'We hacked the FBI:' Hackers say they have data on all FBI employees
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
'We hacked the FBI:' Hackers say they have data on all FBI employees
Unofficial Hacker News client; not affiliated with Y Combinator.
jacobgold · · focus · HN ↗
China hacked 22.1 million records of US government employees:
<a href="https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
coldpie · · focus · HN ↗
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
josephg · · focus · HN ↗
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
msla · · focus · HN ↗
awesome_dude · · focus · HN ↗
kulahan · · focus · HN ↗
By the way, there are countless ways to account for humans. There are entire branches of engineering devoted to this. If you don't want someone to leave the bank with a pen customers use for signing checks, you just chain it to the desk. If you don't want the installer to forget to put the pen-chain in, make a photo of the chain part of the checklist required to get paid. If you want to... etc.
The idea is that you determine an acceptable level of risk, then secure to that level. Maybe the acceptable level of risk chosen by companies is wrong. Maybe we need to increase that risk exposure via heavier fines and regulations. Maybe the cost of reducing that risk is too high already. Maybe we need to fund that. Maybe it's too confusing and we need to research better standard practices. I dunno. But this is not some unsolvable problem.
awesome_dude · · focus · HN ↗
There really isn't
Ask anyone seriously involved in security - whether computer science related, or in general.
A thought experiment: Think about the most important secrets a country can have - now think how they are still discovered by competing countries, enemies, etc.
As long as there are humans in the loop there is a known weakness.
kulahan · · focus · HN ↗
This is EXACTLY what I was talking about. The tech that makes the F-22 an unmitigated terror of the skies is of utmost importance, so it’s still kept secret. The barriers around that information are obnoxious, but effective. What blood type a subsection of your military has is of much less importance. That’s why that data was stolen (See: OPM hack) and our best weapons remain secret.