Why the US federal employee record breach is worse than others
caseysoftware.com
caseysoftware.com
Obviously, a huge blunder of government, totally irresponsible and reckless that such a massive breach was even possible. And it happened in dec 2014, and they only just now found out. A team of amateurs could do better than that.
I know data security is hard, but maybe if the government spent money on proper protections of people's data instead of building data centers to spy on it's citizens, this wouldn't have happened. But it's clear that's not what their priorities are.
Really, just disgusted by this.
That said, what did they do wrong? what should they have done, that they didn't do? Getting hacked seems like an eventuality at some level. What can an organization do to protect such sensitive information, or at least reduce their exposure and the amount of data that is able to be leaked before detection?
Seems like you'd have to partition up your data at some level, maybe encrypt it at rest; but I don't know how far one has to go.
The Gozer Principal: in Information Security you get to design the weapon that will be used against you [1]. Don't build a tool you are unwilling to hand to your greatest enemy.
For example what happens when foreign governments steal the domestic bulk surveillance data? I bet the NSA accidentally hoovers up all sorts of top secret information that is just accidentally sent over the wire or non-classified data that could do great damage to US interests. Or what happens when a foreign government gains access to the tools used to perform this bulk collection? They could inject fake traffic or hide traffic for strategic deception campaigns.
Collect it all is a strategically empty slogan, it represents a serious risk to US national security, but on the other hand it is a wonderful Rice Bowl [2] for the NSA.
>What can an organization do to protect such sensitive information, or at least reduce their exposure and the amount of data that is able to be leaked before detection?
* Keep it offline/airgapped.
* Store the most dangerous data on paper with hashes replicated online to insure integrity.
* Delete information you don't need anymore.
* Do not have a centralized repository of data to reduce risk of catastrophic exposure.
There are always trade offs between usability, functionality and security.
[1]: https://twitter.com/ethan_heilman/status/510993743156375552
[2]: https://en.wikipedia.org/wiki/Iron_rice_bowl#Other_uses
> * Keep it offline/airgapped.
Agreeable, but what about physical access? What about compromised individuals, or nefarious agents?
> * Store the most dangerous data on paper with hashes replicated online to insure integrity.
Interesting; i guess that reduces the accessibility of the information, so it's harder for you and harder for someone else. Interesting, and in line with your comment about the Gozer Principal (is there anything more than a tweet about that?)
> * Do not have a centralized repository of data to reduce risk of catastrophic exposure.
Also a great point too; and pretty contrary to how we typically design systems.
Thanks again!
Always a risk and a very hard problem to solve since someone always needs access and that person can be compromised. Detecting and preventing this is what counter-intelligence is for, but counter-intelligence is never a guarantee of security.
You can trade off usability for security to slow the speed at which an attacker can copy everything giving you more time to detect the activity. This only makes sense if they information is exceptionally important to protect. That being said, even paper can be stolen in large quantities. Jonathan Pollard managed to steal quite a bit of classified paper from the US during his tenure. The Israeli's needed multiple highspeed copying machines to keep up with his output [1].
One could imagine a system in which records are stored in multiple places and people only have access to the local files. No one agent could compromise the entire system. Then again, you might be so secure you protect the information from yourself and may not be able to "connect the dots" which is probably what you have the information for in the first place.
As Snowden suggested, "The Two Man Rule" [2] can also make enemies spies jobs harder. While it is true a determined attacker can overcome it by gaining the other parties credentials, such actions raise the risk the spy being caught.
A very silly idea:
I've been told on older nuclear armed submarines the device used to launch the missiles must be carried from one part of the sub to another to begin the launch sequence. The device was extremely heavy and awkward requiring multiple people to move it and making the movement of it very obvious and loud. Thus, they accidentally achieved an additional "Two Man Rule". Perhaps if very secret information was encrypted and then stored on heavy large objects which could only be read/decrypted at another location in the building than it would be difficult to quickly steal and decrypt many of the files. A computational version of this would be a cipher that requires massive resources (memory, CPU) to decrypt. This is likely more fantasy than reality, but at least enemies spies would have to break a sweat.
>Interesting, and in line with your comment about the Gozer Principal (is there anything more than a tweet about that?)
I've been working on a blog post on it, but I don't really have enough content to flesh it out and make it worth reading at the moment.
