Personal data for more than 130K U.S. Navy sailors hacked
reuters.com
reuters.com
Am I missing something here? A statistically relevant subset of people have important secrets, and a statistically relevant subset of those (perhaps most) are relatively easy to control when you know them. If the US has similar information on other governments' personnel, we might even fall into the caricature of the US guiding their actions while they guide those of the US, since those controlling and those being controlled will (largely) not be the same members of their respective governments.
The entire situation seems quite messy.
it really is child's play
[0] https://www.amazon.com/Sovereign-Individual-Mastering-Transi...
The state actors responsible for this want the US to know that they have these records. That they can attack/disturb/flood the personal computers, social networks, and family of these soldiers / military assets.
Also note the apparent warning in the Shadow Brokers auction:
> You see what cryptolockers and stuxnet can do. You see free files we give for free. You see attacks on banks and SWIFT in news. Maybe there is Equation Group version of cryptolocker+stuxnet for banks and financial systems? If Equation Group lose control of cyber weapons, who else lose or find cyber weapons? If electronic data go bye bye where leave Wealthy Elites? Maybe with dumb cattle?
The effectiveness of our country's response depends on your answer to this question: Can you as the CIO be trusted with highly personal, highly sensitive data on millions of Americans?
I guarantee most Federal CIOs never even saw the report, and wouldn't believe the question actually applies to them. The folks at DDS did though (including Matt Cutts), and I'm willing to bet they have it pinned up on the wall.
(1) https://oversight.house.gov/wp-content/uploads/2016/09/The-O...
Perhaps a better question is: can anyone be expected to properly secure data on that scale, against well-resourced malicious actors?
https://www.washingtonpost.com/world/national-security/chine...
How about when Google's data center links were tapped by the NSA?
https://www.washingtonpost.com/world/national-security/nsa-i...
Google right after the NSA reveal started doubling up on their efforts to use encrypted links between servers within their data centers, leading me to believe that it could have been a lot worse - just get access to some non-critical host, and if the traffic is unencrypted, just hang out with a packet sniffer and just record all traffic passing by.
Google is much more vigilant with their security (not that they weren't before, just even more so) - It's better to not underestimate the extent of breaches.
Bitcoin Security Forum Gmail Dump: In September 2014, a large dump of nearly 5M usernames and passwords was posted to a Russian Bitcoin forum. Whilst commonly reported as 5M "Gmail passwords", the dump also contained 123k yandex.ru addresses. Whilst the origin of the breach remains unclear, the breached credentials were confirmed by multiple source as correct, albeit a number of years old.
Compromised data: Email addresses, Passwords
https://www.washingtonpost.com/world/national-security/nsa-i...
Therefore, if google isn't storing large numbers of credit cards, social security numbers of health records they probably will never tell you wether or not they had their servers breached.
"Center of Information Assurance and Cybersecurity at the University of Washington, designated by the NSA/DHS as a Center for Academic Excellence in Information Assurance Education and Research"
http://www.washington.edu/research/centers/126
https://www.pce.uw.edu/certificates/information-security-and...
Taught by a ~70 year old woman with lit major, MBA, fake IT Phd and zero real IT knowledge https://www.coursera.org/instructor/~115
I took three classes wasting my time listening to >50 year old industry veterans(LAX airport CISO boasting how he doesnt know _anything_ about computers etc) tell me CIO role is to get a piece of paper stating you delegated responsibility and obey all the federal/industry pat on the back standards (PCI, HIPAA, SOX).
I somehow don't think that whoever targeted a 'a laptop used by a Hewlett Packard Enterprise Services employee working on a U.S. Navy contract' was doing so to grab personal data for smash-n-grab identity theft or other things that'd rapidly leave 'evidence to suggest misuse of the information'...
Why even mention that part at all, just makes them sound dumber. Should have just said "there's an active investigation, we will release the full scope in a report later"
Or they have a developer image on their laptop that isn't locked down and download Warez or Torrent and visit Porno sites.
Until there are consequences when this kind of thing happens, like people getting fired or severe penalties, I'm afraid it will just continue. It's either some 15 year old kid in Eastern Europe or the Chinese and Russians have some more info to build dossiers on the American Armed Forces.
1 :
>A NASA inspector general report this year determined 48 NASA laptops and mobile computing devices were lost or stolen between April 2009 and April 2011, many containing sensitive data.
http://www.reuters.com/article/us-space-nasa-security-idUSBR...
2:
Personally identifiable information of "at least" 10,000 NASA employees and contractors remains at risk of compromise following last month's theft of an agency laptop, a spokesman told Computerworld via email Thursday.
http://www.computerworld.com/article/2493084/security0/nasa-...
3:
NASA decides to encrypt all their laptops, because PEOPLE STORE SENSITIVE INFORMATION UNENCRYPTED on laptops that they take home.
https://oig.nasa.gov/Special-Review/SpecialReview(12-17-12)....
And recently, we've started transitioning to new encryption software. Our implementation of the software prohibits more than one encryption passphrase per machine. So, in order to share machines between employees, organizations have begun sharing the same passphrase across all the organization's machines.
Source: HPES employee working on NASA ACES contract
They want to know that if someone attempts to blackmail you, you would rather the information become public than betray your country.
For the last ~5 years the only credit card that hasn't been reissued before the expiration date because of some large corporate data breach is the one I never use.
That sort of arrogance begets an unprecedented sense of entitlement. Coupled with a severe dependence on Microsoft Tuesday updates, and a general inability to recognize an SQL query (not making that up), and you have a real problem.
I would not doubt, for a second, that 134k SSNs were on some contractor's laptop.
You're posting on HN. I'd wager that a lot of us are or have been guilty of a bias like that.
What about if the app chokes on real data and it's not something covered by testing?
You're not living in the real world. Users do weird things.
At some point someone will legally change their name to an emoji and it'll break a whole load of systems. Nobody saw that coming when they originally built some middleware in 1998.
I've written plenty of code that checks out against out test environment, but it'll choke on a weird thing in production. You NEED access to real data if you're going to make any progress in that scenario.
"It worked on test, but not in production. It's supposed to be live already, what's the holdup? Fine, I'm not supposed to do this but I'll give him access to the live-server, read only, of course, since you have security clearance anyway. Plus, the data is in the DB, not on the application server. Ok, so now you have the whole /deploy folder, find the issue..."
"What do you mean you lost you laptop on the metro this morning? Fuck! Ok, well you only had access to the /deploy folder, but now I'm required to audit your laptop's backup to see if you had anything important, what a pain in the ass. Wait, what's this? There are all these XML files with personnel data in them in /deploy/api/xml/!!!!! Those files are supposed to be processed and removed from the web server, not stored! Shit!"
Source - I was a Yeoman in the Navy and had access to this. I already didn't think much of the Navy's PII procedures, but seeing this thing for the first time blew me away. It shouldn't exist.
http://www.cnn.com/2009/POLITICS/01/27/va.data.theft/ 600+
http://thehill.com/policy/technology/97817-va-loses-another-... 26.5 million veterans/active
The funniest part of all of this is that the non veterans here seem to be surprised by this.
It would not surprise me the Navy contractor had the same setup.
HP's culture is incentivized to propagate 1990's client-server architecture as a result of their product line. Gov procurement officials and CIOs must demand that HP move to cloud-based infrastructure with 2-factor authentication.