‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. josephg · · focus · HN ↗
        &gt; It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

        Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

        We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.

        1. taurath · · focus · HN ↗
          &gt; Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”.

          I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too.

          1. ChrisMarshallNY · · focus · HN ↗
            I believe the technical term is “Move fast, and break things.” MVP is a huge disaster. I can see it working for applications that don’t process PID, but only an idiot ships data handling software before it’s been dragged through a lot of testing. I tested my app for two years, before finalizing, and an LLM still found a couple of holes (minor ones, but ones I missed).

            After the DOGE debacle, I suspect that all the previously really secure stuff, is now out there, too. In fact, I wouldn’t be surprised if some of these leaks, came from that.

            FBI employee data is very bad.

            1. dasil003 · · focus · HN ↗
              The issue is that in consumer and enterprise software, move fast-and-break-things outcompetes secure-by-default every time. Critical infrastructure needs to have a different set of priorities, but it’s very hard because the expertise is so thin on the ground. Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things for $150k a year when they can easily make multiples of that in big software companies that don’t own that level of risk.
              1. bch · · focus · HN ↗
                &gt; but it’s very hard because the expertise is so thin on the ground.

                This might be part of it...

                &gt; Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things

                But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit.

              2. generic92034 · · focus · HN ↗
                The incentives have to change. Any breach regarding PID should have fines as a percentage of revenue of the company. Any breach intentionally covered up and found out later by a third party should mean jail time for the C level. Yes, I know it is hard to make such laws &quot;foolproof&quot;. And yes, in the current political and economical climate it will not happen anyway.
                1. mitxela · · focus · HN ↗
                  EU has these laws
              3. lesostep · · focus · HN ↗
                The real problem is that even for companies that wish to pay more and wait more for secure-by-default can&#x27;t easily tell the difference.

                The only solution I can come up with is some form of certification or paid code review from a third party. I know that at least for Windows prior to 7 Microsoft actually allowed some parties to come in and check the code&#x2F;checksum on an air-gaped computer. We somehow moved to &quot;trust more&quot; in the last decade, and now we can trust nobody

                1. AlotOfReading · · focus · HN ↗
                  I&#x27;ve yet to see any form of certification or paid code review I&#x27;d be willing to bet critical infrastructure on. And working in safety critical software, that&#x27;s not for lack of trying. Good review is usually harder than building a working system and the asymmetry of offense and defense applies to anything you miss.
            2. parineum · · focus · HN ↗
              If DOGE is going to have an effect on network security, it&#x27;s not going to be for many more years.
              1. ChrisMarshallNY · · focus · HN ↗
                Not really. It’s likely that the dumped (and compromised) data might contain things like keys and URLs that could be used to pry open other sites. Blackhats have become really good at following breadcrumb trails, and using “innocuous” clues to ascertain much more dangerous access.

                LLMs have been a huge force multiplier. Here.

                If that data got out (which probably happened within hours of the data being dumped to insecure storage), then it’s probably already been analyzed and used to leverage access.

                1. parineum · · focus · HN ↗
                  That&#x27;s an awfully exciting narrative you&#x27;ve spun.
                  1. ChrisMarshallNY · · focus · HN ↗
                    Not really. It&#x27;s par for the course. I didn&#x27;t say anything that isn&#x27;t common knowledge.

                    Why are you so interested in defending DOGE?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.