Slashdot Mirror


SF86 Data Captured In OPM Hack

Etherwalk writes: The security clearance process in the United States includes filling out the 127-page SF86 form, which includes things like the citizenships of all your relatives and housemates, foreign contacts and financial interests, foreign travel, psychological and emotional health, illegal drug use, and many other matters. The recent breach by the Chinese Government apparently included that information for all executive employees up to cabinet level. It's pretty much a gold mine for intelligence work and social engineering of any kind.

23 of 173 comments (clear)

  1. Bah! Media! by quonsar · · Score: 5, Insightful

    So, what exactly do they mean by "breach". Someone got into some systems? Once there, did they take copies of data? That's a lot of data. Why didn't anyone see the mass exodus of gigabytes? The weasel worded breathless media reports are just dripping with a lack of specificity and reek of "omg phear the evil hackerz!" - they feel more designed to generate fear than inform. I view the whole thing with a jaundiced, skeptical eye.

    1. Re:Bah! Media! by rrr00bb5454 · · Score: 5, Interesting

      SF86 data is extraordinarily sensitive. What they mean is that the attackers made off with a database of the financial problems, drug habits, family problems, hidden crimes, and sex fetishes of anybody that's working on anything sensitive. This data will determine who comes home to a hooker in his bed with requests for information and a crowbar in one hand and a bag of illegal drugs in the other. I'd say that the information is so sensitive, that it may actually weaken security to continue with this practice of having all of these confessions written down. I mean... if you can approach your boss and say "hey, i need to take a few weeks off to go to jail!" to which he responds "ok. you have plenty of leave!"; then that may leave you far less open to coercion then if you go into a panic over being found out by your boss for adultery. ("gah! i'll lose my clearance and never ever work again!")

    2. Re:Bah! Media! by lgw · · Score: 4, Interesting

      What they mean is that the attackers made off with a database of the financial problems, drug habits, family problems, hidden crimes, and sex fetishes of anybody that's working on anything sensitive.

      It's worse than that. Foreign agents might be identifiable through this data. People sleeping with foreign nationals report that, and those foreign nationals might find their own government treats them like a spy now.

      People will get killed behind this - likely a large number of people.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    3. Re:Bah! Media! by bitingduck · · Score: 2

      If you don't admit to a past drug problem and they find out about it, you don't get a clearance, or you lose it if you had it. If you tell the truth about it and it's in the past you probably will get a clearance. They ask about it on the SF85 (the form for non-sensitive positions) and people have been denied employment or fired for lying about it.

    4. Re:Bah! Media! by cfalcon · · Score: 4, Informative

      Fetishes are not listed in an SF86. Arrests and convictions are, but those are also public record. You are likely thinking of a lifestyle polygraph. SF86s are not lists of confessions.

      I would still say that your overall statement of "extraordinarily sensitive" applies, however. Earlier addresses, tons of contacts to vouch for the person, etc. It's not just the subject of an SF86 who has personal info in their, it's the other people in their lives who have agreed to be interviewed and such as well.

      Note that adultery is not generally illegal, nor is it something that would appear on an SF86.

      This form is on the web:
      http://www.gsa.gov/portal/form...

    5. Re:Bah! Media! by Ungrounded+Lightning · · Score: 2

      The clearance process includes finding out if you're blackmailable into turning over secrets. So of course they question you about everything enemy spies may use as blackmail material. They're often willing to approve you if you confess all your sins to them - because the spies can no longer use the threat of revealing them to the intelligence agencies to pressure you.

      It behoves you to confess ALL of it, because if you leave anything out they'll pull your clearance when they discover it. On the other hand, if YOU don't care if its revealed, THEY don't care either. So to get the clearance you tell them everything and claim you don't care.

      Of course that means the intelligence agency files includes pretty much all the juicy blackmail material there IS on you. So if there's something you really DO care about, and you were bluffing the agencies, you ARE subject to blackmail threats.

      Of course you also expose your life history, to prove you're not a mole. And THAT is everything an identity thief needs to completely replace you. SS number and mother's maiden name are a drop in the bathtub compared to this info.

      The agencies should have guarded this MORE TIGHTLY than they do nuclear secrets. It's the key to ALL the people who know ALL the secrets.

      --
      Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  2. if it's somehow accessible by the internet by turkeydance · · Score: 2, Insightful

    it's Out There. All of it.

  3. WTF did they think would happen? by Anonymous Coward · · Score: 5, Interesting

    The SF86 data is essentially designed to track and identify every aspect of federal employees lives and backgrounds which would make them a target of extortion or blackmail by foreign intelligence.

    Instead of keeping those records in distributed and isolated/compartmentalized silos(where the scope of any individual security failure would be non-catastrophic) where the cost-to-benefit ratio of data ex-filtration was much less attractive: they consolidated all of this data in one place where a single chink in the armor would allow an adversary to acquire the sum total knowledge in existence of their entire classified documents workforce...

