# Federal Government: 4 million Employees Data Hacked, at Risk

**URL:** <https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [June 4, 2015, 10:19pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666 "2015-06-04T22:19:14Z")\
**Posts on this page:** 19\
**Page:** 3

<div class="post-metadata">

**Author:** ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)\
**Post date:** [June 6, 2015, 2:36am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/41 "2015-06-06T02:36:22Z")

</div>

> [@Slash1972](#):
>
> Whose heads do you think should roll in the OPM data breech?

Won’t know that until an investigation is done. The federal government should treat its own the same way they treated Target.

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [June 6, 2015, 3:39am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/42 "2015-06-06T03:39:03Z")

</div>

> [@PastTense](#):
>
> There’s no reason a lot of this stuff has to be on computers connected to the internet.

If the information is going to be useful, it pretty much has to be on a network of some kind. Even if it’s a closed network, not attached to the internet, and accessible only to employees who badge into a building, there are still opportunities for breaches. The Natanz nuclear facility in Iran was air gapped and surrounded by thick concrete walls. The US and Israel still got malware onto the systems there and mucked about with the enrichment processes (Stuxnet).

---

<div class="post-metadata">

**Author:** ![RTFirefly](https://avatars.discourse-cdn.com/v4/letter/r/c77e96/32.png) [@RTFirefly](https://boards.straightdope.com/u/RTFirefly)\
**Post date:** [June 6, 2015, 10:36am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/43 "2015-06-06T10:36:57Z")

</div>

> [@adaher](#):
>
> THe knives haven’t come out. At all. In fact, I’m annoyed, not that Obama isn’t being raked over the coals, but that the government is going easy on itself when it came down like a ton of bricks on Target. This incident should be treated with just as much seriousness. Heads should roll.

Well, you keep saying this. But, absent _our_ doing the research to back up _your_ argument, all we have is your assertion that there WAS any difference.

So, in what way was the Federal government coming down like a ton of bricks on Target, at this point in the story of that data breach?

> [@](#):
>
> So is assuming that when things go wrong it’s always because there wasn’t enough money. The government has 20%+ of GDP to spend. Any 536 morons(Congress+the President) should be able to meet most priorities with a $3 trillion pot.

It’s nice to wave around that $3 trillion figure, but it’s not like the President can do whatever he damn well pleases with it.

The U.S. government has often been described as a retirement program with an army. The bulk of the money is going to Social Security, Medicare, Medicaid, and defense programs. And what’s left has largely been allocated to specific programs. It would be nice if the President could simply shut down some defense boondoggle, and spend the money on information security, or more USDA and FDA inspectors, or whatever.

But we settled this one back in the Nixon Administration: the President can’t just take money that Congress has allocated to a particular purpose, and spend it on something else, or just not spend it. He has to carry out the laws as passed by Congress, to the extent that Congress gives him the resources to do so.

And in the case of the budget, that’s pretty straightforward, unless Congress fails to extend the debt ceiling one of these days.

---

<div class="post-metadata">

**Author:** ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)\
**Post date:** [June 6, 2015, 11:03am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/44 "2015-06-06T11:03:30Z")

</div>

Keeping IT systems current can be covered under departments’ existing budgets. Or are we to assume that the DoD can’t keep a Chinese hacker from launching our nukes?

---

<div class="post-metadata">

**Author:** ![even\_sven](https://avatars.discourse-cdn.com/v4/letter/e/dfb087/32.png) [@even\_sven](https://boards.straightdope.com/u/even_sven)\
**Post date:** [June 6, 2015, 11:23am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/45 "2015-06-06T11:23:44Z")

</div>

> [@adaher](#):
>
> Keeping IT systems current can be covered under departments’ existing budgets. Or are we to assume that the DoD can’t keep a Chinese hacker from launching our nukes?

And you realize the difference in vulnerability between networked and non-networked machines?

---

<div class="post-metadata">

**Author:** ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)\
**Post date:** [June 6, 2015, 12:18pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/46 "2015-06-06T12:18:02Z")

</div>

Most importantly, I recognize the difference in accountability between corporations and the government. If a corporation gets hacked, the corporation is responsible and faces punitive action from the government. If the government gets hacked, it’s just an unfortunate incident and we have to live with it. And please, continue to voluntarily give your personal info to the government. Otherwise, it will become mandatory.

---

<div class="post-metadata">

**Author:** ![even\_sven](https://avatars.discourse-cdn.com/v4/letter/e/dfb087/32.png) [@even\_sven](https://boards.straightdope.com/u/even_sven)\
**Post date:** [June 6, 2015, 12:52pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/47 "2015-06-06T12:52:21Z")

</div>

> [@adaher](#):
>
> Most importantly, I recognize the difference in accountability between corporations and the government. If a corporation gets hacked, the corporation is responsible and faces punitive action from the government. If the government gets hacked, it’s just an unfortunate incident and we have to live with it. And please, continue to voluntarily give your personal info to the government. Otherwise, it will become mandatory.

