‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. shepherdjerred · · focus · HN ↗
        It used to be that nothing was secure but that was OK because at least adversaries would have to expend effort. If you are one of a million companies why would anyone hack you. Maybe if you are a target you need a lot of investment, but most orgs only prevent the most egregious of vulnerabilities.

        The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.

        It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.

        Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.

        1. autoexec · · focus · HN ↗
          &gt; Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.

          The problem is that most companies don&#x27;t care if they get hacked so long as the hackers are just taking data and not interfering in their ability to bill customers and make money.

          They face zero meaningful consequences if their data gets leaked. The money they save by not taking security and employee&#x2F;customer privacy seriously will more than pay for the year of &quot;identity protection&quot; they&#x27;d have to pay for (assuming the hack gets found out) anyway.

          They actually care about ransomware, but most of the time that&#x27;s also something they can comfortably buy their way out of. We&#x27;ve seen a lot of companies pay off ransomware gangs rather than invest in the kinds of robust backups that would make recovery possible&#x2F;less painful than rewarding the hackers.

          What&#x27;s needed for change is regulation with actual teeth that makes not protecting their data either meaningfully expensive or criminal resulting in executives spending time behind bars for their negligence. Without that, things are only going to get worse, especially as companies experiment with using AI and increase dependence on third parties and cloud providers who themselves become rich targets.

          That probably still won&#x27;t help the FBI though. Our government isn&#x27;t exactly big on holding themselves accountable or even prioritizing competency right now.

          1. SoftTalker · · focus · HN ↗
            &gt; Our government isn&#x27;t exactly big on holding themselves accountable or even prioritizing competency right now.

            Hasn&#x27;t been since before Vietnam.

          2. dpoloncsak · · focus · HN ↗
            &gt;We&#x27;ve seen a lot of companies pay off ransomware gangs rather than invest in the kinds of robust backups that would make recovery possible&#x2F;less painful than rewarding the hackers.

            Experienced Ransomware gangs will set the price target as something high, but not cost more than the price of being down a few days while you rebuild, making paying them seem like the most cost-effective solution

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.