‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. josephg · · focus · HN ↗
        &gt; It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

        Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

        We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.

        1. msla · · focus · HN ↗
          The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn&#x27;t have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans.
          1. awesome_dude · · focus · HN ↗
            There&#x27;s absolutely no way to account for humans, who can be tricked, or pressured, or just make human sized mistakes.
            1. josephg · · focus · HN ↗
              Again, of course there is.

              Decades ago, I worked in a bank in an old building. The door had a card reader for access. You boop your card and the door opened. People would hold the door open for each other all the time out of politeness, even when they didn&#x27;t know each other. Security told us not to do that, but it&#x27;s hard to convince people to stop being polite.

              I had a laptop stolen from my desk in a place like that once. (Not a bank - but similar door-card reader system). This guy came in in the middle of the day, wearing overalls. He confidently walked through the door after someone, like he belonged there. He walked up to my desk, swiped my laptop and just strolled out.

              At the bank, they&#x27;ve replaced the door with mechanical gates and a security guard. The gates - physically - only let one person to walk through at a time. You can&#x27;t hold a gate open any more. And the security guards stop anyone who tries.

              Is it 100% foolproof? No. But it&#x27;s way more secure. It would have stopped that laptop thief.

              There&#x27;s this pernicious, defeatist attitude that if you can&#x27;t make a system 100% secure, so you shouldn&#x27;t try. That&#x27;s misguided. Most systems can be made orders of magnitude more secure than they are today. It just takes a bit of care and work.

              1. wombatpm · · focus · HN ↗
                As soon as you make something foolproof, the universe evolves a better fool
                1. awesome_dude · · focus · HN ↗
                  This is the key truth that we keep forgetting
                  1. josephg · · focus · HN ↗
                    I&#x27;m not really sure what point you&#x27;re trying to make, or how this relates to computer security.
                    1. awesome_dude · · focus · HN ↗
                      Funny - now you&#x27;re talking about context...
                      1. josephg · · focus · HN ↗
                        You seem mad about something I&#x27;ve said? I&#x27;d appreciate if you come out and say it instead of making vague insults, awesome_dude.
                2. josephg · · focus · HN ↗
                  Fine. Make the universe work for it. The whole system becomes more resilient as a result.

                  Look at our immune system. Incredibly complex and clever, and able to keep us alive in the face of all sorts of pathogens. It exists because of this cat and mouse game, played over millions of years.

                  There&#x27;s people in the highlands of PNG who regularly eat each other. Of course, many are thought to have died due to prion diseases. But now these tribespeople seem to have become largely immune to prion disease. Incredible.

                  1. awesome_dude · · focus · HN ↗
                    We still get diseases though, proving the point that millions of years of evolution are still not enough to build a perfect defence.

                    Your comment on PNG, seems to ignore Kuru

                    1. defrost · · focus · HN ↗
                      It explicitly mentions Kuru as &quot;prion disease&quot;, it ignores that the mortuary practice of eating various parts of respected dead has long passed in time .. although the lingering effect on the woman and children that ate portions of the brain in the 1970s, early 1980s, is still residual in a very few.
                      1. awesome_dude · · focus · HN ↗
                        The claim is that people in PNG are &quot;largely immune&quot; to these diseases, where kuru shows that they are not, and the &quot;cure&quot; was a stop in the practice, not some evolutionary upgrade
                        1. ericbarrett · · focus · HN ↗
                          While you are correct that the disease has died out due a change in their funerary practice, the claim stands:

                          &gt; In 2009, researchers at the Medical Research Council discovered a naturally occurring variant of a prion protein (PrnP) in a population from Papua New Guinea that confers strong resistance to kuru. In the study, which began in 1996, researchers...identified a variation in the prion protein: G127V....G127V polymorphism is the result of a missense mutation, and is highly geographically restricted to regions where the kuru epidemic was the most widespread.

                          <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Kuru_(disease)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Kuru_(disease)

                        2. defrost · · focus · HN ↗
                          They are largely immune to Kuru - the number of people that could contract it (ie. the number who ate brain) was significantly larger than the number of people who actually did contract it.

                          The resistance came about via two separate &quot;evolutionary upgrade&quot;(s).

                          1. awesome_dude · · focus · HN ↗
                            I cannot find any such claim in the literature.

                            It appears to me that, like BSE (aka Mad Cow disease) it really depends on exposure.

                            1. defrost · · focus · HN ↗
                              It was specifically endemic to the Fore, not so much to the Yate and Usurufa, and not particularly at all to other highland people in the general region.

                              There&#x27;s a twofer that skittled the Fore, a ~1900 mutation that created a new form of infectious prion proteins, and a local variation that saw less uptake in the Fore of a resistant prion protein (alongside other resistant prion protein).

                              So, over the highlands region, there was general resistance thanks to several evolved variations, in one specific locale (the Fore) there was insufficient resistance to the mutation that hit a peak of 200 deaths &#x2F; annum for about three years(?) in the late 50s.

                              I can&#x27;t speak to &quot;the literature&quot;, I just had a lot of conversations with the people on the ground (Mike Alpers, etc), on again &#x2F; off again, since the mid 1960s.

                    2. josephg · · focus · HN ↗
                      &gt; millions of years of evolution are still not enough to build a perfect defence.

                      Who said anything about a perfect defence? And since when was that the bar?

                      1. awesome_dude · · focus · HN ↗
                        The context is very clear - but, sure you can play word games, why not.

                        Just, you&#x27;re doing it on your own.

                        1. josephg · · focus · HN ↗
                          What seems obvious to you doesn&#x27;t seem obvious to me. I&#x27;m not a malicious or incompetent enemy. But you will need to explain your perspective for me to understand it.
                    3. robocat · · focus · HN ↗
                      [delayed]
                      1. awesome_dude · · focus · HN ↗
                        The paper relies on the fact that people who were dying did not have the disease, but those that didn&#x27;t ... didn&#x27;t

                        That&#x27;s not really enough to say &quot;We have found the gene&quot; - it&#x27;s just really good data to warrant further investigation

                        Also, the incubation period of the disease is up to 50 odd years, have there been follow up studies?

                  2. lazide · · focus · HN ↗
                    The best way to make them work for it? Put it on paper.
                    1. josephg · · focus · HN ↗
                      Put what on paper? I don’t understand your comment.
                      1. lazide · · focus · HN ↗
                        Don’t store important and sensitive data in databases or computers at all. Put it on paper.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.