Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Page / 2
Next Page Arrow Left
Link Posted: 2/9/2016 10:24:45 AM EDT
[#1]


The hackers told Motherboard they accessed the information by
compromising an email account of a Justice Department official. They
used the email address to "social engineer” access to the DOJ intranet, calling technical support to give them a password.


"So I called up, told them I was new and I didn't understand how to get past [the portal],” one of the hackers told Motherboard. "They asked if I had a token code, I said no, they said ‘that's fine – just use our one’.”

View Quote


https://www.rt.com/usa/331788-hacker-doj-fbi-doxxed/



Wonder if the IT worker who gave out the info could be criminally charged?  Should.  This crap happens all too often.
Link Posted: 2/9/2016 12:57:15 PM EDT
[#2]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
But no one hacked into the Spawn of Satan's unsecured private server..............so I have been told.
View Quote


They never had to.  All they needed to do was hold a fundraiser and the world was their oyster.

Link Posted: 2/9/2016 1:12:06 PM EDT
[#3]

Discussion ForumsJump to Quoted PostQuote History
Quoted:


What's the issue with the OFFICIAL WORK contact info (basically a phone/e-mail directory) of PUBLIC EMPLOYEES being PUBLIC?
View Quote
I was wondering the same thing. You probably should not work for the gov is you don't want people to know you work for the gov.



 
Link Posted: 2/9/2016 1:14:50 PM EDT
[#4]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
The more interesting thing here is that we actually have 20,000 FBI agent.
View Quote



not really.  I bet it is more like FBI employees - not all of whom are agents...
Link Posted: 2/9/2016 1:16:37 PM EDT
[#5]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
STOP treating hacking as a crime, and start treating it as a terroristic act. F'n FIND them and KILL them. Doesn't matter if they're a 30-year-old foreign agent or a 16-year-old dysfunctional teenager. END them. You'll see a lot of this crap stop.

Too many people believe that the stuff they do over the internet has no consequences... about time it does.
View Quote


Yeah, that won't fucking be abused at all.  

We already have local departments abusing the "terror" moniker to justify some atrocious bullshit they've done.  Brilliant move what could possibly go wrong?
Link Posted: 2/9/2016 1:16:59 PM EDT
[#6]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Why the fuck do we have 20000 FBI employees?
View Quote


that isn't that many. The FBI covers all of the US and also works overseas

they have labs, technicians, secretaries, janitorial staff, clerks, trainers, medics, etc.

they probably have a couple hundred folks in IT alone. between networks, programmers, analysts, operators etc.
Link Posted: 2/9/2016 1:19:28 PM EDT
[#7]
#ohwell
Link Posted: 2/9/2016 1:24:13 PM EDT
[#8]
You would think they would do a better job at keeping information secure
Link Posted: 2/9/2016 1:33:36 PM EDT
[#9]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

https://www.rt.com/usa/331788-hacker-doj-fbi-doxxed/

Wonder if the IT worker who gave out the info could be criminally charged?  Should.  This crap happens all too often.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
The hackers told Motherboard they accessed the information by compromising an email account of a Justice Department official. They used the email address to "social engineer” access to the DOJ intranet, calling technical support to give them a password.


"So I called up, told them I was new and I didn't understand how to get past [the portal],” one of the hackers told Motherboard. "They asked if I had a token code, I said no, they said ‘that's fine – just use our one’.”



https://www.rt.com/usa/331788-hacker-doj-fbi-doxxed/

Wonder if the IT worker who gave out the info could be criminally charged?  Should.  This crap happens all too often.


Practically anyone who ever sent an email to Hilary's unsecured server did the same thing.
Link Posted: 2/9/2016 1:37:53 PM EDT
[#10]
Homeland Security is an oxymoron.
Link Posted: 2/9/2016 11:48:05 PM EDT
[#11]
Bet the admin password was "administrator"
Link Posted: 2/9/2016 11:52:27 PM EDT
[#12]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
still not close to what the OPM allowed.  everyone with a clearance got fucked by that one.
View Quote


I laughed pretty hard when I got that letter in the mail.

