Live data from Hacker News

State employees authorized courthouse 'penetration,' records show

desmoinesregister.com

11–18 of 18 posts

Re: State employees authorized courthouse 'penetration,' records show

#11

.. PenTesters for the state/government cybersecurity require a special designation #red_team that allows for incursion and flag dropping; 'tracepoints' -- public disclosure. There are a lot of steps and often it involves writing out a clear mission scope/goals to avoid this type of circumstance. This includes progress reports to their organizational handler announcing the intentions/progress .. progressive research.…

> If the building administrators decline the #red_team audit; then we submit that back into the report and put them on our "naughty list"; which means well try 2x harder to embarrass that particular person You sound quite unprofessional :/

is there a better technique? please share. independent cyber-merc "white hat; with blood stains"

my best approach -- marking people "declined to participate" and naughty list; or for shaming them for not participating in the drill?

?? as i see it; i'm a good guy by paying them a courtesy by informing them of the intentions; working with them; they are the unprofessional ones. perhaps this is my low EQ; and it's why I have assistants.

I have no patience for bureaucrats (i.e. election officials) telling me their system is secure while I know damn well they aren't .. usually I suspect corruption/secrets they would rather not be public ... and the funny thing is ... most of the time I'm right and they turn out to be real pieces of shit that I just happened to get caught on my boot.

Too many of our systems relying on closed source software vendors hiding behind the law pretending (i'm looking at you Oracle) .. ignoring that 90% of North Koreas income comes from hacking; cyber-terrorism cyber-ransom funding radical terrorism scares me.

the small terrorists cells usually don't have a hypermind *(180+ IQ); but nation state [even small ones] probably have at least one or two on the payroll.

iran is a good example of this; we've been talking about these types of attacks "in theory" for years; literally 10 years -- more importantly; due to the success how long before this type of guerilla warfare expands to schools in the USA.

Re: State employees authorized courthouse 'penetration,' records show

#12
post #3

>"I advised them that this building belonged to the taxpayers of Dallas County and the State had no authority to authorize a break-in of this building," Leonard wrote in the email. I was wondering about that. If it is the county courthouse I'm not sure a state employee necessarily can authorize something like a break in.

The right to bring in a 3rd party for security assessment is sometimes part of an IT service contract; the state might have had this (or thought they had this) as part of its electronic records integration with the county.

Re: State employees authorized courthouse 'penetration,' records show

#14

Earlier quoted context omitted.

> If the building administrators decline the #red_team audit; then we submit that back into the report and put them on our "naughty list"; which means well try 2x harder to embarrass that particular person You sound quite unprofessional :/

is there a better technique? please share. independent cyber-merc "white hat; with blood stains" my best approach -- marking people "declined to participate" and naughty list; or for shaming them for not participating in the drill? ?? as i see it; i'm a good guy by paying them a courtesy by informing them of the intentions; working with them; they are the unprofessional ones. perhaps this is my low EQ; and it's why I…

  is there a better technique? please share.
Get hired by someone who has the authority to instruct building services to cooperate.

If the person hiring you doesn't have the authority to do that, they certainly don't have the authority to get your guys out of jail.

Re: State employees authorized courthouse 'penetration,' records show

#16
post #15

This seems silly. The state clearly authorized the operation. The contractor acted in good faith. Yes some mistakes may have been made on both sides but it serves no one to prosecute these guys and label them burglars.

yes your correct

Re: State employees authorized courthouse 'penetration,' records show

#17
post #3

>"I advised them that this building belonged to the taxpayers of Dallas County and the State had no authority to authorize a break-in of this building," Leonard wrote in the email. I was wondering about that. If it is the county courthouse I'm not sure a state employee necessarily can authorize something like a break in.

This is going to be state specific. Generally courthouses are built by county boards, paid for with county bonds, and under the control and management of the local county sherriff. Counties are creatures of the state, but that doesnt mean any random state employee with a similar sounding adjective in their title have any authority over a county institution; it will all depend on the authority granted by legislation and constitutions.

Re: State employees authorized courthouse 'penetration,' records show

#18
post #3

>"I advised them that this building belonged to the taxpayers of Dallas County and the State had no authority to authorize a break-in of this building," Leonard wrote in the email. I was wondering about that. If it is the county courthouse I'm not sure a state employee necessarily can authorize something like a break in.

The right to bring in a 3rd party for security assessment is sometimes part of an IT service contract; the state might have had this (or thought they had this) as part of its electronic records integration with the county.

I don't doubt you're right, I do wonder to what extent everyone would understand something that looks like a physical break in might be part of that.
Post reply on HN