[url=http://meincmagazine.com/civis/viewtopic.php?p=27492255#p27492255:k91hvo94 said:Drakkenmensch[/url]":k91hvo94]As bad as it is that those employees' financial records have been exposed, there is a bigger issue here: how much damage could be done using the stolen information as authentication credentials?
Well, it's not like China needs to impersonate someone to get a credit card or something. This was probably to identify the security folks and get any supplemental info they could (connections in other countries, languages spoken, assignments, etc.). This is the kind of background-noise espionage we expect from foreign countries.[url=http://meincmagazine.com/civis/viewtopic.php?p=27492259#p27492259:2e88hp9s said:topham[/url]":2e88hp9s][url=http://meincmagazine.com/civis/viewtopic.php?p=27492255#p27492255:2e88hp9s said:Drakkenmensch[/url]":2e88hp9s]As bad as it is that those employees' financial records have been exposed, there is a bigger issue here: how much damage could be done using the stolen information as authentication credentials?
Think blackmail of people who provide security...
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492307#p27492307:2qbze3ws said:AJacobson[/url]":2qbze3ws]Imagine the NSA would use all its vast knowledge and resources to actually help secure IT infrastructure and communications instead of constantly undermining everything...
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492307#p27492307:25cb7ivt said:AJacobson[/url]":25cb7ivt]Imagine the NSA would use all its vast knowledge and resources to actually help secure IT infrastructure and communications instead of constantly undermining everything...
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492259#p27492259:27h8kqqe said:topham[/url]":27h8kqqe][url=http://meincmagazine.com/civis/viewtopic.php?p=27492255#p27492255:27h8kqqe said:Drakkenmensch[/url]":27h8kqqe]As bad as it is that those employees' financial records have been exposed, there is a bigger issue here: how much damage could be done using the stolen information as authentication credentials?
Think blackmail of people who provide security...
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492317#p27492317:877edrpt said:Skullsnstuff[/url]":877edrpt][url=http://meincmagazine.com/civis/viewtopic.php?p=27492307#p27492307:877edrpt said:AJacobson[/url]":877edrpt]Imagine the NSA would use all its vast knowledge and resources to actually help secure IT infrastructure and communications instead of constantly undermining everything...
That would undermine their abilities to spy on their own bosses in Congress and fellow security agencies. Wait, what was their mission again? I forgot and so did they.
I'm curious what repercussions the executive staff suffers (if any).[url=http://meincmagazine.com/civis/viewtopic.php?p=27492461#p27492461:1xspej5q said:Zathrus1[/url]":1xspej5q]It helps to remember that there are people who really do get hurt by this kind of shit.
This is why homosexuals couldn't get security clearances for a long time. Even if you were out of the closet, they assumed your lover or future lover might not be. There was some arduous process to get an exception, but it was probably easier to hide your orientation from the government than it was to get the exception.[url=http://meincmagazine.com/civis/viewtopic.php?p=27492429#p27492429:3cudngb8 said:Shavano[/url]":3cudngb8]DHS and the other TLAs do a lot to reduce the chance of blackmail -- or they're supposed to. Background checks exist largely to investigate whether there's something that could be used to blackmail you. If they find something, they make an assessment whether they think it's serious enough for you to actually risk effing jail time to not have it revealed. Usually the answer is no, but if the answer is yes, you aren't cleared.
But you have to be willing to put up with them looking under your fingernails. It's a high price, but if you pay it you know the government isn't worried about the stuff they found there, and they're usually right about whether what they know could be used against you in a serious way.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492601#p27492601:1dc4p5kd said:FrankM[/url]":1dc4p5kd]This is why homosexuals couldn't get security clearances for a long time. Even if you were out of the closet, they assumed your lover or future lover might not be. There was some arduous process to get an exception, but it was probably easier to hide your orientation from the government than it was to get the exception.[url=http://meincmagazine.com/civis/viewtopic.php?p=27492429#p27492429:1dc4p5kd said:Shavano[/url]":1dc4p5kd]DHS and the other TLAs do a lot to reduce the chance of blackmail -- or they're supposed to. Background checks exist largely to investigate whether there's something that could be used to blackmail you. If they find something, they make an assessment whether they think it's serious enough for you to actually risk effing jail time to not have it revealed. Usually the answer is no, but if the answer is yes, you aren't cleared.
But you have to be willing to put up with them looking under your fingernails. It's a high price, but if you pay it you know the government isn't worried about the stuff they found there, and they're usually right about whether what they know could be used against you in a serious way.