[1]: https://books.google.com/books?id=MDZlAgAAQBAJ&pg=PT66&lpg=P...
The two-man rule is a good idea - not fool-proof, but I suppose nothing really is.
And the story about the heavy device on nuclear subs; that's brilliant! Although I'm not sure a computational version would be a ciper that needs a lot of resources to decrypt, unless that is something that even people who have valid access need to expend resources for in order to access.
It really seems like ease of access is the enemy; that's a pretty fruitful take away.
I do hope you share your blog post about the Gozer Principal on HN when you're done, I look forward to reading that.
your points are what you would want to do if you wanted to make an ideally secure system, but nobody wants only an ideally secure system...
Indeed! The ideally secure system would be one which doesn't exist/doesn't have ANY interface, much like the perfect computer which doesn't perform any IO with the rest of the world.
- Prof. Gene "Spaf" Spafford
I'm just proposing some tools which might be useful when security is significantly more important than other considerations.
Security people (and armchair security people especially) think that security is the end goal. Security is never the end goal. The mission is the end goal. Security is only useful in so much as it helps you achieve the mission. Sometimes security needs to get out of the way when the mission needs to get done. It is always a tradeoff. The personnel clearance system is already such a tradeoff, a background investigation system that needs to scale to millions of people. Good luck making it "ideally secure."
There were data hygiene and application/network security best practices that OPM should have followed. In hindsight, they would have been way cheaper than the response to a breach like this. Responding by taking all the systems offline would most likely be far more expensive to the system as a whole than a future breach.
Like what? Can you reference anything?
Your comment criticizes security but, this is a HUGE leak. You can't just sweep this kinda data under the rug for the sake of usability. That's just laziness. The mission matters and is important, but if you can't protect the data that people give you, you shouldn't have it at all.
This was a government agency; there is NO REASON for any kind of security tradeoff.
A company with CC info? Ok, yeah that's a different story with different tradeoffs. But this is the kind of data breaches that can cause vast amounts of harm to individuals and the nation; people's lives are put in danger by this leak. You wanna tell me that it's OK to sacrifice security for the sake of usability in cases like that? Would you feel the same if it was your life that was now at risk?
They had a responsibility to protect the data they held AS WELL AS to serve the mission. not one or the other. both. it is irresponsible to take risks with data that is not yours.
So when your agency needs an application to do X, and you will face consequences if it doesn't get spun up, and to do so requires you cut a lot of security corners, but you won't face any consequences for doing so, you're going to cut those corners. Especially if not cutting those concerns means delays in rolling out that system, or spending a ton of money to fix all those security problems. The state of information security in the government is atrocious for this reason. It's not that complicated. There is no real incentive to secure systems, and very real insentives to not do so. You just issue the ATO and accept the risk. It's up an running and everyone is happy. If it's not and running people are pissed. It gets owned, people shrug and say "well nothing is totally secure".
Until this changes, compromises will continue.
This only seems to be your mistaken perception of what security people think. I'm a security analyst and I've never met anyone in my industry that believes that security is a goal that can be achieved. Security is a process that will never end.
>I don't think that this is a case where you want to trade off security for usability, and I don't think that generally those cases exist. You always want more usability.
If you believe that security is always a tradeoff(which you stated) and you believe that there is never a situation where you would want to make such a tradeoff, you are basically saying that there is never a situation where you would want security, which is ridiculous. There is always a balance between usability and security. In most cases, the scales will tip towards usability by a large margin, but there are times where a significant hit to usability in the name of security is the right decision.
The uncomfortable truth for many HN readers is that this is also true for all of that user data that businesses are currently aggregating: from the data people trust an online service to manage to the modern version of "library records" we call analytics. Thee is value in all of this, or it wouldn't be worth paying to collect/store it.
Unfortunately, even if the data is collected with the best intentions, the fact that the database exists creates a target that must secured. It also creates an "attractive nuisance" for governments holding national security letters and PRISM. Those are troubling enough, but gathering data about people has another risk that is rarely addressed: moral hazard. There is always the temptation to sell that data to the highest bidder, which we have seen happen many times as businesses look to find new ways to "monetize" their users.
