Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

121–130 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#121

> At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.” This article is hilarious. The two bickering brothers remind me of the guys in the Oceans movies played by Casey Affleck and Scott Caan. It’s amazing they got this close to sensitive data.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

They forgot a

> "How do I clear chat logs from LLM?"

I guess?

Re: Twin brothers wipe 96 government databases minutes after being fired

#122
> While this was going on, the brothers held a running conversation. (The government is not clear about whether this took place over text, instant message, or in person.)

Explain to me how we can have a transcript of a conversation without knowing whether it was in person or not. I'm baffled by this sentence.

Re: Twin brothers wipe 96 government databases minutes after being fired

#124

Earlier quoted context omitted.

Policy and practice might not be the same thing. The company and the entire management staff should be on somebody’s blacklist for future procurement.

The whole point of stuff like SOC2 and audit to verify that policy is actually implemented. Seems like nobody actually checked.

SOC2 requires an audit. But one of the weaknesses of SOC2 is that the audit mostly checks to determine that you are following whatever your policy is. It doesn't verify that your policy is rigorous.

Re: Twin brothers wipe 96 government databases minutes after being fired

#125

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

Yeah but if you defense against somebody erasing a database is "we remove their access when they're fired" then your defense is garbage. Like there's so many other attack vectors besides an upset ex-employee.. Like all those articles about NK employees who presumably are trying very hard not to be fired. Or employees using company provided insecure email software leaving them vulnerable to ransomware et al.

I'm talking about off-boarding not general day to day security.

Re: Twin brothers wipe 96 government databases minutes after being fired

#126

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

They do all of that now though...

In the US, they'll terminate your access while you're on the Teams Meeting behind the scenes and if you have any gaps, issues, blips, or smudges in your resume it gets thrown into the recycle bin by some AI agent.

Re: Twin brothers wipe 96 government databases minutes after being fired

#127

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

> a more balanced version:

Too complicated and subjective, stinks of more risk.

Also, I don't think it's dehumanizing it all (having been on the receiving end of it way back when during a layoff, and involved in the process more times than I care to count). It's standard practice for involuntary terms at all companies we work with, whether employee is IT or not. If a company is not doing this already, I'd encourage them to.

Re: Twin brothers wipe 96 government databases minutes after being fired

#129
post #8

> At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.” This article is hilarious. The two bickering brothers remind me of the guys in the Oceans movies played by Casey Affleck and Scott Caan. It’s amazing they got this close to sensitive data.

Those two in the movies were always a highlight for me, especially when the one joins the other in the Mexican factory riot.

One of my favorite lines "Peligroso es mi nombre medio" (which of course is not grammatically correct in Spanish) and then his short inspirational speech invoking general Zapata were great.

Re: Twin brothers wipe 96 government databases minutes after being fired

#130

Earlier quoted context omitted.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

I love how this leaks out the fact that the DHS is running production databases on operating systems that are months away from end of extended support. Windows Server has 5 years of mainstream support, 5 years of extended support, and then an extra 3 years paid Extended Security Updates (ESU) support. For 2012 and 2012 R2 that ends in October 2026. The three years of ESU exists only for organisations like government…

It can be quite politically valuable to kick the can to the next administration.
Post reply on HN