Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

291–300 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#291

Earlier quoted context omitted.

If you're talking about Oracle, the large round previous to that they did had individual meetings with employee, manager, and HR. With so many layoffs it took a week+ to do, effectively torturing an entire set of employees who had no idea if they'd have a job by the end of the hour, let alone week. I'm not sure there's any good way to lay off large amounts of staff (besides not getting yourself into the situation in…

>I'm not sure there's any good way to lay off large amounts of staff Someone on HN once wrote that after the dot.com bust, Yahoo! HR had 1-1 meetings with every single employee that was part of the mass layoffs back then, and they did this for hundreds of workers. Boy what I wouldn't give to go back to such state of affairs, even though I wasn't yet part of the workforce back then. An older family friend of mine who…

[deleted]

Re: Twin brothers wipe 96 government databases minutes after being fired

#292

Earlier quoted context omitted.

As opposed to what? Your question seems unclear to me. I already answered you that if you assume full MITM of the frontend then it is physically impossible to prevent gradual credential harvesting. Did you have a different scenario in mind? > how is client side hashing really helping Compared to what? Server side hashing? It prevents the plaintext from ever hitting your infra which minimizes to the greatest extent po…

There is certainly good reason to do server-side hashing: you do not keep a persistent record of the customer's secret, yet keep the ability for them to authenticate with it. If you are never logging a clear-text secret and storing a hashes version to validate against, and using TLS between client and server, client-side hashing does not bring much benefit other than protecting customers' reused passwords against peo…

> There is certainly good reason to do server-side hashing: you do not keep a persistent record of the customer's secret, yet keep the ability for them to authenticate with it.

That is not a property of server side hashing but rather hashing in general.

> If you are never logging a clear-text secret

Yeah good luck with that. /s

It's better not to need to worry about logging plaintext. The less of your infra that falls within any given security boundary the easier it will be to properly secure. The difference between server and client side hashing is how much of your infra touches the plaintext. Less is always better.

Sure, an insider could make direct use of hashes pulled from the logs. However if the attacker already has access to your systems then they are already inside the security boundary (or at least most of them) and likely have many other (probably better) options available to them.

It's important to keep in mind that the primary purpose behind hashing credentials is to minimize the degree to which your systems come into contact with the plaintext. The goal here is to contain the blast radius of any intrusion to only your own systems and only the immediate intrusion (ie to prevent future abuse after you've cleaned everything up) given the unfortunate reality that end users will frequently reuse credentials.

It's also important to keep in mind that hashing is cheap enough that you should probably be doing both. Hash it on the client so that you don't need to worry about logs (or snooping the LAN or whatever other way an employee might come up with to obtain plaintext passwords) and then hash it again before it enters the db so that you don't need to worry about the logs that contain hashes leaking.

Re: Twin brothers wipe 96 government databases minutes after being fired

#293
post #266

Earlier quoted context omitted.

Amateurs. My employer does mass layoffs by terminating access to everything except their email account at 3am, and then sending an email to the victim saying “you were let go at 3am”. Managers get to figure out who’s left on their team by pinging everyone when they learn about it at work.

Google powerwashes your corp Chromebook when they let you go. A friend was composing an email on the train when their screen went black and the device reset itself to factory settings. They even send the “you’re being fired” email to their personal email they have on file. Didn’t even schedule a meeting.

A full email? We need a "you've been fired" emoji.

Re: Twin brothers wipe 96 government databases minutes after being fired

#294

Earlier quoted context omitted.

Looking at it from Europe, this definitely also happens. It depends on the situation. I know of ppl who were kept bcs the parting was in good faith (which was less a firing and more an agreement that parting is in everyone's interest), but I also know of ppl who had their access revoked before firing bcs it wasn't. The latter had unilateral system access as well, which added to it. It's not about humane or inhumane,…

> It's part of the reason why Europe is falling behind on everything. I read a news article that Orange Telecom in France was being sued by a woman they had on payroll for the last 20 years doing nothing, because due to a medical condition she suffered, she became unable to do her job, and since they couldn't fire her due to France unions and labor laws, nor did they have any available job that could fit her current…

If curious, the person is Laurence Van Wassenhove. That should suffice to find out more on the story. Interesting tale.

Re: Twin brothers wipe 96 government databases minutes after being fired

#295

> [Opexus] said that “the individuals responsible for hiring the twins are no longer employed by Opexus.” Getting close to the classic Monty Python line: "Those responsible for sacking the people who have just been sacked, have been sacked." Jokes aside, stuff like this sucks because I suspect many employers will take from it the most extreme, dehumanizing lessons, e.g.: (a) make firings [edit: including lay-offs] as…

When you are talking about access like they had "make firings as abrupt as possible including terminating all access immediately" not doing this is incompetence. This is absolutely a standard and has to be for these kinds of positions. I've never worked anywhere where it wasn't for the majority of IT staff. You meet with HR, someone clears your desk, and security walks you out.

There is another thread elsewhere on the first page about low-trust USA.

Sadly, behaviors and expectations converge toward one another.

Re: Twin brothers wipe 96 government databases minutes after being fired

#296
post #156

Earlier quoted context omitted.

Terminating access and rotating passwords (if needed) while the person is in the meeting but has not yet found out they are being let go has been SOP for at least the last 20 years

Heh, a place where I worked some guy who left kept committing code for months (he went to work for a company we were a vendor for). Some of my teammates knew and just thought it was no big deal, he was fixing bugs and adding features. The color the director turned when he found out!! Oh man.

so he was doing free labor for your company? What's he getting out of that?

Re: Twin brothers wipe 96 government databases minutes after being fired

#297

> On March 12, 2025, a search warrant was executed at Sohaib’s home in Alexandria. Agents grabbed plenty of tech gear but also turned up seven firearms and 370 rounds of .30 caliber ammunition. Given his former crimes, Sohaib should have had none of this. For god's sake, don't commit crimes while you're committing crimes.

> Given his former crimes, Sohaib should have had none of this.

Nobody should have a personal armory.

Re: Twin brothers wipe 96 government databases minutes after being fired

#299
post #156

Earlier quoted context omitted.

Terminating access and rotating passwords (if needed) while the person is in the meeting but has not yet found out they are being let go has been SOP for at least the last 20 years

Heh, a place where I worked some guy who left kept committing code for months (he went to work for a company we were a vendor for). Some of my teammates knew and just thought it was no big deal, he was fixing bugs and adding features. The color the director turned when he found out!! Oh man.

Was his name … Milton?

Re: Twin brothers wipe 96 government databases minutes after being fired

#300

I'm just amused how these people were even hired to begin with ? They don't seem to be Americans? How were they even allowed to work on sensitive systems? Why was this even allowed? So many questions. At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.” At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” H…

I mean it's the DHS. Let's not pretend they're known for competence or hiring the best and brightest. Glorified chimps with ties and guns.
Post reply on HN