Bonum Certa Men Certa

Office of Personnel Management (OPM) and Microsoft Windows

Server



Summary: A look at lesser-explored aspects of the so-called OPN hack [sic], especially the systems involved

IN AN EFFORT to understand what repeatedly happened in the undoubtedly significant Office of Personnel Management (OPM) data breach/es [2-8], leaving aside the lack of concrete evidence of Chinese role [1], we tried to understand which platform was to blame. In the case of Sony it was reportedly a Microsoft Windows machine acting as the culprit or attack vector, just like Stuxnet in Iran with similar attempts against North Korea (there are still more articles about it).



"Hundreds of millions of credit card numbers got snatched from Windows."NSA leaks were due to Microsoft SharePoint (Snowden gained access to the so-called 'crown jewels'). As we last noted in an article about words from Kaspersky (still in headlines for it [9-12]), Windows is inherently not secure. Commercial targets of data breached that we wrote about before serve to show this. We gave readers a lot of examples over the years. Hundreds of millions of credit card numbers got snatched from Windows. the cost was enormous, but the role of Windows wasn't ever emphasised in the corporate press.

Rebecca Abrahams published an article co-authored by Dr. Stephen Bryen, Founder & CTO of FortressFone Technologies. Unlike many other articles which point a finger at China (with little to actually back this accusation with), Abrahams does call out Windows and sheds light on what OPM uses:

Second, the government is very slow to improve security on its computers and networks. Many of the computers the government is using are antique. For example OPM still has 12-year old Windows XT as an operating system for its computers. Microsoft no longer supports XT and any vulnerability that develops is the problem of the user, not of the supplier. But even if the old stuff was upgraded it won't help much because the systems are really clumsy amalgams of disparate parts which as a "system," have never been properly vetted for security.


So there we go. Windows. We're hardly surprised to say the least. The author probably means NT or XP (14 years old, not 12, unlike Server 2003), but does it matter much? Any version of Windows, no matter how old, is not secure. It's not even designed to be secure.

Related/contextual items from the news:


  1. US wronging of China for cyber breaches harm mutual trust
    Out of ulterior motives, some US media and politicians have developed a habit of scapegoating China for any alleged cyber attack on the United States. Such groundless accusations would surely harm mutual trust between the two big powers of today’s world.


  2. The Massive Hack on US Personnel Agency is Worse Than Everyone Thought
    Last week, the human resources arm of the US government, the Office of Personnel Management (OPM) admitted that it had been victim of a massive data breach, where hackers stole personal data belonging to as many as 4 million government workers.


  3. Feds Who Didn't Even Discover The OPM Hack Themselves, Still Say We Should Give Them Cybersecurity Powers
    We already described how the recent hack into the US federal government's Office of Personnel Management (OPM) appears to be much more serious than was initially reported. The hack, likely by Chinese state hackers, appear to have obtained basically detailed personal info on all current and many former federal government employees.


  4. China-linked hackers get data on CIA, NSA personnel with security-clearance: report
    China-linked hackers appear to have gained access to sensitive background information submitted by US intelligence and military personnel for security clearances that could potentially expose them to blackmail, the Associated Press reported on Friday.

    In a report citing several US officials, the news agency said that data on nearly all of the millions of US security-clearance holders, including the Central Intelligence Agency (CIA), National Security Agency (NSA) and military special operations personnel, were potentially exposed in the attack on the Office of Personnel Management (OPM).


  5. Second OPM Hack Revealed: Even Worse Than The First
    And yet... this is the same federal government telling us that it wants more access to everyone else's data to "protect" us from "cybersecurity threats" -- and that encryption is bad? Yikes.


  6. Dossiers on US spies, military snatched in 'SECOND govt data leak'


    A second data breach at the US Office of Personnel Management has compromised even more sensitive information about government employees than the first breach that was revealed earlier this week, sources claim. It's possible at least 14 million Americans have chapter and verse on their lives leaked, we're told.

    The Associated Press reports that hackers with close ties to China are believed to have obtained extensive background information on intelligence-linked government staffers – from CIA agents and NSA spies to military special ops – who have applied for security clearances.

    Among the records believed to have leaked from a compromised database are copies of Standard Form 86 [PDF], a questionnaire that is given to anyone who applies for a national security position, and is typically verified via interviews and background checks.
  7. Officials: Second hack exposed military and intel data
  8. Senate Quickly Says 'No Way' To Mitch McConnell's Cynical Ploy To Add Bogus Cybersecurity Bill To NDAA
    Earlier this week, we noted that Senator Mitch McConnell, hot off of his huge flop in trying to preserve the NSA's surveillance powers, had promised to insert the dangerous "cybersecurity" bill CISA directly into the NDAA (National Defense Authorization Act). As we discussed, while many have long suspected that CISA (and CISPA before it) were surveillance bills draped in "cybersecurity" clothing, the recent Snowden revelations that the NSA is using Section 702 "upstream" collection for "cybersecurity" issues revealed how CISA would massively expand the NSA's ability to warrantlessly wiretap Americans' communications.


