This OPM data breach is bad, real BAD!!!

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

paperfist

Diamond Member
Nov 30, 2000
6,517
280
126
www.the-teh.com
It's not.

But I suspect the vector is online. Back in 2007 the Gov switched the SF-86 to a online site called eqip.

https://www.opm.gov/investigations/e-qip-application/

As you can see the site is down for security enhancements!!!!!

My suspicion is some sort of hack traversal through this system to the repository!!!

lol down for security enhancements!

I guess my point is why does it need to be attainable online in some shape or form? I can see why you'd want law enforcement data like that, but to house employee data is just asking for it.
 

Kwatt

Golden Member
Jan 3, 2000
1,602
12
81
It's not.

But I suspect the vector is online. Back in 2007 the Gov switched the SF-86 to a online site called eqip.

https://www.opm.gov/investigations/e-qip-application/

As you can see the site is down for security enhancements!!!!!

My suspicion is some sort of hack traversal through this system to the repository!!!

The horse has fled the barn! Let's lock the door!

My fraud protection for the SC breach has expired. So 3 more years for free!...Hip hip hooray



.
 

lxskllr

No Lifer
Nov 30, 2004
57,644
7,877
126
Instead of trying to break my encryption, maybe they should more effort into encrypting their shit.
 

Sabrewings

Golden Member
Jun 27, 2015
1,942
35
51
lol down for security enhancements!

I guess my point is why does it need to be attainable online in some shape or form? I can see why you'd want law enforcement data like that, but to house employee data is just asking for it.

It's for the investigators. They don't send someone from the OPM central offices to you for an interview. They have a network of local investigators and they all use that system. It's also for submissions and revisions by the applying member.

Unfortunately for me, the Chinese now know everything about me all the way back to 2003.
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
Are military clearances involved with this? I've heard that they could be, but the OPM doesn't acknowledge that at all.
 

Sabrewings

Golden Member
Jun 27, 2015
1,942
35
51
With this latest release, yes, military is affected. We already got word at my unit. Pretty much every SF86 ever submitted to eQIP has been stolen.
 

MarkXIX

Platinum Member
Jan 3, 2010
2,642
1
71
https://www.opm.gov/cybersecurity/

The answer is "highly likely" yes, it does affect you. It appears to go all the way back to 2000.

So according to that site, OPM will be providing ID theft services to 20 million people, who will all apparently be notified with details in the mail in the next few weeks ....

Here's what is counter-intuitive about the ID theft services though. It requires you to submit all the same information basically that just got stolen, which is a bit unnerving.

So, I just had all my private info stolen (dates of birth for all of my family members, financial accounts, etc.) and in order to protect myself I'm expected to give all that same information to someone else in order to protect myself.
 

Kwatt

Golden Member
Jan 3, 2000
1,602
12
81
Here's what is counter-intuitive about the ID theft services though. It requires you to submit all the same information basically that just got stolen, which is a bit unnerving.

So, I just had all my private info stolen (dates of birth for all of my family members, financial accounts, etc.) and in order to protect myself I'm expected to give all that same information to someone else in order to protect myself.

Yep we could not keep it secure the first time so please give it to us again.

"We take security very seriously"


...
 

steppinthrax

Diamond Member
Jul 17, 2006
3,990
6
81
lol down for security enhancements!

I guess my point is why does it need to be attainable online in some shape or form? I can see why you'd want law enforcement data like that, but to house employee data is just asking for it.

When you obtain employment within the fed gov or cleared contractor and they require a security clearance. They will direct you to this OPM website. This site pretty much allows you to fill out the SF-86 online and submit it. Honestly the interface is quite good. It branches quite well and authenticates the SF-86 quite well.

As a developer I know that no matter how strong you make a system, if there is a way to get in there will always be a way to get in!!!
 

kranky

Elite Member
Oct 9, 1999
21,014
137
106
I don't think this info will be used for fraud or identity theft. If it was the Chinese who got the data, it will be used for espionage, to try to get people to spy for them.

