7 ms·
US hit by 'massive data breach'
- Zikes 11y agohttps://news.ycombinator.com/item?id=9661848 https://news.ycombinator.com/item?id=9661848 I am shocked. Shocked, I tell you.
- deleted 11y ago[deleted]
- jsingleton 11y agoBit short currently. Looks like more detail from these sources: http://mashable.com/2015/06/04/data-breach-hack/ http://mashable.com/2015/06/04/data-breach-hack/ http://www.washingtonpost.com/world/national-security/chinese-hackers-breach-federal-governments-personnel-office/2015/06/04/889c0e52-0af7-11e5-95fd-d580f1c5d44e_story.html http://www.washingtonpost.com/world/national-security/chines...
- sehugg 11y agoArs too: http://arstechnica.com/security/2015/06/federal-agency-hit-by-chinese-hackers-around-4-million-employees-affected/ http://arstechnica.com/security/2015/06/federal-agency-hit-b...
- austenallred 11y agoLooks like officials suspect it originated in china https://grasswire.com/data-breach https://grasswire.com/data-breach
- redwards510 11y agoWhat would be a suitable response to this? America does not have a clear cyberwar policy and I haven't heard many suggestions.
- fixermark 11y agoDo they have any centrifuges that need to be exploded? ;)
- JohnTHaller 11y agoWell, they could confront the issue instead of publicly ignoring it for a change. Haven't heard much about China's massive DDoS against github. Even github won't point the finger at China even though it was clearly done at the Great Firewall.
- deleted 11y ago[deleted]
- a3n 11y agoA suitable response would be to present proof of what happened and who did it, then pursue law enforcement solutions and public shaming. If this had been a land incursion, and the public Army had been the responding department, there'd be no question, and we'd have pictures of tanks and AK-47s on the front page of every newspaper. Congress would be discussing nothing else. However, it's the spies, and FBI wannabe-spies that are probably handling this. The proof is not as obvious as a tank in North Dakota, but I suspect that there's is enough evidence and forensics to prove to the NSA and their ilk who did it and how. But a spy's natural instinct is to hide the fact that they know something. It's a card up the sleeve, and their concern is more about being able to continue to spy than to stop a currently ongoing crime.
- themeek 11y agoThe US is trying to establish norms for cyber operations in the international community - this is a missing and critical piece. But the US does have cyberwarfare policies. As part of a deterrence strategy the US strikes back when it can attribute attacks to a specific party. You may also remember the recent Executive Order from the Obama Administration whereby a series of policies were joined so that the US is organized to levy sanctions against governments, actors and corporations overseas that are involved in sponsoring intrusions into US networks.
- gress 11y agoIf only there had been a backdoor in the system, or no encryption, law enforcement could have prevented this. /s
- themeek 11y agoThe US government has some of the best CNA/E defense anywhere in the world - certainly better than almost all of industry - even departments that you would otherwise think are puny. The backdooring and lack of encryption in software is because the US is still a primary exporter of technology and we want to be able to continue to hack, surveil, message and control those who get US technology. US FedRAMP and other compliance minimums insist on the use of properly configured encryption in private industry to protect government information and cyber sharing programs enable both the sharing of data between private and public sectors for surveillance and for the detection and analysis of foreign cyber attacks. The US government has state of the art encryption (for the most part) and some of the most heavily monitored perimeters. None of this is enough to stop cyberattacks, which have all of the advantages in their favor. So while I'm inclined to agree with you that the US should stop mandating backdoors and weak encryption I don't think its a fair characterization to suggest this anything to do with why the US was breached. China and the US are battling each other in several arenas of influence, as are Russia and the US. In this case the US is trying to stop Russia and China's global and regional power projection and these countries do not accept the US world order and their current place in it. Conflict is inevitable. It will be interesting to read the history books to see what gets written about the role of the information warfare space and what role it plays in whatever outcome we get.
- Dewie3 11y ago> The backdooring and lack of encryption in software is because the US is still a primary exporter of technology and we want to be able to continue to hack, surveil, message and control those who get US technology. Booh.