So you think government IT offices don’t have performance metrics and don’t face consequences when they don’t meet them?

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [June 6, 2015, 1:41pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/48 "2015-06-06T13:41:32Z")

</div>

Its early and I was up till 1:00 AM last night helping my company respond to a hack. So I’m not running on all cylinders yet. But, what punitive actions does the government take against companies that have been hacked? HIPAA provides for some sanctions for noncompliance, but as far as I know they haven’t hit very many healthcare organizations with them as the direct result of a hack. SOX provides penalties for noncompliance and for filing fraudulent financials, but I don’t think it has penalties for being hacked. I’m having a hard time remembering any corporation that was penalized by the feds for being hacked.

-Bayard  
Computer forensics and incident response guy

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [June 6, 2015, 9:21pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/49 "2015-06-06T21:21:51Z")

</div>

> [@even\_sven](#):
>
> So you think government IT offices don’t have performance metrics and don’t face consequences when they don’t meet them?

So what are the consequences? The general view is that only total fuckups get fired if they work for the government.

---

<div class="post-metadata">

**Author:** ![even\_sven](https://avatars.discourse-cdn.com/v4/letter/e/dfb087/32.png) [@even\_sven](https://boards.straightdope.com/u/even_sven)\
**Post date:** [June 6, 2015, 10:51pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/50 "2015-06-06T22:51:58Z")

</div>

> [@PastTense](#):
>
> So what are the consequences? The general view is that only total fuckups get fired if they work for the government.

On an agency level, screw up enough Congress gets upset. Get Congress upset, and they either micromanage you or they just cut funding. Get the administration upset at you, and you may find your agency lose power very quickly.

On a management level, screw up bad enough and someone is going to have to resign in disgrace. It’s not pretty.

On an individual level, you can definitely get fired, especially for hard lapses like something that violates privacy policy. You can also be demoted. More likely, you’ll end pushed out, assigned to do filing alone in a basement somewhere until you either get the hint or your career is totally derailed.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [June 7, 2015, 3:15am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/51 "2015-06-07T03:15:35Z")

</div>

> [@even\_sven](#):
>
> On an agency level, screw up enough Congress gets upset. Get Congress upset, and they either micromanage you or they just cut funding. Get the administration upset at you, and you may find your agency lose power very quickly.
> 
> On a management level, screw up bad enough and someone is going to have to resign in disgrace. It’s not pretty.
> 
> On an individual level, you can definitely get fired, especially for hard lapses like something that violates privacy policy. You can also be demoted. More likely, you’ll end pushed out, assigned to do filing alone in a basement somewhere until you either get the hint or your career is totally derailed.

Unfortunately, I think you’ll find that many agency computer systems are contracted out to commercial companies, who only have to make target percentages of patched/secured/updated systems. And the contract will also be written to exclude responsibility for any data breaches that occur. So, yeah, an agency system gets hacked. Investigation reveals one user clicked a bad attachment, and caused an opening that allowed other hackers in. The network was 95% patched in accordance with the contract, so the contractor is not at fault. Information Security is now a required line item in agency budgets, and the agency can show they have been screaming for more money but not getting it. Various heads of departments say “Not my fault, I’m not responsible. Here’s my Statement of Work, and I’ve exceeded all targets as shown by my annual review”

So whose fault is it? Nobody. The only punishment would be to the poor person who clicked the attachment. And nobody gets fired for that, certainly not a government employee.

---

<div class="post-metadata">

**Author:** ![MrDibble](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mrdibble/32/114_2.png) [@MrDibble](https://boards.straightdope.com/u/MrDibble)\
**Post date:** [June 7, 2015, 8:42am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/52 "2015-06-07T08:42:41Z")

</div>

> [@samclem](#):
>
> So, who of the current candidates for President in 2016 would you suggest would fill the bill you have just posted?

The one with enough tech savvy to run her own email server from her house? 😃

---

<div class="post-metadata">

**Author:** ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)\
**Post date:** [June 8, 2015, 2:48am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/53 "2015-06-08T02:48:29Z")

</div>

> [@MrDibble](#):
>
> The one with enough tech savvy to run her own email server from her house? 😃

That just speaks to transparency, of course, not security. We do not know what security Clinton was running or how her system performed against hacks.

We could achieve the same result simply by prohibiting OPM from informing the public about hacks. Personally, as an employee who was potentially affected, I prefer an employer who will at least tell me when it happens.

---

<div class="post-metadata">

**Author:** ![even\_sven](https://avatars.discourse-cdn.com/v4/letter/e/dfb087/32.png) [@even\_sven](https://boards.straightdope.com/u/even_sven)\
**Post date:** [June 8, 2015, 8:33am UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/54 "2015-06-08T08:33:58Z")

</div>

> [@Slash1972](#):
>
> Unfortunately, I think you’ll find that many agency computer systems are contracted out to commercial companies, who only have to make target percentages of patched/secured/updated systems. And the contract will also be written to exclude responsibility for any data breaches that occur.

