“EPIC” fail–how OPM hackers tapped the mother lode of espionage data
arstechnica.com
arstechnica.com
Good lord.
Yet, somehow, someone might still present the solution as needing to spend more money sooner: It was only when OPM was assessing systems to actually implement the sort of continuous monitoring tools ... that OPM security officers discovered traffic outbound from the network. If only they'd demo'd the software a year ago, right? /s
Is anyone getting fired? Why should anyone lift a finger during this 30-day sprint? And what happens on Day 31?
No, with a small caveat: If that civilian agency (say DHS) is connected to the GIG[1], then DISA has a say-so and can threaten to disconnect them for failing security audits.
Something to keep in mind is that the STIGs are merely implementation guides to secure a system. Therefore, different agencies have different interpretations. In some cases specific secure implementations break systems and applications (mostly legacy ones), so they avoid securing those particular settings all together.
There isn't really any U.S. equivalent to the Home Secretary, the responsibilities are divided over several offices reporting to the president.
Additionally, the Secretary of State is foreign affairs and not the equivalent of the Home Secretary.
https://en.wikipedia.org/wiki/Katherine_Archuleta
That is the person who is responsible for the OPM.
It operates on a fee-for-service model for 90% of its budget and isn't properly funding IT and IT security. Given she has only been there 18 months, I'm not sure how you can really blame her beyond the fact she didn't follow the "shutdown and repair" recommendation...except for the fact if she did that, she'd have to burn through the OPM's cash reserves as the only way to fund it.
Its honestly more of a flaw in the way Congress built the OPM incentive structure and the fact the director is a revolving door position that changes every 2-4 years.
The government simply just doesn't fund/prioritize IT & IT security properly outside of the intelligence services. They also build these psuedo-private-sector funding models that create the incentive to "ignore" cost centers like Security into critical infrastructure like the OPM. Its really horrific.
It's a long time since any UK politician resigned on principle or on honor. I think the late Robin Cook was the last (over the Iraq invasion which he believed was illegal).
Private Eye has an endless stream of 'highly suspect' (since any suggestion of 'corrupt' may get HN into trouble, just to be clear, I'm not saying 'corrupt'.) activities of various government ministers, none of whom resigned or even came close - despite their misdeeds being exposed. Look at how many were caught in the expenses scandal - some UK politicians even tried to hold on while being convicted of fraud and other criminal convictions (with some initial success too, https://en.wikipedia.org/wiki/Nazir_Ahmed,_Baron_Ahmed). That's never going to fly in the US.
You really need to go back to Margaret Thatcher's cabinet before you can really find many examples of resignation on the back of government screwups.
I think a resignation is more likely in the US than the UK. And it's not at all likely in the US.
The end result of honor resignation is that you have politicians who worry more about appearances than actually getting anything done. Does that sound at familiar?
Where I come from, CVS and PIV mean completely different things. One of them is an abomination before God, and the other is a natural act of biology.
Let me get this straight. You had really sensitive data, you knew it wasn't secure and huge portions of the systems didn't have valid authorization procedures?
This is pretty eye opening, even for a governmental agency. The scary thing is, this is just the tip of the iceberg. It seems this breach was inevitable considering how many other EPIC FAILS are mentioned in the article.
(JRun and Windows XP? Really?)
Now id believe Bruce more than a Murdoch Rag
And for disinformation and source hiding, I'm sure they all (even internally and to their own "customers") claim now that the source is Snowden. I would if I were in their place.
ps you do know who Bruce is?
Yes, I do know who Bruce is. Do you? Did you actually read the piece[0] we are talking about?
Schneier himself seems to believe that the journalists are likely hacked, but that state actors have had this info long before Snowden:
""" Which brings me to the second potential source of these documents to foreign intelligence agencies: the US and UK governments themselves. I believe that both China and Russia had access to all the files that Snowden took well before Snowden took them because they've penetrated the NSA networks where those files reside. After all, the NSA has been a prime target for decades. """
and
""" The point I make in the article is that those nations didn't have to wait for Snowden. More specifically, GCHQ claims that "we have now seen our agents and assets being targeted." One, agents and assets are not discussed in the Snowden documents. Two, it's two years after Snowden handed those documents to reporters. Whatever is happening, it's unlikely to be related to Snowden. """.
Oh, and when you mention [ex]CIA employees, are you including the head of the CIA[1] or not? Cause, you know, that guy failed miserably at information security.
[0] https://www.schneier.com/blog/archives/2015/06/the_secrecy_o...
And Petraeus shows that parachuting outsiders to the DCI's job isn't a good idea and also if your bonking a spook you don't behave like some 15 year old high school student.
Granted there are a couple hiccups moving from 9 to 10 but mostly (and understandably) it involved if you were calling Java directly. For the most part its pretty painless to upgrade.
At seven bucks a piece, this seems very cheap, especially for a rushed government purchase. Any thoughts? Am I missing something?
Likely the Unit thing was done to make the bureaucracy that pays for things happy. I have worked places where a 1,000 payments of $1 each was easy to make happen than one $600 purchase.
http://travel.state.gov/content/travel/english/news/technolo...
from https://firstlook.org/theintercept/2015/06/12/data-breach-th...
The article also mentions a pending Supreme Court case (Spokeo v. Robins) which could "'open up the floodgate for lawsuits, in all contexts, but especially in data breach litigation'".