"Look, we aren't asking you to be a traitor. We're just asking for a little help so we don't have to tell your family or your wife about the incident. We can get the same information from the papers eventually and all we're asking is for you to give it to us directly. It's the same information they will release anyway, there's no harm in that. And you don't want your wife to find out about what happened before you met her, do you? Imagine how your kids will feel when it's all over the local papers and their friends find out."
 

destrekor

Lifer
Nov 18, 2005
28,799
359
126
I don't think this info will be used for fraud or identity theft. If it was the Chinese who got the data, it will be used for espionage, to try to get people to spy for them.

"Look, we aren't asking you to be a traitor. We're just asking for a little help so we don't have to tell your family or your wife about the incident. We can get the same information from the papers eventually and all we're asking is for you to give it to us directly. It's the same information they will release anyway, there's no harm in that. And you don't want your wife to find out about what happened before you met her, do you? Imagine how your kids will feel when it's all over the local papers and their friends find out."

This is one time I am hoping this was government-backed, as it would be as you say: a lesser likelihood that this information is sold on the black markets to be used for identity theft.
 

Gillbot

Lifer
Jan 11, 2001
28,830
17
81
Is there a way aside from sitting back and waiting to find out if your info has been compromised?
 

Red Squirrel

No Lifer
May 24, 2003
67,882
12,354
126
www.anyf.ca
Don't worry, I'm sure the government agencies or whoever was responsible for this breach has plenty of liability insurance. It's business as usual for them and they don't care.

This does sound pretty bad though. This is only in the US right? I guess I don't have to worry, for now... But so many companies and agencies have our info now days, and they really don't care about security, so it's pretty much a ticking time bomb at all times.
 

cabri

Diamond Member
Nov 3, 2012
3,616
1
81
Is there a way aside from sitting back and waiting to find out if your info has been compromised?
In theory, you can go to a gov website to find out.

But that was prior to the last revelation.

Best to figure that if you had anything to do with clearances and/or Fed gov employment after 2000, you have been compromised.
 

WackyDan

Diamond Member
Jan 26, 2004
4,794
68
91
This is pretty crazy.

If anyone has Security Clearance (like me) they would know the process and the "full compliance" of information you have to provide on the SF-86 to obtain clearance.

Just imagine this get's released onto some dark website somewhere. People will see some very very very very private information about these individuals.

Far beyond on who has a clearance or not!!!!

Yeah.... I've been parsing the Homeland Security bulletin and IOCs within with all the suspect files and md5 hashes. I've been helping customers automate the discovery of those files with my endpoint management agent.

MD5? Really? Sha1 and Sha256 are so much better for this than MD5 as MD5 will have false positives.

Federal gov't IT needs to get with the times.
 

ImpulsE69

Lifer
Jan 8, 2010
14,946
1,077
126
Is it wrong that I'm not as worried about this data breach as I am about all that DNA they took from us years ago for "studies"?
 

CZroe

Lifer
Jun 24, 2001
24,195
856
126
I think the CIA is just trying to demonstrate how much they know about the source of PLA hacks.
 

reallyscrued

Platinum Member
Jul 28, 2004
2,617
5
81
Remember when you got asked "Could this information ever be used against you as blackmail?"

Time to put your money where your mouth is.
 

mikeford

Diamond Member
Jan 27, 2001
5,670
160
106
Amazing,Obama's campaign worker with no IT experience was an epic fail, and the cover up didn't work. Nothing new.
 
Feb 24, 2001
14,550
4
81
I don't think this info will be used for fraud or identity theft. If it was the Chinese who got the data, it will be used for espionage, to try to get people to spy for them.

"Look, we aren't asking you to be a traitor. We're just asking for a little help so we don't have to tell your family or your wife about the incident. We can get the same information from the papers eventually and all we're asking is for you to give it to us directly. It's the same information they will release anyway, there's no harm in that. And you don't want your wife to find out about what happened before you met her, do you? Imagine how your kids will feel when it's all over the local papers and their friends find out."

I agree. Go through the SF86s and figure out who was a gambling addict, a kiddy toucher, etc. Then use as blackmail for nefarious deeds.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |