Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

11–20 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#11

> At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.” This article is hilarious. The two bickering brothers remind me of the guys in the Oceans movies played by Casey Affleck and Scott Caan. It’s amazing they got this close to sensitive data.

I think its them on video: https://youtu.be/Rx19zOzQeis

Re: Twin brothers wipe 96 government databases minutes after being fired

#13

so, apparently, the passwords were stored in cleartext.

Remind me of a forum a long time ago that sent me my password in clear when I used the "forgot password" link. When I advised them that it was a bad idea to store password in clear, they answered that they keep it in clear so that they can send it when someone forget. Defeated by such argument, I deleted my account.

I've got a better one. I once had the same argument mentioned to me by my manager at the time when I pointed out that passwords were being stored in clear text. That it needs to be this way so that it is read/sent when the users forget their passwords(which happened a lot). I tried to explain that typically a "reset password" flow is used for that but that fell on deaf ears. That system contained healthcare data.

Something bad did end up happening due to that lax security and there were oh so many meetings about it.

Re: Twin brothers wipe 96 government databases minutes after being fired

#14
post #2

I have no problem with my credentials being revoked everywhere before I know about a layoff. I don't really care how I learn about it, just please don't make me come in to the office.

So this was why the FBI Director Kash Patel was in a panic when he couldn't log in one day. Revoking credentials before firing someone makes a lot of sense in security.

no, becaus the simple and pragmatic solution for ANYONE who is subject to arbitrary termination, is to litter everything they build with caltrops and dead man triggers and then hint that they will go into "consulting" when fired.

I know of one case where this was totaly unintentional, and a machinest at a local pulp and paper plant had self delegated to write the software that controlled tension on the giant machines in the mill, but as it was his only real forey into sofware, nobody else could operate it, and they fired him after a manegment reshuffle, and then after the next scheduled shut down, nothing worked right, greasy dusty ancient screen with a blinking cursor was what they had, plugged into the important bits of a half sqare mile plant. still funny to think about!

Re: Twin brothers wipe 96 government databases minutes after being fired

#15

> On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter. That password was subsequently used to access that individual’s email accou…

This is what I want to know. Are there any consequences for this contractor? At least fraud or negligence or something?

Re: Twin brothers wipe 96 government databases minutes after being fired

#17

so, apparently, the passwords were stored in cleartext.

Remind me of a forum a long time ago that sent me my password in clear when I used the "forgot password" link. When I advised them that it was a bad idea to store password in clear, they answered that they keep it in clear so that they can send it when someone forget. Defeated by such argument, I deleted my account.

Greetings, Bioconductor

Re: Twin brothers wipe 96 government databases minutes after being fired

#18
> Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter.

WTF?

Re: Twin brothers wipe 96 government databases minutes after being fired

#19

so, apparently, the passwords were stored in cleartext.

Remind me of a forum a long time ago that sent me my password in clear when I used the "forgot password" link. When I advised them that it was a bad idea to store password in clear, they answered that they keep it in clear so that they can send it when someone forget. Defeated by such argument, I deleted my account.

In my free time, I help maintain the web presence for a small non-profit org with memberships. The original system when I started helping was a bespoke system that was smart in many ways (essentially a static site generator with membership control years before SSGs were cool, with regular automated tests), but the guy who wrote it absolutely insisted on storing passwords in plaintext and could not be convinced otherwise. Eventually he had to drop the volunteer position due to other things in life, and the first thing we did was correct this issue.

Re: Twin brothers wipe 96 government databases minutes after being fired

#20
post #4

How on earth did someone previously convicted of what sounds like hacking get job access to so many prod government databases? Wild that it took them so long to get caught.

I had the same questions. Apparently discovery of the prior conviction is what lead to them being fired:

> When the company discovered Sohaib Akhter’s felony conviction, it terminated both brothers’ employment during an online remote meeting on Feb. 18, 2025

from https://www.justice.gov/opa/pr/federal-jury-convicts-virgina... which is a better source on this.

That prompts the question of why background checks are so lax that they were hired before this was discovered.

Post reply on HN