Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

101–110 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#101
post #22

Earlier quoted context omitted.

> just please don't make me come in to the office. But how do you pick up the stuff from your desk? I once lost a nice pair of headphones this way.

Meh. Don't leave anything at work. Forgo the convenience and carry your things on your commute. Use a bag. If there's "too much stuff", that's a sign to pare back what you "need" at work.

If they are keeping your personal possessions, isn't that theft?

Re: Twin brothers wipe 96 government databases minutes after being fired

#102
post #94

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

Having people with that level of access without some form of two-person-control is already a sign of incompetence.

Twins can defeat two-person control (okay I know one of them was locked out).

Re: Twin brothers wipe 96 government databases minutes after being fired

#103

so, apparently, the passwords were stored in cleartext.

Remind me of a forum a long time ago that sent me my password in clear when I used the "forgot password" link. When I advised them that it was a bad idea to store password in clear, they answered that they keep it in clear so that they can send it when someone forget. Defeated by such argument, I deleted my account.

Circa 2012 the San Francisco water bill pay was able to send me my password in plaintext when I forgot it. I was scandalized. But the alternative was to not pay the water bill, so I just made extra sure the password was very random and wasn't one that got re-used anywhere... I think they fixed this issue in the years since.

Re: Twin brothers wipe 96 government databases minutes after being fired

#104
post #34

Earlier quoted context omitted.

Meh. Don't leave anything at work. Forgo the convenience and carry your things on your commute. Use a bag. If there's "too much stuff", that's a sign to pare back what you "need" at work.

I had my gym stuff in a gym locker. The reason I was able to commit to a gym routine was being able to get off my desk, get down the elevator, enter the gym and change in gym clothes in literally 5 minutes. I would never be willing to commute with all that gear. And I never got that gear back. Still a net positive in my experience.

Same, almost. When I was a student, I rented a locker near the showers so I could start my day at the school gym, shower, and go to my first class.

My workplaces have not had gyms, but I bought equipment for my home that maintains the streamline. I haven't been perfect at my routine because my work schedule isn't consistent which is annoying, but I do still get some exercise in at least twice per week with it. I doubt I'd be getting at least that otherwise.

Re: Twin brothers wipe 96 government databases minutes after being fired

#105
post #94

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

Having people with that level of access without some form of two-person-control is already a sign of incompetence.

Maybe they did, but since they were twins...

Re: Twin brothers wipe 96 government databases minutes after being fired

#106

> At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.” This article is hilarious. The two bickering brothers remind me of the guys in the Oceans movies played by Casey Affleck and Scott Caan. It’s amazing they got this close to sensitive data.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

Yep, Windows Server 2012 being a big one :o

Re: Twin brothers wipe 96 government databases minutes after being fired

#107

Earlier quoted context omitted.

Ready access to AI tools sure makes vandalism easy.

Ai is just a tool. You can kill with hammer, doesn't mean you ban hammers. And they could have used stack overflow instead of ai.

The tools we use are not neutral. A sword can be made to work like an axe, but we use axes for chopping wood because a sword makes a shitty axe. A sword is designed to kill people. The handle, the mass, the weight distribution, and every other aspect I am not qualified to get in to, means swords are designed to kill. They are a tool, and their use is not neutral.

This is a clear example, but I don't believe any tools are neutral. Your immediate fallback was to a hammer, not a mouse, with the obvious corrollary being to bludgeon, but the same line applies. Tools are not neutral, and that's why when you looked for something that causes harm, you grabbed something that's objectively been serving a dual-purpose for hundreds of years. Nobody's using a computer mouse to bludgeon someone to death; it makes a shitty bludgeon, and the design of the tool reflects that.

That's also why these comparisons always fall back to knives, or hammers, or the AK-47: they are dangerous tools that are designed to make killing easier. Nobody is making these comparisons to more benign tools, like desk lamps, coffee cups, or car stereos, and it's because tools are not neutral, and none of my examples are designed to make direct, bodily harm, easier.

Re: Twin brothers wipe 96 government databases minutes after being fired

#109
post #55

How did they get access to 5k passwords? Are they being sent/stored in cleartext? This is the most baffling part of the article for me. The second part I'm unclear about is how you could pass SOC2 when you aren't terminating account access simultaneously with the employment termination.

From the article, it sounds like the passwords are indeed stored in cleartext: > On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akht…

It still blows my mind. Shouldn't the government audit their contracting companies for egregious issues like this? Seems extremely reckless not to.

Re: Twin brothers wipe 96 government databases minutes after being fired

#110
post #55

How did they get access to 5k passwords? Are they being sent/stored in cleartext? This is the most baffling part of the article for me. The second part I'm unclear about is how you could pass SOC2 when you aren't terminating account access simultaneously with the employment termination.

Policy and practice might not be the same thing. The company and the entire management staff should be on somebody’s blacklist for future procurement.

The whole point of stuff like SOC2 and audit to verify that policy is actually implemented. Seems like nobody actually checked.
Post reply on HN