9 ms·
Data on 7% of Americans Were Just Hacked, Now What?
- eli 11y ago> Worse… access to ALL of this information was given to certain foreign contractors, some of whom were in China. Pretty sure this is unproven and, regardless, had nothing to do with the hack.
- wvenable 11y agoBut it has everything to do with the security of your information.
- polymatter 11y agoI'm not sure if it was edited, but reference to China has now gone.
- eli 11y agoYes, it was silently edited, which is not a particularly classy move. I think this whole "foreign contractors" angle is sourced to a single anonymous ex-contractor speaking to Ars. Even if true, I don't think there's any evidence it has anything to do with this hack.
- shea256 11y agoHi author here. Thank you for pointing this out and sorry, I meant to mention that I edited it.
- eli 11y agoNo worries, I'm definitely guilty of quickly editing my own comments to phrase them better :) I still feel like I'm a little lost in the essay, though. It's easy to say that all data requires senior people to sign off before data can be decrypted. But that sounds really hard to implement and even harder to legislate. What specifically are you asking for? What am I supposed to be asking my representative to do?
- ExpiredLink 11y agoThe post was modified in the meantime.
- jganetsk 11y agoDoes anyone know if the OPM's data included Global Entry?
- jessriedel 11y agoI don't, but the NYTimes says this: > Every person given a government background check for the last 15 years was probably affected, the Office of Personnel Management http://www.nytimes.com/2015/07/10/us/office-of-personnel-management-hackers-got-data-of-millions.html http://www.nytimes.com/2015/07/10/us/office-of-personnel-man... Not sure if Global Entry / NEXUS is considered a background check, since they are certainly less intensive than the one done for a security clearance, but it doesn't sound good.
- jwildeboer 11y agoExactly why is $AUTHOR so sure it was a foreign power that hacked OPM? Which proof can $AUTHOR provide besides unfounded rumours? It's just too simple.
- tedunangst 11y agoThe author of the post isn't variable.
- deleted 11y ago[deleted]
- Shivetya 11y agoI am not sure what is actually the worst thing we learned here, that this many people were hacked or this percentage is/was employed by the US government
- DennisP 11y agoIt's not just those employed. A family member of mine has a security clearance, and let me know that I'd be one of the 20 million with my SSN exposed, since I was one of the people the government checked on when doing his clearance.
- sgs1370 11y agoAnd DOB of your family member, unless the forms have changed. Also (not related to your family), when you're trying to identify yourself on the phone to a credit card or bank (etc.) because you are starting with them or "lost your password", they usually quiz you - almost all of the questions can be answered if you know the previous addresses.
- ams6110 11y agoThis is what needs to change. Personal trivia can no longer serve as proof of identity. We need to make the personal data useless for identity thieves.
- jessriedel 11y agoI wish alternative strategies like "stop having the government collect and store information" would be considered in these situation.
- dragonwriter 11y ago> I wish alternative strategies like "stop having the government collect and store information" would be considered in these situation. I don't think nixing collection for background checks is viable, though limiting the scope (EDIT: both of data collected and the scope of applications for which government background checks are mandated) might be. Similarly, limiting both the scope of data retained and the duration for which it is retained from such checks after the decision they support is made might be viable, though there are costs (among other things, to the accountability of government decision makers) as well as benefits to that.
