Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

151–160 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#151

Earlier quoted context omitted.

I've never had a job with a permanent individual desk like this. The one in-person real job I had, it was only shared working space that different people used at different times of the day or on different days, and I think you were discouraged from leaving anything. The idea of there being "your desk" with a framed photo of your kids and favorite coffee mug seems like a nearly extinct piece of nostalgia. It must have…

May I ask how long you've been working? I'm in my early 40s, and I've never had a job where we've "hot-desked" like that, even when a company was out-growing an office.

I'm on my third job since COVID. None have dedicated desks, and this ranges across startups, corporates and large govt agencies.

Every job I had before COVID back to when I started back in the early/mid 90s had dedicated desks.

Re: Twin brothers wipe 96 government databases minutes after being fired

#152

> While this was going on, the brothers held a running conversation. (The government is not clear about whether this took place over text, instant message, or in person.) Explain to me how we can have a transcript of a conversation without knowing whether it was in person or not. I'm baffled by this sentence.

Probably confession

Re: Twin brothers wipe 96 government databases minutes after being fired

#153
post #107

Earlier quoted context omitted.

Ai is just a tool. You can kill with hammer, doesn't mean you ban hammers. And they could have used stack overflow instead of ai.

The tools we use are not neutral. A sword can be made to work like an axe, but we use axes for chopping wood because a sword makes a shitty axe. A sword is designed to kill people. The handle, the mass, the weight distribution, and every other aspect I am not qualified to get in to, means swords are designed to kill. They are a tool, and their use is not neutral. This is a clear example, but I don't believe any tools…

Murder by computer keyboard: https://www.deseret.com/1997/7/6/19322063/mother-charged-wit...

Murder by ethernet cable: https://www.gainesvilletimes.com/news/dead-woman-found-in-pa...

Murder by laptop: https://www.riverfronttimes.com/william-lynn-gunter-sentence...

Murder by cellphone charger: https://lawandcrime.com/crime/pennsylvania-man-admits-to-str...

Murder by desk lamp: https://www.pressdemocrat.com/2009/01/08/man-beaten-to-death...

Stabbing by coffee mug: https://www.muscalaw.com/blog/north-port-two-women-attack-co...

Re: Twin brothers wipe 96 government databases minutes after being fired

#154

Earlier quoted context omitted.

> When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. You're proving my point—employers take the most extreme lesson and it's considered expected practice. They absolutely should have immediately terminated the credentials that granted unilateral access to sensitive databases. (Ideally those would never exist…

The first option is flipping one switch. The second option is flipping some switches now, and flipping the rest later. Of course the safest (first) option is the correct option from a liability standpoint, which is all a company should operate on since it's first responsibility is to protect the company for those that are still there. There's plenty of ways to communicate with ex-colleagues that don't involve company…

Let’s not forget the third option: proper security practices and principle of least privilege. No one should have been able to do this in the first place. Why were they able to get plaintext passwords with a simple query? Why did they have delete permissions on production db tables? Why were they able to modify system logs and delete backups?

Re: Twin brothers wipe 96 government databases minutes after being fired

#155
This makes sense but also an employee who is dishonest is also a security risk; fired or not.

It's ridiculous that companies don't seem to care about ethics. They never seem to select candidates based on proven ethics. They don't even ask any such questions.

For example, I've been in at least 2 situations where I had the ability to inflict major damage to companies which had treated me very poorly and I could have legally gotten away completely whilst doing variants of 'the wrong thing' and profiting but I didn't do it because I have principles. Unfortunately it seems that few people do nowadays. Leaders are fooling themselves if they think they can completely factor out ethics and make it all about aligning incentives. Incentive alignment creates its own problems as this alignment requires constant maintenance and it's both expensive and detrimental in the long run. These people will tend to sabotage every aspect of their responsibilities which isn't directly measured... In order to gain leverage. It's not clever. It's crooked. Should not be rewarded.

My experience as a software developer is that managers alway have lots of blind spots and the wrong people will take advantage of all of them, even when it negatively impacts the company.

Re: Twin brothers wipe 96 government databases minutes after being fired

#156

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

Terminating access and rotating passwords (if needed) while the person is in the meeting but has not yet found out they are being let go has been SOP for at least the last 20 years

Re: Twin brothers wipe 96 government databases minutes after being fired

#158

> At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.” This article is hilarious. The two bickering brothers remind me of the guys in the Oceans movies played by Casey Affleck and Scott Caan. It’s amazing they got this close to sensitive data.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

> So many red flags

starting with Windows Server _2012_ :O

Re: Twin brothers wipe 96 government databases minutes after being fired

#159

Earlier quoted context omitted.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

I love how this leaks out the fact that the DHS is running production databases on operating systems that are months away from end of extended support. Windows Server has 5 years of mainstream support, 5 years of extended support, and then an extra 3 years paid Extended Security Updates (ESU) support. For 2012 and 2012 R2 that ends in October 2026. The three years of ESU exists only for organisations like government…

It’s a contractor to the DHS, but I’m not sure that makes it worse or better.

Re: Twin brothers wipe 96 government databases minutes after being fired

#160
post #94

Earlier quoted context omitted.

Having people with that level of access without some form of two-person-control is already a sign of incompetence.

Twins can defeat two-person control (okay I know one of them was locked out).

You always have to be careful about overfitting to a specific scenario like "this but if they had also forgotten to lock out the other evil twin". I'd prefer a system that is robust to a malicious employee (more likely: compromise of an employee's credentials) but has a slight gap in the "evil twins" scenario over one that prevents all post-firing malicious access from twins but doesn't consider at all what happens if a current employee's credentials are compromised.
Post reply on HN