- colinbartlett 11y agoWhat is CNA/E? Google wasn't helpful.
- rmrfrmrf 11y agoIt's OK, I'm sure whoever did it had a warrant.
- ephemeralgomi 11y agowhat differentiates a 'cyber database' from a 'database'
- ra1n85 11y agoThe former was built for millions of dollars by the low bidder with a great sales team.
- colinbartlett 11y agoGreat sales team? How about well-connected principals who donate to candidates with the power to decide on the contract.
- supergirl 11y agothe first one is cyber, the second is not.
- deleted 11y ago[deleted]
- elchief 11y agoThe former is uttered by someone who doesn't know what "cyber" or "database" means.
- yellowapple 11y agoThe serious answer is that there are such things as non-electronic databases.
- unclebucknasty 11y agoThe former is much more akin to an "e-database".
- themeek 11y agoThis is part of an ongoing cyberwar between great powers - the largest adversaries to the US being China (mostly smash and grab) and Russia (primarily sophisticated and surgical). It would be nice if there was some place where we could see the scoreboard to know how effective and how often we hack the Chinese back. Right now it looks like our tax dollars are being spent getting hacked, but the US government has doubled down many times on offensive cyberwar capabilities and now have professional cybersoldier career tracks in the DoD. What's the assessment?
- goodcanadian 11y agoActually, this is an interesting question. The U.S. may well be hacking China left, right, and centre. There is nothing forcing China to disclose when they are hacked. There might be political advantage in loudly complaining. On the other hand, they might find it better not to admit weakness, especially to their own people.
- themeek 11y agoThe US undoubtedly hacks China, though there's some forms of asymmetry whereby the US has more to lose. There's also a language and media bubble that filters out information and criticisms of the United States. These bi- and multi-lateral criticisms happen all the time but rarely are subject of US media reporting.
- goodcanadian 11y agoFair point, but you are assuming I rely on U.S. media reporting. I most certainly do not; in fact, I pay little attention to U.S. media reporting. I do rely on English language reporting, however.
- themeek 11y ago:) Thanks good Canadian. Yes, I am speaking primary to a US audience and from my own experience as a US citizen. As a tangent - how is Canadian reporting overall? Is it reliable?
- ChrisAntaki 11y agoThis is a great example of why the NSA & FBI should invest in strengthening American encryption standards, instead of trying to weaken them.
- mpyne 11y agoWhy? Actually using existing standards would have worked just fine. Making existing standards easier to use might have helped, but the problems in government use of IT extend far deeper than just the choice of crypto standards.
- SCAQTony 11y agoHuge data breech and the FBI is screaming from an Ivory tower that encryption is hallmark of all evil and that backdoors are a really good idea. ""Privacy, above all other things, including safety and freedom from terrorism, is not where we want to go..."" FBI Associate director Michael Steinbach
- themeek 11y agoThe USG reserves the use of backdoor-free software and strong encryption for itself, so I'm not sure that this is a worry with regard to the recent data breach. The FBI means that consumers and foreign markets should not have encryption or backdoor-free software. I understand that this is a double standard, but we need to be clear that the double standard doesn't have to do with this most recent breach.
- mc808 11y agoIt is relevant in the general sense that it would only be a matter of time before a "massive data breach" included the keys/procedures to open some or all of the backdoors.
- themeek 11y agoI see. This has already been done. During Operation Aurora the Chinese hacked into the FBI backdoor built into GMail by Google and used it to gather information about intelligence operations being performed by the United States against Chinese nationals and also used it to perform surveillance of their own against their terrorist and dissident watch lists. There are probably more examples. I do not know of a single database that has 'all the keys' to the all software and encryption back doors. If such a thing existed it would be a very valuable target. Somehow, though, I imagine that there isn't such a centralized database.
- yellowapple 11y agoThere isn't such a centralized database yet. With NSA surveillance and FBI calls for backdoors, that is quickly changing as various three-letter-agencies gobble up all the data they physically can and in the process make themselves easy and obvious targets.