The policy did change at some point, but it was due to changing social acceptance of gays, not because the FBI investigators suddenly realized they were discriminating.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492321#p27492321:j9qmohnj said:otomo_1001[/url]":j9qmohnj][url=http://meincmagazine.com/civis/viewtopic.php?p=27492307#p27492307:j9qmohnj said:AJacobson[/url]":j9qmohnj]Imagine the NSA would use all its vast knowledge and resources to actually help secure IT infrastructure and communications instead of constantly undermining everything...
They already do that ...
The 'north american intelligence network' is turning into an oxymoron.[url=http://meincmagazine.com/civis/viewtopic.php?p=27492985#p27492985:3qtwyz3k said:Drakkenmensch[/url]":3qtwyz3k]Is it just me, or is the north american intelligence network turning into an episode of Archer?
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492255#p27492255:3w38mi1b said:Drakkenmensch[/url]":3w38mi1b]As bad as it is that those employees' financial records have been exposed, there is a bigger issue here: how much damage could be done using the stolen information as authentication credentials?
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492461#p27492461:zeoqfvf7 said:Zathrus1[/url]":zeoqfvf7]I
OPM (Office of Personnel Management) and DHS have pulled their contracts. He's been told that the company will not reopen for business until at least October. And even then it's questionable. I haven't seen any of this in news stories, but given that he had to file for unemployment, I think I'll believe his wife.
I don't know of any other hack that has led to a company being shutdown for a month... much less 2-3. It helps to remember that there are people who really do get hurt by this kind of shit.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492695#p27492695:ctlykzf1 said:beebee[/url]":ctlykzf1]I've had to give date of birth and SSN a number of time for base pass clearance. (A bare minimum background check.) I always assumed the data wasn't secure, but such data is easily obtained by hackers anyway.
But I always thought it was weird that the government didn't know this data anyway. Perhaps it was to insure they investigated the right person.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27493497#p27493497:xmpwvf67 said:Shmeelz[/url]":xmpwvf67]Huh. When I worked a shitty job at the bottom of the DHS totem pole (TSA), they lost my SF-85 (the fifteen page background check form). Along with a few thousand others. After two years of employment, they told us we all had to fill the thing out again because they weren't sure if anyone's background check was actually done. Or who, if anyone, actually had all that paperwork.
Of course, they couldn't blame Chinese hackers for disappearing paperwork. But at least they paid the same worthless contractor to gather the same information again.
Good to see they're just as careful with the information now that it's on a computer. Incompetent, but faster!
One million mistakes per second![url=http://meincmagazine.com/civis/viewtopic.php?p=27493497#p27493497:317cy1cw said:Shmeelz[/url]":317cy1cw]Good to see they're just as careful with the information now that it's on a computer. Incompetent, but faster!
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492397#p27492397:8zgstdgo said:dlux[/url]":8zgstdgo]Remember when Microsoft had to drop everything in the early 2000s to address their security problems (thus delaying Longhorn/Vista in the process)? Remember when the entire software industry had to drop everything to address the Y2K problem?
That's the level of attention that we need for our various databases and accounts. Right now.
Anything less at this point is gross negligence, and there should be jail time for anyone who behaves otherwise. I don't think people are taking the stakes seriously anymore.
There are no more excuses, right on up to the CEO and Presidential level.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492247#p27492247:16iy07cz said:Netguru[/url]":16iy07cz]If companies like these can't secure their networks, who the hell can?
[url=http://meincmagazine.com/civis/viewtopic.php?p=27494043#p27494043:2m9me24j said:eduardopozo56[/url]":2m9me24j][url=http://meincmagazine.com/civis/viewtopic.php?p=27492247#p27492247:2m9me24j said:Netguru[/url]":2m9me24j]If companies like these can't secure their networks, who the hell can?
They CAN secure their networks. But that costs money, time and resources.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492471#p27492471:mk6acwo1 said:dlux[/url]":mk6acwo1]I'm curious what repercussions the executive staff suffers (if any).[url=http://meincmagazine.com/civis/viewtopic.php?p=27492461#p27492461:mk6acwo1 said:Zathrus1[/url]":mk6acwo1]It helps to remember that there are people who really do get hurt by this kind of shit.
[url=http://meincmagazine.com/civis/viewtopic.php?p=27492253#p27492253:4zb63pnp said:boottux[/url]":4zb63pnp]I'm trying to think of the next big thing I can claim to do for money but can't and people will still pay me anyway.
Nice work if you can get it.
But on a more serious note. It will only get worse.