- pdkl95 11y agoThis is the only real solution, as it directly addresses the real problem: interdependence. As Dan Geer described[1] the problem: ... risk is a consequence of dependence. Because of shared dependence, aggregate societal dependence on the Internet is not estimable. If dependencies are not estimable, they will be underestimated. If they are underestimated, they will not be made secure over the long run, only over the short. As the risks become increasingly unlikely to appear, the interval between events will grow longer. As the latency between events grows, the assumption that safety has been achieved will also grow, thus fueling increased dependence in what is now a positive feedback loop. Accommodating old methods and Internet rejectionists preserves alternate, less complex, more durable means and therefore bounds dependence. Bounding dependence is *the* core of rational risk management. In software we've had to face this problem of expanding complexity and interdependency so often we have numerous names for the problem like "spaghetti code" and "DLL hell". Numerous techniques have been invented to try and mitigate dependency problems (e.g. "information hiding" with functions and classes, UNIX-style problem separation and component reuse). With Rust, we have even designed an entire programming language with complicated and usual memory management features, with the goal of eliminating some types of interdependent pointer semantics. Even with all that effort, the good designer knows to ask the question "Did we really need to depend on $LIBRARY?". Unfortunately, there are may other areas of our society that are just starting to learn about complexity at this scale, and do not understand why it might be an absolutely terrible idea to replace an old system that worked with a new piece of software that creates a dependency on the internet. There will be a lot of people that end up having to learn the hard way why it might have been a bad idea to change a security problem form "lock it in a thick-walled room behind a lot of people with guns" into something that probably reduces to Halting Problem. [1] http://geer.tinho.net/geer.blackhat.6viii14.txt http://geer.tinho.net/geer.blackhat.6viii14.txt
- bargl 11y agoIs it sad that because I have worked on government systems in the past that this does not surprise me at all? It makes me mad, but it is not at all surprising. The negligence on government software is crazy. That is on top of the regulations that basically don't allow developers to use new/open source technology. While new technologies wouldn't have prevented this by themselves, they might have made it easier to encrypt data so the devs would have said, "oh yeah we can do that". Or they might have had defaults that prevent simple things like cross site scripting.
- __john 11y agoSpot on, most software gets disapproved simply for being open source or liberally licensed. Although recently I've found that it's easier to get open source software on my computer if I can prove that it already exists somewhere else on our network (i.e. we use Redhat servers which come with Python pre-installed after I pointed that out getting Python on my personal box wasn't much of an issue)
- RRRA 11y ago... Because the government is keeping everyone insecure so they can hack other nations and themselves?
- mangeletti 11y ago7% of American't were not "just hacked"[1]. Perhaps the HN title should be changed to avoid misleading users herein. The title is very much click bait. 1. https://en.wikipedia.org/wiki/Hacker_%28computer_security%29 https://en.wikipedia.org/wiki/Hacker_%28computer_security%29
- lisper 11y agoI downvoted you because you need to support your claim. 21 million Americans had their personal information compromised. That's 7% of the ~300M population. Summarizing that state of affairs as "7% of Americans were hacked" seems reasonable to me.
- mangeletti 11y agoWhile I do appreciate your honesty (re: downvote), gaining access to my information isn't intrinsically hacking[1]. Hacking might be the means of gaining the information. In this case, hacking did take place, but not the hacking of 21 million Americans, rather on some government servers. I've added citation to my original comment. Anyway, it doesn't matter because the OP was flagged into oblivion. 1. https://en.wikipedia.org/wiki/Hacker_%28computer_security%29 https://en.wikipedia.org/wiki/Hacker_%28computer_security%29
- lisper 11y ago> gaining access to my information isn't intrinsically hacking Perhaps not, but saying "I was hacked" is a commonly used colloquialism that means, "My supposedly secure personal information was compromised." But I guess it's a moot point now.
- deleted 11y ago[deleted]
- gmuslera 11y ago99% were hacked the last decade, along with most of the rest of the world, by an US government agency. If people didn't care about that, why you expect sympathy for this one?
- kanusterkund 11y agoHack me twice, can't get hacked again, right?