If the contractor didn’t hit the targets, the contractor and possibly the person managing the contract is responsible. If the targets don’t comply the agency policy, then whoever set and approved them gets is responsible. If the agency policy is inadequate, then IT security team that developed them is responsible.

But yeah, if the targets are reasonable given resources available, then it’s either a case of “we did what we could with what we got” or “stuff happens”. IT departments are not staffed by ninjas and magicians. They can only do things that are possible to do.

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [June 11, 2015, 5:08pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/55 "2015-06-11T17:08:10Z")

</div>

> [@](#):
>
> The massive hack into federal systems announced last week was far deeper and potentially more problematic than publicly acknowledged, with hackers believed to be from China moving through government databases undetected for more than a year, sources briefed on the matter told ABC News.
> 
> “If [only] they knew the full extent of it,” one U.S. official said about those affected by the intrusion into the Office of Personnel Management’s information systems.
> 
> It all started with an initial intrusion into OPM’s systems more than a year ago, and after gaining that initial access the hackers were able to work their way through four different “segments” of OPM’s systems, according to sources…
> 
> Of utmost concern are U.S. employees stationed overseas, including in countries such as China, whose government would covet personal information on relatives and contacts of American officials living in the communist country, according to officials.

> **[OPM Hack Far Deeper Than Publicly Acknowledged, Went Undetected For More Than...](https://abcnews.go.com/ABCNews/opm-hack-deeper-publicly-acknowledged-undetected-year-sources/story?id=31689059)**
>
> The hack was far deeper and potentially more problematic than acknowledged.

---

<div class="post-metadata">

**Author:** ![Eva\_Luna](https://avatars.discourse-cdn.com/v4/letter/e/e495f1/32.png) [@Eva\_Luna](https://boards.straightdope.com/u/Eva_Luna)\
**Post date:** [June 12, 2015, 7:39pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/56 "2015-06-12T19:39:58Z")

</div>

Well, that was…less than reassuring. I tried to call OPM to inquire about any efforts being made to notify former employees of the data breach, and if there are any, the info sure hasn’t made its way to the front desk of the IT department. Even after I mentioned that I hast worked for the Feds in 1994 and several addresses ago, I was told a letter would be sent to my home address, or I would receive an e-mail.

Uh, the only e-mail address I had in 1994 when I left was my DOJ one.

I tried the webform - maybe I will have better luck there. I also left a voice mail for the local office where I worked, for someone I worked with who is now the admin manager. Hopefully that will get better results 🙂

---

<div class="post-metadata">

**Author:** ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)\
**Post date:** [June 13, 2015, 2:12pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/57 "2015-06-13T14:12:45Z")

</div>

[Wired](http://www.wired.com/2015/06/opm-breach-security-privacy-debacle/) is reporting that the hack encompassed the SF-86 forms used to apply for a security clearance. Which would mean they know everything: former addresses, close associates, employment history, mental health treatment, foreign contacts. Basically lots of stuff that might be used to blackmail someone is now in the hands of blackmailers.

According to Wired, OPM had no IT security staff until 2013.

---

<div class="post-metadata">

**Author:** ![adaher](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@adaher](https://boards.straightdope.com/u/adaher)\
**Post date:** [June 13, 2015, 2:26pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/58 "2015-06-13T14:26:24Z")

</div>

Wow, the government is really proving the critics right on this one. No IT security until 2013? That’s insane.

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [June 28, 2015, 2:31pm UTC](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666/59 "2015-06-28T14:31:39Z")

</div>

> [@](#):
>
> Infidelity. Sexual fetishes. Drug abuse. Crushing debt. They’re the most intimate secrets of U.S. government workers. And now they’re in the hands of foreign hackers.
> 
> It was already being described as the worst hack of the U.S. government in history. And it just got much worse.
> 
> A senior U.S. official has confirmed that foreign hackers compromised the intimate personal details of an untold number of government workers. Likely included in the hackers’ haul: information about workers’ sexual partners, drug and alcohol abuse, debts, gambling compulsions, marital troubles, and any criminal activity.
> 
> Those details, which are now presumed to be in the hands of Chinese spies, are found in the so-called “adjudication information” that U.S. investigators compile on government employees and contractors who are applying for security clearances.

[http://www.thedailybeast.com/articles/2015/06/24/hackers-stole-secrets-of-u-s-government-workers-sex-lives.html](http://www.thedailybeast.com/articles/2015/06/24/hackers-stole-secrets-of-u-s-government-workers-sex-lives.html)

[Previous page](https://boards.straightdope.com/t/federal-government-4-million-employees-data-hacked-at-risk/721666.md?page=2)
