3 ms·
FBI’s Vetted Info Sharing Network ‘InfraGard’ Hacked
- doodlebugging 4y agoWhen I was a kid back in the 60's we had a joke that FBI stood for Fat, Bald, and Ignorant. Since I was a kid a long time ago and there are probably a lot of people my age (50-60's) at the FBI, maybe this old joke was prescient.
- _8j50 4y agoThe FBI has changed a lot over the years like any org. In the 60s they weren't that different from corporate america. Now too, they reflect corporate america in many ways. Most of their employees want to do good. Their big flaw is they think from a "bigger fish" and heavy handed "I am an agent of the US!" Perspective, kind of like how the airforce's answer to most problems is a bomb. But of course reality is a bit more nuanced than my reduction.
- _8j50 4y agoHah! I was asked to join this multiple times and I refused because they do an FBI background check. Not that I have anything to hide, employers already do a background check but I didn't like volunteering to let the government be part of the equation as part of my day to day stuff and I hear they dig around quite a bit. Other similar orgs vet by simply asking someone at your org to vouch for you (a popular example is virustotal). In europe these orgs are -CERT and in the US they are -ISAC for those who don't know (industry specific intel sharing) but Infragard is all encompassing as an org to share intel between FBI and private sector. I can't imagine it would be much use. Targeted phishing maybe using this list? But then again people on the list are the most likely folks to be best trained and aware against phishing. On the other hand they would alsobe likely to have privileged accounts at their org. I don't think the breach is a big deal other than showing a weakness in the FBIs vetting process.
- opensores 4y agohttps://en.wikipedia.org/wiki/InfraGard https://en.wikipedia.org/wiki/InfraGard My guess is that the haxors will get paid off by the pwned. Whether "Pompompurin" gets caught after "negotiations" remains to be seen, although the public may never hear about this. https://www.extremetech.com/internet/341596-hacker-infiltrates-fbi-portal-lists-details-of-87000-users-for-sale https://www.extremetech.com/internet/341596-hacker-infiltrat... USDoD says their asking price may appear a bit high given some users’ email addresses, Social Security numbers, and dates of birth are missing from the list. The $50k asking price was supposedly a negotiation starter and not a final offer, according to a follow-up comment on the original post. USDoD says the sale, should they find an appropriate buyer, would be facilitated via the Breached administrator who goes by “Pompompurin.” The FBI confirmed the breach earlier this week but has declined to publicly comment on the matter, saying only that the situation is “ongoing.”