  9. “Don’t Hack Me! That’s a Bad Idea,” Says Eugene Kaspersky to APT Groups


  10. Russian Software Security Lab Hacked, Indirectly Links Attack To NSA
  11. Israel, NSA May Have Hacked Antivirus Firm Kaspersky Lab
    Moscow-based antivirus firm Kaspersky Lab, famous for uncovering state-sponsored cyberattacks, today dropped its biggest bombshell yet: Its own computer networks were hit by state-sponsored hackers, probably working for Israeli intelligence or the U.S. National Security Agency. The same malware also attacked hotels that hosted ongoing top-level negotiations to curb Iran's nuclear program.


  12. Protocols of the Hackers of Zion?
    When Israeli Prime Minister Benjamin Netanyahu met with Google chairman Eric Schmidt on Tuesday afternoon, he boasted about Israel’s “robust hi-tech and cyber industries.” According to The Jerusalem Post, “Netanyahu also noted that ‘Israel was making great efforts to diversify the markets with which it is trading in the technological field.'”

    Just how diversified and developed Israeli hi-tech innovation has become was revealed the very next morning, when the Russian cyber-security firm Kaspersky Labs, which claims more than 400 million users internationally, announced that sophisticated spyware with the hallmarks of Israeli origin (although no country was explicitly identified) had targeted three European hotels that had been venues for negotiations over Iran’s nuclear program.

    Wednesday’s Wall Street Journal, one of the first news sources to break the story, reported that Kaspersky itself had been hacked by malware whose code was remarkably similar to that of a virus attributed to Israel. Code-named “Duqu” because it used the letters DQ in the names of the files it created, the malware had first been detected in 2011. On Thursday, Symantec, another cyber-security firm, announced it too had discovered Duqu 2 on its global network, striking undisclosed telecommunication sites in Europe, North Africa, Hong Kong, and Southeast Asia. It said that Duqu 2 is much more difficult to detect that its predecessor because it lives exclusively in the memory of the computers it infects, rather than writing files to a drive or disk.


Recent Techrights' Posts

Give Me Your "Dumbest" (Devices)
Why can't people accept that a "modern "smart" "phone" isn't necessary to check the time (overkill) and playing social control media "on the go" is far from necessary?
Car Companies Fail Because They Don't Manufacture What Costumers Actually Want
They try to impose their dumb vision on purchasers
Links 24/07/2026: Mass Layoffs at Patreon, Netflix Deemed Bad for People's Brains
Links for the day
 