I carefully listed the Russians I knew under penalty of perjury. I've lost touch with most of them. I wasn't trying to turn them into agents, and they were patriotic Russians who liked me despite, not because of, me being American. The fact that they might be getting FSB attention now is sickening.
The fucking government, man. It really blows your mind sometimes.
To expand a bit on that: any job that requires you to list the names of random people that you've had contact with in the past should be avoided like the bloody plague, there is nothing that those people have done to warrant you putting their name into some form and subsequent database with unknown consequences for the people you decide to list.
They're not sheep to be offered up on the altar of your ambition to rise up in the ranks, absolutely nothing good could ever come for them. So if the penalty is perjury just walk, that way you don't perjure yourself.
In fact, I'll go so far as to say that "clearances" are a symptom of the pathology of the security state. Lots and lots of highly cleared people have gone wrong (Pollard, Ames, Hansen, I'm sure there's more), so the process isn't really all that helpful. For a corporation, having "cleared" employees does two things:
1. It raises a huge barrier to entry for competitors. A smaller company just can't afford the specialized record keeping and record keepers, so only lumbering dinosaurs have cleared employees.
2. It means that the corporation can say, just like my kids, "I didn't do it!" as an excuse. An employee goes bad? The corporation didn't do it, because the Defense Investigative Security Clearance Organization cleared that traitor. It's yet another excuse to not have a relationship with employees, just like drug tests. Managers can just fill out forms, they don't have to know or like or have meaningful conversations with employees.
You don't list "random people" of any kind.
You list relatives, roommates, long term relationships, places you've lived, schools you've attended, and jobs you've had and then people who can confirm and validate those. Further - in regard to foreign nationals - you have to list and describe ongoing relationships and any foreign officials you've met.
This not "I was standing next to this guy at Starbucks" and closer to "I lived with, worked with, or dated with this person for X months."
Yes, exactly. Those people that you randomly meet on your walk of life and who take on a role of some significance, and who clearly were NOT consulted about being included in some foreign country's databases on contacts with someone who is now part of the intelligence apparatus of one of their enemies.
What could possibly go wrong?
That person that you dated for X months is now potentially a target for a foreign intelligence service, just like that person that you lived with or worked with. And if they are as paranoid as your country and one of them happens to also be employed in their intelligence services and forgot or intentionally withheld similar information they are quite possibly in trouble.
My only criticism is your use of the word "random" to describe the people listed.
It's not as if any of those people had a way of controlling who they came in contact with. Life is built up out of tons of coincidences and who you know is rarely a matter of deliberation, far more often it is random chance that causes you to know one person and not to know another.
Random is NOT the guy I went to school with in Moscow and would fly back to russia for a wedding for.
The OP didn't say which group he'd classify his friends in, but if he thought it was pertinent enough to list them, than he had a close enough relationship to warrant listing them. Cause when OPM/FBI find out that you went to school for a year in Moscow and you didn't list any acquiescence's, they'll raise some flags and find what you are hiding.
I see the red scare is still alive and well, which 'hostile countries' would those be? How does what someone does in their time off impact your ability to let them work on the plans for your nuclear reactor?
Do you really believe any of the leaks from the past 40 years or so were because someone had a college roommate from a hostile country (whatever that is) and who maintained their relationship?
And then the Gestapo may be closer to home than you might like, for instance the FSB or the Chinese equivalent.
And for those people the consequences are well outside of the sphere of influence of the people that initially reported contact with them.
Databases like these on internet connected computers should not even exist, to see them fall in the wrong hands is absolutely in-excusable and to voluntarily aid in their creation is irresponsible at best.
It means a representative -- military, ambassadorial, intelligence etc. Not sure whether it includes any public / civil servant. There's often a bit of judgement call required.
1) http://www.internetnews.com/bus-news/article.php/1562181/Cou...
2) http://www.indianz.com/News/show.asp?ID=pol01/1262001-1
3) https://en.wikipedia.org/wiki/Cobell_v._Salazar
4) http://fcnl.org/issues/nativeam/chronology_of_the_department...
5) This also for a time included all Native American colleges including those that were buying their own line and charted by the tribe and not the BIA. It left students without access to distance learning classes and research beyond small libraries. It was hellish on students.
