first web site iteration around 2001. Those earlier records may be safe. The image PDF isn't searchable so I couldn't confirm this.
Firstly, why do you insist in letting OPM off the hook?
Secondly, even if we stipulate that OPM isn't at fault and that someone should have stopped this, you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us
I am not. It failed massively. Letting it do what it kept doing before is not going to work. We have hard evidence of its failure. There is no point mentioning it, it is obvious.
> , you should read about roles and responsibilities in the government before blindly blaming NSA. Start here. https://www.us-cert.gov/about-us
So where was US-CERT all this time? It was active since 2003. It had more than a decade to ramp up and get up to speed.
Why where all the electronic SF-86 forms stolen? You'd think out of all the places, they would protect, that would be close to the top.
> before blindly blaming NSA
Because they are probably the only ones that have the smarts to do it? Also isn't that their mission as well. https://www.nsa.gov/what-we-do/ . Second line is "Defends vital networks". OPM files with detailed and personal details on millions of current and past government workers who have clearance is pretty vital one would think.
Most programs for security guidelines seem to be descendants and ongoing implementations of HSPD-12.
I believe the Office of the Inspector General would be in charge of auditing in some cases, but it's usually up to each individual agency.
Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think that the best defense is a good offense, and maybe they have good reasons for that but from the outside it seems like they're just overly affected with wanting to feel 'l33t'.
https://medium.com/@bruces/the-ecuadorian-library-a1ebd2b4a0...
Geopolitics these days isn't about impenetrable borders, it's about deterrence by ability to project force. They are looking at IT security the same way.
In terms of defense, they've got a severe case of Congress-induces toothlessness.
So I tend to view the distinction between the two as something of a legal fiction.
#acronymheatdeath
They still claim that they were never exploited. The arrest records, addresses, and other sensitive info I was able to view say otherwise.
I expected the EINSTEIN program would have helped to quickly defend against heartbleed after disclosure, but apparently not. US Gov just sucks at cybersecurity defense.
Two distinct attacks, likely related, possibly coordinated took place. The first was observed in March 2014 and thought to be expelled in late May 2014.
Before that expulsion, a second attack began. While OPM thought it was in the clear, the 21.5M records were exfiltrated in July 2014. As late as August 2015, that same attack vector was used to steal fingerprint information as well.
"The OPM Data Breach: How the Government Jeopardized Our National Security for More than a Generation"
I'm unaware of the qualifications of either director, so who knows.