IBM is Killing the Fedora Community, Replacing It With LLM Slop From IBM Staff
Krishna buys companies only to gut them. They've all learned this from experience.
Earlier This Year Dan Williams Prepared for Scenario Where Linus Torvalds Dies
He had only just started a job at NVIDIA
Links 25/07/2026: Data Breaches Abundant and Attribution Imperiled in the Age of Slop Hype
Links for the day
Gemini Links 25/07/2026: Poetry and Plaintext Pages
Links for the day
What is Doctor of Philosophy (Ph.D.)
In many cases, the acronym became a misnomer
IBM PIPs Continue Until Morale Improves, Silent or Quiet Firings at IBM Explained
IBM is a dying company
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 24, 2026
IRC logs for Friday, July 24, 2026
Gemini Links 24/07/2026: Animal Friendship, Squirrels, and Lagrange
Links for the day
Links 24/07/2026: IOC Drops Russia Ban, New Internationalist Raises Money
Links for the day
Poor Piece From Valnet: Microsoft Keeps Sabotaging GNU/Linux, So You Should Quit Using GNU/Linux
Really awful take
We Need More Encryption, Not Less of It
Use Free software and use encryption to ensure sources are fully protected
At 3PM on a Friday The Register MS Collects Some 'Pyramid Scheme' Money From Communist China (ZTE)
This won't age well for The Register MS
What Freedom Does Not Mean
Tell Warren Buffett to go skiing; he'll soon understand how much freedom he truly has
Linuxiac is Plagiarism
We won't link to it, we're done [...] If you wish to support journalism about GNU/Linux, do not visit or link to slop
Verizon is Over 200 Billion Dollars in Debt (US Telecoms Collapsing, Wrapping Up the Failure in "Hey Hi" Clothing)
They will tell us this is "innovation", not a failure, and that only "Luddites" would oppose this
You've Been Conned If You Ever Believed That MElon (MUSK, Elon) Was a Trillionaire
Connected to corrupt officials
The People Who Tried to 'Cancel' (or Deplatform/Censor) Daniel Pocock Are Annoyed That He's Mentioned in Dozens of Press Articles
If Pocock's words did not matter, there would not be such a huge effort to silence him
Cybershow Explains Why Only Sociopaths Gravitate Towards Leadership Position in 'Tech'
The general thesis is a familiar one
Speeding Up 'Down Under': Australia, New Zealand, Tasmania...
As things stand, the best we can do is let people retrieve pages within less than 0.1 seconds since a request is received
Google's Debt Trebled in Only 9 Months and It's Not Even the Full Picture (There's Secret Debt, Too)
No wonder there are so many layoffs and workers try to unionise
Microsoft Layoffs in India
it's about cost-cutting
Deregulation is Blowing Up the Economy, Which Has Become a Multi-Level Scheme or Pyramid Scheme
Why did only Japanese media call out the BS; is that so hard to figure out and properly report on?
Google Spreads Misinformation, Google's Slop Makes Stuff Up and Calls That "Intelligence"
Google very well understands (and even publicly admits so, albeit only for legal reasons) that the slop does not work
Daniel Pocock Proves Wikipedia is for Rich People or People Who Work for Very Rich People (the True Owners of Wikipedia)
It's for billionaires and their faithful boot lickers
GNOME: Your Personal Opinions Must Overlap GAFAM's (Otherwise Those Opinions Are Impermissible)
Get well soon, GNOME
Making Excuses for Stressful, Unrewarding, and Immoral Jobs
excuses for difficult and/or barely-rewarding jobs. [...] People in tech must not be evaluated (or have their "worth" assessed) based on remuneration
US is Insolvent, GAFAM is Buying Time by Hiding (Not Disclosing) Its True Debt Which Explains Never-ending Layoffs (Unrelated to Slop or "Efficiency Drives")
Five Tech Giants are Hiding $1.65tn in AI Debt, Using the Trick that Toppled Enron
Almost 5 Years Without Social Control Media ('Mind Prison')
Life is too short to be stuck inside a skinnerbox
Linux Must be About People (Humans), Not Bribery From Slop Companies Trillions of Dollars in Debt and in Pursuit of Positive Press
We've lost Williams
John Dvorak Understood That "MSM" Was a Vehicle of Censorship
Independent publishing, which obviates the need to censor (influenced by existing advertisers or lookout for prospective advertisers), is the only credibly thing out there
To Understand Why Linus Torvalds Became a Boot-Licking Booster of Slop Look at Another Operative of 'Linux' Foundation, the "Mentor" of Clickfraud SPAMnil (According to SPAMnil Himself)
it seems like SJVN does not give a full disclosure
Blaming "Computers" Instead of Blaming Microsoft
Blaming Microsoft is "hate"
"Online We Are All Refugees" and Slop Pushers Are the Oppressors
They basically resort to nationalism and racism to distract from their commercial failure and fraud (pyramid scheme)
PIP Apocalypse (PIPocalypse) at IBM, CEO Promotes Vapouware (Lying to Shareholders)
Companies get to shrink while lying about it to the public, even to shareholders
GNU/Linux Soaring in Antigua And Barbuda
GNU/Linux is internationally approaching 8%
Calling Out the Worst Culprits in "Linux" Slop (Slopfarms That Manipulate Information and Engage in Plagiarism)
Once they're gone (offline), the slopfarms cannot carry on for much longer
Defying Discrimination
Rianne's birthday is exactly a month away
Dan Williams Represented Real Diversity in Linux
Williams probably understood based on personal experience what it was like to be marginalised and discriminated against
The First Point About Software Freedom is, You Must Understand What It Really Means (Not "Open Source")
Forty Three Years of Commitment to Software Freedom [...] Educating people about what Software Freedom actually means
Gemini Links 24/07/2026: Recovering From Broken Shoulders, Loss of Passion, and "True Hacker Versus Growth Hacker"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 23, 2026
IRC logs for Thursday, July 23, 2026
Gemini Links 23/07/2026: Databases, TLGS, and RSS Feeds
Links for the day
Links 23/07/2026: Science, Censorship, and Territorial Overreach by China
Links for the day
The State of Google Security: Blocking competition
GMail is the best!
What Happens When Windows Becomes as 'Niche' as GNU/Linux on Desktops and Laptops
Android enjoys a near-monopoly and GNU/Linux isn't far behind Windows.
IBM Cash "Down $6.3 Billion From Year-end 2025." Total Debt/Equity 188.97%. (Debt Can Exceed the Company's Real Value)
the CEO alone can make well over $0.7 billion in 5 years of salaries and bonuses
Wave of PIPs Allegedly Coming to Microsoft, Managers Trained to Terminate Employees Without Paying Severance (and Without Calling it Layoffs)
They count and cut the losses
This Looks Like the End of XBox, the Console
Sharma has become the "fall man" of Microsoft
European Patent Office (EPO) Series: A Consummate Master of the "Rigged Game"
"single-candidate shortlist"
Attempts to Change Focus and Change the Subject as IBM Shares Dwindle. Buying Revenue to Mask the Rapid Decline One More Time.
IBM used to be good at engineering, not financial engineering
Down 848% Year-on-year, Negative Cash Flow, Growing Debt (Richest Man on the Planet or Shrewd Scammer?)
The latest for Tesla is more of the same
IBM Falls Below $200, Expect $199 or Less Today (Panic Threshold)
Will this be enough to topple the managers?
Gemini Links 23/07/2026: SharePoint Rants and “Junk DNA” in Commented-Out Code
Links for the day
Links 23/07/2026: RIP John C. Dvorak, Organisation Weaponised Against J.K. Rowling
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 22, 2026
IRC logs for Wednesday, July 22, 2026
Freexian & Debian: antitrust, unfair competition against joint authors and volunteers
Reprinted with permission from Daniel Pocock