Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

161–170 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#161
post #107

Earlier quoted context omitted.

The tools we use are not neutral. A sword can be made to work like an axe, but we use axes for chopping wood because a sword makes a shitty axe. A sword is designed to kill people. The handle, the mass, the weight distribution, and every other aspect I am not qualified to get in to, means swords are designed to kill. They are a tool, and their use is not neutral. This is a clear example, but I don't believe any tools…

Murder by computer keyboard: https://www.deseret.com/1997/7/6/19322063/mother-charged-wit... Murder by ethernet cable: https://www.gainesvilletimes.com/news/dead-woman-found-in-pa... Murder by laptop: https://www.riverfronttimes.com/william-lynn-gunter-sentence... Murder by cellphone charger: https://lawandcrime.com/crime/pennsylvania-man-admits-to-str... Murder by desk lamp: https://www.pressdemocrat.com/2009/01/08/…

My larger point is that nobody - nobody - defaults to telling us the coffee mug is unregulated, as AI allegedly ought to be. They always compare it to something much more commonly used as a weapon; something that, when asked to name a household object likely to be used as a weapon, the average person would guess.

Re: Twin brothers wipe 96 government databases minutes after being fired

#162

Earlier quoted context omitted.

It still blows my mind. Shouldn't the government audit their contracting companies for egregious issues like this? Seems extremely reckless not to.

I'm pretty shocked as well. I thought every company stopped doing this like 20 years ago? Even for a legacy system that is a long time to continue storing credentials like that.

20 years is rookie numbers in these systems. I guarantee it’s been at least 40 years since a single fuck was given.

Re: Twin brothers wipe 96 government databases minutes after being fired

#163
post #127

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

> a more balanced version: Too complicated and subjective, stinks of more risk. Also, I don't think it's dehumanizing it all (having been on the receiving end of it way back when during a layoff, and involved in the process more times than I care to count). It's standard practice for involuntary terms at all companies we work with, whether employee is IT or not. If a company is not doing this already, I'd encourage t…

> Too complicated and subjective, stinks of more risk.

I actually think there's less risk, because it's not as narrowly focused on what a just-fired employee can do. That's not the only scenario of concern.

> Also, I don't think it's dehumanizing it all (having been on the receiving end of it way back when during a layoff, and involved in the process more times than I care to count).

Interesting. Thanks for the perspective. I've been fortunate enough to not be on the receiving end of a lay-off, knock on wood. It's happened to my teammates/reports though. Wasn't my decision. :-(

Re: Twin brothers wipe 96 government databases minutes after being fired

#164
I'm just amused how these people were even hired to begin with ? They don't seem to be Americans? How were they even allowed to work on sensitive systems? Why was this even allowed? So many questions.

    At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.”

    At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?”

    In the space of a single hour, Muneeb deleted around 96 databases with US government information.

Re: Twin brothers wipe 96 government databases minutes after being fired

#165

> Muneeb and Sohaib Akhter, now both 34, had been in trouble before. Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two. After their stints in jail, the brothers worked their way back into the tech world. In 2023, Muneeb got a job with a Washington, DC, firm that sold software and services to 45 federal…

No, this is exactly what giving people second chances looks like. It means taking a risk that they're the sort of person who is likely to commit a crime and who will commit a crime again after being given the second chance. The only way to prevent this is to have a blanket policy against giving second chances to people convicted of crimes, which harms people who genuinely intend to reform and not commit crimes again, and who you cannot systematically distinguish from chronic criminals.

Re: Twin brothers wipe 96 government databases minutes after being fired

#166

Earlier quoted context omitted.

Perhaps don't hire people who act as foreign adversaries for government work? Is that really such an absurd proposition?

I don't think they were spies. They have ethnic names, but it sounds like they are just good ol' red-blooded Yankee crooks.

[flagged]

Re: Twin brothers wipe 96 government databases minutes after being fired

#167

Earlier quoted context omitted.

> When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. You're proving my point—employers take the most extreme lesson and it's considered expected practice. They absolutely should have immediately terminated the credentials that granted unilateral access to sensitive databases. (Ideally those would never exist…

The first option is flipping one switch. The second option is flipping some switches now, and flipping the rest later. Of course the safest (first) option is the correct option from a liability standpoint, which is all a company should operate on since it's first responsibility is to protect the company for those that are still there. There's plenty of ways to communicate with ex-colleagues that don't involve company…

I'd argue that failing to segregate things so that there's a switch for the sensitive stuff and a separate switch for the not-sensitive stuff is an operational failure. A rank and file employee having access to his email account should never pose a serious liability to the business.

Re: Twin brothers wipe 96 government databases minutes after being fired

#168

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

If you don't trust your people so much, why to hire them in a first place?

Looking at it from Europe - it is such a weird inhumane practice.

Someone decided your position is redundant. Okay, shit happens, economic downturn, etc. Then you have extra 3-6 months of work to pass your knowledge, train replacement and document everything.

Re: Twin brothers wipe 96 government databases minutes after being fired

#169

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

I suppose that's a very powerful way of preventing "accidents" on termination. But isn't that just theatre? I mean - as though termination is the one and only case where an employee with the power to destroy the company gets angry and might do something really stupid?!

It's not theater, it's defense against aggrievement. Termination is a traumatic event that threatens your ability to exist or provide for dependents. People [rightfully] don't handle exile well.

Someone with an interest in scuttling your company could just as easily maintain a low profile and do it at any time. Termination forces execution into a more-predictable timeframe. Once notified, the malevolent only have opportunity to exfiltrate or sabotage whatever they can reach in the time it takes to walk them out the door.

European laws require us to give people something like two months' notice. Even then we don't trust them; we pay them their salary and tell them to stay home.

Re: Twin brothers wipe 96 government databases minutes after being fired

#170

Earlier quoted context omitted.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

Ready access to AI tools sure makes vandalism easy.

A tool which is supposed to supercharge you - supercharges you.
Post reply on HN