All that bullshit for a TS/SCI and all they sent me was a "whoops lol."
Link Posted: 2/9/2016 11:58:41 PM EDT
[#13]
I don't get it.... why cant these hackers erase everyone's mortgages and credit card debts instead of this bullshit...
Link Posted: 2/10/2016 12:12:24 AM EDT
[#14]
Now, just remember this when you have the head of the FBI nearly demanding the developers of crypto adopt some standard that will allow them unfettered access to a back door in all users of that crytographic standard.  

You have an agency that cannot protect its own employee data wanting the literal keys to every method of secure communications used by a nation.  The fact that FBI Janitor Bob Robinson lives at 123 Anystreet Quantico, VA is not something that most hackers or hacktivist groups give two shits about.  When the FBI has those keys, they become the holy grail of hacking and they will be acquired by outside parties.
Link Posted: 2/10/2016 12:46:46 AM EDT
[#15]
I'm reading between the lines here that a top level DOJ boss clicked on something stupid in a suspicious email or ran his mouth too much outside the office.
Link Posted: 2/10/2016 12:55:59 AM EDT
[#16]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Why the fuck do we have 20000 FBI employees?
View Quote


20,000 FBI guys / 50 states = 400 employees per state
Some state have more, some will have less.
Not to mention, US Territories.
FBI has their own uniformed police force
Not all are gun and badge carriers, but techs and scientists.
Most are a bunch of nerds that don't like to get their hands dirty.

What are you scared of ?
Link Posted: 2/10/2016 8:07:57 AM EDT
[#17]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
What's the issue with the OFFICIAL WORK contact info (basically a phone/e-mail directory) of PUBLIC EMPLOYEES being PUBLIC?
View Quote



"Hi Marcy, this is Bob in section 210 at building 27, ... Yeah the AC is still broken here... Look I have a problem, your boss Mr. Gibbons called here and asked me to set up access to a new network for him, but I don't have anyone from that department to check it for me. Could you try logging in for me to see if it works? The address, sure it's www..."

Nope, no issue at all...
Link Posted: 2/10/2016 8:42:31 AM EDT
[#18]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I'm reading between the lines here that a top level DOJ boss clicked on something stupid in a suspicious email or ran his mouth too much outside the office.
View Quote


Social engineering is the method of convincing people to give up information or authorization that they should not have given.  
Each piece may not seem critical at the time, but it can start adding up.

Back in my 2600 days,  it was the easiest way of getting access.
Link Posted: 2/10/2016 8:46:27 AM EDT
[#19]

Discussion ForumsJump to Quoted PostQuote History
Quoted:


STOP treating hacking as a crime, and start treating it as a terroristic act. F'n FIND them and KILL them. Doesn't matter if they're a 30-year-old foreign agent or a 16-year-old dysfunctional teenager. END them. You'll see a lot of this crap stop.



Too many people believe that the stuff they do over the internet has no consequences... about time it does.
View Quote
Good candidate for dumbest post of the day.

 
Link Posted: 2/10/2016 8:58:56 AM EDT
[#20]
Link Posted: 2/10/2016 9:06:23 AM EDT
[#21]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


I laughed pretty hard when I got that letter in the mail.

All that bullshit for a TS/SCI and all they sent me was a "whoops lol."
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
still not close to what the OPM allowed.  everyone with a clearance got fucked by that one.


I laughed pretty hard when I got that letter in the mail.

All that bullshit for a TS/SCI and all they sent me was a "whoops lol."


