‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. shepherdjerred · · focus · HN ↗
        It used to be that nothing was secure but that was OK because at least adversaries would have to expend effort. If you are one of a million companies why would anyone hack you. Maybe if you are a target you need a lot of investment, but most orgs only prevent the most egregious of vulnerabilities.

        The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.

        It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.

        Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.

        1. BoxwoodSeed · · focus · HN ↗
          I am reminded of the scene of a guy walking through various layers of security to access a computer that isn&#x27;t connected to any network and still wonder what the hell this guy&#x27;s job was in Mission Impossible (1996). The data got stolen either way, because of course it did, but what highly sensitive work can you even do on a computer not connected to any network?

          If there&#x27;s too much security in the way, it seems to me that work becomes impossible.

          1. coldpie · · focus · HN ↗
            We had water and traffic control and electricity for decades and centuries before the Internet. It is less convenient and more expensive, but it also means hostile countries can&#x27;t literally poison your drinking water from across the planet. It&#x27;s not a difficult trade to consider.
            1. burpingtree · · focus · HN ↗
              Is it really more expensive to not connect a water treatment plant to the internet? I can imagine the vendor selling that idea but I struggle to come up with how that could make a water treatment plant cheaper to operate.
              1. elictronic · · focus · HN ↗
                Yes. Without a remote system you must have a real person check levels, pumps, pressures, and many other devices thus be present. This person must be trained and you will likely need a backup as well.

                If not a person you need more redundancies built in. Bigger tanks, multiple backup systems. When items start failing you need them to be shutoff in a timely manner. Water pumps at these facilities are in the 50-100k range. When it starts failing you want to know.

                Think of it like driving a car and it starts making funny noises. The longer you wait to fix it the more it costs.

                1. Tistron · · focus · HN ↗
                  Surely it isn&#x27;t impossible to devise one-way data flows that provably work for remote sensing? And yeah then you have to send somebody to fix stuff if something is off..

                  Like something that would work but not not scale would be one computer writing data to an updating qr code and another reading it. Surely something like that can be made (and probably already exists?) on the cable level?

                  1. TheCapn · · focus · HN ↗
                    Just go dumber

                    Set up a monitor with the data values you need to monitor

                    Point a camera at that monitor.

                    Camera feed is remote accessible. Control software is not.

                    Want alarming? There&#x27;s systems designed specifically to send texts or make phone calls when signaled electronically.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.