Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

131–140 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#131

Earlier quoted context omitted.

From the article, it sounds like the passwords are indeed stored in cleartext: > On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akht…

It still blows my mind. Shouldn't the government audit their contracting companies for egregious issues like this? Seems extremely reckless not to.

I'm pretty shocked as well. I thought every company stopped doing this like 20 years ago? Even for a legacy system that is a long time to continue storing credentials like that.

Re: Twin brothers wipe 96 government databases minutes after being fired

#132
post #105
post #94

Earlier quoted context omitted.

Having people with that level of access without some form of two-person-control is already a sign of incompetence.

Maybe they did, but since they were twins...

This takes the whole "you must mean my evil twin" to an actual example. Maybe this is more "you must mean my other evil twin". Part of me really wishes their names were Daryl

Re: Twin brothers wipe 96 government databases minutes after being fired

#134

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

I suppose that's a very powerful way of preventing "accidents" on termination. But isn't that just theatre? I mean - as though termination is the one and only case where an employee with the power to destroy the company gets angry and might do something really stupid?!

Re: Twin brothers wipe 96 government databases minutes after being fired

#136

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

> When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. You're proving my point—employers take the most extreme lesson and it's considered expected practice. They absolutely should have immediately terminated the credentials that granted unilateral access to sensitive databases. (Ideally those would never exist…

The first option is flipping one switch. The second option is flipping some switches now, and flipping the rest later. Of course the safest (first) option is the correct option from a liability standpoint, which is all a company should operate on since it's first responsibility is to protect the company for those that are still there. There's plenty of ways to communicate with ex-colleagues that don't involve company resources or opening the company up to liability.

Re: Twin brothers wipe 96 government databases minutes after being fired

#137

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

There is a middleground, but it requires conscious effort to prop-up, support, and maintain over the long haul: off-boarding centers. I worked for a Big Tech company that actually did this, and it made the transition a lot easier. You could still access corporate resources necessary for the transition (HR, benefits, internal job postings, training offerings, expense reporting, etc), check-in with colleagues 1:1 (who…

you left out the people who enjoy the suffering and pain of the person it is being done to, while they supervise (and film it, in some cases)

Re: Twin brothers wipe 96 government databases minutes after being fired

#138
post #55

How did they get access to 5k passwords? Are they being sent/stored in cleartext? This is the most baffling part of the article for me. The second part I'm unclear about is how you could pass SOC2 when you aren't terminating account access simultaneously with the employment termination.

I can only think of a scenario where this is still valid: spying.

The minimum one can do is have a different randomized password for every service on a possibly completely offline password manager.

Yes, you will depend on a password manager at all times, but at least the blast radius is minimized to the affected service.

Re: Twin brothers wipe 96 government databases minutes after being fired

#139
post #55

How did they get access to 5k passwords? Are they being sent/stored in cleartext? This is the most baffling part of the article for me. The second part I'm unclear about is how you could pass SOC2 when you aren't terminating account access simultaneously with the employment termination.

And how exactly do you want to store passwords if not in plain text (and then encrypted of course)? 5k is a lot, the authorization process is broken, but this is not related to how the passwords are stored. The only solution is correct access segregation and a bastion

I don't think those words mean what you think they mean.
Post reply on HN