    TLDR: Morons put the 2nd largest and most expensive collection of blackmail material in the history of mankind(The Vatican "Archives" being the obvious #1) in a single place behind a padlock("hacker proof security" seems about as elusive to find in the wild as big foot) and then act shocked when they essentially gift wrapped a knife to cut through the fog of war for APT.

    The ironic implication of this now is that the best defense against security threats is to disqualify anyone who had a security clearance previously from owning one an either:

    A) Clean slate. Go back to the old way of doing things(until this happens again) and get a fresh batch of leverage,err... I mean "federal employees".
    or
    B) Abolish the idiotic system entirely. The spying incidents which the system was designed in reaction too were conspicuous absent of any spies who would have failed the background check process.

    Get rid of ITAR/USML while you're at it!

    Hell, why not just say "fuck it"?
    Take the MAD approach and open source everything. When Predator drones are being 3d printed in people's basement the tree of liberty should get watered way more often.

    Maybe without the illusion of secrecy, the nonsense secret squirrel playground games which caused WWII and WWIII will finally stop. While China is embroiled in a domestic insurgency/civil war America can laugh all the way to the bank.

    1. Re:WTF did they think would happen? by Rich0 · · Score: 2

      Instead of keeping those records in distributed and isolated/compartmentalized silos(where the scope of any individual security failure would be non-catastrophic) where the cost-to-benefit ratio of data ex-filtration was much less attractive: they consolidated all of this data in one place where a single chink in the armor would allow an adversary to acquire the sum total knowledge in existence of their entire classified documents workforce...

      Never underestimate the power of cost-cutting. Having data in one place also increases its utility, if for example there is a need to mine this data for some pattern (trying to find a mole based on disclosed past associations or whatever). An obvious use for having access to all of this data would be to match up the disclosed relationships/etc to every Facebook friend pairing and phone call on the planet and seeing what was left out.

      At work we do all kinds of stupid stuff over quests to save $50 here or there.

  4. OK, I'll bite. by ledow · · Score: 2, Insightful

    "U.S. officials privately said China was behind it."

    Which officials, and why won't they speak on-record? Because they know that, stupidly, they've said that cyber-attacks could be seen as an act of war. And none of them are stupid enough to directly declare war on China on the basis of fuck-all evidence beyond "we got hacked, looked like the last hop had a whois somewhere in China".

    This isn't enough to put in the papers, this isn't enough to act upon, but fuck if the US won't let *that* stand in their way.

    You have NO WAY of knowing whether China are doing this, officially or not. When you do, you can make news stories and bring it up in international committees. Until then, it's some Chinese kid who's found a good source of credit card data to buy some Steam games for all the fuck you know.

    Dickheads like these "officials" are either a) trying to put so much implication into people's heads that people just assume you ARE at war with China or b) have fuck-all to go on and speak carelessly and dangerously.

    I'm not American, nor Chinese. But, fuck, this is a slippery slope if every time some hacker in Beijing touches your systems you're going to cry wolf and accuse China of officially stealing sensitive data.

    What's the matter? Been too long since you had a decent enemy who could shoot back?

  5. With security like this... by mschaffer · · Score: 2

    With security like this, who needs Snowden?

  6. Schadenfreude on so many levels by sideslash · · Score: 4, Insightful

    The NSA has been hacking pretty much everybody in the world and their little sister, so nobody should be shocked when the same thing happens to us.

    The real kicker is the perennial lecture from clueless politicians about how we should put back doors into all our private sector encryption so law enforcement can take a peek whenever it likes. Because our information will be safe with the government. *snort*

  7. Re:If it is the Chinese by rickb928 · · Score: 4, Insightful

    Doubtful. The OPM has been negligent in this area for decades. And they are not the only agency.

    A bottom - to - top review and security renovation is critically needed, and should cost closer to $100Bn than not if it's done right. Everything, from .mil and DOD to mainline agencies and even .gov customer service sites, everything.

    And not a review. A complete reimagining and reinstallation.

    Not going to happen in this Administration, as they fear any analysis.

    The fiasco of our former Secretary of State running a private server at their own residence for official email is a example of the utter and total lack of actual information security in our government, a situation that (or should be) intolerable.

    But, politics.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  8. Re:If... by gcnaddict · · Score: 3, Interesting

    The only times we've ever heard of the US actually doing anything were with Stux and its variants, and that was always after they had done their damage. There really wasn't much of anything else, so there's no real way to know who's better because of the clandestine nature of these operations anyway.

    At the very least, we know the Chinese are prolific, but we have no idea if the Chinese are better, the Russians, the United States, the Israelis... heck, maybe the Brits upstaged everyone. It's impossible to know.

    --
    Viable Slashdot alternatives: https://pipedot.org/ and http://soylentnews.org/
  9. Bullshit ... by CaptainDork · · Score: 2

    ... you're placing this at the feet of Republicans and Democrats when you don't know bullshit from wild honey.

    OPM is not a fucking Super PAC.

    It's the government. It's federal employees, managers, administrators, people who, by and large, are not subjected to turnover.

    You're not going to solve this with the goddam vote.

