11 ms·
I'm in the same boat. I'm not sure if you've had any kind of clearance, or know what kind of info you have to give for the investigations (everything), but this
by scrapcode 11y ago
I'm in the same boat. I'm not sure if you've had any kind of clearance, or know what kind of info you have to give for the investigations (everything), but this will be terrible for generations I presume. Instead of offering us 18 measly months of credit monitoring, they should offer lifetime/18+ years credit monitoring for any dependents involved in the paperwork.
I suspect this will cost their ass.
- hrehhf 11y agoIt sure would help all of us if that kind of background info were no longer used for verifying identity or granting credit. Info like SSNs, addresses, etc. never really was _secret_ anyway, it just wasn't all compiled into one place and for so many people.
- scrapcode 11y agoExactly my point. It has never been a good idea to use something like a social security number and the high school you graduated from to authenticate you as a person. But no one gives a shit because it works for the majority. But most importantly, because that problem isn't being addressed by anyone. Securing a bunch of G employee's information is much less exciting than building the newest SaaS app that gets a few million in funding.
- engi_nerd 11y agoHow do people take advantage of this 18 months of monitoring? My wife and I are almost certainly in the impacted population (and the fact that we've had 4 separate fradulent activities on our accounts in the past month isn't helping...)
- scrapcode 11y agoI was sent an e-mail to my .gov address with a code to signup for the service.
- mirimir 11y agoSadly enough, that would be an obvious phishing ploy.
- engi_nerd 11y agoI'm a former fed...If what I'm hearing is true and they got access to SF86 data on EVERYONE then we are all screwed. Just from that alone the attackers would be able to build a huge map of all sorts of programs that the government has not acknowledged.
- mokus 11y agoAccording to the OPM's web site[0], notifications for the first breach they announced have been completed, and notifications for this newly announced one have not yet begun (see the end of bullet point 2). I don't believe they have officially decided yet what sort of remedy they will offer either - I'm really hoping it'll be a lot more than the 18 months they offered for the first one. A period measured in decades would be more appropriate. [0]https://www.opm.gov/cybersecurity/ https://www.opm.gov/cybersecurity/