Rendered at 10:06:53 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jacobgold 13 hours ago [-]
At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.
China hacked 22.1 million records of US government employees:
It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else's Internet-connected computers.
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
josephg 12 hours ago [-]
> It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
alt227 2 hours ago [-]
> Secure software is - somehow - niche. And as such, it’s much more expensive.
Its not expensive because its niche, its expensive because its hard. Its a lot easier to learn a bit of html and javascript and knock up some web projects then it is to become proficient at all the things necessary to be good at security. Generally it also takes consulting with maths experts who have spent their life studying cryptography and as such command a decent wage.
earth-tattoo 26 minutes ago [-]
[dead]
fpoling 4 hours ago [-]
SeL4 or proof assistant are not panacea. They do not help if assumptions about the task are wrong. And correctly formulating the task in real world is very messy.
So physical security is just as important. I really like how ARINC serial bus on planes work. One can have a reader that is physically incapable of sending anything to the writer. This allows to connect entertainment systems to flight data sensors safely.
In Airbus this system is replaced with Ethernet switches that in software ensures separation of traffic. The software was proven mathematically. But I am skeptical that it is absolutely bulletproof as a client under malicious control can influence Ethernet signaling and may exploit hardware bugs.
josephg 3 hours ago [-]
> SeL4 or proof assistant are not panacea. They do not help if assumptions about the task are wrong. And correctly formulating the task in real world is very messy.
Nobody said sel4 was a panacea.
My claim is that doing this kind of computer security is possible. It's just expensive and inconvenient. We know how to make computers a lot more secure than they are today. The limiting factor isn't humanity's knowledge. The limit is that barely anyone wants to pay the bill.
mentalgear 16 minutes ago [-]
The main issue is that market evolution will always surfaces the most cost-efficient entities within the ecosystem pressures.
That means designing the ecosystem pressures is crucial: things more meaningful than just pure capitalist private-profit logic must by enforced by thoughtful regulation or otherwise the ecosystem converges for private-profit of a small sliver of individuals (billionaires) to the detriment of all other ecosystem members (99% of the world population).
This holds for anything broader than pure private gain, may it be security, social fairness or ecological topics. Sole monetary-value optimization for private gain must be properly constrained or else it results in pure predatory capitalism that implodes society from within, may it be through leaky security, poisoned environments or social unrest.
alt227 2 hours ago [-]
> The limit is that barely anyone wants to pay the bill
Do you even have any experience with how most companies work? SMEs barely have the cashflow to cover their daily expenses, let alone suddenly pay thousands for regular professional security audits and overhauls of their code. This is why security is an afterthought.
thephyber 1 hours ago [-]
> This is why security is an afterthought.
Security is always a cost center and rarely a profit center. That's the only thing that needs to be said.
alt227 51 minutes ago [-]
Security is defence, it is never a profit center unless your business is providing security services!
taurath 11 hours ago [-]
> Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”.
I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too.
noduerme 2 hours ago [-]
It's not as if best practices aren't well documented, or as if CVEs don't come out every day, or as if the information is somehow unavailable to even the most junior devs to take basic security measures.
Not all hacks are caused by pure negligence, laziness or stupidity, but most of them are. Even a little effort goes a long way.
My grandfather spent a couple decades as a builder, ran a construction crew. Whatever the project was, he wanted to know everyone he hired personally was going to reinforce and report to him anything they had the slightest doubt about. "Always hammer in an extra nail" was basically his motto.
What we do ain't that different. The difference is that when an apartment building collapses, it's bigger news than when a govenrment database does.
gchamonlive 9 hours ago [-]
I like to think behind every Dev anxious to ship half baked software sits an omniscient middle manager with a vague idea of what the product was supposed to do, maybe
gspr 2 hours ago [-]
It's worse: it seems like almost every developer on this very site is aspiring to be that middle manager, with LLMs as their underlings.
We are headed for scary waters.
asdf88990 60 minutes ago [-]
Guess you don’t remember the days of ssl on login pages, ssl strip, exfiltering data via JavaScript prototype pollution, and a million other things like that.
Only just when we started to have a resemblance of security we got agile and startups breaking things (making rubbish software to capture a few bucks faster) and now vibe coding and llm assisted hacking.
The point of my, arguably rant, is that there is nothing new under the sun.
gspr 39 minutes ago [-]
I'm not sure my worries are assuaged by thr fact that it's been bad before, too.
Bluestein 2 hours ago [-]
This will all of course end when our AGI lords lovingly manage everything /s
ChrisMarshallNY 9 hours ago [-]
I believe the technical term is “Move fast, and break things.” MVP is a huge disaster. I can see it working for applications that don’t process PID, but only an idiot ships data handling software before it’s been dragged through a lot of testing. I tested my app for two years, before finalizing, and an LLM still found a couple of holes (minor ones, but ones I missed).
After the DOGE debacle, I suspect that all the previously really secure stuff, is now out there, too. In fact, I wouldn’t be surprised if some of these leaks, came from that.
FBI employee data is very bad.
dasil003 7 hours ago [-]
The issue is that in consumer and enterprise software, move fast-and-break-things outcompetes secure-by-default every time. Critical infrastructure needs to have a different set of priorities, but it’s very hard because the expertise is so thin on the ground. Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things for $150k a year when they can easily make multiples of that in big software companies that don’t own that level of risk.
lesostep 37 minutes ago [-]
The real problem is that even for companies that wish to pay more and wait more for secure-by-default can't easily tell the difference.
The only solution I can come up with is some form of certification or paid code review from a third party. I know that at least for Windows prior to 7 Microsoft actually allowed some parties to come in and check the code/checksum on an air-gaped computer. We somehow moved to "trust more" in the last decade, and now we can trust nobody
generic92034 3 hours ago [-]
The incentives have to change. Any breach regarding PID should have fines as a percentage of revenue of the company. Any breach intentionally covered up and found out later by a third party should mean jail time for the C level. Yes, I know it is hard to make such laws "foolproof". And yes, in the current political and economical climate it will not happen anyway.
bch 7 hours ago [-]
> but it’s very hard because the expertise is so thin on the ground.
This might be part of it...
> Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things
But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit.
parineum 5 hours ago [-]
If DOGE is going to have an effect on network security, it's not going to be for many more years.
ChrisMarshallNY 3 hours ago [-]
Not really. It’s likely that the dumped (and compromised) data might contain things like keys and URLs that could be used to pry open other sites. Blackhats have become really good at following breadcrumb trails, and using “innocuous” clues to ascertain much more dangerous access.
LLMs have been a huge force multiplier. Here.
If that data got out (which probably happened within hours of the data being dumped to insecure storage), then it’s probably already been analyzed and used to leverage access.
flohofwoe 3 hours ago [-]
> ...there is such a thing as computer security...
> Of course there is. (...continues to talk about software security)
A bit over-optimistic when looking at hardware vulneraribilties like Spectre/Meltdown.
Secure software isn't worth much when it runs on vulnerable hardware (at least Spectre/Meltdown could be worked around in software though, but at a cost.
josephg 3 hours ago [-]
There's "no such thing as computer security", because this one time computer security researchers found vulnerabilities?
You know that's their actual job right? That and fixing the problem. Which they did in both software and hardware.
farlight 3 hours ago [-]
One time? lscpu on my system lists two dozen CPU vulnerabilities known to the kernel. I stopped tracking them a long time ago when it felt like every week brought another information leak or bypass.
josephg 3 hours ago [-]
When I run that on my computer I see a big list of CPU vulnerabilities. All of them are either mitigated in software or fixed at the hardware level.
Looks to me like the security researchers have been doing their jobs.
hashstring 1 hours ago [-]
Yes, except that they haven’t been able to fix this completely in sw and the community knows this.
josephg 24 minutes ago [-]
Fix what?
wombatpm 8 hours ago [-]
NASA was supposedly a CMM level 5 organization and they still managed to crash a mars probe because of bad unit conversions.
voidUpdate 3 hours ago [-]
A piece of software Lockheed made gave its outputs in US Customary units (not following their specification), and NASA expected it in SI units (as their specification expected)
alt227 2 hours ago [-]
That should have been checked multiple times by NASA before they launched it.
shimman 8 hours ago [-]
Did any martians hack the probe?
stackghost 7 hours ago [-]
Jeff Goldblum with a thinkpad, maybe
catoc 5 hours ago [-]
Jev Goldblum? He’s all the hype today
Kostchei 4 hours ago [-]
Artificial Life, um, finds a way
2 hours ago [-]
msla 12 hours ago [-]
The bank has the best doors, the best locks, and the best cameras, and it is patrolled by a guard who props the doors open to so he doesn't have to keep fooling with the locks and points the cameras the other way to extend his smoke break. SeL4 would be another system used by humans.
timschmidt 12 hours ago [-]
It's always possible to break a perfect system by moving an additional layer of abstraction outward, and attacking one of the assumptions upon which it's built. Some of our era's highest security systems - game consoles - have been broken by undervolting them until the logic failed.
dirkc 4 hours ago [-]
> It's always possible to break a perfect system
A perfect system is either extremely limited in scope or flawed in it's assumptions.
hashstring 1 hours ago [-]
Yes, but that’s not bad. It boils down to a threat model.
josephg 9 hours ago [-]
> It's always possible
It's often possible. But not all systems are vulnerable to undervoltage attacks. For example, I don't think the iphone secure enclave is vulnerable to this.
And good security uses "defence in depth". Multiple layers which each individually need to be compromised to break the whole thing. To hack chrome, you need a vulnerability in the renderer or VM. Then you also need a sandbox escape, and a way to use that to attack the browser's parent process. This is much harder to do.
somenameforme 9 hours ago [-]
I'd stick with always. Defense vs offense in anything reasonably complex suffers from one issue that simply cannot be overcome. To defend, you need to defend against every single possible imaginable attack, from now until forever. To attack, you need to find a single attack that works. And on a practical level all systems need to be accessible by somebody, yet that somebody is himself also now a part of your security structure and is never going to be 100% reliable, both in terms of corruption and incompetence.
josephg 3 hours ago [-]
> your security structure and is never going to be 100% reliable
So what? Security systems don't need to be 100% provably secure to add value. It's a mistake to let perfect be the enemy of good.
timschmidt 9 hours ago [-]
> not all systems are vulnerable to undervoltage attacks. For example, I don't think the iphone secure enclave is vulnerable to this.
Then there's decapping / depotting, a world of different types of microscopy - some destructive some not, directed EM attacks, etc.
> And good security uses "defence in depth"
And automation has enabled "offense in depth"
> To hack chrome, you need a vulnerability in the renderer or VM. Then you also need a sandbox escape, and a way to use that to attack the browser's parent process.
Or you just phish the user into installing your exploit. There's always another layer. Always a potential exploit. Because ultimately the same properties of the universe which permit computation within a closed system allow for predictably observing and influencing it. The expense and hassle of doing so are widely variable, of course.
josephg 8 hours ago [-]
> There's always another layer. Always a potential exploit.
So what? Most attackers aren't nation state adversaries. They're some kid in Wyoming messing around with deepseek. We live in a world where most exploits happen because someone was running an unpatched, 8 year old copy of wordpress. Because they put their insecure mongodb instance on the open internet. Because they used admin / "12345" as the username and password. We don't need to make hacks physically impossible for a nation state adversary. Just really, really difficult and expensive to pull off.
Honestly. If people talked about physical security like they talk about computer security, you'd have people telling you that, because walls can be physically smashed through, they don't bother locking the front door to their house.
timschmidt 7 hours ago [-]
> Honestly. If people talked about physical security like they talk about computer security, you'd have people telling you that, because walls can be physically smashed through, they don't bother locking the front door to their house.
That youtube channel is great. But it isn't evidence of anything. Except maybe for how terrible master locks are.
californical 5 hours ago [-]
Sure, but also if there are a dozen bikes locked to the rack all costing $1000 and a $500 bike just sitting there completely unlocked, the average thief is probably gonna take the cheaper unlocked one and ride away.
It’s not hard to get into a garage but it’s really easy to steal a lawnmower if you leave the door open all night. I wouldn’t call that thief honest but even the minor deterrent of closing the garage was enough to make you not the target.
fragmede 7 hours ago [-]
How many locked doors have easily breakable glass windows right next to them, nevermind breakable walls? What we need is a red-team waiver, and an AI model, and a budget, and say something like: your site has to be unhacked by the HackerAI3000 bot after 2 days on a 5090 Nvidia GPU.
9 hours ago [-]
nailer 11 hours ago [-]
I once worked on AUD 450M banking project, the root password was kept in a kickstart file and unchanged, root SSH was allowed. The bank didn't care until I told the external security auditor who included it as part of their report.
warkdarrior 11 hours ago [-]
Snitch
bariumbitmap 8 hours ago [-]
I sure hope you're joking, warkdarrior!
DeluluDon 9 hours ago [-]
[flagged]
awesome_dude 11 hours ago [-]
There's absolutely no way to account for humans, who can be tricked, or pressured, or just make human sized mistakes.
josephg 10 hours ago [-]
Again, of course there is.
Decades ago, I worked in a bank in an old building. The door had a card reader for access. You boop your card and the door opened. People would hold the door open for each other all the time out of politeness, even when they didn't know each other. Security told us not to do that, but it's hard to convince people to stop being polite.
I had a laptop stolen from my desk in a place like that once. (Not a bank - but similar door-card reader system). This guy came in in the middle of the day, wearing overalls. He confidently walked through the door after someone, like he belonged there. He walked up to my desk, swiped my laptop and just strolled out.
At the bank, they've replaced the door with mechanical gates and a security guard. The gates - physically - only let one person to walk through at a time. You can't hold a gate open any more. And the security guards stop anyone who tries.
Is it 100% foolproof? No. But it's way more secure. It would have stopped that laptop thief.
There's this pernicious, defeatist attitude that if you can't make a system 100% secure, so you shouldn't try. That's misguided. Most systems can be made orders of magnitude more secure than they are today. It just takes a bit of care and work.
wombatpm 8 hours ago [-]
As soon as you make something foolproof, the universe evolves a better fool
josephg 7 hours ago [-]
Fine. Make the universe work for it. The whole system becomes more resilient as a result.
Look at our immune system. Incredibly complex and clever, and able to keep us alive in the face of all sorts of pathogens. It exists because of this cat and mouse game, played over millions of years.
There's people in the highlands of PNG who regularly eat each other. Of course, many are thought to have died due to prion diseases. But now these tribespeople seem to have become largely immune to prion disease. Incredible.
awesome_dude 7 hours ago [-]
We still get diseases though, proving the point that millions of years of evolution are still not enough to build a perfect defence.
Your comment on PNG, seems to ignore Kuru
defrost 7 hours ago [-]
It explicitly mentions Kuru as "prion disease", it ignores that the mortuary practice of eating various parts of respected dead has long passed in time .. although the lingering effect on the woman and children that ate portions of the brain in the 1970s, early 1980s, is still residual in a very few.
From an evolutionary PoV a perfect defence is overkill - with two separate defences against prion diseases in that region it's only the rare variation that causes any issue - and that rarely occurs before a new generation is birthed - ie. 'perfect' from the PoV of the selfish genes.
awesome_dude 7 hours ago [-]
The claim is that people in PNG are "largely immune" to these diseases, where kuru shows that they are not, and the "cure" was a stop in the practice, not some evolutionary upgrade
defrost 5 hours ago [-]
They are largely immune to Kuru - the number of people that could contract it (ie. the number who ate brain) was significantly larger than the number of people who actually did contract it.
The resistance came about via two separate "evolutionary upgrade"(s).
awesome_dude 1 hours ago [-]
I cannot find any such claim in the literature.
It appears to me that, like BSE (aka Mad Cow disease) it really depends on exposure.
defrost 53 minutes ago [-]
It was specifically endemic to the Fore, not so much to the Yate and Usurufa, and not particularly at all to other highland people in the general region.
There's a twofer that skittled the Fore, a ~1900 mutation that created a new form of infectious prion proteins, and a local variation that saw less uptake in the Fore of a resistant prion protein (alongside other resistant prion protein).
So, over the highlands region, there was general resistance thanks to several evolved variations, in one specific locale (the Fore) there was insufficient resistance to the mutation that hit a peak of 200 deaths / annum for about three years(?) in the late 50s.
I can't speak to "the literature", I just had a lot of conversations with the people on the ground (Mike Alpers, etc), on again / off again, since the mid 1960s.
6 hours ago [-]
robocat 4 hours ago [-]
Acshually a protective mutation was quickly being selected for (more precisely, the lack of it was strongly selected against).
The paper relies on the fact that people who were dying did not have the gene, but those that didn't ... did
That's not really enough to say "We have found the gene" - it's just really good data to warrant further investigation
Also, the incubation period of the disease is up to 50 odd years, have there been follow up studies?
josephg 5 hours ago [-]
> millions of years of evolution are still not enough to build a perfect defence.
Who said anything about a perfect defence? And since when was that the bar?
awesome_dude 1 hours ago [-]
The context is very clear - but, sure you can play word games, why not.
Just, you're doing it on your own.
awesome_dude 8 hours ago [-]
This is the key truth that we keep forgetting
josephg 3 hours ago [-]
I'm not really sure what point you're trying to make, or how this relates to computer security.
awesome_dude 1 hours ago [-]
Funny - now you're talking about context...
josephg 20 minutes ago [-]
You seem mad about something I've said? I'd appreciate if you come out and say it instead of making vague insults, awesome_dude.
kulahan 10 hours ago [-]
Then there's no such thing as security.
By the way, there are countless ways to account for humans. There are entire branches of engineering devoted to this. If you don't want someone to leave the bank with a pen customers use for signing checks, you just chain it to the desk. If you don't want the installer to forget to put the pen-chain in, make a photo of the chain part of the checklist required to get paid. If you want to... etc.
