Live data from Hacker News

Twin brothers wipe 96 government databases minutes after being fired

arstechnica.com

431–440 of 463 posts

Re: Twin brothers wipe 96 government databases minutes after being fired

#431

Earlier quoted context omitted.

> Given his former crimes, Sohaib should have had none of this. Nobody should have a personal armory.

Fortunately enough Americans have enough guns that no matter how much people like you whine about it you'll never be able to take them away.

Yes, because if the American army went rogue I'm sure a bunch of untrained goons cosplaying as John Wick will be able to take them with some assault rifles and pistols. A very important freedom indeed.

Re: Twin brothers wipe 96 government databases minutes after being fired

#432

Earlier quoted context omitted.

That lawsuit sounds legitimate enough to me. They couldn't find anything for her to do? Hard to believe, but if there's a reason not to fire her then then pay her the money she's owed and stop demanding she show up. Making someone come in with no tasks assigned is fun for a week and quickly turns into punishment detail. Putting someone on punishment detail because you're not allowed to fire them is Bad. Unless she wa…

>They couldn't find anything for her to do? Hard to believe, If a person's now disabled, what can a company give them to do profitably, that isn't already optimized, automated or offshored? There's plenty of civil servants whose jobs are just moving one paper from one room to the next, just to keep more useless people employed that nobody would hire in the private sector. But this doesn't really exist as much in the…

I don't think they offshored the entire office, but if they did they'd probably be able to fire her at that point.

If I found the right article, the disability is epilepsy and paralysis on one side.

Which mean she can do pretty much any office job fine. She already was doing office work, so the disability should not have changed things all that much. I'm sure she typed slower, but that can be worked around and mitigated.

Re: Twin brothers wipe 96 government databases minutes after being fired

#433
post #266

Earlier quoted context omitted.

Google powerwashes your corp Chromebook when they let you go. A friend was composing an email on the train when their screen went black and the device reset itself to factory settings. They even send the “you’re being fired” email to their personal email they have on file. Didn’t even schedule a meeting.

Most of the employer behaviour described in such gleeful terms here would be outright illegal in most of Europe and open up the employer to risk of being sued for wrongful dismissal, etc.

Skeptical that this would actually be illegal in Europe if all the details were provided.

I went through a similar thing at Amazon. Locked out of my laptop at 3 a.m. and emailed I was laid off. The key thing though is that my official end date was 90 days in the future. Legally, the 3 a.m. lock out was actually just a warning of impending layoffs. I got paid to “work from home” for 3 months after I returned my badge and laptop.

My understanding is that Europe may have longer wait periods, but most tech companies still essentially do the same thing there. Amazon’s laid off Berlin employees still get locked out at 3am and told to do nothing for months while legal does whatever it needs to do to get rid of them.

Re: Twin brothers wipe 96 government databases minutes after being fired

#434
post #430

Earlier quoted context omitted.

(I will be copy/paste this answer for the other comments) My bad - I misread the post. To clear things up: I am completely aware about how to store passwords in services that check against them . You are likely to have read some of my prose on that topic in OWASP or at a conference :) My point, after misreading the article, was that in order to authenticate to a service (the one that holds the hashed version of that…

You should have stuck with the 'My bad...' and left out the eye-roll inducing humble brags and inscrutable non-clarifications. But what do I know...I've only been an infosec practitioner since the early 90s...I'm sure 'conference experience' trumps that. (I will not 'be copy/paste' (?) this response everywhere you spammed someone who pointed out the glaringly obvious)

Or I could have let it go.

See, I respect people who point out mistakes, and explain why I did it.

Why did I mention that I do security? Because I spent the last, 25 years trying to push proper practices and did not want to jump into discussions where over 10 comments we would end up flexing about details.

Since you are an infosec practitioner since the early 90s you either are a saint, or did not have to yell through best practices to just let it go.

Not sure what you don't like about conferences? Never got anything from them? I did and I am sure glad to have listened to great presentations.

Re: Twin brothers wipe 96 government databases minutes after being fired

#435

Earlier quoted context omitted.

The fuck would I keep working for if I get fired? Give me my severance if it exists and let me go home that day to start looking for another job. Don't waste my time for 2 weeks to make sure your business doesn't experience any hiccups. If I'm so important that you cannot run without my knowledge, maybe you shouldn't fire me? That being said, burning everything down on your way out the door is absolutely not standard…

> burning everything down on your way out the door is absolutely not standard behavior in the US. Then why is the termination of employment always abrupt with absurd security measures in place including escorting people out of the building?

Why do you use anti malware on your computer or take vaccinations?

Because safety, that's why.

Re: Twin brothers wipe 96 government databases minutes after being fired

#438

Earlier quoted context omitted.

Most of the employer behaviour described in such gleeful terms here would be outright illegal in most of Europe and open up the employer to risk of being sued for wrongful dismissal, etc.

Skeptical that this would actually be illegal in Europe if all the details were provided. I went through a similar thing at Amazon. Locked out of my laptop at 3 a.m. and emailed I was laid off. The key thing though is that my official end date was 90 days in the future. Legally, the 3 a.m. lock out was actually just a warning of impending layoffs. I got paid to “work from home” for 3 months after I returned my badge…

Funnily enough it is actually illegal in Europe and so our laid off German employees were reinstated by court order, several other countries as well. Amazon presumably ran into the same problem, or was smart enough to know they would: they give plenty of notice to European employees and follow local laws. https://www.reddit.com/r/cscareerquestionsEU/comments/1qpni5...

Re: Twin brothers wipe 96 government databases minutes after being fired

#439

Earlier quoted context omitted.

Amateurs. My employer does mass layoffs by terminating access to everything except their email account at 3am, and then sending an email to the victim saying “you were let go at 3am”. Managers get to figure out who’s left on their team by pinging everyone when they learn about it at work.

If you're talking about Oracle, the large round previous to that they did had individual meetings with employee, manager, and HR. With so many layoffs it took a week+ to do, effectively torturing an entire set of employees who had no idea if they'd have a job by the end of the hour, let alone week. I'm not sure there's any good way to lay off large amounts of staff (besides not getting yourself into the situation in…

No, Salesforce.

Re: Twin brothers wipe 96 government databases minutes after being fired

#440
post #248

Earlier quoted context omitted.

It still blows my mind. Shouldn't the government audit their contracting companies for egregious issues like this? Seems extremely reckless not to.

I've been through a handful of SOC2 audits and they've never asked us to _prove_ that we aren't storing passwords in plaintext or with reversible encryption (we weren't). This is why so much of vetting & compliance is toothless. You can have robust change management, physical security, network security, identity management, etc. policies but absolutely nobody wants to spend enough on audit & enforcement to make them…

See: the entire existence of Delve https://www.iansresearch.com/resources/all-blogs/post/securi...
Post reply on HN