TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Office of Personnel Management Says Hackers Got Data of Millions of Individuals

109 点作者 mrmaddog将近 10 年前

12 条评论

murbard2将近 10 年前
And yet, tomorrow they'll have no qualms making the case that, of course, the government can securely keep backdoor keys to investigate encrypted communications.
评论 #9861756 未加载
评论 #9861670 未加载
评论 #9861612 未加载
评论 #9861599 未加载
评论 #9861931 未加载
fixermark将近 10 年前
No surprises there.<p>I get deeply frustrated (though I understand where they are coming from) when governments make the argument that they can&#x27;t take advantage of this or that cloud service because the service&#x27;s security isn&#x27;t vetted. Clearly, the security in the backing systems owned by the government isn&#x27;t sufficiently vetted either, so they&#x27;re sacrificing velocity for non-security.<p>I know, it&#x27;s a flippant attitude. Blame a lousy day. ;)
评论 #9860589 未加载
评论 #9860772 未加载
评论 #9860726 未加载
hamburglar将近 10 年前
When are we going to move from a nine-digit number to something a little more secure for identity? I effectively want a public key and a private key and require signing of forms submitted as me.<p>edit: Freely provide easy to use tools for doing the signing and verification, and for people who still aren&#x27;t savvy enough to do it themselves, train notaries to do it.
评论 #9860970 未加载
评论 #9861237 未加载
评论 #9860834 未加载
bitJericho将近 10 年前
The worst of this is that I had just taken a government job when the 4.2 million person breach was claimed to have happened. I had very serious concerns about giving out so much (and it was an absolute ton, more than any other employer I&#x27;ve ever worked for) information. I had thought about not taking the job but like many Americans I really didn&#x27;t have much of a choice. The choice was homelessness and perhaps even going to court for failing to pay my obligations, or a nice comfy job and pay.<p>Why does the government need so much data on its employees; that&#x27;s what should be asked!
评论 #9860737 未加载
评论 #9860988 未加载
评论 #9860690 未加载
dguido将近 10 年前
Before you start shitting on OPM and the like, is this any different than what would happen if a dedicated attacker came after the most valuable data in <i>your</i> company?<p>Clearly, OPM should know, but omg is the state of security poor.
评论 #9861520 未加载
评论 #9861069 未加载
aburan28将近 10 年前
This hack occurred well over a year ago. The DoD knows exactly how many people this affected as it was informing its employees to be wary of the implications of this (telling their kids to watch out for Chinese blackmail, potential social engineering attempts with more informed information from the data dump). I am honestly surprised this story took this long to be discovered.
melipone将近 10 年前
There is a petition on whitehouse.gov to get free identity theft insurance coverage for life: <a href="https:&#x2F;&#x2F;petitions.whitehouse.gov&#x2F;petition&#x2F;provide-lifetime-identity-protection-federal-employees-who-were-victimized-breach-opm" rel="nofollow">https:&#x2F;&#x2F;petitions.whitehouse.gov&#x2F;petition&#x2F;provide-lifetime-i...</a>
mirimir将近 10 年前
The NSA was slow in adapting to the Internet. Also, US cyberwar efforts have been too focused on offense. They&#x27;ve assumed technological superiority. That was safe 20 years ago (maybe even 10) but it&#x27;s clearly not safe now.
codesilverback将近 10 年前
So did anyone get fired?
评论 #9861178 未加载
ebel将近 10 年前
AWS Govcloud has a very small subset of AWS public features. Enough to get the job done though. Most importantly, it complies to all the FedRAMP, ITAR standards. The Government is just inherently slow in adopting and leveraging AWS&#x27;s awesome infrastructure.
justonepost将近 10 年前
What&#x27;s problematic about this is clearance data usually involves investigators asking questions of references of the applicant: &quot;Do you know anything that could be used to blackmail the applicant into revealing confidential information?&quot; If that sort of info was saved (even for those rejected clearance because they DID find something) and stolen in this hack, that could be rough going for a lot of folks.<p><a href="https:&#x2F;&#x2F;www.clearancejobs.com&#x2F;security_clearance_faq.pdf" rel="nofollow">https:&#x2F;&#x2F;www.clearancejobs.com&#x2F;security_clearance_faq.pdf</a><p>&quot;What will I be asked during a security clearance interview? During a ESI, the investigator will cover every item on your clearance application and have you confirm the accuracy and completeness of the information. You will be asked about a few matters that are not on your application, such as the handling of protected information, susceptibility to blackmail, and sexual misconduct. You will be asked to provide details regarding any potential security&#x2F;suitability issues. During a SPIN, the investigator will only cover the security&#x2F;suitability issue(s) that triggered the SPIN. The purpose of the SPIN is to afford the applicant the opportunity to refute or to confirm and provide details regarding the issue(s).&quot;<p>More:<p><a href="http:&#x2F;&#x2F;www.navytimes.com&#x2F;story&#x2F;military&#x2F;2015&#x2F;06&#x2F;17&#x2F;sf-86-security-clearance-breach-troops-affected-opm&#x2F;28866125&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.navytimes.com&#x2F;story&#x2F;military&#x2F;2015&#x2F;06&#x2F;17&#x2F;sf-86-sec...</a><p>&quot;They got everyone&#x27;s SF-86,&quot; one Pentagon official familiar with the investigation told Military Times.<p>&quot;The SF-86, a 127-page document, asks government employees to disclose information about family members, friends and past employment as well as details on alcohol and drug use, mental illness, credit ratings, bankruptcies, arrest records and court actions.&quot;<p>..<p><a href="http:&#x2F;&#x2F;news.clearancejobs.com&#x2F;2015&#x2F;06&#x2F;13&#x2F;sf-86-stolen-opm-hack&#x2F;" rel="nofollow">http:&#x2F;&#x2F;news.clearancejobs.com&#x2F;2015&#x2F;06&#x2F;13&#x2F;sf-86-stolen-opm-ha...</a><p>&quot;The entirety of at least some SF-85 and SF-86 background investigations held on OPM servers were breached, meaning sensitive data including relatives, spouses, and sensitive information on everything from mental health counseling to sexual behavior is now in the hands of the Chinese government.&quot;<p>And if you&#x27;re really bored:<p><a href="https:&#x2F;&#x2F;www.opm.gov&#x2F;Forms&#x2F;pdf_fill&#x2F;sf86.pdf" rel="nofollow">https:&#x2F;&#x2F;www.opm.gov&#x2F;Forms&#x2F;pdf_fill&#x2F;sf86.pdf</a>
评论 #9861972 未加载
spoiledtechie将近 10 年前
I would like to ask a question, but its real. How many of you yes and no, would be willing to go to war knowing that China is making a record of every single interesting person in the United States? Would you physically be willing to go to war over that fact? They are literally profiling us and it seems like the average US citizen gives 2 shits.
评论 #9861727 未加载