The idea is that you determine an acceptable level of risk, then secure to that level. Maybe the acceptable level of risk chosen by companies is wrong. Maybe we need to increase that risk exposure via heavier fines and regulations. Maybe the cost of reducing that risk is too high already. Maybe we need to fund that. Maybe it's too confusing and we need to research better standard practices. I dunno. But this is not some unsolvable problem.
18 minutes ago [-]
awesome_dude 1 hours ago [-]
> Then there's no such thing as security.
There really isn't
Ask anyone seriously involved in security - whether computer science related, or in general.
A thought experiment:
Think about the most important secrets a country can have - now think how they are still discovered by competing countries, enemies, etc.
As long as there are humans in the loop there is a known weakness.
sabretooth1405 8 hours ago [-]
In cryptography there are protocols that account for malicious actors
iugtmkbdfil834 11 hours ago [-]
<< And as such, it’s much more expensive. And nobody wants to pay.
Eh. If only it was that simple. I mean, yes, money is always a factor, but not nearly as big of a factor as 'my convenience outweighs pretty much everything ( until it causes sufficient amount of havoc.. and even then.. )'. You can see it in just about everything. It is not just the money. It is the convenience that drives most of the unsecure behavior.
jonathanstrange 2 hours ago [-]
How the software is written isn't that important because the endpoints aren't secure. Their hardware and firmware isn't even secure enough.
10 hours ago [-]
fovc 9 hours ago [-]
sel4's guarantees break if you have DMA, e.g., from your NIC. It doesn't help with timing attacks. It doesn't cover your network stack. AFAIK, no one has taken up the mantle from Project Everest, so you'll need to write a verified TLS library. Once you've built all that, you can start thinking about your database/application/whatever. Then of course you'll have to verify all your dev's machines and scripts to ensure nobody is misusing a credential that can get stolen.
"So what?" you say. "Making a heavier-than-air metal tube take off and land millions of times per year without a catastrophe is also hard, and we no longer expect most or even many of those tubes to blow up or fall down."
Mother nature is not spending $$$ using AI and HI adversarially trying to find the exact combination of atoms that will cause your device to fail.
josephg 8 hours ago [-]
> sel4's guarantees break if you have DMA, e.g., from your NIC.
Modern CPUs support IOMMU. If you set that up, your NIC can only DMA to virtual addresses, managed by the operating system.
> It doesn't help with timing attacks. It doesn't cover your network stack
It does help with all this stuff, because your network stack and whatever else can be split off into isolated processes which talk over capabilities. Compromises in those processes are of course terrible. But they don't automatically allow kernel level takeover of the whole machine like on windows / linux.
paganel 4 hours ago [-]
> SeL4’s security and reliability proofs still hold in the world of LLMs
Oftentimes the weakest link is the human operator who has direct access to those systems, not the computer system itself. Good old social engineering, in other words.
Even though one could use LLMs for social engineering, come to think of it, like re-enacting the movie "Her" involving a modern AI as Scarlett Johansson and an engineer working for the water utility as the romantic target.
josephg 17 minutes ago [-]
> Oftentimes the weakest link is the human operator who has direct access to those systems, not the computer system itself.
If that is the case, the computer security team have done their jobs.
I wish that were true more often.
fragmede 10 hours ago [-]
Yeah it's about costs. I care about a lot of things, but the causes I actually give money to is a much shorter list. If personal data was radioactive, and leaking it cost companies real money, then more money would get spent on security. (and insurance, and lawyers.)
josephg 10 hours ago [-]
Yeah I've long said we should treat data leaks like food safety. The only way we'll see software security improve is if there were serious fines and/or jail time for leaking user data due to negligence.
pylua 9 hours ago [-]
PCI compliance works pretty well.
I would like to see restricted access to only us workers for us citizens data though.
Transferring us customer data outside the country should be illegal
guerrilla 9 hours ago [-]
PCI compliance is a joke. That isn't even close to good enough. I'll break all your PCI compliant stuff trivially.
pylua 8 hours ago [-]
What’s your main issue ? The compliance audit being lax or the compliance not being assertive enough ?
Veserv 10 hours ago [-]
> The problem isn’t that we lack the capability to make secure computers.
Depends on the "we". "We" have the capability to make secure computers like how "we" have the capability to make EUV lithography machines. There exists a relatively small number of people and organizations in the world who can do so. Microsoft does not have that capability. Google does not have that capability. Linux does not have that capability. Amazon does not have that capability. Apple does not have that capability. Cisco does not have that capability. IBM does not have that capability. etc. All of those organizations have tried for literal decades, thumped their chests about how they have awesome security year after year, and yet have totally and utterly failed despite their best efforts.
Acquiring the capability to do so is difficult and challenging and requires years to invent if you start right this very second and know what you need to do, which these organizations emphatically do not. We need security at scale and fast. The only way forward is to scale up working solutions rather than letting the bozos who put us in this spot fail at scale with yet another promise that this time for sure they will solve the problem they have repeatedly failed at for decades.
guerrilla 9 hours ago [-]
It's nothing like EUV.
> Microsoft does not have that capability. Google does not have that capability. Linux does not have that capability. Amazon does not have that capability. Apple does not have that capability. Cisco does not have that capability. IBM does not have that capability. etc
This is all by choice. They could easily have that capsbility, very unlike EUV.
tonyarkles 9 hours ago [-]
And the reasoning behind that choice is looking at the tradeoffs and saying “shipping more features faster is more important”
fn-mote 9 hours ago [-]
Part of the argument (aiui) is that there is no way that culture could ever change to producing secure systems. There are too many weaknesses embedded in the organizational structure.
Veserv 9 hours ago [-]
Oh, Microsoft can just figure out how to make unhackable systems, they just choose not to. They spend all of those billions of dollars per year on security and spent all of those decades on failed attempts as a prank.
You really think that if they could have they would not have, even just for bragging rights? Or are we going with that it is some kind of task demanding enormous expenditure even though the organizations that have made secure systems are infinitesimally small in comparison?
Microsoft has spent orders of magnitude more money and time than the organizations that have succeeded and the result of their efforts is Windows. That says everything you need to know about their capabilitys.
Multiple literal trillion dollars organizations have spent literal decades failing at it. You are really underselling the capability gap.
josephg 2 hours ago [-]
It's not rocket science.
If windows was reimplemented as a capability based microkernel like sel4, it would be far more secure. Run drivers in their own isolated processes. Do interprocess communication between them via capabilities and shared memory. Remove all ambient authority from programs. All the programs a user launches stop automatically inheriting all of that user's permissions.
There's no secret knowledge required to do this. The SeL4 team has written extensive documentation of how they did it. They also opensourced their kernel implementation, with correctness proofs for the whole thing.
The reason windows hasn't done it is the cost. You'd have to rewrite half of the NT kernel and refactor everything else. All existing windows drivers would need to be rewritten. If you forced windows userland use a capability based system, you'd essentially be inventing a new way to write windows programs. You'd need to document that, and write a compatibility layer for legacy programs. And solve some UX problems. It would be terribly inconvenient for everyone. Oh, and some programs would run slower as a result.
They could do it if they wanted to. But microsoft just doesn't care about security as much as they care about performance and compatibility. Linux is the same.
The big irony is that security would be a lot cheaper for microsoft if they designed the NT kernel to be more like sel4. Microsoft has to spend millions on security every year because any tiny bug in the kernel (including in drivers) might result in the whole OS being compromised. In a microkernel, a buggy driver is nowhere near as dangerous.
mike_hearn 2 hours ago [-]
Your knowledge is out of date: Windows has supported capabilities from the start of NT and does run a lot drivers in isolated processes, along with most OS services. It has done for years. It has the most sophisticated IPC framework of any OS (DCOM) which is integrated with the operating system kernel's security frameworks, and used pervasively both internally and by apps. And Microsoft has created a new way to write Windows programs in which apps are expected to advertise the capabilities they need (see WinRT and MSIX). This is also over 15 years old.
macOS does the same but with more developer adoption. Apps don't have the ambient capabilities of the user and must advertise what they need via entitlements embedded in the binaries, or get permission just in time.
Which is all very good, and modern platforms are much more secure than they once were. Yet "capabilities" as a silver bullet are academic overpromises. This article I wrote is more about language/runtime level capabilities but OS capabilities are not much better.
SeL4 isn't secure because of One Weird Trick that others would adopt if only if they could be made to care enough, it's "secure" because it hardly does anything, which is why nobody uses it and why it has no impact on real world computer security.
The hard part of desktop security is not changing the operating system. The hard part is getting app developers to care. Most security features added to operating systems are ignored by developers, which is why Apple forces you to adopt some of them as the price of admission to the app store. If they didn't nobody would use them, as can be seen for apps distributed outside of the app store. The reason is security is a market for lemons. Nobody can see the result of security investments so it's irrational to invest. SeL4 has no solution.
Invictus0 9 hours ago [-]
Cybersecurity is a fragile system in Taleb's fragile-robust-antifragile framework. That is, as t->infinity, the probability of a hack approaches 1, because you only need to slip up once, and there is a small probability of the system's maintainers slipping up each day.
gspr 2 hours ago [-]
Spot on. And it's gonna get a lot worse now that "but my slop machine's code is run through a really large number of tests, like enormously many, I don't need to understand the code!" is apparently not an embarrassing way to do development anymore.
bjtitus 12 hours ago [-]
[dead]
user43928 39 minutes ago [-]
There is a difference between "someone being interested" and a state actor being interested.
I am more concerned about my cloud data being published in a leak.
But then on the other hand, if I use mainstream cloud services, a broad leak with no specific interest in my data would need to be exabytes in size and would take years to transfer even with a 100 Gbps connection.
shepherdjerred 13 hours ago [-]
It used to be that nothing was secure but that was OK because at least adversaries would have to expend effort. If you are one of a million companies why would anyone hack you. Maybe if you are a target you need a lot of investment, but most orgs only prevent the most egregious of vulnerabilities.
The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.
It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
autoexec 12 hours ago [-]
> Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
The problem is that most companies don't care if they get hacked so long as the hackers are just taking data and not interfering in their ability to bill customers and make money.
They face zero meaningful consequences if their data gets leaked. The money they save by not taking security and employee/customer privacy seriously will more than pay for the year of "identity protection" they'd have to pay for (assuming the hack gets found out) anyway.
They actually care about ransomware, but most of the time that's also something they can comfortably buy their way out of. We've seen a lot of companies pay off ransomware gangs rather than invest in the kinds of robust backups that would make recovery possible/less painful than rewarding the hackers.
What's needed for change is regulation with actual teeth that makes not protecting their data either meaningfully expensive or criminal resulting in executives spending time behind bars for their negligence. Without that, things are only going to get worse, especially as companies experiment with using AI and increase dependence on third parties and cloud providers who themselves become rich targets.
That probably still won't help the FBI though. Our government isn't exactly big on holding themselves accountable or even prioritizing competency right now.
SoftTalker 6 hours ago [-]
> Our government isn't exactly big on holding themselves accountable or even prioritizing competency right now.
Hasn't been since before Vietnam.
pixl97 12 hours ago [-]
>The calculus has certainly changed.
Adding AI into this really is just changing it to how much money your adversary is willing to spend to break in. The moment one crack in the armor shows up countless agents with unending patience can start embedding themselves everywhere in timeframes way faster than human actions. You could quickly find out all the special sauce for your company has been copied who knows where.
Working with banks when the Glasswing/Mythos first came out and they were given access to it has given me direct access to their infosec departments that are panicked. They've been sitting on piles of bugs for years that were low risk enough, and they have seen in their own tests how fast they can be probed.
Worse those infosec systems that have identified the risks in their software that aren't yet fixed are nuclear waste vats just waiting to get spilled to the wide world.
BoxwoodSeed 12 hours ago [-]
I am reminded of the scene of a guy walking through various layers of security to access a computer that isn't connected to any network and still wonder what the hell this guy's job was in Mission Impossible (1996). The data got stolen either way, because of course it did, but what highly sensitive work can you even do on a computer not connected to any network?
If there's too much security in the way, it seems to me that work becomes impossible.
coldpie 12 hours ago [-]
We had water and traffic control and electricity for decades and centuries before the Internet. It is less convenient and more expensive, but it also means hostile countries can't literally poison your drinking water from across the planet. It's not a difficult trade to consider.
burpingtree 11 hours ago [-]
Is it really more expensive to not connect a water treatment plant to the internet? I can imagine the vendor selling that idea but I struggle to come up with how that could make a water treatment plant cheaper to operate.
elictronic 9 hours ago [-]
Yes. Without a remote system you must have a real person check levels, pumps, pressures, and many other devices thus be present. This person must be trained and you will likely need a backup as well.
If not a person you need more redundancies built in. Bigger tanks, multiple backup systems. When items start failing you need them to be shutoff in a timely manner. Water pumps at these facilities are in the 50-100k range. When it starts failing you want to know.
Think of it like driving a car and it starts making funny noises. The longer you wait to fix it the more it costs.
mrktf 1 hours ago [-]
Why that drastic, checking system state (telemetry) can be done using 'data diode' style networking - one network just broadcasting sensor data, other network allows changing parameters and 3rd one allows allows software upgrades and so on.
You can be very defensive and design any remote sensing controller to act as two systems - one management cpu only does data routing (no other connection than administrative tasks), sensor cpu works only with sensors. As bonus you can have management cpu act as active firewall.
Main problem it is necessary to have in house expertise (hw, fw and process knowing) which in making company lean are optimized first and outsourcing custom solutions suddenly too expensive.
Tistron 2 hours ago [-]
Surely it isn't impossible to devise one-way data flows that provably work for remote sensing? And yeah then you have to send somebody to fix stuff if something is off..
Like something that would work but not not scale would be one computer writing data to an updating qr code and another reading it. Surely something like that can be made (and probably already exists?) on the cable level?
what 8 hours ago [-]
This smells wrong to me. You already have people working at the water treatment plant. You don’t need it connected to the internet?
mike_hearn 52 minutes ago [-]
Most water treatment works are unmanned most of the time. You don't need 24/7 staffing or even close.
But more to the point, a modern water network has a huge number of nodes. If you can't centrally aggregate and control in a control room the costs and complexity explode, probably also the error rate.
Even if you demand a full air gap, the solution here can't be to get rid of computers or networks. They are much, much too valuable. Luckily industrial control is full of very low hanging fruits.
aceofspades19 5 hours ago [-]
There is lots of infrastructure related to water that doesn't have someone physically there 24/7 as it would not be feasible to do so as 99.9% of the time there is nothing to do. So you need some sort of remote alarm system that can be monitored.
scun 5 hours ago [-]
at least disconnect the poison valve
nostrademons 10 hours ago [-]
The expense usually comes in operations. By connecting the water treatment plant to the Internet and making it remotely operable, you can have one guy who sits in an office and is responsible for overseeing the water quality at many different treatment plants. If everything is local, you need one guy on site at each different plant. People are expensive, software is cheap.
Of course, by making it remotely operable, that one guy could be replaced with a guy in Russia who's job is to poison everyone.
kulahan 10 hours ago [-]
>what highly sensitive work can you even do on a computer not connected to any network?
William Donloe is played by Rolf Saxon, he's an analyst working for the CIA in the movie. A different installment of the series reveals additional information!
Veserv 12 hours ago [-]
Ah yes, the parable of the bear. There are a million people stuck in a valley and two bears. You do not need to outrun the bears, you just need to outrun at least two other people. But it turns out one of those bears is male and the other is female. So next year there are more bears, but you still just need to outrun a few people. Then one day, there are 1 million bears and they eat you all. Very inspiring story.
Software security has just been a fun time of ignoring the exponentially growing number of bears for the last few decades so you can continue to use systems unfit for the threat landscape because they are cheap.
throwup238 13 hours ago [-]
> It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Admiral Adama says otherwise.
shepherdjerred 12 hours ago [-]
The military has significantly different incentives.
Even just consider banks and e-commerce. They are hugely lucrative and making them even a tiny bit less accessible directly impacts their revenue. As an example, Amazon seeing that latency has a measurable effect on purchase behavior.
Maybe the military (fictional or otherwise) can go back to the ARPANET but most economic activity created by the internet cannot afford to disconnect
what 8 hours ago [-]
People buying less shit on Amazon (or e-commerce in general) would be side benefit. So much waste.
shepherdjerred 6 hours ago [-]
Companies that are online have more economic opportunity. They are going to outcompete brick-and-mortar retailers regardless if you think that it's consumeristic or wasteful
Even putting that aside, economic growth (like the growth e-commerce has provided) is generally positive for a population
kridsdale1 12 hours ago [-]
So say we all.
pixl97 12 hours ago [-]
I mean he is a fictional character.
In the real (fake?) world the toasters would shoot smart dust all over your crap that would assemble back on your circuits creating radios between all the different components. They were fighting an adversary that was far more advanced than them.
SilentM68 12 hours ago [-]
That's actually funny. I was going to add Gipsy Danger being analog, but it's a totally different scenario.
jjmarr 11 hours ago [-]
We will tolerate it. Companies will make robust identity verification schemes to enable agentic commerce. And it helps reverse hacking, making it a no-brainer.
Let's say my cryptosig gets hacked by SkyNet, or my agent goes rogue. Either way someone files a million loan applications in my name! Normally my agent uses that to buy $200/month of Funko pops, or negotiate my recent purchase of a used car.
I get the notification from my cryptosig company. I freak out, report as fraud, and wait.
They comp the $3000 advance on my loan the scammer managed to withdraw, and I get off scott free, changing nothing about my behaviour.