Same.  It took me almost 2 fucking years to get through that entire process end to end.  Toss in the lifestyle poly and it was even worse.  Then I get a goddamn letter saying "Our bad, here is some credit monitoring."  
Link Posted: 2/10/2016 9:12:31 AM EDT
[#22]
Link Posted: 2/10/2016 9:14:06 AM EDT
[#23]
Link Posted: 2/10/2016 9:18:56 AM EDT
[#24]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Our National Security is a big vagina.
View Quote


I was watching a show the other week about the White House and Secret Service.  Basically, it was a brag piece of how hardened/secretive it is etc....


Yet some jabroni from PA flew his gyrocopter right to the front lawn.
Link Posted: 2/10/2016 2:27:59 PM EDT
[#25]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Should they be, though?

Because here's the thing:

The hackers posed as a DOJ official. This means they posed as someone who has juice, or at least someone who is the favored pet of somebody that has juice.

Those sorts of people do not like being told "no"

By "do not like" I mean they raise holy hell if they don't get what they want exactly when they want it. Even if it is against policy.

They get mad, they start making phone calls or firing off emails and that communication gets to somebody who goes to the supervisors above the person that said "no" on the phone and insists that they just "fix it" and make the person happy. Against policy? Against best practices? MAKE THEM HAPPY RIGHT GODDAMN NOW.

And that happens. Over. And over. And over. And over. Again. And again. And again.

...to the point where it becomes an SOP for them to have a fucking master token for what is supposed to be a two-factor authentication system that they hand out because some entitled ivy league shit working in DOJ will go fucking apoplectic if they don't get what they want exactly when they want it.

So, no...I wouldn't lock the employee who handed out that token up for anything because that little cog does not steer the fucking machine. The people who steer the fucking machine should be the ones ground to powder over this sort of bullshit...but they never are.

You want to talk about privilege, that's privilege.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
The hackers told Motherboard they accessed the information by compromising an email account of a Justice Department official. They used the email address to "social engineer” access to the DOJ intranet, calling technical support to give them a password.


"So I called up, told them I was new and I didn't understand how to get past [the portal],” one of the hackers told Motherboard. "They asked if I had a token code, I said no, they said ‘that's fine – just use our one’.”



https://www.rt.com/usa/331788-hacker-doj-fbi-doxxed/

Wonder if the IT worker who gave out the info could be criminally charged?  Should.  This crap happens all too often.


Should they be, though?

Because here's the thing:

The hackers posed as a DOJ official. This means they posed as someone who has juice, or at least someone who is the favored pet of somebody that has juice.

Those sorts of people do not like being told "no"

By "do not like" I mean they raise holy hell if they don't get what they want exactly when they want it. Even if it is against policy.

They get mad, they start making phone calls or firing off emails and that communication gets to somebody who goes to the supervisors above the person that said "no" on the phone and insists that they just "fix it" and make the person happy. Against policy? Against best practices? MAKE THEM HAPPY RIGHT GODDAMN NOW.

And that happens. Over. And over. And over. And over. Again. And again. And again.

...to the point where it becomes an SOP for them to have a fucking master token for what is supposed to be a two-factor authentication system that they hand out because some entitled ivy league shit working in DOJ will go fucking apoplectic if they don't get what they want exactly when they want it.

So, no...I wouldn't lock the employee who handed out that token up for anything because that little cog does not steer the fucking machine. The people who steer the fucking machine should be the ones ground to powder over this sort of bullshit...but they never are.

You want to talk about privilege, that's privilege.


Oooooh! kinda like Hilary you mean... ?
Link Posted: 2/10/2016 2:41:10 PM EDT
[#26]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
STOP treating hacking as a crime, and start treating it as a terroristic act. F'n FIND them and KILL them. Doesn't matter if they're a 30-year-old foreign agent or a 16-year-old dysfunctional teenager. END them. You'll see a lot of this crap stop.

Too many people believe that the stuff they do over the internet has no consequences... about time it does.
View Quote


The overwhelming majority of gov't IT infrastructure is run by either by incompetent "civil servants" using obsolete equipment and software, or by crony contractors selected by crooked political appointees and required to use the same obsolete equipment and software.  

