TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

US hit by 'massive data breach'

137 点作者 alan_cx将近 10 年前

25 条评论

dpcan将近 10 年前
I feel like we need to change our direction in terms of &quot;identity&quot; all together.<p>We seem to be relying on an &quot;identity&quot; that is our name, ssn, phone number, credit card number, or all these different little bits of data clumped together. Too messy, too easy to steal, to fake, to easy to sell.<p>Maybe our identity is more like a bitcoin wallet. It&#x27;s an encrypted clump of data that we only keep with ourselves, and ourselves alone. It could store money, confirm that we are who we say we are because it can have our picture in it, our names, our &quot;numbers&quot; for various things.<p>Then, when someone needs ANYTHING from us, be it proof of identity, money, or trivial info, we can send them a piece of useless information salted with something that they then return to us with the same salt to get back a confirmation, or money, or access to &quot;use&quot; our other numbers, but they never GET our other numbers.<p>If you want my phone number, you send a request to me asking for it. I get the request, confirm it, send back another piece of data to you. This is NOT my phone number, but something you can use to send to me again in the future when you want to call me, and then my number is dialed, but you never see it. At any time, I can wipe you off my safe list, and you don&#x27;t have my phone number anymore. Same thing can work when paying for something, or proving I am who I say I am when getting a loan, buying beer, whatever.<p>Maybe this is ridiculous.
评论 #9662959 未加载
评论 #9663067 未加载
评论 #9663480 未加载
评论 #9663965 未加载
SCAQTony将近 10 年前
Huge data breech and the FBI is screaming from an Ivory tower that encryption is hallmark of all evil and that backdoors are a really good idea.<p>&quot;&quot;Privacy, above all other things, including safety and freedom from terrorism, is not where we want to go...&quot;&quot; FBI Associate director Michael Steinbach
评论 #9662722 未加载
jacinda将近 10 年前
As a former government contractor, I wish I could say I&#x27;m surprised. Unfortunately, computer&#x2F;network security in many government agencies frequently has more to do with policy documents than with anyone technical actually determining whether the system is secure.
评论 #9662897 未加载
jsingleton将近 10 年前
Bit short currently. Looks like more detail from these sources:<p><a href="http:&#x2F;&#x2F;mashable.com&#x2F;2015&#x2F;06&#x2F;04&#x2F;data-breach-hack&#x2F;" rel="nofollow">http:&#x2F;&#x2F;mashable.com&#x2F;2015&#x2F;06&#x2F;04&#x2F;data-breach-hack&#x2F;</a><p><a href="http:&#x2F;&#x2F;www.washingtonpost.com&#x2F;world&#x2F;national-security&#x2F;chinese-hackers-breach-federal-governments-personnel-office&#x2F;2015&#x2F;06&#x2F;04&#x2F;889c0e52-0af7-11e5-95fd-d580f1c5d44e_story.html" rel="nofollow">http:&#x2F;&#x2F;www.washingtonpost.com&#x2F;world&#x2F;national-security&#x2F;chines...</a>
评论 #9662597 未加载
评论 #9662635 未加载
bashinator将近 10 年前
* cyber attack * cybersecurity system * cyber-intrusion * cyber databases (twice!) * cyber threat<p>Use of the word &quot;cyber&quot; adds virtually no insight or context to this article.
评论 #9662812 未加载
评论 #9663065 未加载
评论 #9662829 未加载
nedwin将近 10 年前
We hear a lot about Chinese attacks on the US but virtually nothing about the opposite, which undoubtably does happen.<p>Reading the wiki page on &quot;Cyberwarfare&quot; there are sections on each country, like &quot;Cyberwarfare in Germany&quot;, &quot;Cyberwarfare in India&quot; etc.<p>Both the &quot;Cyberwarfare in USA&quot; and Cyberwarfare in China&quot; are about Chinese attacks on the US...<p><a href="http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cyberwarfare" rel="nofollow">http:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cyberwarfare</a>
评论 #9663547 未加载
评论 #9662757 未加载
rmrfrmrf将近 10 年前
It&#x27;s OK, I&#x27;m sure whoever did it had a warrant.
评论 #9662928 未加载
ChrisAntaki将近 10 年前
This is a great example of why the NSA &amp; FBI should invest in strengthening American encryption standards, instead of trying to weaken them.
评论 #9662912 未加载
Zikes将近 10 年前
<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9661848" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9661848</a><p>I am shocked. Shocked, I tell you.
评论 #9662610 未加载
cm2187将近 10 年前
It&#x27;s hard not to make this trivial comment so let&#x27;s make it:<p>At least it may give a taste to US nationals of what it feels like to have your country hacked by a foreign power, like most European countries nationals felt after the Snowden leaks.
评论 #9662773 未加载
评论 #9662731 未加载
评论 #9662795 未加载
评论 #9662979 未加载
fieryscribe将近 10 年前
The timing of this report is very &quot;interesting&quot;, given recent news: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9659784" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9659784</a>
themeek将近 10 年前