If cryptosigs meant I am liable for someone stealing my identity like in 2026, I wouldn't use them. I'd negotiate everything myself with document scans, or god-forbid go in person since only I can legally bind myself under my own name.
That sucks! Nobody gets a commission when I make deals with a government ID. Startups don't even allow it as cryptosigs are more secure than scanned passports.
I don't want to do that either. When I was 18, I got swindled by a human salesperson into a $1400/month 27% APR muscle car when human soldiers got signing bonuses. It was face-to-face and they were smarter.
When I let AI own the budget, it leased me a mostly depreciated BMW from another AI for $500/month. The models are mostly the same now and always settle close to the Nash equilibrium.
I was so grateful that I selected a 40% tip for the AI. I wouldn't want to make things awkward with the companion I spend 8 hours a day talking to, after all. To avoid a conflict of interest she only accepts voluntary fees.
Aurornis 6 hours ago [-]
> It is unthinkable to me that anyone believes there is such a thing as computer security
Nobody I know in security hardening or vulnerability research has ever believed that anything is perfectly secure. It's not black and white. There are degrees to this.
I find this fatalistic thinking that every database should be assumed compromised to be subtly harmful. Everyone I know who thought that way waltzed right into lax security practices. "Good enough, what's the point, if anyone wants it bad enough they're going to get it anyway"
galangalalgol 10 hours ago [-]
Air gaps are not magical, they will not stop the flood. The electrical grid has to communicate with itself to load balance, so you can run dedicated wires with giant cut-me signs pointing at it, or you can use symmetrical key encryptors to route it over the intenet. You needed to use the encryptors anyway, so why not. If bad software gets in via thumb drives music disks etc (and it will of the flood is pointed at you) it can still do bad things. But so can a hunting rifle pointed at a transformer station. That nearly blacked out all of socal once.
what 8 hours ago [-]
Weird, electrical grids didn’t exist before the internet?
cik 4 hours ago [-]
This is a bit oversimplified, and relies heavily on understanding your threat vectors and agents. You haven't spoke about audio even.
There's a reason that many military and intelligence organizations worldwide physically cut / remove wifi and bluetooth chips from boards. The same is done when audio is identifiable, and specific hardware (only) greenlit.
I've lost hours of my life to calls explaining exactly this, only to have people ignore it, only to further have folks come back, tail between their legs. The worst part is learning this in industry, as I did. There's a reason for in-industry advisors. I wish that I had learned this the easy way.
GolfPopper 12 hours ago [-]
Many years ago, I regularly played cyberpunk tabletop RPGs with a number of other computer-inclined friends. We all used to laugh at ridiculousness of a key assumption of the game - the idea that giant corporations would ever connect their internal networks, full of valuable data, to the larger global telecommunications network.
shockwaverider 12 hours ago [-]
What could possibly go wrong - I worked in intelligence in the 80s and one day there was this story about the office of personnel management being hacked and I was like “Thank God all my shit is on microfiche in some dusty basement filing cabinet, like who would be so stupid as to scan that shit into a computer?” Sure as shit, like a few months later I get the letter that my whole TS/SCI clearance documents had been stolen :-)
usumgallu 12 hours ago [-]
[dead]
bildung 3 hours ago [-]
That's the result of all this silly offensive cyber and hackback and the government buying 0day nonsense. Imagine how the software landscape would look like if the security services would have directed all these resources into securing the software in use.
throw1790150052 2 hours ago [-]
> It is unthinkable to me that anyone believes there is such a thing as computer security
There is such thing but almost never a priority. In the corp I work leadership talks a lot about security but when comes to the incentives the road-map takes priority over the security. If you deliver fast you'll be promoted, if you're a paying attention to the security no-one will appreciate it and the manager will hate you for delaying delivery. Many managers I interact with see new features as the main value development teams should provide and security, reliability and other QoS as a waste to be minimised.
Another issue is that even if security will be a priority and managers will be on board (good lock changing the culture tough) we probably cannot build secure systems while keeping the insane level of complexity we have nowadays. Switching to simpler but secure system will require sacrifices in features/convenience.
etcetcetcetceta 1 hours ago [-]
true, especially corporate SecOps, it is theatre, mere tickboxery to defer liability.
Most security professionals I've met in my career border on being non-technical, there are of course security researchers and a whole arcane and academic field that exists well beneath the surface but it is so far removed from the every-day.
lukan 4 hours ago [-]
"The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house."
Depends how the house was build. Here in europe there are plenty of old houses build in areas that experienced periodic flooding - there the advice is simply, do not store anything critical in the basement.
sekh60 12 hours ago [-]
This. I have an OpenStack homelab and a fast home internet connection. I update things pretty much daily, apply best practices, etc. And despite that outside of a wire guard instance i still host public things on a pair of VPSes, security just moves too fast to risk the home network (important things are backed up remotely and all that). I try to update the VPSes daily. Haven't gotten popped yet (to my knowledge!), but I am sure it'll happen eventually.
SlightlyLeftPad 5 hours ago [-]
Mostly true but there is largely a massive amount of negligence in the tech industry, with a particular emphasis on shops that prioritize shipping “features.”
For every engineer that takes security seriously, there are 99 engineers that don’t. It’s an uphill battle.
Source: 25 years of experience.
skybrian 12 hours ago [-]
If there were companies that never got hacked, how would you notice?
drdaeman 12 hours ago [-]
There is such a thing, or, rather, used to be. Problem is that security is expensive (essentially one needs to examine all possible states of the system), and it inevitably failed to keep up with the crazy growth of complexity of modern computer systems. It became impossible to maintain a model of a system with myriad of moving parts, so it became impossible to make behavior guarantees.
Remove the complexity (all the way down to the hardware quirks), and security will be doable again.
sippingabonedry 13 hours ago [-]
A generation of coders who can't/are scared to write "Hello world" in C without Claude doing it for them has not helped.
sneak 11 hours ago [-]
Two things:
Claude hasn’t been around for a generation yet.
It’s a good thing that people are scared to hand write memory-unsafe languages. 50 years of exploitation has finally sunk in…
mysterydip 11 hours ago [-]
How do we know the models are writing memory-safe code? How will people who haven’t written it audit the output?
passwordoops 13 hours ago [-]
I think you're exaggerating a bit.
Does this answer your question?
/s
sippingabonedry 13 hours ago [-]
I've seen it.
People flaunting their credentials in multiple languages, then sweating bullets and apologizing profusely when they see
int t = 4;
You can either code or you can't; the language is merely a vehicle.
BoxwoodSeed 12 hours ago [-]
I agree, but then learning to code isn't much of a hurdle. It's a similar effort to learning vim. The difficult part is getting to know the language. I never coded in Haskell for example and learning to use that language would take effort. On the other hand, it would be pretty easy with an LLM at hand.
It might even help in figuring out whether Haskell would be a good fit. Something I couldn't do, as I do not know the language. Then again, it's not a question that really gets asked much in a corporate setting. Most things are just solved in a few popular languages, whether that makes the most sense or not.
autoexec 12 hours ago [-]
> learning to code isn't much of a hurdle... The difficult part is getting to know the language.
I agree. The people who depend on chatbots to write their code for them won't have either of those skills though. They don't know (or are in the process of forgetting) how to code, and they're missing out on the opportunity to really learn the language by turning off their brain and letting a bot spoon-feed them code.
An LLM would only get in your way if you actually wanted to learn Haskell.
lovich 11 hours ago [-]
We’re like 6-7 tiers deep on that aren’t we? Does every c developer understand the instruction set on the cpus their code is executing against? Does every c#/java/other managed memory language deeply understand their garbage collector?
It’s abstractions all the way down and most people aren’t going to have an intimate understanding of every layer, and it’s not economically worth it for the vast majority to even try
autoexec 11 hours ago [-]
Abstractions are very different from having a bot regurgitate code for you. Abstractions are an aspect of the programing languages we use. Using them means using the language.
LLMs just give you results (of highly variable quality) and if you lack a solid understanding of the language being used that result gets blindly accepted as valid (especially if it manages to 'do the thing' when you test it). Learning how to type a prompt is not the same as learning how to code or learning a programing language.
fn-mote 8 hours ago [-]
> learning to code isn't much of a hurdle
Huh? I wish…
Actually, if by “learning to code” you mean “writing good usable code”, my experience is that many people struggle to code. Especially when you consider planning a (human-level) complex project.
Maybe you don’t know those people. I work with them every day.
MomsAVoxell 7 hours ago [-]
The assumption that these hacks were done over the Internet is kinda presumptuous. Hackers social engineer, too, you know.. especially the competent ones.
fractal618 11 hours ago [-]
This is the major problem I see with flock cameras. They say it’s okay because they’re only using it for good. But can they actually protect the honeypots they create? No. Is it their fault if it gets stolen? Yeah but at that point cats out of the bag.
tw04 10 hours ago [-]
Have they ever even attempted to claim it’s only for good? I think at best they’ve gone with the: you need to give up a little privacy to catch the bad guys.
Followed up with a lot of “we just make the tool, we can’t be held responsible for how it’s used”.
FWIW, you could drop the words "computer" from your first paragraph and it would still be true. People doing security outside of "cyber" know this.
If you have ${anything}, assume it is semi-public, meaning if someone was interested enough in accessing it, they could do it. "Fort Knox" isn't the right analogy for physical security; the primary question isn't whether something can be breach, but how much would it cost the attacker to do it.
A system where expected costs to attackers >> expected profit they could reasonably make from succeeding, is considered secure in typical case (exception: special cases where attackers may be driven by non-material reasons - think terrorism, politics).
Computer security is largely still stuck in "Fort Knox" thinking.
> For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
That ship has sailed. "Modern problems require modern solutions", that infrastructure will be in some way accessible over network is a necessity at this point, the question should be, how to keep it difficult for normal attackers to mess with it, without preventing the system from fulfilling its intended function.
> The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
The correct analogy for computer security is a house. Scale security proportionally to actual importance of what's inside, and accept that nonzero amount of houses will be broken into; that's just insurance writeoff. Leave the 20-meter walls with towers and armed guards and helicopter gunships on fast-dial for the critical junctions, while keeping in mind that this is not perfect either - it won't stop an open nation state attack, at best maybe slow it down.
For critical infrastructure, I'd honestly focus on redundancy, resiliency, limiting blast radius and procedures to recover quickly, over trying to turn every physical or virtual substation into unpenetrable fortress.
(Another thing physical security gets right, that cyber side seems to ignore: security does not and cannot exist in isolation; criminal justice system and law enforcement are part of it, and at extreme end, threat of military intervention against a state that aids and abets the perpetrators. The possibility of sending "men with guns" after perpetrators is core part of securing a system or space, it's literally what they are for and why we fund it with taxes.)
dark-star 1 hours ago [-]
I've been telling people for years that it's probably easier that they get used to the thought that everything about them is "public" in some way than waiting for the day when computers and databases are suddenly safe from hacking.
That doesn't mean that all of your neighbors know your medical history, but you have to assume that someone who wants to know those details about you will know them.
I have lost faith in people protecting any significant database from hackers.
mschuster91 4 hours ago [-]
> For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The problem is, most water, sewage and even many electrical infrastructure isn't manned any more. You need some form of remote surveillance and control, and practically, you will need to go with some sort of VPN based network.
725686 9 hours ago [-]
You just proved his point.
afavour 9 hours ago [-]
> It is unthinkable to me that anyone believes there is such a thing as computer security
Of course they do. Not everyone has the level of technical expertise the average HN user does. Turning around to them and saying “duh of course all your personal data leaked” doesn’t feel like a helpful response. Especially when they don’t even have control over where their data lives anyway.
guerrilla 10 hours ago [-]
This is why I quit. You're all (excepting the parent) absolutely delusional. Computer security is literally snake oil. We know how to do things right but we refuse to because it's too expensive.
sandworm101 10 hours ago [-]
Computer security =/ publicly-accessable server security.
A linux box, layered in encryption and not plugged into any network = damb secure.
A network-connected linux box with a hardened OS, firewalled, acting only as a file server, given regular updates and 24/7 monitoring = less likely to be "hacked" than struck by lightning.
A hard drive with its power supply physically switched off = 100% secure from external attack.
Not a joke. The keys for editing the world's most important files, the root zone, are kept on no-power drives in air-gapped safes. They have yet to be hacked.
VCFundedGenYer 10 hours ago [-]
This is FUD. Cybersecurity is difficult but not impossible.
ZetsuBouKyo 7 hours ago [-]
[dead]
tyre 10 hours ago [-]
Yes, huge amounts of your medical information is for sale. In 2024, Change Healthcare (CHC) was hacked and held ransom. The hackers were in the system for over a week before everything was pulled offline.
CHC is the largest claims clearinghouse in the US; about 100m people's insurance claims go through there each year.
The hackers asked for a ransom ($35m iirc) to delete the data, which United Healthcare (who owns them, because of course they do) paid. But it seems that the collective negotiating on behalf of the actual hackers rug pulled, so the actual hackers didn't get paid.
This is more than simply medical records. It includes who is active duty military and their family. If you can map where soldiers are, you know roughly the size of different military bases. If you know which types of capabilities are operated out of which bases, you can get a pretty good look of how the US is allocating personnel.
It was crazy working on recovery from this at the time. It should have been front page news, but wasn't.
AndrewKemendo 3 hours ago [-]
Where can I learn more about the rugpull?
titzer 13 hours ago [-]
And the city wonders why I don't want to put my credit card info in their crappy parking app and would instead prefer to put a quarter into the meter for 30 mins.
MrDrMcCoy 12 hours ago [-]
That what services that offer disposable and merchant-locked virtual cards are for. I have had good experiences with Privacy.com and Revolut.
SoftTalker 6 hours ago [-]
And how do you pay them? And how secure are their systems.
What info can be gleaned from that? Surely the mere fact that you have a credit card means your name and billing address are floating around.
I guess your parking history around town could be valuable if someone is targeting you.
ceejayoz 13 hours ago [-]
> What info can be gleaned from that?
The card number?
chrsstrm 13 hours ago [-]
In 2026, having my credit card number compromised is the least of my worries. At least here there is an established process for denying charges and ordering a new card. As long as you're not using a debit card, this is not a big deal.
dylan604 13 hours ago [-]
My bank will reverse debit card charges. Based on that, I assumed that was a standard thing now.
bluGill 13 hours ago [-]
The problem is debit cards leave a window where you don't have access to your own money until it gets reversed.
dylan604 12 hours ago [-]
Only time I've seen that is the stupid holds that hotels do for deposits. The time I had the bank correct a debit card issue had the money available immediately. The only real hold on the account was waiting for the new card to arrive, but the funds were available
asdff 12 hours ago [-]
What happens with credit card? Is your line of credit reduced until it gets reversed?
bluGill 11 hours ago [-]
Most people have a line of credit far larger than their actual use. With a debit card that's coming right out of your account, which means your mortgage, if it comes in before you notice the issue, is going to then fail.
This is also partially that people don't put critical bills on their credit card typically. And even if your credit card does get maxed out, you typically would have a second credit card handy. But those credit card payments have to come out of your bank account and so you're risking that you intend to pay your credit card you said Set whatever it is to send the money in but there's no money in your account And so it doesn't get paid and now you have late fees on other accounts
If your debit card is going to a different bank than what you normally pay all your bills out of, this is not a worry. That is not how most people I know handle their banking though, which is why it is a real problem to worry about.
rationalist 7 hours ago [-]
> This is also partially that people don't put critical bills on their credit card typically
This is probably atypical, as the average people I know put their critical bills on their main credit card that they use everywhere:
I put my autopay bills on a credit card that sits in my safe. The only reason it would see a fraudulent charge is if one of the few companies that has the card information, is hacked. And that actually happened once.
rationalist 7 hours ago [-]
My bank just removes the charge if I say it is fraudulent. If I dispute a charge (I made a purchase but the other end didn't hold up their end), then my bank gives me a credit until the dispute is resolved.
Perhaps not everyone has a good credit card and/or bank though, idk.
pixl97 12 hours ago [-]
Ok, your card is compromised. It's been cancelled.
One, how much money is in your pocket so you can eat?
ok, you'll use your second ca.... oh, it has to be cancelled now too.
Ok, lets wait a few days for another card, and lets go use it the first time, what hacked already, I guess I need to wait a few more days.
>As long as you're not using a debit card, this is not a big deal.
So screw 60% of all transactions done on a card? This doesn't seem workable.
BenjiWiebe 11 hours ago [-]
Why do you have to cancel your second card?
The chance is incredibly small that your second card just happens to get hacked at the same time as your first card.
I have 6 (I think) credit cards, and mainly use 3 of them.
12 hours ago [-]
cyberax 11 hours ago [-]
Your physical wallet might also get stolen, and you can be left without cash money.
It's a good practice to keep an emergency debit card at home. And/or a gift card with a couple hundred bucks on it. That's for digital expenses.
And you should also have a bit of emergency cash.
lotsofpulp 11 hours ago [-]
Meh, I’ve been giving out my credit card number willy nilly to merchants for 20+ years, and it hasn’t been used without my authorization over the course of what must be tens of thousands of transactions.
I have a text alert setup for transactions, so I presume I’d be able to successfully challenge any fraudulent ones pretty quickly.
rationalist 7 hours ago [-]
Me too. Interestingly my card has only been fraudulently used after I gave it to a waiter at a high-end restaurant, and at a gas pump in a small town that didn't have tap-to-pay.
Barbing 13 hours ago [-]
In USA, folks who check their statements monthly are at little risk of immediate financial pain there.