- deleted 11y ago[deleted]
- tslug 11y agoI'm always amused by these "here's how to protect data better" articles, because today's security is tomorrow's joke, and that's how we got here with the OPM hack. The only way to get ahead of it is to make it so that all private data is public and thus devalued. Privacy creates liability. Visibility creates value. The problem we have right now is the idea that one entity should have domain over any information. That's what we need to get over. It should be shared- all of it, from bank security cameras down to what you're doing in the shower. When all surveillance is shared, you find that people suddenly get a lot more tolerant, because throwing stones in glass houses isn't helpful. The Earth is a closed system. We have finite, shared resources. Privacy creates the fiction that it's not a closed system. You think that's how the space station works? Is that how you want it to work? No, you want cameras on everything, because if someone decides to experiment with the CO2 scrubbers, it affects everyone. The same is true here on Earth. We're now in an age where one person or company or government can single-handedly change the habitability of the entire planet, such as Exxon did in the 80s. That's dangerous. And meanwhile, there's incredibly valuable, life-saving services and conveniences we can all enjoy if we are open with all our surveillance data. How many lives could be saved or improved if we all had a smartwatch measuring our vitals and our food intake and toilet waste were monitored? That one change could single-handedly resolve most of our healthcare issues in the US. What we really need instead of privacy is complete visibility coupled with a code of conduct that emulates the benefits we expect from privacy. Just because we can see everything doesn't mean we have a right to bother people with what we know. That's the issue we need to address. By all means, check out whomever in the shower, but that doesn't give you a right to interfere with that person's life by commenting on their genitalia. That's the key ingredient we're missing from the privacy conversation. We like privacy because we equate it with civility and thus freedom. If someone doesn't know something, then they can't make you miserable with it. But that doesn't really work anymore. Even if someone doesn't know something, big data techniques can interpolate what it is they're not supposed to know. What you're really signing up for with "privacy" is granting visibility to only a privileged few- the spy agencies, the multinational companies, the hackers, and anyone willing to pay for the information.
- miguelrochefort 11y agoEverything you said is correct. Where can I find like-minded people that understand the sustainability of total transparency? I've been struggling to find such a community for years.
- mangeletti 11y agoThe article's title was just edited[1] to read, "Data on 7% of Americans Was Just Hacked, Now What?". This is apparently a living document. 1. http://webcache.googleusercontent.com/search?q=cache:WKgL8jW-Zb0J:blog.onename.com/americans-hacked-opm/+&cd=1&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:WKgL8jW...
- shea256 11y agoYes, I responded to your helpful feedback. Thank you.
- mangeletti 11y agoThanks, Ryan. Despite the fairly negative nature (calling it "click bait") of my prior request, you took it for its objective value. That was pretty big of you.
- TheMagicHorsey 11y agoWhy is everyone so shocked? Has anyone ever talked to a friend that works for the Federal govt.? They are well known to be completely incompetent when it comes to technology. Even the DoD, which gets billions of dollars for cyber defense, often doesn't do things right. How can you expect the Fed. Govt. to handle things competently when some of the best paid private contractors F' things up too. Security is hard. What IS a bit surprising is not the fact that they were hacked, but that they actually found out they were hacked. From what I understand, the Fed. Govt. has lost even more important data (like designs for weapon systems), and not even realized it till like years later when the technology shows up in foreign weapons.
- narrator 11y agoMaybe some parts of the government aren't competent but the NSA is pretty good at what they do.
- DennisP 11y agoPretty good at the surveillance side, but evidently not so good at their other mandate, which is to help the rest of the government secure their stuff.
- kalleboo 11y agoEven the NSA isn't perfect though. Don't forget that Snowden managed to steal hundreds of thousands of documents, and the NSA doesn't even know exactly WHAT he got or not...
- icebraining 11y agothe NSA doesn't even know exactly WHAT he got or not... Or so they say.
- miguelrochefort 11y ago> Security is hard. Security is impossible.
- 11y ago
- informatimago 11y agoI don't see that as a problem. At all. The US government (NSA, CIA, etc) has files on most of the people on the planet (including close spying of most governments, politicians and important corporations worldwide). I don't see how somebody else having 20 million records on US people would change anything. On the other hand, if personal and important information about the activities (behind the curtain) of all those politicians, banksters and big corporations, american or not, was accessible to the public, perhaps things would change.
- elorant 11y agoThat somebody else could be someone who tries identity theft, or worse. And information about state actors has been published, that's what the WikiLeaks case is all about. I don't think it had the effect you might hope for but just because the government acts badly doesn't mean they're the worst predators out there. We also live in a world of industrial espionage. What if someone in this list is the CEO of multibillion corporation with a serious health problem that he/she kept secret. You publish the health records and the stock tanks. Or someone who works as a contractor for the army. There are nightmarish scenarios of what could be done with all that kind of information. There are even fingerprints in there.
- marcoperaza 11y agoExcept that what leaked out is the background checks of almost all of the people that have a security clearance. There's a lot potential for someone to use that information to blackmail ("I'll tell your wife about that affair you had 10 years ago") or socially engineer (pretend to be someone else) their way to the very secrets this process is supposed to protect.
