'We hacked the FBI:' Hackers say they have data on all FBI employees
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
'We hacked the FBI:' Hackers say they have data on all FBI employees
Unofficial Hacker News client; not affiliated with Y Combinator.
jacobgold · · focus · HN ↗
China hacked 22.1 million records of US government employees:
<a href="https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
coldpie · · focus · HN ↗
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
josephg · · focus · HN ↗
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
taurath · · focus · HN ↗
I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too.
gchamonlive · · focus · HN ↗
Bluestein · · focus · HN ↗
gchamonlive · · focus · HN ↗
Bluestein · · focus · HN ↗
gchamonlive · · focus · HN ↗
Bluestein · · focus · HN ↗
gspr · · focus · HN ↗
We are headed for scary waters.
asdf88990 · · focus · HN ↗
Only just when we started to have a resemblance of security we got agile and startups breaking things (making rubbish software to capture a few bucks faster) and now vibe coding and llm assisted hacking.
The point of my, arguably rant, is that there is nothing new under the sun.
gspr · · focus · HN ↗
TeMPOraL · · focus · HN ↗
It's not a guarantee this time will be the same - but it should temper the worry somewhat.
lazide · · focus · HN ↗
Previously no one was dumb enough to put that in one electronic database - it was on paper.
This is going to get orders of magnitude worse.
TeMPOraL · · focus · HN ↗
lazide · · focus · HN ↗
gchamonlive · · focus · HN ↗
goonersallofyou · · focus · HN ↗
ChrisMarshallNY · · focus · HN ↗
After the DOGE debacle, I suspect that all the previously really secure stuff, is now out there, too. In fact, I wouldn’t be surprised if some of these leaks, came from that.
FBI employee data is very bad.
dasil003 · · focus · HN ↗
bch · · focus · HN ↗
This might be part of it...
> Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things
But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit.
generic92034 · · focus · HN ↗
mitxela · · focus · HN ↗
lesostep · · focus · HN ↗
The only solution I can come up with is some form of certification or paid code review from a third party. I know that at least for Windows prior to 7 Microsoft actually allowed some parties to come in and check the code/checksum on an air-gaped computer. We somehow moved to "trust more" in the last decade, and now we can trust nobody
AlotOfReading · · focus · HN ↗
parineum · · focus · HN ↗
ChrisMarshallNY · · focus · HN ↗
LLMs have been a huge force multiplier. Here.
If that data got out (which probably happened within hours of the data being dumped to insecure storage), then it’s probably already been analyzed and used to leverage access.
parineum · · focus · HN ↗
ChrisMarshallNY · · focus · HN ↗
Why are you so interested in defending DOGE?
noduerme · · focus · HN ↗
Not all hacks are caused by pure negligence, laziness or stupidity, but most of them are. Even a little effort goes a long way.
My grandfather spent a couple decades as a builder, ran a construction crew. Whatever the project was, he wanted to know everyone he hired personally was going to reinforce and report to him anything they had the slightest doubt about. "Always hammer in an extra nail" was basically his motto.
What we do ain't that different. The difference is that when an apartment building collapses, it's bigger news than when a govenrment database does.
josephg · · focus · HN ↗
Also when a building collapses, people blame the builders. When software leaks user data, the engineers and companies face no repercussions.
taurath · · focus · HN ↗
duskdozer · · focus · HN ↗
TeMPOraL · · focus · HN ↗
- nothing is, can be, or even should be 100% secure; the optimal rate of security incidents in society is not 0 (with apologies to 'patio11)
- security is a simultaneous trade-off against costs and usability, and those two other factors are more important:
-- security is achieved primarily through raising costs for attackers to beyond profitability, and reducing impact of such attacks (due to "not in isolation from the world" below, this also mostly translates to costs)
-- if "properly secured" (in the current cybersecurity sense) product/service cannot fulfill its function anymore, then you may just as well not make it; either way, no point in paying you for security work
- security isn't done in isolation from other systems and the world at large; "if this happens we'll go straight to filing crime report with the police" is perfectly legitimate security measure (even if it works somewhat less well on the Internet); similarly, "this is secured by us having insured against it" is also a valid solution to some security problems
NooneAtAll3 · · focus · HN ↗
k1t · · focus · HN ↗
rolymath · · focus · HN ↗
deaton · · focus · HN ↗
Cpoll · · focus · HN ↗
taurath · · focus · HN ↗
Those running projects with these beliefs are sputtering and producing impressive PoCs that struggle to make it into production - either through underestimating the amount of detail needed to scale, or often throwing away good practices in favor of letting LLMs handle tradeoffs that later make changes slow to a crawl.
Theres plenty of good ways to utilize LLMs to speed things up, but so many teams got so incentivized by management to move fast at any cost that they’ve thrown out “load-bearing” good practices for software. That bet hasn't been paying off the way they’d hoped. It’s now clear that they thought they’d be able to massively downsize the engineering orgs. Massive token spend is giving very little RoI and now like other companies they’re trying to rein in the biggest spenders who are often not producing value.