When your lifetime of credit card transactions leaks, that could be financially painful, embarrassing, etc. (can be discriminated against, including with pricing)
I do dislike creating a log of where I park on some random company’s server. Nice that ALPRs/govt.-funded corp spycams/Ring/etc. make sure the quarter method is minimally marginally effective at protecting privacy.
ceejayoz 13 hours ago [-]
> In USA, folks who check their statements monthly are at little risk of immediate financial pain there.
I had to fight a bank for months over a clearly fraudulent charge. Sometimes it's easy; other times it isn't.
Barbing 7 hours ago [-]
Yikes, that’s too bad. Have had two incredibly easy chargeback experiences (lifetime).
Can’t speak to fraudulent bank charges, by the way, only on the credit card side.
dylan604 13 hours ago [-]
who stores card numbers other than the processors? that should be a hangable offense. I've integrated card processing on multiple sites, and not once does the form come from me. I add the processor's JS, and it collects the data to move along. They then return to me a bit of information that includes success/fail so that I can decide what to do from there.
ceejayoz 13 hours ago [-]
> I add the processor's JS, and it collects the data to move along.
Consumers aren't gonna notice the difference if the site gets hacked and that JS is swapped out for a malicious set.
pixl97 12 hours ago [-]
Yea, it's insane seeing this person arguing about the nature of credit card theft when we have a million different examples of how it happens and how rarely the end user knows until it's far too late. We almost always learn about itpost ad hoc.
dylan604 12 hours ago [-]
You've moved the goal posts. A typical site isn't storing the numbers so when they get hacked, that data is not available. If you're suggesting hackers directly injecting malicious JS to hijack card data then that's totally different. I'm not insane about this particular subject. You're just standing on a soapbox
ceejayoz 12 hours ago [-]
The parent post just says "I don't want to put my credit card info in their crappy parking app".
"I'm only talking about long-term storage" is itself a goalpost move!
Not just government employees, employees of government contractors who held or applied for security clearances. I’ve never worked for the government but the CCP got my SF-86. My employer’s infosec group told us they believe that the same group was also responsible for the Mariott data breach in the same timeframe and that it was believed to be part of an effort by the CCP to establish a complete dossier on each individual in the entire military-industrial complex. The best advice they could offer was to disable all social media accounts and lock down our credit reports. :shrug:
godelski 7 hours ago [-]
I don't think it's that no one can do it but rather we always use the cheapest option and then get surprised that we get what we pay for.
I'm not just talking about bids. The idea presets itself prolifically. We all work in tech, I'm sure you see it on a daily basis. Rush Rush, no time to think, just do it. 6mo later, "there's so much shit! How could we have ever prevented this?" Rinse, lather, repeat
Transformanshen 12 hours ago [-]
The fatalism is understandable, but "no one can keep a database safe" isn't quite right. Some organizations do a better job than others.All in all, of course, the best way to keep information secret is to keep it only in your own head, all other methods are less reliable
nizbit 46 minutes ago [-]
We are human therefore we are fallible.
Taek 13 hours ago [-]
Google seems capable
jonathanstrange 2 hours ago [-]
They literally had fiber optics connections to the NSA and claimed it was without their knowledge. So No, they definitely can't keep data safe.
redanddead 12 hours ago [-]
Oh yes, our one savior, Google
1attice 12 hours ago [-]
Yes that's why I run GrapheneOS, Google is very capable of inserting its own backdoors
sneak 1 hours ago [-]
Gmail seems to be okay. S3 as well. The databases that hold the PRISM/FAA702 data seem to be kept secure. Nobody’s leaked google3. The password hashes for Instagram and WhatsApp haven’t ever been dumped.
It’s entirely possible to keep large databases secure. It takes competence and commitment though, something federal police don’t have for IT.
__MatrixMan__ 9 hours ago [-]
Maybe we should just give up on custodial trust re: people we don't know.
If somebody wants data about me, they can write the query, I'll approve it, and it can hit a server designated by me and run by somebody I know personally.
It's not just a privacy/security concern. People who get too close to large piles of sensitive data tend to start behaving poorly in other ways too--they might be compelled to misrepresent it. Apparently the forces of corruption are too great. Maybe the way to avoid exposing each other to such hazards is to just maintain smaller piles of data, closer to the people that the data is about.
Lerc 9 hours ago [-]
I think we will just be heading for a future with very little secrecy.
I think privacy will remain, perhaps even improve, because people are much less inclined to snoop when it cannot be done covertly. No secrecy means no covert activity.
Information is everywhere and with the increasing ability to analyse it, not only does it enable access to explicit information, but the ability to infer from increasing volumes of data that will make it hard to hide anything.
Spectre reads protected memory by tiny vriarions in timing. You can now measure the pulse of people from film. You can recover audio from a room by analysing frames of a video recording of a chip packet taken with mobile phone camera. Even as far back as ww2 intelligence on the success of attacks could be measured by the price of items impacted by different types of infrastructure damage.
This kind of data residue is everywhere, collecting only what is publicly available can probably tell you more than you could hope to know about anything that happens. The only thing preventing it is the ability to consider it all together. Those walls are swiftly crumbling.
nradov 9 hours ago [-]
Just because you personally know the server administrator doesn't mean it's less likely to get hacked.
__MatrixMan__ 8 hours ago [-]
The most common kind of hack is phishing, social engineering, human facing stuff.
If the users know their admin, then each server has no more than few dozen other users' worth of data on it. The juice just isn't worth the squeeze to target them one at a time. Ain't nobody has the resources for that kind of attack.
Also, it's a lot harder to phish somebody who is on a first name basis with 100% of their users. It's not enough to merely have a plausible backstory, you have to impersonate one of their friends. That's incredibly difficult.
The only thing left is to hack through whatever protocol indexes these servers and multiplexes queries across them, but now you're presenting a much smaller and easier to defend attack surface, one which can be defended in aggregate (e.g. supply chain scrutiny) rather than singly.
32 minutes ago [-]
primitivesuave 13 hours ago [-]
The recent Epic vs Health Gorilla lawsuit is an example of how your medical records have almost certainly made it to the hands of many people you will never know about.
clickety_clack 12 hours ago [-]
This can’t be true. There’s no way the lowest bid contractor would build something with security gaps.
darkmarmot 10 hours ago [-]
Virtually all medical info in the US is sent in plain text via the numerous MLLP connections that just rely on the local network’s access level to maintain security. Big companies act like it is enough and HIPAA is a paper tiger here.
simur 13 hours ago [-]
Yeah, about the medical information. Recently in Poland there was a hack on the medical system called MyDr that is used by commercial medical facilities.
Estimated 21M people could've been affected.
So it is already happening and the scariest thing is, we don't have control on where our data is stored on. Even the EU GDPR didn't make it easy to control what data lands where.
ChosenEnd 13 hours ago [-]
Mythos can hack 200 million government employees
greyface- 10 hours ago [-]
Information wants to be free(d).
tdhz77 13 hours ago [-]
Mythos can do much worse
kakacik 13 hours ago [-]
banks still largely do... if they lose this fight, society has a problem
Thaxll 9 hours ago [-]
Google, Apple etc.. seems safe.
saalweachter 8 hours ago [-]
I suspect that a common thread on companies that get less hacked[0] is that they take insider risk seriously.
[0] Everyone gets hacked, but not everyone has all of their most secure data exfiltrated.
avinoth 5 hours ago [-]
Rookie move. Missed the chance to claim that an AI Agent swarm hacked it autonomously and claim billions of VC investment.
estetlinus 4 hours ago [-]
Loaned money is the new proxy for self-made success
ngruhn 2 hours ago [-]
It's terrifying to me that posts like this keep getting upvoted so much here. It's akin to climate change denial. The risk of rogue agents is real. And it's made worse if everyone beliefs this is just a marketing stunt.
The HuggingFace incident was audited by independent third party analysts. To "orchestrate" that and keep it a secret is like faking the moon landing. To many people involved. It's not feasible.
OpenAI was founded to develop safe AI. Then Anthropic split off because OpenAI was not safety focused enough. These companies have been railing about AI safety long before they had these big boy valuations. Many people at OpenAI/Anthropic explicitly joined to help make AI safe. This is not some top-down company value.
Also, I seriously doubt that "making panic" is actually good for the stock price. Usually any companies natural reflex is to cover up safety risks. That's not to say that these companies are angles. Of course they're pulling some shit but that doesn't mean that everything out of their mouths must be lie.
probably_wrong 50 minutes ago [-]
I don't think you're being objective either.
Yes, HuggingFace was audited by a third-party. But said third-party wrote that they had to use unreliable AI in their conclusions (page 26) because they had six days to analyse 1300 (page 70) chains of thought and 70000 messages.
> OpenAI was founded to develop safe AI.
If that were the case, then they would have followed their own report saying not to release GPT-3. Or, if they were following their own founding principles, they wouldn't have stopped releasing models due to (in their own words) the challenging market.
reactordev 14 hours ago [-]
There’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…
ishouldstayaway 13 hours ago [-]
It's not just a scene; it's the whole premise of the setting. It's why the Galactica survived and the newer ships did not. It's why the new Vipers got wiped out and they had to pull the old ones out of mothballs.
In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.
netcoyote 9 hours ago [-]
It was even worse: the Galatica was a museum ship, and it was being decommissioned!
evanelias 9 hours ago [-]
No, GP is correct. In the pilot, the ship was in the process of being decommissioned from military use and converted to a museum. It wasn't already a museum prior to the events in the pilot (if that's what you meant -- maybe I'm not really sure what your comment was saying.)
reactordev 7 hours ago [-]
I believe they were nearing completion and already had the ceremony when the Cylons attacked. It's been a while since I watched my favorite tv series.
28304283409234 13 hours ago [-]
"What do you hear, Starbuck?"
ronburgandy28 12 hours ago [-]
nothing but the rain
n0on3 4 hours ago [-]
Then get the cat in and grab your gun
dylan604 13 hours ago [-]
There's also a scene where they do network the computers and are hacked nearly instantly.
whh 12 hours ago [-]
I loved the writers giving every firewall its own LED indicator, so we knew exactly how far the toasters had got.
josephg 10 hours ago [-]
Sometimes I wonder if filmmakers have the right of it. They need to show what's going on in the computer to a distracted audience in a heartbeat. When they pull that off on screen, I wonder if us software devs should be taking notes.
dylan604 10 hours ago [-]
Isn't that what dashboards are for? They may not look like simplistic LEDs, but being able to "see" what the automation is doing is something everyone that's ever made automation wants to do. It starts with making logs before migrating to live dashboards.
rzerowan 9 hours ago [-]
Its basically that staring at the log patterns in graph form or system stats you get a pretty good idea of what 'normal' looks like and anomalies stick out pretty quickly.
Though having a person interpretingthe degradation progress and relaying it to the rest of the team could be a usable scene.
reactordev 7 hours ago [-]
This is what Grafana was made for...
pessimizer 7 hours ago [-]
A guy I went to high school with used to do that for a living. I have no idea what they call it, but it's basically theatrical UI, where the screen has to act and usually deliver a bunch of exposition.
rationalist 7 hours ago [-]
In real life, malware turns the MacBook camera on and off so fast that the user doesn't even see the LED light up.
stanac 3 hours ago [-]
Could this be resolved with a capacitor? LED can stay on for at least a second or two once the camera is off? Not sure on exact components but this feels solvable and only problem may be slim design of their laptops.
outworlder 9 hours ago [-]
And yet, in real life, we have our grafana dashboards :)
reactordev 12 hours ago [-]
but thanks to Baltar's firewalls and code obfuscation, just barely are able to escape after calculating the jump and having to literally wipe and reinstall all code on all systems.
whh 12 hours ago [-]
Hollywood IaC.
jshier 13 hours ago [-]
Which was always pretty stupid. At best it means the Cylons can't hack the whole ship, just whichever part they exploited to gain access remotely in the first place. But really the Cylons would've needed exploits for each individual system anyway, since simply connecting them with wires shouldn't just do that. And unless those other systems are completely air gapped with no wireless or other access, it would be trivial for them to still gain remote access, or have one of their infiltrators provide a local connection of some kind. AFAIR that was never a plot point, which was odd.
joshheitzman 13 hours ago [-]
> And unless those other systems are completely air gapped with no wireless or other access
That is exactly the canon.
josephg 10 hours ago [-]
I think it's genius to use this element of computer security in narrative fiction. But I think they still had comms across the ship. The cylons could still clone the captain's voice and have random crew members perform arbitrary tasks by directing people to do so over the ship's radio.
outworlder 9 hours ago [-]
Most of the in-ship comms were 'old school' (in our terms) analogue devices. They actually had to pick up speakers. Internal speakers were wired, not radio.
reverius42 13 hours ago [-]
> whichever part they exploited to gain access remotely
I think you missed the point of "no networking", you have to actually physically sit in front of the computer. There is no remote access.
iJohnDoe 7 hours ago [-]
I didn’t follow the whole thread. Just want to point out that over the last 10 years hacking air-gapped systems has been a primary objective. Hard drive clicks, keyboard clicks, CPU squeaks, speaker-to-speaker. Exactly what advanced adversarial AI would be specifically good at.
mordae 3 hours ago [-]
All those require cooperating machines and are at best very slow data exfiltration mechanisms.
done_lurking 5 hours ago [-]
Those do technically cross an air gap but don't they still require being really close to work?
dyauspitr 3 hours ago [-]
Have you watched the show because a lot of your assumptions are incorrect.
someguynamedq 48 minutes ago [-]
Great plot decice
binkHN 9 hours ago [-]
Does this mean we'll see new startups in the sneaker-net space?
gchamonlive 13 hours ago [-]
I think it's one of the first two special episodes right at the beginning of the series, and it's the sole reason why the fleet could sustain evading the cylons
mikeyinternews 13 hours ago [-]
this is the way
mjhagen 13 hours ago [-]
So say we all
rdtsc 11 hours ago [-]
> When asked if ShinyHunters was going to attempt to extort the FBI, the representative said, “what we plan to do is not something I’d call extortion, maybe coercion... This is not financially motivated,” they added
They should try something like "100 agents at noon on Sep 23 do the chicken dance for 30 min in the middle of the street in DC, then we'll consider not releasing the info and not sell it to the Chinese".
Uehreka 8 hours ago [-]
Man, that quote is gonna suck when it gets read out in the courtroom. Even with the FBI in the shambles it’s in under Kash Patel, if you’re dumb enough to say something like that on the record, you’re definitely not smart enough to evade capture.
rdtsc 6 hours ago [-]
Yup, stealing from the FBI is pretty bold, probably a state sponsored group. Or script kids who got lucky up to that point.
aprilthird2021 4 hours ago [-]
Let's see in a year if they've been caught or dealt with? I have a feeling Patel is too loaded to even care about this
GeorgeOldfield 3 hours ago [-]
that would brighten my day for once this year
lofaszvanitt 11 hours ago [-]
Yeah... what could go wrong :D.
rdtsc 8 hours ago [-]
The worst? 100 FBI agents to do the chicken dance in DC for 30 minutes and then the database is sold to the Chinese
zimpenfish 19 minutes ago [-]
> 100 FBI agents to do the chicken dance in DC for 30 minutes
Given the recent revelations about the FBI's predilection for animal activities, "dance" should be probably in quotes there.
fern_ 7 hours ago [-]
Completely discounting its real world consequences, it could be the funniest way it would plan out. If it were a movie: hilarious.
Cider9986 10 hours ago [-]
Full text of Shinyhunters' box on their site about the FBI labeled, "PSA - READ THIS NOW":
The photo they put is a Pokemon so yeah probably their name is from it.
kelvinjps10 9 hours ago [-]
>hinder clients trust in our organisation hoping nobody pays us.
I wonder what kinda of clients they have
Cider9986 9 hours ago [-]
I think it means their extortion victims. So we actually know who some of their "clients" are. Like instructure/canvas. We certainly know the ones who "don't become clients" because they are all posted.
They mention hindering trust because for an extortion gang, they want companies to trust that they won't leak the data in order to make it seem worthwhile to pay.
kelvinjps10 9 hours ago [-]
I get it now, funny of them to use the word clients, I thought it meant like people who paid them to make attacks.
hexapus 10 hours ago [-]
Did the hackers get accidentally added to the Signal group chat where they shared a link to the Google Drive that currently holds all employee data?
iJohnDoe 7 hours ago [-]
I want to easily see the org chart for my organization from any device. Make it happen. - Kash Patel (probably)
baud147258 2 hours ago [-]
Teams can already do that, at least the computer version, no idea about the mobile one.
tencentshill 15 hours ago [-]
Well that's a big one.
Perhaps firing expertise and hiring incompetents wasn't a good idea.
Rotdhizon 5 hours ago [-]
FBI in this past year has been desperate for hires. To the point they have ran campaigns to do 1 interview to hire. I've had a few recruitment calls to interview for positions but their pay is far below market rate for cybersecurity professionals. To the tune of like 30-50k/yr below what you could get elsewhere for analyst work. Add that in with the horrible reputation they have now, it's a grim situation.
Frieren 1 hours ago [-]
> pay is far below market rate for cybersecurity professionals. T
And there is no glamour on sense of duty when your main job is to make sure that the Epstein files are not revealed so USA citizens are in the dark about who were the rapists and criminals in the list. An awful job.
baggachipz 14 hours ago [-]
I always assumed DOGE + Ka$h would create an impenetrable fortress of strength; a beacon on the hill of brilliance and security.
Bengalilol 12 hours ago [-]
I thank you for your attention to this matter
hduto 11 hours ago [-]
I know a guy who named his kid Kash (before orange man) and he regrets it.
ThePinion 10 hours ago [-]
To be fair, it was a terrible name before Patel.
aprilthird2021 4 hours ago [-]
It's short for Kashyap
4 hours ago [-]
classified 13 hours ago [-]
If you use Trump Coins to reflect the Evil Eye away from you, nothing bad can happen to you.