    Go home.

    --
    It little behooves the best of us to comment on the rest of us.
    1. Re:Bullshit ... by CaptainDork · · Score: 2

      Your logic is no more flawed than the crazy thinking of people in charge of the nation's security and can't get it right.

      I'll bet you a hundred dollars to a whole in a doughnut that one or both of the following are true:

      1.) The nation's computer systems are unpatched

      2.) Government employees got phished by email or web link.

      What say you?

      --
      It little behooves the best of us to comment on the rest of us.
  10. Snark begets snark by weilawei · · Score: 4, Funny

    No, it's sulfur hexaoctacontafluoride.

  11. Bandwidth Leak over Time by Etherwalk · · Score: 3, Interesting

    He's probably referring to the amount of bandwidth used to move the data. Honestly someone should have been watching for mass uploads or downloads.

    The breach occurred in December, was detected IIRC in April. Plenty of time to move data slowly and prioritize what you take, making you less likely to show a bandwidth spike.

    1. Re:Bandwidth Leak over Time by Rich0 · · Score: 3, Insightful

      He's probably referring to the amount of bandwidth used to move the data. Honestly someone should have been watching for mass uploads or downloads.

      The breach occurred in December, was detected IIRC in April. Plenty of time to move data slowly and prioritize what you take, making you less likely to show a bandwidth spike.

      Also, it isn't like they're copying HD video here. A detailed register of every financial transaction you've ever made in your life including every time you dropped a quarter in an arcade machine as a kid might actually only be maybe a gigabyte in size, if that.

      You can fit every book ever written on a ~1TB hard drive, uncompressed. A 127 page form doesn't actually take that much space to store.

      And of course you can stream the data slowly as you point out, but unless the US is blocking sites like weather/news/etc this kind of bandwidth barely registers in the noise. If they let people listen to spotify at work that would be vastly more data than what was likely stolen.

  12. Formal Accusations are a Big Step by Etherwalk · · Score: 2

    "U.S. officials privately said China was behind it."

    Which officials, and why won't they speak on-record?

    An on-the-record statement is a much bigger diplomatic statement. We don't usually speak on-the-record about the hostile or criminal acts of a foreign power unless we have a very good diplomatic reason to. We know that Putin backs Kaderov, a thuggish head of state who personally tortures people on exercise equipment and disappears reporters critical of his regime, but it would be unusual to have the White House announce that Putin was doing that. It would also require us to be prepared for the inevitable PR backlash based on US torture at Guantanamo Bay, for example. If we make a public announcement, China is more likely to engage in more severe public criticism of us.

    International relations turn out to be more complex than "let's call the other guys on their shit."

  13. Re:Bah! Media! Repent from SIN by TheRealHocusLocus · · Score: 4, Informative

    SF86 data is extraordinarily sensitive. What they mean is that the attackers made off with a database of the financial problems, drug habits, family problems, hidden crimes, and sex fetishes of anybody that's working on anything sensitive.

    Shouldn't that kind of stuff be only on paper, locked inside some kind of... you know... financial problems drug habits family problems hidden crimes and sex fetishes room?

    Tabloid fascination with personal problems or consensual crimes, 'sin' for short --- this whole ability to ruin someone by leaking factual information --- is a known vulnerability of the human condition. One no one wants to fix (it involves losing the moral high ground) or even admit that it is a problem. This means past indiscretions can through blackmail, be used by murders to conceal their crimes, or even drive a blackmailed sociopath on by degrees, to commit murder. In the best of cases it hands the rudder to the most oafish bullies, for the dumbest of reasons. And some brilliant and capable, even trustworthy people find themselves in shit.

    Looks like the USG has handed over it all. Beware, my friend, shit winds are a-comin'

    I recommend Peter McWilliams' book AIN'T NOBODY'S BUSINESS IF YOU DO: The Absurdity of Consensual Crimes in a Free Country, placed on the web with the deceased author's permission, to help sort out (culturally) what should be an actionable --- or blackmail-worthy --- crime. Also check out this (failed) submission on the DEA and my suggestion to implement duress codes (like a blackmail canary) into society.

    --
    <blink>down the rabbit hole</blink>
  14. Re:If... by Rich0 · · Score: 2

    Actually we DO know that China was able to hack the US government networks multiple times and retrieve top secret information, including the F-35 blueprints ( www.rt.com/news/223947-snowden-pentagon-china-hack ). We have no proof that the opposite happened.

    You'd have said the same thing about the US/UK cracking Enigma during WW2.

    The Chinese might very well be better at this stuff than the US. However, we really have no way of knowing. These sorts of things tend to be covert in nature, and sometimes it is in your interests to brag, and at other times it is in your interests to play your cards close to your chest.

  15. Re:If it is the Chinese by rworne · · Score: 3, Insightful

    China flexes their hacking skills while security researchers in the USofA worry they'll be jailed as terrorists by their own government?

    Yup, I see no problem here.

    --
    I tried every decent and legal way I could think of to resolve the issue w/the business before I rented the chicken suit