- Red_Tarsius 11y agoI wonder how much social engineering was involved in the hack. No matter how great is your tech, if your staff is not trained to be paranoid you're going to suffer the consequences. "Hey I just found a usb pen on the floor. I wonder what it's inside it..."
- fieryscribe 11y agoThe timing of this report is very "interesting", given recent news: https://news.ycombinator.com/item?id=9659784 https://news.ycombinator.com/item?id=9659784
- bashinator 11y ago* cyber attack * cybersecurity system * cyber-intrusion * cyber databases (twice!) * cyber threat Use of the word "cyber" adds virtually no insight or context to this article.
- bhauer 11y ago"Cyber databases" was the clincher for me. At least all of the others are using the adjective to (ostensibly) distinguish from a more general version of the same. A cyber-attack versus a straight-up physical attack. A cyber-intrusion versus physical trespassing. But who uses the term "database" to refer to anything but a store of data on a computer system? I realize the BBC has some old-fashioned style guide it's using here, but "cyber databases" betrays a bit of a need to revisit that guide. Edit: I've made a couple of recommended edits for the BBC as seen here: http://i.imgur.com/cewmams.png http://i.imgur.com/cewmams.png
- yellowapple 11y ago> But who uses the term "database" to refer to anything but a store of data on a computer system? Technically, a "database" is just an organized collection of data. While nowadays it's increasingly rare to encounter a non-electronic database, these were once upon very commonplace. One specific example that I recall rather fondly is the list of Dewey Decimal cards that libraries would keep in narrow file cabinets so that users could search through them and find the books they wanted. While my school library's catalog was already digitized, I still used these cards sometimes, finding books that had been omitted from the digital system for whatever reason (though these were eventually cleaned up when the digital system itself started to include the creation of spine labels, thus causing non-cataloged books to become more obvious).
- bhauer 11y agoI am familiar with the term as it was used prior to computers. But the BBC's insistence on qualifying a database as a "cyber-database" in 2015 is gross anachronism the likes of using the phrases "touch-tone phone" or "world-wide web."
- cm2187 11y agoIt's hard not to make this trivial comment so let's make it: At least it may give a taste to US nationals of what it feels like to have your country hacked by a foreign power, like most European countries nationals felt after the Snowden leaks.
- themeek 11y agoOh this isn't new. There has been cyberwarfare now for close to two decades, although there's certainly been increasing amounts of activity. The US of course will reply in kind. It is US defense policy in cyber to retaliate for cyber attacks - specifically this is part of a deterrence strategy.
- chc 11y agoYou seem to think this is something the US is unfamiliar with. The US has been one of the largest targets of attacks for a long time now. This is just the first time the government itself has been attacked on such a large scale rather than private parties. (See http://map.ipviking.com/ http://map.ipviking.com/ if you want a live demonstration.)
- coldtea 11y ago>You seem to think this is something the US is unfamiliar with. The US has been one of the largest targets of attacks for a long time now. Or so they say -- to make the case for more budget and that they are "victims too" not just agressors. And of course to paint some provincial BS backwaters as "credible threats".
- chc 11y agoIt seems both unrealistic and weirdly dismissive toward China to call them a "provincial backwater" and suggest they don't have computer experts capable of attacking US targets.
- coldtea 11y agoThey have some. And there's some stuff happening. So? China will do with it what exactly? US, for example, uses their data aggresively all the time to get leverage on trade agreements and diplomacy, including on its European "allies". China doesn't seem to do much of those kind of shenanigans, except with Asian countries, and certainly not to the US.
- jacinda 11y agoAs a former government contractor, I wish I could say I'm surprised. Unfortunately, computer/network security in many government agencies frequently has more to do with policy documents than with anyone technical actually determining whether the system is secure.
- yellowapple 11y agoWhich explains why the FBI thinks backdooring encryption is a good idea, despite it being the literal opposite of one.
- danso 11y agoInterested in hearing the details about this one. How much of it was facilitated by phishing or social engineering? Are there any government systems that require two-factor auth? So much of federal web infrastructure is based on old code/systems that, while invulnerable to a mass exploit of Rails/WordPress/Bash, have not even remotely been tested and studied against edge cases in the way that large scale open source platforms have.