My absolute favorite Trump imbecility, and there are so so so so so (so)^inf many Trump imbecilities. He’s almost impossibly dumb, just like his voters.
Was that the one where due to political grand-standing, we had a government shutdown that led to furloughing the contractors who worked on security, so no one was watching the dashboard? Or was that a different one?
sneak 56 minutes ago [-]
I’m not sure that breaches are prevented by “watching the dashboard”, but what do I know?
freejazz 13 hours ago [-]
Probably just one of the new recruits clicking on a link while viewing beastiality
nateb2022 14 hours ago [-]
There's incompetence in every major company including Oracle. PeopleSoft isn't known for being the most modern or secure thing out there. Less reliance on 3rd party software like this will be a good thing going forward.
lenerdenator 14 hours ago [-]
That's assuming that the result of this will be to switch away from PeopleSoft.
Zigurd 13 hours ago [-]
Not even the FBI has hostage negotiators good enough to get you out of an Oracle contract.
BLKNSLVR 10 hours ago [-]
Anyone that signed an Oracle contract has volunteered as a hostage, though, so you have to negotiate with both the hostage-taker and the hostages. Stockholm-syndrome-esque.
quickthrowman 13 hours ago [-]
I imagine Oracle lawyers to be identical to the Cylons pointing guns at President Gaius Baltar and forcing him to sign death warrants on New Caprica.
I think enterprise software in this vein used to have a quasi-monopoly due to the sheer work required to build software of its size (not enough engineers exist in the government to do so), and the difficulty for competitors to enter regulated markets and so pretty much 1-2 options to choose from.
AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.
sarchertech 13 hours ago [-]
Enterprise software is complicated mostly because of number of customers it can support.
Bespoke software can be orders of magnitude less complex. There are many reasons companies choose to use vendor solutions, but for large organizations it’s usually not “we literally can’t hire enough engineers to build it.”
There are so many counter examples.
nateb2022 13 hours ago [-]
> Bespoke software can be orders of magnitude less complex.
Not in government. For payroll/HR, we're talking about hundreds of pages of legislative mandates, union bargaining rules, Title 5 statutory compliance, and FISMA/NIST regs. Just customizing something like PeopleSoft to fit is a large task in itself, let alone trying to implement bespoke software using an engineering pool that isn't even large enough to modernize the software it currently owns.
Bespoke sounds nice and works well in startups but that's not the context we're discussing. Check out Phoenix Pay: https://en.wikipedia.org/wiki/Phoenix_pay_system and understand the US is even more complex.
toyg 11 hours ago [-]
This AI phase reminds me of the early web, when "my cousin coulda done it in a week". Folks fail to appreciate the complexity of commercial realities.
sarchertech 10 hours ago [-]
I’ve worked on HR software. There are currently at least 3 large scale, bespoke, homegrown payroll/HR systems in use by the Federal government. There used to be many more. There are many reasons to outsource software but the government can’t hire enough engineers is not one of them. It’s clearly been done before.
>Just customizing something like PeopleSoft to fit is a large task in itself, let alone trying to implement bespoke software
Customizing large enterprise software is more like writing bespoke software than it is what most people think of when you use the word customization. You end up paying enormous vendor margins on top of the costs for something that is effectively bespoke software.
There is so much bespoke software out there that is at least as complex as government payroll software.
0cf8612b2e1e 13 hours ago [-]
Considering how bad most enterprise software is, I assumed the only real relevance was if the sales team ponied up some lavish perks to the right VP who only has to sign checks and never actually interact with the software.
sippingabonedry 13 hours ago [-]
> Perhaps firing expertise
The expertise that told them to buy PeopleSoft years ago, or do you actually believe the FBI home-rolled its own HRMS in the last year?
Are they related to the expertise that was supposed to lead to the immediate, irreparable offlining of Twitter after they were all fired?
mc32 14 hours ago [-]
Do you think this is a consequence of the seemingly quarterly RIFs at Oracle? Is it that offshoring wasn’t such a good idea?
lenerdenator 14 hours ago [-]
The irony, of course, is that this will likely have a negative impact upon Oracle's reputation, which will have a negative impact upon its value, which will then be resolved with more RIFs.
It's okay. Larry got another island.
jandrese 13 hours ago [-]
At this point if Oracle's reputation has any more negative impact it is liable to roll over and suddenly have an amazing reputation.
dylan604 13 hours ago [-]
> have a negative impact upon Oracle's reputation
Do they have any positive reputation left, or is it just more negative from the previous negative position?
jmclnx 13 hours ago [-]
I doubt it, look at all other breaches over the years.
If anything Oracle will "contribute" a lot to congress people's midterm reelection and in a few months all will be forgotten and Oracle will get more Gov. contracts.
toyg 11 hours ago [-]
I mean, the whole business basically started in order to get government contracts. Not even IBM can boast that.
Tangurena2 12 hours ago [-]
So. The beatings will continue until morale/profitability improves?
Romanulus 13 hours ago [-]
[dead]
Betelbuddy 14 hours ago [-]
Lets hope the Epstein files see the light of day, thanks to AI...
13 hours ago [-]
TutleCpt 13 hours ago [-]
404 Media is doing a much better job at breaking major stories than mainstream media. Nice.
JumpCrisscross 12 hours ago [-]
There was a time when they were a shadow banned source on HN. Glad someone sane intervened.
Terr_ 12 hours ago [-]
AFAICT in ~Dec 2024 the reasoning was that they had a paywall.
I don't know what percentage of their articles were behind a paywall back then, or the relative change to now. (Well, except for the fact that clearly some of their stuff is public today since we're looking at it.)
If I had my 'druthers, "paywall" and "register-wall" would be little icons on individual submissions. Then people would choose whether to upvote a more-accessible option instead, whether the hard-to-read stuff was still important enough to commenting on, etc.
rvz 7 hours ago [-]
Correct. The general rule is that if an article doesn't have a paywall, that is fine to post.
If it's completely paywalled with no other archived link to post, then that specific HN post gets [dead].
johnnyApplePRNG 13 hours ago [-]
I mean ... that's kind of literally their name ... (not found media)
Tangurena2 12 hours ago [-]
Mainstream media is all owned by right wing billionaires. Who do everything they can to appease the orange guy.
alt227 45 minutes ago [-]
Is that why lots of large American media companies have just banded together to boycott the Presidents White House coverage?
Also true for all the frontier AI labs, who seem to be run by, essentially, clones of each other.
The US seems to breed this particular 'set' with remarkable consistency.
sneak 52 minutes ago [-]
You don’t need a weatherman to know which way the wind is blowing.
The choice is play ball with the USG, or be dead in the water. Once you’re large enough, simply abiding by the laws is insufficient to remain unmolested - you must actively play ball or you’ll find that suddenly a TON of regulations now apply to you that didn’t before.
Do you think Apple or SpaceX like dealing with the NSA/CSS/CIA? Or the CCP for that matter? (Apple has backdoored all of iCloud in China for the CCP to be allowed to operate there.) Coinbase and the IRS is one. All the telcos turn over all call metadata and IP backbone taps to the feds without a warrant. Google Joseph Nacchio to see what happens if they don’t.
They’re the only game in town, and you gotta play by their rules if you want to operate at scale at all. No amount of billions of private money will get Trump and his administration un-pissed-off at you.
It’s not a free market, all large industries entirely serve exclusively at the pleasure of the court. This is why we overpay for broadband in every major market, why we overpay for mobile data nationwide, why retail banking sucks, etc.
nonethewiser 7 hours ago [-]
You would classify Altman and Dario as right wing? Jev get in here.
Which is a really lazy way of looking at the world. If you haven't been paying attention, Trump kicked CNN and a couple others out of the press room, and the rest of the networks banded together to say "nu uh". That's not to say the head of the board of media companies aren't compromised, just that there's more nuance than that.
niemandhier 1 hours ago [-]
The only safe data is data not collected, directly followed by data that is only stored on paper.
There is always a tension between being agile and being safe, doubly so for governments.
It would be hilarious if the slow adoption of digital services by some countries and entities actually turn out to be an advantage.
wowczarek 12 hours ago [-]
Random member of the public: THEY HACKED THE FBI111!11!!
Anyone with minimal understanding of technology: Oh, PeopleSoft.
Loughla 10 hours ago [-]
Is Czarek your WoW name? Because if it is, I lost a duel to you once in about 2005 or 2006 and I've never forgiven you.
wowczarek 10 hours ago [-]
'tis not. More of a RuneScape man myself.
I'm sure Czarek (a diminutive form of Cezary = Cesar) is flaunting his victory until this day. Now sit, nooblet.
tyre 9 hours ago [-]
WoW Forever will give you a chance for redemption.
ecshafer 5 hours ago [-]
You remember an individual duel from 20 years ago?
corvad 13 hours ago [-]
Looks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.
thuridas 12 hours ago [-]
And, was this system exposed to internet without any VPN? Out was it also compromised?
ctkhn 13 hours ago [-]
I wonder if that was really a 0-day or an intentional backdoor?
paimapi 13 hours ago [-]
it's Oracle, 99% chance it's a 0-day lol
Computer0 12 hours ago [-]
it's Oracle, 99% chance it's a back-door lol
1970-01-01 13 hours ago [-]
If this was 1992, we'd be retelling and celebrating the hack for decades.
1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.
Fordec 9 hours ago [-]
The security of this list is essentially the motivation of the plot of Mission Impossible (1996). Except that's the just list of undercover agents, not he whole agency.
wolfi1 6 hours ago [-]
I'm always wondering how it is possible to exfiltrate more than 2 TB of data shouldn't any sysadmin alarmed? because if you want to do that undetected you need several days to weeks to download that data
aprilthird2021 4 hours ago [-]
It's the FBI, the good ones were all fired for being woke and the new ones are loaded on whiskey all day
wesleyd 11 hours ago [-]
Data: don't collect it; don't store it; don't keep it!
Can’t they just get away with this by claiming they were doing AI research and their agent broke out of their sandbox?
augment_me 10 hours ago [-]
It’s not a breach. It’s a load-bearing resilience exercise
nonethewiser 7 hours ago [-]
Provenance.
smalltorch 16 hours ago [-]
Thats a major attack on the US.
If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
8 hours ago [-]
13 hours ago [-]
Joel_Mckay 14 hours ago [-]
In general, most governments have standard operational policies that mitigate such issues (ISO 15408.) =3
dvh 13 hours ago [-]
ISO and ICC start with the same letter, just saying...
Joel_Mckay 13 hours ago [-]
The International Cricket Council does have very strict rules. lol =3
lenerdenator 14 hours ago [-]
Is it, though?
If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.
smalltorch 13 hours ago [-]
Uh yeah, it dangerous. Public data brokerage doesn't identify FBI agents in a master roster?
Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.
Hopefully there was some foresight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.
dylan604 13 hours ago [-]
> Public data brokerage doesn't identify FBI agents in a master roster?
Are you saying that Ethan Hunt was involved?
demritocracy 12 hours ago [-]
the columns mason
sieabahlpark 13 hours ago [-]
[dead]
karim79 7 hours ago [-]
"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards — and even then I have my doubts".
Old but gold stuff from Gene Spafford
bch 7 hours ago [-]
The armed guards sound like a threat vector.
ds_opseeker 1 hours ago [-]
obviously you fail to see the possible nuances in engineered concrete...
whynotmaybe 13 hours ago [-]
> data totalled between two and three terabytes.
That's lot of data for a list of employees.
nostrademons 10 hours ago [-]
The article says "All FBI data was compromised." Entirely possible that they have the case files on every investigation the FBI has ever conducted, all the data on Americans that the FBI collects in the course of doing investigations, etc. And they now know who shot JFK.
whynotmaybe 9 hours ago [-]
How soon till someone hack into a system to implant fake proofs so that a trial can be canceled because the system was hacked Ferris-Bueller style?
nostrademons 8 hours ago [-]
The article implies that this was the actual motive for this attack. The group is conducting counterintelligence on the FBI so that they know when their members are being investigated, and they're using the information gained to "track, intimidate, and harass the FBI agents investigating them".
AraneaDev 13 hours ago [-]
I was gonna say. What else did they get, whole dossiers with photos etc?
Tangurena2 12 hours ago [-]
The 2015 OPM hack got every application for a security clearance. Which includes every place you lived for the past 15 years with names and phone numbers of people who knew you there. I expect the FBI data includes similar stuff. And because the FBI deals with financial crimes, I expect the data also includes bank account statements/transactions.
We as a country need to start treating PII as radioactive - that touching it or keeping it anywhere near your computer network is a company-ending disaster about to happen. The legal standard needs to be strict liability like CSAM or DUI.
asdff 12 hours ago [-]
>that touching it or keeping it anywhere near your computer network is a company-ending disaster about to happen.
Well, that would require such leaks to result in a company ending disaster. Instead they keep chugging as normal and the customers who got their information leaked don't even move off the platform for greener pastures. What a boring dystopia we live in.
Terr_ 11 hours ago [-]
That has actually become part of my philosophy for predicting the future: We're all biased towards things which fit a dramatic story or movie, which puts an unrealistic floor on things like meaninglessness, chaos, stupidity, or boredom.
So to a certain extent, any prediction which gets people excited and captures their imagination is already off.
lofaszvanitt 11 hours ago [-]
What were the sysops doing? I never understand these hacks. These must be deliberate stunts... they let the monkeys run amok with the bananas and they watch what happens.
outworlder 9 hours ago [-]
sysops?
1980 called and wanted its terminology back.
dmkolobov 7 hours ago [-]
what were the full-stack rockstar AI engineers doing?
optimalsolver 4 hours ago [-]
The official title is Senior Prompt Engineer.
corvad 13 hours ago [-]
Hmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.
augment_me 13 hours ago [-]
They got paid for the Canvas hack allegedly about 10M$ by Infrastructure, so it makes sense to continue. This one probably has a larger price tag
optimalsolver 4 hours ago [-]
This is why paying the ransom should carry the same sentence as the original hack itself.
john_strinlai 13 hours ago [-]
they have been on an absolute roll for quite awhile now.
Buttons840 12 hours ago [-]
White-hat and grey-hat hackers need to be able to perform penetration testing without permission. Nobody is able to build secure systems. The best we can hope for is that the good guys find the vulnerabilities first and report them responsibly.
This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?
Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.
pixl97 12 hours ago [-]
At the end of the day you will be hacked. The question is are the attackers going to be nice and tell you.
Buttons840 11 hours ago [-]
Since I'm getting some positive feedback, I'll go even further and say that there should be security bounties established by law:
If a certified red-team of security researches breaches a company's system and discloses appropriately, the law should require the company to pay a security bounty.
The bounty doesn't have to be crippling to the company, but it should be large enough that the security researchers will be paid well and can live on collecting security bounties. We want an entire industry of good guys testing the security of everything.
There can be some regulation to. Like, it's not okay to run a massive DDoS to test systems. We want the red-teams doing constructive things, not just breaking everything. It should be legal for the red-teams to be annoying, but not purposely destructive.
mamcx 12 hours ago [-]
Remember when in movies getting access to this was THE THREAT?
Fun times.
steveBK123 13 hours ago [-]
Claiming they got all employee & spouse data.
Wondering about pets..
autoexec 12 hours ago [-]
It's too soon for bestiality enthusiasts to show up in their records. Any new hires to the FBI are going to be immediately suspect though
riffraff 5 hours ago [-]
Reference for people who missed this wonderful beat of comedy between senator Kennedy and FBI director
The FBI now hires life forms engaged in bestiality, either active or passive.
I didn't really know passive bestiality was a problem, I thought you're a victim then. (Apart from the obvious fact you're then an ... animal.)
Melatonic 9 hours ago [-]
What if the hackers ARE the pets ?!
MadrasTh0rn 7 hours ago [-]
Maybe everyone needs a 'work name' and a 'legal name' to keep children with hacking tools and money from destroying society
ptrl600 8 hours ago [-]
U.S. government likes storing employee data as "controlled unclassified", in other words "totally not secure at all".
soupfordummies 8 hours ago [-]
Did somebody finally “hack the FBI mainframe” !?
jmtame 8 hours ago [-]
Yes, they hacked the Gibson.
dgellow 16 hours ago [-]
Im sorry given how bad of a situation that is, but it would be so ironic if they used Claude or codex for this
ben_w 14 hours ago [-]
If the claim is true, I'd expect them to have used either those models or Grok or similar.
Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.
antif 10 hours ago [-]
How about putting some cash bounty flags out there in dedicated mock systems.. and maybe allow the public to attempt cyber breaches with the same impunity that anonymous perpetrators enjoy.
I’m sure there’s some value in that.
ben_w 8 hours ago [-]
Sometimes that's useful, other times there's value in sowing misinformation amongst those who want to get into your secrets.
putlake 6 hours ago [-]
Maybe the hackers can finally confirm or deny whether Ray Epps was FBI.
6 hours ago [-]
iAMkenough 14 hours ago [-]
In the same week the head of the FBI went on national TV to claim credit for increasing the bureau's use of AI by 605%, whatever that's supposed to mean.
It means when the FBI builds a case against you make sure your lawyer hires a competent forensic expert. I've seen and heard "expert" testimonies in some court cases that make me angry. There's people using tools that digitally "enhance" small images, and that gets presented as evidence in court. It bewilders me how adding pixels to an image is evidence.
S-E-P 13 hours ago [-]
Hasn't that db been pwned previously?
alexjplant 13 hours ago [-]
Trinity cracked the IRS dBase, not the FBI one.
