‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. josephg · · focus · HN ↗
        &gt; It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

        Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

        We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.

        1. msla · · focus · HN ↗
          The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn&#x27;t have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans.
          1. timschmidt · · focus · HN ↗
            It&#x27;s always possible to break a perfect system by moving an additional layer of abstraction outward, and attacking one of the assumptions upon which it&#x27;s built. Some of our era&#x27;s highest security systems - game consoles - have been broken by undervolting them until the logic failed.
            1. josephg · · focus · HN ↗
              &gt; It&#x27;s always possible

              It&#x27;s often possible. But not all systems are vulnerable to undervoltage attacks. For example, I don&#x27;t think the iphone secure enclave is vulnerable to this.

              And good security uses &quot;defence in depth&quot;. Multiple layers which each individually need to be compromised to break the whole thing. To hack chrome, you need a vulnerability in the renderer or VM. Then you also need a sandbox escape, and a way to use that to attack the browser&#x27;s parent process. This is much harder to do.

              1. timschmidt · · focus · HN ↗
                &gt; not all systems are vulnerable to undervoltage attacks. For example, I don&#x27;t think the iphone secure enclave is vulnerable to this.

                Then there&#x27;s decapping &#x2F; depotting, a world of different types of microscopy - some destructive some not, directed EM attacks, etc.

                &gt; And good security uses &quot;defence in depth&quot;

                And automation has enabled &quot;offense in depth&quot;

                &gt; To hack chrome, you need a vulnerability in the renderer or VM. Then you also need a sandbox escape, and a way to use that to attack the browser&#x27;s parent process.

                Or you just phish the user into installing your exploit. There&#x27;s always another layer. Always a potential exploit. Because ultimately the same properties of the universe which permit computation within a closed system allow for predictably observing and influencing it.

                1. josephg · · focus · HN ↗
                  &gt; There&#x27;s always another layer. Always a potential exploit.

                  So what? Most attackers aren&#x27;t nation state adversaries. They&#x27;re some kid in Wyoming messing around with deepseek. We live in a world where most exploits happen because someone was running an unpatched, 8 year old copy of wordpress. Because they put their insecure mongodb instance on the open internet. Because they used admin &#x2F; &quot;12345&quot; as the username and password. We don&#x27;t need to make hacks physically impossible for a nation state adversary. Just really, really difficult and expensive to pull off.

                  Honestly. If people talked about physical security like they talk about computer security, you&#x27;d have people telling you that, because walls can be physically smashed through, they don&#x27;t bother locking the front door to their house.

                  1. timschmidt · · focus · HN ↗
                    &gt; Honestly. If people talked about physical security like they talk about computer security, you&#x27;d have people telling you that, because walls can be physically smashed through, they don&#x27;t bother locking the front door to their house.

                    The saying is that locks only keep honest people honest. Plenty of evidence of that: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;@lockpickinglawyer" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;@lockpickinglawyer

                    1. californical · · focus · HN ↗
                      Sure, but also if there are a dozen bikes locked to the rack all costing $1000 and a $500 bike just sitting there completely unlocked, the average thief is probably gonna take the cheaper unlocked one and ride away.

                      It’s not hard to get into a garage but it’s really easy to steal a lawnmower if you leave the door open all night. I wouldn’t call that thief honest but even the minor deterrent of closing the garage was enough to make you not the target.

                    2. josephg · · focus · HN ↗
                      &gt; The saying is that locks only keep honest people honest. Plenty of evidence of that: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;@lockpickinglawyer" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;@lockpickinglawyer

                      That youtube channel is great. But it isn&#x27;t evidence of anything. Except maybe for how terrible master locks are.

                  2. fragmede · · focus · HN ↗
                    How many locked doors have easily breakable glass windows right next to them, nevermind breakable walls? What we need is a red-team waiver, and an AI model, and a budget, and say something like: your site has to be unhacked by the HackerAI3000 bot after 2 days on a 5090 Nvidia GPU.
              2. somenameforme · · focus · HN ↗
                I&#x27;d stick with always. Defense vs offense in anything reasonably complex suffers from one issue that simply cannot be overcome. To defend, you need to defend against every single possible imaginable attack, from now until forever. To attack, you need to find a single attack that works. For very simple things, this is a winnable game, but as the complexity of systems increases - I think it&#x27;s fairly safe to say that perfect defense is, if not literally, then at least practically impossible.
              3. somenameforme · · focus · HN ↗
                I&#x27;d stick with always. Defense vs offense in anything reasonably complex suffers from one issue that simply cannot be overcome. To defend, you need to defend against every single possible imaginable attack, from now until forever. To attack, you need to find a single attack that works. And on a practical level all systems need to be accessible by somebody, yet that somebody is himself also now a part of your security structure and is never going to be 100% reliable, both in terms of corruption and incompetence.
                1. josephg · · focus · HN ↗
                  &gt; your security structure and is never going to be 100% reliable

                  So what? Security systems don&#x27;t need to be 100% provably secure to add value. It&#x27;s a mistake to let perfect be the enemy of good.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.