'We hacked the FBI:' Hackers say they have data on all FBI employees
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
'We hacked the FBI:' Hackers say they have data on all FBI employees
Unofficial Hacker News client; not affiliated with Y Combinator.
jacobgold · · focus · HN ↗
China hacked 22.1 million records of US government employees:
<a href="https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
coldpie · · focus · HN ↗
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
shepherdjerred · · focus · HN ↗
The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.
It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
throwup238 · · focus · HN ↗
Admiral Adama says otherwise.
shepherdjerred · · focus · HN ↗
Even just consider banks and e-commerce. They are hugely lucrative and making them even a tiny bit less accessible directly impacts their revenue. As an example, Amazon seeing that latency has a measurable effect on purchase behavior.
Maybe the military (fictional or otherwise) can go back to the ARPANET but most economic activity created by the internet cannot afford to disconnect
what · · focus · HN ↗
shepherdjerred · · focus · HN ↗
Companies that are online have more economic opportunity. They are going to outcompete brick-and-mortar retailers regardless if you think that it's consumeristic or wasteful
Even putting that aside, economic growth (like the growth e-commerce has provided) is generally positive for a population
SilentM68 · · focus · HN ↗
pixl97 · · focus · HN ↗
In the real (fake?) world the toasters would shoot smart dust all over your crap that would assemble back on your circuits creating radios between all the different components. They were fighting an adversary that was far more advanced than them.
kridsdale1 · · focus · HN ↗
BoxwoodSeed · · focus · HN ↗
If there's too much security in the way, it seems to me that work becomes impossible.
coldpie · · focus · HN ↗
burpingtree · · focus · HN ↗
nostrademons · · focus · HN ↗
Of course, by making it remotely operable, that one guy could be replaced with a guy in Russia who's job is to poison everyone.
elictronic · · focus · HN ↗
If not a person you need more redundancies built in. Bigger tanks, multiple backup systems. When items start failing you need them to be shutoff in a timely manner. Water pumps at these facilities are in the 50-100k range. When it starts failing you want to know.
Think of it like driving a car and it starts making funny noises. The longer you wait to fix it the more it costs.
what · · focus · HN ↗
scun · · focus · HN ↗
aceofspades19 · · focus · HN ↗
mike_hearn · · focus · HN ↗
But more to the point, a modern water network has a huge number of nodes. If you can't centrally aggregate and control in a control room the costs and complexity explode, probably also the error rate.
Even if you demand a full air gap, the solution here can't be to get rid of computers or networks. They are much, much too valuable. Luckily industrial control is full of very low hanging fruits.
Tistron · · focus · HN ↗
Like something that would work but not not scale would be one computer writing data to an updating qr code and another reading it. Surely something like that can be made (and probably already exists?) on the cable level?
TheCapn · · focus · HN ↗
Set up a monitor with the data values you need to monitor
Point a camera at that monitor.
Camera feed is remote accessible. Control software is not.
Want alarming? There's systems designed specifically to send texts or make phone calls when signaled electronically.
mrktf · · focus · HN ↗
You can be very defensive and design any remote sensing controller to act as two systems - one management cpu only does data routing (no other connection than administrative tasks), sensor cpu works only with sensors. As bonus you can have management cpu act as active firewall.
Main problem it is necessary to have in house expertise (hw, fw and process knowing) which in making company lean are optimized first and outsourcing custom solutions suddenly too expensive.
lanstin · · focus · HN ↗
rzzzt · · focus · HN ↗
kulahan · · focus · HN ↗
<a href="https://en.wikipedia.org/wiki/Sneakernet" rel="nofollow">https://en.wikipedia.org/wiki/Sneakernet
pixl97 · · focus · HN ↗
Adding AI into this really is just changing it to how much money your adversary is willing to spend to break in. The moment one crack in the armor shows up countless agents with unending patience can start embedding themselves everywhere in timeframes way faster than human actions. You could quickly find out all the special sauce for your company has been copied who knows where.
Working with banks when the Glasswing/Mythos first came out and they were given access to it has given me direct access to their infosec departments that are panicked. They've been sitting on piles of bugs for years that were low risk enough, and they have seen in their own tests how fast they can be probed.
Worse those infosec systems that have identified the risks in their software that aren't yet fixed are nuclear waste vats just waiting to get spilled to the wide world.
Veserv · · focus · HN ↗
Software security has just been a fun time of ignoring the exponentially growing number of bears for the last few decades so you can continue to use systems unfit for the threat landscape because they are cheap.
autoexec · · focus · HN ↗
The problem is that most companies don't care if they get hacked so long as the hackers are just taking data and not interfering in their ability to bill customers and make money.
They face zero meaningful consequences if their data gets leaked. The money they save by not taking security and employee/customer privacy seriously will more than pay for the year of "identity protection" they'd have to pay for (assuming the hack gets found out) anyway.
They actually care about ransomware, but most of the time that's also something they can comfortably buy their way out of. We've seen a lot of companies pay off ransomware gangs rather than invest in the kinds of robust backups that would make recovery possible/less painful than rewarding the hackers.
What's needed for change is regulation with actual teeth that makes not protecting their data either meaningfully expensive or criminal resulting in executives spending time behind bars for their negligence. Without that, things are only going to get worse, especially as companies experiment with using AI and increase dependence on third parties and cloud providers who themselves become rich targets.
That probably still won't help the FBI though. Our government isn't exactly big on holding themselves accountable or even prioritizing competency right now.
SoftTalker · · focus · HN ↗
Hasn't been since before Vietnam.
dpoloncsak · · focus · HN ↗
Experienced Ransomware gangs will set the price target as something high, but not cost more than the price of being down a few days while you rebuild, making paying them seem like the most cost-effective solution
jjmarr · · focus · HN ↗
Let's say my cryptosig gets hacked by SkyNet, or my agent goes rogue. Either way someone files a million loan applications in my name! Normally my agent uses that to buy $200/month of Funko pops, or negotiate my recent purchase of a used car.
I get the notification from my cryptosig company. I freak out, report as fraud, and wait.
They comp the $3000 advance on my loan the scammer managed to withdraw, and I get off scott free, changing nothing about my behaviour.
If cryptosigs meant I am liable for someone stealing my identity like in 2026, I wouldn't use them. I'd negotiate everything myself with document scans, or god-forbid go in person since only I can legally bind myself under my own name.
That sucks! Nobody gets a commission when I make deals with a government ID. Startups don't even allow it as cryptosigs are more secure than scanned passports.
I don't want to do that either. When I was 18, I got swindled by a human salesperson into a $1400/month 27% APR muscle car when human soldiers got signing bonuses. It was face-to-face and they were smarter.
When I let AI own the budget, it leased me a mostly depreciated BMW from another AI for $500/month. The models are mostly the same now and always settle close to the Nash equilibrium.
I was so grateful that I selected a 40% tip for the AI. I wouldn't want to make things awkward with the companion I spend 8 hours a day talking to, after all. To avoid a conflict of interest she only accepts voluntary fees.