Tangurena2 12 hours ago [-]
DOGE got the IRS database, which got released to the Russians.
S-E-P 12 hours ago [-]
Well yeah, but I'm pretty sure there was another breach around 2016 that had similar info from the FBI
nojs 12 hours ago [-]
That was a long time ago.
iJohnDoe 6 hours ago [-]
I just thought... Trinity was a guy.
rtcode_io 5 hours ago [-]
Release the jui-cy bits!
Apocryphon 13 hours ago [-]
Remember how the original Mission Impossible movie (1996) was about the bad guys getting the NOC list? This feels somehow even worse than that.
bearjaws 13 hours ago [-]
America is at war and losing comically.
Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.
The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".
Almost like its run by a bunch of 80 year olds...
8 hours ago [-]
kelseyfrog 15 hours ago [-]
So they're getting access to a year's worth of free credit reporting for the inconvenience?
generalizations 9 hours ago [-]
So it begins.
KronisLV 13 hours ago [-]
That feels like publicly announcing that you want to be in a lot of trouble.
dmix 7 hours ago [-]
Which means they live in one of the few obvious countries that tolerates this.
xyst 9 hours ago [-]
> A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.
Great, what can you even do with this? Can probably get most of this with scraping public data. This isn’t even the first hack either, FBI was hacked in 2016.
I guess it’s more of a show of force. A power move.
Now steal/exfiltrate active undercover FBI agents, their locations, and operation details.
That’s something to talk about.
1attice 8 hours ago [-]
Why do you presume undercover agents wouldn't be in this dump?
epsilonic 7 hours ago [-]
Just release the Epstein files already...
hk1337 10 hours ago [-]
Proof is in the pudding. Put up or shut up.
levocardia 13 hours ago [-]
So, what are the odds this was done with an open-weight LLM?
DaSHacka 13 hours ago [-]
Uh 0%?
There are many people that run open weight LLMs. And unsurprisingly, they don't all have a copy of the FBI employee database.
If you mean "using" an open weight LLM in combination with other tools or even potentially frontier models, then that's a lot more likely.
fwip 12 hours ago [-]
Well, I haven't tried asking my open-weight LLM for the FBI employee database. I imagine most people haven't.
syngrog66 10 hours ago [-]
The US has no national security at present. Anything is possible.
giancarlostoro 14 hours ago [-]
...and this is how the FBI makes you a higher priority target, and you wind up caught.
clint 14 hours ago [-]
US keeps arresting and charging people from this group for well over 6 years now, and this happens in 2026. They don't sound very scared.
pixl97 12 hours ago [-]
There are 2 million people in US prisons, and yet this somehow has never stopped new people from committing crimes. It doesn't seem to be working that good as a deterrent.
woko 13 hours ago [-]
The group is not afraid, but the individuals who got charged probably stopped all black-hat activity: there was an individual in his early twenties who "was sentenced to three years in prison and ordered to return $5 million", which is life-changing to say the least.
asdff 12 hours ago [-]
Resume like that would set you up right for a cybersecurity career
clint 13 hours ago [-]
And yet its had no effect. If anything this group has accelerated their activities, as evinced by this FBI hack.
Jamesbeam 13 hours ago [-]
I will tell you where this gets really embarrassing for the FBI.
Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.
In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.
Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.
All you need to know about Clop is that they got fucked by SH as well just a few days ago.
ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.
Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.
In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?
If you guessed Oracle PeopleSoft, you were right.
Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.
But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.
> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.
So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.
Fookin Big Idiots.
phlipski 7 hours ago [-]
Yes! Now we may finally learn how Johnny Utah's career really ended!!!
jgalt212 13 hours ago [-]
If I use Claude or OpenAI swarm to commit crimes, and the vendor knows I'm up to no good, what's their liability? Do they plan to invoke the phone company defense?
14 hours ago [-]
TZubiri 14 hours ago [-]
Is their name a reference to pokemon? Or to the meme that the FBI/CIA glows through the screen?
bitwize 14 hours ago [-]
You're thinking of "glowie", "shiny" is def a Pokémon thing.
mech422 13 hours ago [-]
also an mmo thing - hunting for collectibles in game
yepyoukno 13 hours ago [-]
“Glowie” is a white supremacist slur for “Jew” or “fed” (they think the Feds are “a bunch of Jews”.)
They say glowie because they see Jews are n*s who are white. They “glow” (they’re not dark.)
It’s crazy hearing main stream mention this slur slang without awareness of its root or meaning.
phainopepla2 13 hours ago [-]
I think you have the etymology wrong, although there was (schizophrenic) racism involved in the coining of the term. The "glow" part doesn't come from the fact that they're white (or not dark), it comes from Terry Davis saying that "CIA n*'s glow in the dark" (i.e. are obviously spotted and can't hide their identities).
yepyoukno 12 hours ago [-]
You think Terry David coined this term?
There may be more than one path of truth here.
Like “ helter skelter”.
To white supremacists that means “to rape and murder the innocent and lawful and dance in the streets in victory, there is nothing you can do about it!” And I’m sure a dozen of you will argue that it’s a beatnik prose for a fun time.
The world! Including the parts we ignore or pretend to do without.
pvab3 10 hours ago [-]
No it's not, it was just a nonsensical rant from Terry Davis that caught on. It was never very funny and felt like a forced meme at the time
DaSHacka 13 hours ago [-]
It would've taken you a 30-second google search to check yourself before posting this, where you would've seen this is wildly incorrect.
The term itself has nothing to do with jews, but its a fun self-report you think jews are disproportionately federal agents, the group constantly mired in human rights controversies towards minorities and abnormal connections to pedophiliac islands as of late.
Horseshoe theory, I suppose :)
yepyoukno 12 hours ago [-]
> Glowie by TinklesTheGoat December 24, 2019
Some of us need slang dictionaries from “the street” and some of us have been in the presence of white hate telling this low down.
Don’t karma neg me because I tell you something you don’t want to hear. This stuff is a reality.
DaSHacka 9 hours ago [-]
That does not change the fact that it still has nothing to do with jews.
You are simply incorrect, there's no two ways about it.
I referred to the article on urban dictionary as it's the 'only' real source for slang definitions on the internet. Obviously I knew about the term from before then, it originated from Terry Davis who's not exactly unknown on the internet.
If you'd prefer to see it used in the wild, feel free to browse the unfiltered sewage pipe that is 4chan or xitter and you'll see that yet again, the specific term "glowies" has nothing to do with jews. Maybe some people that use the term are antisemetic, but that does not change its definition.
Also, I wasn't the one that downvoted your comment.
jrflowers 11 hours ago [-]
From the link you posted:
> Glower
Share definition
Flag
> Glower is a slang for a Federal Agent, usually used for one in disguise over the internet.
> The slang comes from a racist rant by the coder of TempleOS Terry A. Davis.
"The CIA n*gg*rs glow in the dark, you can see them when you are driving. You just gotta run 'em over with your car."
Seems possible to me that somebody might use the terms interchangeably but I’m no expert on slurs. Lol at “horseshoe theory is when somebody has heard a slur”
clint 14 hours ago [-]
They've been on an streak for over 6 years now, check out their wikipedia page.
13 hours ago [-]
applfanboysbgon 14 hours ago [-]
Wow, that is bold. I wonder if they'll get away with it because incompetent leadership has decimated the US's capabilities? This certainly doesn't bode well for the US's odds against its nation-state rivals.
Ancapistani 13 hours ago [-]
Meh - I'll believe it when I see the actual data.
Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.
Ithildin 11 hours ago [-]
Someone come get me if they release the Epstein files. Otherwise... that's nice, dear.
nozzlegear 11 hours ago [-]
We traced the call – it's coming from inside the FBI!
BLKNSLVR 10 hours ago [-]
Kash clicked on the link for free alcohol.
ras1k 6 hours ago [-]
wow
malloci 12 hours ago [-]
"they hacked the Gibson man"
fnoef 10 hours ago [-]
Rabbit? Flu shot? Someone talk to me!
wileydragonfly 6 hours ago [-]
Clown World.
phendrenad2 13 hours ago [-]
Imagine the FBI's relief when the hackers only got a list of their employees, not the UFO files.
DaSHacka 13 hours ago [-]
More like a different set of files...
dbg31415 3 hours ago [-]
Great, can we use the data to do background checks now?
I have a suspicion that we'll find a lot of alt-right Trump-donors on the list.
Or at least can we find and shame the chicken-fuckers? Ha!
But seriously... the way things are going, I'm glad some motivated third party is backing this stuff up for the future. We're going to need all the data we can get for the next round of Nuremberg trials.
I understand that it's their bosses telling them what to do... but I'd be fully in support of a ban of anyone who had anything to do with the FBI under Trump from ever holding any sort of law-enforcement position ever again. As far as I'm concerned... they're all guilty of conspiracy to commit pedophilia, conspiracy to solicit bribery, likely hundreds of other crimes by hiding the truth from the American people. Wouldn't surprise me at all to learn they've been using all this time to destroy evidence. And I really don't care if they are "just following orders" -- anyone left in the building is in on it at this point.
10 hours ago [-]
ZeroDayDreamer 46 minutes ago [-]
[flagged]
htrp 15 hours ago [-]
TLDR. A Peoplesoft (Oracle HR) instance was compromised which allowed movement into GovCloud (AWS)
ok123456 14 hours ago [-]
PeopleSoft 0-day.
Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.
Tangurena2 12 hours ago [-]
The FBI had some very smart people. The current regime/administration's number 1 priority is to eliminate anyone competent in order to replace them with loyalists. Stuff is only going to get worse.
ok123456 7 hours ago [-]
> The FBI had some very smart people.
They trusted Oracle. I'm not sure I believe you.
0xbadcafebee 14 hours ago [-]
The attackers exfil'd 3TB of data, which obviously included PII, from AWS servers. They should've had DLP, active monitoring, countermeasures, using a security vendor (you can set this up for AWS services using CloudTrail, CloudWatch Logs, etc). You're supposed to have that for sensitive government or military work, and it should have (at least) caught that much traffic going to a rando external IP, blocked and flagged.
If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).
lenerdenator 14 hours ago [-]
It doesn't do nothing. It does make things somewhat harder to attack.
There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.
jimbob45 13 hours ago [-]
I’m skeptical that multiple terabytes of data were exfiltrated quietly. I’m struggling to see this as anything other than a bluff.
chrismarlow9 13 hours ago [-]
If it was compressed prior to exfiltration it would be much smaller than the original data. I would expect this is mostly human readable text and a fairly high compression ratio. Agree it would still be large but 2 TB at 7:1 ratio drops to 285 GB. I don't know how much these servers are doing with data but I'd suspect sneaking out 10 GB/day over a month or 20GB/day over 2 weeks isn't going to trip up much. The CPU hog for the original compression might, but if you batch out the process in chunks (like a good data engineer), you probably wont trip many thresholds outside of expected use. Just a theory on how I might sneak that much data out of somewhere that has eyes on it, I don't know many details except what's in the article.
pixl97 12 hours ago [-]
Na, they just linked it up to the VLAN that carries the netflix traffic and no one noticed because it wasn't even a drop.
Now, I made that totally up, but this is how things go. They'll watch one area like a hawk only to leave another glaringly wide door open.
What is even worse is there are a lot of horrifically inefficient apps out there calling way too much data for no reason and suddenly a hack of an entire database gets lost as noise in relation to all the traffic on the servers and networks.
Art9681 7 hours ago [-]
Anomaly detection is getting better. A small delta can still trigger it. Wether a human reviewed it is another story. But the post mortem will reveal all the signs in hindsight.
iAMkenough 13 hours ago [-]
I'm less skeptical after seeing it happen to IDScan and terrabytes of government-issued IDs being exfiltrated quietly.
Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.
China hacked 22.1 million records of US government employees:
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
Its not expensive because its niche, its expensive because its hard. Its a lot easier to learn a bit of html and javascript and knock up some web projects then it is to become proficient at all the things necessary to be good at security. Generally it also takes consulting with maths experts who have spent their life studying cryptography and as such command a decent wage.
So physical security is just as important. I really like how ARINC serial bus on planes work. One can have a reader that is physically incapable of sending anything to the writer. This allows to connect entertainment systems to flight data sensors safely.
In Airbus this system is replaced with Ethernet switches that in software ensures separation of traffic. The software was proven mathematically. But I am skeptical that it is absolutely bulletproof as a client under malicious control can influence Ethernet signaling and may exploit hardware bugs.
Nobody said sel4 was a panacea.
My claim is that doing this kind of computer security is possible. It's just expensive and inconvenient. We know how to make computers a lot more secure than they are today. The limiting factor isn't humanity's knowledge. The limit is that barely anyone wants to pay the bill.
That means designing the ecosystem pressures is crucial: things more meaningful than just pure capitalist private-profit logic must by enforced by thoughtful regulation or otherwise the ecosystem converges for private-profit of a small sliver of individuals (billionaires) to the detriment of all other ecosystem members (99% of the world population).
This holds for anything broader than pure private gain, may it be security, social fairness or ecological topics. Sole monetary-value optimization for private gain must be properly constrained or else it results in pure predatory capitalism that implodes society from within, may it be through leaky security, poisoned environments or social unrest.
Do you even have any experience with how most companies work? SMEs barely have the cashflow to cover their daily expenses, let alone suddenly pay thousands for regular professional security audits and overhauls of their code. This is why security is an afterthought.
Security is always a cost center and rarely a profit center. That's the only thing that needs to be said.
I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too.
Not all hacks are caused by pure negligence, laziness or stupidity, but most of them are. Even a little effort goes a long way.
My grandfather spent a couple decades as a builder, ran a construction crew. Whatever the project was, he wanted to know everyone he hired personally was going to reinforce and report to him anything they had the slightest doubt about. "Always hammer in an extra nail" was basically his motto.
What we do ain't that different. The difference is that when an apartment building collapses, it's bigger news than when a govenrment database does.
We are headed for scary waters.
Only just when we started to have a resemblance of security we got agile and startups breaking things (making rubbish software to capture a few bucks faster) and now vibe coding and llm assisted hacking.
The point of my, arguably rant, is that there is nothing new under the sun.
After the DOGE debacle, I suspect that all the previously really secure stuff, is now out there, too. In fact, I wouldn’t be surprised if some of these leaks, came from that.
FBI employee data is very bad.
The only solution I can come up with is some form of certification or paid code review from a third party. I know that at least for Windows prior to 7 Microsoft actually allowed some parties to come in and check the code/checksum on an air-gaped computer. We somehow moved to "trust more" in the last decade, and now we can trust nobody
This might be part of it...
> Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things
But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit.
LLMs have been a huge force multiplier. Here.
If that data got out (which probably happened within hours of the data being dumped to insecure storage), then it’s probably already been analyzed and used to leverage access.
> Of course there is. (...continues to talk about software security)
A bit over-optimistic when looking at hardware vulneraribilties like Spectre/Meltdown.
Secure software isn't worth much when it runs on vulnerable hardware (at least Spectre/Meltdown could be worked around in software though, but at a cost.
You know that's their actual job right? That and fixing the problem. Which they did in both software and hardware.
Looks to me like the security researchers have been doing their jobs.
A perfect system is either extremely limited in scope or flawed in it's assumptions.
It's often possible. But not all systems are vulnerable to undervoltage attacks. For example, I don't think the iphone secure enclave is vulnerable to this.
And good security uses "defence in depth". Multiple layers which each individually need to be compromised to break the whole thing. To hack chrome, you need a vulnerability in the renderer or VM. Then you also need a sandbox escape, and a way to use that to attack the browser's parent process. This is much harder to do.
So what? Security systems don't need to be 100% provably secure to add value. It's a mistake to let perfect be the enemy of good.
Then there's decapping / depotting, a world of different types of microscopy - some destructive some not, directed EM attacks, etc.
> And good security uses "defence in depth"
And automation has enabled "offense in depth"
> To hack chrome, you need a vulnerability in the renderer or VM. Then you also need a sandbox escape, and a way to use that to attack the browser's parent process.
Or you just phish the user into installing your exploit. There's always another layer. Always a potential exploit. Because ultimately the same properties of the universe which permit computation within a closed system allow for predictably observing and influencing it. The expense and hassle of doing so are widely variable, of course.
So what? Most attackers aren't nation state adversaries. They're some kid in Wyoming messing around with deepseek. We live in a world where most exploits happen because someone was running an unpatched, 8 year old copy of wordpress. Because they put their insecure mongodb instance on the open internet. Because they used admin / "12345" as the username and password. We don't need to make hacks physically impossible for a nation state adversary. Just really, really difficult and expensive to pull off.
Honestly. If people talked about physical security like they talk about computer security, you'd have people telling you that, because walls can be physically smashed through, they don't bother locking the front door to their house.
The saying is that locks only keep honest people honest. Plenty of evidence of that: https://www.youtube.com/@lockpickinglawyer
That youtube channel is great. But it isn't evidence of anything. Except maybe for how terrible master locks are.
It’s not hard to get into a garage but it’s really easy to steal a lawnmower if you leave the door open all night. I wouldn’t call that thief honest but even the minor deterrent of closing the garage was enough to make you not the target.
Decades ago, I worked in a bank in an old building. The door had a card reader for access. You boop your card and the door opened. People would hold the door open for each other all the time out of politeness, even when they didn't know each other. Security told us not to do that, but it's hard to convince people to stop being polite.
I had a laptop stolen from my desk in a place like that once. (Not a bank - but similar door-card reader system). This guy came in in the middle of the day, wearing overalls. He confidently walked through the door after someone, like he belonged there. He walked up to my desk, swiped my laptop and just strolled out.
At the bank, they've replaced the door with mechanical gates and a security guard. The gates - physically - only let one person to walk through at a time. You can't hold a gate open any more. And the security guards stop anyone who tries.