- dpweb 11y agoOf course, China. How is it they are incompetent to protect the data, yet competent enough to know immediately who did it.
- themeek 11y agoStopping Computer Network Exploitation is very, very difficult (the attacks happen at close to the speed of light). However with appropriate signals intelligence, sources of attacks can be determined. We don't know that China was really behind these attacks, but the US has a pretty good track record at attestation so far.
- jessaustin 11y agoHow would we know? The most notable attestation I can think of was NK-Sony, and that is dubious at best. I'll stipulate that China is behind lots of hacks, but that means attributing any particular one to them could be just a good guess.
- themeek 11y agoThe NK-SONY episode was undoubtedly NK or NK-sympathizers. The malware analysis from Fireeye is a good start for this (it was a variant of malware used by NK to target SK media outlets that run negative press against the regime, was compiled with Korean character sets, and much more), but it's also true that the motive of the hack, written by the Guardians of Peace themselves, was to punish the US for the State Department and CIA's involvement in the creation of The Interview and the plans to get the movie into NK. Curiously linguistic analysis of the Guardian of Peace messages suggest that the author was possibly Russian and variants of the malware package had also been used in an Iranian attack on US oil companies in the Middle East. (These nations are known to collaborate in malware development and tactics, tools and proceedures.)
- foxhedgehog 11y agoA lot of people here are commenting, rightly, that this is an example of why the USG should be strengthening encryption. It's also a reminder that, despite its disproportionate focus in media, including on HN, the US is obviously not the only government engaged in this behavior.
- nedwin 11y agoWe hear a lot about Chinese attacks on the US but virtually nothing about the opposite, which undoubtably does happen. Reading the wiki page on "Cyberwarfare" there are sections on each country, like "Cyberwarfare in Germany", "Cyberwarfare in India" etc. Both the "Cyberwarfare in USA" and Cyberwarfare in China" are about Chinese attacks on the US... http://en.wikipedia.org/wiki/Cyberwarfare http://en.wikipedia.org/wiki/Cyberwarfare
- cm2187 11y agoI presume you would need to search the web in chinese, not in english, to read about those.
- sanderjd 11y agoThat's too bad. Theoretically, we have english-language journalistic institutions doing that for us.
- Sideloader 11y agoThey generally toe the official government line, at least the mainstream media does. The opinion pages contain the odd piece here and there that deviates from this narrow perspective. But don't rely on the English-language (or any language) media to present an unbiased viewpoint that gives equal weight to both sides of an argument when it involves the US or an ally/client state and an "enemy" state like China or Iran.
- devnul3 11y agoYou think Snowden, GG, wikileaks, etc toe the government line?
- themeekforgotpw 11y agoI think he means CNN, Fox, MSN, NBC, NPR, etc. https://wikileaks.org/sony/emails/emailid/133736 https://wikileaks.org/sony/emails/emailid/133736 (From the State Department to the CEO of SONY.)
- thyrsus 11y agoNote the Office of Personnel Management's scores in this report, and note the scores of the State Department. Ms. Clinton's e-mails may have been more secure at her private residence :-\ https://www.whitehouse.gov/sites/default/files/omb/assets/egov_docs/final_fy14_fisma_report_02_27_2015.pdf https://www.whitehouse.gov/sites/default/files/omb/assets/eg...
- blisterpeanuts 11y agoThis is perhaps a stupid or uninformed question, but if databases are so vulnerable, why is so much information still stored in cleartext? It seems to me that taking the extra step to strongly encrypt data prior to writing to tables would make the intruder's job much harder. I speak not only as a programmer and database guy from way back, but as one of the millions of Anthem subscribers whose personal data was stolen a few months ago in a massive breach. I know that "data breach" might well mean the keys were stolen which decrypted an otherwise secure file, but the terminology suggests that the breach was simple access into the system rather than acquisition of the precious keys themselves. Someone with superior knowledge of these things, kindly explain.
