The Story WWDC Week Buried

The Story WWDC Week Buried

Tech News data breach opm security two-factor-auth wwdc 2015

So this is WWDC week, and my Twitter timeline is exactly what you'd expect: everyone losing it over Apple Music, Beats 1, Jimmy Iovine talking like he's hosting a radio show from 1996, and about four hundred hot takes on whether Connect is going to be the new iTunes Ping (it will be, dont @ me). Ill probably write something about Apple Music once I've actually used it, because right now its just a keynote slide and a promise, and Ive learned not to get excited about promises from big companies until I can put my hands on the thing.

What I actually want to talk about is smaller and got buried under all that noise, which is exactly why it bugs me.

Last Thursday the Office of Personnel Management confirmed a breach affecting the personal data of up to 4 million current and former federal employees. Names, addresses, social security numbers, employment history, some of it going back years. A handful of reports have pointed toward hackers based in China, though nobody's said that officially and I'm not going to pretend I know more than the people actually investigating it. What I do know is this: it's the kind of story that should be the biggest tech news of the month and instead it got a day and a half of coverage before Apple Music ate the internet.

I dont think that's an accident exactly, its just how attention works. A new streaming service with a slick keynote and a British DJ is fun to talk about. A federal HR database getting cracked open is not fun, its just scary, and scary doesn't get retweeted the same way excitement does.

Heres my actual opinion on it, for what its worth: I am not remotely surprised this happened. Ive done freelance contract work for a couple of government-adjacent outfits over the years and the amount of stuff still running on infrastructure that predates me is genuinely wild. One place I worked with in 2012 had a production system that only worked correctly in Internet Explorer 8. Not because anyone loved IE8, but because rewriting it wasnt in anyones budget and nobody wanted to be the person who broke it. I'd bet real money OPM has systems in a similar spot, held together with duct tape and nobody with the authority to say "we need to rip this out and it's going to cost a fortune."

(Sidebar, completely unrelated except that it put me in a bad mood this week: I spent forty five minutes on hold with my own state's DMV website trying to renew a registration online, got kicked back to a login screen twice, and eventually just drove there in person on Saturday morning. Waited in a folding chair for an hour. Government software is government software whether its protecting your SSN or letting you renew a license plate, and it usually shows.)

The part that actually changed my behavior this week wasnt the breach itself, it was just sitting with the idea that a lot of my own passwords are old and lazy. I finally went and turned on two factor everywhere I could Thursday night — Gmail, Dropbox, the works — and moved off the three-password rotation Ive apparently been running since roughly 2009. I'd been meaning to do this for over a year. Nothing like reading about millions of SSNs sitting in a database somewhere to actually get you off your ass.

I'm not saying set up 2FA because of one specific hack, thats not really how any of this works, breaches happen constantly and mostly quietly. Im saying I'd been putting it off out of laziness, not because I thought I was fine, and this was the nudge. If you're the type who's also been meaning to do it: Authy is decent, Google Authenticator works, either one takes fifteen minutes and covers most of the accounts that would actually ruin your week if someone got into them.

Anyway. Apple Music launches at the end of the month and Ill have opinions on it soon enough, don't worry. For now Im just annoyed that a real security story got a news cycle and a half while a beta streaming app is going to get three weeks.