Is it 100% foolproof? No. But it's way more secure. It would have stopped that laptop thief.
There's this pernicious, defeatist attitude that if you can't make a system 100% secure, so you shouldn't try. That's misguided. Most systems can be made orders of magnitude more secure than they are today. It just takes a bit of care and work.
Look at our immune system. Incredibly complex and clever, and able to keep us alive in the face of all sorts of pathogens. It exists because of this cat and mouse game, played over millions of years.
There's people in the highlands of PNG who regularly eat each other. Of course, many are thought to have died due to prion diseases. But now these tribespeople seem to have become largely immune to prion disease. Incredible.
Your comment on PNG, seems to ignore Kuru
From an evolutionary PoV a perfect defence is overkill - with two separate defences against prion diseases in that region it's only the rare variation that causes any issue - and that rarely occurs before a new generation is birthed - ie. 'perfect' from the PoV of the selfish genes.
The resistance came about via two separate "evolutionary upgrade"(s).
It appears to me that, like BSE (aka Mad Cow disease) it really depends on exposure.
There's a twofer that skittled the Fore, a ~1900 mutation that created a new form of infectious prion proteins, and a local variation that saw less uptake in the Fore of a resistant prion protein (alongside other resistant prion protein).
So, over the highlands region, there was general resistance thanks to several evolved variations, in one specific locale (the Fore) there was insufficient resistance to the mutation that hit a peak of 200 deaths / annum for about three years(?) in the late 50s.
I can't speak to "the literature", I just had a lot of conversations with the people on the ground (Mike Alpers, etc), on again / off again, since the mid 1960s.
Paper about Kuru and mutations referenced in comment here: https://news.ycombinator.com/item?id=49719102
That's not really enough to say "We have found the gene" - it's just really good data to warrant further investigation
Also, the incubation period of the disease is up to 50 odd years, have there been follow up studies?
Who said anything about a perfect defence? And since when was that the bar?
Just, you're doing it on your own.
By the way, there are countless ways to account for humans. There are entire branches of engineering devoted to this. If you don't want someone to leave the bank with a pen customers use for signing checks, you just chain it to the desk. If you don't want the installer to forget to put the pen-chain in, make a photo of the chain part of the checklist required to get paid. If you want to... etc.
The idea is that you determine an acceptable level of risk, then secure to that level. Maybe the acceptable level of risk chosen by companies is wrong. Maybe we need to increase that risk exposure via heavier fines and regulations. Maybe the cost of reducing that risk is too high already. Maybe we need to fund that. Maybe it's too confusing and we need to research better standard practices. I dunno. But this is not some unsolvable problem.
There really isn't
Ask anyone seriously involved in security - whether computer science related, or in general.
A thought experiment: Think about the most important secrets a country can have - now think how they are still discovered by competing countries, enemies, etc.
As long as there are humans in the loop there is a known weakness.
Eh. If only it was that simple. I mean, yes, money is always a factor, but not nearly as big of a factor as 'my convenience outweighs pretty much everything ( until it causes sufficient amount of havoc.. and even then.. )'. You can see it in just about everything. It is not just the money. It is the convenience that drives most of the unsecure behavior.
"So what?" you say. "Making a heavier-than-air metal tube take off and land millions of times per year without a catastrophe is also hard, and we no longer expect most or even many of those tubes to blow up or fall down."
Mother nature is not spending $$$ using AI and HI adversarially trying to find the exact combination of atoms that will cause your device to fail.
Modern CPUs support IOMMU. If you set that up, your NIC can only DMA to virtual addresses, managed by the operating system.
> It doesn't help with timing attacks. It doesn't cover your network stack
It does help with all this stuff, because your network stack and whatever else can be split off into isolated processes which talk over capabilities. Compromises in those processes are of course terrible. But they don't automatically allow kernel level takeover of the whole machine like on windows / linux.
Oftentimes the weakest link is the human operator who has direct access to those systems, not the computer system itself. Good old social engineering, in other words.
Even though one could use LLMs for social engineering, come to think of it, like re-enacting the movie "Her" involving a modern AI as Scarlett Johansson and an engineer working for the water utility as the romantic target.
If that is the case, the computer security team have done their jobs.
I wish that were true more often.
I would like to see restricted access to only us workers for us citizens data though.
Transferring us customer data outside the country should be illegal
Depends on the "we". "We" have the capability to make secure computers like how "we" have the capability to make EUV lithography machines. There exists a relatively small number of people and organizations in the world who can do so. Microsoft does not have that capability. Google does not have that capability. Linux does not have that capability. Amazon does not have that capability. Apple does not have that capability. Cisco does not have that capability. IBM does not have that capability. etc. All of those organizations have tried for literal decades, thumped their chests about how they have awesome security year after year, and yet have totally and utterly failed despite their best efforts.
Acquiring the capability to do so is difficult and challenging and requires years to invent if you start right this very second and know what you need to do, which these organizations emphatically do not. We need security at scale and fast. The only way forward is to scale up working solutions rather than letting the bozos who put us in this spot fail at scale with yet another promise that this time for sure they will solve the problem they have repeatedly failed at for decades.
> Microsoft does not have that capability. Google does not have that capability. Linux does not have that capability. Amazon does not have that capability. Apple does not have that capability. Cisco does not have that capability. IBM does not have that capability. etc
This is all by choice. They could easily have that capsbility, very unlike EUV.
You really think that if they could have they would not have, even just for bragging rights? Or are we going with that it is some kind of task demanding enormous expenditure even though the organizations that have made secure systems are infinitesimally small in comparison?
Microsoft has spent orders of magnitude more money and time than the organizations that have succeeded and the result of their efforts is Windows. That says everything you need to know about their capabilitys.
Multiple literal trillion dollars organizations have spent literal decades failing at it. You are really underselling the capability gap.
If windows was reimplemented as a capability based microkernel like sel4, it would be far more secure. Run drivers in their own isolated processes. Do interprocess communication between them via capabilities and shared memory. Remove all ambient authority from programs. All the programs a user launches stop automatically inheriting all of that user's permissions.
There's no secret knowledge required to do this. The SeL4 team has written extensive documentation of how they did it. They also opensourced their kernel implementation, with correctness proofs for the whole thing.
The reason windows hasn't done it is the cost. You'd have to rewrite half of the NT kernel and refactor everything else. All existing windows drivers would need to be rewritten. If you forced windows userland use a capability based system, you'd essentially be inventing a new way to write windows programs. You'd need to document that, and write a compatibility layer for legacy programs. And solve some UX problems. It would be terribly inconvenient for everyone. Oh, and some programs would run slower as a result.
They could do it if they wanted to. But microsoft just doesn't care about security as much as they care about performance and compatibility. Linux is the same.
The big irony is that security would be a lot cheaper for microsoft if they designed the NT kernel to be more like sel4. Microsoft has to spend millions on security every year because any tiny bug in the kernel (including in drivers) might result in the whole OS being compromised. In a microkernel, a buggy driver is nowhere near as dangerous.
macOS does the same but with more developer adoption. Apps don't have the ambient capabilities of the user and must advertise what they need via entitlements embedded in the binaries, or get permission just in time.
Which is all very good, and modern platforms are much more secure than they once were. Yet "capabilities" as a silver bullet are academic overpromises. This article I wrote is more about language/runtime level capabilities but OS capabilities are not much better.
https://blog.plan99.net/why-not-capability-languages-a8e6cbd...
SeL4 isn't secure because of One Weird Trick that others would adopt if only if they could be made to care enough, it's "secure" because it hardly does anything, which is why nobody uses it and why it has no impact on real world computer security.
The hard part of desktop security is not changing the operating system. The hard part is getting app developers to care. Most security features added to operating systems are ignored by developers, which is why Apple forces you to adopt some of them as the price of admission to the app store. If they didn't nobody would use them, as can be seen for apps distributed outside of the app store. The reason is security is a market for lemons. Nobody can see the result of security investments so it's irrational to invest. SeL4 has no solution.
I am more concerned about my cloud data being published in a leak.
But then on the other hand, if I use mainstream cloud services, a broad leak with no specific interest in my data would need to be exabytes in size and would take years to transfer even with a 100 Gbps connection.
The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.
It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
The problem is that most companies don't care if they get hacked so long as the hackers are just taking data and not interfering in their ability to bill customers and make money.
They face zero meaningful consequences if their data gets leaked. The money they save by not taking security and employee/customer privacy seriously will more than pay for the year of "identity protection" they'd have to pay for (assuming the hack gets found out) anyway.
They actually care about ransomware, but most of the time that's also something they can comfortably buy their way out of. We've seen a lot of companies pay off ransomware gangs rather than invest in the kinds of robust backups that would make recovery possible/less painful than rewarding the hackers.
What's needed for change is regulation with actual teeth that makes not protecting their data either meaningfully expensive or criminal resulting in executives spending time behind bars for their negligence. Without that, things are only going to get worse, especially as companies experiment with using AI and increase dependence on third parties and cloud providers who themselves become rich targets.
That probably still won't help the FBI though. Our government isn't exactly big on holding themselves accountable or even prioritizing competency right now.
Hasn't been since before Vietnam.
Adding AI into this really is just changing it to how much money your adversary is willing to spend to break in. The moment one crack in the armor shows up countless agents with unending patience can start embedding themselves everywhere in timeframes way faster than human actions. You could quickly find out all the special sauce for your company has been copied who knows where.
Working with banks when the Glasswing/Mythos first came out and they were given access to it has given me direct access to their infosec departments that are panicked. They've been sitting on piles of bugs for years that were low risk enough, and they have seen in their own tests how fast they can be probed.
Worse those infosec systems that have identified the risks in their software that aren't yet fixed are nuclear waste vats just waiting to get spilled to the wide world.
If there's too much security in the way, it seems to me that work becomes impossible.
If not a person you need more redundancies built in. Bigger tanks, multiple backup systems. When items start failing you need them to be shutoff in a timely manner. Water pumps at these facilities are in the 50-100k range. When it starts failing you want to know.
Think of it like driving a car and it starts making funny noises. The longer you wait to fix it the more it costs.
You can be very defensive and design any remote sensing controller to act as two systems - one management cpu only does data routing (no other connection than administrative tasks), sensor cpu works only with sensors. As bonus you can have management cpu act as active firewall.
Main problem it is necessary to have in house expertise (hw, fw and process knowing) which in making company lean are optimized first and outsourcing custom solutions suddenly too expensive.
Like something that would work but not not scale would be one computer writing data to an updating qr code and another reading it. Surely something like that can be made (and probably already exists?) on the cable level?
But more to the point, a modern water network has a huge number of nodes. If you can't centrally aggregate and control in a control room the costs and complexity explode, probably also the error rate.
Even if you demand a full air gap, the solution here can't be to get rid of computers or networks. They are much, much too valuable. Luckily industrial control is full of very low hanging fruits.
Of course, by making it remotely operable, that one guy could be replaced with a guy in Russia who's job is to poison everyone.
https://en.wikipedia.org/wiki/Sneakernet
Software security has just been a fun time of ignoring the exponentially growing number of bears for the last few decades so you can continue to use systems unfit for the threat landscape because they are cheap.
Admiral Adama says otherwise.
Even just consider banks and e-commerce. They are hugely lucrative and making them even a tiny bit less accessible directly impacts their revenue. As an example, Amazon seeing that latency has a measurable effect on purchase behavior.
Maybe the military (fictional or otherwise) can go back to the ARPANET but most economic activity created by the internet cannot afford to disconnect
Even putting that aside, economic growth (like the growth e-commerce has provided) is generally positive for a population
In the real (fake?) world the toasters would shoot smart dust all over your crap that would assemble back on your circuits creating radios between all the different components. They were fighting an adversary that was far more advanced than them.
Let's say my cryptosig gets hacked by SkyNet, or my agent goes rogue. Either way someone files a million loan applications in my name! Normally my agent uses that to buy $200/month of Funko pops, or negotiate my recent purchase of a used car.
I get the notification from my cryptosig company. I freak out, report as fraud, and wait.
They comp the $3000 advance on my loan the scammer managed to withdraw, and I get off scott free, changing nothing about my behaviour.
If cryptosigs meant I am liable for someone stealing my identity like in 2026, I wouldn't use them. I'd negotiate everything myself with document scans, or god-forbid go in person since only I can legally bind myself under my own name.
That sucks! Nobody gets a commission when I make deals with a government ID. Startups don't even allow it as cryptosigs are more secure than scanned passports.
I don't want to do that either. When I was 18, I got swindled by a human salesperson into a $1400/month 27% APR muscle car when human soldiers got signing bonuses. It was face-to-face and they were smarter.
When I let AI own the budget, it leased me a mostly depreciated BMW from another AI for $500/month. The models are mostly the same now and always settle close to the Nash equilibrium.
I was so grateful that I selected a 40% tip for the AI. I wouldn't want to make things awkward with the companion I spend 8 hours a day talking to, after all. To avoid a conflict of interest she only accepts voluntary fees.
Nobody I know in security hardening or vulnerability research has ever believed that anything is perfectly secure. It's not black and white. There are degrees to this.
I find this fatalistic thinking that every database should be assumed compromised to be subtly harmful. Everyone I know who thought that way waltzed right into lax security practices. "Good enough, what's the point, if anyone wants it bad enough they're going to get it anyway"
There's a reason that many military and intelligence organizations worldwide physically cut / remove wifi and bluetooth chips from boards. The same is done when audio is identifiable, and specific hardware (only) greenlit.
I've lost hours of my life to calls explaining exactly this, only to have people ignore it, only to further have folks come back, tail between their legs. The worst part is learning this in industry, as I did. There's a reason for in-industry advisors. I wish that I had learned this the easy way.
There is such thing but almost never a priority. In the corp I work leadership talks a lot about security but when comes to the incentives the road-map takes priority over the security. If you deliver fast you'll be promoted, if you're a paying attention to the security no-one will appreciate it and the manager will hate you for delaying delivery. Many managers I interact with see new features as the main value development teams should provide and security, reliability and other QoS as a waste to be minimised.
Another issue is that even if security will be a priority and managers will be on board (good lock changing the culture tough) we probably cannot build secure systems while keeping the insane level of complexity we have nowadays. Switching to simpler but secure system will require sacrifices in features/convenience.
Most security professionals I've met in my career border on being non-technical, there are of course security researchers and a whole arcane and academic field that exists well beneath the surface but it is so far removed from the every-day.
Depends how the house was build. Here in europe there are plenty of old houses build in areas that experienced periodic flooding - there the advice is simply, do not store anything critical in the basement.
For every engineer that takes security seriously, there are 99 engineers that don’t. It’s an uphill battle.
Source: 25 years of experience.
Remove the complexity (all the way down to the hardware quirks), and security will be doable again.
Claude hasn’t been around for a generation yet.
It’s a good thing that people are scared to hand write memory-unsafe languages. 50 years of exploitation has finally sunk in…
Does this answer your question?
/s
People flaunting their credentials in multiple languages, then sweating bullets and apologizing profusely when they see
You can either code or you can't; the language is merely a vehicle.It might even help in figuring out whether Haskell would be a good fit. Something I couldn't do, as I do not know the language. Then again, it's not a question that really gets asked much in a corporate setting. Most things are just solved in a few popular languages, whether that makes the most sense or not.
I agree. The people who depend on chatbots to write their code for them won't have either of those skills though. They don't know (or are in the process of forgetting) how to code, and they're missing out on the opportunity to really learn the language by turning off their brain and letting a bot spoon-feed them code.
An LLM would only get in your way if you actually wanted to learn Haskell.
It’s abstractions all the way down and most people aren’t going to have an intimate understanding of every layer, and it’s not economically worth it for the vast majority to even try
LLMs just give you results (of highly variable quality) and if you lack a solid understanding of the language being used that result gets blindly accepted as valid (especially if it manages to 'do the thing' when you test it). Learning how to type a prompt is not the same as learning how to code or learning a programing language.
Huh? I wish…
Actually, if by “learning to code” you mean “writing good usable code”, my experience is that many people struggle to code. Especially when you consider planning a (human-level) complex project.
Maybe you don’t know those people. I work with them every day.
Followed up with a lot of “we just make the tool, we can’t be held responsible for how it’s used”.
https://www.yahoo.com/news/politics/articles/flock-ceo-asks-...
If you have ${anything}, assume it is semi-public, meaning if someone was interested enough in accessing it, they could do it. "Fort Knox" isn't the right analogy for physical security; the primary question isn't whether something can be breach, but how much would it cost the attacker to do it.
A system where expected costs to attackers >> expected profit they could reasonably make from succeeding, is considered secure in typical case (exception: special cases where attackers may be driven by non-material reasons - think terrorism, politics).
Computer security is largely still stuck in "Fort Knox" thinking.
> For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
That ship has sailed. "Modern problems require modern solutions", that infrastructure will be in some way accessible over network is a necessity at this point, the question should be, how to keep it difficult for normal attackers to mess with it, without preventing the system from fulfilling its intended function.
> The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
The correct analogy for computer security is a house. Scale security proportionally to actual importance of what's inside, and accept that nonzero amount of houses will be broken into; that's just insurance writeoff. Leave the 20-meter walls with towers and armed guards and helicopter gunships on fast-dial for the critical junctions, while keeping in mind that this is not perfect either - it won't stop an open nation state attack, at best maybe slow it down.
For critical infrastructure, I'd honestly focus on redundancy, resiliency, limiting blast radius and procedures to recover quickly, over trying to turn every physical or virtual substation into unpenetrable fortress.
