Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

271–280 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#271
post #47

Earlier quoted context omitted.

Perhaps don't hire people who act as foreign adversaries for government work? Is that really such an absurd proposition?

Uhh... The guy in charge of the whole thing does things a foreign adversary would do. Has for years and he's back for round two. He even tried to overthrow the government once.

He wasn’t hired, he was elected.

Re: Twin brothers wipe 96 government databases minutes after being fired

#272
post #266

Earlier quoted context omitted.

Amateurs. My employer does mass layoffs by terminating access to everything except their email account at 3am, and then sending an email to the victim saying “you were let go at 3am”. Managers get to figure out who’s left on their team by pinging everyone when they learn about it at work.

Google powerwashes your corp Chromebook when they let you go. A friend was composing an email on the train when their screen went black and the device reset itself to factory settings. They even send the “you’re being fired” email to their personal email they have on file. Didn’t even schedule a meeting.

Man, that's cold.

Re: Twin brothers wipe 96 government databases minutes after being fired

#273

Earlier quoted context omitted.

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

Last time I was laid off they let me keep my laptop for the rest of the day. I gave it to them immediately to avoid any accusations of sabotage. Eventually I tried to log into one of my old cloud accounts, to find it was only disabled since 9 days after my layoff. Pretty sloppy.

Last time I resigned, I got to keep the laptop and got to promise I had deleted everything work-related.

Re: Twin brothers wipe 96 government databases minutes after being fired

#274
post #254

Earlier quoted context omitted.

Either your dates or experiences are off, because I've been working in software since 1999 and the easiest time to get a job was quite recent, in the back-half of COVID. The early 2000's were decent, but I didn't experience - or know anyone who did - any sort of "free jobs' period. Also pay was relatively decent but much less than what you saw even 5 years ago. It's only the in the past year or so that the world has…

Annecdata: 1996-1999 was super easy, one round start next Monday. 2000-2003 difficult. Easy again until 2008. Hard till 2013. No data since then. What I hear about today seems crazy hard.

Late '90s were crazy easy compared to anything since. If you could demonstrate any amount of technical skill you were in.

Re: Twin brothers wipe 96 government databases minutes after being fired

#275

Earlier quoted context omitted.

> At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?” So many red flags, I can't even.

I love how this leaks out the fact that the DHS is running production databases on operating systems that are months away from end of extended support. Windows Server has 5 years of mainstream support, 5 years of extended support, and then an extra 3 years paid Extended Security Updates (ESU) support. For 2012 and 2012 R2 that ends in October 2026. The three years of ESU exists only for organisations like government…

That's normal in big bureaucracies. I've worked on systems nobody wanted to breath around because nothing could be fixed.

Re: Twin brothers wipe 96 government databases minutes after being fired

#276
post #55

How did they get access to 5k passwords? Are they being sent/stored in cleartext? This is the most baffling part of the article for me. The second part I'm unclear about is how you could pass SOC2 when you aren't terminating account access simultaneously with the employment termination.

Policy and practice might not be the same thing. The company and the entire management staff should be on somebody’s blacklist for future procurement.

The tighter your security is, the more inconvenient it is for legitimate users, and the more you have to do audits because it's easy to justify going around security in the name of efficiency.

It's not just information security, either. I've seen vault doors propped open because the people working inside didn't want to do all the sign-in/sign-out paperwork to take a leak.

Re: Twin brothers wipe 96 government databases minutes after being fired

#277

Earlier quoted context omitted.

If you're talking about Oracle, the large round previous to that they did had individual meetings with employee, manager, and HR. With so many layoffs it took a week+ to do, effectively torturing an entire set of employees who had no idea if they'd have a job by the end of the hour, let alone week. I'm not sure there's any good way to lay off large amounts of staff (besides not getting yourself into the situation in…

>I'm not sure there's any good way to lay off large amounts of staff Someone on HN once wrote that after the dot.com bust, Yahoo! HR had 1-1 meetings with every single employee that was part of the mass layoffs back then, and they did this for hundreds of workers. Boy what I wouldn't give to go back to such state of affairs, even though I wasn't yet part of the workforce back then. An older family friend of mine who…

The 2010s were not that easy to get a job in. It took quite a lot to actually get a job. It didn't take 6+ interviews and takehomes. But you could use a recruiter, go through the interview etc.

There was no leetcode and the resources weren't great. The introduction of leetcode made everything super painful.

Re: Twin brothers wipe 96 government databases minutes after being fired

#279
post #156

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

Terminating access and rotating passwords (if needed) while the person is in the meeting but has not yet found out they are being let go has been SOP for at least the last 20 years

Heh, a place where I worked some guy who left kept committing code for months (he went to work for a company we were a vendor for). Some of my teammates knew and just thought it was no big deal, he was fixing bugs and adding features.

The color the director turned when he found out!! Oh man.

Re: Twin brothers wipe 96 government databases minutes after being fired

#280

Earlier quoted context omitted.

There was a screenshot of some website floating around a few years ago, where if you entered the correct password but a wrong username, it would helpfully tell you which user the password is really for.

But did they handle the edge case of two users having the same password?

"That password's already been taken by user 'mekdoonggi'"
Post reply on HN