As part of the clearance process, your co-workers are interviewed regarding your work-habits, perceived integrity, etc. We had one woman, "Mary", in the office who was a bit of a busy-body, listening in on phone calls, other people's conversations, etc. One day she overheard another young woman, co-worker "Jane" talking on the phone regarding meeting her boyfriend John at the airport. In order to embarrass him, Jane and a friend were going to dress up like hookers, hang all over him etc. Only Mary didn't hear the whole story and became convinced that Jane was really involved in prostitution and was going to meet a John at the airport. So when investigators were working on Jane's clearance, Mary flat-out told them that Jane was a practicing prostitute on the side. I'm sure these investigators hear it all, but I can only guess that this was a memorable interview. Of course when the investigator confronted Jane with the accusation that she was a hooker, she flipped out. Mary and Jane's relationship was never quite the same after than..
Apparently, they succeeded in centralizing security clearance data. Then, of course, it had to be made available to all the security agencies. Remember the demands after 9/11 for "tearing down the walls" between the law enforcement and security communities? That means lots of people able to access databases in other agencies. Of course, people will want to access the data from the field on their mobile device.
[1] http://www.washingtonpost.com/sf/national/2014/03/22/sinkhol...
They have to look it up somehow. That lookup will likely involve a computer database, and the pathway to reach that database will likely involve the Internet.
Practically all the rest of this sad story follows immediately, because the whole strategy of how the government handles computerized records in general is all screwed up.
Even after this I'm not sure it will get better... the trend in government is for inexorable centralization of related information. At the same time there's incredible demand to have those work-related systems available online and all the time, so that people can work while on duty travel, or from home.
Obviously there are technical things that can be done to mostly have our cake and eat it too (VPNs, redacted mirrors/views of the sensitive central database to be made available across the public Internet, etc.). But no one gets promoted in the government for doing that, and much of the talent is at Google or Facebook or Silicon Valley anyways :P.
This was the actual plotline of Skyfall.
Maybe the solution is to have a smaller law enforcement and security community. Fewer components, better MTBF.
The SF-86 form gets very, very personal, so I can imagine that some folks will be panicked, but reading my form would be a yawner. Maybe I need to get out more :-)
What if the calculation of both maximum effect and maximum deniability is exactly that: Create a shadowy, possibly composite hacker persona (a "Satoshi Nakamoto"), release a bunch of signatures and generate publicity, and then roll out the database, verifiable by the previously released signatures.
Everybody
The first sentence of the article I linked to: "The Chinese breach of the Office of Personnel Management network was wider than first acknowledged, and officials said Friday that a database holding sensitive security clearance information on millions of federal employees and contractors also was compromised."
It's a bit like wishing slaughterhouse workers would start to consider the animal's feelings and spend more time thinking about them.
I hope so too, just like I hope I get to fly around in a UFO because that would be pretty cool. Not really expecting that to happen though.
Everyone has things in their lives they'd rather not have made public because it's nobodies business, and this compromise just betrayed the trust all those people put in the US government.
But, deleting information might result in an error of commission which would have your signature on it rather than an error of omission which has no one readily blameable. So, no one in the organization will ever sign off on it.
..and that for twins, having the same post-code can be fatal..
But what about the obvious fix: Pull clearances from everyone who does not need one. I mean really NEED. There are hundreds of thousands of schlubs with clearances only because the paperwork they have access to is classified higher than FOUO. And that classification is the product of self-importance and ass-coverage.
https://en.wikipedia.org/wiki/Personnel_Reliability_Program
Has anything been said about this?
Only part of the danger of what the NSA is doing due to the "what if government turns evil" scenario.
The other danger is the "what if hackers/scumbags/criminals get hold of it" scenario.
Only one of those scenarios has to happen, in order for it to hurt you. And the NSA has the very biggest pot of gold at rainbow's end, PII/fraud/blackmail-wise, of any of these systems to date. Contemplate that. Fear that. Take political action. Make day-to-day choices based on that.
Why for christs sake do they even collect this data in the first place? This is not a database on felons or potential terrorists ... why does the government care about the neighbours of their employees???
Heck, just to apply to the bar I had to list eight character references plus a contact at every employer I've had in 13 years. It's pretty standard practice for trust-sensitive jobs to ferret out people who have something to hide or are lying on their application.
I think that's so they can ask the neighbours questions.