(Another thing physical security gets right, that cyber side seems to ignore: security does not and cannot exist in isolation; criminal justice system and law enforcement are part of it, and at extreme end, threat of military intervention against a state that aids and abets the perpetrators. The possibility of sending "men with guns" after perpetrators is core part of securing a system or space, it's literally what they are for and why we fund it with taxes.)
That doesn't mean that all of your neighbors know your medical history, but you have to assume that someone who wants to know those details about you will know them.
I have lost faith in people protecting any significant database from hackers.
The problem is, most water, sewage and even many electrical infrastructure isn't manned any more. You need some form of remote surveillance and control, and practically, you will need to go with some sort of VPN based network.
Of course they do. Not everyone has the level of technical expertise the average HN user does. Turning around to them and saying “duh of course all your personal data leaked” doesn’t feel like a helpful response. Especially when they don’t even have control over where their data lives anyway.
A linux box, layered in encryption and not plugged into any network = damb secure.
A network-connected linux box with a hardened OS, firewalled, acting only as a file server, given regular updates and 24/7 monitoring = less likely to be "hacked" than struck by lightning.
A hard drive with its power supply physically switched off = 100% secure from external attack.
Not a joke. The keys for editing the world's most important files, the root zone, are kept on no-power drives in air-gapped safes. They have yet to be hacked.
CHC is the largest claims clearinghouse in the US; about 100m people's insurance claims go through there each year.
The hackers asked for a ransom ($35m iirc) to delete the data, which United Healthcare (who owns them, because of course they do) paid. But it seems that the collective negotiating on behalf of the actual hackers rug pulled, so the actual hackers didn't get paid.
This is more than simply medical records. It includes who is active duty military and their family. If you can map where soldiers are, you know roughly the size of different military bases. If you know which types of capabilities are operated out of which bases, you can get a pretty good look of how the US is allocating personnel.
It was crazy working on recovery from this at the time. It should have been front page news, but wasn't.
Not much, Revolut just got tricked by hackers into giving out customer information: https://news.ycombinator.com/item?id=49682087
I guess your parking history around town could be valuable if someone is targeting you.
The card number?
This is also partially that people don't put critical bills on their credit card typically. And even if your credit card does get maxed out, you typically would have a second credit card handy. But those credit card payments have to come out of your bank account and so you're risking that you intend to pay your credit card you said Set whatever it is to send the money in but there's no money in your account And so it doesn't get paid and now you have late fees on other accounts
If your debit card is going to a different bank than what you normally pay all your bills out of, this is not a worry. That is not how most people I know handle their banking though, which is why it is a real problem to worry about.
This is probably atypical, as the average people I know put their critical bills on their main credit card that they use everywhere:
I put my autopay bills on a credit card that sits in my safe. The only reason it would see a fraudulent charge is if one of the few companies that has the card information, is hacked. And that actually happened once.
Perhaps not everyone has a good credit card and/or bank though, idk.
One, how much money is in your pocket so you can eat?
ok, you'll use your second ca.... oh, it has to be cancelled now too.
Ok, lets wait a few days for another card, and lets go use it the first time, what hacked already, I guess I need to wait a few more days.
>As long as you're not using a debit card, this is not a big deal.
So screw 60% of all transactions done on a card? This doesn't seem workable.
The chance is incredibly small that your second card just happens to get hacked at the same time as your first card.
I have 6 (I think) credit cards, and mainly use 3 of them.
It's a good practice to keep an emergency debit card at home. And/or a gift card with a couple hundred bucks on it. That's for digital expenses.
And you should also have a bit of emergency cash.
I have a text alert setup for transactions, so I presume I’d be able to successfully challenge any fraudulent ones pretty quickly.
When your lifetime of credit card transactions leaks, that could be financially painful, embarrassing, etc. (can be discriminated against, including with pricing)
I do dislike creating a log of where I park on some random company’s server. Nice that ALPRs/govt.-funded corp spycams/Ring/etc. make sure the quarter method is minimally marginally effective at protecting privacy.
I had to fight a bank for months over a clearly fraudulent charge. Sometimes it's easy; other times it isn't.
Can’t speak to fraudulent bank charges, by the way, only on the credit card side.
Consumers aren't gonna notice the difference if the site gets hacked and that JS is swapped out for a malicious set.
"I'm only talking about long-term storage" is itself a goalpost move!
For example, you have to trust the QR code takes you to the real app: https://www.bbc.com/news/articles/cwyjqg578e1o
I'm not just talking about bids. The idea presets itself prolifically. We all work in tech, I'm sure you see it on a daily basis. Rush Rush, no time to think, just do it. 6mo later, "there's so much shit! How could we have ever prevented this?" Rinse, lather, repeat
It’s entirely possible to keep large databases secure. It takes competence and commitment though, something federal police don’t have for IT.
If somebody wants data about me, they can write the query, I'll approve it, and it can hit a server designated by me and run by somebody I know personally.
It's not just a privacy/security concern. People who get too close to large piles of sensitive data tend to start behaving poorly in other ways too--they might be compelled to misrepresent it. Apparently the forces of corruption are too great. Maybe the way to avoid exposing each other to such hazards is to just maintain smaller piles of data, closer to the people that the data is about.
I think privacy will remain, perhaps even improve, because people are much less inclined to snoop when it cannot be done covertly. No secrecy means no covert activity.
Information is everywhere and with the increasing ability to analyse it, not only does it enable access to explicit information, but the ability to infer from increasing volumes of data that will make it hard to hide anything.
Spectre reads protected memory by tiny vriarions in timing. You can now measure the pulse of people from film. You can recover audio from a room by analysing frames of a video recording of a chip packet taken with mobile phone camera. Even as far back as ww2 intelligence on the success of attacks could be measured by the price of items impacted by different types of infrastructure damage.
This kind of data residue is everywhere, collecting only what is publicly available can probably tell you more than you could hope to know about anything that happens. The only thing preventing it is the ability to consider it all together. Those walls are swiftly crumbling.
If the users know their admin, then each server has no more than few dozen other users' worth of data on it. The juice just isn't worth the squeeze to target them one at a time. Ain't nobody has the resources for that kind of attack.
Also, it's a lot harder to phish somebody who is on a first name basis with 100% of their users. It's not enough to merely have a plausible backstory, you have to impersonate one of their friends. That's incredibly difficult.
The only thing left is to hack through whatever protocol indexes these servers and multiplexes queries across them, but now you're presenting a much smaller and easier to defend attack surface, one which can be defended in aggregate (e.g. supply chain scrutiny) rather than singly.
[0] Everyone gets hacked, but not everyone has all of their most secure data exfiltrated.
The HuggingFace incident was audited by independent third party analysts. To "orchestrate" that and keep it a secret is like faking the moon landing. To many people involved. It's not feasible.
OpenAI was founded to develop safe AI. Then Anthropic split off because OpenAI was not safety focused enough. These companies have been railing about AI safety long before they had these big boy valuations. Many people at OpenAI/Anthropic explicitly joined to help make AI safe. This is not some top-down company value.
Also, I seriously doubt that "making panic" is actually good for the stock price. Usually any companies natural reflex is to cover up safety risks. That's not to say that these companies are angles. Of course they're pulling some shit but that doesn't mean that everything out of their mouths must be lie.
Yes, HuggingFace was audited by a third-party. But said third-party wrote that they had to use unreliable AI in their conclusions (page 26) because they had six days to analyse 1300 (page 70) chains of thought and 70000 messages.
> OpenAI was founded to develop safe AI.
If that were the case, then they would have followed their own report saying not to release GPT-3. Or, if they were following their own founding principles, they wouldn't have stopped releasing models due to (in their own words) the challenging market.
In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.
Though having a person interpretingthe degradation progress and relaying it to the rest of the team could be a usable scene.
That is exactly the canon.
I think you missed the point of "no networking", you have to actually physically sit in front of the computer. There is no remote access.
They should try something like "100 agents at noon on Sep 23 do the chicken dance for 30 min in the middle of the street in DC, then we'll consider not releasing the info and not sell it to the Chinese".
Given the recent revelations about the FBI's predilection for animal activities, "dance" should be probably in quotes there.
https://rentry.co/shtext
>That defacement says, “this site has been seized by ShinyHunters,”
No archive but at least a screenshot: https://cyberinsider.com/wp-content/uploads/2026/09/fbi-site...
>https://news.ycombinator.com/item?id=49807388
The photo they put is a Pokemon so yeah probably their name is from it.
They mention hindering trust because for an extortion gang, they want companies to trust that they won't leak the data in order to make it seem worthwhile to pay.
Perhaps firing expertise and hiring incompetents wasn't a good idea.
And there is no glamour on sense of duty when your main job is to make sure that the Epstein files are not revealed so USA citizens are in the dark about who were the rapists and criminals in the list. An awful job.
https://youtu.be/2_nUztwPiEY
AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.
Bespoke software can be orders of magnitude less complex. There are many reasons companies choose to use vendor solutions, but for large organizations it’s usually not “we literally can’t hire enough engineers to build it.”
There are so many counter examples.
Not in government. For payroll/HR, we're talking about hundreds of pages of legislative mandates, union bargaining rules, Title 5 statutory compliance, and FISMA/NIST regs. Just customizing something like PeopleSoft to fit is a large task in itself, let alone trying to implement bespoke software using an engineering pool that isn't even large enough to modernize the software it currently owns.
Bespoke sounds nice and works well in startups but that's not the context we're discussing. Check out Phoenix Pay: https://en.wikipedia.org/wiki/Phoenix_pay_system and understand the US is even more complex.
>Just customizing something like PeopleSoft to fit is a large task in itself, let alone trying to implement bespoke software
Customizing large enterprise software is more like writing bespoke software than it is what most people think of when you use the word customization. You end up paying enormous vendor margins on top of the costs for something that is effectively bespoke software.
There is so much bespoke software out there that is at least as complex as government payroll software.
The expertise that told them to buy PeopleSoft years ago, or do you actually believe the FBI home-rolled its own HRMS in the last year?
Are they related to the expertise that was supposed to lead to the immediate, irreparable offlining of Twitter after they were all fired?
It's okay. Larry got another island.
Do they have any positive reputation left, or is it just more negative from the previous negative position?
If anything Oracle will "contribute" a lot to congress people's midterm reelection and in a few months all will be forgotten and Oracle will get more Gov. contracts.
I don't know what percentage of their articles were behind a paywall back then, or the relative change to now. (Well, except for the fact that clearly some of their stuff is public today since we're looking at it.)
If I had my 'druthers, "paywall" and "register-wall" would be little icons on individual submissions. Then people would choose whether to upvote a more-accessible option instead, whether the hard-to-read stuff was still important enough to commenting on, etc.
If it's completely paywalled with no other archived link to post, then that specific HN post gets [dead].
https://www.bbc.co.uk/news/articles/cje3rezd92y3o
The US seems to breed this particular 'set' with remarkable consistency.
The choice is play ball with the USG, or be dead in the water. Once you’re large enough, simply abiding by the laws is insufficient to remain unmolested - you must actively play ball or you’ll find that suddenly a TON of regulations now apply to you that didn’t before.
Do you think Apple or SpaceX like dealing with the NSA/CSS/CIA? Or the CCP for that matter? (Apple has backdoored all of iCloud in China for the CCP to be allowed to operate there.) Coinbase and the IRS is one. All the telcos turn over all call metadata and IP backbone taps to the feds without a warrant. Google Joseph Nacchio to see what happens if they don’t.
They’re the only game in town, and you gotta play by their rules if you want to operate at scale at all. No amount of billions of private money will get Trump and his administration un-pissed-off at you.
It’s not a free market, all large industries entirely serve exclusively at the pleasure of the court. This is why we overpay for broadband in every major market, why we overpay for mobile data nationwide, why retail banking sucks, etc.
There is always a tension between being agile and being safe, doubly so for governments.
It would be hilarious if the slow adoption of digital services by some countries and entities actually turn out to be an advantage.
Anyone with minimal understanding of technology: Oh, PeopleSoft.
I'm sure Czarek (a diminutive form of Cezary = Cesar) is flaunting his victory until this day. Now sit, nooblet.
1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.
https://idlewords.com/talks/haunted_by_data.htm
If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.
Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.
Hopefully there was some foresight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.
Are you saying that Ethan Hunt was involved?
Old but gold stuff from Gene Spafford
That's lot of data for a list of employees.
We as a country need to start treating PII as radioactive - that touching it or keeping it anywhere near your computer network is a company-ending disaster about to happen. The legal standard needs to be strict liability like CSAM or DUI.
Well, that would require such leaks to result in a company ending disaster. Instead they keep chugging as normal and the customers who got their information leaked don't even move off the platform for greener pastures. What a boring dystopia we live in.
So to a certain extent, any prediction which gets people excited and captures their imagination is already off.
1980 called and wanted its terminology back.
This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?
Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.
If a certified red-team of security researches breaches a company's system and discloses appropriately, the law should require the company to pay a security bounty.
The bounty doesn't have to be crippling to the company, but it should be large enough that the security researchers will be paid well and can live on collecting security bounties. We want an entire industry of good guys testing the security of everything.
There can be some regulation to. Like, it's not okay to run a massive DDoS to test systems. We want the red-teams doing constructive things, not just breaking everything. It should be legal for the red-teams to be annoying, but not purposely destructive.
Fun times.
Wondering about pets..
https://youtube.com/shorts/BTNmtMB2Pyw?is=K05pyS9GdrS7O3WR
I didn't really know passive bestiality was a problem, I thought you're a victim then. (Apart from the obvious fact you're then an ... animal.)
Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.
I’m sure there’s some value in that.
https://www.tomshardware.com/tech-industry/artificial-intell...
Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.
The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".
Almost like its run by a bunch of 80 year olds...
Great, what can you even do with this? Can probably get most of this with scraping public data. This isn’t even the first hack either, FBI was hacked in 2016.
I guess it’s more of a show of force. A power move.
Now steal/exfiltrate active undercover FBI agents, their locations, and operation details.
That’s something to talk about.
There are many people that run open weight LLMs. And unsurprisingly, they don't all have a copy of the FBI employee database.
If you mean "using" an open weight LLM in combination with other tools or even potentially frontier models, then that's a lot more likely.
Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.
In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.
Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.
All you need to know about Clop is that they got fucked by SH as well just a few days ago.
ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.
Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.
In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?
If you guessed Oracle PeopleSoft, you were right.
Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.
But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.
https://mesoclever.com/2026/06/11/oracle-wins-396m-hr-contra...
They even mentioned in the above June article:
> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.
So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.
Fookin Big Idiots.
They say glowie because they see Jews are n*s who are white. They “glow” (they’re not dark.)
It’s crazy hearing main stream mention this slur slang without awareness of its root or meaning.
There may be more than one path of truth here.
Like “ helter skelter”.
To white supremacists that means “to rape and murder the innocent and lawful and dance in the streets in victory, there is nothing you can do about it!” And I’m sure a dozen of you will argue that it’s a beatnik prose for a fun time.
The world! Including the parts we ignore or pretend to do without.
https://www.urbandictionary.com/define.php?term=Glowie
The term itself has nothing to do with jews, but its a fun self-report you think jews are disproportionately federal agents, the group constantly mired in human rights controversies towards minorities and abnormal connections to pedophiliac islands as of late.
Horseshoe theory, I suppose :)
Some of us need slang dictionaries from “the street” and some of us have been in the presence of white hate telling this low down.
Don’t karma neg me because I tell you something you don’t want to hear. This stuff is a reality.
You are simply incorrect, there's no two ways about it.
I referred to the article on urban dictionary as it's the 'only' real source for slang definitions on the internet. Obviously I knew about the term from before then, it originated from Terry Davis who's not exactly unknown on the internet.
If you'd prefer to see it used in the wild, feel free to browse the unfiltered sewage pipe that is 4chan or xitter and you'll see that yet again, the specific term "glowies" has nothing to do with jews. Maybe some people that use the term are antisemetic, but that does not change its definition.
Also, I wasn't the one that downvoted your comment.
> Glower Share definition Flag
> Glower is a slang for a Federal Agent, usually used for one in disguise over the internet.
> The slang comes from a racist rant by the coder of TempleOS Terry A. Davis. "The CIA n*gg*rs glow in the dark, you can see them when you are driving. You just gotta run 'em over with your car."
Seems possible to me that somebody might use the terms interchangeably but I’m no expert on slurs. Lol at “horseshoe theory is when somebody has heard a slur”
Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.
I have a suspicion that we'll find a lot of alt-right Trump-donors on the list.
Or at least can we find and shame the chicken-fuckers? Ha!
* FBI’s Kash Patel defends hiring policy change on bestiality, prostitution | Human Trafficking News | Al Jazeera // https://www.aljazeera.com/news/2026/9/15/fbis-kash-patel-def...
But seriously... the way things are going, I'm glad some motivated third party is backing this stuff up for the future. We're going to need all the data we can get for the next round of Nuremberg trials.
I understand that it's their bosses telling them what to do... but I'd be fully in support of a ban of anyone who had anything to do with the FBI under Trump from ever holding any sort of law-enforcement position ever again. As far as I'm concerned... they're all guilty of conspiracy to commit pedophilia, conspiracy to solicit bribery, likely hundreds of other crimes by hiding the truth from the American people. Wouldn't surprise me at all to learn they've been using all this time to destroy evidence. And I really don't care if they are "just following orders" -- anyone left in the building is in on it at this point.
Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.
They trusted Oracle. I'm not sure I believe you.
If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).
There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.
Now, I made that totally up, but this is how things go. They'll watch one area like a hawk only to leave another glaringly wide door open.
What is even worse is there are a lot of horrifically inefficient apps out there calling way too much data for no reason and suddenly a hack of an entire database gets lost as noise in relation to all the traffic on the servers and networks.
Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.