'We hacked the FBI:' Hackers say they have data on all FBI employees
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
'We hacked the FBI:' Hackers say they have data on all FBI employees
Unofficial Hacker News client; not affiliated with Y Combinator.
jacobgold · · focus · HN ↗
China hacked 22.1 million records of US government employees:
<a href="https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
coldpie · · focus · HN ↗
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
josephg · · focus · HN ↗
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
wombatpm · · focus · HN ↗
voidUpdate · · focus · HN ↗
alt227 · · focus · HN ↗
hnedeotes · · focus · HN ↗
voidUpdate · · focus · HN ↗
> "The output from the SM_FORCES application code as required by a MSOP Project Software Interface Specification (SIS) was to be in metric units of Newtonseconds (N-s)"
(MSOP = Mars Surveyor Operations Program) One of the recommendations was
> "Conduct software audit for specification compliance on all data transferred between JPL and Lockheed Martin Astronautics"
So yes, NASA should have checked the provided software more thoroughly, but also Lockheed should have actually followed the spec they were given. I doubt the SIS is available online to check any harder
dh2022 · · focus · HN ↗
hnedeotes · · focus · HN ↗
lightedman · · focus · HN ↗
Both parties fucked up.
Lockheed's job is to follow the customer's specifications.
NASA's job is to check to make sure what they paid for is what they received.
I do this every single day as a quality inspector here. I don't know why a bunch of highly-degreed engineers can't do a simple job that a person with oonly a GED does without fail.
hnedeotes · · focus · HN ↗
lightedman · · focus · HN ↗
Tell me you don't run AS9100D quality inspections without saying so directly.
hnedeotes · · focus · HN ↗
Besides it looks like the first AS9100 Standard was released after the incident even happened - perhaps even as a result of this.
lightedman · · focus · HN ↗
Again, tell me you don't actually handle quality without directly saying so.
hnedeotes · · focus · HN ↗
alt227 · · focus · HN ↗
hnedeotes · · focus · HN ↗