This is part of an ongoing cyberwar between great powers - the largest adversaries to the US being China (mostly smash and grab) and Russia (primarily sophisticated and surgical).<p>It would be nice if there was some place where we could see the scoreboard to know how effective and how often we hack the Chinese back. Right now it looks like our tax dollars are being spent getting hacked, but the US government has doubled down many times on offensive cyberwar capabilities and now have professional cybersoldier career tracks in the DoD.<p>What&#x27;s the assessment?
评论 #9662772 未加载
评论 #9663297 未加载
foxhedgehog将近 10 年前
A lot of people here are commenting, rightly, that this is an example of why the USG should be strengthening encryption. It&#x27;s also a reminder that, despite its disproportionate focus in media, including on HN, the US is obviously not the only government engaged in this behavior.
Red_Tarsius将近 10 年前
I wonder how much social engineering was involved in the hack. No matter how great is your tech, if your staff is not trained to be <i>paranoid</i> you&#x27;re going to suffer the consequences.<p><i>&quot;Hey I just found a usb pen on the floor. I wonder what it&#x27;s inside it...&quot;</i>
blisterpeanuts将近 10 年前
This is perhaps a stupid or uninformed question, but if databases are so vulnerable, why is so much information still stored in cleartext? It seems to me that taking the extra step to strongly encrypt data prior to writing to tables would make the intruder&#x27;s job much harder.<p>I speak not only as a programmer and database guy from way back, but as one of the millions of Anthem subscribers whose personal data was stolen a few months ago in a massive breach.<p>I know that &quot;data breach&quot; might well mean the keys were stolen which decrypted an otherwise secure file, but the terminology suggests that the breach was simple access into the system rather than acquisition of the precious keys themselves.<p>Someone with superior knowledge of these things, kindly explain.
评论 #9662946 未加载
评论 #9662878 未加载
评论 #9662866 未加载
redwards510将近 10 年前
What would be a suitable response to this? America does not have a clear cyberwar policy and I haven&#x27;t heard many suggestions.
评论 #9662708 未加载
评论 #9662630 未加载
评论 #9662753 未加载
评论 #9662613 未加载
ephemeralgomi将近 10 年前
what differentiates a &#x27;cyber database&#x27; from a &#x27;database&#x27;
评论 #9662665 未加载
评论 #9662806 未加载
评论 #9662678 未加载
评论 #9662997 未加载
评论 #9662962 未加载
评论 #9662768 未加载
dpweb将近 10 年前
Of course, China. How is it they are incompetent to protect the data, yet competent enough to know immediately who did it.
评论 #9662740 未加载
sgacka将近 10 年前
This hit every US news service. How is it so low in points?<p>&quot;breach could potentially affect every federal agency, officials said&quot;<p>I love HN&#x27;s ability to filter news that matters to dev&#x2F;tech-professionals, but when stuff like this pops up it should be top 10, for at _least_ a few hours. This is some serious shit. Who here does business with government agencies? Most of you have IRS Tax&#x2F;Employer IDs... with the rate that this is &quot;expanding&quot; what is to say that it wasn&#x27;t just HR records, but more. Your e-filed IRS return could be sitting with folks outside of the IRS...<p>No intention to fear monger but think of the statement &quot;breach could potentially affect every federal agency&quot; - every business in the US does something, with sensitive data, with an agency :&#x2F;
fleitz将近 10 年前
It&#x27;s not a data breach, it&#x27;s essential that the US keep their database unencrypted so that the Chinese national security agency can search their records for ties to terrorism.<p>If anything China just did the OPM a favour to help them keep their freedom.
thyrsus将近 10 年前
Note the Office of Personnel Management&#x27;s scores in this report, and note the scores of the State Department. Ms. Clinton&#x27;s e-mails may have been more secure at her private residence :-\<p><a href="https:&#x2F;&#x2F;www.whitehouse.gov&#x2F;sites&#x2F;default&#x2F;files&#x2F;omb&#x2F;assets&#x2F;egov_docs&#x2F;final_fy14_fisma_report_02_27_2015.pdf" rel="nofollow">https:&#x2F;&#x2F;www.whitehouse.gov&#x2F;sites&#x2F;default&#x2F;files&#x2F;omb&#x2F;assets&#x2F;eg...</a>
danso将近 10 年前
Interested in hearing the details about this one. How much of it was facilitated by phishing or social engineering? Are there any government systems that require two-factor auth? So much of federal web infrastructure is based on old code&#x2F;systems that, while invulnerable to a mass exploit of Rails&#x2F;WordPress&#x2F;Bash, have not even remotely been tested and studied against edge cases in the way that large scale open source platforms have.
ams6110将近 10 年前
<i>The breach did not involve background checks and clearance investigations, officials said.</i><p>No, that breach[1] was a couple of years ago.<p>1: <a href="http:&#x2F;&#x2F;www.nextgov.com&#x2F;cybersecurity&#x2F;2014&#x2F;12&#x2F;opm-alerts-feds-second-background-check-breach&#x2F;101622&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.nextgov.com&#x2F;cybersecurity&#x2F;2014&#x2F;12&#x2F;opm-alerts-feds...</a>
gress将近 10 年前
If only there had been a backdoor in the system, or no encryption, law enforcement could have prevented this. &#x2F;s
评论 #9662707 未加载
multinglets将近 10 年前
Oh no, the Chinese are stealing all our datas in an unprecedented cYbErattack!<p>I didn&#x27;t realize it was Thursday again already.