‹ BackHN Continuity

Thread

'We hacked the FBI:' Hackers say they have data on all FBI employees

817 points · 614 comments · spenvo

  1. jacobgold · · focus · HN ↗
    At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

    China hacked 22.1 million records of US government employees:

    <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...

    1. coldpie · · focus · HN ↗
      It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else&#x27;s Internet-connected computers.

      For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

      The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

      1. josephg · · focus · HN ↗
        &gt; It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

        Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

        We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.

        1. msla · · focus · HN ↗
          The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn&#x27;t have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans.
          1. awesome_dude · · focus · HN ↗
            There&#x27;s absolutely no way to account for humans, who can be tricked, or pressured, or just make human sized mistakes.
            1. kulahan · · focus · HN ↗
              Then there&#x27;s no such thing as security.

              By the way, there are countless ways to account for humans. There are entire branches of engineering devoted to this. If you don&#x27;t want someone to leave the bank with a pen customers use for signing checks, you just chain it to the desk. If you don&#x27;t want the installer to forget to put the pen-chain in, make a photo of the chain part of the checklist required to get paid. If you want to... etc.

              The idea is that you determine an acceptable level of risk, then secure to that level. Maybe the acceptable level of risk chosen by companies is wrong. Maybe we need to increase that risk exposure via heavier fines and regulations. Maybe the cost of reducing that risk is too high already. Maybe we need to fund that. Maybe it&#x27;s too confusing and we need to research better standard practices. I dunno. But this is not some unsolvable problem.

              1. awesome_dude · · focus · HN ↗
                &gt; Then there&#x27;s no such thing as security.

                There really isn&#x27;t

                Ask anyone seriously involved in security - whether computer science related, or in general.

                A thought experiment: Think about the most important secrets a country can have - now think how they are still discovered by competing countries, enemies, etc.

                As long as there are humans in the loop there is a known weakness.

                1. kulahan · · focus · HN ↗
                  This simply isn’t the case. There are plenty of secrets that every military keeps just fine. See how long we’ve gone without anyone ripping off the F-22? That’s not even a new airframe anymore.

                  This is EXACTLY what I was talking about. The tech that makes the F-22 an unmitigated terror of the skies is of utmost importance, so it’s still kept secret. The barriers around that information are obnoxious, but effective. What blood type a subsection of your military has is of much less importance. That’s why that data was stolen (See: OPM hack) and our best weapons remain secret.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.