- tokenizerrr 11y agoWhere will you store the key?
- droopybuns 11y agoIf it's a relational database, the core function of the database is to make it searchable. If you encrypt the fields, you have to decrypt everything to search them. So if search or relationships are important to you, encrypting the whole database would be disruptive. There is a type of encryption called "homomorphic" which could allow you to perform operations on encrypted information. I haven't ever tried to implement it and consider it one of those seductive ideas that probably can't get implemented correctly in practice. But if there was a way to deliver an entire encrypted database and still make it useful, homomorphic encryption is the only way I am aware of that would make it work.
- jessaustin 11y agoPerhaps the data you need to search is not the same as the data you might want to encrypt? For instance name, address, ssn (or similar), billing info, etc. could all be encrypted and you could still look for e.g. 50yo women in the Northeast USA who haven't had a checkup in the last three years. Of course many DBs need to search by name, but maybe it can be set up to search by a hash of name? Hashes seem a bit simpler than homomorphic search.
- dpcan 11y agoI feel like we need to change our direction in terms of "identity" all together. We seem to be relying on an "identity" that is our name, ssn, phone number, credit card number, or all these different little bits of data clumped together. Too messy, too easy to steal, to fake, to easy to sell. Maybe our identity is more like a bitcoin wallet. It's an encrypted clump of data that we only keep with ourselves, and ourselves alone. It could store money, confirm that we are who we say we are because it can have our picture in it, our names, our "numbers" for various things. Then, when someone needs ANYTHING from us, be it proof of identity, money, or trivial info, we can send them a piece of useless information salted with something that they then return to us with the same salt to get back a confirmation, or money, or access to "use" our other numbers, but they never GET our other numbers. If you want my phone number, you send a request to me asking for it. I get the request, confirm it, send back another piece of data to you. This is NOT my phone number, but something you can use to send to me again in the future when you want to call me, and then my number is dialed, but you never see it. At any time, I can wipe you off my safe list, and you don't have my phone number anymore. Same thing can work when paying for something, or proving I am who I say I am when getting a loan, buying beer, whatever. Maybe this is ridiculous.
- bikeshack 11y agoA great talk by Jake Appelbaum that one should watch: https://www.youtube.com/watch?v=6kilAPZ-vGA https://www.youtube.com/watch?v=6kilAPZ-vGA A very in depth and revealing talk about the current state of the union of 'identity' on the web and the apparent digital doppelgängers we carry around with us. Frankly the notion of a digital doppelgänger is hillarious and identity is not a hard problem when people are effectively schizoid when they surf and flitter between multiple idens all the time.
- dpcan 11y agoInteresting, thank you for the video link
- higherpurpose 11y ago
- fleitz 11y agoIt's not a data breach, it's essential that the US keep their database unencrypted so that the Chinese national security agency can search their records for ties to terrorism. If anything China just did the OPM a favour to help them keep their freedom.
- multinglets 11y agoOh no, the Chinese are stealing all our datas in an unprecedented cYbErattack! I didn't realize it was Thursday again already.
- ams6110 11y agoThe breach did not involve background checks and clearance investigations, officials said. No, that breach[1] was a couple of years ago. 1: http://www.nextgov.com/cybersecurity/2014/12/opm-alerts-feds-second-background-check-breach/101622/ http://www.nextgov.com/cybersecurity/2014/12/opm-alerts-feds...
- sgacka 11y agoThis hit every US news service. How is it so low in points? "breach could potentially affect every federal agency, officials said" I love HN's ability to filter news that matters to dev/tech-professionals, but when stuff like this pops up it should be top 10, for at _least_ a few hours. This is some serious shit. Who here does business with government agencies? Most of you have IRS Tax/Employer IDs... with the rate that this is "expanding" what is to say that it wasn't just HR records, but more. Your e-filed IRS return could be sitting with folks outside of the IRS... No intention to fear monger but think of the statement "breach could potentially affect every federal agency" - every business in the US does something, with sensitive data, with an agency :/
- deleted 11y ago[deleted]