- a3n 11y agoAnd at least links to all their family, friends and associates. Making those people targets for further data theft.
- Qantourisc 11y agoIf it's such a big deal to loose / get the data stolen. Should you have been storing it in the first place ? And if you do really need it, like fingerprints, start by using a hash. The other data you wish to keep are current data (not history): ssn, address, family(maybe you should be able to opt out of that, but risk them no getting contacted in certain situations) Medical records? Have a standard form that list anything important: allergies, blood-type. Well that's my (maybe naive) view on it.
- deleted 11y ago[deleted]
- 1971genocide 11y agoI am so happy this is happening ! I always felt cryptography was treated as a back room kind of operations. We are all so busy making iOS apps. The real computer science has always taken a back seat. Hopefully MORE such breeches occurs and investment in security recieves the kind of investment and respect it deserves. We are all so focused on this MBA growth bullshit. Time to do some real computer science !
- 1971genocide 11y agoI remember reading about how openSSL had like one programmer and he used his own funds. It's embarrassing that we let this shit happen. this is why I think cs needs some form of labour union ( like the brotherhood of teamster, I didn't know truck drivers got better wage than half of us ) the wages keep on dropping and we have no say in where to divert investment.
- NhanH 11y agoHow do you think labor union would have helped in the openSSl case?
- 1971genocide 11y agoLabour unions are know to manage and divert investment for the common good for a field. They help enforce regulations and prevent random programmers from doing something stupid. IN the case of openSSL. Even though we all collectively know how important security is for the Internet in general, it would be hard to convince investors to fund something that is a collective good with long term potential. Right now except for EFF, no one is voicing the concern about encryption. And it's all programmers collective fault for letting this happen.
- NhanH 11y agoI understand the general appeal, what I was wondering is the specific mechanism that would work to help case like openSSL (if anything, I can see it hurting the effort, as you said, "stopping programmer from doing something stupid"). I'm more worried that labor union will be doing things more in the veins of RIAA and MPAA: seemingly good for short term of the field, but completely stupid in the big picture.
- carl7081 11y agoBut hey - they erase their disks 7 times and spike them before they throw them away - so we are safe now.
- trhway 11y ago93% later we'd be able to stop worrying about hacking and love the open Internet.
- sologoub 11y agoDoes anyone know if this affects immigration records, as I'm pretty sure they collect fingerprints and such?
- Litost 11y agoThis might well be the dumbest thing i've ever said on the internet, but extrapolating from "data on 7% of americans just got hacked" to the premise nothing is actually secure a) What would happen if we embraced this and just made all information freely available? b) Is one of the likely/possible end or transitional states of the human race, all information being freely available and presumably along with it, a more enlightened approach to dealing with it? c) Are there any good sci-fi books where this is explored?
- TrevorJ 11y agoInteresting idea. I think in a hypothetical situation where everyone had total info awareness you could make it work. If somebody uses your info to steal your identity or something, you'd know who it was and they would open themselves up to reprisal. Some equilibrium would be reached. In the real world though, releasing 'everyone's' data wouldn't really do anything to protect any given person if somebody wanted to specifically target them and you also wouldn't know who perpetrated it so really you have a system in place that rewards the bad actors.
- CamperBob2 11y agoThe 7% of Americans in question are a big, big deal. In an old-school Cold War context, this sort of thing would be considered nothing short of apocalyptic. To answer your question, check out David Brin's original writings on "The Transparent Society." If this material were to be leaked in public, it would almost constitute a field trial of his thesis. It would take a serious act of restraint on the Federal government's part not to pull the plug on the whole Internet, or at least every plug they can reach.
- imaginenore 11y agoWhy don't you post your private bitcoin keys for your wallets, if you have any. Just to put your money where your mouth is.
- vehementi 11y agoYou may need to reread the comment
- deleted 11y ago[deleted]
- a3n 11y agoSo wait a minute. Why couldn't this have been the NSA? I'm sure the NSA has no automatic right to at least some of that data. And if they're investigating someone (or everyone), breaking in would be their style, right? Wouldn't it be really valuable to them to zip together what they already have, and what's in the OPM data, to create more links and associations?
- deleted 11y ago[deleted]