Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

351–360 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#351
post #91

Earlier quoted context omitted.

And how exactly do you want to store passwords if not in plain text (and then encrypted of course)? 5k is a lot, the authorization process is broken, but this is not related to how the passwords are stored. The only solution is correct access segregation and a bastion

I hope youre joking

(I will be copy/paste this answer for the other comments)

My bad - I misread the post.

To clear things up: I am completely aware about how to store passwords in services that check against them. You are likely to have read some of my prose on that topic in OWASP or at a conference :)

My point, after misreading the article, was that in order to authenticate to a service (the one that holds the hashed version of that password) you need to have access to its cleartext version. This is VERY bad, should never be stored without special considerations etc.

I read the articlae as if they accessed the source of the passwords, the one used to access to services (a vault, with its encryption, access restrictions etc.). 5k was a lot but that could have been bearers or similar ones.

So my comment, and the comments to it, actually yelled at me (that's good!) the way I yell at actual implemententions sometimes :)

In all seriousness - thanks for the reaction, we need more of these. My next obsession are servies that require "only digits" or "strictly 8 to 11 chars" for credentials :)

Re: Twin brothers wipe 96 government databases minutes after being fired

#352
post #79

Earlier quoted context omitted.

And how exactly do you want to store passwords if not in plain text (and then encrypted of course)? 5k is a lot, the authorization process is broken, but this is not related to how the passwords are stored. The only solution is correct access segregation and a bastion

Typically you store a hash of user passwords instead, then when logging in you hash the user password client-side and compare the hashes. This acts like a one-way function that protects the password while letting the user authenticate themselves.

(I will be copy/paste this answer for the other comments)

My bad - I misread the post.

To clear things up: I am completely aware about how to store passwords in services that check against them. You are likely to have read some of my prose on that topic in OWASP or at a conference :)

My point, after misreading the article, was that in order to authenticate to a service (the one that holds the hashed version of that password) you need to have access to its cleartext version. This is VERY bad, should never be stored without special considerations etc.

I read the articlae as if they accessed the source of the passwords, the one used to access to services (a vault, with its encryption, access restrictions etc.). 5k was a lot but that could have been bearers or similar ones.

So my comment, and the comments to it, actually yelled at me (that's good!) the way I yell at actual implemententions sometimes :)

In all seriousness - thanks for the reaction, we need more of these. My next obsession are servies that require "only digits" or "strictly 8 to 11 chars" for credentials :)

Re: Twin brothers wipe 96 government databases minutes after being fired

#353
post #222

Earlier quoted context omitted.

If positive correlations exist between people who do bad things, and their ethnic backgrounds, then it's a pattern worth looking into.

if you personally believe there is a positive correlation between having an ethnic background (mexican or middle eastern or whatever) and doing bad things, I can't control your beliefs still pretty gross of you though

Beliefs can't be "gross", they can only be true or false, justified or unjustified. There is no such thing as a morally wrong belief. That would be the confusion between fact and value.

Re: Twin brothers wipe 96 government databases minutes after being fired

#355
I was always curious how come firing a person is a risk in the US culture.

Outside of the US it's almost never done like that and a person fired is expected to be cooperative and probably even continue working for another two weeks. And not only expected - this is what actually happens.

Re: Twin brothers wipe 96 government databases minutes after being fired

#356
post #156

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

Terminating access and rotating passwords (if needed) while the person is in the meeting but has not yet found out they are being let go has been SOP for at least the last 20 years

But I'm guessing that doesn't work with someone who's been collecting other logins:

> Muneeb had been assembling usernames and passwords—5,400 of them taken from his own company’s network data.

Re: Twin brothers wipe 96 government databases minutes after being fired

#357
post #89

Earlier quoted context omitted.

The obvious middle ground is don’t leave anything valuable at your desk that you wouldn’t want to lose. You shouldn’t leave valuable stuff at your desk even if you don’t expect to be laid off. Unless you work in a very secure environment, you don’t really know who will be sniffing around your desk. Go ahead and leave a coffee mug, who cares if you lose a coffee mug?

I'm really happy I live in a country and company sizes where you could leave your wallet on your desk and nothing happens. Glad I don't need to secure my mug to my desk.

Even in the safest country I would never intentionally leave my wallet at my desk.

Re: Twin brothers wipe 96 government databases minutes after being fired

#358

Earlier quoted context omitted.

he went to work for a company we were a vendor for Sounds like he's getting paid to work on the same thing by a slightly different stakeholder. I'd happily pay $$$$$$ to hire someone with commit access to Cloudflare, AWS or Google's codebase who could fix the goddamn bugs, let alone add new features.

> Sounds like he's getting paid to work on the same thing by a slightly different stakeholder. This honestly sounds like the sort of thing I'd sit down with the employee, their new employer, and various "Compliance Team" members, and firm up a bit. Sounds good for everyone. We get our bugs fixed, $vendor gets to say "Well we have this thing that was developed in-house for BoshNet, that might solve your problem too, i…

No company with a legal rep is going to be happy with that situation - ever.

Who even owns the code the person is working on? Who is responsible when it goes wrong?

Re: Twin brothers wipe 96 government databases minutes after being fired

#359
post #343

Earlier quoted context omitted.

That lawsuit sounds legitimate enough to me. They couldn't find anything for her to do? Hard to believe, but if there's a reason not to fire her then then pay her the money she's owed and stop demanding she show up. Making someone come in with no tasks assigned is fun for a week and quickly turns into punishment detail. Putting someone on punishment detail because you're not allowed to fire them is Bad. Unless she wa…

She had 20 years to resign if it was such a terrible ordeal

They were trying to force her to resign, so she would lose any unemployment benefits.

Re: Twin brothers wipe 96 government databases minutes after being fired

#360

Earlier quoted context omitted.

I suppose that's a very powerful way of preventing "accidents" on termination. But isn't that just theatre? I mean - as though termination is the one and only case where an employee with the power to destroy the company gets angry and might do something really stupid?!

It's not theater, it's defense against aggrievement. Termination is a traumatic event that threatens your ability to exist or provide for dependents. People [rightfully] don't handle exile well. Someone with an interest in scuttling your company could just as easily maintain a low profile and do it at any time. Termination forces execution into a more-predictable timeframe. Once notified, the malevolent only have opp…

Ok but with the European laws the incentive to do something at the last minute doesn't really exist.

This seems like a self inflicted problem where the solution to the problem also made the problem worse when it happens.

If you know that you have X months of pay if you behave, then why misbehave? You'll lose out on money and get a criminal record. Meanwhile if the employer wants you gone it's free money. Everyone is happy.

You've been given enough time to find a new job. It's enough time to sit back and relax at work since you're getting paid either way.

The primary reason why people want to get revenge is because of how inhumane the entire process is.

The mass layoffs are random and impersonal, so you inherently think it is unfair and you will never agree with the reason of the layoff.

The immediate access block and security escort is a reaction and extension of the inhuame treatment.

Post reply on HN