Live data from Hacker News

How hackers made minced meat of Department of Energy networks

arstechnica.com

1–10 of 21 posts

Re: How hackers made minced meat of Department of Energy networks

#3
TL;DR version - if you don't apply security patches, or take basic precautions, you will get compromised.

It is sad that our government IT organizations are so poor, I would consider that a National Security threat much more than having the FBI help some whack job build a fake bomb so they can publicly "break up" a terror plot.

Re: How hackers made minced meat of Department of Energy networks

#4
post #3

TL;DR version - if you don't apply security patches, or take basic precautions, you will get compromised. It is sad that our government IT organizations are so poor, I would consider that a National Security threat much more than having the FBI help some whack job build a fake bomb so they can publicly "break up" a terror plot.

[deleted]

Re: How hackers made minced meat of Department of Energy networks

#5
post #3

TL;DR version - if you don't apply security patches, or take basic precautions, you will get compromised. It is sad that our government IT organizations are so poor, I would consider that a National Security threat much more than having the FBI help some whack job build a fake bomb so they can publicly "break up" a terror plot.

Did the fake bomb scenario actually happen? I'd be interested in reading about that.

Re: How hackers made minced meat of Department of Energy networks

#6
post #3

TL;DR version - if you don't apply security patches, or take basic precautions, you will get compromised. It is sad that our government IT organizations are so poor, I would consider that a National Security threat much more than having the FBI help some whack job build a fake bomb so they can publicly "break up" a terror plot.

Did the fake bomb scenario actually happen? I'd be interested in reading about that.

It sure did; http://www.theguardian.com/world/2013/dec/13/fbi-kansas-suic...

Re: How hackers made minced meat of Department of Energy networks

#7
post #3

TL;DR version - if you don't apply security patches, or take basic precautions, you will get compromised. It is sad that our government IT organizations are so poor, I would consider that a National Security threat much more than having the FBI help some whack job build a fake bomb so they can publicly "break up" a terror plot.

Did the fake bomb scenario actually happen? I'd be interested in reading about that.

http://www.cbsnews.com/news/fbi-terror-stings-entrapment-or-...

I've seen various stories about it. In a couple cases, evidence suggested that the FBI sought out unstable individuals and convinced them to engage in terror plots (instead of working their way into existing terror groups).

Re: How hackers made minced meat of Department of Energy networks

#8
post #3

TL;DR version - if you don't apply security patches, or take basic precautions, you will get compromised. It is sad that our government IT organizations are so poor, I would consider that a National Security threat much more than having the FBI help some whack job build a fake bomb so they can publicly "break up" a terror plot.

One significant reason I don't want the government collecting all of my data is because they seem totally incapable of creating a secure system or even a system that operates properly.

Re: How hackers made minced meat of Department of Energy networks

#9

Earlier quoted context omitted.

Did the fake bomb scenario actually happen? I'd be interested in reading about that.

http://www.cbsnews.com/news/fbi-terror-stings-entrapment-or-... I've seen various stories about it. In a couple cases, evidence suggested that the FBI sought out unstable individuals and convinced them to engage in terror plots (instead of working their way into existing terror groups).

Ahh ok, a little different than what I expected. When I read

> so they can publicly "break up" a terror plot

I thought it was purely to get publicity or instill fear in people while getting good press for the FBI, rather than for a sting operation.

Re: How hackers made minced meat of Department of Energy networks

#10
> Chief among them is the fact that none of the 354 database tables containing social security numbers were encrypted. Using strong cryptography to protect such "at rest" PII has long been considered a best practice in government and corporate data security.

Really? Although I don't work in that field ('government and corporate data security', or generally anything where we have to deal with SSN's and such) -- that doesn't make a lot of sense to me. Encrypted database tables? I've never even heard of that. Can someone who does work in this domain tell us if this makes any sense at all, or translate this into what it actually means technically?

(On the other hand, the fact that 354 database tables existed with SSN's is a red flag in the first place, clearly. There's plenty of clear problems with what was described, I'm just curious about this alleged 'encrypted database table best practice')

Post reply on HN