8 ms·
CIA pulled officers from Beijing after breach of federal personnel records
- chaostheory 11y agoAs some previous articles have already mentioned, they probably already knew who they were anyways. Only their offices have special locks. They don't mingle with anyone else at the embassy but their own. They also don't have same 3-4 year requirement of staying at the embassy so they leave early; and when their replacements arrive, they take over the same offices.
- caio1982 11y agoI believe you're talking about https://news.ycombinator.com/item?id=10291691 https://news.ycombinator.com/item?id=10291691
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- cm2187 11y agoI like the idea that CIA officers are directly identifiable by their absence from the database. It reminds me of submarines and sonars. I understand that modern submarines are pretty good at diverting sonar waves so that they have a small footprint. However when a fishing boat passes over a submarine while scanning the ocean floor looking for fish, the submarine becomes immediately visible as a dark shape of sonar waves not returning from the ocean floor.
- Luc 11y agoThat smells fishy, as it would be something exploited immediately by any anti-submarine vessel.
- EliRivers 11y agoAnti-submarine vessels have to do one thing really well to have any chances; be quiet. Fishing vessels can happily plough the ocean wave pinging to their heart's content. An anti-submarine vessel that did that quickly becomes a target, or if the submarine is feeling generous, something to go around - thanks for telling us where you are. There's a time and a place for active sonar in finding and killing submarines, but it's not from your anti-submarine ship, all day every day.
- cm2187 11y agoPlus you have to be right above the submarine. The ocean is vast.
- Luc 11y agoSure, but I just don't think a sub would show up as a black, signal-free shape on a fishing boat's sonar, except under contrived conditions. Though I may be judging it wrong based on only having used crappy sonar equipment.
- 3pt14159 11y agoThen part of your navy is hacked fishing boat sonar kits and an uplink to the anti-submarine vessel. :)
- CapitalistCartr 11y agoThe Soviets used to do that with their "fishing fleet". We would send submarines out the Strait of Juan De Fuca, it would drop down to 1,000 feet, and the "fishing boats" would lose it every time. It still didn't work. I don't know of any reliable way to find a submarine, even today.
- TeMPOraL 11y agoWhich, if the word of it ever got out, would paint fishing boats as a valid target in combat operations.
- appleflaxen 11y ago"We, too, practice cyberespionage and . . . we’re not bad at it" - James Clapper Ironic, for the intelligence leader of a country that had their defensive systems completely penetrated (with the federal personnel records), and their offensive systems fully outed in the most humiliating way possible (by Snowden) It seems to me that yeah... you kind are bad at it. At the very least, a little less self-certainty might be in order.
- pp19dd 11y agoFor what it's worth, the CIA is the only federal agency that keeps their own employee records. Everyone else goes through OPM. They (rightfully) assumed that OPM couldn't keep secrets and that's where we find ourselves today. It's probable that these records are printed, locked in a vault. James Clapper, the DNI, heads 16 intelligence agencies under him, one of which (CIA) didn't have their records stolen. Though the budget breakdowns are not disclosed, arguably, they are the largest of the bunch and only ones that have deployed field operatives.
- marme 11y agothis is exactly the problem. The CIA did not get hacked it was OPM and no CIA records were stolen. But by simple process of elimination china could look at all the embassy staff in beijing and find out who is not in the OPM records, since the CIA is the only one not keeping personel files with OPM anyone working at the beijing embassy and not in the OPM records must be a CIA agent
- digikata 11y agoI don't think it's possible to conclude that the CIA employee records were not hacked in separate attempts - only that there is no public record of a hack. But that's poor proof, if there were CIA records were separately stolen, I assume there would be a strong justification made to hide that outcome.
- mdc 11y agoBeing bad at defense doesn't necessarily imply being bad at offense. Security is hard because you have to win 100% of the time. Being good at cyberespionage means getting a win now and then. I'm not saying the US is good at it, just that neither the OMB breach nor the Snowden incident bear on that. And a lot of the info released by Snowden indicate they were pretty good at it (at least targeting their own citizens) or those disclosures wouldn't be such a big deal.
- discardorama 11y agoWhen Chelsea Manning leaked the documents, noone was put in danger. When Snowden leaked the documents, no one was endangered. This breach, and lots of people are endangered. But are you getting calls for criminal investigation? Are heads rolling (other than the head of OPM, who was hated anyways)?
- kasey_junk 11y agoIsn't that what this article is about? We are pretty certain that this was an act of espionage by another nation state. Criminal investigations are not how you respond in those cases (unless we found the agent on our soil, which AFAIK we did not). What is curious is that we aren't sure what the norms are for how to respond to cyber espionage, unlike with in person espionage which had a whole set of responses we could fall back on.
- pasbesoin 11y agoCriminal negligence? Certainly, negligence that should incur public disgrace. Also arguably demonstrating one of the points made by the whistleblowers: You can't trust the government to properly manage all the information they collecting.
- irq-1 11y agoThis isn't negligence. Instead of trying to protect data and networks the US government has made "cyber crime" a military issue. They've been doing it deliberately and publicly, for over a decade. Domestically they followed the same plan: companies get protection (financial, legal, image,) discouraging them from taking security seriously, and individuals get the CFAA which has a similar effect. They want data and network security to be a military problem, not to encourage security. We can't blame the OPM for the security issues. They were a victim of a bad national strategy. If you "see something, say something" unless its about cyber security.
- pasbesoin 11y ago
- rrggrr 11y agoAnother vindication of Ishamel Jones' position on the stupidity of relying upon State Dept covers for CIA personnel. For a hilarious and unparalleled informative look at the Agency: http://www.amazon.com/The-Human-Factor-Dysfunctional-Intelligence/dp/159403382X http://www.amazon.com/The-Human-Factor-Dysfunctional-Intelli...
- gadders 11y agoI don't know why these hacking incidents are not considered acts of war.
- ceejayoz 11y agoWhat makes you think we're not already responding in kind?
- TeMPOraL 11y agoBe thankful for that. Cyberattacks are so hard to trace back that it's very easy to set up a false-flag operation. Framing someone else for your attack would become a simple way of starting a war between two of your opponents.
- blisterpeanuts 11y agoThis OPM breach is an unmitigated disaster. What were they thinking, storing sensitive biometric information like fingerprints in an easily hacked database[1]? One can envision a time in the very near future (if not already), when a random foreigner is stopped on the streets of Beijing and asked to press his finger to a reader attached to an Android phone. The device would then display his picture, official position, address, salary, clearance level, etc. Or else, just walk into the restaurant he just left and take the fingerprint off a used glass. If he's there in some intelligence gathering capacity, the Chinese could then have him followed, or send him packing, or maybe even detain him for a day as a form of harassment, knowing that the U.S. government is powerless to do anything about it. They have us over a barrel. [1]http://blogs.scientificamerican.com/observations/what-could-criminals-do-with-5-6-million-fingerprint-files/ http://blogs.scientificamerican.com/observations/what-could-...