‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. __MatrixMan__ · · focus · HN ↗
      Maybe we should just give up on custodial trust re: people we don&#x27;t know.

      If somebody wants data about me, they can write the query, I&#x27;ll approve it, and it can hit a server designated by me and run by somebody I know personally.

      It&#x27;s not just a privacy&#x2F;security concern. People who get too close to large piles of sensitive data tend to start behaving poorly in other ways too--they might be compelled to misrepresent it. Apparently the forces of corruption are too great. Maybe the way to avoid exposing each other to such hazards is to just maintain smaller piles of data, closer to the people that the data is about.

      1. nradov · · focus · HN ↗
        Just because you personally know the server administrator doesn&#x27;t mean it&#x27;s less likely to get hacked.
        1. __MatrixMan__ · · focus · HN ↗
          The most common kind of hack is phishing, social engineering, human facing stuff.

          If the users know their admin, then each server has no more than few dozen other users&#x27; worth of data on it. The juice just isn&#x27;t worth the squeeze to target them one at a time. Ain&#x27;t nobody has the resources for that kind of attack.

          Also, it&#x27;s a lot harder to phish somebody who is on a first name basis with 100% of their users. It&#x27;s not enough to merely have a plausible backstory, you have to impersonate one of their friends. That&#x27;s incredibly difficult.

          The only thing left is to hack through whatever protocol indexes these servers and multiplexes queries across them, but now you&#x27;re presenting a much smaller and easier to defend attack surface, one which can be defended in aggregate (e.g. supply chain scrutiny) rather than singly.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.