The idea that they're going to be catching anyone is a fantasy - these agencies are fundamentally dysfunctional, and they're incapable of doing it.     The entire government is groaning under the weight of its own incompetence, and you expect them to play super-sleuth?    They can't even keep their own people from handing out passwords to damn near anyone.
Link Posted: 2/10/2016 3:55:56 PM EDT
[#27]
I read that the IRS was hacked again, but they are claiming no info was taken, but people will be getting a letter
Link Posted: 2/10/2016 3:59:01 PM EDT
[#28]
OPM, DHS, FBI...

Yet they still haven't compromised and leaked the NFRTR.

Pathetic.
Link Posted: 2/10/2016 4:10:12 PM EDT
[#29]
so where does one see the information?
Link Posted: 2/10/2016 4:11:50 PM EDT
[#30]
Lists everywhere..we need a list of all the people making lists..
Link Posted: 2/10/2016 4:15:19 PM EDT
[#31]
Public office should be public information.
Link Posted: 2/10/2016 4:22:03 PM EDT
[#32]
I have a family member who is one of the gun toting agents.   He doesn't divulge much but he investigates some pretty heavy organizations.  

Not good news.

Link Posted: 2/10/2016 6:26:29 PM EDT
[#33]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
STOP treating hacking as a crime, and start treating it as a terroristic act. F'n FIND them and KILL them. Doesn't matter if they're a 30-year-old foreign agent or a 16-year-old dysfunctional teenager. END them. You'll see a lot of this crap stop.

Too many people believe that the stuff they do over the internet has no consequences... about time it does
View Quote


I'm with this guy. Give the .gov more power to determine what is/isn't terrorism, and then let them execute the accused.

Nothing could go wrong!
Link Posted: 2/10/2016 6:37:01 PM EDT
[#34]
I say Hillary is behind it as a diversion from them breathing down her neck.
Link Posted: 2/11/2016 11:06:39 AM EDT
[#35]
Link Posted: 2/11/2016 11:17:29 AM EDT
[#36]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
What's the issue with the OFFICIAL WORK contact info (basically a phone/e-mail directory) of PUBLIC EMPLOYEES being PUBLIC?
View Quote

This is what I was wondering. So they got their email address, big f#$%Ing deal.

Or was it all of their home addresses, photos, and work schedules that got published?
Link Posted: 2/11/2016 11:19:44 AM EDT
[#37]
Scully, Dana...
Link Posted: 2/11/2016 11:20:15 AM EDT
[#38]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
We have some seriously incompetent people running the US government and it's various agencies; unfortunately I'm not surprised.  
View Quote

File early if you're due a refund. The IRS was hacked and someone may be trying to beat you to it.
Link Posted: 2/11/2016 11:29:01 AM EDT
[#39]
Is it bad that I don't care?  This stuff happens all the time to all sorts of people.
Link Posted: 2/11/2016 11:32:03 AM EDT
[#40]
I agree with John_Wayne777 and boltcatch. The work I've done with government IT folks has shown me that they're mostly mediocre to incompetent and led by whiny, entitled bitches who general don't know their ass from their elbow.
Link Posted: 2/11/2016 7:34:19 PM EDT
[#41]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I agree with John_Wayne777 and boltcatch. The work I've done with government IT folks has shown me that they're mostly mediocre to incompetent and led by whiny, entitled bitches who general don't know their ass from their elbow.
View Quote


I've found that to be a function of the paltry salaries they are willing to pony up with the ridiculous requirements to accompany them.  Combine that with the issue that the FBI brought up, being that the zero tolerance for marijuana use by anyone in federal service, and you have a recipe for mediocrity.  Especially if you are a white guy trying to land a job in an affirmative action paradise.
Link Posted: 2/11/2016 7:36:51 PM EDT
[#42]
"But by god, let's keep beating the drum about cell phone encryption, because we want to lose your data, too!"
Page / 2
Next Page Arrow Left
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top