‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. josephg · · focus · HN ↗
        &gt; It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

        Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

        We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.

        1. wombatpm · · focus · HN ↗
          NASA was supposedly a CMM level 5 organization and they still managed to crash a mars probe because of bad unit conversions.
          1. voidUpdate · · focus · HN ↗
            A piece of software Lockheed made gave its outputs in US Customary units (not following their specification), and NASA expected it in SI units (as their specification expected)
            1. alt227 · · focus · HN ↗
              That should have been checked multiple times by NASA before they launched it.
              1. hnedeotes · · focus · HN ↗
                It seems like it should have been checked by Lockheed not NASA since supposedly NASA provided a specification, that specified the units, and paid for the software no?
                1. voidUpdate · · focus · HN ↗
                  I just had a quick scan of the incident report (<a href="https:&#x2F;&#x2F;llis.nasa.gov&#x2F;llis_lib&#x2F;pdf&#x2F;1009464main1_0641-mr.pdf" rel="nofollow">https:&#x2F;&#x2F;llis.nasa.gov&#x2F;llis_lib&#x2F;pdf&#x2F;1009464main1_0641-mr.pdf) and:

                  &gt; &quot;The output from the SM_FORCES application code as required by a MSOP Project Software Interface Specification (SIS) was to be in metric units of Newtonseconds (N-s)&quot;

                  (MSOP = Mars Surveyor Operations Program) One of the recommendations was

                  &gt; &quot;Conduct software audit for specification compliance on all data transferred between JPL and Lockheed Martin Astronautics&quot;

                  So yes, NASA should have checked the provided software more thoroughly, but also Lockheed should have actually followed the spec they were given. I doubt the SIS is available online to check any harder

                2. dh2022 · · focus · HN ↗
                  Should have been checked by both. Lockheed should have checked because of contractual obligations; NASA should have checked because of minimal engineering practices (bugs happen in all your dependencies).
                  1. hnedeotes · · focus · HN ↗
                    They happen and some are put there on purpose too. In this case it&#x27;s not a &quot;bug&quot; in your dependencies, and yes NASA since it&#x27;s using public funding should have been more careful, but ultimately it&#x27;s Lockheed that was paid to do something no?
                3. lightedman · · focus · HN ↗
                  I work in aerospace.

                  Both parties fucked up.

                  Lockheed&#x27;s job is to follow the customer&#x27;s specifications.

                  NASA&#x27;s job is to check to make sure what they paid for is what they received.

                  I do this every single day as a quality inspector here. I don&#x27;t know why a bunch of highly-degreed engineers can&#x27;t do a simple job that a person with oonly a GED does without fail.

                  1. hnedeotes · · focus · HN ↗
                    Actually no, it&#x27;s Lockheed&#x27;s that should have had a test-suite and conformance-suite for it, but probably only has a C-Suite. If the program is non-trivial proving its correctness can be very expensive to prove, both money and time wise, and something that is done contrary to the spec is obviously on the one executing the spec and being paid for it, which probably wasn&#x27;t cheap and probably these expenses add to the &quot;NASA only burns money...&quot; narrative.
                    1. lightedman · · focus · HN ↗
                      &quot;Actually no, it&#x27;s Lockheed&#x27;s that should have had a test-suite and conformance-suite for it&quot;

                      Tell me you don&#x27;t run AS9100D quality inspections without saying so directly.

                      1. hnedeotes · · focus · HN ↗
                        Well, it seems like simple test &amp; conformance suites would have been enough to catch this, so you wouldn&#x27;t need to run AS9100D quality inspections.

                        Besides it looks like the first AS9100 Standard was released after the incident even happened - perhaps even as a result of this.

                        1. lightedman · · focus · HN ↗
                          AS9100 is based off of ISO9001. It doesn&#x27;t fucking matter, the responsibility is on both parties.

                          Again, tell me you don&#x27;t actually handle quality without directly saying so.

                          1. hnedeotes · · focus · HN ↗
                            yeah Mr. Quality supervisor
                4. alt227 · · focus · HN ↗
                  No, if NASA chose not to triple check everything before sending something into space then they are as much to blame as the supplier. Blindly assuming something works like it should without testing it makes an ass out of u and me.
                  1. hnedeotes · · focus · HN ↗
                    Very fitting for the AI age as well. &quot;Yeah I just put the specs of the project you&#x27;re paying me to do (in NASA&#x27;s case, probably 100% public funds) but Claude the gimp missed the units because all previous training data use Stones and Yards as units, you should have verified it yourself! I just prompt!&quot;
            2. abc123abc123 · · focus · HN ↗
              That is why the good lord invented acceptance tests.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.