back to article Audit finds new flaw at US Office of Personnel Management

A security review that followed the original hack at the US Office of Personnel Management (OPM) has turned up a new, but hopefully-unexploited, vulnerability. The “Electronic Questionnaires for Investigations Processing” system, abbreviated to e-QIP, was found to be vulnerable under the review, and will be taken offline for …

  1. Anonymous Coward
    Anonymous Coward

    Only 18 million?

    I appreciate understatement, but that takes the cake.

  2. Robert Helpmann??
    Childcatcher

    Stop the Madness

    ...one response may be for the US government to issue fewer clearances.

    Not likely given that clearances are linked to positions and the information employees and contractors are allowed to handle. A more realistic response might be to extend the time between the periodic background checks required to maintain a clearance or to change the way follow-up investigations are run. Of course that might lessen the effectiveness of the process, so not necessarily a great idea either. Perhaps it would be better for the government to get a realistic grasp on the concept of total cost of ownership instead of massaging the data to win elections. Now why don't we have a flying pig icon?

    1. Wzrd1 Silver badge

      Re: Stop the Madness

      Flying pig hell, should be a dunce cap.

  3. Destroy All Monsters Silver badge
    Facepalm

    “This proactive, temporary suspension of the e-QIP system will ensure our network is as secure as possible for the sensitive data with which OPM is entrusted”

    Is this some kind of shitty Hollywood "comedy" playing?

    1. Pascal Monett Silver badge
      Coat

      Of course. Haven't you noticed the awards ceremony every four years ?

      1. Wzrd1 Silver badge

        "Haven't you noticed the awards ceremony every four years ?"

        No, that's the real comedy act. This is just the warm-up act.

        Although, the second warm-up act is one political party being forced to switch from a clown car to a clown bus.

  4. Antonymous Coward
    Holmes

    Not competent.

    Perhaps US gov should contract all this sort of security related stuff out to a company with a good security record?

    1. Wzrd1 Silver badge

      Re: Not competent.

      Even money, that's *who* hacked OPM. What is known is it was PRC in origin.

  5. Rich 11
    Flame

    Lo-tech hi-sec

    The discovery of the vulnerability, the newswire says, has some agencies switching to handling security clearance information on paper

    Typewriters and carbon paper. Just remember to dispose of the carbon sheets and the ribbon cassette properly.

    1. Wzrd1 Silver badge

      Re: Lo-tech hi-sec

      "Typewriters and carbon paper. Just remember to dispose of the carbon sheets and the ribbon cassette properly."

      That leaves two forms, one immense in pages. The SF85 for general public trust and the SF86 for an actual clearance.

      That is what e-Qip was filling out, the SF86. The papers, when printed are labeled SF86.

      I know, I did one not all that long ago.

      So, I'm quite enraged over this on two parts. One, I'm an information security professional and this is an exhibition of the most mind boggling incompetence imaginable. On the other side, I'm immensely pissed off, as my family's information is in there as well.

      They're a bunch of incompetent, myopic, anencephalic arboreal misanthropes and the lot of them, from the junior IA staff to the IAM and DAA should be given the sack.

      Preferably, with the sack filled with venomous snakes.

  6. Warm Braw

    Why do so many people *need* security clearance?

    That's the question that seems to stand out.

    Are these low level functionaries who are being "security cleared" as a kind of band-aid to mitigate the lack of data security in the systems they are operating - in which case there's a much bigger IT issue lurking round the corner?

    Or is the secret "inner state" really that big - in which case perhaps its size is the reason for its vulnerability?

    1. Sir Runcible Spoon

      Re: Why do so many people *need* security clearance?

      Don't forget: a lot of these jobs will involve access to buildings as well as networks. Even if someone doesn't have clearance to get into the 'secure' room, they could still do something nasty in the canteen where people with all sorts of clearance will visit at some point.

      1. Wzrd1 Silver badge

        Re: Why do so many people *need* security clearance?

        Some work on unclassified networks, but required a clearance for classified threat briefings. Some work on classified networks or sensitive networks and require a classification background investigation one level higher than their duties because of regulations that insist those with such access are of impeccable character.

        Even a public trust position requires much of the same background investigation.

        1. Warm Braw

          Re: Why do so many people *need* security clearance?

          >Even a public trust position requires much of the same background investigation.

          Why? If someone's dealings in a position of public trust are transparent, you don't need to do background checks because their activities are in full public view and you can trust the public to keep an eye on them.

          And if their dealings are covert as a matter of policy or practice, then all background checks do is to ensure public positions are stuffed with people who will do what they're told "because national security, drugs, children....". Now clearly you need some of those people, just as you need a bunch of people who like guns and can be convinced they're serving some higher cause by pointing them at anyone they're told to, but if you have too many, they have a habit of dictating public policy rather than supporting it.

  7. Mark 85
    Facepalm

    And the hits stupidity just keeps on coming.....

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like