Live data from Hacker News

Hacker wipes Romania's land registry database

news.risky.biz

411–420 of 440 posts

Re: Hacker wipes Romania's land registry database

#411

Earlier quoted context omitted.

Shooting people in the head because they're not wearing a helmet is still a crime.

You can downvote all you want, but there were actual admin accounts with the password P@ssw0rd. So in your view incompetence should just be ignored because blaming people for lack of common sense will hurt their feelings?

Nope. I said that a crime is still a crime, even if the target should know better, in a response to a now flagged comment that was arguing that the criminals were in the right.

You somehow twisted that into "incompetence should just be ignored because blaming people for lack of common sense will hurt their feelings" which is such a ridiculous strawman that you're either arguing in bad faith or you've completely lost all ability to do even the most basic of reading and reasoning.

Re: Hacker wipes Romania's land registry database

#412
post #335
post #208

The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.

Any guidelines on how to back up such that the attacker cannot reach (when the hacker otherwise had some valid credentials)?

You can use old school way. You can have a tape backup, ssd, or a device that is not connected to the network constantly. Copy there and unplug the device.

Re: Hacker wipes Romania's land registry database

#413

Earlier quoted context omitted.

You can't do any real money/real estate transactions without canonical order (chain of events). that's why git analogy is not applicable here. You'd need "main" branch to be canonically finalized for each and every participant.

What? Sure you can. All you need is confidence in the current owner. You don't need the whole history. Can you imagine the poor store clerk trying to say "sorry sir I can't accept that $20 bill unless you can name every prior owner in order". Not sure if you're being deliberately obtuse here but this isn't an issue with the cadence of real estate transactions. Real estate ledgers do not need to support HFT.

Never said you need to store the whole history at all times, i said it must be established in canonical way. Storing latest state is just fine. Event Sourcing works this way too, and allows caching recent state.

Re: Hacker wipes Romania's land registry database

#414

Earlier quoted context omitted.

> Basically, what happened is that they rebuilt it from proof of ownership and testimonies of the people In a similar vein, I was once curious how you would prove your identity if ALL of your relevant documents (passport, driver's license, birth certificate etc) were lost in some kind of cataclysm e.g. a house fire pre-digital etc Turns out there is actually a mechanism for this: - get multiple people to sign sworn a…

In my country (and I think by now most non-US developed countries do something similar) everybody has a CPR(CentralPersonRegistry) number that identifies you, you need it to do almost everything so you aren't likely to forget (its your birthday + 4 digits). You get it at birth or if you come to the country for more than 3 months, it legally mandatory and it's also legally required to inform the government if you chan…

I can’t think of any British or Australian or French personal ID number like this?

Re: Hacker wipes Romania's land registry database

#415

Earlier quoted context omitted.

My ex was late from work once a week because the company did commercial real estate logistics (sort of similar domain here) and she had the job of going to the secure data center and grabbing a backup disk out of the cage and transferring it to a safety deposit box. The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or…

Yes, quite, this. One of the lessons (and subsequent data integrition / continuity of business practices) learned from the 9/11 attacks in New York City, and destruction of both primary and secondary data stores of multiple entities (as well as several emergency-response agencies at various government levels from city to federal) was that essential data and operational roles need to be redundant across very widely-se…

Odd that a terrorist attack achieved what historical knowledge of flood and earthquake damage did not.

Re: Hacker wipes Romania's land registry database

#416

Earlier quoted context omitted.

Yes, quite, this. One of the lessons (and subsequent data integrition / continuity of business practices) learned from the 9/11 attacks in New York City, and destruction of both primary and secondary data stores of multiple entities (as well as several emergency-response agencies at various government levels from city to federal) was that essential data and operational roles need to be redundant across very widely-se…

Odd that a terrorist attack achieved what historical knowledge of flood and earthquake damage did not.

Earthquakes and floods tend not to specifically target major banking and information centres. Terrorist attacks have intentionality.

That said: San Francisco / Silicon Valley are home to both tech and an active seismic zone, and there's long been a tacit understanding that data centres are best located (or at least backed up) at quite some distance. One large brokerage firm located at the time in downtown SF had its datacentre in Arizona, and it wasn't the only such instance. Many other organisations opted for nearer-but-still-remote locations in the Central Valley.

Re: Hacker wipes Romania's land registry database

#417
post #378
post #357

Earlier quoted context omitted.

This is how we implemented this at our company: - We have 2 sources of data that we must backup to continue existing as a business; our postgres and binary files in S3. Everything else is derivable (elasticsearch, so on). - For postgres, we use barman. With the help of opus/fable, you can get a streaming replication backup working in no time. We have one into another server in the same datacenter (we use baremetal) a…

So if a hacker infiltrated your system and silently fed plausable but wrong data into your databases for 10 days, your whole system would be screwed?

My friend, our users would flood our support within 30 seconds of the first blip of this happening.

I'm curious: what's _your_ defense against this?

Re: Hacker wipes Romania's land registry database

#419
He is no scam,I tested him and he delivered a good job,he helped me settle bank loans,he also helped my son upgrade his scores at high school final year which made him graduate successfully and he gave my son free scholarship into the college,all I had to do was to settle the bills for the tools on the job,I used $500 to get a job of $50000 done all thanks to thechoosenhacklord@gmail.com,he saved me from all my troubles,sharing this is how I can show gratitude in return for all he has done for me and my family

Re: Hacker wipes Romania's land registry database

#420
definitely if you're getting a trusted ethical hacker to help you with hack or clone of your spouse phones or even their social media accounts, like messenger, Instagram whatsapp,e mails, etc. i'll recommend to you this hacker with the contact email address, thechoosenhacklord@gmail.com. he has helped me on several hack jobs since my sister introduced him to me , he's been so spectacular . for obvious reasons , i wouldn't want to go into details on how he's helped me hack my spouses accounts and even my friends when they gossip . for relative hack jobs ranging from accounts hack CREDIT SCORE INCREASE CREDIT REPORT FIX SOCIAL MEDIA ACCOUNTS HACK SCHOOL GRADES UPGRADE HACK and some other relative hack job, just hit him up thechoosen hack lord @ g mail.c om, thumbs up for a job well done , that's my review.
Post reply on HN